Largest blow to self-custody: hackers withdrew more than 1700 BTC from Coldcard hardware wallets

A large-scale campaign against users of Coldcard hardware wallets has resulted in losses of at least 1,778.84 BTC — about $112.7 million at the current exchange rate. During the investigation, which I conducted jointly with the analytical team Galaxy Research, we confirmed the theft of funds from more than 8,600 addresses belonging to 190 victims. The actual damage is likely significantly higher: taking into account unconfirmed episodes, the volume of stolen funds could reach 2,417.35 BTC (~$153 million).
Root of the problem: an error in entropy generation
The attack began no later than the morning of July 30, 2026. The attackers systematically recovered seed phrases generated by vulnerable devices, after which they withdrew funds to addresses under their control. The cause lies in a 2021 Coinkite firmware update: due to a bug, the random number generator worked incorrectly, and the devices imperceptibly switched to an entropy source that proved critically insufficient for protecting private keys. The problem existed for years but only manifested now — with sufficient computing power, hackers were able to reproduce the keys.
Attacks have stopped, but bitcoins are going into the shadows
The last confirmed chain of hacks dates to August 6. After that date, new victims continue to contact analysts, but no confirmed cases of further exploitation of the vulnerability have been found. The attacks likely stopped either because owners managed to move their funds, or because available assets had already been exhausted. It is important to emphasize: this is not about a single hacker — I identified at least 33 separate traces of activity, indicating that several groups were exploiting the vulnerability simultaneously.
Of the confirmed 1,778 BTC, about 1,531 BTC remain on the attackers' addresses. The remaining ~246 BTC have already been moved: 65% passed through CoinJoin transactions, complicating tracking, and 35% followed the Peel Chain scheme, where small micro-transfers are repeatedly separated from large sums. A small portion of the funds was observed on centralized exchanges and cross-chain bridges; I have provided lists of addresses to compliance departments and law enforcement agencies.
A blow to the self-custody narrative
The distinctive feature of the incident lies in the victims' profile. These are not newcomers taking risks on DeFi protocols, but conservative bitcoin enthusiasts who trusted their assets to hardware wallets as the gold standard of security. The consequences were not long in coming: in the first four days of the attacks, more than 22,000 BTC flowed into exchanges, and by August 8, the total balance on platforms reached an all-time high of 3.683 million BTC. This is a clear signal of panic among holders.
Multisignature and AI as new risk factors
It is telling that not a single confirmed theft was carried out from multisig addresses. Services Casa and Anchorwatch recorded a sharp increase in clients, but, as Unchained co-founder Dhruv Bansal rightly notes, the victory of custodial solutions over non-custodial ones is a false dilemma. The problem lies in the single point of failure: whether it be an exchange, a manufacturer, or the user themselves. The incident forces a rethink of storage approaches in favor of distributing risk across multiple keys.
Separately, the use of AI is alarming. Some of the attackers, apparently, used Chinese open-source LLMs without cybersecurity restrictions, while Bitcoin Red Team researchers, on the contrary, faced blocks from leading American models. This is a troubling imbalance: the ability to find vulnerabilities is becoming more accessible to attackers than to defenders.
My comment: This incident is not just a technical failure, but a systemic challenge to the entire industry. If previously we relied on manufacturers' reputations and the complexity of attacks, now it is obvious: even "impenetrable" devices can have hidden defects that wait years for their moment. The market needs entropy audit standards and mandatory firmware testing by independent laboratories, otherwise trust in self-custody will be undermined for good. Against the backdrop of a record $1.1 billion in losses from hacks in the first half of 2026, this attack will become a turning point in the evolution of bitcoin storage.