BTC
ETH
HTX
SOL
BNB
View Market
简中
繁中
English
日本語
한국어
ภาษาไทย
Tiếng Việt

Coldcard Vulnerability Leads to $89 Million Theft, Triggering Largest On-Chain Migration Since FTX Collapse

Foresight News
特邀专栏作者
2026-08-03 03:08
This article is about 2520 words, reading the full article takes about 4 minutes
Put/Call Ratio Hits Record Low, On-Chain Signals Distorted, AI Defense Gaps Exposed.
AI Summary
Expand
  • Core Insight: A firmware vulnerability in Coldcard wallets triggered large-scale Bitcoin theft and user migration to safer alternatives, distorting on-chain data and severely dampening market sentiment, while also exposing how U.S. AI safety guardrails constrain cybersecurity defense efforts.
  • Key Elements:
    1. A Coinkite firmware flaw resulted in insufficient mnemonic entropy, compromising 4,585 addresses and leading to the theft of 1,367.05 BTC (approximately $89 million).
    2. Users transferred funds en masse to mitigate risk, with total transaction volume from outputs under 1 BTC reaching 39,600 BTC on July 31 — the highest since the FTX collapse. Active addresses surged by 350,000 in a single day to nearly 1 million.
    3. Market sentiment deteriorated sharply, with the bullish/bearish comment ratio plummeting to 0.58, an all-time low, as the compromise of cold wallets shook holders' confidence in their last line of defense.
    4. Galaxy Research has reported approximately 600 hacker addresses, but major U.S.-based AI models refused to analyze the attack payloads due to safety rules, forcing the investigation team to switch to an open-source Chinese AI model for tracing.
    5. Hugging Face faced a similar dilemma: its security team was denied analysis of attack logs by commercial large language models, ultimately using Zhipu AI's open-source model GLM 5.2 for local forensics, reducing several days of work to just hours.
    6. Only 77,402 BTC from long-dormant wallets moved on-chain. Analysts emphasize this reflects wallet hardening behavior rather than panic selling, but it will skew metrics such as long-term holder supply statistics.

Original Author: Oluwapelumi Adejumo

Original Translation: Saoirse, Foresight News

The Coldcard wallet crisis has hit Bitcoin market sentiment hard, distorting various on-chain reference metrics while exposing long-standing shortcomings in AI-assisted network defense systems.

On July 30, hardware manufacturer Coinkite issued a risk warning to users: wallets generated by specific versions of Coldcard firmware are at risk of asset theft, caused by a software bug that made the randomness of mnemonic phrases far lower than design standards.

Galaxy Research stated that the security incident involved three waves of attacks, with a total of 4,585 addresses targeted for intrusion and 1,367.05 BTC stolen, valued at approximately $89 million.

Coldcard Bitcoin wallet hack (Source: Galaxy Research)

Alex Thorn, Galaxy's Head of Global Research, said the stolen Bitcoin from the three attack waves remains in addresses controlled by the attackers. However, he added that some small, scattered stolen funds have already been laundered through peel chains, cross-chain services, and offshore casinos.

Coldcard Wallet Migration Disrupts Bitcoin Bearish Signals

As the security risk continues to unfold, users with potential exposure are rushing to move their Bitcoin to prevent their assets from being stolen by hackers. Although Coinkite has pushed a fixed firmware update for affected models, the high-risk mnemonic phrases already generated cannot be repaired through system updates. Users can only create brand-new wallets and transfer their assets to secure addresses.

This large-scale wallet migration has caused an abnormal surge in on-chain activity from small holders and long-dormant Bitcoin. Julio Moreno, Head of Research at CryptoQuant, noted that on July 31, the total volume of transactions with outputs under 1 BTC reached 39,600 BTC. This is the highest single-day figure for this transaction category since the FTX collapse in November 2022; shortly after the FTX incident, the same category saw a flow of 39,900 BTC.

The number of daily active Bitcoin addresses also surged from approximately 645,000 on July 30 to nearly 1 million the following day, marking the highest level since December 10, 2024. Moreno stated that the surge in address numbers was concentrated in outgoing addresses, with receiving addresses seeing only minimal growth — a clear indication that users were transferring funds out of their original wallets for risk-avoidance purposes.

Bitcoin daily active addresses (Data source: CryptoQuant)

Exchange deposits from transfers under 10 BTC rose to 7,300 BTC, hitting a new high since February 6 of this year. Some users temporarily deposited assets into exchanges during the transition period while creating new secure wallets, though this fund flow also includes holdings from investors preparing to sell and cash out.

Bitcoin exchange deposits surge after Coldcard incident (Source: CryptoQuant)

CryptoQuant analyst JA Maartunn added that since the vulnerability was disclosed, 77,402 BTC that had been dormant for an extended period have been transferred. However, Maartunn cautioned that this large-scale fund movement should not be interpreted as evidence of widespread panic selling. Given the context of the incident, the fund movement essentially reflects users strengthening wallet security.

He stated: "The Coldcard mnemonic issue has prompted users to move long-held Bitcoin to ensure asset security. This will distort the accuracy of various chart data, including changes in long-term holder supply, coin days destroyed, and spent output age distribution."

Alongside the surge in on-chain transaction activity, overall market sentiment has deteriorated sharply. Blockchain analytics firm Santiment noted that the ratio of bullish to bearish Bitcoin comments across the network has fallen to its lowest level since the platform began modern social data tracking. On platforms like X, Reddit, and Telegram, there are only 0.58 bullish comments for every 1 bearish comment.

Bitcoin market sentiment turns bearish (Source: Santiment)

Santiment believes the intense market reaction stems from the fact that this vulnerability attacked cold storage wallets. Most holders view cold wallets as the last line of defense for their Bitcoin assets after withdrawing from exchanges and distancing themselves from high-risk crypto platforms.

US AI Governance Rules Complicate Coldcard Case Investigation

The wallet transfers that disrupted Bitcoin market signals also make stolen fund tracing an urgent priority — the flow must be tracked before funds reach platforms where they can be exchanged and withdrawn.

Galaxy Research compiled victim reports, identified a list of suspected hacker addresses, and shared the information with law enforcement, compliance agencies, and other cybersecurity investigators. Thorn revealed that the firm has reported approximately 600 suspected hacker addresses holding stolen Bitcoin.

However, he stated that safety guardrails on major American AI models have hindered stolen asset tracing and user protection efforts, forcing the investigation team to switch to an open-source Chinese AI model. Thorn did not specify which American AI models were involved, which queries were blocked, or how the alternative model assisted the investigation. Even so, the dilemma he described closely mirrors the challenges Hugging Face faced after a previous cyberattack.

The AI platform reported that automated programs had infiltrated parts of its infrastructure, requiring the security team to analyze over 17,000 event records. Initially, investigators accessed mainstream frontier models through commercial APIs, uploading attack instructions, exploit payloads, and command-and-control logs for analysis.

Hugging Face stated that all these queries were blocked by the systems. The reason: AI security frameworks could not distinguish between investigators responding to an emergency and actual attackers. The team ultimately chose GLM 5.2, an open-weight model developed by Zhipu AI, and completed all forensic analysis on their own servers.

The model helped staff piece together the complete attack timeline, locate leaked credentials, extract intrusion signatures, and distinguish genuine attack traces from decoy interference. Hugging Face noted that forensic work that would normally take days was compressed to just hours with AI assistance.

This case illustrates the AI asymmetry problem Thorn identified in the Coldcard incident: attackers can use unrestricted, self-modifiable AI tools that are not bound by commercial model safety rules, while defenders submitting materials with malicious characteristics for case investigation often face AI refusals — even when the intent is to contain a serious security incident.

However, broadly removing AI safety restrictions would create new risks. AI service providers cannot simply grant unrestricted access based on a user's verbal claim of tracing stolen coins, as such unrestricted tools could equally be abused for wallet attacks, money laundering, and evading trading regulations.

Within the crypto space, this contradiction is particularly acute: stolen assets can flow through cross-chain bridges, exchanges, and gambling platforms within minutes. If tracing is delayed, funds will be transferred to platforms where they can be freely withdrawn before victims receive their police reports or investigators complete manual forensics, eliminating any chance of freezing them.

wallet
Safety
FTX
Welcome to Join Odaily Official Community