A cracked golden 3D Bitcoin coin with two thin light trails flowing in opposite directions: one green trail toward a shield-and-lock icon, one red/amber trail toward an exchange-building icon, over a dark candlestick-chart background
Original illustration generated with AI (Adobe Firefly) — not representative of real data.

The Coldcard Panic Moved as Much Bitcoin as FTX Did — In the Opposite Direction

On July 31, 2026, sub-1 BTC transfers hit 39,600 BTC in a single day — 300 BTC short of the all-time record set after FTX collapsed in November 2022. The size matches almost exactly. The direction doesn't: in 2022, panic pushed people out of exchanges and into self-custody. This time, a real share of it is moving the other way.

Coverage of the Coldcard entropy flaw has mostly tracked one number: how much got stolen. It went from 594 BTC to 1,596 to 1,816, depending on who was counting and when. July 31 produced a different kind of number — not how much was taken, but how many people reacted, measured directly on-chain.

What the CryptoQuant figure measures, and what it doesn't

CryptoQuant's head of research, Julio Moreno, published the figure the same day: transfers under 1 BTC — the size bracket typically used as a rough proxy for retail activity, not whale or institutional flow — hit 39,600 BTC on July 31. That's the highest daily total since November 2022, sitting just 300 BTC below the category's all-time high: 39,900 BTC, moved on November 16, 2022, days after FTX filed for bankruptcy.

The comparison is real, but it deserves the same caution any aggregate figure does: "transfers under 1 BTC" says nothing about where those coins ended up. And that's the part most coverage skipped past. The same day, deposits under 10 BTC into exchanges rose to 7,300 BTC — the highest level since February 6. A real portion of this stampede isn't people moving to a safer, fresh wallet. It's people handing their funds to an exchange.

Comparison between November 16, 2022 (39,900 BTC fleeing exchanges for self-custody, fear of exchange insolvency) and July 31, 2026 (39,600 BTC fleeing self-custody for exchanges, fear of hardware wallet failure) — same volume, reversed direction
Original diagram, built from the two figures cited in the text. In 2022 the fear was the exchange. In 2026, it's the device itself.

That's close to an exact inversion of the FTX pattern. Back then, the fear was that an exchange would collapse and take deposits down with it — pulling funds into a wallet you control was the rational response. This time, the fear is that the self-custody device itself generated a weak seed — and part of the response is sending those same funds back to a third party, which is precisely the risk self-custody exists to remove.

Why so many people are moving at once

If you want the mechanism — why some Coldcard units ended up running a weak software formula instead of hardware noise, with the exact entropy math and the per-model, per-firmware triage — it's covered in full in our original breakdown. Short version: a 2021 integration bug left some devices generating seeds with roughly 40 bits of randomness instead of 128 — weak enough for a well-resourced attacker to brute-force. An affected seed shows no symptom at all; it looks exactly like a secure one.

What to do — and what not to do

If your Coldcard falls in the affected range, sequence matters as much as the action itself:

  1. Update the firmware first. The fixed version stops generating weak seeds, but it does nothing for one that already exists.
  2. Generate a genuinely new seed. Never reuse the old one, not even on a different device or brand — the weakness travels with the phrase, not the hardware.
  3. Send a small test transaction before moving anything else, to confirm the new wallet behaves as expected.
  4. Migrate the rest. Only then.

Two mitigations still hold if you already used them: a seed generated from at least 50 fair, independent dice rolls never depended on the device's random number generator in the first place, and a strong, self-generated BIP-39 passphrase adds a layer that survives even a weak base seed.

And here's the one move to avoid, however unsettling the headline feels: sending your funds to an exchange "just in case." That's exactly the behavior the data above shows part of the market already doing — and it swaps a risk you can personally audit (your seed's entropy) for one you have zero visibility into (a third party's solvency and custody practices).

Don't enter your recovery phrase into any site that offers to "check if your wallet is affected." Not this one, not any other. Typing those words anywhere hands control of your funds to whoever runs that page — and scams built around exactly this incident are already active. The only legitimate way to check your exposure is by provenance: which device, which firmware, which method generated the seed. Never by typing the phrase in.

A manufacturer's bug isn't a bug in the model

Worth saying with the same clarity we used to cover the flaw itself: this isn't an argument against self-custody, it's the argument for being able to verify it yourself. The bug belongs to one manufacturer — Coinkite, specifically its Coldcard line — not to the idea of holding your own keys. Other signing and custody devices from the same maker, TAPSIGNER, OPENDIME, and SATSCARD, are unaffected: they run on a different codebase entirely. And the defenses that predate this incident — dice-generated seeds, a self-chosen passphrase, splitting keys across a multisig with hardware from different manufacturers — remain solid for the same reason they always were: none of them depend on one manufacturer getting everything right, every time.

You can investigate any Bitcoin address, including the ones in this case, with our address analyzer, free, against our own node.

Last updated: August 6, 2026