What happens when a hardware wallet vulnerability forces a network-wide evacuation? Bitcoin active addresses answered that question this week, surging to an eight-month high as users scrambled to move funds off devices running compromised Coldcard firmware.
The spike marks the most active daily address count since December 2024. On-chain data shows the surge was not driven by exchange inflows or whale accumulation but by a coordinated migration from wallets generated with vulnerable firmware versions. Users moved bitcoin to new addresses en masse, creating a temporary but measurable lift in network activity.
BTC traded at $64,189 during the episode, down 0.5% over 24 hours with $18.1 billion in volume. The price barely moved despite the address surge, underscoring a disconnect between on-chain utility metrics and spot market pricing. Market cap held at $1.29 trillion while total crypto market cap sat at $2.27 trillion with Bitcoin dominance at 56.6%.
| Metric | Value | 24h Change |
|---|---|---|
| BTC Price | $64,189 | -0.50% |
| 24h Volume | $18.1B | — |
|---|---|---|
| Market Cap | $1.29T | — |
| Active Addresses (Daily) | 8-Month High | — |
|---|---|---|
| BTC Dominance | 56.6% | — |
| Circulating Supply | 20.07M | — |
The migration pattern resembles previous firmware scares where address counts spike as users rotate keys, then normalize once the vulnerable cohort completes its move. Historical precedent from the 2023 Ledger Connect Kit incident showed a similar two-week elevation in active addresses before reverting to trend. This time, the Coldcard-specific vulnerability triggered a faster, more concentrated rotation window.
Miners and validators saw no corresponding uptick in fee revenue, confirming the activity was value-preserving transfers rather than economic transactions. The mempool remained uncongested throughout the episode, with median fees holding below 5 sat/vB. This suggests users prioritized security over speed, batching migrations during low-fee windows.
Supply pressure implications are minimal. The 20.07 million circulating bitcoin did not change; addresses simply rotated custody. No new bitcoin entered circulation, and no dormant supply awakened. The episode illustrates how infrastructure vulnerabilities can distort on-chain metrics without altering fundamental supply dynamics.
Watchpoints for the coming week: address count reversion toward the 30-day mean, any secondary firmware advisories from other hardware vendors, and whether the migration cohort begins transacting economically once secured. The network absorbed the shock without fee spikes or mempool congestion — a stress test passed quietly.
What the Address Surge Signals
The eight-month high in active addresses reflects a security response, not a demand signal. Users moved funds from compromised key derivation paths to fresh addresses, a one-time rotation that inflates the metric temporarily. Once the vulnerable wallet cohort completes migration, active addresses should decay back to structural trend levels around 800,000-900,000 daily.
Miner Revenue Unaffected
Fee revenue for miners showed no correlation with the address spike. Block rewards remained the dominant income source at 3.125 BTC per block post-halving. The migration's batched, low-fee nature meant miners captured minimal additional revenue — a reminder that not all on-chain activity translates to miner income.
Historical Parallel: Ledger 2023
The 2023 Ledger Connect Kit exploit produced a comparable address surge lasting approximately 14 days. Active addresses peaked 40% above trend before normalizing. Coldcard's narrower device footprint suggests a shorter, sharper rotation window — possibly 7-10 days based on current velocity.