- Retail Bitcoin inflows surged below 1 BTC, while whale deposits stayed muted.
- Active addresses neared one million as holders moved funds after the Coldcard breach.
- Corrected firmware cannot secure exposed seeds, making wallet migration essential.
A security failure tied to older Coldcard firmware pushed thousands of Bitcoin holders to move funds, yet exchange data showed little evidence of whale selling. CryptoQuant’s spent-output bands recorded the strongest inflow growth below 1 BTC, while larger transfers remained well beneath earlier peaks.
Retail Bitcoin Inflows Rise While Whale Deposits Stay Muted
Combined inflows from the sub-0.01, 0.01–0.1, and 0.1–1 BTC bands approached 2,000 BTC during the latest surge. That total stood well above their normal daily range and marked the clearest concentration of activity after the incident.

However, transfers above 1 BTC followed another pattern. Their combined inflows stayed near the mid-20,000 area, far below early June spikes exceeding 60,000 BTC. The difference showed that smaller balances drove the increase, rather than large holders depositing coins on exchanges.
Moreover, exchange net inflows exceeded 11,000 BTC, while transactions involving less than one coin climbed toward 39,600. Daily active addresses also rose from about 645,000 to nearly one million, reaching their highest level since December 2024.

Nevertheless, sending addresses produced most of that increase, while receiving addresses rose much less, separating emergency transfers from broad network expansion. The defensive movement followed substantial losses linked to the exploit.
Galaxy Research estimated that 1,596 BTC was stolen from roughly 7,300 addresses across three confirmed waves and 14 smaller incidents. Moreover, including a suspected fourth wave would raise the estimated total to approximately 2,055 BTC, valued near $130 million at reported prices.
Coldcard Firmware Flaw Leaves Existing Seeds Exposed
The scale of the losses reflected a deeper technical failure within the affected firmware. Block’s analysis traced the vulnerability to an integration error that redirected seed generation through a deterministic MicroPython fallback.
As a result, the fallback process replaced the intended hardware random-number generator under specific conditions. This reduced the unpredictability required to create secure private keys and left affected wallet seeds vulnerable.
Under constrained conditions, affected Mk2 and Mk3 firmware could generate deterministic outputs, while later Coldcard models retained sharply reduced entropy. Although Coinkite released corrected firmware across the affected product lines, installing the update cannot secure seeds created by vulnerable software.
Therefore, exposed users must generate a fresh seed using corrected firmware, verify the replacement wallet, and transfer their Bitcoin holdings. Meanwhile, Bitcoin’s contained price reaction remained consistent with the exchange data, as larger deposit bands stayed well below levels recorded during heavier distribution.
Related: Coldcard Wallet Vulnerabilities Explained: What Bitcoin Users Need to Know
Disclaimer: The information presented in this article is for informational and educational purposes only. The article does not constitute financial advice or advice of any kind. Coin Edition is not responsible for any losses incurred as a result of the utilization of content, products, or services mentioned. Readers are advised to exercise caution before taking any action related to the company.