Largest blow to self-custody: hackers withdrew 1778 BTC from Coldcard hardware wallets

A large-scale campaign against Coldcard hardware wallet owners resulted in the theft of at least 1,778.84 BTC, equivalent to $112.7 million. My colleagues at Galaxy Research have confirmed at least 190 victims and over 8,600 compromised addresses. Moreover, if unconfirmed incidents are taken into account, the actual damage could reach 2,417.35 BTC (~$153 million). No new confirmed hacks have been recorded since August 6.
The Root of the Problem: A Defective Entropy Generator
The attack began on July 30, 2026. The attackers systematically recovered seed phrases generated by vulnerable devices. The cause was a bug in Coinkite's 2021 firmware. The update changed the cryptographic entropy generation mechanism, but due to the bug, devices silently switched to a source with insufficient randomness. The problem existed for years, but only now did the attackers have the computational power to reproduce private keys.
Cessation of Attacks and Multiple Trails
Galaxy suggests that the attacks subsided either due to users migrating their funds or due to the exhaustion of "easy pickings." Importantly, this was not the work of a lone actor: researchers identified at least 33 separate activity trails, indicating that several groups were exploiting the vulnerability simultaneously. I strongly recommend that all owners of single-signature Coldcard wallets immediately move their assets.
The Fate of the Stolen Coins
Of the confirmed 1,778 BTC, approximately 1,531 BTC remain on the attackers' addresses. The remaining ~246 BTC have already been moved: 65% passed through CoinJoin to obfuscate trails, and 35% followed the Peel Chain scheme, where large amounts are broken down into micro-transactions. Some funds have been spotted on centralized exchanges and cross-chain bridges. Galaxy has shared the lists of addresses with exchanges and law enforcement.
Irony of Fate and a Blow to the Narrative
The main blow has been dealt to the ideology of self-custody. The victims are not reckless speculators, but conservatives who trusted "impregnable" hardware wallets. After the attacks began, a flood hit exchanges: in the first four days, more than 22,000 BTC, and by August 8, the balance on platforms reached an all-time high of 3.683 million BTC. This is a classic fear reaction.
Multisignature as Salvation
Notably, no confirmed theft affected multisig addresses. Services Casa and Anchorwatch are recording a sharp influx of clients. However, as Dhruv Bansal from Unchained rightly notes, the victory of custodial solutions is an illusion. The problem lies in a single point of failure, whether it be an exchange, a vendor, or the user themselves. Distributing risk across multiple keys is the only sensible path.
AI on the Side of Evil
Separately, I note an alarming signal: Galaxy with high probability links part of the attacks to the use of Chinese open-source LLMs without cybersecurity restrictions. While Bitcoin Red Team researchers suffer from censorship by American AI models, attackers gain access to powerful vulnerability-hunting tools. This only underscores that in the first half of 2026, losses from hacks have already reached $1.1 billion, and we will likely see new records.
My verdict: This incident is not just a technical failure, but a fundamental challenge to trust in hardware wallets. It proves that even "cold" storage is not absolute protection if there is a hidden defect in the key generation chain. Investors should reconsider their strategies: multisignature and infrastructure diversification are becoming not an option, but a necessity.