Security

Coldcard Exploit Fallout: 233k BTC Moved to Safety, New Address Creation Spikes

2 min read
Coldcard Exploit Fallout: 233k BTC Moved to Safety, New Address Creation Spikes

Four waves of theft since July 30. At least 1,816 bitcoin gone, roughly $116 million siphoned from Coinkite’s Coldcard hardware wallets by attackers exploiting a firmware bug. And holders have relocated a far larger sum to safer setups.

The damage, though, is only half the story.

New Bitcoin addresses jumped from roughly 260,000 to more than 330,000 per day last week, The Block reported. The spike snapped a decline trend that had held through most of 2026. It is the clearest network-level signal that holders acted on the advisory at scale. They did not wait out the vulnerability.

The root cause, per The Block, traces to 2021. Coldcard units generated wallet seeds using a weak software random number generator instead of the device’s hardware entropy source. That collapsed effective key strength enough for attackers to brute-force wallet generations offline, then drain the resulting wallets. Coinkite advised anyone who generated a wallet between March 2021 and the subsequent security patch to move funds to freshly created wallets.

Casa CEO Nick Neuman told Bitcoin Magazine that 233,000 BTC were moved to safer self-custody configurations in the exploit’s aftermath. A flow Casa observed as users restructured their holdings. The figure dwarfs the stolen amount and frames the episode less as a pure loss event than as a real-time forced migration of the self-custody base.

The Block framed things differently. A stress test of self-custody itself. Removing a custodial counterparty does not remove implementation risk. Events like this surface dangers holders still face even when following recommended practices. Users, the outlet notes, are increasingly weighing self-custody against custodial options (exchanges, ETFs) as hardware-wallet exploits have stacked up through 2026.

Neuman sees it the other way. The 233,000-BTC relocation proves self-custody held up. Not that it failed. Holders, as ever, are divided on which reading fits.

What remains unclear is the exact composition of the 233,000-BTC flow. Single-key users upgrading to multisig? Multisig users dropping Coldcard from their signer sets? Both? Casa has not published a breakdown by source setup. Coinkite has not detailed the patch timeline beyond the advisory to regenerate wallets from the affected window. And a widely circulated Reddit thread attributing roughly $130 million in losses to a developer known as “Doc Hex” is unconfirmed by either primary source. The Block’s own tally sits lower, at $116 million across four waves.

The gap between the two figures is the part worth watching — $116 million stolen, 233,000 BTC relocated. One measures what the bug cost. The other measures what it spooked into moving.

Avatar of Mara Velasquez

Mara Velasquez

Mara Velasquez covers markets and DeFi for NFT Signals, reporting on price action, liquidity and the listed companies with crypto on their balance sheets. She also tracks exploits and stolen-funds recovery.