Bitcoin (BTC) energetic addresses reached roughly 0.98 million a day on July 31, the best day by day depend since December 2024, after attackers started sweeping wallets whose seeds have been generated on faulty Coldcard firmware.
Glassnode revealed the determine on August 6 and known as the surge “fear-driven on-chain exercise.” The analytics agency said that “holders migrating seeds and shifting funds to various custody displays an operational safety response, not a change in market conviction.”
Following the Coldcard firmware exploit, the variety of energetic Bitcoin addresses surged to 0.98M/day, the best since December 2024.
That is fear-driven on-chain exercise. Holders migrating seeds and shifting funds to various custody displays an operational safety response,… pic.twitter.com/BoKql7UpDH
— glassnode (@glassnode) August 6, 2026
Trade Balances Climb 22,135 BTC
Coin Metrics recorded 967,546 energetic addresses that day, 54% above the July common of 627,061. The final larger studying on that sequence was 985,635 on December 10, 2024.
Bitcoin held on exchanges rose from 2,654,863 on July 29 to 2,676,998 on August 3, a construct of twenty-two,135 cash or 0.83%, in keeping with Coin Metrics. The stability eased to 2,667,058 by August 5, leaving roughly 12,200 of these cash on exchanges.
The transaction depend moved the opposite approach. The community processed 607,581 transactions on July 31, under the July common of 656,321, whereas energetic addresses ran 54% above their month-to-month common.
Coin Metrics logged 730,433 energetic addresses on August 5, roughly 16% above the July common and the seventh straight day above it.
Losses Move $100 Million
Coinkite, the Canadian agency behind Coldcard, disclosed that seeds created on Mk2 and Mk3 firmware model 4.0.1, launched in March 2021, by model 4.1.9 carry weakened randomness.
Likewise, seeds generated on Mk4, Mk5, and Q gadgets earlier than the patched releases maintain about 72 bits of entropy towards the 128 bits meant. Mounted firmware shipped as model 4.2.0 for Mk2 and Mk3, 5.6.0 for Mk4 and Mk5, and 1.5.0Q for Q.
One thing to note is that seeds constructed with at the least 50 honest, unbiased, and personal cube rolls drew sufficient entropy from the cube alone, and a robust, distinctive BIP-39 passphrase forces an attacker to find the passphrase as effectively.
Furthermore, Coinkite famous {that a} passphrase “doesn’t restore the affected seed” and instructed these customers emigrate anyway. Putting in the patch doesn’t repair a seed already created.
The primary sweep took 594.5 BTC throughout 1,324 UTXOs from about 500 single-signature addresses in 4 consecutive blocks on July 30. Median loss per sufferer was 0.41 BTC, and the most important single loss was 29.9 BTC.
Galaxy Analysis counts 1,596 BTC confirmed stolen from about 7,300 addresses, rising to 2,055 BTC as soon as suspected sweeps are included. As CryptoPotato reported, the confirmed haul handed $100 million final week.
Santiment measured 0.58 bullish feedback for each bearish one throughout social channels, the bottom positive-to-negative ratio for the reason that agency started monitoring. Coinkite has instructed each proprietor who generated a seed on affected firmware to maneuver funds to a brand new seed on patched {hardware}. Bitcoin traded at $64,606 on August 6.
The publish Bitcoin Lively Addresses Surge to 8-Month Excessive After Coldcard Panic appeared first on CryptoPotato.

