Coldcard theft hits $88.6M as exchange BTC deposits surge
Blockchain analysts report a suspected Coldcard theft campaign that has ballooned to about 1,367 BTC (≈$88.6M) across three sweeps. Galaxy Research traced funds swept from 4,585 addresses, while a separate dashboard (Coldcard Sweep Watch) estimates 1,158.8480 BTC by 5 p.m. EDT on Saturday. The largest Coldcard theft wave occurred July 30, when 1,082.65 BTC was swept from 1,195 addresses in 41 minutes. A smaller second wave followed July 31 with 76.16 BTC from 1,478 addresses, then a third wave (July 31–Aug 1) drained roughly 208 BTC from 1,912 addresses.
A key detail is how the third wave moved victims’ coins: instead of the more centralized collection pattern seen earlier, funds were sent into 293 separate P2WSH vaults, complicating attribution and tracking. Galaxy linked the activity to a vulnerable Coinkite Coldcard firmware release from March 17, 2021, matching the behavior of long-dormant cold-storage-style wallets.
A second signal came from exchanges: on July 31, net BTC exchange inflows reached about 11,163 BTC (Timechainindex data). River, Binance, Kraken, and OKX accounted for large portions of these inflows. Such spikes can precede selling, collateral moves, or internal custody transfers, but the data does not prove the Coldcard theft directly caused the deposits.
Third, some dormant BTC addresses (2010–2017 vintages) began moving coins after 9–16 years of inactivity (about 306 BTC visible July 30–Aug 1), though the report says this activity cannot be directly tied to the Coldcard sweeps. At the time of writing, BTC traded around $62,326, and online sentiment remained deeply bearish.
Bearish
This news is likely bearish because it combines (1) a large, concrete Coldcard theft (≈1,367 BTC / $88.6M) with (2) a notable BTC exchange inflow spike the same day, which traders often interpret as preparation for selling, hedging, or collateral use. Even though the report stresses that blockchain data cannot prove the exchange inflows were directly caused by the theft, the correlation in timing can still worsen short-term risk sentiment.
In the short term, similar incidents typically trigger forced re-positioning: holders re-check key-management, rotate wallets, and some move funds to exchanges or other custody paths, increasing volatility around BTC. In the longer term, if the vulnerable Coldcard firmware link leads to broader remediation and public awareness, it can reduce repeat risk for some users, but immediate market impact is dominated by uncertainty, potential sell pressure, and bearish sentiment (BTC trading below $63k in the article).
Compared with past large wallet-exploit headlines, the market reaction often hinges on follow-through: whether additional vault spends occur and whether attacker-linked liquidity hits exchanges. Until first outbound spends from the 293 vaults clarify who controls scripts/keys, downside pressure remains the more probable outcome.