Bitcoin active addresses surge to 980K after Coldcard firmware exploit drains up to $100M

1 hour ago 13

On July 31, 2026, Bitcoin’s active address count hit approximately 980,000, the highest reading since December 2024. Before you interpret that as a sign of a bull market waking up, here’s the thing: it wasn’t enthusiasm driving the surge. It was panic.

The spike came one day after Coinkite, the manufacturer behind Coldcard hardware wallets, issued an emergency security advisory disclosing a critical vulnerability in its Mk3 devices. Thousands of Bitcoin holders rushed to move their funds off compromised wallets, producing a sharp jump in network activity that had nothing to do with market sentiment.

What the exploit actually was

The vulnerability traces back to a firmware update, version 4.0.1, released in March 2021. That update contained a flaw in the device’s random number generator, the component responsible for generating the entropy that makes a seed phrase cryptographically secure.

Coinkite published its advisory on July 30, urging any user who generated seeds on the affected firmware to treat those seeds as compromised and migrate funds immediately. By July 31, the network was flooded with precautionary movement transactions.

Active addresses went from roughly 645,000 on July 30 to approximately 980,000 the following day. That single-day jump of more than 330,000 addresses is a direct readout of how many people were scrambling simultaneously.

Attackers didn’t wait for users to act first. Coordinated draining of vulnerable wallets began on July 30, hitting between approximately 4,585 and 7,300 addresses across multiple waves. The addresses targeted had an average dormancy of around three years, suggesting attackers methodically identified wallets that had been sitting untouched since the vulnerable firmware era.

Confirmed losses from those coordinated attacks landed between 1,367 and 1,596 BTC, translating to roughly $89 million to over $100 million at current prices. Analysts noted that if follow-on attack waves continued, total losses could exceed 2,000 BTC, or approximately $130 million.

Why this is bigger than one hardware wallet brand

Coinkite responded with firmware version 5.0.3, released in early August 2026, which addresses the RNG flaw. But the damage to affected users was already done. You can patch a firmware; you can’t un-drain a wallet.

What this means for Bitcoin investors

The security incident arrives at an interesting moment for Bitcoin investment infrastructure. Spot Bitcoin ETFs have been accumulating assets and providing institutional-grade custody to a growing segment of retail investors who would previously have managed their own keys. Analysts tracking the incident have flagged that events like this could accelerate capital flows toward regulated investment vehicles where custody is handled by professional operations with insurance, audits, and redundancy.

For active Bitcoin holders still using Coldcard Mk3 devices, the immediate action is straightforward: check which firmware version was active when your seed was generated. If it falls in the affected window, treat that seed as compromised regardless of whether your wallet has been touched. Generate a new seed on patched firmware, transfer funds to the new wallet, and treat the old address set as abandoned.

Disclosure: This article was edited by Editorial Team. For more information on how we create and review content, see our Editorial Policy.

Read Entire Article