Following the ongoing spread of vulnerabilities in the Coldcard hardware wallet, large-scale fund movements have occurred on-chain. Multiple institutional data sources indicate that approximately 233,000 bitcoins were transferred out of long-term holder addresses before and after the incident, estimated at around $15 billion based on the prices mentioned in the article—significantly exceeding the direct losses caused by this attack.
The stolen amount approached $130 million.
The incident began on July 30. The attacker exploited a key generation flaw in the Coldcard firmware, gradually draining funds from affected addresses. Reports indicate that approximately 2,100 bitcoins have been stolen, resulting in losses of nearly $130 million.
Galaxy Research documented three confirmed attacks, stating that over 5,200 addresses have been affected, with losses totaling approximately 1,596 bitcoins. Another set of on-chain data cited by Checkonchain reported a higher stolen amount, around 2,100 bitcoins.
233,000 BTC withdrawn
While thefts continue to occur, larger-scale active migrations are also taking place on-chain. Checkonchain data shows that approximately 233,000 bitcoins left long-term holder wallets around the time of the incident. Long-term holders typically refer to addresses that have not conducted any transfers for at least 155 days and are often regarded as a more stable holding group.
The same data also showed that approximately 22,000 bitcoins flowed into exchanges. Glassnode’s statistics corroborate this shift: the supply held by long-term holders decreased from nearly 15 million bitcoins to around 14.7 million, marking the largest weekly decline since December 2024.
Multisig migration and exchange inflows occurring in parallel
Casa CEO Nick Neuman said not all of these transfers originated from Coldcard users. Based on communications with its customers, some funds came from Coldcard users moving to multisig wallets, while others came from Ledger and Trezor users who also began adjusting their custody methods after seeing the attack.
The report notes that multisignature wallets require multiple independent keys to authorize transactions, so compromising a single device does not directly lead to the loss of all funds. However, on-chain data shows that some bitcoins have still been transferred to exchanges, indicating that certain users opted to first move their assets to more liquid platforms before deciding on long-term custody arrangements.
Additional information: Coinkite has advised users that if a mnemonic was generated on firmware versions 4.0.1 to 4.1.9 during the period from March 2021 to July 2026, they should consider the associated wallet compromised and migrate to a new seed wallet as soon as possible.

