Coldcard flaw drives 978,570 Bitcoin active addresses on July 31

Add as a preferred source on Google

A Coldcard firmware security flaw triggered a sharp rise in Bitcoin on-chain activity as users moved funds to new addresses. Despite the surge in transfers and negative sentiment, exchange inflows remained subdued, suggesting the incident was driven more by defensive wallet migration than widespread selling.

A security flaw affecting older Coldcard firmware triggered a sharp increase in Bitcoin on-chain activity after attackers began draining vulnerable wallets on July 30. However, Santiment data show the response was largely a migration to new addresses rather than a broad rush to exchanges, offering a more nuanced picture of market stress.

Coldcard incident lifts Bitcoin activity to 978,570 on July 31

Bitcoin active addresses reached 978,570 on July 31, according to Santiment data, about 1.6 times July’s average. The figure was 43% above July’s busiest day. From August 1 through August 6, Bitcoin averaged about 720,000 daily addresses.

Coldcard incident lifts Bitcoin activity to 978,570 on July 31
Source: Santiment

Santiment defines daily active addresses as unique addresses involved in transactions. The spike does not indicate selling. It shows unusually high Bitcoin transfer activity during the scare.

Also Read: Trezor Warns of Rising Phishing Attempts Amid Coldcard Hack 2026

Coldcard security scare pushes Bitcoin sentiment to -540

Santiment’s sentiment balance fell to -540 on August 1, its lowest level since February, before recovering most of the decline. The metric measures the difference between positive and negative sentiment, making the reading a gauge of social pessimism.

The reaction matters because Coldcard is designed for Bitcoin self-custody. Coinkite says its devices keep keys offline and can operate without exposing them to the internet. The incident shows offline storage still depends on secure firmware and key generation.

Coldcard flows show no matching Bitcoin exchange rush

Despite the activity spike, exchange inflows did not show an equivalent surge. Santiment data supplied for this analysis put average Bitcoin exchange inflows at about $1.55 billion from August 1 through August 6, below the roughly $1.67 billion July average. That gap weakens the case for selling.

The distinction matters because on-chain movement is not synonymous with selling. If holders moved coins into newly generated self-custody addresses, the activity represents defensive repositioning rather than an attempt to sell. Exchange flows are therefore more useful than raw address activity for judging market impact.

Coldcard fallout leaves Bitcoin holders watching key flows

The next signal is whether active addresses normalize as the incident fades. A sustained increase in exchange inflows would suggest more holders are moving Bitcoin toward trading venues. Continued transfers between self-custody addresses would support the migration interpretation.

The episode highlights a custody lesson. Self-custody reduces exchange counterparty risk but does not remove firmware or key-generation risks. Coinkite’s current guidance provides firmware verification and update procedures, making those steps relevant for users assessing their devices or seeds.

Also Read: Galaxy Estimates Coldcard Exploit Losses Could Reach 2,055 BTC

Amrin Sanjay

Amrin Sanjay

Amrin Sanjay is an Industry Reporter at Tron Weekly, covering developments across the cryptocurrency and blockchain sector. Her reporting focuses on Bitcoin, Ethereum, altcoins, and decentralized finance, alongside market activity, protocol updates, and ecosystem trends. She closely tracks Layer 1 and Layer 2 projects, DeFi tokens, and key technical indicators to explain market movements and on-chain activity with clarity and accuracy for both new and experienced readers.

Articles: 521