Crypto news

15.08.2026
14:20

Attack on Coldcard: 1778 BTC stolen, and it's a blow to the idea of self-custody

hack

A large-scale campaign against Coldcard hardware wallet owners has resulted in losses of at least 1,778.84 BTC — about $112.7 million at the current exchange rate. My colleagues at Galaxy Research confirmed the theft of funds from more than 8,600 addresses, having contacted 190 victims. The actual damage could be far more severe: factoring in unconfirmed incidents, we are talking about 2,417.35 BTC or roughly $153 million.

The root of the problem lies in a five-year-old vulnerability

The attack began on July 30, 2026. The attackers systematically recovered seed phrases generated by Coldcard devices and transferred funds to their own addresses. The cause was a firmware bug that Coinkite released back in 2021. The update changed the cryptographic entropy generation mechanism, but due to the bug, the random number generator worked incorrectly. Devices silently switched to an alternative entropy source, which proved critically weak for protecting private keys.

The problem existed for years but only manifested now: with sufficient computing power, hackers were able to reproduce keys created on vulnerable devices. The last confirmed chain of attacks dates to August 6. Since then, new victims have reached out to researchers, but no further confirmed hacks have occurred. Likely, owners managed to withdraw their funds, or most of the available coins have already been stolen.

Funds are moving through CoinJoin and Peel Chain

Of the confirmed 1,778 BTC, about 1,531 BTC still remain on the attackers' addresses. The remaining ~246 BTC have already been moved: 65% went through CoinJoin transactions, which complicate tracking, and 35% followed the Peel Chain scheme, where small transactions are repeatedly peeled off from a large amount. Some coins have been spotted on centralized exchanges and cross-chain bridges. Galaxy has already shared address lists with exchanges, compliance companies, and law enforcement.

A blow to the self-custody narrative

This incident is unique not only in scale. The victims are precisely those users who took the most responsible approach to storage: they did not use dubious exchanges or risky DeFi protocols, but trusted hardware wallets — the gold standard of security. Now this narrative has been undermined. After the attacks began, there was a sharp surge in transfers to exchanges: over four days, more than 22,000 BTC flowed in, and by August 8, the balance on platforms reached an all-time high of 3.683 million BTC.

Notably, no confirmed theft affected multisignature addresses. Services Casa and Anchorwatch report a surge in clients moving funds to multisig vaults. As Unchained co-founder Dhruv Bansal rightly notes, this is not a victory for custodial solutions, but a signal of the need to eliminate single points of failure — whether it be an exchange, a manufacturer, or the user themselves.

AI as an attacker's tool

The role of AI is particularly concerning. Galaxy believes that some attackers used open Chinese LLMs without cybersecurity restrictions. At the same time, researchers from Bitcoin Red Team, who audit the ecosystem's codebase, face the opposite problem: restrictions from American AI companies prevent them from using the most powerful models for defense. This is a dangerous imbalance that will only worsen.

Recall that the first half of 2026 already set a record for crypto hacks: projects lost about $1.1 billion. The Coldcard incident is not an isolated case but part of a systemic problem. The market needs to rethink its approach to security, or trust in self-custody will be permanently undermined.

My conclusion: this case is a vivid example of how "ironclad" security can turn out to be an illusion if there is a hidden defect in the key generation chain. For the industry, this is a reason to accelerate the adoption of multisignature schemes and firmware audits, and for users, a lesson: risk diversification matters more than blind faith in a single brand. For now, I recommend that all Coldcard owners immediately verify the origin of their seed phrases and, at the slightest doubt, move funds to new addresses.