Coldcard Key Flaw Triggers Sub-1 BTC Surge as Suspected Theft Waves Push Losses Toward $114M

Small Bitcoin transfers hit post-FTX highs after a Coldcard seed bug surfaced. Active addresses jumped, price held steady, and Galaxy flagged a likely fourth theft wave.

Bitcoin
Cryptocurrency
Regulations
Economy
Because Bitcoin
Because Bitcoin

Because Bitcoin

August 3, 2026

Bitcoin’s smallest holders just moved like it was November 2022 again. On July 31, transfers of less than 1 BTC totaled 39,600 BTC (about $2.5 billion), a pace last seen days after the FTX collapse when 39,900 BTC moved, according to CryptoQuant’s Julio Moreno. Daily active addresses climbed from 645,000 on July 30 to nearly 1 million on July 31—the most since December 2024—with the surge concentrated in sending, not receiving, addresses. Sub-10 BTC deposits to exchanges reached 7,300 BTC ($459 million), the highest since February 6. Yet Bitcoin barely budged, trading around $62,724 and down 0.7% on the day per CoinGecko, suggesting users were repositioning for safety, not selling.

Why the stir: a Coldcard hardware wallet firmware build error from March 2021 produced seed phrases from a far too small pool of possibilities. Once disclosed, Galaxy Research tracked three organized theft waves through Saturday, summing to 1,367 BTC across 4,585 addresses—initially estimated near $38 million and then $70 million as attention grew. On Monday, Galaxy’s Alex Thorn flagged a likely fourth wave: sweeps spanning 15 consecutive blocks at roughly 45x normal rates. After excluding misclassified multisig, he put this wave at 709 addresses and 448.73 BTC (~$28 million), lifting the running total to about 1,816 BTC, or roughly $114 million. Thorn cautioned no victim has confirmed this fourth wave; the call rests on pattern-matching. Some sweeps were still in the mempool with replace-by-fee enabled—meaning fast actors paying up might outbid the attacker. Notably, none of the first three waves hit multisig addresses.

The deeper issue isn’t chips, it’s entropy accountability. Many teams lean on “certified secure elements,” but certification often evaluates components in isolation. As Kraken’s Nick Percoco highlighted, Coldcard’s Mk4, Mk5, and Q ship with certified secure elements and still produced seeds around 72 bits of effective entropy because the certification didn’t validate which code path actually supplied randomness. That’s security theater risk: strong parts, weak composition.

From experience, the single control that changes outcomes here is provable, firmware-bound randomness verification: - Independent lab validation of entropy sources tied to specific firmware versions, published in a public registry (similar to payment terminal requirements), so users and exchanges can verify the exact RNG lineage. - Deterministic, reproducible builds where the wallet’s RNG path is pinned and fails-closed if the correct generator isn’t linked—a guardrail Coinkite has now added in a hotfix that fails the build unless the proper generator is present, a control they implemented in roughly 48 hours once targeted. - Ongoing on-device health tests that escalate to user-facing warnings if entropy checks fall out of bounds.

Users are telegraphing their threat model in the data: higher send-side activity, elevated sub-10 BTC exchange deposits, stable price. Many are not panic-selling; they are trying to get to known-good custody. Psychologically, a hardware wallet “bug” breaks the core trust contract: that offline randomness is sacrosanct. Once that’s in doubt, people route to perceived institutional safety, even if only temporarily. Business-wise, this is the cost of opaque RNG: exchanges absorb operational surges, while hardware brands face a credibility drawdown that can take years to earn back.

One practical note that keeps getting missed: the first three theft waves didn’t touch multisig. Attackers exploiting low-entropy single-sig seeds struggle when recovery requires multiple keys from distinct entropy sources. Multisig is not a cure-all, but it meaningfully diversifies RNG risk and buys time when replace-by-fee races are live.

What I expect to see next: - Exchanges and custodians will start requiring or incentivizing firmware-attested entropy provenance for withdrawals to retail self-custody. - Wallet makers will standardize public RNG attestations tied to firmware hashes and third-party lab results. - Power users will increasingly favor multisig or layered setups (HSM + hardware wallet) until entropy supply chains are routinely auditable.

People often say “don’t trust, verify.” With randomness, that requires giving users something verifiable. Until then, metrics like we saw on July 31 will keep spiking whenever trust wobbles.