Bitcoin logged 2.27 million new wallets and 751,000 active wallets this week, its strongest onchain activity in months, as holders raced to move funds off Coldcard hardware wallets following a firmware exploit that has drained more than $116 million.
Key Takeaways
Bitcoin logged 2.27 million new wallets and 751,000 active wallets, its strongest reading in months.The spike follows a Coldcard firmware flaw that has drained more than $116 million in BTC since July 30.Exchange inflows stayed below July’s average, suggesting security moves rather than a selling wave.What makes this spike different from a typical bull-market address boom is what’s missing, i.e. buying. Exchange inflows over the same stretch averaged about $1.55 billion daily, actually slightly below July’s $1.67 billion average. Wallets are multiplying and moving coins, but the money isn’t piling into exchanges to trade. That divergence suggests defensive behavior.
Inside the Coldcard FlawThe trigger traces back to Coinkite’s Coldcard hardware wallets, where a firmware bug (first introduced in a March 2021 build across versions 4.0.1 through 4.1.9) routed seed-phrase generation through a software random-number generator instead of the device’s dedicated hardware entropy chip on affected Mk3 units.
As word spread that certain Coldcard Mk3, Mk4, Mk5 and Q devices running vulnerable firmware could have their seeds brute-forced, security-conscious holders had every reason to generate new wallets on unaffected hardware, sweep their coins to fresh addresses, and rotate away from any setup that might share the same weak-entropy flaw.
That behavior alone can explain the spike in new and active wallets, paired with exchange inflows that never followed.
Not a Protocol-Level Problem


















