Coldcard Exploit Leads Investors to Move Bitcoin Back to Exchanges: A Reversal of FTX Collapse Trend
A security vulnerability in Coldcard hardware wallets is prompting smaller Bitcoin holders to transfer their funds to centralized cryptocurrency exchanges for safety. This movement represents a trend opposite to what was observed following the FTX collapse in late 2022.
A critical security vulnerability identified in Coldcard hardware wallets has resulted in the theft of approximately 1,367 Bitcoin (BTC), valued at around $89 million, from 4,585 addresses. According to blockchain analytics firms, this incident has led smaller Bitcoin investors to move their funds from self-custody back to centralized cryptocurrency exchanges, seeking greater security. This behavior starkly contrasts the trend seen after the FTX collapse in late 2022, when investors rapidly withdrew funds from exchanges.
The issue within Coldcard wallets, manufactured by Canadian firm Coinkite, stems from a software flaw introduced with firmware version 4.0.1 for Mk3 models in March 2021. This bug caused the wallets to generate seed phrases using a predictable software pseudorandom number generator (PRNG) instead of the intended hardware random number generator (RNG). Consequently, the randomness of the generated seeds was significantly reduced, making it possible for attackers to guess private keys. The vulnerability affected Mk3, Mk4, Mk5, and Q models to varying degrees.
The attacks unfolded in three waves. The first wave occurred on July 30, 2026, with 1,082.65 BTC being drained from 1,196 wallets in just 41 minutes. Subsequent waves targeted smaller balances. Coinkite acknowledged the vulnerability and released emergency firmware updates on July 31, 2026. However, the company emphasized that updating the firmware does not rectify already compromised seeds, and users must generate new seed phrases and transfer their funds to new addresses to ensure safety.
This incident has significantly shifted sentiment in the Bitcoin market. The bullish-to-bearish sentiment ratio for Bitcoin plummeted to a record low, even surpassing levels recorded during previous major crypto crises. This decline is attributed to concerns over the security of self-custody rather than a broader market downturn. Despite the widespread fear, Bitcoin's price has remained relatively stable, holding above the $63,000 level.
The Coldcard exploit has reignited a fundamental debate within the cryptocurrency ecosystem concerning the security of hardware wallets and the practice of self-custody. It underscores that even hardware wallets, long considered one of the most secure methods for holding funds, can be susceptible to software vulnerabilities. Some experts have even suggested that artificial intelligence technologies might have been employed to discover this flaw. This situation is prompting investors to re-evaluate the balance between self-custody and custodial solutions, such as Bitcoin exchange-traded funds (ETFs).
Analysts and market observers anticipate that such security breaches, particularly those affecting self-custody, could increase trust in centralized and regulated platforms, especially among retail investors. While the FTX collapse eroded confidence in centralized exchanges, leading to withdrawals, the Coldcard hardware wallet exploit has highlighted the inherent risks of self-custody. This dual impact may lead to a more balanced and diversified approach to cryptocurrency storage solutions. In the coming period, hardware wallet manufacturers are expected to further strengthen their security protocols and place greater emphasis on independent audits.
Related Symbols
₿ Want to ride this crypto move?
Open an account in minutes. Compare brokers offering crypto and start investing today — zero commission options available.
Comments (0)
No comments yet. Be the first to comment!