Coldcard’s $89M wallet bug triggers the biggest Bitcoin movement since FTX and completely distorts market signals
Coinkite’s Coldcard firmware flaw created weak seed phrases, exposing users to wallet theft and triggering an estimated 1,367.05 BTC drained across three suspected attack waves from 4,585 addresses, worth about $89 million. Because affected seeds cannot be fixed by firmware, users have been rushing to create new wallets and move funds, driving unusual Bitcoin activity: small-balance transfers hit their highest level since 2022, daily active addresses neared 1 million, and older coins moved sharply. Exchange deposits also rose, though much of the flow appears defensive rather than capitulation. Sentiment turned sharply negative as the breach hit cold storage, long seen as Bitcoin’s safest defense. Galaxy Research traced stolen funds and shared findings with law enforcement, but said AI safety limits on commercial U.S. models hindered tracing, forcing use of an open-source Chinese model. The episode shows how AI guardrails can impede defenders during active crypto thefts.
