Bitcoin’s on-chain activity just jumped for the wrong reason: a Coldcard firmware flaw forced holders to move coins out of vulnerable wallets, pushing active addresses to 0.98 million a day while Bitcoin price stayed stubbornly calm in the mid-$60, 000s.
- 0.98 million active addresses/day, Glassnode said that was the highest since December 2024
- Coldcard seed-generation bug, a hardware-wallet failure, not a Bitcoin protocol problem
- Loss estimates vary, from 1, 596 BTC stolen to Galaxy’s roughly 2, 000 BTC estimate
- Price held firm, BTC remained around the mid-$60, 000 range despite the panic
The cleanest way to read this is simple: this was defensive wallet migration, not a fresh wave of bullish demand. People were not piling into Bitcoin because they suddenly found religion. They were moving fast because a widely used cryptocurrency wallet had a serious seed-generation flaw, and nobody wants to learn the hard way that “cold storage” can still come with a burn risk if the randomness is broken.
Glassnode said on August 6 that Bitcoin active addresses surged to 0.98 million per day, the highest level since December 2024. The firm described the move as fear-driven on-chain activity, with holders migrating seeds and shifting funds to alternative custody after the Coldcard exploit.
That distinction matters. Active addresses can rise for a lot of reasons: new demand, wallet consolidation, exchange activity, or, in this case, pure self-preservation. A chart can look bullish while the underlying behavior is basically people sprinting for the exits.
What actually broke
The issue sits with Coldcard, the hardware wallet made by Coinkite. The flaw was in seed generation, which is the process used to create the master recovery phrase that controls a wallet’s private keys. In plain English, some affected wallets were born with weaker randomness than they should have had.
That is not a minor cosmetic bug. Entropy is the randomness that makes one wallet seed unpredictable and another one impossible to guess. If the seed space is weakened, the resulting keys become materially easier to attack than a properly generated 128-bit seed.
Coinkite’s advisory said the problem affected multiple models and firmware versions. For Mk2 and Mk3, firmware 4.0.1 through 4.1.9 inclusive was vulnerable. For Mk4, Mk5, and Q, Coinkite said affected seeds had about 72 bits of entropy rather than the expected 128 bits.
That also means updating firmware alone does not fix an already-generated weak seed. Coinkite told affected users to move their Bitcoin and reseed with safe settings. No fluff here: if the seed was generated badly, the wallet is not “kind of okay.” It is a problem waiting to happen.
To make the point even clearer, this was not a remote hack of the Bitcoin network. It was a custody failure at the hardware-wallet layer. Bitcoin kept working. The wallet security stack did not.
The theft numbers are ugly, but they are not all the same number
Loss estimates vary depending on who is counting and what they are counting. Some figures refer to confirmed thefts, while others include suspected compromised funds or broader exposure. That means the safest way to present the numbers is as a range, not as one neat headline dressed up as certainty.
Galaxy Research said thieves had stolen 1, 596 BTC, worth over $100 million, from around 7, 300 addresses. In broader reporting cited by CoinMarketCap, Galaxy put the total closer to about 2, 000 BTC, or roughly $130 million, and said at least 15 different attackers were racing to drain vulnerable wallets.
CoinMarketCap also cited Cantor with a separate estimate: at least 1, 816 BTC in confirmed losses, worth around $114 million, from more than 5, 200 addresses.
Those numbers do not fully line up because they are not measuring exactly the same thing. Different analysts are using different time frames, confidence thresholds, and address-linking methods. Some are counting only confirmed thefts. Others are including suspected attacker-controlled wallets. That is normal during an active security event, and it is also why anyone claiming perfect precision is probably overselling it.
One important detail from the broader reporting: later analysis reportedly mapped a smaller, more specific set of suspected attacker-controlled addresses, but also noted that not every address could be computationally confirmed as being generated with weak Coldcard entropy. In other words, the event is real, the damage is real, but the final accounting is still messy.
Why Bitcoin price barely reacted
Bitcoin held in the mid-$60, 000 range while the security scare unfolded, and volatility stayed relatively contained. That matters because it suggests the market is treating this as a vendor-specific custody failure, not a Bitcoin failure.
If the protocol itself were broken, the reaction would likely have been much harsher. Instead, the signal from price was basically: this is bad, but it is not systemic.
That is an important distinction for anyone who still thinks “Bitcoin” and “wallet” are the same thing. They are not. Bitcoin the network kept doing its job. The problem was the software and hardware used by some holders to secure their keys.
That does not make the event harmless. It means self-custody is only as strong as the entire chain around it: hardware, firmware, randomness, passphrases, backups, and user discipline. “Be your own bank” sounds heroic until you realize you also need to be your own security team.
Why this spike looks defensive, not bullish
Glassnode’s framing is the right one here: fear-driven on-chain activity. The market saw a security scare, and holders responded by moving funds to safer storage.
That is not the same thing as healthy adoption. It is more like an evacuation than a crowd arriving for a concert. Same direction of movement, very different meaning.
The practical response from users will likely split in a few directions. Some will migrate to other hardware setups. Some will use multisig, which requires multiple keys to spend funds and reduces single-device failure risk. Others may decide that managing self-custody is too much of a pain and hand the job to a custodian.
That last option comes with its own trade-offs. Centralized custody is easier, but it reintroduces counterparty risk. There is always a bill somewhere in the system. You just pay it in a different currency.
What this means for self-custody
Coldcard is a reminder that hardware wallets are not magic talismans. They reduce attack surface, but they still depend on good software, good randomness, and good operational hygiene. If any of those break, the whole setup can go sideways fast.
This is why weak randomness is such a nasty failure mode. It does not just create a bug. It can create a wallet that was weak from birth. And once the seed exists, updating the device later does not retroactively make it stronger.
Coldcard flaw tops $100M as David Schwartz warns pointed to that deeper tension: self-custody is powerful, but users still trust the hardware and software that generated the keys in the first place. FRNT does not expect this to kill self-custody. It does expect pressure for higher standards, which is the least the industry should demand after a screw-up like this.
The comparison to the 2023 “Milk Sad” exploit is useful here. That was another key-generation flaw in wallet-related software, and it caused roughly $900, 000 in losses. Different product, same ugly lesson: weak randomness is not a small bug. It is a disaster with a delay timer on it.
The takeaway for Bitcoiners is not to panic about the network. It is to stop romanticizing custody as if gadgets alone solve security. They do not. They help, sometimes a lot, but they are still built by humans, and humans ship bugs.
Key questions and takeaways
-
Was Bitcoin hacked?
No. The problem points to a Coldcard seed-generation flaw, not a failure of the Bitcoin protocol itself. -
Why did active addresses jump?
Holders were moving funds defensively after the exploit. That is on-chain activity, but it is not the same thing as fresh demand. -
How serious was the damage?
Very serious. Reported losses range from 1, 596 BTC stolen to Galaxy’s broader estimate of about 2, 000 BTC, depending on what was counted. -
Did all Coldcard products get hit?
No. Coinkite said TAPSIGNER, OPENDIME, and SATSCARD are not affected. -
Why did Bitcoin price stay firm?
The market appears to view this as a wallet-security failure, not a systemic Bitcoin problem. -
What is the real lesson?
Self-custody gives freedom, but it also demands serious operational discipline. If the seed generation is weak, “your keys” can become “your problem” in a very expensive way.
Further reading
A few related reports and primary-source notes if you want to track the fallout and the self-custody angle a bit deeper.
- Bitcoin Active Addresses Surge to 0.98M/Day After Coldcard
- Firmware Update Advisory for Coldcard Mk2, Mk3, Mk4, Mk5
- Two More Waves Raise Suspected Coldcard-Linked Losses to
- one of my wallets was drained
- Bitcoin Active Addresses Surge to 0.98 M/Day After
- Bitcoin Holds Steady After Coldcard Firmware Flaw Drains
- Bitcoin Faces $512M $70K Bid Wall as Coldcard MK5 Pushes