TLDR
A firmware flaw in Coldcard hardware wallets has triggered one of Bitcoins largest self?custody breaches and a sharp spike in BTC network activity.
- Attackers exploited weak seed generation in Coldcard devices, stealing roughly 1,6002,000 BTC (about $100130 million) from thousands of addresses.
- On?chain activity jumped to multi?month and yearly highs, with active addresses, mempool congestion, and both whale and retail transactions surging.
- Price impact has stayed muted so far, but elevated panic flows and custody shifts could mark an important turning point in how BTC is stored and moved.
Deep Dive
1. What Happened In The Coldcard Hack
Researchers link the incident to a March 2021 Coldcard firmware change that generated wallet seeds with much less randomness than intended, making some recovery phrases guessable offline. Reports from Galaxy Research and others put confirmed losses at about 1,596 BTC, with total exposure potentially up to 2,055 BTC (around $130 million) across roughly 7,300 addresses created with vulnerable firmware on multiple Coldcard models.Coldcard attack details
Coinkite, the maker of Coldcard, has shipped emergency firmware and destroyed remaining vulnerable inventory, but updating does not fix old weak seeds: users must create new wallets and move funds. Around 90% of stolen BTC is still sitting in tagged attacker addresses, and some of it is now being moved through cross?chain routes and mixers, increasing laundering risk.Network impact overview
2. How BTC Network Activity Spiked
As the exploit unfolded, Bitcoins on?chain metrics jumped. K33 and others report about 890,000 BTC moving on?chain over seven days, the highest seven?day active supply of 2026.Seven?day active supply
Santiment data cited by several outlets show around 712,000 active addresses in the week (a three?month high) and 61,800 transactions over $100,000 (a five?month high), as both whales and smaller holders reshuffled coins.Address and whale activity
Hot supply (BTC in more liquid states) nearly doubled, and exchanges saw net inflows of over 22,000 BTC while mempool pending transactions climbed to the highest levels since early 2025.Hot supply and mempool
On?chain, you are seeing a mass migration out of single?sig wallets and into exchanges or new setups rather than a normal trading spike.
3. Price Reaction And Custody Shifts
Despite the scale of the breach and the activity surge, BTC has held in a relatively tight range around the mid?$60,000s, with only small single?digit moves during the peak of flows.Price range and mempool
Analysts note that similar spikes in seven?day active supply often appear near local tops or bottoms, but do not give a clear direction by themselves. The more durable change may be in custody behavior: many affected users are moving toward multisignature vaults or institutional custody, while others reassess hardware wallet risk across brands.
Confidence: high, based on multiple consistent research and news sources.
Conclusion
The Coldcard exploit did not compromise Bitcoin itself, but it exposed a critical weakness in one popular self?custody tool and pushed an unusually large volume of BTC across the network.
The immediate impact is a wave of defensive transactions and custody changes, with price comparatively stable. The next key signals will be whether attacker coins start moving in size, whether exchange inflows reverse, and how quickly users adopt more robust custody setups.
