Crypto news

15.08.2026
14:39

Attack on Coldcard: firmware vulnerability results in $112 million loss in bitcoins

hack

A large-scale hacking campaign targeting Coldcard hardware wallets has resulted in the theft of at least 1,778.84 BTC, equivalent to $112.7 million. My colleagues at Galaxy Research confirmed this damage by contacting 190 affected users. It is important to emphasize: the attacks ceased after August 6, but the final figure could rise to 2,417.35 BTC (~$153 million) if still-unconfirmed incidents are taken into account.

The root of the problem lies in a five-year-old bug

The attack began on July 30, 2026. The attackers systematically recovered seed phrases generated by vulnerable devices and transferred funds to their own addresses. The cause is a critical error in the Coinkite firmware released in 2021. The update changed the cryptographic entropy generation mechanism, but due to a bug, the random number generator operated incorrectly, silently switching to an insufficiently secure source.

In essence, a time bomb was ticking for years. With sufficient computing power, hackers were able to reproduce private keys. This is not an isolated case: Galaxy identified traces of at least 33 different attackers, indicating simultaneous exploitation of the vulnerability by several groups.

Laundering and market reaction

Of the stolen funds, approximately 1,531 BTC remain under the attackers' control. Around 246 BTC have already been moved, with 65% passing through CoinJoin transactions, which complicate tracking, and 35% through Peel Chain schemes, a classic laundering method. Some coins have been spotted on centralized exchanges and cross-chain bridges; Galaxy has already submitted lists of addresses to law enforcement and compliance companies.

The incident dealt a serious blow to the self-custody narrative. The victims were not novices taking risks on DeFi platforms, but conservative holders who trusted "hardware." The result was panic: in the first four days of the attacks, more than 22,000 BTC flowed into exchanges, and by August 8, the balance on platforms reached an all-time high of 3.683 million BTC.

A new reality: multisignature and AI

Notably, no confirmed theft was carried out from multisignature addresses. Services like Casa and Anchorwatch are already recording a sharp increase in clients. This is a logical conclusion: a single point of failure—whether it be an exchange, a manufacturer, or the user themselves—is unacceptable.

The role of AI deserves special attention. Galaxy believes that some attackers used Chinese open-source LLMs without cybersecurity restrictions. Ironically, Bitcoin Red Team researchers, on the contrary, faced blocks from American AI companies, hindering defense efforts. Against the backdrop of $1.1 billion in losses for the first half of 2026, this case is a wake-up call for the entire industry.

My verdict: this incident is not just a technical failure, but a fundamental challenge to the idea of "not your keys, not your coins." Even the most reliable-looking solutions may have hidden defects, and diversifying risk through multisignature is becoming not an option, but a necessity. The market is already voting with bitcoins, and this is only the beginning of the restructuring.