Catenaa, Wednesday, August 19, 2026- New Bitcoin addresses surged above 330,000 last week as Coldcard hardware wallet users moved funds following an exploit linked to a years-old firmware flaw.
The number of new addresses climbed from about 260,000, sharply reversing a downward trend that had persisted through much of 2026, according to data cited by The Block.
The increase appears closely connected to users migrating Bitcoin from potentially vulnerable Coldcard wallets into newly generated addresses.
Coldcard maker Coinkite advised affected customers to move their Bitcoin into fresh wallets after the vulnerability was traced to wallet seeds generated using weak randomness.
At least 1,816 BTC, worth about $116 million, has been stolen across four waves of theft since July 30, according to The Block.
The vulnerability reportedly originated in 2021 firmware. Affected wallets generated seeds using a weaker software random number generator rather than the device’s hardware entropy source.
The weakness reduced the effective security of some wallet keys, allowing attackers to attempt offline brute-force attacks against them.
Coinkite has advised users who generated wallets during the affected period to transfer their holdings to newly created wallets.
That migration offers a likely explanation for the sudden increase in new Bitcoin addresses.
However, the incident carries implications beyond the immediate movement of funds.
Self-custody has long been promoted as a way for Bitcoin holders to eliminate counterparty risk by retaining direct control over their private keys. The Coldcard incident demonstrates that this does not eliminate technical or implementation risks.
A holder may control the private keys but still face losses if the hardware, firmware or cryptographic processes generating those keys contain weaknesses.
The incident could therefore influence how investors assess the trade-offs between hardware wallets, centralized custodians and regulated spot Bitcoin exchange-traded funds.
The security concerns come as investors already have more ways to gain Bitcoin exposure without directly managing private keys.
The incident does not necessarily weaken the case for self-custody. Instead, it shows that custody decisions involve different categories of risk rather than a simple choice between safe and unsafe methods.
Catenaa View
The surge in new Bitcoin addresses should not automatically be treated as evidence of accelerating Bitcoin adoption.
Existing holders appear to be creating fresh addresses as part of a security migration. That makes the increase primarily a security-driven onchain event rather than a clean indicator of new users entering Bitcoin.
The larger lesson concerns the meaning of self-custody itself.
Controlling private keys removes dependence on a financial intermediary, but users still depend on hardware design, firmware integrity and secure key generation.
Coldcard therefore turns a familiar Bitcoin debate in a different direction. The question may increasingly become not whether investors should choose self-custody or institutional custody, but how they distribute risk between them.
What to Watch
Watch whether Bitcoin address creation remains elevated once Coldcard users complete their migrations. A sharp decline would support the view that the current increase was mainly security-driven.
Further disclosures about stolen Bitcoin and the number of vulnerable wallets will also matter.
Hardware wallet manufacturers could face greater scrutiny over firmware auditing, entropy generation and independent security testing.
Another indicator will be Bitcoin flows into exchanges, professional custodians and spot ETFs. Sustained movement toward those vehicles could indicate that the exploit is changing investor attitudes toward self-custody.
