This week, Santiment published network data, noting that 751,000 active wallets and 2.27 million newly created wallets indicate the highest Bitcoin network activity in recent months. The number of active addresses peaked at around 978,000 on July 31st, approximately 1.6 times the July daily average, before stabilizing during the first week of August at a still-high level of around 751,000 per day—compared to the July average of close to 610,000.

The distinction of this surge from a typical bull-market address boom lies in what's missing: purchases. Exchange inflows during the same period averaged about $1.55 billion per day, essentially slightly below July's average of $1.67 billion. The number of wallets is growing, coins are moving within them, but money is not flowing onto exchanges for trading. This divergence points to a defensive stance among market participants.
Inside the Coldcard Vulnerability
The root cause lies in the Coldcard hardware wallets by Coinkite, where a firmware bug (first appearing in the March 2021 build for versions 4.0.1 through 4.1.9) led to seed phrase generation on affected Mk3 devices being handled by a software random number generator instead of the device's dedicated hardware entropy chip.
What was supposed to be a 128-bit cryptographic key turned out, on the most affected devices, to have about 40 bits of real randomness, and on some later models around 72 bits. Bitcoin.com News is tracking the scale of the damage: losses have exceeded $116 million, and a fourth wave of thefts continues to drain wallets even days after the initial disclosure.
What the Data Really Shows
When news spread that seeds for certain Coldcard Mk3, Mk4, Mk5, and Q devices running vulnerable firmware could be brute-forced, security-conscious owners had every reason to create new wallets on unaffected hardware, move their coins to new addresses, and abandon any configurations that might harbor the same weak-entropy vulnerability.
This behavior alone could explain the spike in new and active wallets combined with the lack of expected exchange inflows.
Since then, Coinkite has released a firmware patch and published a post-mortem on fixing the entropy issue, detailing how much random data the vulnerable devices were actually generating. Independent security researchers have also joined the effort: one emergency audit found nearly 5,000 separate vulnerabilities across hundreds of Bitcoin-related projects in just over a day of testing.
This Is Not a Protocol-Level Issue
Experts are keen to draw a clear distinction between this incident and a vulnerability in Bitcoin itself. The vulnerability was solely in how one manufacturer's firmware generated random data for seed phrases—a self-custody supply chain failure, not a blockchain problem.
Geographic data added another layer of complexity: researchers tracking victim wallets found that Canadian users account for roughly a quarter of the losses linked to this vulnerability, likely reflecting Coinkite's Canadian base and the concentration of early customers in that country.
Coupled with reports that this vulnerability briefly amplified market anxiety over unrelated Bitcoin fork proposals circulating at the same time, this episode serves as a vivid example of how a narrow, fixable firmware bug can still ripple through key blockchain metrics, extending its impact beyond the number of affected devices.
end-content







