Coldcard flaw sparks surge to 330,000+ new Bitcoin addresses in one week

AI Market Summary
A disclosed Coldcard-related firmware RNG flaw has driven a sharp rise in new Bitcoin addresses as users migrate wallets after reported thefts totaling at least 1,816 BTC. The episode underscores operational and implementation risk in self-custody, potentially increasing short-term on-chain activity (address creation, UTXO consolidation) while reinforcing investor attention on custodial alternatives such as exchanges and spot ETFs.
Impact level
● Medium
Affected assets
BTC/USDT-0.61%
AI Insight · BTC/USDTAI Insight
● Neutral
Trade now
⚠️ AI-generated insights are based on news content and are provided for informational purposes only. They do not constitute investment advice or represent the views of BingX. Investing involves risk. Please trade responsibly.
According to The Block, wallet migrations tied to a security vulnerability affecting Coldcard devices pushed the number of newly created Bitcoin addresses from roughly 260,000 to more than 330,000 last week, snapping a decline that had persisted through most of 2026. Since July 30, users of Coinkite hardware wallets have lost at least 1,816 BTC—about $116 million—in four separate waves of attacks. The issue traces back to a 2021 firmware bug: instead of relying on the device's built-in hardware entropy, the firmware used a weak software-based random number generator to create mnemonic phrases, enabling attackers to brute-force wallets generated offline. Coinkite has urged users who created wallets between March 2021 and the release of the security patch to move funds to newly generated wallets. The episode underscores the operational risks of self-custody and is prompting some holders to re-evaluate the trade-offs versus custodial alternatives such as centralized exchanges or Bitcoin ETFs.