Largest theft from hardware wallets: hackers withdrew more than 1700 BTC from Coldcard

A large-scale attack on Coldcard hardware wallets has resulted in the largest confirmed losses in this segment: attackers siphoned off at least 1,778.84 BTC, equivalent to $112.7 million. My colleagues at Galaxy Research contacted 190 victims and verified the theft of funds from more than 8,600 addresses. Actual losses may be higher—including unconfirmed incidents, the figure stands at 2,417.35 BTC (~$153 million).
The root of the problem lies in a 2021 firmware bug
The attack began on July 30, 2026. Hackers systematically recovered seed phrases generated by vulnerable devices and transferred funds to their own addresses. The cause was an error in the Coinkite firmware update released in 2021. A change to the entropy generation mechanism led to incorrect operation of the random number generator. Devices silently switched to a weak entropy source, making private keys vulnerable to reproduction given sufficient computing power.
Notably, the problem existed for years, but exploitation only became possible now. This is a classic case of a "silent" vulnerability that only manifested during large-scale key enumeration.
Attacks have ceased, but funds are moving into the shadows
The last confirmed chain of hacks dates to August 6. No new theft cases have been recorded, but this is more a result of available funds being exhausted than successful defense. Of the stolen 1,778 BTC, about 1,531 BTC remain under hacker control. Approximately 65% of these coins have passed through CoinJoin transactions, complicating tracking, while 35% were moved using the Peel Chain scheme—a classic laundering method where small portions are repeatedly separated from a large sum.
Importantly, the attacks were not carried out by a single group: Galaxy identified at least 33 separate traces of activity, indicating simultaneous exploitation of the vulnerability by multiple attackers.
A blow to the self-custody narrative
This incident strikes at the very foundation of the self-custody idea. The victims are not newcomers taking risks on DeFi platforms, but conservative holders who trusted "hardware." After the attacks began, a sharp outflow was observed: in the first four days, more than 22,000 BTC flowed to exchanges, and by August 8, balances on centralized platforms reached an all-time high of 3.683 million BTC.
Notably, no confirmed theft affected multisignature addresses. Casa and Anchorwatch services report a surge in demand for multisig solutions. However, as Dhruv Bansal from Unchained rightly notes, the problem is not custodianship per se, but the single point of failure—whether it be an exchange, a manufacturer, or the user themselves.
AI on the attackers' side
A particularly alarming detail is the likely use of AI models without cybersecurity restrictions, including Chinese open-source LLMs. This confirms a trend: tools for finding vulnerabilities are becoming available not only to defenders but also to attackers.
Against the backdrop of a record $1.1 billion in losses from hacks in the first half of 2026, this case is a sobering signal for the entire industry. Storage on a single device is no longer a guarantee of security, and distributing risk across multiple keys is becoming not a recommendation but a necessity.