Coldcard exploit sends bitcoin network activity to its highest level since February 2025
Bitcoin transactions and active addresses jumped as users reacted to the $120 million hardware-wallet theft, while the market stayed inside a narrow $62,000-to-$65,000 range.
Bitcoin network activity rose sharply Tuesday as users responded to the ongoing theft from wallets linked to a Coldcard hardware-wallet exploit. The network processed 89,031 transactions in the mempool, the highest daily reading since February 2025, according to Blockchain.com data cited in CoinDesk's market coverage.
Santiment counted about 712,000 active addresses, a three-month high, and 61,800 large-holder transactions, the strongest reading in five months. The burst of activity did not produce a comparable price move: bitcoin remained inside a range of roughly $62,000 to $65,000.
A security event becomes a market event
The activity appears to combine defensive transfers, wallet checks and the movement of coins connected to the theft. It is not the same as a broad return of speculative demand. When a large security incident occurs, users may transact more because they are trying to migrate funds, consolidate addresses or monitor the attacker rather than because they expect prices to rise.
That distinction matters for interpreting onchain data. A record mempool or a jump in active addresses can signal urgency without showing whether new capital is entering the market. Price and liquidity stayed comparatively calm while the wallet community dealt with an operational problem.
The policy backdrop is still unresolved
Marex analysts said the Senate's CLARITY Act timetable remained a binary policy risk, with lawmakers facing a short window before the Aug. 10 recess. Their estimate of year-end passage fell to 23% from 75% in mid-May, while prediction-market restrictions could add another procedural obstacle.
The market's technical picture is therefore being shaped by two different forces: a wallet-security incident that is visible in transaction data and a policy process that remains uncertain. The next useful signal will be whether activity falls after users complete migrations, or whether the exploit produces a longer shift toward multisignature and other custody practices.