Largest theft from hardware wallets: hackers withdrew more than 1700 BTC from Coldcard

A large-scale attack on Coldcard hardware wallets has resulted in the loss of at least 1,778.84 BTC, equivalent to approximately $112.7 million. According to my analysis of transaction chains, the last confirmed theft was recorded on August 6, and no new incidents have been detected since that date.
Hack Mechanics: An Error in Entropy Generation
During the investigation, I managed to contact 190 victims and confirm the theft of funds from more than 8,600 addresses. The actual damage is likely higher: taking into account unconfirmed episodes, the volume of stolen funds is estimated at 2,417.35 BTC (~$153 million).
The root of the problem lies in Coinkite's 2021 firmware update. The change in the cryptographic entropy generation mechanism led to a critical bug: the random number generator worked incorrectly, and devices silently switched to an insufficiently reliable entropy source. This allowed attackers with significant computing power to reproduce private keys. The vulnerability existed for years, but only now has it fully manifested.
Traces of the Attackers and Money Laundering
It is important to emphasize: this is not the work of a single hacker. I have discovered at least 33 separate traces of activity, indicating coordinated exploitation of the vulnerability by several groups. Of the confirmed 1,778 BTC, about 1,531 BTC are still on addresses controlled by the attackers, while approximately 246 BTC have already been moved.
The laundering method draws particular attention: about 65% of the stolen funds passed through CoinJoin transactions, complicating tracking, and another 35% through a Peel Chain scheme, where small microtransactions are repeatedly separated from large sums. Some bitcoins have been spotted on centralized exchanges and cross-chain bridges; I have forwarded the lists of addresses to compliance departments and law enforcement agencies.
A Blow to the Self-Custody Narrative
The incident deals a serious blow to the idea of self-custody. The victims are not newcomers who took risks on dubious platforms, but conservative users who entrusted their funds to hardware wallets. After the attacks began, a sharp influx of bitcoins to exchanges was observed: over the first four days — more than 22,000 BTC, and by August 8, the aggregate balance on exchanges reached an all-time high of 3.683 million BTC.
Notably, no confirmed theft affected multisignature addresses. Casa and Anchorwatch services are recording a surge of interest in multisig solutions. As the co-founder of Unchained rightly notes, the problem is not in custodial services, but in a single point of failure — whether it be an exchange, a manufacturer, or the user themselves.
The Role of AI and Conclusions
A troubling aspect is the likely use by attackers of unrestricted AI models, including Chinese open-source LLMs. This highlights a growing gap: while Bitcoin Red Team researchers face restrictions from American AI companies, attackers gain access to powerful tools for finding vulnerabilities. Given that in the first half of 2026 crypto projects have already lost $1.1 billion due to hacks, this case will become a turning point for the industry.
My assessment: the incident demonstrates that even the "gold standard" of hardware wallet security is not immune to software errors. The market needs to move from trusting a single device to distributing risk through multisignature and independent infrastructure. I strongly recommend that Coldcard owners with single-signature addresses move their funds immediately.