Bitcoin is trading near $62,560 as of Monday morning UTC, down about 1.5% over 24 hours and consolidating well below the multi-week highs it touched before the Coldcard news broke. Price isn't the story. Where the coins are going is. Five days into the Coldcard hardware-wallet exploit, holders are searching coldcard exploit bitcoin exchanges because the day-one advice — move your funds to a fresh seed — no longer feels safe enough, now that the attacker has learned to outrun it.

What changed on day five

The drain started July 30 and has escalated in waves rather than happening all at once. Each wave has pushed the cumulative loss estimate higher: roughly $38 million, then $70 million, then $89 million, and now near $114 million across more than 5,200 addresses, according to Galaxy Research's tracking. That upward creep matters more than any single figure, because it means investigators still haven't found the edge of the problem. They're finding more exposed wallets every time they look, not confirming a fixed, already-drained pool.

Monday brought a fourth wave, and it's a meaningfully different threat. The attacker is now using replace-by-fee (RBF), a standard Bitcoin feature that lets someone resubmit a pending transaction with a higher fee to get it confirmed faster. Coinkite's own emergency advice to affected users has been to move funds to a new, uncompromised seed as soon as they realize they're exposed. RBF lets the attacker watch for that rescue attempt in the mempool and outbid it — turning the fix itself into a race the victim can lose.

The coldcard exploit bitcoin exchanges trade-off

That's the mechanism behind the search term. Faced with an open-ended bug of unknown scope and an attacker who can now beat your own rescue transaction, a growing number of holders are concluding that the safest place for BTC this week isn't a self-custody wallet at all — it's an exchange account, where this specific firmware flaw simply doesn't apply.

CryptoQuant data show sub-10 BTC exchange deposits climbing to roughly 7,300 BTC on July 31 — the highest level since February 6 — while Timechainindex separately tracked total net exchange inflows of roughly 11,163 BTC that same day, spread across Binance, River, Kraken and OKX. Together they point the same way: a real, measurable reversal of a trend that has run the other way since the FTX collapse, as bitcoiners have spent more than two years pulling coins off exchanges and onto hardware. Binance founder CZ posted on August 1 urging holders to diversify across wallets — a sign the exchange side of the industry sees the same shift and is trying to get ahead of it rather than just benefit from it.

Is my BTC still at risk?

That depends on one thing nobody outside Coinkite and Galaxy Research can currently answer: whether your seed was generated on the vulnerable March-2021-era firmware. If it was, and you haven't migrated to a new seed on updated firmware, you're inside the pool the attacker is still working through. If you're on newer firmware or you've already rotated to a fresh seed, you're not part of the technique this specific exploit targets — but the RBF wave shows the migration process itself now carries risk if it isn't done cleanly and fast.

The honest, slightly unsatisfying answer is that risk here is a function of information you don't have. Nobody has published a bounded count of affected units, only a running total of what's been stolen so far. That gap is exactly why the exchange trade looks rational to so many people right now, even though it runs against everything the self-custody community has argued for since 2022.

Should you move your BTC to an exchange right now?

If you know your Coldcard is unaffected — different model, firmware updated well before the bug window, seed already verified clean — there's no new reason to move funds anywhere. If you don't know, or you generated your seed on an old firmware version and haven't rotated it, temporarily parking funds on a reputable exchange is the lower-risk option until you can migrate properly, precisely because RBF has made the DIY rescue path riskier to execute under pressure. That's a statement about relative risk this week, not a verdict on self-custody as a strategy.

The trade is explicitly temporary. Custodial risk (an exchange freezing withdrawals, getting hacked, or mismanaging reserves) hasn't gone away — it's just smaller than an unquantified firmware bug for the specific window most affected users are in right now.

What would change the calculus

The flow reverses once Coinkite or Galaxy Research can put a real number on total exposure — how many units shipped with the affected firmware, how many seeds are confirmed still unrotated. Until then, expect the loss total to keep climbing at each check, as it has all week, and expect exchange inflows tied to this story to stay elevated. The base case is that this is a temporary, rational risk transfer rather than a lasting rejection of self-custody: once the population of exposed seeds is bounded and visibly shrinking, the incentive to sit on an exchange disappears and funds should drift back toward hardware wallets, likely newer models with the bug already patched. The risk to that view is a fifth wave, or a total that keeps stepping up past $114 million with no end in sight — at which point the exchange-inflow shift stops looking temporary and starts looking structural.

Sources