Bitcoin Active Addresses Surge to 8-Month High After Coldcard Panic

Blockonomics



Bitcoin active addresses hit their highest daily level since December 2024 after users moved funds from wallets generated with vulnerable Coldcard firmware, seeking alternatives.

Bitcoin (BTC) active addresses reached roughly 0.98 million a day on July 31, the highest daily count since December 2024, after attackers began sweeping wallets whose seeds were generated on defective Coldcard firmware.

Glassnode published the figure on August 6 and called the surge “fear-driven on-chain activity.” The analytics firm stated that “holders migrating seeds and moving funds to alternative custody reflects an operational security response, not a change in market conviction.”

Exchange Balances Climb 22,135 BTC

Coin Metrics recorded 967,546 active addresses that day, 54% above the July average of 627,061. The last higher reading on that series was 985,635 on December 10, 2024.

Bitcoin held on exchanges rose from 2,654,863 on July 29 to 2,676,998 on August 3, a build of 22,135 coins or 0.83%, according to Coin Metrics. The balance eased to 2,667,058 by August 5, leaving roughly 12,200 of those coins on exchanges.

The transaction count moved the other way. The network processed 607,581 transactions on July 31, below the July average of 656,321, while active addresses ran 54% above their monthly average.

Coin Metrics logged 730,433 active addresses on August 5, roughly 16% above the July average and the seventh straight day above it.

Losses Pass $100 Million

Coinkite, the Canadian firm behind Coldcard, disclosed that seeds created on Mk2 and Mk3 firmware version 4.0.1, released in March 2021, through version 4.1.9 carry weakened randomness.

Likewise, seeds generated on Mk4, Mk5, and Q devices before the patched releases hold about 72 bits of entropy against the 128 bits intended. Fixed firmware shipped as version 4.2.0 for Mk2 and Mk3, 5.6.0 for Mk4 and Mk5, and 1.5.0Q for Q.

Something to notice is that seeds built with at least 50 fair, independent, and private dice rolls drew enough entropy from the dice alone, and a strong, unique BIP-39 passphrase forces an attacker to discover the passphrase as well.

Moreover, Coinkite noted that a passphrase “does not repair the affected seed” and told those users to migrate anyway. Installing the patch does not fix a seed already created.

The first sweep took 594.5 BTC across 1,324 UTXOs from about 500 single-signature addresses in four consecutive blocks on July 30. Median loss per victim was 0.41 BTC, and the largest single loss was 29.9 BTC.

Galaxy Research counts 1,596 BTC confirmed stolen from about 7,300 addresses, rising to 2,055 BTC once suspected sweeps are included. As CryptoPotato reported, the confirmed haul passed $100 million last week.

Santiment measured 0.58 bullish comments for every bearish one across social channels, the lowest positive-to-negative ratio since the firm began tracking. Coinkite has told every owner who generated a seed on affected firmware to move funds to a new seed on patched hardware. Bitcoin traded at $64,606 on August 6.





Source link

Blockonomics

Be the first to comment

Leave a Reply

Your email address will not be published.


*