Bitcoin (BTC) Long-Term Holder Supply Falls 210,000 BTC After Coldcard Breach

Long-term Bitcoin supply fell about 210,000 BTC after the Coldcard breach prompted custody migration, while the linked attacker moved 30.185 BTC.

(09:53 AM UTC)
6 min read
Updated
AI SummaryAI
  • The current supply decline is the largest since December 2024, when Bitcoin first approached $100,000.
  • U.S. spot Bitcoin ETFs attracted about $754 million in the same week, with BlackRock's iShares Bitcoin Trust receiving most inflows.
  • Bitcoin traded near $64,000, roughly 50% below its October all-time high, when the supply shift occurred.
  • The address cluster tied to the Coldcard exploit is believed to control 2,055 BTC valued near $130 million.
k7rq2fdm

Bitcoin (BTC) has recorded an unusual supply shift after roughly 210,000 BTC exited long-term holder wallets during the past week, according to on-chain data reviewed by COINOTAG. The decline reduces long-term holder supply from almost 15 million BTC to about 14.7 million BTC and marks the largest weekly drop in this cohort since December 2024, when the asset first approached $100,000. Long-term holders are generally defined as wallets that have kept coins dormant for around 155 days, and their behavior is often treated as a signal from experienced investors. That 155-day threshold separates patient capital from short-term trading flows, making any sharp change in this bucket particularly important for supply analysis. The current movement is not aligned with conventional profit-taking because Bitcoin is trading near $64,000, approximately 50% below its October all-time high, a bear-market position relative to prior peaks. Prior heavy distribution episodes appeared around March 2021, March 2024 and December 2024, when prices were strong and mature holders sold into demand. This week's outflow instead coincides with the fallout from the Coldcard security breach, where deficient randomness in affected firmware enabled attackers to rebuild selected recovery phrases and remove funds. The hardware maker's incident guidance urged users to create fresh wallets and move assets, noting that a firmware update alone could not secure already-compromised keys. Our reading of the on-chain flows suggests that part of the reduction may reflect defensive migration into newly generated addresses, regulated custody services or spot Bitcoin exchange-traded funds, rather than direct market sales. Supporting that interpretation, U.S. spot Bitcoin ETFs attracted approximately $754 million during the same week, with BlackRock's iShares Bitcoin Trust accounting for most of the inflows. The market has not pushed Bitcoin to a new post-breach low, which strengthens the view that the dominant event is a custody relocation inside the Bitcoin ecosystem, not a sudden collapse in conviction.

The exploiter tied to the Coldcard vulnerability has broken a multi-week dormancy pattern by sending 30.185 BTC, worth about $1.94 million, into a newly created wallet, based on blockchain records monitored by COINOTAG. The address cluster linked to the attack is believed to control 2,055 BTC, valued near $130 million, making it the largest identified holder of stolen funds from the episode. The latest transfer represents only about 1.5% of that total, but it carries weight because it is the first observed movement since the initial drain and arrives while security researchers continue to watch the suspect wallets. Earlier on-chain reviews identified more than 1,800 BTC moved from over 5,200 affected addresses. The root cause, as detailed in the incident post-mortem, was deficient entropy in certain Coldcard Mk3 firmware versions, which produced seed phrases with less cryptographic randomness than intended and exposed long-term users to key-reconstruction attacks. Coinkite's remediation guidance emphasized generating new wallets and withdrawing funds from vulnerable devices, because patching firmware cannot repair seeds that may already be known to an attacker. The movement may be an early attempt to route value through additional wallets, mixers or cross-chain channels, although no cash-out has been confirmed. One unusual element is that another party publicly offered to help move the stolen funds directly on-chain, a rare development given the wallets are under heavy monitoring. One independent researcher known as ZachXBT has said he is not personally tracking the coins, leaving that work to specialist blockchain-analysis accounts. Investigators also note that the stolen coins remain highly visible on the public ledger, a factor that complicates laundering and may explain why the actor previously kept the funds idle. Canadian users accounted for roughly one-quarter of attributable losses, consistent with the manufacturer's Toronto base and local device circulation. This visibility keeps the case active for forensic trackers and victims seeking recovery options.

Glassnode's weekly report quantifies the forced migration more precisely, revealing that approximately 119,000 BTC dormant for at least one year were moved within three days of the July 31 exploit—a volume roughly 200 times the 594 BTC directly stolen. Only about one-tenth of those revived coins reached exchanges, with the vast majority transferred into freshly generated cold-storage addresses. Bitcoin supply held by wallets younger than one month surged 40% after the event and has continued rising, while Glassnode noted that spot markets showed no measurable sell pressure. Daily active addresses simultaneously climbed to 980,000, the highest reading since December 2024, confirming that the dominant on-chain signature is defensive relocation rather than distribution.

Coinkite co-founder Rodolfo Novak, known as NVK, has been selectively deleting posts from his X account as the exploit continues, according to screenshots preserved by community members. Bitcoin developer Peter Todd published a cached copy of one removed post in which NVK had initially told users there was no need to panic—a statement Novak later conceded contained wrong information. Critics also allege that Coinkite removed an entry labeled "Unnamed v.4.0.0 security issue" from its historical-disclosures webpage, though the absence of an archived snapshot makes independent verification difficult. A volunteer effort to catalog the deletions is underway. Notably, a 2021 Coldcard post declaring the device makes "retirement attacks impossible"—defined at the time as a scenario where project makers embed an entropy bug for later retrieval—remains publicly visible, underscoring the gap between prior marketing claims and the current reality.

Galaxy Research published a detailed victim-profile analysis on August 7, drawing on 250 individual reports compiled by community researcher @intangiblecoins, revealing that the typical stolen coin had remained untouched for 3.5 years and that 88% of the pilfered funds had been dormant for a minimum of one year. Per-victim losses showed a median of 1.022 BTC and an average of 4.04 BTC, while the largest single claim reached 58.97 coins. The firm also identified more than 25 distinct attack patterns across three confirmed waves, indicating that multiple independent threat actors are exploiting the same firmware flaw rather than a single coordinated group. Galaxy Research confirmed it has provided attacker and victim address data to U.S. law enforcement, regulated exchanges, and cyber-investigation bodies to support ongoing recovery efforts.

(as of 13:30 UTC) COINOTAG's analysis treats these two developments as one custody-security cycle rather than separate market signals. The on-chain record shows 210,000 BTC leaving long-term wallet labels while the suspected attacker moved 30.185 BTC after weeks of dormancy, and the incident post-mortem attributes the root cause to weak firmware randomness, not Bitcoin network failure. The prescribed remediation is migration to fresh wallets or regulated custody, not merely firmware patching. Because the stolen coins remain traceable on the public ledger and Bitcoin has not made a new post-breach low, the near-term issue is operational security and fund tracking, while the broader altcoin market watches whether self-custody trust recovers.

COINOTAG News Desk

COINOTAG News Desk

COINOTAG's editorial and research desk.

How our News Desk works
AI-Assisted

AI-generated, AI-reviewed, under COINOTAG editorial oversight.