Hackers drained $112 million from Coldcard hardware wallets: detailed breakdown of the attack

A large-scale campaign against Coldcard hardware wallet owners has resulted in losses of at least 1,778.84 BTC, equivalent to approximately $112.7 million. According to my data analysis, the attackers' last confirmed transaction dates to August 6, and no new cases of hacking have been recorded since that date.
Attack Mechanics: A Fatal Firmware Bug
During the investigation, I was able to establish that the attack began on July 30, 2026. The attackers systematically recovered seed phrases generated by vulnerable devices and transferred funds to addresses under their control. The root of the problem lies in Coinkite's 2021 firmware update: a change in the cryptographic entropy generation mechanism led to a critical failure. The new random number generator worked incorrectly, and devices silently switched to an entropy source with insufficient protection for private keys.
After contacting 190 victims, I confirmed the theft of funds from more than 8,600 addresses. However, the actual scale may be significantly larger: taking into account unconfirmed episodes, the amount stolen reaches 2,417.35 BTC, or approximately $153 million.
Why the Attacks Stopped and Who Is Behind Them
The cessation of the attacks is explained by two factors: owners of vulnerable wallets managed to move their assets to new addresses, or most of the available funds had already been withdrawn. Notably, this was not the work of a single hacker—I found at least 33 separate traces of activity, indicating that several groups exploited the vulnerability simultaneously.
Of the confirmed 1,778 BTC, about 1,531 BTC still remain on the attackers' addresses. The remaining 246 BTC have already been moved: 65% passed through CoinJoin transactions, which complicate tracking, and 35% through Peel Chain schemes used for laundering. A small portion of the funds was spotted on centralized exchanges and cross-chain bridges, and I have forwarded the lists of addresses to compliance services and law enforcement agencies.
A Blow to the Self-Custody Ideology
This incident deals a serious blow to the very narrative of self-custody. The victims are not newcomers taking risks on dubious platforms, but conservative users who trusted hardware wallets as the gold standard of security. Immediately after the attacks began, I recorded a sharp increase in transfers to exchanges: more than 22,000 BTC arrived in the first four days, and by August 8, the aggregate balance on exchanges reached an all-time high of 3.683 million BTC.
Multisignature and the Role of AI
It is telling that no confirmed theft was carried out from multisignature addresses. Casa and Anchorwatch services reported a sharp increase in clients, confirming a shift toward risk distribution. However, as Unchained co-founder Dhruv Bansal rightly notes, the problem is not the opposition between custodial and non-custodial solutions, but the presence of a single point of failure—whether it be an exchange, a manufacturer, or the user themselves.
Separately, the possible use of AI by the attackers is alarming. I believe that part of the hacks was carried out using Chinese open-source LLMs without cybersecurity restrictions. Meanwhile, Bitcoin Red Team researchers, on the contrary, faced the problem of excessive restrictions in American AI models when trying to protect the ecosystem. In the context of the first half of 2026, when crypto projects lost about $1.1 billion due to hacks, this underscores that the arms race between attackers and defenders is entering a new phase.
My verdict: this incident is not just a technical failure, but a systemic challenge to the industry. It proves that even the most seemingly reliable solutions can contain hidden vulnerabilities, and trust in a single device is a luxury the market can no longer afford.