Largest blow to self-custody: hackers withdrew 1778 BTC from vulnerable Coldcard hardware wallets

A large-scale attack on Coldcard hardware wallets has resulted in losses of at least 1,778.84 BTC — approximately $112.7 million at the current exchange rate. My colleagues at Galaxy Research have confirmed the theft of funds from more than 8,600 addresses, having contacted 190 victims. The actual damage could be significantly higher: if unconfirmed incidents are taken into account, we are talking about 2,417.35 BTC or roughly $153 million.
The root of the problem lies in a 2021 firmware error
The attack began on July 30, 2026. The attackers systematically recovered seed phrases generated by vulnerable devices. The cause was a bug in the firmware update from Coinkite: the new random number generator worked incorrectly, and devices imperceptibly switched to an entropy source with critically insufficient protection. The problem existed for years, but only now, with sufficient computing power, were hackers able to reproduce private keys.
Attacks have ceased, but the threat has not disappeared
The last confirmed chain of hacks dates to August 6. No new incidents have been recorded, but this more likely indicates that available funds have either already been stolen or owners managed to move them to new addresses. It is important to emphasize: these were not lone actors. I have found at least 33 additional traces of activity, pointing to coordinated exploitation of the vulnerability by several groups.
The fate of the stolen funds
Of the confirmed 1,778 BTC, about 1,531 BTC remain on the attackers' addresses, while 246 BTC have already been moved. A significant portion — 65% — passed through CoinJoin transactions, which seriously hinder tracking. Another 35% moved via the Peel Chain scheme, classic for laundering. A small share has been spotted on centralized exchanges and cross-chain bridges; address lists have already been provided to exchanges and law enforcement agencies.
A blow to the idea of self-custody
This incident strikes at the very essence of the self-custody narrative. The victims were not careless users taking risks on dubious platforms. They trusted hardware wallets, considered the gold standard of security. The consequences are tangible: in the first four days of the attacks, more than 22,000 BTC flowed into exchanges, and their aggregate balance reached an all-time high of 3.683 million BTC by August 8. This is a clear sign of panic and loss of trust.
Multisignature as salvation
It is telling that no confirmed theft affected multisig addresses. Services Casa and Anchorwatch are recording a sharp increase in clients moving to multisignature vaults. As Unchained co-founder Dhruv Bansal rightly notes, it is not about the victory of custodial solutions, but about eliminating a single point of failure — whether it be an exchange, a device manufacturer, or the user themselves.
AI on the hackers' side
I would separately note a worrying trend: some attackers likely used AI models without cybersecurity restrictions, including Chinese open-source LLMs. This creates an asymmetry: researchers from Bitcoin Red Team, on the contrary, face restrictions from American AI companies when trying to protect the ecosystem. Given that in the first half of 2026 crypto projects had already lost about $1.1 billion due to hacks, this case is merely the tip of the iceberg.
My conclusion: the Coldcard incident is not just another hack, but a systemic signal that even the most seemingly reliable solutions contain hidden risks. The market needs to rethink its approach to storage: risk distribution through multisignature and independent components is becoming not a recommendation, but a necessity. To users still holding funds on single-signature Coldcards, I strongly advise immediately migrating to new addresses.