Coldcard’s wallet crisis has shaken Bitcoin sentiment, blurred on-chain signals and exposed a recurring weakness in AI-assisted cyber defenses.
On July 30, hardware maker Coinkite warned users that wallets generated with affected Coldcard firmware could be drained because a software error produced seed phrases with far less randomness than intended.
This security incident, Galaxy Research said, resulted in three suspected attack waves that targeted 4,585 addresses and drained 1,367.05 BTC, worth about $89 million.

The Bitcoin associated with the three identified waves remains in attacker-controlled addresses, according to Alex Thorn, Galaxy Digital’s head of firmwide research.
However, he said smaller opportunistic thefts were already moving through peel chains, cross-chain services and offshore casinos.
Coldcard migrations blur Bitcoin’s bearish signals
This escalating threat has pushed potentially exposed users to move their Bitcoin before attackers reach it.
Although Coinkite has released fixed firmware for affected models, existing affected seed phrases cannot be repaired through an update, leaving holders to generate new wallets and transfer their funds to secure addresses.
That migration has produced an unusual surge in activity among smaller holders and long-dormant coins.
CryptoQuant research head Julio Moreno said transactions involving outputs of less than 1 BTC reached 39,600 BTC on July 31. That was the largest daily total for the cohort since November 2022, when 39,900 BTC moved shortly after FTX collapsed.
Bitcoin’s daily active addresses also jumped from about 645,000 on July 30 to nearly 1 million the following day, their highest level since Dec. 10, 2024.

Moreno said the increase was concentrated among sending addresses, while receiving addresses rose by a much smaller proportion, suggesting holders were moving funds out of existing wallets as a precaution.
Exchange deposits involving transfers below 10 BTC climbed to 7,300 BTC, their highest level since Feb. 6. Some holders may have used exchanges as temporary destinations while creating replacement wallets, although the flows could also include investors preparing to sell.

CryptoQuant analyst JA Maartunn added that 77,402 BTC from older unspent-transaction-output bands had moved since the vulnerability became public.
However, Maartunn cautioned against treating the resulting movements as evidence of broad investor capitulation, saying the context pointed heavily toward users securing their wallets.
He stated:
“The Coldcard seed phrase issue may cause old coins to move as users secure their savings. That can distort LTH Supply Change, Coin Days Destroyed, Spent Output Age Bands and other related charts.”
Meanwhile, broader market sentiment deteriorated sharply amid the heightened network activity.
Blockchain analytics firm Santiment said Bitcoin’s ratio of positive to negative commentary fell to its lowest level since its modern social tracking began. The reading reached 0.58 bullish comments for every bearish one across X, Reddit, Telegram and other platforms.

Santiment attributed the unusually severe reaction to the nature of the breach. The exploit struck cold storage, which many holders regarded as Bitcoin’s safest final line of defense after withdrawing their funds from exchanges and avoiding riskier crypto platforms.
US AI guardrails complicate Coldcard investigation
The same wallet movements that blurred Bitcoin’s market signals have increased the urgency of tracing stolen funds before they reach services where they can be converted or withdrawn.
Galaxy Research has collected reports from victims, clustered suspected attacker addresses and shared its findings with law enforcement, compliance firms and other cyber investigators. Thorn said the firm had reported about 600 addresses believed to be holding Bitcoin stolen from vulnerable Coldcard wallets.
However, he said guardrails on US large language models hindered attempts to track the stolen assets and protect users, forcing investigators to turn to an open-source Chinese model.
Thorn has not identified the US models, disclosed the prompts they rejected, or explained what the alternative system contributed to the investigation.
His concerns nevertheless echo a recent problem encountered by Hugging Face during a live cyberattack.
The AI platform said its security team needed to analyze more than 17,000 recorded events after an autonomous agent compromised parts of its infrastructure. Investigators initially submitted attack commands, exploit payloads, and command-and-control artifacts to frontier models accessed through commercial application programming interfaces.
Those requests were blocked because the models’ safety systems could not distinguish the incident responders from attackers, Hugging Face said. The company instead conducted the forensic analysis with GLM 5.2, an open-weight model developed by China’s Z.ai and operated on its own infrastructure.
The model helped reconstruct the attack timeline, identify compromised credentials, extract indicators of compromise and separate genuine damage from decoy activity. Hugging Face said the AI-assisted investigation reduced work that could have taken days to a matter of hours.
The episode illustrates the asymmetry Thorn says investigators encountered during the Coldcard crisis.
Attackers can use unrestricted or modified systems without observing the safeguards imposed on commercial models. Defenders, meanwhile, may encounter refusals when submitting material that resembles malicious activity, even when their purpose is to contain an active incident.
Broadly removing those restrictions would create a separate risk. Model providers cannot grant elevated capabilities whenever someone claims to be investigating a theft, particularly when the same tools could support wallet attacks, money laundering or attempts to evade transaction-monitoring systems.
That distinction becomes especially urgent in crypto because stolen assets can pass through bridges, exchanges and gambling platforms within minutes. Delays can allow funds to leave services capable of freezing them before victims obtain police reports or investigators complete manual tracing.
The post Coldcard’s $89M wallet bug triggers the biggest Bitcoin movement since FTX and completely distorts market signals appeared first on CryptoSlate.






