Original author: Oluwapelumi Adejumo
Original compilation: Saoirse, Foresight News
The Coldcard wallet crisis has severely impacted Bitcoin market sentiment, distorted various on-chain reference metrics, and simultaneously exposed long-standing weaknesses in AI-assisted cybersecurity defense systems.
On July 30, hardware manufacturer Coinkite issued a risk alert to users: wallets generated by specific versions of Coldcard firmware were at risk of asset theft due to a software flaw that caused the random generation of seed phrases to fall far below the design standard.
Galaxy Research stated that this security incident involved three waves of attacks, targeting a total of 4,585 addresses. The amount of Bitcoin stolen was 1,367.05 BTC, with an approximate value of $89 million.

Coldcard Bitcoin Wallet Hacking Incident (Source: Galaxy Research)
Alex Thorn, Global Head of Research at Galaxy, said that the Bitcoin stolen in the three attack waves remains in addresses controlled by the attackers. However, he added that some scattered, small amounts of stolen funds have already been laundered through peel chains, cross-chain services, and overseas casinos.
Coldcard Wallet Migration Disrupts Bitcoin Bearish Signals
As the security risk continued to develop, users with potentially exposed vulnerabilities rushed to transfer their Bitcoin to prevent theft by hackers. Although Coinkite has already released a patched firmware version for affected devices, the high-risk seed phrases previously generated cannot be fixed through system updates. Users could only create new wallets and transfer assets to secure addresses.
This large-scale wallet migration caused an abnormal surge in the on-chain activity of small holders and long-dormant Bitcoin. Julio Moreno, Head of Research at CryptoQuant, explained that on July 31, the total volume of transactions with an output of less than 1 Bitcoin reached 39,600 BTC. This is the single-day highest value for this category since the FTX bankruptcy in November 2022; shortly after the FTX collapse that year, the flow volume for similar transactions was 39,900 BTC.
The daily number of active Bitcoin addresses also surged from about 645,000 on July 30 to nearly 1 million the next day, marking the highest level since December 10, 2024. Moreno noted that the surge in address count was mainly concentrated in sending addresses, with a very limited increase in receiving addresses, which is sufficient to indicate that users were transferring funds out of their original wallets due to security concerns.

Daily Active Bitcoin Addresses (Data Source: CryptoQuant)
Exchange deposits from transactions involving less than 10 Bitcoin rose to 7,300 BTC, hitting a new high since February 6 of that year. Some users temporarily deposited assets into exchanges during the transition period while setting up new secure wallets, although this flow also included chips that investors intended to sell for cash.

Surge in Bitcoin Exchange Deposits After Coldcard Incident (Source: CryptoQuant)
CryptoQuant analyst JA Maartunn added that after the vulnerability was exposed, 77,402 BTC that had been inactive for a long time were transferred. However, Maartunn cautioned that this large-scale movement of funds should not be seen as evidence of widespread panic selling by investors. Considering the context of the event, the nature of the fund movement is essentially users strengthening their wallet security.
He stated: "The Coldcard seed phrase issue has led users to transfer their long-held Bitcoin to ensure asset safety. This will interfere with the accuracy of various chart data such as Long-Term Holder supply changes, Coin Days Destroyed, and Spent Output Age Bands."
With the surge in on-chain transaction activity, overall market sentiment deteriorated sharply. Blockchain analytics firm Santiment pointed out that the ratio of bullish to bearish Bitcoin comments across the entire network fell to its lowest level since the platform began modern social data tracking. On platforms like X, Reddit, and Telegram, for every 1 bearish comment, there were only 0.58 bullish comments.

Bitcoin Market Sentiment Turns Bearish (Source: Santiment)
Santiment believes the reason for such a strong market reaction lies in the fact that the vulnerability attack targeted cold storage wallets. Most holders view cold wallets as the final line of security for their Bitcoin assets after withdrawing from exchanges and distancing themselves from high-risk crypto platforms.
US AI Control Regulations Increase Difficulty in Tracking Coldcard Case
These wallet transfers, which caused the distortion of Bitcoin market signals, also made tracing the stolen funds an urgent task, requiring the flow to be identified before the funds enter platforms where they can be exchanged or withdrawn.
Galaxy Research compiled information reported by victims, collated a series of suspected hacker addresses, and shared the materials with law enforcement, compliance institutions, and other cybersecurity investigators. Thorn revealed that institutions have reported approximately 600 suspected hacker addresses holding stolen Bitcoin.
However, he stated that security guardrails set by major mainstream AI models in the United States have hindered stolen asset tracking and user protection efforts, forcing the investigation team to switch to a Chinese open-source AI model. Thorn did not specify which U.S. AI models were involved, which query commands were blocked, nor did he detail what assistance this alternative model provided for the investigation. Nonetheless, the dilemma he described closely resembles the challenges faced by Hugging Face during a previous cyberattack.
This AI platform stated that automated programs had once infiltrated part of its infrastructure, and the security team needed to analyze over 17,000 event logs. Initially, investigators used commercial APIs to call mainstream leading AI models, uploading attack commands, exploit payloads, and command-and-control-related logs for analysis.
Hugging Face claimed that all these queries were blocked by the system. The reason was that the AI security system could not distinguish between investigators conducting emergency response and actual attackers. Ultimately, the team chose GLM 5.2, an open-source weight model independently developed by China's Zhipu AI, and completed all forensic analysis on their own servers.
This model assisted staff in mapping out the complete attack timeline, locating leaked credentials, extracting intrusion characteristics, and differentiating between real attack traces and decoy interference. Hugging Face stated that forensic work that originally would have taken several days was shortened to a few hours with AI assistance.
This case confirms the offensive-defensive AI asymmetry mentioned by Thorn in the Coldcard case: hackers can use unrestricted, self-modifiable AI tools, free from the security rules of commercial models; meanwhile, defenders often face AI rejections when submitting materials containing malicious characteristics for case investigation, even if the intent is to contain a severe security incident.
However, broadly removing AI security restrictions would create new risks. AI service providers cannot grant permissions based solely on users' verbal claims of tracking stolen funds, as such unrestricted tools could also be abused for wallet attacks, money laundering, evading transaction regulations, and other illegal activities.
This contradiction is particularly acute in the crypto field: stolen assets can circulate through cross-chain bridges, exchanges, and gambling platforms within minutes. Any delay in tracking means funds could be transferred into platforms that allow free withdrawals before victims receive a police report receipt or investigators complete manual tracing, completely losing the opportunity for freezing.





