210,000 BTC Exits Long-Term Holder Wallets After Coldcard Breach
Glassnode data shows 210,000 BTC exited long-term holder wallets over the past week, the largest such outflow since December 2024, attributed to the Coldcard firmware breach. Unlike prior LTH distribution waves, this one is happening near cycle lows.

The largest on-chain LTH outflow in over a year is happening near cycle lows, not a top. The data points to custody migration, not capitulation.
Key takeaways
- Glassnode data shows 210,000 BTC left long-term holder wallets in the past week, the largest single-week LTH decline since December 2024, as first reported by CoinDesk, attributed directly to the Coldcard firmware exploit.
- Unlike every prior LTH distribution wave of this magnitude (March 2021, March 2024, December 2024), this one is occurring with bitcoin roughly 50% below its all-time high set in early October 2025 near $126,000, near cycle lows, which points to forced custody migration rather than profit-taking.
- Multisig wallets were unaffected by the exploit, and U.S. spot bitcoin ETFs absorbed approximately $754 million in inflows over the same week, according to SoSoValue data, raising a pointed question about where the migrating coins are landing.
Glassnode data shows approximately 210,000 BTC exited long-term holder (LTH) wallets in the seven days ending August 7, 2026, the largest such outflow since December 2024. LTH supply fell from just under 15 million BTC to approximately 14.7 million BTC. The catalyst is the Coldcard RNG vulnerability: a firmware entropy flaw in Coldcard Mk2 and Mk3 devices running versions 4.0.1 through 4.1.9, disclosed by Coinkite on July 30, 2026, that allowed attackers to reconstruct wallet recovery phrases and drain funds.
What the On-Chain Data Actually Shows
Glassnode classifies long-term holders as entities whose coins have remained dormant for approximately 155 days. This cohort is treated as "smart money" precisely because it holds through short-term volatility. When it moves, the market pays attention.
Previous waves of LTH distribution of this scale coincided with market peaks: March 2021, March 2024, December 2024. Each time, experienced holders were distributing into strength, taking profits as demand absorbed supply. This time is structurally different. Bitcoin is trading around $64,000, roughly 50% below its all-time high set in early October 2025 near $126,000. There is no profit-taking impulse at these prices for coins acquired near the top.
The more plausible read: these coins moved because they had to. The Coinkite security advisory is explicit on this point. "Updating the firmware does not repair a seed that was generated by affected firmware. A new seed must be generated and the funds migrated to the new wallet." Every holder running affected firmware had a binary choice: migrate or remain exposed.
Losses from the exploit range from approximately $89 million and 1,367 BTC across at least 4,585 addresses per Galaxy Research's early analysis, to as high as $116 million per TRM Labs blockchain forensics, with Galaxy Research's own updated tally placing the figure near that level as well. TRM Labs and others attribute the attacks to multiple operators; Galaxy Research's earlier wave-by-wave analysis pointed toward a single sophisticated operator per wave, though by August 4 Galaxy Research was estimating at least 15 separate attackers. The figures conflict; the scale does not. Bitcoin did not make new lows in the aftermath.
Custody Migration vs. Capitulation: Where the Coins Are Going
The distinction matters enormously. An on-chain move from an LTH wallet is not a sale. Coins migrating to a newly generated wallet on patched hardware, or into a multisig setup, never touch an exchange order book. The 14.7 million BTC still classified as LTH supply represents coins that completed their migration and re-aged, or coins that haven't moved yet. The 210,000 BTC in transit is the churn of a community auditing its own security posture under duress.
The uncomfortable secondary signal: some portion of those coins appears to have landed in spot ETFs. U.S. spot bitcoin ETF inflows reached approximately $754 million over the past week, according to SoSoValue data, with BlackRock's IBIT absorbing most of it. Not all of that is Coldcard fallout, but the timing is notable. Every bitcoin that routes into IBIT because a holder lost confidence in hardware self-custody is a bitcoin that left the sovereign stack. BlackRock benefiting from a Coinkite firmware bug is not a headline anyone in this community wanted to write.
The multisig data point cuts the other way. Wallets using multisig setups were entirely unaffected by the exploit. The argument that multisig is the correct threat model for meaningful bitcoin holdings just got its strongest real-world proof. Unchained, Casa, and anyone else in the collaborative custody space should see material inbound interest. Whether that shows up in adoption data over the next 30 days is the signal worth watching.
The falsifiable read on this data: if Glassnode's LTH-to-exchange transfer volume spikes sharply over the next two weeks, or if spot ETF inflows reverse into net outflows, then actual capitulation is in the picture and the custody-migration thesis weakens. If exchange inflows stay muted and multisig adoption accelerates, the conviction held. Watch the on-chain forensics of what moved and where.
What to Watch Now
The patched firmware is live: Mk3 users need version 4.2.0; Mk4/Mk5 need 5.6.0 or later; Q device users need 1.5.0Q or later. The Coinkite advisory is the authoritative source. Firmware update alone is not sufficient. Any seed generated on affected versions must be treated as compromised and migrated immediately. The next two weeks of LTH supply data and exchange flow data will determine whether 210,000 BTC was a one-time security rotation or the beginning of something larger.
Update, August 10, 2026
U.S. spot bitcoin ETFs closed the week with $853.5 million in total net inflows across five consecutive positive sessions: $170.1 million on August 3, $211.5 million on August 4, $244.4 million on August 5, $128.8 million on August 6, and $98.85 million on August 7.
IBIT captured $694 million of that total, over 80% of all bitcoin ETF inflows for the week, as investors concentrated into the two largest funds and largely ignored smaller products.
The run represented a roughly $915 million swing from the prior week, when the products had posted $61.5 million in net outflows.
Bloomberg Intelligence senior ETF analyst Eric Balchunas said in an X post Friday that BlackRock's IBIT, Fidelity's FBTC, and several other funds drew inflows every day since the Coldcard hack, making it "hard not to see causation in the correlation."
In an earlier post, Balchunas said ETFs' reliance on traditional financial institutions to safeguard assets could increasingly be seen as an advantage, writing that what was once considered a "bug" by some crypto users may "all the sudden seem like a feature."
Binance co-founder Changpeng Zhao also weighed in, arguing that storing crypto on centralized exchanges may now be "statistically safer" than self-custody, citing data from analyst Willy Woo that cumulative bitcoin losses from self-custody incidents have surpassed those from exchange hacks.
The causation claim has a genuine wrinkle that deserves honest handling. Nothing in the flow data directly connects the two events. What it shows is that self-custody and regulated custody carry different risk profiles; a failure in hardware wallets may make regulated exposure more appealing to some investors, but that remains an inference, not a demonstrated driver of the flows. Ether ETFs posted their own best week since April over the same five sessions, despite ether holders having no exposure to a bitcoin-only hardware wallet, which complicates the cleanest version of the Coldcard-to-ETF narrative. OKX told The Block that the exploit drove record inflows to centralized exchanges, and research firm K33 measured roughly 890,000 BTC moving on-chain over seven days, a 2026 high, suggesting the migration was broader than the ETF channel alone captures.
Investors had pulled $8.26 billion out of U.S. spot bitcoin ETFs across eight straight weeks through the start of July, and the funds barely recovered any of it over the rest of the month before this week's reversal.
Balchunas wrote that it would be "ironic, but somehow on brand, if the hack of btc in cold storage... marked the beginning of next run." The self-custody community should read the subtext clearly: every time a hardware or software failure makes headlines, the ETF wrapper gains a talking point that no amount of education fully neutralizes. The answer is not to abandon self-custody but to demand and enforce higher standards from hardware manufacturers, which is exactly what the Coldcard disclosure and the migration wave already underway represent.
Update, August 11, 2026
The clearest vindication of multisig is now in the books: Casa and Unchained, both of which run collaborative multisig custody with no single point of failure, reported zero customer losses from the exploit. That is the floor-level proof of concept the self-custody community needed. The architecture worked exactly as designed. No customer who held keys across multiple devices and geographic locations was touched.
Jameson Lopp drew the sharpest conclusion from the wreckage: "If you want to hedge against vendor risks and supply chain risks, the solution is multi-vendor multisig." That is not a new argument, but it now has a nine-figure stress test behind it. The Coldcard entropy flaw was a single-key failure. Multisig by definition requires compromising multiple independent signers, a categorically harder problem for any attacker.
The friction counterargument is real: Tanguma, co-founder of Unchained, acknowledged that setting up concierge multisig "would take weeks and weeks, and people didn't understand it." That is the honest tension the industry has to resolve. The security model is proven. The onboarding path is not yet good enough for the majority of bitcoin holders, and the Coldcard migration wave put that gap on full display.
Update, August 12, 2026
Casa CEO Nick Neuman has put a number on the response and it reframes the entire incident. In an X post on August 9, Neuman cited Checkonchain data showing that in the days after the Coldcard hack, where approximately 2,100 BTC was stolen, 233,000 BTC left long-term holder wallets in on-chain transactions. At current prices that migration represents roughly $15 billion. Neuman's summary: "So somewhere between ~10x-100x the amount of bitcoin stolen was moved to safety as people sounded the alarm."
The migration was not limited to Coldcard users. Casa confirmed through actual customer conversations that some of the 233,000 BTC came from Ledger and Trezor users who upgraded to multisig after watching the hack unfold.
Other flows involved multisig users removing Coldcard devices from their existing keysets. The exploit triggered a broader single-key risk audit across the hardware wallet ecosystem, not just a Coldcard-specific evacuation.
Neuman's structural point is the one worth holding onto. When a centralized exchange gets breached, everything goes at once. Here, the attacker had to crack addresses individually, earning a trickle at a time while the rest of the network had time to respond.
As Neuman wrote, "This is a giant flashing neon sign showcasing the resilience that self-custody adds to the network. If all that BTC was held at a custodian and the custodian was hacked instead, those numbers would have been flipped." The distributed architecture did not fail. It absorbed a live attack, gave holders time to move, and the network cleared it without contagion.
Sources
Frequently Asked Questions
The vulnerability affects Coldcard Mk2 and Mk3 devices that ran firmware versions 4.0.1 through 4.1.9 at any point after March 2021. If your seed was generated on those firmware versions, the seed is potentially compromised regardless of whether you have since updated. The Coinkite advisory details the affected version range and the required remediation steps: generate a new seed on patched firmware and migrate all funds to the new wallet.
No. This was a specific firmware entropy flaw in one manufacturer's product across a defined version range. The self-custody model is not broken. Multisig wallets were entirely unaffected by this exploit. The correct update to the threat model: hardware wallet plus multisig is a meaningfully stronger configuration than a single-sig hardware wallet alone, and seed generation entropy matters at setup. One manufacturer's firmware bug is not an argument for handing coins to an exchange or an ETF custodian.
On-chain movement is not equivalent to selling. The majority of coins that left LTH wallets appear to have migrated to new self-custody wallets or other custody arrangements, not to exchange order books. Coins moving between a holder's own wallets never touch the market. That distinction, plus continued ETF absorption, kept sell-side pressure contained. Bitcoin not making new lows following both a nine-figure theft event and the largest LTH outflow since December 2024 is a data point worth holding onto.


