Crypto news

15.08.2026
10:46

The biggest blow to self-custody: the Coldcard hack cost $112 million

hack

A large-scale hacking campaign targeting Coldcard hardware wallets has led to the loss of at least 1,778.84 BTC, equivalent to $112.7 million at the current exchange rate. My analysis of the data shows that this is not just another incident, but a systemic failure in the fundamental security principles of the crypto industry.

Timeline and scale of the attack

The attack began on the morning of July 30, 2026. The attackers systematically recovered seed phrases generated by vulnerable devices and transferred funds to addresses under their control. During the investigation, it was possible to contact 190 victims and confirm theft from more than 8,600 addresses. However, the actual damage could be significantly higher: taking into account unconfirmed episodes, the volume of stolen assets is estimated at 2,417.35 BTC, or approximately $153 million.

Root of the problem: an error in entropy generation

The cause lies in a firmware update released by the manufacturer Coinkite in 2021. A change to the cryptographic entropy generation mechanism led to a critical bug: the new random number generator worked incorrectly, and devices silently switched to an alternative entropy source that proved fatally insufficient for protecting private keys. The problem existed for years but only manifested now, when attackers gained enough computing power to reproduce the keys.

Cessation of attacks and new threats

The last confirmed chain of attacks dates to August 6. The attacks likely stopped either because owners moved funds to new addresses or because most of the available assets had already been stolen. It is important to note: this is not about a single attacker — at least 33 additional traces of activity have been detected, indicating that several groups were exploiting the vulnerability simultaneously.

Fate of the stolen funds

Of the confirmed 1,778 BTC, approximately 1,531 BTC still remain in the attackers' addresses. About 65% of these funds have passed through CoinJoin transactions, which seriously complicate tracking, while 35% were moved using the Peel Chain scheme — a method in which small transactions are repeatedly separated from a large amount. A small portion was spotted on centralized exchanges and cross-chain bridges, and lists of addresses have already been provided to law enforcement agencies and compliance companies.

Blow to the self-custody narrative

It is especially notable that the victims were users who approached self-custody with the utmost responsibility: they did not use dubious exchanges or risky DeFi protocols, but trusted hardware wallets — the gold standard of security. This incident has dealt a serious blow to trust in the concept of self-custody. After the attacks began, the number of transfers to exchanges surged: in the first four days, more than 22,000 BTC flowed to centralized platforms, and the aggregate balance reached an all-time high of 3.683 million BTC by August 8.

Growing interest in multisignature and the role of AI

It is telling that no confirmed theft was carried out from addresses protected by multisignature. Services like Casa and Anchorwatch are already reporting a sharp increase in clients. This confirms my long-standing position: a single point of failure — whether it be an exchange, a manufacturer, or the user themselves — is the main risk in the crypto industry. Distributing risk across multiple keys is becoming not a recommendation, but a necessity.

Special attention deserves the likely use of AI models by the attackers. Galaxy Research suggests that some of the attackers used Chinese open-source LLMs without strict cybersecurity restrictions. This is an alarming signal: as AI spreads, the capabilities for finding and exploiting errors become more accessible not only to defenders, but also to attackers.

My verdict: this incident is not just a statistic of losses, but a turning point for the entire industry. It proves that even the most reliable-looking solutions can contain hidden fatal vulnerabilities. Investors and custodians should reconsider their strategies, prioritizing multisignature schemes and risk diversification. In an era when AI strengthens both sides of the barricades, the only reasonable strategy is to assume that your current level of protection may be insufficient.