Economics

210,000 BTC Exits Long-Term Holder Wallets After Coldcard Breach

Glassnode data shows 210,000 BTC exited long-term holder wallets over the past week, the largest such outflow since December 2024, attributed to the Coldcard firmware breach. Unlike prior LTH distribution waves, this one is happening near cycle lows.

5 min read
A weathered metal hardware wallet sits on a scratched wooden desk beside a coiled USB cable, bathed in the cold blue glow of a single monitor in a dim, cluttered home office at night.
Share

The largest on-chain LTH outflow in over a year is happening near cycle lows, not a top. The data points to custody migration, not capitulation.

Key takeaways

  • Glassnode data shows 210,000 BTC left long-term holder wallets in the past week, the largest single-week LTH decline since December 2024, as first reported by CoinDesk, attributed directly to the Coldcard firmware exploit.
  • Unlike every prior LTH distribution wave of this magnitude (March 2021, March 2024, December 2024), this one is occurring with bitcoin roughly 50% below its all-time high set in early October 2025 near $126,000, near cycle lows, which points to forced custody migration rather than profit-taking.
  • Multisig wallets were unaffected by the exploit, and U.S. spot bitcoin ETFs absorbed approximately $754 million in inflows over the same week, according to SoSoValue data, raising a pointed question about where the migrating coins are landing.

Glassnode data shows approximately 210,000 BTC exited long-term holder (LTH) wallets in the seven days ending August 7, 2026, the largest such outflow since December 2024. LTH supply fell from just under 15 million BTC to approximately 14.7 million BTC. The catalyst is the Coldcard RNG vulnerability: a firmware entropy flaw in Coldcard Mk2 and Mk3 devices running versions 4.0.1 through 4.1.9, disclosed by Coinkite on July 30, 2026, that allowed attackers to reconstruct wallet recovery phrases and drain funds.

What the On-Chain Data Actually Shows

Glassnode classifies long-term holders as entities whose coins have remained dormant for approximately 155 days. This cohort is treated as "smart money" precisely because it holds through short-term volatility. When it moves, the market pays attention.

Previous waves of LTH distribution of this scale coincided with market peaks: March 2021, March 2024, December 2024. Each time, experienced holders were distributing into strength, taking profits as demand absorbed supply. This time is structurally different. Bitcoin is trading around $64,000, roughly 50% below its all-time high set in early October 2025 near $126,000. There is no profit-taking impulse at these prices for coins acquired near the top.

The more plausible read: these coins moved because they had to. The Coinkite security advisory is explicit on this point. "Updating the firmware does not repair a seed that was generated by affected firmware. A new seed must be generated and the funds migrated to the new wallet." Every holder running affected firmware had a binary choice: migrate or remain exposed.

Losses from the exploit range from approximately $89 million and 1,367 BTC across at least 4,585 addresses per Galaxy Research's early analysis, to as high as $116 million per TRM Labs blockchain forensics, with Galaxy Research's own updated tally placing the figure near that level as well. TRM Labs and others attribute the attacks to multiple operators; Galaxy Research's earlier wave-by-wave analysis pointed toward a single sophisticated operator per wave, though by August 4 Galaxy Research was estimating at least 15 separate attackers. The figures conflict; the scale does not. Bitcoin did not make new lows in the aftermath.

Custody Migration vs. Capitulation: Where the Coins Are Going

The distinction matters enormously. An on-chain move from an LTH wallet is not a sale. Coins migrating to a newly generated wallet on patched hardware, or into a multisig setup, never touch an exchange order book. The 14.7 million BTC still classified as LTH supply represents coins that completed their migration and re-aged, or coins that haven't moved yet. The 210,000 BTC in transit is the churn of a community auditing its own security posture under duress.

The uncomfortable secondary signal: some portion of those coins appears to have landed in spot ETFs. U.S. spot bitcoin ETF inflows reached approximately $754 million over the past week, according to SoSoValue data, with BlackRock's IBIT absorbing most of it. Not all of that is Coldcard fallout, but the timing is notable. Every bitcoin that routes into IBIT because a holder lost confidence in hardware self-custody is a bitcoin that left the sovereign stack. BlackRock benefiting from a Coinkite firmware bug is not a headline anyone in this community wanted to write.

The multisig data point cuts the other way. Wallets using multisig setups were entirely unaffected by the exploit. The argument that multisig is the correct threat model for meaningful bitcoin holdings just got its strongest real-world proof. Unchained, Casa, and anyone else in the collaborative custody space should see material inbound interest. Whether that shows up in adoption data over the next 30 days is the signal worth watching.

The falsifiable read on this data: if Glassnode's LTH-to-exchange transfer volume spikes sharply over the next two weeks, or if spot ETF inflows reverse into net outflows, then actual capitulation is in the picture and the custody-migration thesis weakens. If exchange inflows stay muted and multisig adoption accelerates, the conviction held. Watch the on-chain forensics of what moved and where.

What to Watch Now

The patched firmware is live: Mk3 users need version 4.2.0; Mk4/Mk5 need 5.6.0 or later; Q device users need 1.5.0Q or later. The Coinkite advisory is the authoritative source. Firmware update alone is not sufficient. Any seed generated on affected versions must be treated as compromised and migrated immediately. The next two weeks of LTH supply data and exchange flow data will determine whether 210,000 BTC was a one-time security rotation or the beginning of something larger.

Sources

Frequently Asked Questions

The vulnerability affects Coldcard Mk2 and Mk3 devices that ran firmware versions 4.0.1 through 4.1.9 at any point after March 2021. If your seed was generated on those firmware versions, the seed is potentially compromised regardless of whether you have since updated. The Coinkite advisory details the affected version range and the required remediation steps: generate a new seed on patched firmware and migrate all funds to the new wallet.

No. This was a specific firmware entropy flaw in one manufacturer's product across a defined version range. The self-custody model is not broken. Multisig wallets were entirely unaffected by this exploit. The correct update to the threat model: hardware wallet plus multisig is a meaningfully stronger configuration than a single-sig hardware wallet alone, and seed generation entropy matters at setup. One manufacturer's firmware bug is not an argument for handing coins to an exchange or an ETF custodian.

On-chain movement is not equivalent to selling. The majority of coins that left LTH wallets appear to have migrated to new self-custody wallets or other custody arrangements, not to exchange order books. Coins moving between a holder's own wallets never touch the market. That distinction, plus continued ETF absorption, kept sell-side pressure contained. Bitcoin not making new lows following both a nine-figure theft event and the largest LTH outflow since December 2024 is a data point worth holding onto.

News and analysis, not financial, investment, legal, or tax advice. Figures and quotes are verified against primary sources where possible. See our editorial and financial disclosures.

Keep reading

All of TFTC

The Bitcoin Brief

Bitcoin, markets, energy, and the tech reshaping all three.

A daily brief on the freedom tech building a parallel economy, written for the curious and the convicted alike. Signal, not noise. Truth for the Commoner.

Free, daily. Unsubscribe anytime.