The ongoing Coldcard hardware-wallet exploit has done more than drain some $130 million in Bitcoin. It has sent a visible tremor through Bitcoin’s on-chain data, waking up long-dormant coins, some untouched for more than a decade, and driving the fastest pace of small-holder transfers since the collapse of FTX. On-chain trackers including Whale Alert, Lookonchain, and CryptoQuant have all flagged the unusual movement of aged supply in the days since the attacks began on July 30.
But the data deserves careful reading. Not all of the dormant Bitcoin now moving belongs to hack victims, and long-idle coins shift for many reasons that have nothing to do with a security breach. What the numbers show most clearly is a market reacting — some of it theft, some of it fear, and some of it ordinary movement that simply happened to coincide with the biggest self-custody scare in years.
A Decade-Old Whale Wakes Up
The most eye-catching single event came on August 3, when a wallet labeled “18TExP,” dormant since 2013, moved its entire 500 BTC balance, worth about $31.3 million today, to a new address. The transaction was first flagged by Whale Alert. According to Lookonchain, the coins had sat untouched for more than 12 years, and the analytics firm assessed that the transfer was likely prompted by security concerns following the Coldcard hack. When the coins last moved, in 2013, they were worth roughly $500,000.
That wallet was not alone. Several old addresses have activated within the same narrow window, part of a broader stirring of aged Bitcoin that on-chain analysts began tracking as the hack unfolded.
The On-Chain Fingerprints: What the Data Shows
The clearest evidence sits in a CryptoQuant metric called spent output age bands, which groups all Bitcoin moved on a given day by how long each coin had been dormant before being spent. It is a close cousin of “coin days destroyed,” a classic indicator where a spike signals that old, long-held coins, not just recently traded ones, are on the move.
By that measure, the movement is real and concentrated. CryptoQuant data show coins dormant for seven to 10 years becoming active around the hack window, and coins idle for 10 years or longer saw roughly 935 BTC move on August 3, the largest single-day total for that oldest cohort since March, according to CoinDesk’s reading of the data.
The activity was not limited to whales. CryptoQuant’s head of research, Julio Moreno, reported that transfers of less than 1 BTC reached 39,600 BTC on Friday, July 31, the highest daily total since November 2022, the month FTX collapsed. Because these are small, defensive-looking transactions rather than large accumulations, analysts read them as ordinary holders moving coins to safety rather than buyers stepping in. The number of active Bitcoin addresses also spiked toward one million in a single day, among the highest readings in more than a year.
Separate tracking compiled by Bitcoin.com from btcparser.com showed a cluster of addresses created between 2010 and 2017, idle for nine to 16 years, moving roughly 306 BTC between July 30 and August 1, including an address created in July 2010 that spent an old Coinbase transaction of more than 50 BTC.
Two Different Populations Are Moving
Here is where careful analysis matters, because the awakening dormant coins are not a single group.
The first population is the hack itself. As Galaxy Research has documented, the stolen coins were long-dormant, with an average dormancy of about 3.18 years, so the attackers’ sweeps of vulnerable Coldcard wallets themselves register on-chain as aged coins suddenly moving. In that sense, part of the “awakening” is simply the theft in progress.
The second population is different, and it is the one that complicates the picture. Galaxy has been explicit that the suspected victims’ coins were all created after the vulnerable firmware was released in 2021. Yet many of the newly active dormant wallets — the 2010-to-2017 vintage, and the 2013 whale — held Bitcoin years before Coldcard devices existed. Those holders cannot be hack victims. The most reasonable read, echoed by several analysts, is that some long-term holders, rattled by the breach, are moving coins preemptively to review or upgrade their own security setups, even though their storage was never exposed to this particular flaw.
Correlation, Not Proof
That distinction leads to the central caveat of this whole story: clustering in time is not the same as causation. Long-dormant coins shift for many reasons unrelated to any hack, inheritance settlements, exchange or custodian consolidations, over-the-counter (OTC) deals between large parties, or simple wallet housekeeping.
What makes the current cluster notable is the timing: several large dormant wallets activating within days of the Coldcard hack raises the reasonable possibility of security-driven migration, without proving it for any individual transaction. Responsible on-chain analysis treats these moves as suggestive signals, not confirmed cause and effect.
Where Are the Coins Going?
The more market-relevant question is where the awakened coins are heading, because that determines whether the movement implies selling pressure. Over the weekend, several analysts noted increased Bitcoin inflows to exchanges, which can be a precursor to selling. But CryptoQuant cautioned it had not classified every transaction, and exchange-inflow spikes are notoriously ambiguous, they can also reflect custodial reshuffling, ordinary customer deposits, or internal bookkeeping.
Crucially, much of the observed dormant activity appears to involve transfers to freshly generated self-custody wallets rather than to exchange deposit addresses, consistent with holders securing funds, not dumping them. On-chain trackers have separately noted that a large share of aged-coin movements in 2026 have resolved as OTC transactions rather than open-market sells.
The Market Impact So Far
Despite the churn, Bitcoin’s price has been strikingly stable, trading in a band around $63,000 to $64,000 through the episode. That resilience is itself informative: it suggests the dormant movement has been dominated by security-driven repositioning and traceable, still-parked stolen coins rather than a rush of sellers hitting order books.
Analysts do flag a classic caution setup, old coins moving and rising exchange inflows together can foreshadow selling pressure, but so far the second half of that combination has not produced a sustained sell-off. Notably, Galaxy has said roughly 90% of the stolen Bitcoin has not moved at all and remains traceable, meaning the largest single block of “awakened” coins is sitting in attacker addresses under active surveillance rather than being liquidated. Nothing here is a forecast of where Bitcoin trades next; it is a snapshot of a fast-moving, still-unfolding situation.
The Bottom Line
The Coldcard hack has produced a rare, real-time case study in how a security event ripples through Bitcoin’s on-chain data. Dormant coins are genuinely stirring, the metrics from CryptoQuant, Whale Alert, and Lookonchain are not in doubt, but the “whale awakening” is a composite of at least three things: attackers sweeping stolen wallets, long-term holders defensively migrating funds (some who were never even at risk), and the ordinary background noise of old coins that move for their own reasons.
The signals worth watching from here are whether the stolen “vaults” Galaxy is monitoring begin to move, and whether awakened supply starts routing to exchanges rather than to new cold storage. Until then, the on-chain tremor looks more like a market flinching than a market breaking.
Also Read: Nothing Is 100% Safe in Crypto: Bitcoin’s Coldcard Exploit and Growing Security Crisis
