Bitcoin’s onchain activity has reached its highest level of 2026, with researchers linking the sharp increase in transfers to the continuing Coldcard hardware wallet exploit and warning that similar surges have previously appeared near major market turning points.
Almost 890,000 BTC changed hands onchain in the seven days to K33 Research’s latest report, marking the largest amount of active supply recorded over a seven-day period this year. The increase came despite Bitcoin trading in one of its narrowest price ranges of recent years.
The rise in activity coincides with an expanding investigation into the Coldcard breach. Galaxy Research said on Tuesday that at least 15 separate attackers had exploited the vulnerability. Its latest confirmed figures show that 1,596 BTC was stolen from about 7,300 addresses in three verified waves.
Galaxy said the losses could rise to approximately 2,055 BTC, worth about $130m, if a fourth suspected wave is confirmed after further reports from victims.
The research firm said it had reduced earlier estimates after distinguishing confirmed victims from onchain activity that remains unverified. It added that roughly 90% of the stolen Bitcoin had not moved since the attacks, allowing investigators more time to track the funds while working with cryptocurrency exchanges, blockchain security companies and US law enforcement agencies.
Vetle Lunde, head of research at K33, said Bitcoin transfers had accelerated significantly even though the market itself had remained relatively stable.
The firm’s report said Bitcoin’s 30-day high-to-low range was its narrowest since 2023, while realised volatility had fallen below that of the Nasdaq 100. However, active supply had risen quickly as users affected by the Coldcard incident moved their coins.
The increase was “very likely driven by the Coldcard attacks”, Lunde said. The incident had “likely heightened concerns about other hardware wallets, including Ledger and Trezor, prompting some owners to consider centralized custodians or multisignature setups.”
The shift in custody preferences has also been noted by OKX. Its chief compliance officer, Jonathan Brockmeier, told crypto.news that the exchange had recorded record inflows after the Coldcard incident, as some customers transferred assets from hardware wallets to centralised custody.
Brockmeier said exchanges could offer dedicated security teams and automated monitoring for customers who preferred managed custody. He also stressed that self-custody remained available to users prepared to take responsibility for securing their own funds.
K33 said the current activity was significant because comparable spikes have historically occurred around local market tops and bottoms. Periods in which seven-day active supply entered the top 10% of readings in its rolling 365-day history coincided with reversals during the 2022 bear market, the bull markets of 2024 and 2025, and the 2026 bear market.
“The intuition behind this observation is clear: panic is visible onchain,” Lunde wrote.
He said falling markets often led investors to send coins to exchanges in an attempt to limit further losses. Rising markets, meanwhile, could prompt profit-taking as well as buying driven by fear of missing out.
The report said two of the biggest active-supply increases this year came during sell-offs in February and June. A separate rise in late April was considered more likely to have resulted from routine address rotation than from transfers to exchanges.
K33 did not claim that elevated onchain activity could, by itself, forecast the next direction of Bitcoin’s price. However, it said the historical pattern meant the current rise warranted close attention while the Coldcard investigation continued.
The attack was traced to a flaw in Coldcard firmware disclosed by manufacturer Coinkite. Affected devices generated wallet seeds using a deterministic pseudo-random number generator rather than the intended hardware-backed true random number generator.
Coinkite’s technical review said the vulnerability had been introduced in March 2021, when engineers integrated a new cryptographic library into the firmware. Although the hardware random-number generator continued to operate elsewhere in the software, the wallet creation process mistakenly used MicroPython’s deterministic generator, reducing the entropy available for new seed phrases.
Block’s Bitcoin engineering and security team reached the same conclusion in an independent firmware review. It said vulnerable devices called the deterministic MicroPython fallback during wallet creation instead of the STM32 hardware random-number generator. Block added that it had not tested every affected model before publishing its findings because thefts were already taking place.
Coinkite estimates that affected Mk2 and Mk3 wallets may have had about 40 bits of effective entropy. Vulnerable Mk4, Mk5 and Coldcard Q devices may have generated about 72 bits, compared with the intended security level of 128 bits.
Emergency firmware updates are available for all affected product lines. Coinkite has warned, however, that updating the firmware only protects wallets created after the fix was installed.
Owners whose seed phrases were generated using vulnerable firmware have been told to create new wallets. They should verify the new destination address with a small test transaction and move their Bitcoin only once that transfer has been confirmed.
The incident has also intensified debate about the checks applied to hardware wallet firmware before release.
Kraken chief security officer Nick Percoco argued on X that manufacturers should not be solely responsible for verifying how production firmware creates wallet seed phrases. He cited the NIST SP 800-90B and Germany’s BSI AIS-31 standards, saying similar end-to-end checks were not routinely applied to hardware wallet firmware despite the importance of secure seed generation.
Ripple CTO Emeritus David Schwartz described the breach as an example of outlier risk, in which an unusual technical failure causes losses far greater than users anticipate. He compared the incident with the 2011 collapse of MF Global, arguing that self-custody removes dependence on financial intermediaries but still leaves users reliant on hardware and firmware working as intended.
Schwartz also said Coldcard owners whose funds were stolen through compromised wallet seeds currently had no equivalent recovery mechanism to the protections available to customers of regulated financial institutions.
