Newsletter Subscribe
Enter your email address below and subscribe to our newsletter
[forminator_form id="25163"]

cbc+1bloomingbit+1finance.yahoo+1A firmware vulnerability in Coldcard hardware wallets that has drained an estimated $130 million in Bitcoin since July 30 triggered a far larger response across the self-custody ecosystem, with approximately 233,000 BTC — worth roughly $15 billion — migrating from long-term holder wallets to new storage setups, according to reporting by Decrypt and Yahoo Finance.finance.yahoo
Casa CEO Nick Neuman said the mass migration demonstrated that "distributed self-custody is Bitcoin's immune system, not its weakness," according to Yahoo Finance. The movement dwarfed the stolen funds by more than 100 times, as holders rushed to secure their assets in multisig wallets, fresh seeds, and regulated custodians.finance.yahoo
The attack exploited weak randomness in Coldcard Mk3 firmware versions 4.0.1 through 5.0.3, released beginning in March 2021, which routed private key generation through predictable software randomness rather than true hardware randomness. This allowed attackers to reconstruct affected wallet recovery phrases and drain funds off-device.youtube
The first wave struck on July 30, draining more than 1,000 BTC worth about $70 million from roughly 1,200 wallets in just 41 minutes. Subsequent attack waves pushed total losses past $130 million across more than 7,000 addresses, according to Galaxy Research. Manufacturer Coinkite warned that firmware updates alone cannot protect keys generated during the vulnerable window — affected users must generate entirely new seeds and migrate funds.redsecuretech+4
On-chain data tracked by CoinDesk showed long-term holder supply falling from 15.0 million BTC to 14.7 million BTC in the week following the breach. Analysts characterized the movement as custody migration rather than capitulation, noting Bitcoin's price remained stable near its pre-hack levels. Some transfers came from Coldcard users shifting to multisig setups, while others came from Ledger and Trezor users prompted to reassess their own security.bloomingbit+2
New wallet creation spiked to 2.27 million in the days after the hack, the strongest on-chain reading in months.news.bitcoin
The incident has reignited debate over hardware wallet security. Neuman, whose company sells multisig custody solutions, argued that the rapid community response validated the broader self-custody model — estimating that ten times more Bitcoin was proactively secured than was stolen. Critics note, however, that the vulnerability went undetected for more than five years before exploitation.thestreet
CoinDesk described the episode as "not profit-taking, but a migration in how bitcoin is being stored" — a distinction that may define how the industry remembers the largest hardware wallet exploit of 2026.coindesk