BTC/USD $68,420 +2.8%
ETH/USD $3,540 +1.4%
SOL/USD $142.80 -0.6%
BNB/USD $605.20 +0.9%
XRP/USD $0.62 -1.2%
DOGE/USD $0.18 +5.4%
BTC/USD $68,420 +2.8%
ETH/USD $3,540 +1.4%
SOL/USD $142.80 -0.6%
BNB/USD $605.20 +0.9%
XRP/USD $0.62 -1.2%
DOGE/USD $0.18 +5.4%
Bitcoin

Coldcard Hack Triggers Biggest 'Small' Bitcoin Move Since FTX

The suspected hack of Coldcard hardware wallets has triggered a wave of on-chain activity not seen since the collapse of FTX in 2022, with small $BTC holders rushing to move their funds to sa

AnonymousCryptoCompass newsroom
August 3, 2026
3 min read
NEWS
Coldcard Hack Triggers Biggest 'Small' Bitcoin Move Since FTX
CryptoCompass editorial visual for bitcoin coverage.

The suspected hack of Coldcard hardware wallets has triggered a wave of on-chain activity not seen since the collapse of FTX in 2022, with small $BTC holders rushing to move their funds to safety.

Small Bitcoin Transfers Hit Three-Year High

According to CryptoQuant, the combined volume of all transfers smaller than 1 BTC reached 39,600 BTC on July 31, just shy of the 39,900 BTC moved on November 16, 2022, the day after FTX filed for bankruptcy."The Bitcoin plebs had not moved this amount of BTC in a day since the FTX collapse," said CryptoQuant head of research Julio Moreno, adding that he viewed the uptick as encouraging activity rather than passive exposure.

The on-chain flow marks a reversal of the pattern seen after FTX's collapse, when investors rushed to pull large volumes of coins off centralized platforms and into self-custody solutions. Now they are doing the opposite, moving coins back to exchanges as the ongoing Coldcard incident has raised fresh questions about the safety of self-custody.

Attack Scale and Technical Background

A vulnerability in a March 2021 Coldcard firmware release enabled attackers to systematically drain bitcoin from thousands of wallets. Three distinct waves of attacks swept 1,367 BTC, worth nearly $89 million at recent prices, from 4,585 addresses.

Researchers say a firmware flaw in certain Coldcard hardware wallets made supposedly unguessable seed phrases computationally enumerable, allowing attackers to reconstruct private keys without ever touching the devices.A March 2021 firmware integration error routed seed generation to a deterministic software pseudorandom number generator instead of the STM32 hardware random number generator.

Coldcard confirmed the vulnerability and said it has halted shipments, adding that it has destroyed all remaining units with the affected firmware installed at its facilities.Galaxy Research's Alex Thorn urged users to move funds off the Coldcard wallet immediately, using high transaction fees to prioritize their rescue transaction ahead of the attacker's.

Galaxy said anyone using a single-signature Coldcard-generated seed, particularly one created without sufficient additional randomness or a strong BIP-39 passphrase, should move their Bitcoin to a new wallet generated with a fresh recovery seed.

The Coldcard exploit fits a broader trend in crypto attacks. According to blockchain security firm Blockaid, most losses in the first half of 2026 came not from smart contract hacks but from compromised keys and operational security failures.

Sources:CoinDesk: Coldcard exploit has investors sending bitcoin back to exchangesBloomberg: Hackers Target Bitcoin's Safest Hiding Place in Ongoing AttackThe Hacker News: Coldcard Hardware Wallet Flaw Linked to Bitcoin Theft