TLDR
A security flaw in Coldcard hardware wallets triggered a record spike in recently moved Bitcoin, effectively doubling its seven day "hot supply" without major price damage so far.
- The Coldcard firmware bug let attackers reconstruct wallet seeds, stealing around 1,6002,000 BTC and forcing many holders to move coins urgently.
- Onchain data shows seven day hot supply jumped about 98 percent to nearly 800,000 BTC, plus exchange net inflows of over 22,000 BTC, while price stayed relatively stable.
- The incident is reshaping custody behavior, raising hardware wallet scrutiny and nudging some users toward multisig, custodians, or ETFs; further attack waves and inflows remain key to watch.
Deep Dive
1. What Actually Broke
Reports link the chaos to a Coldcard hardware wallet exploit caused by a firmware flaw introduced in 2021 that generated wallet seeds with too little randomness.
Researchers at Galaxy and K33 estimate at least 1,596 BTC was stolen from about 7,300 addresses, with potential losses up to roughly 2,055 BTC, or around 130 million dollars, across multiple attack waves.
Because the flaw made some seeds predictable, attackers could reconstruct private keys offline and drain single signature wallets without touching the devices, forcing affected users to migrate funds in a hurry.
2. How Hot Supply Doubled And Why It Matters
"Hot supply" here means Bitcoin that moved within a given window, often seven days, not coins in exchange hot wallets. K33 and Newhedge recorded seven day hot supply jumping from about 403,000 BTC to around 797,000 BTC, a roughly 98 percent increase in one week.
Nearly 890,000 BTC moved onchain in seven days, the highest seven day active supply of 2026, and exchanges saw net inflows of roughly 22,000 BTC as some users treated them as temporary safer custody. Yet BTC price stayed in a tight range around 63,00064,000 dollars, with volatility muted.
Historically, such spikes in seven day active supply have clustered near local tops and bottoms, but they do not guarantee direction; they mainly show "panic visible onchain" as long term holders reshuffle positions.
Elevated activity without big price swings suggests defensive repositioning more than outright capitulation, but it marks a stress point where sentiment can flip quickly if inflows turn into sustained selling.
3. Custody, Risk, And What To Watch
The breach has put hardware wallet security under heavy scrutiny, with commentators warning that self custody depends on both good firmware and user practices, and that importing a weak seed into another device does not remove the vulnerability.
Industry responses emphasize generating new recovery phrases, using more robust setups such as multisig, and for some users considering regulated custodial solutions or spot Bitcoin ETFs that outsource key management to professional custodians.
Key signals to monitor now are any further attack waves, whether stolen BTC starts moving toward mixers or exchanges, and whether exchange reserves and seven day hot supply retreat back toward normal levels or stay elevated.
Confidence: high because multiple independent onchain analyses and news reports converge on the same theft estimates and activity patterns.
Conclusion
The Coldcard incident did not create new Bitcoin, but it abruptly turned a large chunk of dormant supply "hot," exposing how concentrated technical flaws can ripple through network behavior.
For crypto users, the takeaway is that custody choice is a security trade off: hardware wallets, exchanges, and ETFs each carry different risks, and events like this shift where the market collectively feels safest.
If onchain activity normalizes and stolen coins remain hard to monetize, the episode may become a contained stress test; if attacks or inflows persist, it could evolve into a deeper debate about how Bitcoin should be held at scale.
