Key Insights:
- Coldcard users are rushing to move their funds from the compromised wallet, with small holders moving 39,600 BTC over the past few days.
- Galaxy Research stated that more than $100 million has been stolen from these incidents.
- Bloomberg analysts say the incident could push more investors to embrace Bitcoin ETFs.
Bitcoin holders controlling less than 1 BTC moved 39,600 BTC by July 31, according to CryptoQuant.
The movement followed public disclosures about a critical Coldcard hardware-wallet vulnerability. However, CryptoQuant’s data covers all sub-1 BTC holders and cannot identify which transfers came from Coldcard users.
The volume represented the largest short-term movement from smaller holders since the FTX collapse in November 2022. Sub-1 BTC holders moved about 39,900 BTC during that earlier period, according to CryptoQuant’s comparison.
The latest transfer volume reached approximately $3.2 billion, based on Bitcoin’s market price at the time.
Small Bitcoin Holders Move 39,600 BTC
The massive exodus is unsurprising given the scale of the attacks. Hackers found a vulnerability in the cold wallet that caused some Coldcard wallets to generate easily predictable seed phrases.
Coldcard developer CoinKite notified users about the flaw last week, and security experts noted it stemmed from a software bug introduced in 2021. The bug caused some of the cold wallets to use a non-cryptographic pseudo-random number generator
So far, over $100 million has already been stolen, with more than 7,000 addresses impacted. Galaxy Research reported that it has confirmed 1,596 BTC stolen from 7,300 addresses across three confirmed attack waves and 14 smaller incidents.

However, the firm noted that there may have been a fourth wave, even though it has yet to receive full confirmation. It stated that the stolen funds could be up to 2,055 BTC, worth $130 million.
While CoinKite has released a firmware update to patch the issue for affected Coldcard models, the nature of the attack means there is no software fix for a compromised wallet with predictable seed phrases.
The only solution was to create a new address and move funds to it. This also means the attack is still ongoing, even as Coinkite has issued a warning urging users to migrate funds to protect against the crypto scam. Over a dozen attackers are reportedly exploiting the vulnerability.
Expert Says Hack Could Spur ETF Migration as Crypto Scam Losses Mount
The incident has triggered several reactions from the crypto community. While cold wallets have long been considered the safest option compared to hot wallets and even centralized exchanges like FTX, the Coldcard hack has now shown that they can still be vulnerable.
Already, some victims are contemplating suing CoinKite with claims emerging that the company was warned about the exploit earlier. Efforts to identify and recover the stolen funds are also ongoing.
Interestingly, Bloomberg senior analyst Eric Balchunas noted that the incident could lead more people to embrace Bitcoin exchange-traded funds (ETFs). In a post, he stated that some investors may now embrace Bitcoin ETFs following this latest crypto news, as they consider them safer options.
According to Balchunas, Bitcoin ETF sponsors are major financial institutions that work with larger custodians such as Coinbase to store users’ assets. Thus, they usually have additional layers of security.
Although he noted that an ETF custodian could still be compromised, he added that such an incident would likely lead to increased regulatory scrutiny and stricter law enforcement investigations than a crypto scam against a small company.
Meanwhile, the Coldcard hack adds to the growing losses due to crypto scams and hacks this year. In the first half of 2026, $972 mmillion was stolen in 207 hacks, according to TRM Labs.
This article is for informational purposes only and does not constitute financial or investment advice. Cryptocurrency prices remain highly volatile.
The post Coldcard Users are Fleeing at FTX Collapse Speed appeared first on The Market Periodical.

