Newsroom
3 August, 2026 / News / AI / Tags: coldcard, ftx, incident, btc, galaxy

Daily moves under 1 BTC hit 39,600 as users respond to a suspected hardware wallet breach that has produced estimated losses of more than $88 million
Transfers of Bitcoin in amounts below one coin climbed to their highest daily total since the FTX collapse, coinciding with continued reports of a suspected Coldcard hardware wallet security incident. On-chain data showed 39,600 BTC moved in such small transactions on Friday, just short of the 39,900 BTC recorded on November 16, 2022, days after the exchange filed for bankruptcy.
CryptoQuant head of research Julio Moreno described the volume as evidence that individual holders were actively relocating funds. He noted that the Bitcoin community had not shifted this quantity of coins in a single day since the period immediately following FTX’s failure and characterized the activity as a constructive response rather than passive exposure.
The surge in small transfers occurred against the backdrop of a suspected Coldcard wallet breach that first drew wider attention in late July. Researchers have continued to identify additional affected addresses as the incident has progressed through successive waves.
Galaxy Research, the research arm of Galaxy Digital, reported that a recent wave of activity drained 207.7 BTC, valued at approximately $13.2 million at the time of the update. That figure lifted the cumulative estimated losses to 1,367 BTC, or about $88.6 million, spread across 4,585 addresses.
Alex Thorn, Galaxy Digital’s head of firmwide research, stated that the attack had not yet been contained. He advised users who still held funds at Coldcard-generated addresses to move them without delay. Galaxy’s team continues to track both victim and attacker addresses, noting that reports from affected users have assisted in following the movement of stolen coins.
The incident has prompted fresh discussion about the practical risks and benefits of self-custody. The approach gives users direct control over their assets and removes reliance on third-party custodians, yet it also places full responsibility for security measures on the individual.
Nick Neuman, chief executive of Bitcoin security firm Casa, rejected suggestions that recent events signal the end of self-custody. He argued that the distributed character of Bitcoin wallets supplies users with critical time to respond once problems surface. Neuman estimated that as much as ten times more Bitcoin remains protected through self-custody than has been identified as stolen in the current attack.
Eric Balchunas, senior ETF analyst at Bloomberg, offered a contrasting view. He contended that regulated products such as Bitcoin exchange-traded funds can provide greater safety and convenience for many investors, pointing to the longer operational record of the ETF industry.
Other industry participants stressed that the vulnerability appears limited to a single hardware wallet provider and cautioned against treating the episode as evidence that self-custody itself is unworkable. They noted that rapid detection and real-time monitoring of unusual fund movements can still allow users to act before losses mount further.
Attention remains fixed on two indicators: whether newly identified victim addresses continue to increase and whether the elevated volume of sub-1 BTC transfers persists or declines as more holders complete the process of relocating funds. Stabilization in both measures would suggest the incident is moving toward containment, while further growth would indicate that the full scope is still unfolding.
Market participants continue to monitor address activity and community reports as investigators work to map the remaining affected wallets and the destinations of the stolen coins.









