Mid-tier Bitcoin wallets holding 10 to 10,000 coins have added 19,610 BTC since July 29. That's a billion dollars of fresh buying, and it arrived right on schedule: the moment retail got spooked.
A critical firmware bug in Coldcard hardware wallets triggered the panic. On July 30, hackers began exploiting a vulnerability that had been lurking since a March 2021 firmware update. The Mk3 model took the worst hit, though Mk4, Mk5, and Q units were also exposed. The damage tally: 1,367 BTC stolen, worth roughly $87 to $89 million at the time.
Coinkite, Coldcard's maker, released hotfixes between July 31 and August 1. But here's the catch. Users who generated seeds on the vulnerable firmware need to migrate them entirely. If they don't, they stay at risk. That uncertainty is poison for retail confidence.
The usual pattern repeats
While larger holders quietly accumulated, the smallest retail wallets, those sitting under 0.01 BTC, trimmed positions by 0.55%. It's the old story. Fear spreads through small accounts. Big money buys the dip. The Coldcard exploit wasn't a macro event or policy shift. It was a firmware mistake. Yet it moved the needle on actual Bitcoin distribution across wallet sizes, and that matters because it shows how quickly security theater can shake conviction among regular holders.
The 19,610 BTC acquisition represents a 0.14% increase for the mid-tier cohort. Not massive in percentage terms, but significant in absolute value. Someone, somewhere, made a deliberate choice to load up while others were heading for the exits.
This article is informational only and should not be treated as financial advice. Cryptocurrency markets remain volatile, and self-custody comes with real security responsibilities.



