NewsCryptoColdcard Users Rush to Move Funds as Hardware Wallet Vulnerability Triggers Major Outflows

Coldcard Users Rush to Move Funds as Hardware Wallet Vulnerability Triggers Major Outflows

Author: The Market Periodical·

Key Takeaways

  • CryptoQuant said Bitcoin holders with less than 1 BTC moved 39,600 BTC by July 31 after the vulnerability was disclosed.
  • The transfer volume was the largest short-term movement by smaller holders since the FTX collapse in November 2022.
  • Security researchers said some Coldcard wallets generated predictable seed phrases because of a software bug introduced in 2021.
  • Galaxy Research said it has confirmed 1,596 BTC stolen from 7,300 addresses across multiple attack waves, with losses possibly reaching 2,055 BTC.
  • Bloomberg analyst Eric Balchunas said the incident could make some investors view Bitcoin ETFs as safer alternatives.
Coldcard Users Rush to Move Funds as Hardware Wallet Vulnerability Triggers Major Outflows

Coldcard users are rushing to move funds after a critical hardware-wallet vulnerability was disclosed, with smaller holders moving 39,600 BTC over the past few days, according to CryptoQuant. Galaxy Research said more than $100 million has already been stolen in the incidents, while Bloomberg analyst Eric Balchunas said the episode could push more investors toward Bitcoin exchange-traded funds (ETFs).

Bitcoin holders controlling less than 1 BTC moved 39,600 BTC by July 31, CryptoQuant reported. The activity followed public disclosures about a severe Coldcard hardware-wallet vulnerability. CryptoQuant’s data, however, covers all sub-1 BTC holders and cannot identify which transfers came specifically from Coldcard users.

The volume marked the largest short-term movement from smaller holders since the FTX collapse in November 2022. During that earlier period, sub-1 BTC holders moved about 39,900 BTC, according to CryptoQuant’s comparison. At current Bitcoin prices, the latest transfer volume was worth roughly $3.2 billion.

Small Bitcoin Holders Move 39,600 BTC

The large outflow is unsurprising given the scale of the attacks. Hackers discovered a vulnerability in the cold wallet that caused some Coldcard wallets to generate easily predictable seed phrases.

Coldcard developer CoinKite notified users about the flaw last week, and security experts said it stemmed from a software bug introduced in 2021. The bug caused some of the wallets to use a non-cryptographic pseudo-random number generator.

So far, more than $100 million has been stolen, and more than 7,000 addresses have been affected. Galaxy Research said it has confirmed 1,596 BTC stolen from 7,300 addresses across three confirmed attack waves and 14 smaller incidents.

The firm also said there may have been a fourth wave, although it has not received full confirmation. It estimated the stolen funds could total as much as 2,055 BTC, or about $130 million.

CoinKite has released a firmware update to patch the issue for affected Coldcard models, but the nature of the attack means there is no software fix for a wallet that has already been compromised with predictable seed phrases.

The only solution is to create a new address and move funds to it. That also means the attack remains ongoing, even after CoinKite issued a warning urging users to migrate funds to protect against the crypto scam. More than a dozen attackers are reportedly exploiting the vulnerability, underscoring why the incident has prompted such rapid movement from smaller holders who may be trying to secure funds before any additional exposure.

Expert Says Hack Could Spur ETF Migration as Crypto Scam Losses Mount

The incident has drawn a range of reactions from the crypto community. Cold wallets have long been considered safer than hot wallets and even centralized exchanges such as FTX, but the Coldcard hack has shown they can still be vulnerable.

Some victims are already considering suing CoinKite, with claims emerging that the company was warned about the exploit earlier. Efforts to identify and recover the stolen funds are also continuing.

Bloomberg senior analyst Eric Balchunas said the episode could lead more people to embrace Bitcoin ETFs. In a post, he said some investors may now view Bitcoin ETFs as safer options after the latest crypto news.

According to Balchunas, Bitcoin ETF sponsors are major financial institutions that work with larger custodians such as Coinbase to store users’ assets, which typically adds extra layers of security.

He noted that an ETF custodian could still be compromised, but said such an incident would likely trigger greater regulatory scrutiny and stricter law-enforcement investigations than a crypto scam involving a small company.

The Coldcard hack adds to the rising losses from crypto scams and hacks this year. In the first half of 2026, $972 million was stolen in 207 hacks, according to TRM Labs.

This article is for informational purposes only and does not constitute financial or investment advice. Cryptocurrency prices remain highly volatile.