The largest theft from hardware wallets: hackers stole more than 1700 BTC through a vulnerability in Coldcard

A large-scale attack on Coldcard hardware wallets resulted in the loss of at least 1,778.84 BTC, equivalent to $112.7 million. My colleagues at the Galaxy Research analytical division have confirmed: after August 6, no new cases of hacking were recorded, indicating that the active phase of exploiting the vulnerability has concluded.
Attack on Coldcard: Timeline and Scale
During the investigation, researchers contacted 190 victims and verified the theft of bitcoins from more than 8,600 addresses. However, the actual damage is likely significantly higher: taking into account unconfirmed episodes, the volume of stolen funds could reach 2,417.35 BTC, or approximately $153 million.
The attack began on the morning of July 30, 2026. The attackers systematically recovered seed phrases generated by vulnerable Coldcard devices, after which they withdrew funds to wallets under their control. The root of the problem lies in a firmware error made by Coinkite in 2021 when updating the cryptographic entropy generation mechanism. Due to the bug, the random number generator operated incorrectly, and devices silently switched to an entropy source that was critically insufficient to protect private keys.
The vulnerability existed for years but only manifested itself now: possessing sufficient computing power, hackers were able to reproduce private keys created on the affected devices.
Cessation of Attacks and Multiple Trails
The last confirmed chain of attacks dates to August 6. After this date, new victims continue to contact researchers, but there are no longer any verified cases of hacking. I believe the attacks ceased for two reasons: either owners managed to move funds to new addresses, or the available assets had already been exhausted. Moreover, this is not about a single attacker—Galaxy has discovered at least 33 additional activity trails, which with high probability indicates the simultaneous exploitation of the vulnerability by several groups.
The Fate of Stolen Funds
Of the confirmed 1,778 BTC, approximately 1,531 BTC still remain on the attackers' addresses. Roughly 246 BTC have already been moved since the theft. Notably, 65% of these funds passed through CoinJoin transactions, which complicate tracking, while 35% went through a Peel Chain scheme, where small microtransactions are repeatedly "peeled off" from a large amount. A small portion of the bitcoins was observed on centralized exchanges and cross-chain bridges; Galaxy has already provided lists of addresses to exchanges, compliance companies, and law enforcement.
A Blow to the Idea of Self-Custody
This incident is unique not only in scale but also in the profile of its victims. Those affected are users who approached self-custody with maximum responsibility: they did not use dubious exchanges, risky DeFi protocols, or high-yield schemes. They trusted hardware wallets, which were considered the gold standard of security. As a result, the narrative about self-custody received a serious blow: after the attacks began, the number of small transfers to exchanges rose sharply, and in the first four days, more than 22,000 BTC flowed into centralized platforms. By August 8, the aggregate exchange balance reached an all-time high of 3.683 million BTC.
Multisignature as a Solution
One of the unexpected consequences is a surge of interest in multisig wallets. No confirmed theft was carried out from addresses protected by multisignature. Services Casa and Anchorwatch reported a sharp increase in clients, and Unchained co-founder Dhruv Bansal rightly notes: the problem is not custodial versus non-custodial solutions, but a single point of failure—whether it be an exchange, a device manufacturer, or the user themselves. The incident forces a reconsideration of storage approaches, distributing risks across multiple keys and independent infrastructure components.
AI on the Attackers' Side
A separate alarming detail is the possible use of artificial intelligence. Galaxy believes that some attackers used AI models without strict cybersecurity restrictions, in particular Chinese open-source LLMs. The irony is that Bitcoin Red Team researchers, while auditing the ecosystem's codebase, faced the opposite problem: restrictions from American AI companies prevented them from using the most powerful models for defense. This underscores that with the spread of AI, the ability to find and exploit errors is becoming more accessible not only to defenders but also to malicious actors.
Let me remind you that in the first half of 2026, crypto projects lost about $1.1 billion due to hacks, and the number of confirmed exploits became a record for a half-year period. This incident is a stark reminder: even the most reliable tools can contain hidden defects, and risk diversification is not a luxury but a necessity.
My conclusion: the Coldcard story is not just a technical failure, but a systemic challenge to the entire industry. Trust in hardware wallets has been undermined, and it can only be restored through transparency in audits and a mandatory transition to multisignature schemes for significant amounts.