Bitcoin On-Chain Activity Hits 8-Month High as Coldcard Users Race to Migrate Wallets
A weak random-number bug in older Coldcard firmware pushed holders to move funds to new seeds, driving daily active addresses to their busiest level since December 2024 — while confirmed thefts from unmigrated wallets have already topped $100 million.
By Jane Doe
Published on Aug 7, 2026
Quick Take
- Coin Metrics counted 967,546 Bitcoin active addresses on July 31 — the busiest day since a 985,635-address reading on December 10, 2024.
- The spike followed disclosure that certain Coldcard hardware-wallet firmware generated seeds with weakened randomness, prompting affected holders to migrate funds to fresh wallets.
- Attackers have already swept an estimated 1,596–2,055 BTC from vulnerable, unmigrated addresses, with confirmed losses passing $100 million.
- Exchange balances briefly climbed by roughly 22,135 BTC before partly reversing, and Bitcoin last traded at $64,606 on August 6.
What Happened
Coinkite, the Canadian maker of the Coldcard hardware wallet, disclosed that seeds generated on certain firmware versions carried significantly weaker randomness than intended. On Mk2 and Mk3 devices, the flaw affects seeds created with firmware version 4.0.1 through 4.1.9 — a window stretching back to a March 2021 release. On Mk4, Mk5, and Q devices, affected seeds were generated with roughly 72 bits of entropy instead of the 128 bits the design called for, making them meaningfully easier for an attacker to guess.
Fixes are already out: version 4.2.0 for Mk2 and Mk3, 5.6.0 for Mk4 and Mk5, and 1.5.0Q for the Q device. But installing the patch does not retroactively secure a seed that was already generated on the vulnerable software ⚠️ per Coinkite's own guidance — Coinkite said a passphrase does not repair an already-affected seed. Anyone who generated a seed on the affected firmware has been told to move their coins to a brand-new seed created on patched hardware, not simply to add a passphrase or update the firmware in place.
One exception: seeds built from at least 50 fair, independent, private dice rolls drew their entropy from the dice itself rather than the flawed firmware random-number generator, so those seeds were not weakened by the bug.
Attackers moved quickly. The first documented sweep took 594.5 BTC across 1,324 UTXOs from roughly 500 single-signature addresses, executed across four consecutive blocks on July 30. The median loss per victim in that sweep was 0.41 BTC, while the single largest loss was 29.9 BTC.
Why It Matters
Why It Matters
This is a hardware-wallet supply-chain problem, not a network-level Bitcoin bug — but it's landing at scale because Coldcard is a widely used cold-storage device, and the flawed firmware was live for over three years before disclosure. Every affected user effectively has a countdown: their coins are only as safe as it takes an attacker to brute-force a 72-bit (rather than 128-bit) key, and that gap is exactly what the recorded sweeps have been exploiting.
Glassnode framed the resulting on-chain surge as "fear-driven on-chain activity," adding that holders moving seeds to new custody reflects an operational security response rather than a shift in market conviction. In other words, the spike in addresses is holders defending themselves, not a wave of new buying or selling interest.
The Numbers
| Metric | Value |
|---|---|
| First documented sweep (Jul 30) | 594.5 BTC / 1,324 UTXOs / ~500 addresses |
| Median loss per victim (first sweep) | 0.41 BTC |
| Largest single loss (first sweep) | 29.9 BTC |
| Confirmed stolen (Galaxy Research) | 1,596 BTC from ~7,300 addresses |
| Confirmed + suspected stolen | 2,055 BTC |
| Confirmed dollar value | Passed $100 million ⚠️ per CryptoPotato |
Methodology & sourcing notes
Active-address and exchange-balance figures come from Coin Metrics, as cited in Glassnode's August 6 publication. Theft totals come from Galaxy Research and were reported further by CryptoPotato. Sentiment data comes from Santiment. Firmware and entropy details come from Coinkite's own disclosure. No independent verification of these third-party figures was performed for this article.
Market Reaction
Transaction counts moved in the opposite direction from active addresses: the network processed 607,581 transactions on July 31, below the July average of 656,321, even as the address count ran 54% above its monthly average. That gap is consistent with many smaller, address-consolidation-style moves (sweeping funds to new wallets) rather than a broad increase in overall transaction volume.
Social sentiment tilted cautious. Santiment measured 0.58 bullish comments for every bearish one across social channels — the lowest positive-to-negative ratio the firm has recorded since it began tracking that metric. ⚠️ The source does not specify Santiment's tracking start date, so "lowest since tracking began" should be read as a relative, not absolute, historical claim.
Exchange balances rose by 22,135 BTC (0.83%) between July 29 and August 3 before partly reversing, easing to 2,667,058 BTC by August 5 — leaving about 12,200 of the added coins still sitting on exchanges. Bitcoin itself traded at $64,606 on August 6.
⚠️ Flagged / Unverified
The source does not state whether the August 3 exchange-balance build was driven specifically by Coldcard-related migrations, general market activity, or a mix of both — treat that link as circumstantial rather than confirmed. It also doesn't specify what portion of active addresses were verified as Coldcard-related versus unrelated on-chain activity.
What's Next / Things to Watch
Coinkite's guidance to affected owners is unambiguous: migrate every seed generated on the vulnerable firmware to a new seed created on patched hardware (4.2.0 for Mk2/Mk3, 5.6.0 for Mk4/Mk5, 1.5.0Q for Q) — a passphrase alone does not fix an already-compromised seed. The pace of active addresses running above the July average for seven straight days through August 5 suggests migrations were still underway as of the source's publication date.
The gap between Galaxy Research's confirmed (1,596 BTC) and confirmed-plus-suspected (2,055 BTC) totals implies the final theft count could still move as more sweeps are identified or ruled out. Coin Metrics' address and exchange-balance series are the metrics to watch for signs of whether migration activity is winding down or continuing.
FAQs
What caused Bitcoin active addresses to spike?
A firmware flaw in certain Coldcard hardware wallets generated seeds with weaker-than-intended randomness. Once disclosed, affected holders began moving funds to new, securely generated seeds, which shows up on-chain as a surge in active addresses.
Which Coldcard devices and firmware versions are affected?
Mk2 and Mk3 devices running firmware 4.0.1 through 4.1.9 (a range dating to a March 2021 release), and Mk4, Mk5, and Q devices running pre-patch firmware that generated seeds with about 72 bits of entropy instead of 128. Patches are 4.2.0, 5.6.0, and 1.5.0Q respectively.
Does updating the firmware fix an already-created seed?
No. Coinkite has said the patch does not repair a seed that was already generated on the vulnerable firmware, and that a passphrase doesn't fix it either — affected users are told to migrate to an entirely new seed.
How much Bitcoin has been stolen so far?
Galaxy Research puts confirmed thefts at 1,596 BTC from about 7,300 addresses, rising to 2,055 BTC if suspected sweeps are included. CryptoPotato reported the confirmed total has passed $100 million.
Were dice-generated seeds affected?
No. Seeds created using at least 50 fair, independent, private dice rolls drew sufficient entropy from the dice itself and were not weakened by the firmware bug.
Investment disclaimer: The content reflects the author’s personal views and current market conditions. Please conduct your own research before investing in cryptocurrencies, as neither the author nor the publication is responsible for any financial losses.
Ad Disclosure: This site may feature sponsored content and affiliate links. All advertisements are clearly labeled, and ad partners have no influence over our editorial content.