The Coldcard Thief Moved 1,083 BTC. Everyone Else Moved 210,000.

The Coldcard exploit drained roughly 1,083 BTC. It also pushed 210,000 BTC out of long-term holder wallets and lifted active addresses to a 20-month high, distorting on-chain signals.

Jan Whitfield Analysis

The Coldcard exploit produced two numbers. Almost all of the coverage used the first one.

The theft itself has been traced to roughly 1,196 addresses and about 1,083 BTC, worth somewhere near $70m, moved over a window of roughly 41 minutes with the core burst compressed into about 25. Dollar figures in circulation range from $89m to $130m depending on which address clusters an analyst includes and which price they mark against.

The second number is the one that matters for anyone reading on-chain data this month. Glassnode recorded roughly 210,000 BTC leaving long-term holder wallets in the week after the disclosure. That is close to 194 times the amount actually stolen.

What the flaw was

The vulnerability traces to a firmware defect introduced in March 2021 that weakened the randomness used to generate seed phrases on affected Coldcard devices. In practical terms it reduced effective key strength from 128 bits to about 40.

Forty bits is not a wall. It is a queue. An attacker with the shortcut replicated on their own hardware can enumerate candidate recovery phrases offline and check which ones correspond to funded addresses. No physical access to the device is required, no malware, no user error. A wallet sitting untouched in a drawer since 2021 was drained without anything happening to it.

Coinkite advised affected users to generate entirely new wallets and move their coins immediately. That advice is what produced the second number.

The on-chain distortion

Long-term holder supply fell from roughly 15 million BTC to about 14.7 million over the week — the largest weekly decline in long-held supply since December 2024. Daily active addresses rose to approximately 980,000, also the highest since December 2024.

Under any ordinary reading, that combination is a top signal. Long-dormant coins waking up in size while network activity spikes is the classic distribution pattern: old money moving, retail arriving, supply rotating from patient hands to impatient ones.

It is not what happened. Glassnode called the spike "an operational security response, not a change in market conviction."

The coins did not go to exchanges to be sold. They went from one self-custodied address to another self-custodied address, because the first one had a compromised key. The long-term holder cohort did not lose faith; it lost its seed entropy. Every one of those coins reset its holding-period clock the moment it moved, which is why the metric collapsed.

Why this breaks a lot of models

On-chain analysis works by inferring intent from movement. The inference is usually sound because most large movements are economically motivated. This one was not.

Three specific consequences are worth flagging.

The LTH cohort is now understated. Roughly 210,000 BTC that belonged to holders with multi-year conviction has been reclassified as short-term supply. Any model that treats short-term holder supply as latent sell pressure is now carrying a large block of coins that will not behave that way. This distortion persists for 155 days — the standard threshold at which a coin re-enters the long-term cohort — which means it will be contaminating readings into January 2027.

Realised-price and cost-basis metrics have been reset on a large tranche. Coins that moved re-price their on-chain cost basis at the moment of transfer, not at their original acquisition price. Anything derived from that — realised cap contributions, MVRV by cohort, unrealised profit bands — has absorbed a mechanical shift that reflects no trading at all.

The active address high is not demand. Nearly a million daily active addresses would normally be read as network growth or renewed retail interest. Here it is one population of users generating two addresses each, once, under duress.

The part nobody can size yet

There is a question underneath all of this that the data cannot answer: how much of the migration was necessary?

Only wallets generated on affected firmware within the vulnerable window are actually at risk. The 210,000 BTC figure almost certainly contains a large share of coins that were never exposed, moved by holders who could not quickly determine whether their device qualified and reasonably chose not to find out the hard way.

That is the honest read on the ratio. The exploit stole 1,083 BTC. The uncertainty about the exploit moved 210,000.

What to watch

Whether long-term holder supply rebuilds on schedule from roughly January 2027 as these coins re-age — if it does, the episode was pure noise and every bearish LTH reading published this month was wrong. Whether exchange inflows stayed flat through the migration window, which is the cleanest test of whether any of this was selling. And whether Coinkite publishes a firmware-version-level breakdown, which is the only thing that would let anyone separate necessary moves from precautionary ones.

Until then, treat every on-chain chart with an August 2026 spike as suspect. The chain recorded panic about custody, not a change of mind about price.

Disclaimer The information provided on Coinliva is for informational purposes only and does not constitute financial or investment advice. Cryptocurrency investments are highly volatile and involve risk. While we strive to provide accurate and up-to-date information, some details may change over time. Always conduct your own research before making any financial decisions.
Jan Whitfield
Author

Jan Whitfield

Jan Whitfield is the founder and Editor-in-Chief of Coinliva. His coverage focuses on the macro crypto landscape, including regulatory developments, institutional adoption, and structural shifts shaping the digital asset industry. He tracks how policy decisions, ETF flows, and corporate treasury moves connect to broader market dynamics, drawing on primary regulatory filings, official statements, and on-chain data.