The Coldcard wallet crisis has severely impacted the Bitcoin market sentiment, distorted on-chain metrics, and exposed a long-standing weakness in AI-assisted network defense systems.
On July 30, hardware manufacturer Coinkite issued a risk advisory to users: wallets generated under a specific version of the Coldcard firmware were at risk of asset theft due to a software bug that significantly reduced the entropy of the mnemonic seed generation.
Galaxy Research stated that this security incident experienced three waves of attacks, with a total of 4585 addresses being targeted, resulting in the theft of 1367.05 bitcoins, equivalent to approximately $89 million.
Alex Thorn, Director of Galaxy Global Research, mentioned that the stolen bitcoins from the three waves of attacks remain in addresses controlled by the attackers. However, he added that some scattered small amounts of stolen funds have been laundered through peel chains, cross-chain services, and overseas casinos.
Coldcard Wallet Migration Disrupts Bitcoin Bearish Signals
As the security risk continues to escalate, users with exposed vulnerabilities have been rushing to migrate their bitcoins to prevent asset theft by hackers. While Coinkite has released patched firmware for affected models, mnemonic seeds generated prior to this fix cannot be recovered through a system update. Users must create a new wallet and transfer their assets to a secure address.
This large-scale wallet migration has led to an abnormal surge in on-chain activity for small holders and long-term dormant bitcoins. Julio Moreno, Director of Research at CryptoQuant, explained that on July 31, transactions involving less than 1 bitcoin each reached a total of 39,600 bitcoins. This marked the highest daily volume for this category of transactions since the collapse of FTX in November 2022. In the aftermath of the FTX debacle that year, a similar transaction volume of 39,900 bitcoins was recorded.
The number of Bitcoin daily active addresses also surged from around 645,000 on July 30 to nearly 1 million the next day, reaching its peak since December 10, 2024. Moreno stated that the surge in address numbers was mainly concentrated in sending addresses, with a very limited increase in receiving addresses, indicating that users were transferring funds from their existing wallets out of a hedge demand.

The Binance deposit amount for single transfers below 10 bitcoins rose to 7,300 bitcoins, hitting a new high since February 6 of that year. Some users, in the transition period of setting up a new secure wallet, temporarily deposited assets into the trading platform. Of course, this fund inflow also includes chips from investors preparing to sell off and cash out.

CryptoQuant analyst JA Maartunn added that after the vulnerability was exposed, 77,402 bitcoins that had been dormant for a long time were transferred. However, Maartunn warned against interpreting this large-scale fund movement as evidence of significant investor panic selling. Considering the context of the event, the nature of the fund movement is for users to strengthen wallet security.
He said, "The Coldcard mnemonic issue caused users to transfer long-held bitcoins to secure their assets. This will disrupt various chart data accuracy, including changes in long-term holder supply, coin-days destroyed, spending output distribution, etc."
Alongside the significant increase in on-chain transaction activity, overall market sentiment sharply weakened. Blockchain analytics firm Santiment pointed out that the ratio of bullish comments to bearish comments on Bitcoin across the entire network dropped to the lowest level since the platform launched modern social data tracking. On platforms like X, Reddit, Telegram, etc., for every 1 bearish comment, there are only 0.58 bullish comments.

Santiment believes that the market's strong reaction is due to the fact that this particular hack targeted a cold storage wallet. Most holders consider cold wallets to be the final security line for their Bitcoin assets, used when withdrawing from exchanges and staying away from high-risk crypto platforms.
US AI Governance Rules Increase Coldcard Case Investigation Difficulty
The series of wallet transfers that caused turmoil in the Bitcoin market also made it urgent to trace the stolen funds before they could be exchanged or cashed out. Galaxy Research compiled information reported by victims, identified a set of suspected hacker addresses, and shared the data with law enforcement, compliance agencies, and other cybersecurity researchers. Thorn revealed that the organization has reported approximately 600 suspected hacker addresses holding the stolen bitcoins.
However, Thorn mentioned that the security barriers set by major mainstream US models have restricted the tracking of stolen assets and user protection efforts. As a result, the investigation team had to resort to a Chinese open-source AI model. Thorn did not specify which US AI models were involved, which query commands were blocked, or how exactly this alternative model assisted in the investigation. Nevertheless, the dilemma he described closely resembled the challenges faced by Hugging Face during a previous cyberattack.
The AI platform stated that automated processes had infiltrated some of its infrastructure, requiring the security team to analyze over 17,000 event records. Initially, investigators invoked mainstream cutting-edge models through commercial APIs and uploaded attack commands, exploit payloads, and C&C-related logs for analysis.
Hugging Face reported that all these queries were blocked by the system. The reason was that the AI security system could not distinguish between investigators conducting emergency response and actual attackers. Eventually, the team opted to use their in-house developed open-source weighted model GLM 5.2 through the Smart Spectrum AI, completing all forensic analyses on their own servers.
This model helped the staff to create a complete attack timeline, identify leaked credentials, extract intrusion features, and differentiate between real attack traces and decoy disruptive behaviors. Hugging Face stated that what would have taken several days for forensic work was reduced to just a few hours with AI assistance.
This case confirmed the AI defense asymmetry issue mentioned by Thorn in the Coldcard incident: hackers can leverage unrestricted, self-modifiable AI tools without the constraints of commercial model security rules, while the defense side often faces AI rejection when submitting data with malicious features for investigation into security incidents, even if the intention was to control malicious security events.
However, if AI security restrictions are widely lifted, it will create new risks. AI service providers cannot simply relax permissions based on a user's verbal claim to track stolen assets. Such unrestricted tools can also be abused for wallet attacks, money laundering, circumventing transaction monitoring, and other illegal activities.
Within the cryptocurrency space, this contradiction is particularly acute: stolen assets can be transferred within minutes using cross-chain bridges, exchanges, or gambling platforms. If there is a delay in tracking, the funds can be moved to a platform where they can be freely withdrawn before the victim receives a case report receipt and investigators complete manual tracing, permanently losing the opportunity to freeze the assets.
Welcome to join the official BlockBeats community:
Telegram Subscription Group: https://t.me/theblockbeats
Telegram Discussion Group: https://t.me/BlockBeats_App
Official Twitter Account: https://twitter.com/BlockBeatsAsia
