Coldcard Bug Triggers $89M Heist, Reversing Post-FTX Self-Custody Trend

Key Takeaways

A firmware flaw in Coldcard wallets triggered an $89 million Bitcoin heist, causing investors to reverse post-FTX trends by depositing coins into centralized exchanges like Binance and Kraken for perceived safety.

Woofun AI reports that the prevailing narrative of self-custody superiority has been abruptly inverted by a critical security failure in Coldcard hardware wallets, manufactured by Coinkite. Rather than fleeing centralized platforms following the FTX collapse, investors are now migrating assets back to exchanges, driven by the revelation that self-custody solutions can harbor fatal vulnerabilities. This behavioral shift marks a significant departure from the post-2022 risk aversion that had previously defined the market’s approach to asset storage.

The reversal in investor behavior is quantifiable through on-chain metrics that highlight a sudden surge in exchange inflows. On Friday, July 30, daily deposits of Bitcoin transactions under 10 BTC spiked to 7.3K BTC, a volume not seen since February 6. Julio Moreno, head of research at CryptoQuant, noted that this anomaly likely stems from users seeking the perceived safety of centralized custodians amid the Coldcard hack. The data indicates a rapid flight to liquidity and institutional-grade security protocols, contrasting sharply with the previous year’s trend of withdrawal.

Structurally, the vulnerability exploited by attackers dates back to a firmware bug introduced in March 2021, which compromised the integrity of seed phrase generation in certain Coldcard devices. Instead of utilizing the device’s hardware random number generator (RNG), affected units fell back on a predictable software random number generator. This fallback mechanism drastically reduced the entropy of the generated seeds, allowing attackers to reconstruct likely seed phrases offline. Consequently, private keys could be derived without any physical interaction with the hardware wallet, exposing the stored assets to immediate theft.

Woofun AI data shows that the scale and timeline of the exploit reveal a coordinated and efficient attack vector. The thefts commenced on Friday, July 30, and have continued in waves, with losses estimated between 1,000 and 1,300 BTC, valued at approximately $70–$90 million. These funds were drained from more than 1,000 distinct addresses, with the largest bursts moving hundreds of BTC in under an hour. Researchers indicate that the attacks may still be ongoing, suggesting that the window for exploitation remains open for unpatched devices, thereby sustaining the pressure on users to relocate their holdings.

Industry reaction has been swift, with high-profile figures re-evaluating the safety of hardware wallets and self-custody models. Binance Founder CZ, among others, has publicly questioned the reliability of current self-custody standards in light of the incident. This commentary underscores a broader skepticism regarding the assumption that physical possession of a device equates to absolute security. The incident has forced a re-examination of the trade-offs between decentralization and the operational security provided by established exchange platforms.

On-chain activity further corroborates the mass migration of assets, with address metrics showing unprecedented levels of engagement. On July 31, daily Bitcoin deposits to exchanges in transactions under 10 BTC jumped to 7,300 BTC, the highest level recorded since Feb 6. Simultaneously, the number of daily active addresses surged from 645,000 on July 30 to almost one million on July 31, a peak not seen since Dec. 10, 2024. Julio Moreno attributed this growth primarily to addresses sending coins to exchanges, signaling a collective move driven by extreme caution rather than speculative trading.

Small transaction volumes provide additional context to this historical comparison, revealing the intensity of the market’s response. According to CryptoQuant, the combined volume of all transfers smaller than 1 BTC reached 39,600 BTC on Friday, nearly matching the 39,900 BTC moved on November 16, 2022, the day after FTX filed for bankruptcy. Moreno remarked that "the Bitcoin plebs had not moved this amount of BTC in a day since the FTX collapse," highlighting the severity of the panic. This parallel suggests that the fear of self-custody failure is now rivaling the fear of exchange insolvency that dominated the previous cycle.

Exchange inflows and final context illustrate the destination of these fleeing assets. Blockchain sleuth Timechainindex observed that total net inflows to exchanges totaled 11,163 BTC on July 31, with the majority flowing into major platforms such as Binance, River, Kraken, and OKX. On X, the handle described these movers as "plebs who are scared," emphasizing the emotional driver behind the capital shift. The total number of BTC held in wallets tied to centralized exchanges increased to 2.715 million from 2.703837 million prior to the Coldcard exploit. While the incident is specific to Coldcard and does not represent a broad failure of self-custody, it has temporarily shifted the risk calculus for retail holders, favoring the familiar infrastructure of centralized exchanges over the complexities of secure hardware management.

Comments

Me
Replying to @User
0/800

No comments yet.

Notifications

Sign in to view messages
View all messagesManage subscriptions