Key facts
- Bitcoin did move back onto exchanges after the Coldcard disclosure. CryptoQuant data shows net exchange inflows of 11,163 BTC on 31 July 2026, spread across Binance, River, Kraken and OKX.
- Retail transfer volume matched the FTX collapse. Transfers smaller than 1 BTC totaled 39,600 BTC in a single day, just short of the 39,900 BTC moved on 16 November 2022, the day after FTX filed for bankruptcy.
- But the headline "holders flee to exchanges" tells only part of it. On-chain analysis found that much of the movement went into freshly generated wallets the owners still control, not to exchange deposit addresses.
- US spot Bitcoin ETFs took in around $620 million that week. Bloomberg ETF analyst Eric Balchunas was direct about it: the connection is not established, and nobody knows.
- The cause was entropy, not a break-in. A 2021 firmware change narrowed the randomness behind new seeds to roughly 40 bits on some models, against a design target of 128. Attackers reconstructed keys without ever touching a device.
- What protected people was dice rolls and passphrases, not the badge on the device. Anyone who added their own entropy or used a passphrase was unaffected.
- SIAMBC does not sell Coldcard. This is not a comparison written to sell a replacement. It is a reading of where the money actually went, and what the lesson is.
A short recap of what happened
On 30 July 2026, Coinkite, the manufacturer of the Coldcard hardware wallet, disclosed a firmware flaw dating back to March 2021. The mistake came in when the company migrated its firmware to Bitcoin Core's cryptographic library: seed generation ended up calling a predictable software random number generator instead of the hardware one.
The effect was to narrow the pool of possible seeds to roughly 40 bits on the Mk2 and Mk3, and roughly 72 bits on the Mk4, Mk5 and Q, against a design target of 128 bits. At 40 bits, searching every possibility is work an ordinary computer finishes. The attacker never needed access to a device. They ran the same flawed randomness on their own machines, derived the addresses those seeds would produce, and checked which held money.
The damage figure is still climbing and differs by source and by reporting date. The range being reported is roughly 1,600 to 1,800 BTC, worth somewhere between $100 and $130 million, spread across several thousand addresses. Close to half the value was taken in the first 41 minutes.
SIAMBC has already published the full technical explanation, with affected models, firmware version numbers and the steps to take in order. It is in our explainer on the Coldcard flaw. This article does not repeat it. It looks at what happened next.
Where the money actually went
The more interesting story is what Bitcoin holders did in the following week, which is measurable on-chain.
Onto exchanges. CryptoQuant and Timechainindex recorded net exchange inflows of 11,163 BTC on 31 July 2026, most of it into Binance, River, Kraken and OKX.
Retail movement reached crisis levels. CryptoQuant reported that transfers smaller than 1 BTC totaled 39,600 BTC in a single day, just short of the 39,900 BTC moved on 16 November 2022, the day after FTX filed for bankruptcy. That comparison is the clearest measure of how alarmed people were.
Into ETFs. US spot Bitcoin ETFs recorded roughly $620 million of inflows during the week, spread across several funds including IBIT, FBTC and ARKB.
And into new self-custody wallets. This is the part most headlines left out. On-chain analysis found that a great deal of the movement from long-dormant wallets went to freshly generated wallets whose owners still hold the keys, rather than to exchange deposit addresses. That pattern is consistent with people securing funds, not with people giving up on holding their own keys.
Why the headline is incomplete
Several international headlines summarized this as Bitcoin holders rushing back to exchanges. That is true of part of the flow and misleading about the rest.
First, the money did not go to one place. It went to at least three: exchanges, ETFs, and new self-custody wallets. The last of those is what the on-chain analysis points to as a large share, and it is not an abandonment of self-custody. It is precisely what the manufacturer instructed affected users to do, which is generate a new seed on fixed firmware and move funds off the old one.
Second, the ETF link is unproven. Eric Balchunas, ETF analyst at Bloomberg, said plainly that he is not claiming a connection and that nobody knows, while allowing that some holders may migrate over time. Money flows in and out of ETFs for many market reasons at once. Two things happening in the same week is not evidence that one caused the other.
Third, an inflow during a crisis does not mean the money stays. In practice an exchange is the fastest available parking space when you have to move funds off a compromised seed within hours, and reaching for it is an understandable decision. The question that matters is whether it stays there afterwards.
Is moving back to an exchange rational?
In the short term, yes. Anyone who learned their seed might be reconstructible had little time and needed somewhere to put the funds immediately. Transferring to an exchange account you already hold is faster than waiting for a new device to arrive.
As a permanent answer, it trades one set of risks for another rather than reducing risk.
The Coldcard flaw was a single manufacturer's mistake. It was disclosed publicly, fixed firmware was released, and there is a way to check whether your own device is affected. The risk of leaving assets with a third party cannot be inspected from the outside at all.
Thailand has its own example. Bitkub was breached in 2021 for around 1.7 billion baht, and customers did not know for five years, until the Thai SEC filed a complaint against the company and two former directors in late July 2026. With Coldcard, users knew within hours and could check their own position immediately. That difference is worth weighing.
We covered this at length in our article on keeping crypto on an exchange. The conclusion there is that the two approaches work together: buy and sell through a licensed exchange, and hold in your own custody in between.
The lessons that hold up
The most useful part of this incident has nothing to do with brands. It is what saved the people who were not affected.
Anyone who added their own entropy with dice was unaffected. Coldcard lets the user roll dice to contribute randomness to seed generation. Those rolls come from a source the faulty firmware did not control, so the flaw did not reach them. This is a case where an extra step that felt fussy on setup day turned out to be what preserved the funds five years later.
Anyone using a passphrase was also unaffected, because a passphrase is not stored on the device and is not produced by the broken random number generator. An attacker who reconstructs the recovery phrase reaches only the wallet without a passphrase. If that mechanism is new to you, see what a passphrase is.
Do not concentrate everything with one manufacturer. Holders with significant amounts can spread that risk with a multisig setup using keys from devices by different makers, so that one vendor's mistake cannot reach all of it.
Open source matters, but it is not a guarantee. Coldcard's firmware has been public throughout, and this flaw sat there unnoticed for five years. Open code makes review possible. It only helps when somebody actually reviews it.
A firmware update does not repair a seed you already created. This is the most common misunderstanding of the whole episode. The seed was generated once, at setup. Updating firmware only fixes the next generation. Affected users have to create a new recovery phrase and move funds to a new wallet.
If you are replacing a device
SIAMBC is not a Coldcard reseller and has never stocked the product, so we have no reason to push anyone to switch brands over this. If you have checked and your device is unaffected, you do not need to change anything.
For those who have to generate a new recovery phrase regardless, the first thing to prepare is not a device. It is somewhere to keep the new phrase, because the paper card in the box is always the weakest part of the setup.
CryptoSafe
฿299
- 86 x 54 x 2.5 mm stainless steel, credit-card sized
- Records a full 24-word BIP39 phrase, stamped by you
- Rated to withstand fire up to 1000°C for 30 to 60 minutes
Adding: Plate only. Sets with pen, stamp and hammer are on the product page.
For anyone genuinely changing device, the two below answer the same priorities a Coldcard owner had in the first place: open code you can inspect.
Blockstream
฿3,190 ฿4,990-36%
- Fully open source, with a Bitcoin-first design focus
- BIP39 passphrase support, including entry by selecting words from the BIP39 list
- Virtual Secure Element keeps the decryption mechanism off the device, so attacking the device alone does not yield the keys
Adding: Black. Green and Orange are on the product page.
Jade is the one Bitcoin-focused holders tend to look at, because its design priorities line up closely with what a Coldcard owner valued: open code and a deliberate focus on Bitcoin rather than broad asset support.
Trezor
฿3,890 ฿4,590-15%
- Open-source firmware and design, public for inspection since 2014
- EAL6+ certified secure element
- Passphrase entered on the device, creating a separate hidden wallet
Adding: Cosmic Black. Three other colors on the product page.
One thing worth stating plainly: no brand can guarantee it will never ship a firmware mistake. What a user does control is adding their own entropy where the device allows it, using a passphrase, and not concentrating everything with a single manufacturer.
Common questions
Does SIAMBC sell Coldcard?
No, and we never have stocked it. This article is written as information for crypto holders in Thailand, not as a comparison intended to sell a replacement.
Should I move my funds back to an exchange?
If your recovery phrase is among those affected, moving funds immediately is the right call, and a licensed exchange is an acceptable temporary parking space. Longer term, treat it as parking rather than a destination, because it exchanges a risk you can inspect for one you cannot.
Are hardware wallets still safe?
This was one manufacturer's mistake in how randomness was generated, not a flaw in the idea of holding your own keys. Users of other brands, or anyone whose seed was generated on a different device, are unaffected by this flaw. It is, however, a reminder that trusting a single manufacturer too completely is a risk in itself.
How do I check whether my device is affected?
Look at the firmware version the device was running when the recovery phrase was first created, not the version it runs now. Version numbers by model are in our explainer on the Coldcard flaw, and you should always take them from the manufacturer's own advisory.
Why can the ETF inflows not be attributed to this?
Money moves in and out of ETFs for many market reasons simultaneously. Two figures landing in the same week does not establish that one caused the other, and Bloomberg's own ETF analyst said as much.
Someone claiming to be from the manufacturer offered to recover my funds. What should I do?
Do not reply. Events like this are reliably followed by people impersonating manufacturer staff or offering recovery services. No manufacturer, no retailer and no recovery service needs your recovery phrase in order to help you.
Buying in Thailand
SIAMBC is an authorized distributor for a number of hardware wallet brands, with a physical shop in Thawi Watthana, Bangkok. Free delivery nationwide within one to two business days, and same-day delivery in Bangkok by Grab or LINEMAN, arranged through LINE.
If you need to generate a new recovery phrase and are not confident about the steps, come to the shop. Our team will set the device up with you, check that the phrase is recorded correctly, and run a test transfer before you move anything that matters. Open Monday to Saturday, 9:00 to 17:00.
See all hardware wallets or contact us before deciding.
One rule to remember
Anyone who asks for your 24-word recovery phrase is a scammer. No exceptions.
Neither SIAMBC nor any manufacturer will ever ask for it, whatever reason is given — warranty claims, identity verification, system updates or account recovery. Those 24 words are the key to your funds. Whoever has them owns your crypto, and it can never be recovered.






Share:
Do You Need a Hardware Wallet If Your Crypto Is on Bitkub?
Why SMS OTP no longer protects you in Thailand