BTC/USD $68,420 +2.8%
ETH/USD $3,540 +1.4%
SOL/USD $142.80 -0.6%
BNB/USD $605.20 +0.9%
XRP/USD $0.62 -1.2%
DOGE/USD $0.18 +5.4%
BTC/USD $68,420 +2.8%
ETH/USD $3,540 +1.4%
SOL/USD $142.80 -0.6%
BNB/USD $605.20 +0.9%
XRP/USD $0.62 -1.2%
DOGE/USD $0.18 +5.4%
Bitcoin

Old Bitcoin Whales Awaken After Coldcard Hack

A Whale Alert-flagged Bitcoin wallet that had sat untouched since 2013 moved 500 $BTC, worth approximately $31.3 million, marking the first on-chain activity from the address in more than 12

AnonymousCryptoCompass newsroom
August 4, 2026
3 min read
NEWS
Old Bitcoin Whales Awaken After Coldcard Hack
CryptoCompass editorial visual for bitcoin coverage.

A Whale Alert-flagged Bitcoin wallet that had sat untouched since 2013 moved 500 $BTC, worth approximately $31.3 million, marking the first on-chain activity from the address in more than 12 years. The transfer drew immediate attention from on-chain analysts, arriving in the middle of one of the most serious hardware wallet security incidents in Bitcoin's history.

Security Fears Drive Early Holders to Act

On-chain intelligence firm Lookonchain flagged the move as potentially linked to the Coldcard exploit, suggesting the holder may have grown concerned about wallet security in the wake of the breach. Several other long-dormant wallets also became active during the same period, according to CryptoQuant.

Hackers exploited a firmware flaw in Coldcard devices produced by Canadian manufacturer Coinkite, draining approximately 1,367 BTC from 4,585 addresses across several waves of attacks beginning July 30, 2026.Galaxy Research tracked total losses across those attack waves at roughly 1,367 BTC, worth about $89 million, from 4,585 addresses.

The theft was not caused by phishing, malware, physical device theft, or a conventional remote breach. Instead, a firmware error weakened the randomness used when some Coldcard devices created wallet seeds.According to Block's engineering team, a single code change on March 1, 2021 caused the firmware to silently fall back to a software-based generator instead of the hardware one. That made it mathematically feasible for an attacker to reconstruct private keys offline, without ever touching the physical device.

A Broader Wake-Up Call for Self-Custody

Coinkite issued a security advisory and released patched firmware by August 1, 2026, roughly two days after the first wave began. The company advised users whose seeds were generated on affected firmware versions to migrate funds to new seeds immediately.Coinkite CEO Rodolfo Novak issued a public apology, saying the company was taking "full accountability for the firmware bug."

The Coldcard exploit fits a broader trend in crypto attacks. According to blockchain security firm Blockaid, most losses in the first half of 2026 came not from smart contract hacks but from compromised keys and operational security failures. It remains unclear who is behind the hack. While recent large crypto thefts have often been attributed to state-backed groups, investigators have not yet linked this incident to any specific actor.

The movement of early-era Bitcoin holdings, some dating back to when $BTC traded below $1,000, serves as a reminder of how much dormant wealth remains embedded in the network. Whether these reactivations represent precautionary wallet migrations or the beginning of broader selling pressure remains to be seen.

Sources:Crypto Briefing: Coldcard firmware flaw and Bitcoin theft detailsFortune: What we know about the Coldcard exploitCoinDesk: Coldcard exploit and self-custody debate