Loading market data...

Coldcard Exploit Sends Dormant Bitcoin to Exchanges, Price Barely Budges

Coldcard Exploit Sends Dormant Bitcoin to Exchanges, Price Barely Budges

What the onchain data shows

K33 Research Head of Research Vetle Lunde identified the transfers as a "glaring exception" in a report titled "Textbook summer doldrums." The movement involved coins that had been idle for extended periods, now suddenly shifting to centralized exchanges, multi-sig setups, and new wallets. Some of the coins hadn't moved in years. The exact scale of the exploit and the number of affected wallets remain unclear, but the pattern suggests a coordinated response to a vulnerability in Coldcard's firmware or hardware. Onchain sleuths have been tracking the flows, noting that the destinations include at least two major exchanges, though K33's report does not name them.

Why the market shrugged

Bitcoin's price has held steady through the week, barely registering the sudden supply movement. That's partly because the total volume of coins moved, while notable onchain, is still small relative to daily trading volumes. The market's focus this August appears to be elsewhere — macroeconomic data, regulatory news, and the usual summer lull. With volatility at multi-year lows, a single exploit — even one involving dormant coins — isn't enough to shift sentiment. The price action this week has been rangebound, with Bitcoin trading in a narrow band.

K33's summer doldrums thesis

Lunde's report frames the exploit as an outlier in a market that's otherwise stuck in low-volatility mode. "Textbook summer doldrums" describes a period where trading volumes thin out and price action flattens — exactly the environment where a single exploit can look dramatic onchain without moving the needle on price. The report doesn't name the specific exchange or addresses involved, but the implication is clear: even a notable security event isn't enough to shake Bitcoin out of its summer slumber.

Coldcard has not yet issued a public statement about the exploit. Users holding funds on the device may want to