Coldcard hack fuels sub‑1 Btc transfers as bitcoin holders rush to secure funds

8 минут чтения

Coldcard hack widens as sub‑1 BTC transfers hit post‑FTX record

Bitcoin holders rushed to move coins in small batches as the suspected Coldcard wallet hack continued to unfold, pushing sub‑1 BTC on-chain activity to its highest level since the collapse of FTX.

On Friday, Bitcoin transfers of less than 1 BTC surged to 39,600 BTC in total volume, according to data shared by CryptoQuant’s head of research, Julio Moreno. That daily figure was only 300 BTC shy of the record set on Nov. 16, 2022, in the immediate aftermath of FTX’s bankruptcy.

Moreno noted that such levels of “pleb-sized” movements – small, retail-style transactions – had not been seen in nearly two years, interpreting the spike as a sign that everyday users were proactively securing their holdings in response to the ongoing security incident.

Loss estimates swell to $88.6 million

The suspected Coldcard-related exploit, which first drew attention in late July, has continued to grow as investigators identify more compromised addresses. Galaxy Research, the research division of crypto investment firm Galaxy Digital, reported over the weekend that a newly detected wave of attacks siphoned off an additional 207.7 BTC, worth around 13.2 million dollars at recent prices.

That latest tranche lifted the estimated total haul to 1,367 BTC – roughly 88.6 million dollars – spread across 4,585 victim addresses. Data compiled by the Coldcard Watch monitoring effort shows a steadily expanding list of wallets drained over several attack waves.

Galaxy Digital’s head of firmwide research, Alex Thorn, warned that the operation remained active. In a post on X, he urged anyone still using addresses generated by affected Coldcard setups to move their coins immediately to fresh, uncompromised wallets. Thorn added that new victim and attacker addresses were being identified in real time, and that user reports were proving vital for mapping the flow of stolen funds.

Anatomy of the attack waves

While the full technical details remain under investigation, researchers have described the attacks as unfolding in clearly defined waves rather than as a single, one-off drain. Each wave appears to target new clusters of addresses that share similar wallet-generation patterns, suggesting a systemic vulnerability or supply-chain compromise rather than random phishing.

The attackers have displayed patience and coordination, often waiting until substantial balances accumulate before sweeping funds. This behavior has made it harder for casual users to detect an issue early: a wallet may appear to function normally for some time before suddenly being emptied.

Investigators are also tracking how quickly stolen coins are consolidated, mixed, and redistributed across the network. The pattern of movement can help distinguish between amateur thieves and more professional, organized groups. In this case, the structured nature of the theft and the scale of the operation point to well-prepared attackers with a deep understanding of Bitcoin’s transaction graph.

Self-custody under the microscope

Beyond the immediate financial damage, the Coldcard incident has ignited a broader discussion about one of Bitcoin’s foundational ideas: self-custody. The principle that users should hold their own private keys – rather than trusting centralized intermediaries – has long been a defining ethos of the ecosystem. But every major wallet hack or exploit reopens the question of how realistic and safe that ideal is for the average person.

For some critics, the Coldcard case is proof that self-custody, especially via hardware wallets, is simply too complex and fragile for mainstream adoption. They argue that ordinary users face an unfair burden of security: choosing reputable hardware, verifying devices, managing backups and seed phrases, staying alert to firmware or supply-chain risks, and reacting quickly when something goes wrong.

Supporters of self-custody counter that the problem lies not with the concept, but with specific implementations and user practices. They point out that failures of a single wallet vendor or configuration do not invalidate the entire model. In their view, incidents like the Coldcard hack should lead to better standards, clearer user education, and more robust wallet designs – not a wholesale retreat to centralized custody.

Industry response: not the end of self-custody

Nick Neuman, CEO of Bitcoin security firm Casa, rejected claims that the Coldcard exploit signaled the “end” of self-custody. He emphasized that the distributed nature of self-custodial setups – where millions of users control their own keys with different tools and configurations – can actually provide resilience.

Neuman estimated that, despite the high dollar value of the hack, the amount of Bitcoin effectively protected by self-custody is likely an order of magnitude larger than the coins stolen and identified so far. From this perspective, the incident represents a serious but localized failure, not a systemic collapse.

Security specialists also note that many self-custody users employ multi-key or multi-signature setups, hardware diversity, and strict operational procedures that dramatically reduce single-point-of-failure risk. Users who relied on a single device and a single seed, especially if they skipped verification steps, were inherently more exposed.

ETFs and custodians: safer, or differently risky?

The debate has also drawn in voices from traditional finance. Eric Balchunas, a senior ETF analyst at Bloomberg, argued that for a significant share of the population, professionally managed Bitcoin exchange-traded funds offer a safer and more convenient alternative to managing private keys.

Proponents of ETFs and other institutional products highlight the long track record of the broader ETF industry, regulatory oversight, audited custody, and well-established operational processes. From their standpoint, it is more realistic for most people to rely on professional custodians than to expect them to master the nuances of cryptographic security.

Opponents respond that while institutional products may reduce some technical risks, they introduce a different class of dangers: regulatory freezes, asset seizures, redemption halts, mismanagement, or insolvency at the custodian level. For users who value censorship resistance and direct control over their money, those trade-offs are unacceptable.

The Coldcard incident has therefore sharpened, rather than settled, the choice between “not your keys, not your coins” and the comfort of regulated, custodial exposure.

Lessons for everyday Bitcoin users

For individual holders trying to navigate this landscape, the hack offers several practical takeaways:

Diversify custody methods. Relying entirely on a single wallet brand, device, or seed phrase concentrates risk. Spreading funds across different wallet types, security models, and even different custodians can limit worst-case losses.
Verify devices and software. Whenever possible, obtain hardware directly from trusted channels, verify seals and firmware, and follow vendor and community guidance on detecting tampering or compromised distributions.
Use multi-key setups. Multi-signature or threshold schemes, where several keys are required to move funds, can make it dramatically harder for a single compromised device to result in total loss.
Test recovery and migration. Regularly practicing small test transactions to new wallets and verifying backup restores can ensure you can move quickly if a vulnerability is discovered.
Stay informed about security advisories. Many losses occur simply because users do not realize their setup is at risk. Following wallet-specific security updates and broader industry alerts is critical.

Why sub‑1 BTC activity matters

The surge in small transactions during the Coldcard episode is not just a curiosity; it provides a window into how retail and smaller holders react to perceived threats.

Historically, spikes in sub‑1 BTC movements have often coincided with moments of acute stress or uncertainty. The wave that followed the FTX collapse reflected users yanking coins off exchanges into self-custody. The latest surge appears to reflect the inverse: users reshuffling self-custodial holdings, sometimes toward new wallets, sometimes back to custodial or institutional solutions they perceive as safer.

Analysts view this kind of behavior as increasingly important for understanding market sentiment. Large whale transfers can move markets, but it is the collective behavior of tens of thousands of smaller addresses that often signals a broader shift in trust and risk tolerance.

Broader implications for wallet design and standards

For wallet makers and security researchers, the Coldcard saga underscores the need for more transparent, verifiable, and user-friendly designs. Future hardware and software solutions are likely to prioritize:

Stronger supply-chain protections and easy-to-use verification procedures that ordinary users can actually follow.
Built-in redundancy and multi-key support so that a compromise of one device does not automatically mean a total loss.
Clear, non-technical alerts when unusual or suspicious patterns are detected, prompting users to review transactions or migrate funds.
Independent, public security audits that can be verified without relying solely on marketing claims or opaque certifications.

The incident may also accelerate efforts to develop open standards for wallet security and recovery, allowing users to migrate between providers without losing important protections.

Market backdrop: Bitcoin under pressure

The hack has unfolded against a challenging macro backdrop for Bitcoin. The asset recently slipped to two‑week lows as United States equities failed to sustain a rebound seen in Asian markets. Rising US Treasury yields and renewed debate around inflation, fueled in part by movements in inflation-protected securities, have weighed on risk assets broadly.

Despite late‑month selling pressure, US‑listed Bitcoin ETFs still managed to close July in positive territory, highlighting steady institutional interest even as spot prices fluctuate. Meanwhile, in the broader digital asset landscape, real-world asset perpetual futures on some derivatives platforms are seeing volumes that increasingly rival Bitcoin’s, signaling continued experimentation and diversification within the crypto market.

Self-custody is evolving, not disappearing

Taken together, the Coldcard exploit, the surge in sub‑1 BTC transfers, and the renewed custody debate point to a maturing ecosystem grappling with hard trade-offs rather than a simple binary of “safe” versus “unsafe.”

Self-custody is unlikely to vanish: for many, it remains the only way Bitcoin fulfills its original promise of being borderless, seizure-resistant money. At the same time, the incident highlights that self-custody is not a one-size-fits-all solution and that its security depends heavily on implementation, education, and continuous improvement in wallet technology.

For now, the attack remains active, loss estimates continue to rise, and investigators are still piecing together the full scope of the compromise. The response – from users rapidly moving coins in small denominations to analysts debating the future of custody – suggests that how the industry digests this event may shape Bitcoin security practices for years to come.