All Posts
Technology

210,000 Bitcoin Just Moved Without Changing Owners. The Largest Re-Keying Event in Bitcoin's History Is Happening Right Now — Under Deadline, in Fear, and Mostly Onto Paper.

August 15, 20267 min read

On August 7, Glassnode's long-term-holder supply metric did something it has only done a handful of times in bitcoin's history: it fell off a cliff. Roughly 210,000 BTC left wallets that had sat untouched for at least 155 days, dropping the cohort from just under 15 million coins to about 14.7 million — the sharpest weekly decline since December 2024, when bitcoin first approached $100,000 and early holders sold into the euphoria. Every previous drawdown of that magnitude arrived near a market top: March 2021, March 2024, December 2024. Experienced money taking profit into strength is the oldest pattern in the chart. But this one broke the pattern completely, because bitcoin was trading around $64,000 at the time — roughly fifty percent below its October all-time high — and the price did not make new lows afterward. Coins moved and the market barely noticed, which is the tell. This was not distribution. This was a migration, and it is still running.

What triggered it is now well documented: on July 30 attackers began sweeping bitcoin out of single-signature Coldcard wallets whose seed phrases had been generated by firmware containing a randomness flaw dating to March 2021, and Coinkite's own advisory told affected users the only real remedy was to generate fresh keys and move their funds, because patched firmware cannot repair a seed that was born weak. Tens of thousands of people did the arithmetic on their own exposure and reached the same conclusion at the same time. New bitcoin wallet creation hit its highest level of 2026 that week. Dormant addresses that had not signed a transaction in over a decade — including one untouched since 2013 that moved $31 million — suddenly woke up. And in parallel, U.S. spot bitcoin ETFs absorbed about $754 million in a single week, most of it into BlackRock's IBIT, as a second cohort reached a different conclusion: that the problem was self-custody itself. Put those numbers next to each other and you are looking at the largest coordinated re-keying event bitcoin has ever experienced, executed by ordinary people, on a deadline, with no coordination and no playbook.

Take the second cohort first, because their reasoning deserves a real answer rather than a slogan. The argument for handing coins to a regulated custodian after an event like this is genuinely coherent: institutional key generation with audited entropy sources, geographically distributed multi-signature quorums, insurance, and — the part self-custody structurally cannot offer — someone who is accountable when it goes wrong. A Coldcard user who lost eleven bitcoin to a preprocessor typo has no counterparty, no recourse, and no one to sue. That asymmetry is real and it is the strongest case custodians have ever had. But it is a trade, not an upgrade, and the terms should be stated plainly. You exchange a silent technical single point of failure for a loud institutional one: issuer risk, custodian risk, management fees, no on-chain optionality, withdrawal at someone else's discretion, and — if enough people make the same move — a concentration problem this publication has written about before, where the overwhelming majority of ETF assets sit behind a small handful of custodial keys. Trading one 1-of-1 for another 1-of-1 with better branding is not a security improvement. It is a change in who fails first.

Now the first cohort, the one this site cares most about, because their risk is being almost entirely ignored. Every person who migrated in the past two weeks executed the same sequence: generate a new seed on new or reflashed hardware, write down twelve or twenty-four fresh words, verify the receiving address, and move a life-altering sum of money in a single irreversible transaction. That sequence is the most exposure-dense hour in the entire life of a bitcoin holding, and it was performed at scale by frightened people who wanted it over with. Consider what "write down twelve fresh words" actually looks like at eleven at night, with an attacker on the clock. It looks like the back of an envelope, because the steel plate is on order. It looks like a photo "just until the plate arrives," which is to say a permanent copy in a cloud backup. It looks like typing the phrase into a second wallet app to confirm it restores. It looks like a text to a spouse so somebody else knows. Every one of those improvisations recreates the single complete copy that the entire threat model was supposed to eliminate — and unlike the firmware bug, none of them are anyone's fault but the architecture's.

The historical pattern here is unkind and worth naming. Coin losses following a disclosure are rarely dominated by the disclosed vulnerability; they are dominated by the migration. People who move under time pressure skip verification steps, mistype addresses, fall for "official support" accounts offering migration help, sign rescue transactions that get front-run, and — most commonly and most quietly — make a temporary backup that outlives its own temporariness by a decade. Three weeks from now the news cycle will move on, the emergency will feel resolved, and a meaningful fraction of these newly generated seeds will still be sitting on the envelope, in the photo roll, in the drawer. The wrench attacks this blog has covered, the hidden camera that filmed a man typing twelve words, the 77 kidnappings France logged in six months — every one of those attacks is a bet that somewhere there exists one complete copy of a phrase. August 2026 is manufacturing hundreds of thousands of new bets to place.

So the practical guidance is narrow and it is all about the hour after generation. Do not let the new phrase exist as a single complete artifact any longer than the moment it takes to record it. Give the new wallet a BIP-39 passphrase, which sits outside any generator the device controls, and never store it with the words. Consider whether the setup that just survived this event — a multisig quorum drawn from genuinely different vendors, so that one company's build-configuration error cannot enumerate all of your keys at once — is worth the operational overhead you previously talked yourself out of. Verify the receiving address on the device screen, not the computer's, and send a small test transaction first even though it feels like an insult to your own competence. Move slowly in exactly the situation designed to make you move fast. And write down, somewhere your heirs will find it, what you just changed — because a migration that nobody else knows about converts a security event into an inheritance failure with a delay of twenty years.

seQRets exists for the specific problem this month is generating at industrial scale. It could not have prevented the Coldcard flaw and makes no such claim: entropy that was weak at birth stays weak, and the only fix was the migration people are doing right now. What it addresses is the artifact the migration creates. A freshly generated seed is encrypted on your own device, split into QR-encoded threshold shares — 3-of-5, 2-of-3, whatever fits the people and places actually in your life — and distributed so that no single location, no single trusted person, and no single burglary reveals anything at all. There are no servers, no accounts, and nothing on our side to breach. The 210,000 coins that moved last week are the clearest signal bitcoin has ever produced that people will change their custody under pressure. The question is whether what they changed to is a genuinely better structure, or the same fragile envelope with a newer set of words on it.