Need help? Support
BITCOIN
Tether Dominance USDT.D

Coldcard hack drives BTC network activity

Published 530 words 3 min read

TLDR

A firmware flaw in Coldcard Bitcoin hardware wallets has enabled a large theft and triggered a visible spike in Bitcoin on-chain and mempool activity.

  1. Attackers exploited weak seed generation in Coldcard devices, stealing roughly 1,600 to 2,055 BTC, or about 100 to 130 million dollars, from thousands of addresses.
  2. As users rush to move coins, Bitcoins active supply, address activity, whale transactions and mempool congestion have all jumped to multi?month or yearly highs.
  3. The incident is reshaping custody behavior, pushing some holders toward exchanges or multisig, and elevated activity may mark an important market turning point to watch.

Confidence: high because several independent research and news outlets report consistent metrics and link the activity surge directly to the Coldcard exploit.

Deep Dive

1. Scale And Nature Of The Hack

Coldcard is a popular Bitcoin (BTC) hardware wallet; its firmware contained a bug that generated recovery seeds with far less randomness than intended, letting attackers reconstruct private keys offline. Galaxy Research and others estimate at least 1,596 BTC stolen from about 7,300 addresses, with potential losses up to around 2,055 BTC (about 130 million dollars) if a fourth attack wave is confirmed, all tied to the same Coldcard wallet flaw.

The vulnerability affects wallets created with specific firmware versions since 2021, not the Bitcoin protocol itself. Updating firmware alone does not protect old seeds, so affected users must generate new wallets and move funds to new addresses.

2. How Activity Spiked On-Chain

Research from K33 and others links the Coldcard crisis to the strongest Bitcoin on-chain activity of 2026, with nearly 890,000 BTC moving on-chain in seven days and seven?day active supply at a yearly high, as detailed in this surge-in-activity report.

Santiment data shows around 712,000 active addresses in a week and about 61,800 whale transactions above 100,000 dollars, the highest in months, while mempool transactions waiting for confirmation have climbed to levels not seen since early 2025, according to a mempool-focused analysis.

Exchanges have seen net inflows of tens of thousands of BTC as holders move funds to perceived safer venues, and hot supply (coins that recently moved) has nearly doubled in a week, described as panic visible onchain in a hot-supply study.

3. Custody Shifts And What To Watch

Many affected and non?affected users are rotating from single?signature hardware wallets into multisig setups, centralized custodians, or ETFs, as coverage like this custody-shift overview notes.

Analysts highlight that similar spikes in active supply often appear around local tops and bottoms, so traders are watching whether increased exchange inflows lead to selling, or whether strong hands absorb coins and tighten liquid supply.

What this means

The Coldcard hack is a stress test for self?custody; monitoring hardware wallet security, BTC flows to and from exchanges, and future active?supply spikes can help gauge whether this shock turns into a lasting market inflection.

Conclusion

The Coldcard exploit has not broken Bitcoin itself, but it has driven one of the largest hardware?wallet hacks to date and unleashed a wave of defensive coin movement.

That wave is lighting up on-chain metrics, mempool congestion and exchange balances, while forcing many holders to rethink how they store BTC.

If elevated activity coincides with shifts in exchange inflows and volatility, this hardware wallet failure could mark an important turning point in Bitcoins current cycle.

Educational information only. Crypto markets are volatile and this is not financial advice.


Top