Casa CEO Nick Neuman confirmed that 233,000 bitcoin flowed into multisig wallets after researchers disclosed a Coldcard firmware vulnerability that could leak private key material during transaction signing. The movement originated from two distinct user cohorts: single-key Ledger and Trezor holders upgrading to multisig, and existing multisig users ejecting Coldcard devices from their signing quorums.
The vulnerability surfaced in late July when a security team demonstrated that Coldcard's secure element could be coerced into revealing nonce data under specific timing conditions. Coldcard manufacturer Coinkite issued a firmware patch within 72 hours, but the disclosure triggered immediate repositioning. On-chain analytics firms observed the first large-scale multisig deposits within six hours of the public advisory.
Single-key holders accounted for roughly 60% of the inflows, per Casa's internal telemetry. These users had previously relied on Ledger Nano X or Trezor Model T devices for cold storage. The exploit demonstrated that a compromised single-key device offers no recovery path — a multisig quorum requires multiple independent keys, limiting blast radius. The remaining 40% came from 2-of-3 and 3-of-5 multisig vaults where Coldcard served as one signer. Those users replaced Coldcard with alternative hardware — primarily Ledger, Keystone, or Foundation devices — without changing their quorum thresholds.
Bitcoin's price action during the migration window was subdued. CoinGecko data shows BTC at $63,267, down 0.40% in 24 hours and 0.70% over seven days. Volume registered $19.9 billion. Total crypto market capitalization held at $2.25 trillion with $50.2 billion in 24-hour turnover, indicating the flows were custodial rather than speculative.
| Metric | Value | 24h Change | 7d Change |
|---|---|---|---|
| --- | --- | --- | --- |
| BTC Price | $63,267 | -0.40% | -0.70% |
|---|---|---|---|
| BTC Volume | $19.9B | — | — |
| Total Market Cap | $2.25T | -0.65% | — |
|---|---|---|---|
| BTC Dominance | 56.3% | — | — |
The sector implication extends beyond Coldcard. Hardware wallet manufacturers now face pressure to open-source secure element firmware and submit to third-party side-channel audits. Ledger and Trezor have not reported similar nonce-leakage vectors, but the Coldcard incident established that secure element isolation alone does not guarantee signing integrity. Multisig adoption data from Unchained Capital and Nunchuk shows a 34% quarter-over-quarter increase in new vault creations since the disclosure.
Casa's Neuman stated the migration validates the multisig threat model: "When one hardware vendor fails, the quorum holds. That is the entire point." The company's dashboard now flags any vault containing a Coldcard device pending firmware version 5.1.2 or later.