New bitcoin addresses surge after Coldcard wallet exploit
The number of new bitcoin addresses created each day climbed from roughly 260,000 to more than 330,000 over the past week, reversing a decline that had persisted through most of the year. The surge traces to a firmware flaw in Coldcard hardware wallets, first exploited on 30 July, that bypassed the device's dedicated hardware randomness chip during key generation in favour of a predictable software substitute, making some wallets' seed phrases reconstructable by attackers.
Coinkite, which makes Coldcard, has urged anyone who generated a wallet between March 2021 and the release of its patch to move funds to a freshly created wallet, a recommendation that accounts for much of the new address activity. The flaw affects firmware dating back five years, and attackers have continued draining exposed wallets in waves since the initial sweep.
A five-year-old firmware bug now driving the sharpest wallet migration of the year is a reminder that self-custody security depends on trusting the device that generated the keys, not just the keys themselves.