The Coldcard firmware hack has drained ~$130M in BTC from 7,300+ addresses, driving 890K BTC in weekly onchain movement, with analysts flagging rising demand for regulated custody.
Bitcoin News
A flaw in the Coldcard hardware wallet's firmware has cost users an estimated $114 million to $130 million in Bitcoin since July 30, and the fallout is now showing up in onchain data, with coin movement reaching its highest level of the year.
K33 Says Panic From Coldcard Hack Is Visible in Onchain Data
K33 head of research Vetle Lunde attributed the surge primarily to users moving funds in response to the Coldcard exploit. He said the breach had also raised concerns among users of other hardware wallets, including Ledger and Trezor. Some of those users appear to have shifted funds to centralized custodians or multisignature setups, Lunde said. He added that elevated active supply readings have historically lined up with local market turning points, citing examples across the 2022 bear market, the 2024 and 2025 bull markets, and the current 2026 bear market. Two of this year's largest spikes in active supply coincided with selloffs in February and June.
Related Article: Coldcard Hack Tops $100M as Galaxy Flags Possible 4th Wave
Loss estimates differ across firms covering the exploit. K33 calculated roughly 1,596 BTC stolen from about 7,300 addresses. Cantor put confirmed losses at at least 1,816 BTC, worth around $114 million, drained from more than 5,200 addresses. Galaxy Research estimated total losses at approximately 2,000 BTC, or about $130 million, when including suspected but unconfirmed thefts. Galaxy also said at least 15 separate attackers exploited the firmware vulnerability behind the breach.
Cantor Sees Custody Firms as Potential Beneficiaries of the Breach
Investment bank Cantor said in an Aug. 5 client note that the exploit may redirect users toward managed custody solutions. It named Robinhood Markets, Coinbase Global, BitGo Holdings, Bullish, eToro Group, and Gemini Space Station as firms that could see increased inflows as a result. Digital asset specialist Nico Pasquariello wrote that token flows to custodians and exchanges would be expected to rise in the wake of the hack.
FRNT Financial said the incident highlights a fundamental tension in self-custody. Holders who control their own private keys still place trust in the hardware and software that generated those keys. The firm compared the Coldcard breach to the 2023 "Milk Sad" exploit, where a flaw in key generation led to roughly $900,000 in losses. FRNT said it does not expect the breach to turn users away from self-custody entirely. Instead, it said wallet providers will face pressure to raise security standards as users demand stronger guarantees.
For those who prefer not to manage private keys, FRNT said spot Bitcoin ETFs are becoming a more practical option. The firm did not name specific products.