Bitcoin holders moved 39,600 BTC in transactions under 1 BTC on Friday, the largest daily volume of small transfers since November 2022. CryptoQuant head of research Julio Moreno flagged the
Bitcoin holders moved 39,600 BTC in transactions under 1 BTC on Friday, the largest daily volume of small transfers since November 2022. CryptoQuant head of research Julio Moreno flagged the figure on Saturday, tying it directly to a self-custody hack that has been draining Coldcard hardware wallets since July 30.
The number sits just 300 BTC below the 39,900 BTC moved on November 16, 2022, days after FTX filed for bankruptcy. Moreno called it a sign that "Bitcoin plebs" were taking action to protect their coins, the first time this scale of small-wallet movement has appeared since the exchange collapse that reshaped how the industry thinks about custody.
What Triggered The Rush To Move Coins
The spike traces back to a firmware flaw in Coldcard, a Bitcoin-only hardware wallet made by Canadian company Coinkite. On July 30, an attacker drained roughly 594 BTC, worth about $38 million, from around 500 wallets in a 25-minute sweep. The attacker never touched a physical device.
The cause was a random number generator bug introduced in March 2021. Coldcard's firmware was built to disable MicroPython's built-in randomness source and use its own hardware-based generator instead. A flawed check in a supporting code library meant that instruction never took effect on some devices. Seed phrases ended up generated with predictable, guessable data instead of true randomness.
An attacker could reconstruct candidate seeds on an ordinary computer, derive the addresses each seed would produce, and match them against Bitcoin's public blockchain. No malware, phishing, or physical access was needed. Wallets created between 2021 and 2026 on affected Mk3 firmware versions were exposed, and many had sat untouched for years before being swept.
Losses Kept Climbing Through The Week
The initial estimate of 594 BTC did not hold for long. Galaxy Research, the research arm of Galaxy Digital, mapped a second wave on July 31 that pushed the total to 1,082.65 BTC across 1,196 addresses, worth about $70 million. A further wave the same day brought the count to 1,158.66 BTC from 2,673 addresses.
By August 1, Galaxy's tracking reached roughly $88.6 million, or about 1,367 BTC, spread across 4,585 addresses. Alex Thorn, Galaxy's head of firmwide research, said on Sunday that the attack was still active and urged anyone holding funds on a Coldcard-generated address to move them without delay.
Coinkite responded with emergency firmware releases on July 31 covering the Mk3, Mk4, Mk5, and Q devices. Updating firmware does not repair a seed already generated under the flawed code. Anyone affected has to generate a fresh seed on the patched firmware and transfer funds to a new address, which is the migration driving the transfer volume CryptoQuant tracked.
Why Passphrases Made A Difference
Wallets protected with a BIP-39 passphrase, an additional word or phrase layered on top of the standard seed, largely escaped the theft. A passphrase changes the final key derivation in a way the attacker's guessing method could not reproduce from public chip data alone. Security researchers have pointed to this as the clearest practical defense that worked during the incident.
Blockaid, a blockchain security firm, noted that most crypto losses in the first half of 2026 came from compromised keys and operational failures rather than smart contract exploits. Its CEO, Ido Ben-Natan, said the Coldcard case fits that pattern, with the failure occurring at the wallet's key-generation stage, a step users have no way to verify themselves.
The Self-Custody Debate Reopens
The incident has renewed argument over whether holding your own keys is safer than trusting a third party. Casa CEO Nick Neuman pushed back on claims that self-custody had failed, estimating that roughly ten times more Bitcoin remains safely self-custodied than was stolen in this attack.
Bloomberg senior ETF analyst Eric Balchunas argued that spot Bitcoin ETFs offer a more practical option for many holders, pointing to the ETF industry's operating record. Others in the community countered that the flaw was specific to one hardware wallet maker, not a failure of the self-custody model itself. Some analysts expect the episode to push cautious holders toward regulated custodians and ETFs, at least in the near term.
What It Means Going Forward
The Coldcard flaw is the third major documented case of this kind, following the 2023 Milk Sad randomness bug and a 2026 mobile wallet vulnerability known as Ill Bloom. Each case failed at the same point: wallet creation, a moment users cannot independently audit.
For Bitcoin holders, the practical takeaway is not that self-custody failed, but that the source of a wallet's randomness matters as much as keeping the device offline. A seed generated with weak entropy is vulnerable no matter how well the physical device is secured. The current wave of sub-1 BTC transfers reflects users acting on that lesson, migrating funds to seeds generated under patched firmware while the attack window remains open.