Crypto news

15.08.2026
11:47

Largest theft from hardware wallets: hackers stole more than 1,700 BTC due to a fatal bug in Coldcard

hack

A large-scale incident that shook the Bitcoin maximalist community has received official confirmation. As a result of exploiting a critical vulnerability in Coldcard hardware wallets, attackers stole at least 1,778.84 BTC, equivalent to $112.7 million. Monitoring conducted by my team shows that new hacking cases ceased after August 6, but this is no reason for complacency — the picture of the incident is much deeper than it seems at first glance.

Attack on Coldcard: Timeline and Scale

During the investigation, contact was established with 190 victims and the theft of funds from more than 8,600 addresses was confirmed. At the same time, the actual damage could be significantly higher: if unconfirmed episodes are included in the calculation, the amount stolen rises to 2,417.35 BTC (~$153 million). The attack began on the morning of July 30, 2026. The attackers systematically recovered seed phrases generated by vulnerable devices and then instantly withdrew funds.

The root of the problem lies in an error made by the manufacturer Coinkite back in 2021. At that time, the company updated its firmware, changing the cryptographic entropy generation mechanism. Due to a bug, the new random number generator worked incorrectly, and devices silently switched to an alternative entropy source, which turned out to be catastrophically weak for protecting private keys. The problem existed for years but only manifested now, when attackers gained enough computing power to reproduce the keys.

Cessation of Attacks and New Threats

The last confirmed chain of attacks dates to August 6. Since then, new victims have continued to contact researchers, but there are no more confirmed hacks. Likely reasons include the migration of funds to new addresses or the exhaustion of the available pool of coins. To users who still hold bitcoins on single-signature Coldcard devices, I strongly recommend immediately moving their assets.

An important nuance: the attack was not a single event. My analysis has identified at least 33 separate traces of activity, indicating the simultaneous exploitation of the vulnerability by several independent groups. This turns the incident from a targeted hack into a systemic threat.

Fate of the Stolen Funds

Of the confirmed 1,778 BTC, about 1,531 BTC remain under the control of the attackers. Another 246 BTC have already been moved. Notably, 65% of the funds passed through CoinJoin transactions, which seriously complicate tracking. The remaining 35% moved according to the Peel Chain scheme — a classic laundering technique where small transactions are repeatedly split off from a large amount. A small portion of the coins was spotted on centralized exchanges and cross-chain bridges; address lists have already been provided to compliance departments and law enforcement agencies.

Blow to the Self-Custody Narrative

This incident is not just a financial loss. The victims are those very users who took the most responsible approach to self-custody: no dubious exchanges, no risky DeFi, only hardware wallets. The blow to trust was instantaneous: in the first four days after the attacks began, more than 22,000 BTC were deposited into exchanges, and the aggregate balance of centralized platforms reached an all-time high of 3.683 million BTC by August 8.

It is telling that no theft was committed from multi-signature addresses. Services Casa and Anchorwatch have already reported a sharp increase in clients. However, as experts like Dhruv Bansal from Unchained rightly note, the problem is not custodians versus non-custodians, but a single point of failure — whether it be an exchange, a hardware manufacturer, or the user themselves. Multi-signature distributes risk, and it is this approach that is becoming the new security standard.

AI as an Escalation Factor

Separately, I will note a worrying trend: some attackers likely used AI models without cybersecurity restrictions, including Chinese open-source LLMs. At the same time, Bitcoin Red Team researchers faced the opposite problem — restrictions from American AI companies hinder the use of the most powerful models to protect the codebase. This creates an asymmetry: attackers gain access to advanced tools faster than defenders.

Against the backdrop of crypto projects losing about $1.1 billion to hacks in the first half of 2026, with a record number of exploits, this case will become a turning point. The market is forced to rethink the very philosophy of security: trust in a single device is giving way to multi-layered protection, and the role of AI in cyber warfare will only grow.

My verdict: the Coldcard incident is not an accident, but a natural outcome of manufacturer negligence and the evolution of attacks. Investors should view this as a signal to diversify keys and infrastructure, rather than a reason to abandon self-custody in favor of custodians.