Crypto news

15.08.2026
10:26

The biggest blow to self-custody: the Coldcard hack resulted in the loss of 1778 BTC

hack

A massive attack on Coldcard hardware wallets has led to unprecedented losses: the theft of at least 1,778.84 BTC, equivalent to $112.7 million, has been confirmed. However, based on my data, the final figure could be much higher — taking unconfirmed incidents into account, we are talking about 2,417.35 BTC (~$153 million). It is important to note that no new successful hacks have been recorded since August 6.

My analysis of the incident shows that this is not an ordinary theft, but a systemic flaw embedded years earlier. In 2021, the manufacturer Coinkite updated the firmware, changing the entropy generation mechanism. Due to a bug, the random number generator worked incorrectly, and devices silently switched to an entropy source that proved catastrophically weak for protecting private keys. The problem remained hidden for several years, but attackers with sufficient computing power were able to reproduce the keys and systematically drain wallets starting July 30, 2026.

The attack has stopped, but the residue remains

Galaxy Research contacted 190 victims and confirmed theft from more than 8,600 addresses. The cessation of attacks is explained either by users managing to move their funds or by available assets being exhausted. Notably, traces of activity suggest that at least 33 different attackers were involved — several groups exploited the vulnerability simultaneously.

Of the stolen 1,778 BTC, about 1,531 BTC remain on hackers' addresses. The remaining 246 BTC are being actively laundered: 65% went through CoinJoin, and 35% through Peel Chain schemes. A small portion has been spotted on centralized exchanges and cross-chain bridges, and address lists have already been shared with regulators and exchanges for blocking.

A blow to the self-custody narrative

This incident is not just a financial loss. The victims were precisely those users who took the most responsible approach to self-custody: they did not use dubious exchanges or risky DeFi protocols, but trusted hardware wallets as the gold standard of security. Now that narrative is undermined. After the attacks began, a sharp influx of bitcoins to exchanges was observed: more than 22,000 BTC flowed in over the first four days, and by August 8, the balance on centralized platforms reached an all-time high of 3.683 million BTC.

Notably, no confirmed theft affected multi-signature addresses. This has sparked a surge of interest in multisig solutions: services Casa and Anchorwatch reported growth in clients. However, as Unchained co-founder Dhruv Bansal rightly notes, the victory of custodial services here is not absolute. The problem lies in a single point of failure, whether it be an exchange, a manufacturer, or the user themselves.

AI as a new threat factor

Separately, I would note an alarming signal: some attackers likely used AI models without cybersecurity restrictions, including Chinese open-source LLMs. This underscores that tools for finding and exploiting vulnerabilities are becoming more accessible not only to researchers but also to malicious actors. Given that in the first half of 2026 crypto projects already lost $1.1 billion due to hacks, this case is a stark reminder that even the most reliable solutions require reconsideration.

My verdict: the Coldcard incident is not just a technical failure, but a tectonic shift in the perception of security. Relying on a single hardware wallet means ignoring risks we cannot foresee. The distribution of keys and infrastructure is the only sensible path forward.