Bitcoin Onchain Activity Surges Amid Ongoing Coldcard Attack, Analysts Link to Market Volatility

Bitcoin Onchain Activity Surges Amid Ongoing Coldcard Attack, Analysts Link to Market Volatility

Bitcoin onchain activity has reached its highest level of 2026 as the Coldcard attack continues, with K33 noting a surge in coin movement resembling patterns seen around market turning points. Galaxy Research estimates at least 15 attackers have exploited the vulnerability, with losses potentially exceeding $130 million. K33 reports approximately 1,596 BTC stolen from 7,300 addresses. Analysts suggest the spike in transaction activity may reflect panic or heightened concerns about hardware wallet security.

Over the past seven days, 890,000 BTC has moved on the Bitcoin blockchain, marking the most significant onchain activity of the year. K33’s analysis highlights that such spikes often coincide with periods of market uncertainty, though the firm cautioned that the connection remains speculative. Galaxy Research’s estimate of $130 million in losses includes suspected but unconfirmed thefts, adding complexity to the assessment of the attack’s full impact.

Vetle Lunde, head of research at K33, noted that the current activity levels mirror historical patterns observed during market turning points, though he stressed that correlation does not imply causation. The Block, which published the findings, has disclosed financial ties to Foresight Ventures, a firm with investments in blockchain-related ventures. The alleged theft patterns reported by Galaxy Research are reportedly under further investigation by cybersecurity experts.

The incident has reignited debates over hardware wallet security, with industry observers calling for greater transparency from affected firms. While the scale of the attack remains unclear, the movement of hundreds of thousands of BTC underscores the vulnerability of digital assets during periods of heightened market stress. As the Coldcard breach continues, analysts warn that the broader cryptocurrency ecosystem may face prolonged scrutiny over security protocols.


Written by Daniel Brooks
Security Desk

Share