Sub-1 BTC Transfers Surge to FTX-Era Levels Amid Coldcard Hack
Key Takeaways
Suspected Coldcard breach drives small Bitcoin transfers to highest volumes since November 2022. Galaxy Digital reports $88.6M lost across 4,585 addresses. Experts debate self-custody risks versus ETF safety as attackers remain active.
Woofun AI reports that a significant exodus of small Bitcoin holdings has emerged, directly attributed to the ongoing suspected Coldcard security incident. This surge in sub-1 BTC transfers marks the most intense movement of retail-scale assets since the collapse of cryptocurrency exchange FTX, reigniting a high-stakes debate regarding the efficacy of self-custody versus third-party reliance. The incident serves as a critical stress test for Bitcoin’s core principle of user-controlled funds, with data indicating that the current volume of small transactions rivals the panic-driven movements observed during previous market catastrophes.
The scale of this capital flight is quantifiable through specific on-chain metrics. Bitcoin transfers below 1 BTC climbed to their highest daily level since November 2022 on Friday, with 39,600 BTC moved, according to data shared by CryptoQuant head of research Julio Moreno on Saturday. This figure was just 300 BTC below the 39,900 BTC transferred on Nov. 16, 2022, days after FTX filed for bankruptcy. Moreno noted that "The Bitcoin plebs had not moved this amount of BTC in a day since the FTX collapse," adding that he was encouraged to see users "taking action." The proximity of these two data points—39,600 BTC on Friday versus 39,900 BTC in November 2022—highlights the severity of the current disruption, suggesting that user behavior is mirroring the urgency seen during the FTX crisis.
Woofun AI data shows that the financial impact of the breach continues to expand as researchers identify new victim clusters. Galaxy Research, the research arm of crypto investment company Galaxy Digital, reported Saturday that the latest identified wave drained an additional 207.7 BTC, worth about $13.2 million. This recent theft brought estimated total losses to 1,367 BTC ($88.6 million) across 4,585 addresses.
Alex Thorn, Galaxy Digital’s head of firmwide research, warned in an X post on Sunday that the attack was still ongoing and urged users to move funds from Coldcard-generated addresses immediately if they had not already done so. Thorn emphasized that his team continued to identify new victim and attacker addresses, noting that reports from users had helped researchers and authorities track stolen funds. The persistence of the threat is underscored by the fact that the hack first surfaced in late July and appeared to remain active at the time of publication, indicating a sustained operational capability by the attackers.
Despite the mounting losses, proponents of self-custody argue that the system remains resilient. Nick Neuman, CEO of Bitcoin security company Casa, pushed back against claims that "self-custody is over," arguing that its distributed nature gave users time to react. He estimated that potentially 10 times more Bitcoin was protected through self-custody than was stolen and identified in the attack so far. Neuman’s perspective isolates the incident as a failure of specific wallet infrastructure rather than a flaw in the broader concept of holding one’s own keys. By framing the narrative around the ratio of protected assets to stolen ones, he suggests that the majority of the ecosystem remained secure, even as a subset of users fell victim to the exploit.
Conversely, traditional finance advocates are using the incident to promote alternative custody solutions. Eric Balchunas, senior ETF analyst at Bloomberg, argued that Bitcoin exchange-traded funds (ETFs) provide a safer and more convenient alternative for many users, pointing to the long operating history of the ETF industry. Balchunas’s argument rests on the premise that institutional-grade oversight reduces the risk of individual user error or targeted hacks.
However, others pushed back, saying the Coldcard incident was a failure of one wallet provider rather than a failure of self-custody itself. This counter-argument maintains that the security model of self-custody is sound, but the implementation by Coldcard was compromised, thereby isolating the risk to a specific vendor rather than the entire paradigm.
The broader implication of this event is a renewed scrutiny of Bitcoin self-custody principles and the risks associated with third parties. As the debate intensifies, users are forced to weigh the convenience and regulatory protection of ETFs against the sovereignty and potential vulnerabilities of self-custody. The Coldcard hack has not only resulted in significant financial losses but has also exposed the fragility of relying on single points of failure in decentralized systems. This marks a pivotal moment for the industry, where the balance between user autonomy and security infrastructure will likely dictate future adoption trends.
Comments
No comments yet.