TLDR
A critical firmware bug in Coldcard hardware wallets has triggered one of Bitcoins largest self-custody breaches and a record surge in mempool and on-chain activity as users migrate funds.
- Coldcards flawed seed generation has been linked to thefts of roughly 1,596 to 2,055 BTC, or about $120 million to $130 million, across thousands of addresses.
- Panic-driven moves doubled Bitcoins seven-day hot supply, with about 890,000 BTC moving and mempool congestion reaching around 90,000 pending transactions, a 2026 high.
- The episode is reshaping custody preferences, pushing some users toward multisig and institutional custody while the market watches for further sweeps, exchange inflows and delayed price reactions.
Deep Dive
1. Scale Of The Exploit
Reports from Galaxy Research and multiple outlets describe a firmware flaw in Coldcard devices that caused wallet seeds to be generated with much less randomness than intended. This allowed attackers to reconstruct private keys without touching the hardware, draining single-signature wallets remotely.
Analyses estimate at least 1,596 BTC stolen, with a possible fourth wave lifting losses toward 2,055 BTC, worth roughly $130 million, affecting about 7,300 addresses across several attack waves. Coverage from Decrypt explains that older Mk2 and Mk3 devices dropped from 128 bits of entropy to around 40 bits, making brute-force attacks feasible, while newer models still fell short of expected security levels.
Manufacturer Coinkite has pushed emergency firmware, destroyed vulnerable inventory and urged users to generate new seeds and move funds, noting that updating firmware alone does not fix already compromised seeds.
2. Record On-Chain Activity
On-chain data shows the Coldcard crisis has driven unusual Bitcoin network activity despite relatively calm prices. Research from K33 and others finds around 890,000 BTC moved over seven days, the highest seven-day active supply seen in 2026.
Newhedge data cited by Bitcoin.com reports Bitcoins seven-day hot supply jumping 98 percent, from about 403,000 BTC to around 797,000 BTC, while price slipped only about 0.5 percent before rebounding. At the same time, mempool statistics highlighted by CoinDesk show pending transactions around 89,000 to 96,000, the highest congestion since early 2025.
Exchanges have seen net inflows in the tens of thousands of BTC as users temporarily park coins on large venues while migrating away from weak seeds. Dormant addresses, including some dating back to 2010, have also woken up to move significant balances.
Bitcoins fee and congestion profile is being driven more by defensive repositioning than by speculative froth, which can precede later volatility if stress in custody persists.
3. Custody And Next Steps
The incident has sharpened the trade-off between self-custody and delegated custody. Commentators note that self-custody avoids exchange failure risk but exposes users to hardware, software and phishing vulnerabilities, while ETFs and institutional custodians add third-party risk but potentially tighter operational controls.
In the near term, security teams are tracking attacker wallets and early laundering attempts via mixers and cross-chain routes. Roughly 90 percent of the stolen BTC reportedly remains unmoved, giving investigators time but also leaving a large overhang.
For users, the main signals to watch are any further waves of sweeps from vulnerable seeds, sustained exchange inflows, shifts toward multisig setups and whether this spike in active supply eventually breaks Bitcoins unusually tight recent trading range.
Conclusion
The Coldcard hack has turned a niche firmware bug into a system-wide custody stress test, driving record mempool congestion and seven-day Bitcoin movement without an immediate price collapse. How users and institutions re-allocate between hardware wallets, multisig solutions and regulated custodians in the coming weeks will shape both network usage and the next phase of Bitcoins risk profile.
