Coldcard’s $89M wallet bug triggers the biggest Bitcoin movement since FTX and completely distorts market signals
Coldcard’s wallet disaster has shaken Bitcoin sentiment, blurred on-chain signals and uncovered a recurring weak spot in AI-assisted cyber defenses.
On July 30, {hardware} maker Coinkite warned customers that wallets generated with affected Coldcard firmware might be drained as a result of a software program error produced seed phrases with far much less randomness than supposed.
This safety incident, Galaxy Research said, resulted in three suspected assault waves that focused 4,585 addresses and drained 1,367.05 BTC, value about $89 million.

The Bitcoin related to the three recognized waves stays in attacker-controlled addresses, in response to Alex Thorn, Galaxy Digital’s head of firmwide analysis.
However, he mentioned smaller opportunistic thefts have been already transferring via peel chains, cross-chain providers and offshore casinos.
Coldcard migrations blur Bitcoin’s bearish signals
This escalating menace has pushed probably uncovered customers to maneuver their Bitcoin earlier than attackers attain it.
Although Coinkite has launched fastened firmware for affected fashions, present affected seed phrases can’t be repaired via an replace, leaving holders to generate new wallets and switch their funds to safe addresses.
That migration has produced an uncommon surge in exercise amongst smaller holders and long-dormant cash.
CryptoQuant analysis head Julio Moreno mentioned transactions involving outputs of lower than 1 BTC reached 39,600 BTC on July 31. That was the largest each day whole for the cohort since November 2022, when 39,900 BTC moved shortly after FTX collapsed.
Bitcoin’s daily active addresses additionally jumped from about 645,000 on July 30 to almost 1 million the following day, their highest degree since Dec. 10, 2024.

Moreno mentioned the improve was concentrated amongst sending addresses, whereas receiving addresses rose by a a lot smaller proportion, suggesting holders have been transferring funds out of present wallets as a precaution.
Exchange deposits involving transfers beneath 10 BTC climbed to 7,300 BTC, their highest degree since Feb. 6. Some holders could have used exchanges as momentary locations whereas creating alternative wallets, though the flows may additionally embrace traders making ready to promote.

CryptoQuant analyst JA Maartunn added that 77,402 BTC from older unspent-transaction-output bands had moved since the vulnerability grew to become public.
However, Maartunn cautioned in opposition to treating the ensuing actions as proof of broad investor capitulation, saying the context pointed closely towards customers securing their wallets.
He stated:
“The Coldcard seed phrase situation could trigger outdated cash to maneuver as customers safe their financial savings. That can distort LTH Supply Change, Coin Days Destroyed, Spent Output Age Bands and different associated charts.”
Meanwhile, broader market sentiment deteriorated sharply amid the heightened community exercise.
Blockchain analytics agency Santiment mentioned Bitcoin’s ratio of constructive to unfavorable commentary fell to its lowest degree since its trendy social monitoring started. The studying reached 0.58 bullish feedback for each bearish one throughout X, Reddit, Telegram and different platforms.

Santiment attributed the unusually extreme response to the nature of the breach. The exploit struck cold storage, which many holders thought to be Bitcoin’s most secure closing line of protection after withdrawing their funds from exchanges and avoiding riskier crypto platforms.
US AI guardrails complicate Coldcard investigation
The identical wallet actions that blurred Bitcoin’s market signals have elevated the urgency of tracing stolen funds earlier than they attain providers the place they are often transformed or withdrawn.
Galaxy Research has collected experiences from victims, clustered suspected attacker addresses and shared its findings with legislation enforcement, compliance companies and different cyber investigators. Thorn mentioned the agency had reported about 600 addresses believed to be holding Bitcoin stolen from weak Coldcard wallets.
However, he mentioned guardrails on US large language models hindered makes an attempt to trace the stolen property and shield customers, forcing investigators to show to an open-source Chinese mannequin.
Thorn has not recognized the US fashions, disclosed the prompts they rejected, or defined what the various system contributed to the investigation.
His considerations however echo a current downside encountered by Hugging Face throughout a reside cyberattack.
The AI platform mentioned its safety group wanted to research greater than 17,000 recorded occasions after an autonomous agent compromised elements of its infrastructure. Investigators initially submitted assault instructions, exploit payloads, and command-and-control artifacts to frontier fashions accessed via industrial software programming interfaces.
Those requests have been blocked as a result of the fashions’ security techniques couldn’t distinguish the incident responders from attackers, Hugging Face mentioned. The firm as an alternative carried out the forensic evaluation with GLM 5.2, an open-weight mannequin developed by China’s Z.ai and operated by itself infrastructure.
The mannequin helped reconstruct the assault timeline, establish compromised credentials, extract indicators of compromise and separate real harm from decoy exercise. Hugging Face mentioned the AI-assisted investigation diminished work that might have taken days to a matter of hours.
The episode illustrates the asymmetry Thorn says investigators encountered throughout the Coldcard disaster.
Attackers can use unrestricted or modified techniques with out observing the safeguards imposed on industrial fashions. Defenders, in the meantime, could encounter refusals when submitting materials that resembles malicious exercise, even when their objective is to include an energetic incident.
Broadly eradicating these restrictions would create a separate danger. Model suppliers can not grant elevated capabilities every time somebody claims to be investigating a theft, notably when the identical instruments may assist wallet assaults, cash laundering or makes an attempt to evade transaction-monitoring techniques.
That distinction turns into particularly pressing in crypto as a result of stolen property can cross via bridges, exchanges and playing platforms inside minutes. Delays can permit funds to go away providers able to freezing them earlier than victims acquire police experiences or investigators full guide tracing.
The put up Coldcard’s $89M wallet bug triggers the biggest Bitcoin movement since FTX and completely distorts market signals appeared first on CryptoSlate.
