According to K33 research head Vetle Lunde and on-chain data, a Coldcard hardware wallet firmware vulnerability has triggered transfers of approximately 890,000 BTC over the past 7 days, with the 7-day active supply surging 98% from 403,101.95 BTC on July 28 to 797,407.72 BTC on August 4.
The vulnerability stems from a 2021 Coinkite firmware flaw that could generate insufficiently random wallet seeds. Since July 30, coordinated transfers have moved approximately 1,596 to 2,000 stolen BTC, valued at over $100 million, across 7,300 affected addresses. Exchange net inflows reached 22,052 BTC following the incident.