Bitcoin Active Addresses Jump to 8-Month High as Users Rush to Secure Funds After Coldcard Flaw
AI Market Summary
Bitcoin on-chain activity spiked to ~0.98M daily active addresses, driven by Coldcard firmware-related wallet sweeps and urgent custody migrations rather than improved demand. Confirmed losses exceed $100M, and exchange balances briefly rose by ~22k BTC, signaling potential near-term distribution risk. Social sentiment weakened materially (Santiment bullish-to-bearish ratio at a tracking low), reinforcing security-driven risk aversion across BTC.
Impact level
● High
Affected assets
BTC/USDT-0.72%
AI Insight · BTC/USDTAI Insight
▼ Bearish
Trade now
⚠️ AI-generated insights are based on news content and are provided for informational purposes only. They do not constitute investment advice or represent the views of BingX. Investing involves risk. Please trade responsibly.
Bitcoin (BTC) activity spiked at the end of July as attackers began draining wallets whose seed phrases were created using flawed Coldcard firmware. On July 31, active addresses climbed to about 0.98 million for the day, the highest level since December 2024, according to Glassnode data published on August 6. Glassnode described the move as "fear-driven on-chain activity", saying users were shifting seed phrases and moving coins to new custody setups as an operational security measure rather than a change in market outlook.
Coin Metrics reported 967,546 active addresses on July 31, up 54% from July's average of 627,061. The last higher figure in that series was 985,635 on December 10, 2024. Activity remained elevated into early August, with Coin Metrics logging 730,433 active addresses on August 5, about 16% above the July average and the seventh consecutive day above it.
Exchange balances also rose during the window. Coin Metrics said bitcoin held on exchanges increased from 2,654,863 on July 29 to 2,676,998 on August 3, a gain of 22,135 BTC, or 0.83%. Balances then slipped to 2,667,058 by August 5, leaving roughly 12,200 BTC of the earlier inflows still on exchanges.
Transaction volume did not follow the same pattern. The network processed 607,581 transactions on July 31, below July's average of 656,321, even as active addresses ran far above their monthly norm.
Coinkite, the Canadian company behind the Coldcard hardware wallet, said seeds created on Mk2 and Mk3 devices running firmware version 4.0.1 (released in March 2021) through version 4.1.9 suffered from weakened randomness. The firm added that seeds generated on Mk4, Mk5, and Q devices before patched releases contained about 72 bits of entropy versus the intended 128 bits. Patched firmware was released as version 4.2.0 for Mk2 and Mk3, 5.6.0 for Mk4 and Mk5, and 1.5.0Q for Q.
Coinkite noted that users who created seeds using at least 50 fair, independent, private dice rolls would have drawn sufficient entropy from the dice alone, and that a strong, unique BIP39 passphrase would also force an attacker to discover the passphrase. The company stressed that a passphrase "does not repair the affected seed" and advised users to migrate regardless. Installing the patch does not fix a seed that was already generated.
The first reported sweep removed 594.5 BTC across 1,324 UTXOs from roughly 500 single-signature addresses in four consecutive blocks on July 30. Median losses were 0.41 BTC per victim, and the largest single loss was 29.9 BTC. Galaxy Research estimates 1,596 BTC has been confirmed stolen from about 7,300 addresses, rising to 2,055 BTC when suspected sweeps are included. CryptoPotato previously reported that confirmed losses surpassed $100 million last week.
Social sentiment also deteriorated. Santiment recorded 0.58 bullish comments for every bearish one across social channels, the lowest positive-to-negative ratio since it began tracking.
Coinkite has urged all users who generated seeds on affected firmware to move funds to a new seed created on patched hardware. Bitcoin was trading at $64,606 on August 6.