Bitcoin Active Addresses Jump to 980K After Coldcard Mk3 Flaw Sparks Wallet Run, Losses Seen Up to $100M
AI Market Summary
Bitcoin active addresses spiked to ~980k due to emergency fund migrations after Coinkite disclosed a critical Coldcard Mk3 RNG flaw, not organic demand. Coordinated drains reportedly hit thousands of long-dormant wallets, with estimated losses of ~1,367–1,596 BTC ($89–$100M+) and risk of further waves. The incident elevates near-term security and custody risk perceptions and may shift preferences toward institutional custody via spot BTC ETFs.
Impact level
● High
Affected assets
BTC/USDT+0.12%
AI Insight · BTC/USDTAI Insight
▼ Bearish
Trade now
⚠️ AI-generated insights are based on news content and are provided for informational purposes only. They do not constitute investment advice or represent the views of BingX. Investing involves risk. Please trade responsibly.
Bitcoin network activity spiked on July 31, 2026, with active addresses climbing to roughly 980,000—the highest level since December 2024. The move wasn't a sign of renewed bullish momentum. It was a rush to safety.
The surge followed an emergency security advisory from Coinkite on July 30 warning of a critical vulnerability affecting Coldcard Mk3 hardware wallets. As thousands of users hurried to move funds away from potentially exposed wallets, the network saw a wave of precautionary transactions. Active addresses rose from about 645,000 on July 30 to around 980,000 a day later, a one-day increase of more than 330,000.
The root cause traces back to firmware version 4.0.1, released in March 2021. According to the advisory, that update introduced a flaw in the device's random number generator, weakening the entropy used to create seed phrases. Coinkite urged anyone who generated seeds on the affected firmware to assume those seeds were compromised and migrate funds immediately.
Attackers acted quickly. Coordinated draining began on July 30, striking an estimated 4,585 to 7,300 addresses in multiple waves. Many of the targeted wallets had been dormant for about three years on average, suggesting attackers systematically sought out addresses likely created during the vulnerable firmware period.
Confirmed losses from the attacks were estimated at 1,367 to 1,596 BTC, or roughly $89 million to more than $100 million at current prices. Analysts warned that if additional waves continue, total losses could exceed 2,000 BTC—approximately $130 million.
Coinkite released firmware version 5.0.3 in early August 2026 to fix the RNG issue, but the incident underscored the reality that patches cannot reverse stolen funds.
The episode also lands as Bitcoin's investment plumbing continues to evolve. Spot Bitcoin ETFs have been expanding assets and offering institutional-grade custody, drawing in investors who previously self-custodied. Analysts following the incident said events like this may accelerate flows toward regulated vehicles where custody is handled by professional operations with insurance, audits, and redundancy.
For Coldcard Mk3 users, the remediation is operational and urgent: verify which firmware was running when the seed was generated. If it falls within the affected window, treat the seed as compromised even if no theft is visible. Generate a new seed on patched firmware, transfer funds to a new wallet, and retire the old address set.