Community Trust ScoreVerified
A firmware flaw. Two thousand bitcoins stolen. Over a hundred million dollars gone.
Since the end of July, Coldcard holders have been doing something not seen on this scale since the collapse of FTX in November 2022: they are massively moving their BTC back to centralized platforms. Not because they want to sell, not really. Rather, because they are afraid. The vulnerability identified in Coldcard’s firmware — a flaw dating back to March 2021 — exposed the private keys of many users. The result: a massive theft, widespread panic, and a sudden reversal of behaviors thought to be entrenched for two years.
39,600 Bitcoins Move in Seven Days
The numbers are clear. Between July 28 and August 3, the total reserves of bitcoins on centralized platforms increased from 2.701 million to 2.719 million BTC. This represents about 18,000 additional bitcoins stored on exchanges in the span of a week. But the most striking figure is that of the directly affected Coldcard clients: over 39,600 bitcoins moved during this period.
To give an idea of the scale, it’s almost identical to the 39,900 bitcoins transferred during the FTX crash. Almost to the tenth. It’s unsettling.
Binance captured a significant share of these flows. Its BTC reserves increased from 650,000 to 659,000 bitcoins over the same period — a rise of 9,000 BTC in just a few days, which is substantial for a platform of its size. Binance is clearly benefiting from the uncertainty surrounding Coldcard, even though the platform has made no public statement on the matter. No details on other exchanges that absorbed these flows.
A Sudden Reversal of Post-FTX Habits
This is where it gets really interesting — and a bit ironic.
After FTX, the dominant movement in the crypto market was exactly the opposite: fleeing centralized platforms, taking control of one’s private keys, “not your keys, not your coins.” Sales of hardware wallets had exploded. Coldcard, Ledger, Trezor — everyone wanted self-custody. The idea that entrusting one’s BTC to an exchange was fundamentally risky had become almost dogmatic in the community.
And then, in just a few days, a technical incident calls all that into question.
Holders of small amounts of bitcoins reacted particularly quickly. This behavior — small holders moving first — is exactly what was observed during the FTX crisis. Large wallets tend to wait, to analyze. The small ones, they act on reflex. Not always the wrong reflex, by the way.
What is less clear is the intention behind these transfers. Some of these 39,600 bitcoins likely went to new wallets rather than exchanges. The source does not specify the exact distribution. Some users may have just migrated to another hardware wallet or another self-custody solution deemed safer. But the visible increase in reserves on centralized platforms shows that a significant fraction did return to the exchanges.
No details either on how many Coldcard users are actually affected by the firmware flaw. The 2,000 bitcoins stolen — over $100 million — represent the confirmed losses, but the flaw itself, dating from March 2021, could have exposed many more wallets without the thefts being detected or reported yet.
Trust in Self-Custody Takes a Hit
This is the real long-term problem for the hardware wallet industry.
Self-custody is the number one argument against centralized platforms. You control your keys, you control your coins. But that assumes the hardware and firmware are reliable. That there isn’t a dormant flaw for three years in the code running on your device. The Coldcard incident shows that this assumption is not guaranteed.
And users know it now. Despite advice to update private keys, despite technical recommendations circulating since the announcement of the flaw, many prefer not to take the risk. They prefer the perceived security of an exchange — with all the risks that entails, counterparty, potential hack, fund freeze — rather than trusting firmware whose integrity they cannot verify themselves.
It’s a real shift in psychology. Not necessarily 100% rational, but human.
Blockchain activity has significantly increased since the announcement of the flaw. Fund movements have been rapid, sometimes frantic. Transaction fees have likely followed, although the source does not provide precise figures on this.
What is certain is that Coldcard will have to do a lot of work to regain the trust of its user base. And other hardware wallet providers are watching this very closely — because if a firmware flaw can cause an exodus of this magnitude, the entire sector has a perception problem to manage. Binance, meanwhile, has 9,000 more bitcoins in its reserves.
Frequently Asked Questions
What flaw affected Coldcard and when was it introduced?
The flaw is in Coldcard’s firmware and dates back to March 2021. It made users’ private keys vulnerable, allowing the theft of 2,000 bitcoins, worth over $100 million.
How many bitcoins were transferred to centralized platforms after the incident?
More than 39,600 bitcoins were moved by Coldcard clients between July 28 and August 3, pushing total exchange reserves from 2.701 million to 2.719 million BTC. Binance alone saw its reserves increase from 650,000 to 659,000 bitcoins.