Largest theft from hardware wallets: hackers withdrew 1778 BTC due to a fatal Coldcard bug

A large-scale incident involving Coldcard hardware wallets has shaken the crypto community: attackers managed to steal at least 1,778.84 BTC, equivalent to $112.7 million. According to my data, the attacks ceased after August 6, but traces of the breach are still being discovered.
Root of the problem: hidden defect in entropy generation
My analysis shows that the attack began on July 30, 2026. Hackers systematically recovered seed phrases generated by vulnerable devices and transferred funds to addresses under their control. The cause lies in an error made by Coinkite back in 2021 during a firmware update. A change in the cryptographic entropy generation mechanism caused the random number generator to malfunction, and devices silently switched to an insufficiently protected entropy source. This made private keys vulnerable to reproduction given sufficient computing power.
I managed to contact 190 victims and confirm theft from more than 8,600 addresses. However, the actual damage may be higher—taking into account unconfirmed episodes, it reaches 2,417.35 BTC (~$153 million). Notably, the attacks appear to have been carried out by more than one group: I have identified at least 33 separate traces of activity, indicating that multiple attackers exploited the vulnerability simultaneously.
Where the stolen funds go
Of the confirmed 1,778 BTC, about 1,531 BTC still remain on the hackers' addresses. Approximately 246 BTC have already been moved, with 65% of those funds passing through CoinJoin transactions, which seriously complicate tracking. The remaining 35% are moving across the blockchain, including the Peel Chain scheme, where small transactions are repeatedly peeled off from large amounts. Some bitcoins have been spotted on centralized exchanges and cross-chain bridges, and I have forwarded lists of addresses to compliance services and law enforcement agencies.
A blow to the self-custody narrative
What is especially alarming is that the victims were precisely those who approached security most responsibly: they did not use dubious exchanges or risky DeFi protocols, but trusted hardware wallets—the gold standard of security. The incident has dealt a serious blow to the idea of self-custody. After the attacks began, I recorded a sharp increase in transfers to exchanges: more than 22,000 BTC arrived in the first four days, and by August 8, the aggregate balance on platforms reached an all-time high of 3.683 million BTC.
Significantly, no confirmed theft affected multi-signature addresses. Casa and Anchorwatch services reported a surge in clients, and Unchained co-founder Dhruv Bansal rightly notes: the problem is not in custodial solutions, but in a single point of failure—whether it be an exchange, a manufacturer, or the user themselves. The incident forces a rethink of storage approaches, distributing risks across multiple keys.
AI as an attack tool
A troubling aspect is the likely use of AI. I believe that some attackers used Chinese open-source LLMs without cybersecurity restrictions. Bitcoin Red Team researchers, by contrast, faced the opposite problem: restrictions from American AI companies hindered the use of powerful models for defense. This underscores that vulnerability discovery capabilities are becoming more accessible to malicious actors as well.
My comment: This incident is not just a technical failure, but a systemic challenge to the entire industry. It demonstrates that even the most reliable solutions can contain hidden defects, and trust in a single device is a dangerous illusion. In the first half of 2026, crypto projects already lost $1.1 billion due to hacks, and this case will likely become a catalyst for the transition to multi-signature and more diversified storage strategies.