Bitcoin Mempool Spikes to 89,031 After Coldcard Hack
BTC/USDT
$12,961,748,216.37
$64,549.16 / $63,615.38
Change: $933.78 (1.47%)
+0.0046%
Longs pay
AI SummaryAI
- Bitcoin’s mempool reached 89,031 unconfirmed transactions on Tuesday, the highest count since February 2025.
- Active Bitcoin addresses rose to a three-month high of 712,000 during the same period.
- U.S. spot Bitcoin ETFs attracted $170 million Monday and $211.5 million Tuesday, totaling about $382 million.
- BlackRock’s iShares Bitcoin Trust led inflows with $111 million Monday and $170 million Tuesday.
Bitcoin News
Bitcoin (BTC) network activity surged after the July 30 Coldcard wallet theft began, prompting users to reorganize holdings, with unconfirmed transactions in the memory pool reaching 89,031 on Tuesday, the highest count since February 2025, according to blockchain explorer data. The queue of payments awaiting confirmation through ASIC mining rose sharply from late July as holders transferred coins to exchanges and split balances across multiple wallets. Broader usage metrics strengthened at the same time: active addresses climbed to a three-month high of 712,000, while transactions attributed to large holders reached a five-month high of 61,800. Despite that burst of settlement demand, the price stayed contained between $62,000 and $65,000, showing that security concerns did not translate into a clear directional move. Market participants pointed to the Clarity Act as the nearest policy catalyst, noting that the Senate has only a short window before its Aug. 10 recess and that year-end passage odds had slipped to 23% from about 75% in mid-May. Longer-term macro conditions also remained in focus, with one exchange desk warning that a U.S. 10-year real yield above 2.5% could weaken the bullish case; the level stood at 2.41%, nine basis points below that threshold. Bitcoin therefore traded as a high-activity, range-bound network rather than a momentum trade.
U.S. spot Bitcoin exchange-traded funds absorbed fresh capital during the same period, suggesting that some investors responded to the wallet breach by favoring regulated products. Fund-flow data show $170 million in net subscriptions on Monday followed by $211.5 million on Tuesday, a two-day total near $382 million. BlackRock’s iShares Bitcoin Trust led the rebound with $111 million Monday and another $170 million Tuesday, while Fidelity’s Wise Origin Bitcoin Fund added about $33 million and $20 million across the same sessions. Invesco Galaxy’s Bitcoin fund recorded $6.7 million on Monday, its first positive daily flow since July 1 and roughly 3.9% of its $172 million cumulative net inflow. Galaxy Research estimated that the Coldcard incident may have touched as many as 7,300 addresses, with suspected losses near $130 million, a figure that sharpened the custody discussion. ETF analysts argued that professional safekeeping, once criticized by self-custody advocates, could become a selling point when users compare regulated financial custodians with smaller hardware or software providers. The market reaction remained measured: Bitcoin traded near $64,113 when the latest custody debate intensified, down about 0.8% over seven days after dipping below $62,500, while a separate 1,638 BTC sale by Michael Saylor’s Strategy added another supply consideration. Public ledger tracking, however, may limit the attacker’s ability to liquidate large amounts unnoticed.
The technical timeline of the Coldcard incident points to a software flaw in certain 2021 firmware versions rather than a physical compromise of devices. According to technical analyses and incident reviews, the wallet’s random-number generation could fall back to a more predictable software path under specific conditions, producing recovery phrases drawn from a narrower set of possibilities than expected. Attackers apparently precomputed likely seed combinations, identified funded single-signature addresses on the public ledger, and drained them in rapid waves. The first wave moved about 594 BTC from roughly 500 single-signature wallets in around 25 minutes, and later waves expanded the scope. Verified losses exceeded 1,596 BTC, while suspicious transactions lifted the potential total to 2,055 BTC, worth roughly $130 million at current market prices. Researchers said multiple attackers appeared to exploit the weakness once it became known. Coinkite, the hardware maker, warned that updating firmware alone does not neutralize an already-generated vulnerable seed; users must create a fresh seed on updated equipment and transfer funds, because moving an old seed to another device preserves the exposure. Chief Executive Rodolfo Novak apologized and said the company is working with blockchain-analytics firms and law enforcement. On-chain records indicate much of the stolen Bitcoin remains parked in attacker-controlled addresses, leaving the next movement as the key forensic signal.
COINOTAG’s analysis ties these developments to a custody repricing rather than a simple bear-market signal. The mempool spike, ETF subscriptions and attacker address activity all point to users re-examining where private keys live. On-chain evidence is decisive: public transaction hashes and address balances make the drained amounts verifiable, while much of the suspected theft remains unspent. The root cause, as described in the vendor’s incident guidance, was weak seed generation in affected firmware, and the stated remediation is not a patch alone but a newly generated seed and full fund migration. Until those funds move, the incident is both a security post-mortem and a live stress test for institutional custody versus self-sovereignty.
Add COINOTAG as a Preferred Source
Add COINOTAG to your preferred sources in Google News and Search to see our coverage first.
Add on GoogleRelated Tags
AI-generated, AI-reviewed, under COINOTAG editorial oversight.


