Bitcoin holders rushed to move funds after the Coldcard hardware wallet vulnerability, pushing sub-1 BTC transfers to their highest level since the collapse of FTX in November 2022. The security incident affecting Coldcard hardware wallets has triggered one of the largest waves of Bitcoin movement in recent years, with small-value transfers surging to levels not seen since the collapse of cryptocurrency exchange FTX nearly four years ago. According to on-chain data from CryptoQuant, Bitcoin transfers of less than 1 BTC totaled approximately 39,600 BTC in a single day, the highest daily volume since November 16, 2022, when 39,900 BTC moved shortly after FTX filed for bankruptcy. The latest figure was just 300 BTC below that post-FTX peak, indicating a rapid response from retail holders seeking to protect their assets.
The migration followed the disclosure of a flaw affecting historical versions of Coldcard wallet firmware that weakened the randomness used to generate wallet recovery seeds. Blockchain researchers estimate that the exploit has now resulted in the theft of approximately 1,367 BTC, worth about $88.6 million, across 4,585 Bitcoin addresses, with investigators continuing to identify additional affected wallets. Unlike the aftermath of the FTX collapse, however, the direction of the migration has changed.
In November 2022, investors withdrew Bitcoin from centralized exchanges into self-custody after confidence in custodial platforms collapsed. Following the Coldcard incident, blockchain analytics indicate many users are moving Bitcoin away from potentially vulnerable self-custody wallets and, in some cases, back onto exchanges or into newly generated wallets created with unaffected software.
Self-Custody Debate Reignites
The incident has reopened a long-running debate within the Bitcoin community over the safest method of storing digital assets. Coldcard hardware wallets have long been regarded as one of the industry’s most secure self-custody solutions because private keys remain offline. The current incident did not compromise Bitcoin itself or the physical devices. Instead, researchers believe certain historical firmware versions generated recovery seeds with insufficient entropy, allowing attackers to reconstruct private keys through large-scale computation.
CryptoQuant Head of Research Julio Moreno described the surge in small transfers as an encouraging sign that users were proactively responding to the risk rather than remaining exposed. The elevated activity suggests thousands of holders are rotating funds into newly generated wallets before attackers can exploit vulnerable addresses. Galaxy Research has also urged users with potentially affected wallets to migrate funds immediately, warning that the attack may still be ongoing as investigators continue identifying new victim addresses.
Market Impact Extends Beyond the Theft
The migration wave demonstrates how a security incident involving a single hardware wallet provider can influence broader Bitcoin network activity. A sharp increase in small transfers often reflects retail participation rather than institutional repositioning. The latest spike therefore offers a rare real-time view of individual holders reacting to a perceived custody risk.
Some industry observers argue the incident reinforces the importance of self-custody because users retained the ability to move funds once the vulnerability became public. Others contend that professionally managed custodial services or regulated Bitcoin exchange-traded funds may provide a safer option for investors unwilling to manage the technical risks associated with private key security.
Regardless of that debate, the on-chain data reveal an unmistakable trend. The Coldcard vulnerability has prompted one of the largest coordinated movements of Bitcoin since the FTX crisis, with tens of thousands of Bitcoin shifting between wallets as holders race to secure their assets. As investigations continue and additional vulnerable addresses are identified, elevated on-chain activity may persist. For now, the incident serves as a reminder that even offline storage solutions depend on robust software implementation—and that confidence in self-custody can change rapidly when those assumptions are challenged.







