Home » Bitcoin onchain activity surges to yearly high as Coldcard attack unfolds

Bitcoin onchain activity surges to yearly high as Coldcard attack unfolds

by Andrew Grant
0 comments



Bitcoin onchain activity has reached its highest level of 2026 as researchers have linked the surge to the ongoing Coldcard wallet exploit, warning that similar spikes have historically coincided with local market turning points.

Summary

  • Bitcoin onchain activity has reached its highest level of 2026 as the Coldcard wallet exploit continues to unfold.
  • K33 said similar spikes in Bitcoin activity have historically appeared around local market tops and bottoms.
  • Galaxy Research has confirmed the theft of 1,596 BTC from about 7,300 addresses, with losses potentially rising to around 2,055 BTC.
  • The Coldcard breach has prompted some users to move funds to centralized exchanges while raising new questions about hardware wallet security.

K33 Research said nearly 890,000 BTC has moved onchain over the past seven days, the highest seven-day active supply recorded this year, even as Bitcoin has continued trading within one of its tightest price ranges in recent years.

The research note arrives as investigators continue expanding the scope of the Coldcard hardware wallet breach. Galaxy Research said on Tuesday that at least 15 different attackers have now exploited the vulnerability, while its latest confirmed estimate stands at 1,596 BTC stolen from roughly 7,300 addresses across three verified attack waves. The firm added that losses could reach around 2,055 BTC, or about $130 million, if a fourth suspected wave is confirmed through additional victim reports.

Although earlier blockchain observations suggested larger losses, Galaxy said it refined its estimates after separating confirmed victim reports from suspected onchain activity. The research team also said about 90% of the stolen Bitcoin has not moved since the attacks, giving investigators additional time to monitor the funds while coordinating with cryptocurrency exchanges, blockchain security firms and U.S. law enforcement.

Coldcard exploit has driven unusual Bitcoin activity

Despite relatively calm price action, K33 Head of Research Vetle Lunde said the pace of Bitcoin transfers has accelerated sharply.

According to the report, Bitcoin has recorded its narrowest 30-day high-to-low trading range since 2023, while realized volatility has fallen below that of the Nasdaq 100. Even so, active supply climbed rapidly as affected users moved coins following the Coldcard incident.

Lunde said the increase was “very likely driven by the Coldcard attacks,” adding that the incident has “likely heightened concerns about other hardware wallets, including Ledger and Trezor, prompting some owners to consider centralized custodians or multisignature setups.”

Separate reporting covered by crypto.news also pointed to changing custody behavior. OKX Chief Compliance Officer Jonathan Brockmeier told the publication the exchange has experienced record inflows following the Coldcard incident as some users moved assets from hardware wallets to centralized custody.

“We’re seeing record levels of inflows now to centralized exchanges post-Coldcard,” Brockmeier said. “It’s interesting — it’s sort of the flip side of FTX. FTX happens, and everybody moves their money into self-custody, and it’s coming back now.”

He said exchanges can provide dedicated security teams and automated monitoring systems for users who prefer managed custody, while adding that self-custody remains an option for customers willing to manage their own security.

Bitcoin activity has previously accompanied turning points

Looking beyond the immediate exploit, K33 said similar bursts of onchain activity have repeatedly appeared around major market reversals.

The report found that periods when seven-day active supply entered the top 10% of observations compared with its rolling 365-day history aligned with local tops and bottoms during the 2022 bear market, the bull markets of 2024 and 2025, and the 2026 bear market.

“The intuition behind this observation is clear: panic is visible onchain,” Lunde wrote.

He explained that falling markets often push holders to move coins onto exchanges to limit additional losses, while rising prices encourage both profit-taking and buying driven by fear of missing out. The report also noted that two of the largest active supply spikes this year occurred during February and June selloffs, while a separate increase in late April was more likely related to routine address rotations than exchange transfers.

K33 did not argue that elevated activity alone predicts future price direction, but said the historical relationship makes current onchain behavior worth monitoring as the Coldcard investigation continues.

Coldcard flaw has exposed seed generation weakness

The attack originated from a flaw in Coldcard firmware that Coinkite disclosed after discovering affected devices generated wallet seeds with a deterministic pseudo-random number generator instead of the intended hardware-backed true random number generator.

According to Coinkite’s technical review, the vulnerability was introduced in March 2021 while engineers integrated a new cryptographic library into the wallet firmware. Although the hardware random-number generator continued operating elsewhere in the software, wallet creation mistakenly relied on MicroPython’s deterministic generator, reducing the entropy used to create new seed phrases.

Block’s Bitcoin engineering and security team independently reached the same conclusion after reviewing the firmware. The company said vulnerable devices called the deterministic MicroPython fallback during wallet creation instead of the STM32 hardware random-number generator, although it noted it had not completed testing across every affected model before publishing its findings because active thefts were already underway.

Coinkite estimates affected Mk2 and Mk3 wallets may provide around 40 bits of effective entropy, while vulnerable Mk4, Mk5 and Coldcard Q devices may generate roughly 72 bits, well below the intended 128-bit security level.

Emergency firmware updates are now available across all affected product lines. However, Coinkite said installing the updated firmware protects only wallets created after the fix. Owners whose seed phrases were generated with vulnerable firmware have been instructed to create entirely new wallets, verify the destination address with a small test transaction, and move their Bitcoin only after confirming the transfer.

Industry scrutiny has extended beyond Coldcard

The incident has also prompted renewed discussion about how hardware wallet firmware should be verified before release.

Writing on X, Kraken Chief Security Officer Nick Percoco argued that manufacturers should not be solely responsible for validating how production firmware generates wallet seed phrases. He pointed to NIST SP 800-90B and Germany’s BSI AIS-31 standards, saying comparable end-to-end verification is not routinely applied to hardware wallet firmware despite the importance of secure seed generation.

Ripple CTO Emeritus David Schwartz also commented on the incident, describing it as an example of outlier risk where an uncommon technical failure can produce losses far beyond what users expect. Schwartz compared the breach with the 2011 collapse of MF Global, arguing that while self-custody removes reliance on financial intermediaries, users still depend on hardware and firmware functioning correctly. 

He also noted that, unlike customers of regulated financial institutions, affected Coldcard owners currently have no comparable recovery mechanism after funds are stolen through compromised wallet seeds.



Source link

You may also like

Leave a Comment

Editors' Picks

Latest Posts

© 2024 trendingai.shop. All rights reserved.