Crypto World
Coldcard Hack Triggers Largest Sub-1 BTC Shift Since FTX, CryptoQuant
Bitcoin appears to be seeing a renewed pattern of rapid, smaller transfers—an on-chain behavior not observed at similar levels since the immediate aftermath of the FTX collapse. On Friday, transfers below 1 BTC surged to the highest daily level since November 2022, totaling 39,600 BTC, according to research shared by CryptoQuant head of research Julio Moreno on Saturday.
Moreno’s comparison is stark: the figure sat just 300 BTC under the 39,900 BTC moved on Nov. 16, 2022, days after FTX filed for bankruptcy. “The Bitcoin plebs had not moved this amount of BTC in a day since the FTX collapse,” Moreno said, adding that he viewed the uptick as encouraging activity rather than passive exposure.
Key takeaways
- Daily transfers under 1 BTC reached 39,600 BTC, the highest since November 2022, per CryptoQuant’s Julio Moreno.
- Galaxy Research says the suspected Coldcard hack added a further 207.7 BTC drained from victim addresses, pushing estimated losses higher.
- Galaxy reports cumulative figures of 1,367 BTC estimated losses across 4,585 addresses tied to the incident.
- Executives and researchers are using the event to renew debate over whether self-custody is safer than third-party custody.
Smaller transfers spike as users react
Moreno’s data focuses on movement of less than 1 BTC at a time—a slice of network activity often associated with people reallocating funds quickly rather than executing large, institutional transactions. Reaching levels last seen in late 2022 suggests heightened urgency across segments of the market.
The timing aligns with an ongoing suspected Coldcard hack, which first came into view in late July. As new victims were reportedly identified, the incident has increasingly framed itself as a stress test for how quickly users can respond when self-custody systems are believed to generate compromised receiving addresses.
Galaxy Research tracks additional drained funds
While on-chain movement is one signal, Galaxy Research says the theft itself has continued in identifiable stages. In a report posted Saturday, Galaxy Research said it observed an additional attack wave that drained 207.7 BTC—worth about $13.2 million at the time of reporting.
With that update, Galaxy Research estimated total losses at 1,367 BTC (about $88.6 million), across 4,585 addresses. The firm’s tracking also indicates the attackers’ activity is not a one-off event, but an evolving process with multiple waves that continue to surface as investigators connect addresses to victims.
Galaxy Research’s post also referenced the continuing discovery of new addresses tied to the suspected scheme, reinforcing the idea that the full scope may still be expanding as researchers refine their identification methods.
Attack still ongoing, warning to move funds
Alex Thorn, head of firmwide research at Galaxy Digital, warned in an X post on Sunday that the attack was still ongoing. Thorn urged users to move funds from Coldcard-generated addresses immediately if they had not already done so.
Thorn said his team continued to identify both victim addresses and attacker addresses. He also added that reports from users were helping investigators and authorities track the stolen funds—highlighting the role of community reporting alongside on-chain analysis.
The repeated “ongoing” language matters for users because it suggests the situation is dynamic: even if some victims have already moved funds, more affected addresses may still be discovered. That is also consistent with the broader pattern reflected in the day’s spike in small transfers.
Self-custody debate resurfaces
The suspected Coldcard hack has renewed debate over the safety and practicality of Bitcoin self-custody—one of the sector’s foundational principles that allows users to control funds without depending on centralized intermediaries.
Nick Neuman, CEO of Bitcoin security company Casa, pushed back against claims that self-custody is “over.” Neuman argued that self-custody’s distributed nature provides users with time to react once suspicious activity becomes apparent. He also said he “estimated” that potentially 10 times more Bitcoin was protected through self-custody than was stolen and identified so far in the attack.
The exchange also drew responses from people more aligned with traditional finance. Eric Balchunas, a senior ETF analyst at Bloomberg, argued on X that Bitcoin ETFs may offer a safer and more convenient route for many investors, citing the longer operating history of the ETF industry.
Not everyone agreed with that framing. Other observers suggested the incident should be viewed as a failure attributable to a wallet provider rather than as evidence that self-custody as a concept is fundamentally broken—an important distinction for readers assessing risk.
In practical terms, the disagreement reflects two realities that can coexist: individual wallet implementations can fail, while self-custody still reduces reliance on centralized exchanges. The Coldcard case, as described through public tracking, becomes a test of how resilient users are when compromised address generation is detected and when timely migration is possible.
What investors should watch next
Watch for two signals in the coming days: whether the number of newly identified victim addresses continues to grow (which would imply the blast radius is still being uncovered), and whether the elevated level of small transfers under 1 BTC sustains or fades as affected users complete migration. The more those patterns stabilize, the clearer it will become whether the incident is trending toward containment or still expanding.
You must be logged in to post a comment Login