Bitcoin wallets spike to 2026 high after Coldcard exploit
Bitcoin recorded 2.27 million new wallets and about 751,000 active addresses this week after a Coldcard firmware flaw allowed attackers to drain over $116 million.
Bitcoin recorded 2.27 million new wallets and about 751,000 active addresses this week, the strongest onchain activity in months, after a Coldcard firmware flaw allowed attackers to brute-force seed phrases and drain more than $116 million.
Onchain analytics showed active addresses peaking near 978,000 on July 31 before settling around 751,000 per day through the first week of August, compared with a July daily average near 610,000. New wallet creation totaled 2.27 million over the same period. Daily exchange inflows averaged about $1.55 billion during the stretch, versus a July average of $1.67 billion.
The flaw appeared in firmware released in March 2021 in builds labeled 4.0.1 through 4.1.9. Vulnerable devices routed seed-phrase generation through a software random-number generator instead of the device’s hardware entropy chip. On the most affected Mk3 units the resulting seed phrases had roughly 40 bits of real randomness; later models produced about 72 bits instead of the intended 128 bits.
Affected models include Mk3, Mk4, Mk5 and Q devices running the vulnerable firmware. Attackers used brute-force methods to derive private keys and empty wallets. Tracking data shows losses exceeded $116 million and that thefts continued in multiple waves in the days after the vulnerability was disclosed.
Following the disclosure, many custodians created new wallets on unaffected devices and swept funds into fresh addresses. The device maker published a firmware update and a technical disclosure describing the entropy issue and the fix. Independent security researchers launched emergency audits; one rapid review identified nearly 5,000 separate vulnerabilities across hundreds of bitcoin-related projects within a short testing window.
Geographic analysis of victim addresses found Canadian users accounted for roughly a quarter of the recorded losses. The vulnerability affected how one manufacturer’s firmware generated randomness, not the bitcoin protocol itself.
Hardware wallets generate seed phrases that back private keys. Proper seed generation uses high-entropy sources, typically a hardware entropy chip, to produce unpredictable values. When software substitutes for hardware entropy or produces fewer bits of randomness, seed phrases can be more feasible to brute-force.
The material on GNcrypto is intended solely for informational use and must not be regarded as financial advice. We make every effort to keep the content accurate and current, but we cannot warrant its precision, completeness, or reliability. GNcrypto does not take responsibility for any mistakes, omissions, or financial losses resulting from reliance on this information. Any actions you take based on this content are done at your own risk. Always conduct independent research and seek guidance from a qualified specialist. For further details, please review our Terms, Privacy Policy and Disclaimers.








