Bitcoin (BTC) Long-Term Holder Supply Falls 210,000 BTC After Coldcard Breach
BTC/USDT
$10,909,135,247.74
$64,987.26 / $64,166.00
Change: $821.26 (1.28%)
+0.0020%
Longs pay
AI SummaryAI
- The current supply decline is the largest since December 2024, when Bitcoin first approached $100,000.
- U.S. spot Bitcoin ETFs attracted about $754 million in the same week, with BlackRock's iShares Bitcoin Trust receiving most inflows.
- Bitcoin traded near $64,000, roughly 50% below its October all-time high, when the supply shift occurred.
- The address cluster tied to the Coldcard exploit is believed to control 2,055 BTC valued near $130 million.
Bitcoin News
Bitcoin (BTC) has recorded an unusual supply shift after roughly 210,000 BTC exited long-term holder wallets during the past week, according to on-chain data reviewed by COINOTAG. The decline reduces long-term holder supply from almost 15 million BTC to about 14.7 million BTC and marks the largest weekly drop in this cohort since December 2024, when the asset first approached $100,000. Long-term holders are generally defined as wallets that have kept coins dormant for around 155 days, and their behavior is often treated as a signal from experienced investors. That 155-day threshold separates patient capital from short-term trading flows, making any sharp change in this bucket particularly important for supply analysis. The current movement is not aligned with conventional profit-taking because Bitcoin is trading near $64,000, approximately 50% below its October all-time high, a bear-market position relative to prior peaks. Prior heavy distribution episodes appeared around March 2021, March 2024 and December 2024, when prices were strong and mature holders sold into demand. This week's outflow instead coincides with the fallout from the Coldcard security breach, where deficient randomness in affected firmware enabled attackers to rebuild selected recovery phrases and remove funds. The hardware maker's incident guidance urged users to create fresh wallets and move assets, noting that a firmware update alone could not secure already-compromised keys. Our reading of the on-chain flows suggests that part of the reduction may reflect defensive migration into newly generated addresses, regulated custody services or spot Bitcoin exchange-traded funds, rather than direct market sales. Supporting that interpretation, U.S. spot Bitcoin ETFs attracted approximately $754 million during the same week, with BlackRock's iShares Bitcoin Trust accounting for most of the inflows. The market has not pushed Bitcoin to a new post-breach low, which strengthens the view that the dominant event is a custody relocation inside the Bitcoin ecosystem, not a sudden collapse in conviction.
The exploiter tied to the Coldcard vulnerability has broken a multi-week dormancy pattern by sending 30.185 BTC, worth about $1.94 million, into a newly created wallet, based on blockchain records monitored by COINOTAG. The address cluster linked to the attack is believed to control 2,055 BTC, valued near $130 million, making it the largest identified holder of stolen funds from the episode. The latest transfer represents only about 1.5% of that total, but it carries weight because it is the first observed movement since the initial drain and arrives while security researchers continue to watch the suspect wallets. Earlier on-chain reviews identified more than 1,800 BTC moved from over 5,200 affected addresses. The root cause, as detailed in the incident post-mortem, was deficient entropy in certain Coldcard Mk3 firmware versions, which produced seed phrases with less cryptographic randomness than intended and exposed long-term users to key-reconstruction attacks. Coinkite's remediation guidance emphasized generating new wallets and withdrawing funds from vulnerable devices, because patching firmware cannot repair seeds that may already be known to an attacker. The movement may be an early attempt to route value through additional wallets, mixers or cross-chain channels, although no cash-out has been confirmed. One unusual element is that another party publicly offered to help move the stolen funds directly on-chain, a rare development given the wallets are under heavy monitoring. One independent researcher known as ZachXBT has said he is not personally tracking the coins, leaving that work to specialist blockchain-analysis accounts. Investigators also note that the stolen coins remain highly visible on the public ledger, a factor that complicates laundering and may explain why the actor previously kept the funds idle. Canadian users accounted for roughly one-quarter of attributable losses, consistent with the manufacturer's Toronto base and local device circulation. This visibility keeps the case active for forensic trackers and victims seeking recovery options.
COINOTAG's analysis treats these two developments as one custody-security cycle rather than separate market signals. The on-chain record shows 210,000 BTC leaving long-term wallet labels while the suspected attacker moved 30.185 BTC after weeks of dormancy, and the incident post-mortem attributes the root cause to weak firmware randomness, not Bitcoin network failure. The prescribed remediation is migration to fresh wallets or regulated custody, not merely firmware patching. Because the stolen coins remain traceable on the public ledger and Bitcoin has not made a new post-breach low, the near-term issue is operational security and fund tracking, while the broader altcoin market watches whether self-custody trust recovers.
Add COINOTAG as a Preferred Source
Add COINOTAG to your preferred sources in Google News and Search to see our coverage first.
Add on GoogleRelated Tags
AI-generated, AI-reviewed, under COINOTAG editorial oversight.


