Largest theft from hardware wallets: 1778 BTC leaked through Coldcard vulnerability

A large-scale incident that shook the bitcoin maximalist community has received official confirmation. As a result of the exploitation of a critical vulnerability in Coldcard hardware wallets, attackers withdrew at least 1,778.84 BTC, equivalent to $112.7 million at the current exchange rate. Monitoring shows that new confirmed attacks ceased after August 6, but the full picture of the damage could be significantly worse.
Attack on Coldcard
I managed to establish contact with 190 affected holders, and the total amount of confirmed losses is distributed across more than 8,600 addresses. If unconfirmed episodes are included in the calculation, the volume of stolen funds rises to 2,417.35 BTC — approximately $153 million. This makes the incident one of the largest in history, if not the most extensive, among attacks on hardware wallets.
The attack began on the morning of July 30, 2026. The attackers systematically recovered seed phrases generated by vulnerable Coldcard devices, after which they transferred funds to addresses under their control. The root of the problem is a firmware error made by Coinkite in 2021 when updating the cryptographic entropy generation mechanism. The new random number generator worked incorrectly, and devices silently switched to a backup entropy source that proved critically weak for protecting private keys.
In essence, a time bomb existed for years but only detonated now: with sufficient computing power, the attackers were able to reproduce private keys created on vulnerable devices.
Cessation of attacks and new traces
Analysis of confirmed transaction chains shows that the last successful attack dates to August 6. New victims continue to come forward, but no confirmed cases of further hacking have been found. This is explained either by the fact that owners of vulnerable wallets managed to move funds to new addresses, or by the fact that most of the available assets had already been withdrawn.
It is important to emphasize: this is not the work of a single hacker. I have identified at least 33 separate traces of activity, which with high probability indicates the simultaneous exploitation of the vulnerability by several groups of attackers.
The fate of the stolen funds
Of the confirmed 1,778 BTC, about 1,531 BTC are still on addresses controlled by the hackers. Another 246 BTC have already been moved after the theft. Notably, 65% of these funds passed through CoinJoin transactions, which seriously complicates tracking. The remaining 35% are moving across the blockchain, including the Peel Chain scheme, where small transactions are repeatedly "peeled off" from a large amount, while the bulk is transferred to new addresses.
A small portion of the stolen bitcoins has been spotted on centralized exchanges and cross-chain bridges. I have provided lists of addresses to exchanges, compliance companies, and law enforcement agencies for further action.
A blow to the idea of self-custody
The peculiarity of this incident lies not only in the scale of the losses. The victims were users who took the most responsible approach to self-custody: they did not use dubious exchanges, risky DeFi protocols, or high-yield schemes. They trusted hardware wallets, which were considered the gold standard of security.
This dealt a serious blow to the narrative of self-custody. After the attacks began, the number of small bitcoin transfers to exchanges surged: more than 22,000 BTC flowed to centralized platforms in the first four days. By August 8, the aggregate balance on exchanges reached an all-time high of 3.683 million BTC.
Multisignature as a solution
An unexpected consequence was the growing interest in multisig wallets. No confirmed theft was carried out from addresses protected by multisignature. Casa and Anchorwatch services reported a sharp increase in new clients and volumes of transferred bitcoins.
Unchained co-founder Dhruv Bansal rightly notes: perceiving what happened as a victory of custodial services over non-custodial ones is a mistake. The problem lies in a single point of failure, whether it be an exchange, a device manufacturer, or the user themselves. The incident forces a rethink of storage approaches: distributing risk across multiple keys and independent infrastructure components is becoming not a recommendation, but a necessity.
The role of AI in the attack
A separate alarming aspect is the use of artificial intelligence. I believe that some of the attackers with high probability used AI models without strict cybersecurity restrictions, in particular Chinese open-source LLMs. This confirms a worrying trend: tools for finding and exploiting errors are becoming more accessible not only to defenders, but also to attackers.
In the first half of 2026, crypto projects had already lost about $1.1 billion due to hacks, and this incident became another record in a series of exploits. The situation requires the industry not just point fixes, but a fundamental revision of security standards.
My conclusion: this case is not an anomaly, but a warning. If hardware wallet manufacturers do not implement multi-layered protection and independent code audits, trust in the very institution of self-custody could be undermined irreversibly. Multisignature is not a panacea, but today it is the only proven way to avoid a single point of failure.