Bitcoin has seen a spike in very small transfers—moves of less than 1 BTC—that match the intensity last observed around the collapse of FTX. The renewed activity comes as researchers continue
Bitcoin has seen a spike in very small transfers—moves of less than 1 BTC—that match the intensity last observed around the collapse of FTX. The renewed activity comes as researchers continue to track a suspected Coldcard wallet-related hack, underscoring how quickly users are reacting when self-custody tools appear compromised.
According to CryptoQuant head of research Julio Moreno, Friday recorded the highest daily level of sub-1 BTC transfers since November 2022, with 39,600 BTC moved. The total was just 300 BTC below 39,900 BTC transferred on Nov. 16, 2022, shortly after FTX filed for bankruptcy. Moreno framed the comparison as a sign of urgency and said users appear to be “taking action.”
Key takeaways
- Daily Bitcoin transfers below 1 BTC hit their highest level since November 2022, totaling 39,600 BTC, per CryptoQuant’s Julio Moreno.
- Galaxy Research says the suspected Coldcard incident caused estimated losses of 1,367 BTC across 4,585 addresses, after identifying a further 207.7 BTC taken in an additional wave.
- Galaxy’s Alex Thorn warned that the attack was still ongoing and urged affected users to move funds immediately from Coldcard-generated addresses.
- The incident is reigniting debate over whether self-custody is safer than relying on third-party platforms, with executives arguing the impact differs across user approaches.
Small-transfer surge echoes the post-FTX era
While large market moves often capture headlines, the current data point focuses on behavior at the granularity of everyday wallet operations: sub-1 BTC transfers. Moreno’s analysis suggests the market is seeing a level of small withdrawals not observed since the period following FTX’s bankruptcy filing.
The comparison matters because it points to reflexive user behavior—moving funds in smaller increments—rather than a single, coordinated “whale” action. In the wake of FTX, exchange-related uncertainty drove users toward faster, more defensive moves. Here, the catalyst is different: ongoing concerns tied to Coldcard-generated addresses.
Moreno’s observation that these transfers had not occurred at similar daily intensity since the FTX collapse suggests that the Coldcard incident may be triggering a comparable sense of immediate risk. That doesn’t prove equivalence in scale or cause, but it does show that user reaction can look similar even when the underlying event is distinct.
Galaxy Research details additional theft wave
Galaxy Research, part of Galaxy Digital, reported Saturday that it had identified another attack wave tied to the suspected Coldcard hack. In that wave, an additional 207.7 BTC was drained—valued at roughly $13.2 million at the time Galaxy cited.
Including the newly identified activity, Galaxy estimated total losses of 1,367 BTC, affecting 4,585 addresses. Galaxy’s reporting suggests the incident is not a single moment of exploitation, but an ongoing process where both victims and attacker infrastructure continue to emerge as investigators refine their tracking.
Galaxy also points readers to a Coldcard-focused tracking resource, “Coldcard Watch,” as part of the broader transparency around wallet activity connected to the suspected incident.
Alex Thorn, Galaxy Digital’s head of firmwide research, said in an X post on Sunday that the attack remained active. Thorn urged users to move funds from Coldcard-generated addresses immediately if they had not already done so.
Thorn added that his team continues to identify both new victim addresses and attacker addresses. He also noted that reports from users have helped investigators and authorities track stolen funds, reinforcing a practical implication for readers: in incidents where on-chain patterns are evolving, user-provided information can accelerate investigative work.
The warning is also a reminder that self-custody isn’t only about holding assets—it’s about operational readiness. When wallet-generated addresses are implicated, the “time to react” becomes part of the security model, whether users follow best practices or not.
The suspected Coldcard hack has again pulled the conversation toward the long-running fault line in crypto security: self-custody versus third-party custody. Self-custody is a foundational principle in Bitcoin, emphasizing user control without dependence on intermediaries. Yet security incidents involving consumer-grade tools can complicate the narrative and raise fresh questions about usability and safety.
Nick Neuman, CEO of Bitcoin security company Casa, pushed back against claims that “self-custody is over.” He argued that because self-custody is distributed, users have time to respond as threats are identified. Neuman also estimated that potentially 10 times more Bitcoin was protected through self-custody than was stolen and identified so far in the attack.
That position reframes the debate from whether an incident can occur at all to how the system responds once the risk becomes visible. In Neuman’s view, the existence of ongoing victims does not negate the defensive advantage that self-custody can provide—especially when users monitor, verify, and act on warnings.
Others took the issue in a different direction. Eric Balchunas, a senior ETF analyst at Bloomberg, argued via X that Bitcoin exchange-traded funds may offer a safer and more convenient alternative for many users, pointing to the longer operating history of ETFs.
In contrast, critics of that argument say the Coldcard episode reflects a failure of a specific wallet provider or implementation rather than a fundamental breakdown of self-custody itself. The tension here is important for readers to recognize: “self-custody” is not a single technology—it’s a set of practices and tools—so incidents can be interpreted as either systemic or localized depending on what readers believe broke down.
What to watch next
With Galaxy saying the attack is still unfolding and continuing to identify new victim and attacker addresses, the next key signal will be whether transfer patterns and wallet-specific indicators stabilize as users move funds. For investors and builders, the bigger question is how quickly the broader community can validate affected addresses and coordinate response—because in cases like this, speed is part of the security outcome.
This article was originally published as Coldcard Hack Fallout Widens as Bitcoin Losses Hit $88.6M on Crypto Breaking News – your trusted source for crypto news, Bitcoin news, and blockchain updates.