Bitcoin (BTC) Coldcard Sweep Losses Reach 1,367 BTC

BTC

BTC/USDT

$62,900.01
-0.07%
24h Volume

$5,632,051,706.04

24h H/L

$63,150.00 / $62,275.00

Change: $875.00 (1.41%)

Long/Short
69.3%
Long: 69.3%Short: 30.7%
Funding Rate

+0.0029%

Longs pay

Data provided by COINOTAG DATALive data
Bitcoin
Bitcoin
Daily

$62,822.01

-0.10%

Volume (24h): -

Resistance Levels
Resistance 3$66,502.95
Resistance 2$64,155.50
Resistance 1$63,160.85
Price$62,822.01
Support 1$61,842.45
Support 2$58,822.51
Support 3$50,986.64
Pivot (PP):$63,587.81
Trend:Downtrend
RSI (14):43.9
(11:04 PM UTC)
4 min read
AI SummaryAI
  • The largest July 30 movement drained roughly 1,082.65 BTC from 1,195 addresses in about 41 minutes.
  • A third phase moved about 208 BTC across 1,912 addresses from Friday midday through Saturday morning UTC.
  • Exchange net inflows reached 11,163 BTC on July 31, with River receiving about 3,679 BTC.
  • Dormant wallets created between 2010 and 2017 moved roughly 306 BTC from July 30 to August 1.

This summary was AI-generated, AI-reviewed and published under COINOTAG editorial oversight.

Bitcoin News

Bitcoin (BTC) wallets generated by a vulnerable Coldcard firmware build have lost about 1,367 BTC across three suspected sweeping campaigns, according to on-chain data reviewed by COINOTAG, with the coins valued near $88.6 million when the latest transfers were recorded. The largest movement occurred on July 30, when roughly 1,082.65 BTC left 1,195 addresses in about 41 minutes. A second cluster on July 31 drew 76.16 BTC from 1,478 addresses, and a third phase running into August 1 moved about 208 BTC from 1,912 addresses. The affected addresses had a median idle period of about 3.5 years, consistent with long-term cold storage, and all traced back to keys created after the March 17, 2021 firmware release that allegedly used a predictable software randomizer rather than hardware entropy. Blockchain records also show a separate surge in exchange deposits on July 31, with net inflows of 11,163 BTC to centralized platforms. River received about 3,679 BTC, Binance about 3,224 BTC, Kraken about 2,848 BTC, and OKX about 1,291 BTC. Those flows may reflect routine custody moves, client deposits, or holders reassessing self-custody arrangements after the security incident, but they do not prove a direct link to the swept wallets. On-chain monitors are tracking seven collector addresses from the first two phases and 293 separate wallets from the third, because first outgoing spends could reveal shared signing keys or common script structures. A third signal came from dormant coins created between 2010 and 2017, which moved roughly 306 BTC from July 30 to August 1. Some of those wallets predate Coldcard, so the activity cannot be automatically tied to the exploit. The incident is isolated to BTC, not an altcoin network. Still, when old Bitcoin balances awaken during a bear market, traders often watch for potential selling pressure. Our desk is treating the theft attribution as confirmed only where blockchain data directly supports it, while the broader deposit and dormant-wallet signals remain circumstantial.

The newest phase of the Coldcard-related operation shows a different collection pattern, suggesting the actor adapted after the initial sweeps were publicly mapped. On-chain records indicate the third wave moved about 208 BTC across 1,912 addresses from Friday midday through Saturday morning UTC, producing an average loss just above 0.1 BTC per victim. That contrasts with the opening wave, which drained nearly 1 BTC per address on average and processed victims one at a time. The latest transactions also batched about six victims per sweep and sent funds to separate pay-to-witness-script-hash outputs, a Bitcoin script format that can conceal spending conditions until the coins are later moved. Instead of testing multiple derivation branches, the activity focused on the default derivation path, the standard key route a wallet checks first. The suspected vulnerability stems from a March 2021 firmware build that allegedly routed seed generation through a software randomizer rather than the secure element’s hardware randomness. That would leave a bounded set of possible keys that can be reproduced offline, without physical access to the device, if the attacker has enough compute and the disclosed weakness. The falling average take implies the most valuable part of the vulnerable key space has already been swept. Blockchain observers cannot yet determine whether one operator rebuilt its tooling after exposure or whether a second actor independently found the same weak-address pool. What is clear is that the third wave’s use of individualized P2WSH vaults makes clustering harder, because each destination can carry its own multisignature or timelock rules. For Bitcoin self-custody users, the episode underscores the importance of firmware provenance, verifiable randomness, and post-deposit monitoring. It also shows why even a mature network can face legacy operational risk long after an all-time high cycle, especially when older wallets remain unmaintained. No affected coins were generated before the vulnerable release, which narrows the forensic scope but does not reduce the immediate loss.

COINOTAG’s proprietary 42-indicator composite S/R scoring engine rates Bitcoin’s nearest support at $62,849.47 at 84/100, driven by Ichimoku Senkou A and Donchian Lower. The $61,081.26 shelf scores 72/100 from Keltner Lower and Fibonacci 0.114. Resistance starts at $63,160.85, a 71/100 zone tied to SMA 50 and Pivot Point, then $66,503.03 at 76/100 with Keltner Upper and Bollinger Upper. Spot is $62,848, down 0.17%, with RSI 44.02 and bearish MACD. Funding is 0.0030%, open interest $12.71 billion, and the long/short account ratio 2.23, showing crowded longs while Fear and Greed reads 27. A close above $63,161 could stabilize; losing $61,081 confirms bearish continuation.

COINOTAG does not provide financial advisory services. This content is for informational purposes only and should not be considered investment advice. Cryptocurrency investments involve high risk.

Add COINOTAG as a Preferred Source

Add COINOTAG to your preferred sources in Google News and Search to see our coverage first.

Add on Google
Sarah Chen

Sarah Chen

COINOTAG author

View all posts
AI-AssistedMarket Analyst·Sarah Chen is a market analyst specializing in technical analysis and risk management for cryptocurrency markets, with five years of active trading desk experience.

AI-generated, AI-reviewed, under COINOTAG editorial oversight.

Comments

Comments