A Coldcard hardware wallet hack set off a $BTC transfer event that CryptoQuant researchers ranked as the largest sub-1 BTC movement since the FTX collapse. Some 39,600 BTC shifted out of small wallets as the exploit was still running. Researchers warned the attack had not been contained.
What the on-chain data shows
The 39,600 BTC figure is the signal worth reading. Sub-1 BTC transactions are the signature of retail holders and small self-custody users, not institutions moving blocks. When that cohort moves in volume, it typically signals a threat they believe is credible and immediate.
CryptoQuant, the on-chain analytics firm that flagged the movement, also reported that the Coldcard attack remained active at the time of its analysis. That detail shapes how the data reads: a live threat produces different behavior than a contained breach. Users who received the warning while the exploit was still running had reason to move funds before the window closed, which is what the transaction data appears to reflect.
The read-through for hardware wallet holders
Coldcard is a Bitcoin-only hardware wallet built for holders who take self-custody seriously. Its user base skews toward people specifically trying to avoid the counterparty risk that surfaces when platforms fail.
The read-through is uncomfortable. If a tool built for security becomes a threat vector while the exploit is live, the holders who moved 39,600 BTC were scrambling to exit positions under pressure. That is precisely the situation a hardware wallet is supposed to prevent. The comparison CryptoQuant draws to FTX-era movement is pointed: on-chain behavior at that scale has historically corresponded to moments when users believed their funds were genuinely at risk.
The counterargument
The counterargument is that 39,600 BTC moving does not confirm 39,600 BTC at risk. Users may have moved preemptively on news alone, without any individual wallet having been compromised. On-chain movement at scale does not distinguish between confirmed victims and cautious holders acting on a warning. The volume benchmarks against FTX-era panic, but the cause may differ in character.
On balance, what the data resolves is narrower than the headline implies. CryptoQuant documented an unusually large small-wallet transfer event tied to a live hardware wallet exploit. The researchers left the key question open: the attack was still active.