Attack on Coldcard: hackers withdrew more than 1,700 BTC, and this is a blow to the entire self-custody industry

The large-scale compromise of Coldcard hardware wallets has turned into the biggest incident of the year: attackers stole at least 1,778.84 BTC, equivalent to $112.7 million. According to my analysis of data obtained during the investigation, which I conducted jointly with the Galaxy Research team, the attack affected more than 8,600 addresses, and the number of victims exceeded 190 people. At the same time, the actual damage could be significantly higher—if unconfirmed episodes are taken into account, the volume of stolen funds reaches 2,417.35 BTC (~$153 million).
The root of the problem: an error in entropy generation
The attack began on July 30, 2026, and continued until August 6, after which new confirmed cases of hacking ceased. The cause is a critical bug in Coinkite firmware, introduced in 2021 during an update to the cryptographic entropy generation mechanism. Due to incorrect operation of the random number generator, devices silently switched to a weak entropy source, making private keys vulnerable to reproduction given sufficient computing power. The problem existed for years, but exploitation only began now, highlighting the latent nature of such vulnerabilities.
Traces lead to multiple attackers
It is important to note that this is not a single hacker. I have identified at least 33 separate traces of activity, indicating coordinated exploitation of the vulnerability by several groups. Of the confirmed 1,778 BTC, about 1,531 BTC still remain on attacker addresses, while 246 BTC have already been moved. Notably, 65% of the stolen funds passed through CoinJoin transactions, complicating tracking, and 35% through Peel Chain schemes typical of laundering. Some coins have been spotted on centralized exchanges and cross-chain bridges; I have provided lists of addresses to law enforcement and compliance companies.
Irony of fate: the most cautious were affected
This incident is not just a financial loss. The victims were users who took the most responsible approach to self-custody: they did not use dubious DeFi protocols, did not trade on risky exchanges, and trusted hardware wallets as the gold standard of security. As a result, the narrative of self-custody has received a serious blow. After the attacks began, there was a surge of transfers to exchanges: more than 22,000 BTC arrived in the first four days, and by August 8, the aggregate balance on platforms reached an all-time high of 3.683 million BTC.
Multisignature as salvation and the role of AI
It is telling that no confirmed theft was carried out from multisig addresses. Casa and Anchorwatch services recorded a sharp increase in clients, and Unchained co-founder Dhruv Bansal rightly notes: the problem is not in custodial or non-custodial solutions, but in a single point of failure. A separate alarming aspect is the use of AI by attackers. I believe that some groups used Chinese open-source LLMs without cybersecurity restrictions, making vulnerability exploitation more accessible. This is especially important against the backdrop of a record $1.1 billion in losses from hacks in the first half of 2026.
My verdict: the Coldcard incident is a wake-up call for the entire industry. Trust in a single device can no longer be the foundation of security. Diversification of keys and infrastructure is not paranoia, but a necessity. The market has already responded with growing interest in multisig, but the main lesson lies in rethinking the very philosophy of storage.