A Coldcard hardware wallet exploit that began on July 30 has affected more than 1,000 addresses, with estimated losses between 1,000 and 1,300 BTC, valued at approximately $70 million to $90 million. A firmware bug that weakened seed phrase generation entropy since March 2021 was the culprit behind the compromise of investor funds.
Panic over the security of personal storage devices immediately triggered an unexpected exodus of assets.
The Return to Centralized Platforms
Small-sized transfer volume for wallets under 1 BTC reached 39,600 BTC on July 31, nearing the 39,900 BTC moved on the day of FTX’s bankruptcy on November 16, 2022. CryptoQuant’s head of research, Julio Moreno, emphasized that the retail Bitcoin investor group had not moved this much assets in a single day since the collapse of that exchange.
At the end of July, daily Bitcoin deposits to exchanges in transaction sizes of less than 10 BTC surged to 7,300 BTC, making it the highest level since February 6. Total net inflows to exchanges touched 11,163 BTC on the same day, with the majority of the coins landing on major platforms such as Binance, River, Kraken, and OKX. This influx of funds lifted the Bitcoin supply in exchange wallets from 2,703,837 to 2,715,000 BTC. Network activity also surged, as seen from daily active addresses jumping sharply from 645,000 on July 30 to nearly 1 million the following day, a high point since December 10, 2024.
Why Similar to FTX But in the Opposite Direction?
The scale of this asset movement matches the FTX-era exodus, but in the opposite direction. In 2022, investors raced to withdraw their Bitcoin from centralized exchanges into self-custody to avoid corporate bankruptcy risks. Now, doubts about the security of personal tools have instead driven thousands of coin holders to move their Bitcoin back to exchanges because third-party platforms are perceived to be safer.
Binance founder CZ even responded to this phenomenon by questioning the security of hardware wallets and the practicality of the self-custody concept for the majority of crypto users.
The True Boundary of Vulnerability
The surge in exchange deposits was driven by fear rather than a careful technical evaluation. This exploit specifically targeted a system vulnerability in Coldcard, not indicating a fundamental failure of self-custody functionality. Hardware wallets from other manufacturers and seed phrases generated using correct procedures are completely unaffected by this vulnerability.
For most users, dissecting system specifications when news of a multi-million dollar hack spreads is a luxury they do not have. When uncertainty peaks, the first instinct of many is not to inspect their device’s code, but to run to the nearest open exchange door.
As reported by CoinDesk.
Disclaimer: This article is for informational and educational purposes only, not financial advice. Cryptocurrency assets are highly volatile and carry significant risk. Always do your own research (DYOR) and never invest more than you can afford to lose.