The number of active Bitcoin addresses surged to 0.98 million per day, the highest level since December 2024, as holders rushed to move funds off Coldcard hardware wallets in the wake of an active exploit. On-chain analytics firm Glassnode described the spike as fear-driven activity, with holders migrating seeds and shifting funds to alternative custody as an operational security response rather than routine transactional demand.
The exploit traces back to a five-year-old firmware flaw in Coinkite's Coldcard device. A build configuration error introduced in a March 2021 firmware release caused seed generation to fall back on a weak software random number generator instead of the device's dedicated hardware entropy source, collapsing effective key strength from a designed 128 bits down to as little as 40 bits on affected units, low enough to brute-force with modern computing power and without needing physical access to the device.
Losses Have Climbed Past $116 Million
The theft began on July 30, when an attacker started sweeping funds from affected wallets; within 25 minutes, roughly 594 BTC, worth close to $38 million at the time, had moved out of about 500 wallets into a single consolidation address. At least four separate waves of theft have followed since, and Galaxy Research's running tally now puts total losses near 1,816 BTC, worth close to $116 million, drained from more than 5,200 addresses.
Coinkite has confirmed the vulnerability affects certain Mk3 devices set up on firmware 4.0.1 or later, along with Mk4, Mk5 and Q devices running older firmware versions. Wallets originally generated using Coldcard's dice-roll entropy option are not affected and are considered safe.
Related: Researcher Infiltrated North Korea's Hackers, Found Coinbase and Uniswap Among 1,640 Victims
A Fresh Test for Self-Custody's Reputation
The incident has reignited a long-running debate over the practical risks of self-custody, with some commentators arguing that episodes like this could push more retail holders toward custodial solutions such as spot Bitcoin ETFs rather than managing hardware wallets themselves. That tension echoes broader questions raised elsewhere in crypto custody and security, including recent findings on how systematically attackers have targeted wallet and exchange infrastructure across the industry this year.
For now, the surge in active addresses is itself a signal of how seriously holders are taking the threat: rather than waiting to see whether they are affected, a meaningful share of the network appears to be moving first and asking questions later.