A firmware flaw in Coldcard hardware wallets let attackers drain close to $130 million in Bitcoin starting July 30, but on-chain data shows 233,000 BTC — worth about $15 billion — moved out of long-term holder wallets over the same stretch. Casa CEO Nick Neuman says the shift, drawn from Checkonchain data, shows self-custody responding to a threat rather than breaking down.
Attackers were still draining Coldcard wallets one address at a time in early August when 233,000 BTC — worth about $15 billion at today's prices — began moving out of long-term holder wallets in search of safety. Casa CEO Nick Neuman tracked the shift as the hardware-wallet exploit unfolded.
A firmware bug going back to March 2021
The breach, which started on July 30, has led to close to $130 million in stolen Bitcoin pulled from Coldcard hardware wallets, physical devices that store private keys offline and are made by Canadian company Coinkite. A firmware bug introduced in March 2021 routed key generation through a weak random number generator, collapsing security from 128 bits to roughly 40. Galaxy Research tracked the fallout across three confirmed attack waves, with losses reaching approximately 1,596 BTC across more than 5,200 addresses.
Long-term holders moved first
Long-term holder supply dropped from nearly 15 million BTC to approximately 14.7 million, Glassnode data shows — the largest weekly decline since December 2024. The move happened while Bitcoin traded roughly 50% below its all-time high of $126,000, set in October 2025. That cohort covers addresses dormant for at least 155 days, a group analysts watch as a proxy for patient investors.
Neuman reads the numbers as resilience
Citing Checkonchain analyst James Check, Neuman said 2,100 BTC was stolen and 22,000 BTC moved to exchanges, while 233,000 BTC moved out of long-term holder wallets — more than 100 times what the attackers took. According to Casa CEO Nick Neuman: "somewhere between ~10x-100x the amount of bitcoin stolen was moved to safety". Neuman separately said the migration shows the resilience of distributed self-custody rather than exposing it as a systemic weakness, since holders could react and relocate funds without relying on a centralized custodian.
Coinkite has urged anyone who generated a seed on firmware versions 4.0.1 through 4.1.9 to treat those wallets as compromised and migrate to a new seed immediately.
Sources: Decrypt, Crypto Briefing
Trading involves risk.