Crypto news

15.08.2026
11:26

Largest theft from hardware wallets: hackers stole more than 1700 BTC from Coldcard

hack

A large-scale attack on Coldcard hardware wallets has resulted in the largest confirmed losses this year: attackers stole at least 1,778.84 BTC, equivalent to approximately $112.7 million. According to my analysis based on fresh data from Galaxy Research, the last verified hack transaction dates to August 6, after which no new successful attacks were recorded.

Systemic bug in entropy generation

The key cause of the incident is an error in Coinkite's firmware introduced back in 2021. After an update, the cryptographic entropy generation mechanism began to malfunction: devices silently switched to an alternative source of randomness that proved fatally weak for protecting private keys. This allowed hackers, equipped with sufficient computing power, to reproduce seed phrases and systematically drain wallets starting July 30.

Researchers contacted 190 victims and confirmed theft from more than 8,600 addresses. However, the final figure could be higher: accounting for unconfirmed episodes, the stolen volume is estimated at 2,417.35 BTC (~$153 million). Notably, the attack was not a one-off — Galaxy identified at least 33 separate traces of activity, indicating coordinated exploitation of the vulnerability by several groups.

Money laundering and market reaction

Of the confirmed 1,778 BTC, about 1,531 BTC still remain on the attackers' addresses. Approximately 65% of these funds have passed through CoinJoin mixers, seriously complicating tracking, while another 35% moved via the Peel Chain scheme — a classic laundering method using microtransactions. A small portion of the coins has already surfaced on centralized exchanges and cross-chain bridges, and address lists have been shared with law enforcement and compliance companies.

This incident has dealt a significant blow to the narrative of self-custody. The victims are not inexperienced users, but those who deliberately avoided exchanges and DeFi risks, trusting "hardware." The market reaction was swift: in the first four days after the attacks began, more than 22,000 BTC flowed into exchanges, and the aggregate balance on platforms reached an all-time high of 3.683 million BTC by August 8.

Multisignature as salvation and the AI threat

Notably, no confirmed theft was carried out from multisig addresses. This has triggered a sharp surge in interest in such solutions: services Casa and Anchorwatch reported a spike in new clients. However, as Unchained co-founder Dhruv Bansal rightly notes, the victory of custodial services here is illusory — the problem lies in a single point of failure, whether it be an exchange, a manufacturer, or the user themselves.

Special attention deserves the likely use of AI by the attackers. Galaxy suggests that some of the perpetrators used Chinese open-source LLMs without cybersecurity restrictions. This is an alarming signal: the ability to search for vulnerabilities is becoming accessible not only to defenders but also to hackers, calling into question the effectiveness of traditional security measures.

My conclusion: this incident is not just a technical failure but a systemic challenge to the entire industry. It shows that even the most seemingly reliable solutions can contain hidden flaws, and trust in a single device is becoming an anachronism. I recommend users reconsider their storage approach in favor of multisignature and risk diversification before the market fully grasps the depth of the problem.