Approximately 233,000 Bitcoin, valued at over $15 billion, migrated to new self-custody configurations in the immediate aftermath of a critical exploit targeting Coldcard hardware wallets, according to data cited by custody firm Casa. The scale of the movement represents one of the largest voluntary reallocations of cryptocurrency holdings to date, triggered by a security incident that exposed vulnerabilities in specific hardware signing devices.
The migration patterns observed by Casa indicate that the outflows originated from two distinct user groups. A significant portion came from holders previously relying on single-key setups with Ledger and Trezor devices who elected to upgrade to multi-signature security models. Additionally, existing multi-signature wallet operators moved to remove Coldcard devices from their signing quorums following the disclosure of the exploit, which has been characterized as a $130 million security breach Decrypt.
Rather than interpreting the mass exodus as evidence of self-custody’s fragility, Casa Chief Executive Officer Nick Neuman asserts that the rapid reallocation demonstrates the opposite. According to statements attributed to Neuman, the ability of thousands of individual holders to independently detect the threat and re-secure funds across distributed setups proves that self-custody operates as Bitcoin’s immune system—not a point of vulnerability. The event illustrated how the network’s decentralized architecture allows security-conscious participants to isolate compromised components without relying on centralized intermediaries to freeze or recover assets Bitcoin Magazine.
The incident has effectively served as an unplanned stress test for the broader self-custody infrastructure. As users transitioned away from potentially affected hardware—whether by abandoning single-key setups entirely or by swapping specific devices within existing multi-signature arrangements—the ecosystem exhibited a capacity for rapid self-correction. This behavioral response highlights a fundamental distinction between custodial platforms, where breaches might necessitate catastrophic platform-wide freezes or insolvency proceedings, and self-sovereign models where risk can be compartmentalized and mitigated through protocol-level redundancy.