The Coldcard hardware wallet breach has triggered a far larger wave of Bitcoin movement than the amount believed to have been directly stolen, with roughly $15 billion shifted after the exploit surfaced as users reacted to the security risk. The incident has sharpened debate over self-custody because the available reporting does not yet establish whether the largest transfers were attacker-driven, precautionary relocations by holders, or a mix of both. The flaw has been tied to Coldcard seed generation, and Coinkite has warned users about conditions under which wallet keys could be exposed. TRM Labs described the episode as the largest hardware wallet exploit of 2026. Estimated direct exposure has been placed in the nine figures, with potential losses nearing $114 million, a figure distinct from the much larger volume of Bitcoin that was moved on-chain after the disclosure. Large transfers of this kind do not by themselves indicate selling. Coins moved to fresh addresses may reflect users shifting funds into safer setups, a reading consistent with reporting that linked the surge in movement to safety-driven activity and with a rise in new Bitcoin addresses around the incident. Analysts and holders are now watching for follow-up movement from the same addresses, any confirmation from Coinkite, and whether affected coins reach exchange deposit addresses, which would provide a clearer signal of intent to sell. The episode has also renewed scrutiny of self-custody practices, including whether air-gapped wallets are sufficient protection when seed generation or storage is flawed.