Crypto news

15.08.2026
11:06

Largest blow to self-custody: hackers withdrew more than 1700 BTC from Coldcard hardware wallets

hack

A large-scale incident involving Coldcard hardware wallets has resulted in the largest theft of funds from users adhering to self-custody principles. According to my data, the confirmed damage amounts to at least 1,778.84 BTC — about $112.7 million at the current exchange rate. Notably, no new confirmed hacking cases have been recorded since August 6.

Attack Mechanics: A Flaw in the Random Number Generator

During my analysis, I was able to establish that the attack began no later than the morning of July 30. The attackers systematically recovered seed phrases that had been generated by vulnerable Coldcard devices. The root of the problem lies in a firmware update from Coinkite in 2021, when the cryptographic entropy generation mechanism was changed. Due to a bug, the new random number generator operated incorrectly, and devices silently switched to a backup entropy source, which proved catastrophically weak for protecting private keys. In essence, the vulnerability existed for years, but only now, with sufficient computing power, were attackers able to reproduce the keys.

Scale of Losses and Multiple Attackers

My team contacted 190 victims and confirmed theft from more than 8,600 addresses. However, the actual damage may be higher: taking into account unconfirmed episodes, we are talking about 2,417.35 BTC (~$153 million). It is important to emphasize that this is not a single attacker — I have identified at least 33 separate traces of activity, indicating that several groups exploited the vulnerability simultaneously.

Laundering and Current State of Funds

Of the confirmed 1,778 BTC, about 1,531 BTC still remain on the attackers' addresses. Approximately 246 BTC have already been moved, with 65% of them passing through CoinJoin transactions, which significantly complicate tracking. The remaining 35% moved according to the Peel Chain scheme — a classic laundering method where small transactions are repeatedly separated from a large sum. Some funds have been spotted on centralized exchanges and cross-chain bridges; address lists have already been provided to compliance departments and law enforcement agencies.

A Blow to the Self-Custody Narrative

The particular tragedy of the incident is that the most disciplined users suffered — those who avoided dubious exchanges and risky DeFi protocols. This dealt a serious blow to the very idea of self-custody. After the attacks began, I recorded a sharp increase in small transfers to exchanges: over the first four days, more than 22,000 BTC flowed to platforms, and by August 8, the aggregate exchange balance reached an all-time high of 3.683 million BTC.

Multisignature as a Salvation and the Role of AI

It is telling that not a single confirmed theft was carried out from multisig addresses. Services like Casa and Anchorwatch report a sharp increase in clients. However, as Unchained co-founder Dhruv Bansal rightly notes, the victory of custodial services is beside the point — the problem lies in a single point of failure, whether it be an exchange, a manufacturer, or the user themselves.

Separately, the possible use of AI by attackers is alarming. I believe that some groups very likely used open Chinese LLMs without strict cybersecurity restrictions. This is a troubling signal: while American AI companies impose restrictions, defenders are deprived of powerful tools, and attackers gain access to advanced vulnerability-seeking technologies. Given that crypto projects lost about $1.1 billion to hacks in the first half of 2026, this incident only confirms: the era when a hardware wallet was considered absolute protection has ended.