Key facts
- A firmware bug in Coldcard hardware wallets allowed attackers to reconstruct seed phrases.
- The exploit has led to an estimated loss of 1,000-1,300 BTC, valued at $70-90 million.
- Daily Bitcoin deposits to exchanges under 10 BTC reached their highest level since February 6.
- Daily active Bitcoin addresses saw a significant spike following the exploit.
- The movement of funds to exchanges is the opposite of the trend observed after the FTX collapse.
The recent Coldcard hardware wallet exploit, which began on July 30, has prompted some Bitcoin holders to move their assets to centralized exchanges, a move that contrasts with the investor behavior following the FTX collapse in late 2022. The exploit, stemming from a firmware bug that weakened seed phrase generation, has led to estimated losses of 1,000-1,300 BTC, approximately $70-90 million, across over 1,000 addresses.
Blockchain analytics firm CryptoQuant reported a significant spike in daily exchange deposits of Bitcoin transfers under 10 BTC, reaching 7,300 BTC on July 31, the highest since February 6. This surge in small transfers to exchanges was accompanied by a spike in daily active addresses, which climbed to nearly one million on July 31, the highest since December 10, 2024. Julio Moreno, head of research at CryptoQuant, noted that these movements suggest increased caution among investors seeking safety.
Blockchain sleuths observed total net inflows to exchanges of 11,163 BTC on July 31, with funds flowing into major platforms like Binance, River, Kraken, and OKX. This influx of smaller transactions mirrors the volume seen shortly after FTX filed for bankruptcy in November 2022, indicating a heightened level of concern among retail investors, referred to as 'plebs'. The total number of BTC held in wallets tied to centralized exchanges has subsequently increased.
The Coldcard incident exploited a flaw dating back to March 2021, where some devices used a predictable software random number generator instead of a hardware RNG, reducing seed randomness and making seed phrases reconstructible offline. This has led prominent figures, including Binance Founder CZ, to question the general safety of hardware wallets and self-custody. However, the incident is considered specific to Coldcard, with most other hardware wallets and properly generated seeds remaining unaffected.
