Moving Is Not Selling

TL;DR A flaw in a popular wallet device is pushing owners to move their coins to fresh wallets. Moving a coin is not selling it. But two of this dashboard's thirteen gauges cannot tell the difference. Both rest on a figure that values every coin at the price it last moved. Move a coin, and the figure changes, though nobody bought and nobody sold. So the question is how much moving it would take to change what the dashboard says. The answer is far more than this event, and far more than any event. To shift the weaker of the two gauges by one grade, at least 862,812 coins would have to move in a single day. That is one coin in every twenty-three that exists. The theft that started all this took up to 1,300. The entire day's flow to exchanges was 11,163. The gauge is safe by a factor of 77. That is the good news, and it is worth more than the news that prompted it, because it holds for any future stampede as well. The test did turn up a real problem. It was not the flaw. Both gauges are being fed by a file that stopped updating on 23 May, 71 days before the price shown next to them. Nothing on the page says so, and the two of them still count for 13.1 percent of the score.

On 1 August 2026 the makers of the Coldcard, a hardware wallet that keeps bitcoin keys off the internet, told their customers to move their money. Wallets the device had created, on affected models going back to March 2021, were not as random as they were meant to be. The fix was not a patch. It was to update the firmware, make a brand new wallet, and send every coin to it.

Owners started doing exactly that. And in doing so, each of them quietly nudged two of the gauges on this dashboard.

This article covers three things. How an ordinary wallet move can shift a reading that is supposed to be about buying and selling. How large such a move would have to be before the dashboard changed its mind. And what turned up while measuring that, which was not what this article set out to find.

How a Move Becomes a Number

Two of the thirteen gauges here, MVRV and NUPL, try to answer one question: are the people holding bitcoin sitting on a profit, and how big a one? Answering it means knowing what they paid. Nobody does. So the trade is estimated with a stand-in called realized capitalization, and the stand-in works like this. Take every coin in existence. Ask what the price was on the day that coin last changed hands. Value it at that price. Add it all up.

It is a clever trick and it is the best available. It also has one honest weakness, and the weakness is the whole of this article. Realized cap does not know why a coin moved. It only knows that it moved.

So picture a man who bought bitcoin in 2017 and has not touched it since. His coins are carried on the books at 2017 prices. On Friday he reads the Coldcard notice, buys nothing, sells nothing, and sends his coins from one wallet he owns to another wallet he owns. Nothing has happened. His holdings are identical. Yet realized cap now carries those coins at Friday's price, and the sum jumps. Both gauges move. The dashboard concludes that holders are less deep in profit than it thought, and it is wrong, because moving is not selling.

Worth pausing on one detail before going further, because it changes the arithmetic later. MVRV and NUPL look like two independent opinions. They are not. On this site NUPL is calculated straight from MVRV, by the formula one minus one over MVRV. One is a rearrangement of the other. They are a single measurement shown twice, and between them they carry 13.1 percent of the composite score. Anything that bends one bends the other, in step, by construction.

How Much Moving It Would Take

That is the mechanism. Now the size of it, which is the part that decides whether any of this matters.

The gauges are not read as raw numbers. Each is sorted into a letter grade with fixed boundaries, and only the letter reaches the score. So contamination is harmless until it pushes a reading across a boundary. That turns a vague worry into a question with an answer: the number of coins that must move, in one day, to shift a letter.

On the most recent on-chain reading available here, 23 May 2026, bitcoin's market value was $1.5350 trillion and its realized cap $1.0851 trillion. Spread over the 20,033,382 coins then in existence, that puts the average coin on the books at $54,165, against a price of $76,620. MVRV stood at 1.4146, a B. NUPL at 0.2931, a C.

NUPL is the nearer of the two to a boundary, so it falls first. Its next grade sits at a realized cap high enough to require 2,944,061 coins to move in one day, assuming those coins are typical ones carried at the average price. Almost fifteen percent of every bitcoin there is.

That assumption can be attacked, so it is worth removing. Old coins are carried at old prices, and old coins are exactly the ones a flaw dating to March 2021 would flush out, so a migration might be unusually potent per coin. Push that objection to its absolute limit. Suppose every migrating coin were carried at zero, the cheapest any coin can possibly be held at, which maximises the jolt each one delivers. The requirement falls to 862,812 coins. It cannot fall further, whatever the coins turn out to be. One in twenty-three of all bitcoin, moving inside a single day.

Against that, the event. Blockchain analysts at Timechainindex counted 11,163 coins moving on to exchanges on 31 July, the busiest day, a figure reported by CoinDesk on 2 August. Treat all of it as migration, which is generous, since ordinary trading is mixed in. It is 77 times too small to move NUPL, and 526 times too small to move MVRV. The theft that triggered the panic, put at 1,000 to 1,300 coins in the same report, is smaller again: 664 times short.

Put in money, the largest of those numbers re-prices $0.855bn of a $1.0851 trillion total. Under eight hundredths of one percent. An ordinary, uneventful day in the past year moved realized cap by the equivalent of 4,949 coins re-priced at the going rate, so the busiest day of a global custody scare registers as 2.3 times a median day. Busy. Not remarkable.

The honest caveat is that these thresholds are not fixed. They collapse whenever a reading happens to be sitting on top of a boundary, and on those days a small push does travel. Run every one of the 5,789 days of on-chain history and count them. A migration the size of 31 July's would have flipped NUPL's grade on 18 of them, and MVRV's on 18 as well, which is 0.31 percent each, about one day in three hundred. A hundred thousand coins, a plausible size for a large custodian re-keying itself, would have reached NUPL's boundary on 192 days, or 3.3 percent, and MVRV's on 140. So the correct statement is not that these gauges are immune. It is that they are safe on roughly 997 days out of a thousand, and that the day to worry about is the day a reading is already balanced on an edge.

What the Test Found Instead

All of the above is reassuring, and it is also beside the point, which only became clear at the end.

Note the date on the reading above: 23 May. Not August. The file that feeds MVRV and NUPL stopped receiving new on-chain data on 23 May 2026, and the price shown beside them on the same page is current to 2 August. Seventy-one days apart.

The natural assumption is that a gauge with no fresh data goes dark, and this site is built to do that. Missing gauges are dropped from the composite rather than filled in with a guess. But that is not what happens here, because the data is not missing. It is old. The code that loads the file discards rows it cannot read and keeps the last good one. The code that grades reads the last row it is handed and does not ask what day it is from. So MVRV and NUPL are not absent from today's reading. They are present, confident, carrying full weight, and reporting a market that existed in May.

Which lands the article's own finding on its own head. The migration cannot bend these two gauges, and that turns out not to matter, because for the past 71 days nothing could. A gauge cannot be misled by this week's events if it has not heard about them.

The irony is worth stating plainly rather than hurrying past. This piece went looking for a subtle way that real on-chain activity might corrupt a measurement, found the effect genuine but roughly two orders of magnitude too small to reach the score, and in the course of checking discovered that the same measurement had been quietly frozen since spring. The exotic risk was negligible. The dull one was live. That is usually how it goes, and it is the reason for running the arithmetic instead of arguing about it.

An article published here on 31 July already noted that the on-chain series ended on 23 May, and was careful to say so wherever it used those numbers. What was not noticed then is that the stale figures do not merely limit what an article can claim. They are still being served to every visitor, on the front page, with a current timestamp beside them.

What to Take Away

Three numbers, and one repair.

The first is 862,812. That is the floor, in coins, on a one-day migration large enough to shift either of these two grades, and it is a floor rather than an estimate, because it already assumes the most damaging coins imaginable. Moving is not selling, and this is the number that says how much moving it would take before the dashboard stopped noticing the difference. It generalises well past this wallet flaw. An exchange re-keying its cold storage, a custodian consolidating, a future scramble to move coins for whatever reason: measure it against 862,812 and the answer is available before the argument starts.

The second is 77. That is how many times larger the Coldcard migration would have to have been to reach the floor, taking the whole of the busiest day's exchange flow and generously calling all of it migration. There is no story here about the news bending the dashboard. There was never going to be, and it is better to have the ratio than the reassurance.

The third is 0.31 percent. That is the share of the past sixteen years on which a migration of that size would have flipped a grade, because the reading was already resting on a boundary. Small, real, and the only version of this worry that survives the arithmetic. Grades built on thresholds are always most fragile at the threshold.

The repair is the one this article did not go looking for. Two gauges are being graded from a file 71 days stale, at 13.1 percent of the composite, with nothing on the page to say so. The fix is a recency check in the loading code, so an on-chain reading past a sensible age is marked unavailable and drops out, exactly as a missing one already does. Until that ships, the reading on the front page is thirteen percent May.

Every figure above comes from one pass over this site's own price and on-chain history, in ml/research/realized_cap_migration.py. Run python3 ml/research/realized_cap_migration.py to reproduce all of them, including the one that argues against the article's own premise.

Sources and Limits

The wallet flaw is described by Coinkite, the manufacturer, in its advisory of 1 August 2026. It affects Mk2 and Mk3 units on firmware 4.0.1 through 4.1.9, and Mk4, Mk5 and Q units on firmware older than the fixed releases. For the latter group the company quantifies the damage: about 72 bits of entropy where 128 were intended. For Mk2 and Mk3 it gives no such figure, and none is invented here. Coinkite publishes no count of affected devices, users, or coins.

Loss estimates do not agree. CoinDesk reported 1,000 to 1,300 coins, roughly $70m to $90m, across more than a thousand addresses, on 2 August. Other tallies circulating that week were larger. The figures used above are CoinDesk's, dated, and the disagreement is left standing rather than averaged away.

The exchange-flow figures are vendor analytics and cannot be checked against anything in this repository. The 11,163 coins are Timechainindex's count via CoinDesk. CryptoQuant separately put deposits in transfers under 10 coins at 7,300 on 31 July, its highest since 6 February, and its head of research, Julio Moreno, wrote that this "could be related to the coldcard hack". That hedge is his, and it is kept.

Three things this article does not claim. That the migration is ongoing: the number of bitcoin addresses in use reached 620,856 on 31 July, against a range of 386,348 to 541,679 over the previous fortnight, and fell back to 527,596 the next day. That is one busy day, not a trend. That the busy day was all migration: address counts and exchange flows include everybody else, and no method here separates them, which is why the event figures are used only as upper bounds. And that any of this says anything about where the price goes, which it does not, and which is not what these gauges are for.