#What triggered Bitcoin's recent increase in active addresses?
Bitcoin experienced a significant spike in its active address count on July 31, 2026, reaching nearly 980,000, a peak not seen since December 2024. This uptick, however, is not a marker of bullish market sentiment; it stemmed from a wave of panic among Bitcoin users.
The surge in network activity followed an emergency advisory from Coinkite, the company behind the Coldcard hardware wallets. They revealed a serious security flaw in their Mk3 devices, causing thousands of users to withdraw their funds from potentially compromised wallets. This reaction resulted in a noticeable jump in network engagement, not reflective of market enthusiasm.
#What was the nature of the vulnerability?
This vulnerability originated from a firmware update, version 4.0.1, rolled out in March 2021. The patch included a defect in the random number generator that affects the security of seed phrases. Coinkite issued warnings on July 30, promptly advising users who had generated seeds on the vulnerable firmware to consider their funds at risk and to act immediately to secure their investments. Consequently, the number of active addresses surged from about 645,000 to approximately 980,000 in just a single day, illustrating the urgency of those attempting to protect their assets.
#How did attackers exploit this vulnerability?
Coordinated attacks targeting vulnerable wallets began before users could respond. Between July 30 and July 31, attackers drained funds from 4,585 to 7,300 addresses, primarily those that had not been accessed in about three years. The total confirmed losses spanned from 1,367 to 1,596 BTC, equating to an approximate value of $89 million to over $100 million, with projections suggesting that cumulative losses could exceed 2,000 BTC, roughly $130 million, if attacks continued.
#What does this mean for users of Coldcard wallets?
In response to the crisis, Coinkite released firmware version 5.0.3 in early August 2026 to rectify the RNG flaw. However, the damage inflicted was already significant. Remedies are possible for software vulnerabilities, but once funds are drained, they cannot be recovered. For Bitcoin holders using Coldcard Mk3 wallets, it's critical to verify the active firmware version during seed generation. If your seed was created on the affected firmware, treat it as compromised, regardless of whether the wallet itself has been accessed recently. Migrate your funds to a new wallet with a secure firmware version, and abandon the old wallet to minimize potential risks.
#What implications does this incident have for Bitcoin investments?
This event occurs at a pivotal moment in Bitcoin's investment landscape, especially as Spot Bitcoin ETFs are gaining momentum, offering institutional-grade custody options for a wider audience. Analysts suggest that incidents like this could drive investors toward regulated investment avenues that provide enhanced security through professional custodianships. As the situation unfolds, Bitcoin investors must stay vigilant and proactive in managing the security of their assets.