The Coldcard hardware wallet exploit has done more than drain funds from victims. It has set off one of the most significant waves of dormant Bitcoin movement in recent memory, and analysts s
The Coldcard hardware wallet exploit has done more than drain funds from victims. It has set off one of the most significant waves of dormant Bitcoin movement in recent memory, and analysts say the data points firmly to security-driven migration, not a rush to sell.
According to Glassnode, roughly 119,000 $BTC that had been sitting idle for more than a year moved within three days of the Coldcard vulnerability becoming public. That figure is approximately 200 times the 594 BTC initially stolen in the first wave of the hack.
Migration, Not a Sell-Off
Despite the scale of the movement, market impact has been limited. Only about 10% of the moved coins ended up on exchanges, indicating a migration into fresh cold storage rather than a liquidation, which had minimal impact on the spot market and price response. Glassnode described the activity as security-driven wallet migration, a conclusion consistent with the broader on-chain picture.
Much of the observed dormant activity appears to involve transfers to freshly generated self-custody wallets rather than exchange deposit addresses, with the hack triggering a defensive migration of funds among long-term holders. Despite the increased movement, Bitcoin's price remained stable, suggesting that security-driven repositioning dominated the activity rather than a rush to sell.
The Exploit Behind the Alarm
Beginning July 30, 2026, an attacker exploited a five-year-old firmware flaw in Coinkite's Coldcard hardware wallet to systematically drain bitcoin from affected devices, with the flaw tracing to a March 2021 firmware release. A build configuration error caused seed generation to fall back on a weak software random number generator rather than the device's hardware-based source of entropy, collapsing effective key strength from a designed 128 bits down to as little as 40 bits on older devices, low enough to brute force with modern computing power.
The vulnerability in the Coldcard wallet allowed hackers to drain crypto from victims' wallets, with total losses amounting to more than $130 million according to blockchain-monitoring firms. Critically, updating firmware does not fix existing wallets. Anyone who generated a seed on a Coldcard between March 2021 and the patch should treat it as compromised and migrate to a new seed.
The scale of the dormant coin movement shows that even holders with no direct exposure to Coldcard took notice. A surge of long-dormant Bitcoin suddenly moving can, in other contexts, signal that early holders are heading for the exits. The current data indicates the opposite: the coins moved out of fear of theft, not desire to sell, and overwhelmingly into new self-custody rather than onto exchanges.
Sources:TRM Labs: Inside the Coldcard Hardware Wallet Exploit of 2026TechCrunch: Hackers Steal Over $130M via Coldcard BugCrypto Times: Coldcard Theft Sets Off 119K Dormant Bitcoin Migration