Crypto

Coldcard Wallet Flaw Triggers Massive Bitcoin On-Chain Flight as Small Holders Move $2.5 Billion

A critical firmware vulnerability in Coldcard hardware wallets prompted retail investors to transfer tens of thousands of Bitcoins in the largest on-chain shuffle since the FTX crash.

A security vulnerability inside Coldcard hardware wallets sent retail Bitcoin holders scrambling to relocate their funds on July 31, driving small-value transaction volumes to levels unheard of since the collapse of cryptocurrency exchange FTX.

Data from analytics firm CryptoQuant shows that transfers of less than 1 BTC reached 39,600 BTC—worth roughly $2.5 billion—in a single 24-hour window. The surge came as news spread that a flaw in Coldcard firmware had generated predictable cryptographic keys for roughly five years.

Daily active addresses soared from 645,000 on July 30 to nearly one million the following day, marking the highest network activity since December 2024. According to Julio Moreno, Head of Research at CryptoQuant, the spike was almost entirely driven by sending addresses rather than receiving addresses, pointing to a concentrated rush to evacuate funds.

Sub-10 BTC deposits into cryptocurrency exchanges accounted for 7,300 BTC ($459 million) on July 31, reaching a six-month high. Despite the large influx of coins onto trading platforms, Bitcoin’s spot price remained resilient. According to CoinGecko, the asset traded virtually flat at $62,724, down just 0.7%, indicating that holders were using exchanges to safeguard assets or switch wallets rather than liquidate their positions.

The root cause stems from a March 2021 firmware build error by manufacturer Coinkite. The bug forced seed phrases to be drawn from a severely restricted pool of randomness, yielding only about 72 bits of entropy. The flaw left thousands of self-custody keys vulnerable to brute-force key generation.

Exploitation of the vulnerability has moved swiftly. Galaxy Research confirmed that attackers executed three distinct theft waves, draining 1,367 BTC across 4,585 wallet addresses—an exploit initially estimated at $38 million before surging to over $70 million as asset valuations rose and Binance founder Changpeng Zhao issued public warnings.

A suspected fourth wave hit the blockchain on Monday. Alex Thorn, Head of Firmwide Research at Galaxy Research, identified automated sweeps spanning 15 consecutive blocks running at roughly 45 times normal frequency. After adjusting for misidentified multisig wallets, Thorn placed the latest wave at 709 addresses and 448.73 BTC ($28 million). If verified, total losses across all four waves would reach approximately 1,816 BTC, valued at roughly $114 million. None of the compromised wallets in the earlier waves utilized multi-signature setups.

Thorn noted that several pending sweep transactions remain trapped unconfirmed in the Bitcoin mempool with Replace-By-Fee (RBF) enabled. Affected holders who act quickly can potentially front-run the attacker by broadcasting replacement transactions with higher network gas fees.

The breach has sparked widespread concern across the digital asset security industry. Kraken Chief Security Officer Nick Percoco described the vulnerability as a major wake-up call, emphasizing that while Coldcard’s Mk4, Mk5, and Q devices feature certified secure elements, certification alone failed to prevent the underlying software from bypassing proper entropy pathways.

Percoco urged the industry to adopt independent laboratory testing for key entropy generation tied directly to public firmware registries, mimicking security standards used in traditional payment processing terminals. Coinkite has since released a hotfix designed to halt automated firmware builds if the standard random number generator is omitted, a defense safeguard implemented within 48 hours of discovering the bug.

Related Articles

Leave a Reply

Your email address will not be published. Required fields are marked *

Back to top button