ColdCard Exploit Triggers Largest Small-Holder Bitcoin Transfer Surge Since FTX Collapse
Key Takeaways
- •Approximately 39,600 BTC was transferred in sub-1 BTC transactions on July 31, 2026, the highest daily volume by small holders since the FTX collapse in November 2022.
- •The ColdCard exploit has resulted in approximately 1,367 BTC stolen from roughly 4,585 addresses across three coordinated waves, valued at nearly $89 million.
- •The vulnerability stems from a firmware flaw affecting ColdCard devices manufactured between 2021 and 2025 that generated predictable wallet seeds, enabling attackers to reconstruct private keys without physical access.
- •Unlike typical hardware wallet incidents involving phishing or malware, this exploit represents a systemic failure of the device's cryptographic random number generation itself.
- •Security researchers advise affected users to transfer all funds to wallets generated on devices from different manufacturers and to avoid reusing any addresses derived from vulnerable seeds.

Bitcoin holders moved nearly 40,000 BTC in transactions of less than 1 BTC following the ongoing ColdCard wallet exploit, marking the largest daily movement by smaller holders since the collapse of FTX in November 2022, according to CryptoQuant.
ColdCard, manufactured by Coinkite, has been one of the most widely recommended Bitcoin-only hardware wallets among self-custody advocates, making the breach particularly disruptive to a community that has long pointed to dedicated hardware devices as the gold standard for offline private key storage.
CryptoQuant Head of Research Julio Moreno reported that 39,600 BTC were transferred on July 31, 2026 — just shy of the 39,900 BTC moved on November 16, 2022, days after FTX filed for bankruptcy.
"The Bitcoin plebs had not moved this amount of BTC in a day since the FTX collapse," Moreno wrote. "39.6K BTC transferred on July 31st after the coldcard hack, 39.9K BTC transferred on November 16 2022, a few days after the FTX collapse. These are Bitcoin transfers < 1 BTC." He added that it was encouraging to see users "taking action" to secure their funds.
The spike comes as the suspected ColdCard exploit continues to expand. Researchers now estimate the attack has unfolded across three coordinated waves, with approximately 1,367 BTC stolen from roughly 4,585 addresses, worth nearly $89 million at current prices.
The $90 million ColdCard $BTC wallet drain sees #Bitcoin drop as small holders seek refuge on centralized exchanges. The incident has become one of the #LARGEST ATTACKS ever targeting BITCOIN SELF CUSTODY through cryptographic key generation rather than malware, phishing or… pic.twitter.com/wqPL7eQUMa
— BitKE (@BitcoinKE) August 3, 2026
The incident has become one of the largest failures of Bitcoin self-custody in recent years, prompting thousands of users to move funds to new wallets or centralized exchanges as a precaution.
The exploit stems from a firmware flaw that generated predictable wallet seeds on affected ColdCard devices manufactured between 2021 and 2025. Because the vulnerability allowed attackers to mathematically reconstruct private keys without physical access to the hardware wallet, security researchers say it represents a fundamentally different type of hardware wallet failure compared to conventional phishing or malware attacks. Most previously documented hardware wallet incidents have involved supply chain tampering, social engineering, or user error in seed phrase handling — not a systemic failure of the device's cryptographic random number generation itself.
Security researchers advise that users who generated wallet seeds on affected ColdCard devices should assume those wallets are compromised, transfer all funds to a newly generated wallet using a device from a different manufacturer or a independently verified entropy source, and avoid reusing any address derived from the vulnerable seed.
The incident has reignited debate over Bitcoin self-custody. Some users argue that properly generated offline wallets remain the safest way to hold Bitcoin, while others have shifted assets to custodians or spot Bitcoin ETFs following the breach.