Key Highlights
- Bitcoin active addresses climbed to 0.98 million, their highest level since December 2024, after the Coldcard exploit.
- The Coldcard vulnerability reportedly drained more than $130 million, prompting wallet migrations rather than exchange selling, according to Glassnode and Galaxy Research.
- Despite heightened on-chain activity, the recent report suggests that the spot Bitcoin ETFs continued attracting inflows.
Blockchain analytics platform Glassnode reported that Bitcoin’s on-chain activity increased sharply in early August 2026 after details of a Coldcard hardware wallet vulnerability became widely known. Reportedly, the exploit has resulted in losses exceeding $130 million.
In an X post on Thursday, Glassnode reported that the number of active Bitcoin addresses climbed to 0.98 million per day, the highest level recorded since December 2024. The analytics firm described the rise as fear-driven rather than a signal of changing market conviction.
According to Glassnode, holders appeared to be migrating recovery seeds and transferring funds to alternative custody arrangements in response to the vulnerability.
Why the Coldcard incident drew widespread attention
The underlying issue stemmed from a firmware bug introduced in March 2021. On affected Coldcard devices, certain recovery seeds were generated using weak, predictable randomness instead of the hardware random number generator.
Attackers precomputed those keys and systematically swept the associated wallets. Updating the firmware does not repair a seed that was already created under the flawed conditions. Users who generated single-signature seeds on vulnerable devices without sufficient dice-roll entropy or a strong passphrase were advised to move their bitcoin to newly generated seeds on corrected firmware.
Scale of the Coldcard theft
Glassnode’s Week 31 report focused on an incident on July 31 in which roughly 594 BTC, valued at about $38 million at the time, was stolen in approximately 25 minutes, leading to a far larger defensive reaction.
Dormant coins totaling roughly 200 times the stolen amount began moving across the network as holders rotated funds off potentially compromised wallets. Only about 10% of those coins arrived at exchanges, indicating that the majority of the activity represented migration into fresh cold storage rather than liquidation. The spot market registered little immediate reaction.
Subsequent research from Galaxy Research, updated on August 4, expanded the confirmed scope. Investigators said they had high confidence that 1,596 BTC had been taken from approximately 7,300 addresses across three main attack waves and 14 smaller incidents.
At prevailing prices, the confirmed total exceeded $100 million, with unconfirmed losses estimated at an additional $30 million, potentially bringing the overall figure above $130 million. A suspected fourth wave could raise the total to around 2,055 BTC, though that figure remained outside the confirmed tally.
Parallel market flows
After the increased security-driven address, separate capital flows show Bitcoin support. US-listed spot Bitcoin ETFs recorded three consecutive days of net inflows totaling roughly $626 million.
On one of those days, the funds attracted $244.4 million in net inflows, with BlackRock’s iShares Bitcoin Trust accounting for a significant share of the three-day total and lifting its cumulative net inflows to nearly $61 billion. Bitcoin traded above $64,920 during the period. Separately, large holders, commonly referred to as whales, accumulated nearly 190,000 BTC since December.
Broader implications for self-custody
The incident highlighted a key limitation of hardware wallet security. Because the vulnerability originated in seed generation rather than a remote exploit, applying a firmware update alone did not secure seeds that had already been created under the flawed conditions.
The large volume of Bitcoin transferred following the disclosure reflected the scale of the security response, as holders moved funds to newly generated wallets. With only a small portion of those transfers reaching exchanges, the data suggests that most users were relocating assets to more secure storage rather than selling them.
Also Read: Crypto Wrench Attacks Top $30M as France Emerges as Hotspot
