Crypto news

15.08.2026
15:40

The largest theft from hardware wallets: hackers withdrew more than 1700 BTC from vulnerable Coldcard devices

hack

A large-scale attack on Coldcard hardware wallets has turned into the largest incident in the field of self-custody of crypto assets. According to my data, attackers managed to steal at least 1,778.84 BTC, equivalent to $112.7 million. At the same time, the wave of hacks appears to have stopped: after August 6, no new confirmed cases of vulnerability exploitation have been recorded.

The root of the problem lies in the 2021 firmware

During the investigation, contact was established with 190 victims, and the theft of funds from more than 8,600 addresses was confirmed. However, the actual damage may be significantly higher: if unconfirmed episodes are taken into account, the volume of stolen assets reaches 2,417.35 BTC (~$153 million).

The attack began on July 30, 2026. The attackers systematically recovered seed phrases generated by vulnerable devices. The cause lies in an error made by Coinkite in 2021 during a firmware update. A change in the cryptographic entropy generation mechanism led to incorrect operation of the random number generator: devices silently switched to an entropy source critically insufficient to protect private keys. The problem existed for years, but only now, with the growth of computing power, has it become exploitable.

Attacks have stopped, but the bitcoins have not been returned

The cessation of attacks is likely related to the fact that owners managed to withdraw funds or available assets have already been exhausted. However, this does not mean the threat has passed: for users of single-signature Coldcard wallets, I strongly recommend immediately moving funds to new addresses. This is not about a single hacker — at least 33 additional traces of activity have been detected, indicating coordinated actions by several groups.

Of the confirmed stolen funds, about 1,531 BTC remain on the attackers' addresses. Approximately 246 BTC have already been moved, with 65% passing through CoinJoin transactions, complicating tracking, and 35% following the Peel Chain scheme, actively used for laundering. Some coins have been spotted on centralized exchanges and cross-chain bridges; address lists have been provided to compliance departments and law enforcement agencies.

A blow to the self-custody narrative

The particular tragedy of the incident is that the victims were precisely those who approached security most responsibly: they did not use dubious platforms or DeFi protocols, trusting "hardware" considered the gold standard of reliability. This dealt a serious blow to the idea of self-custody. After the attacks began, a surge of transfers to exchanges was observed: over the first four days, more than 22,000 BTC arrived, and by August 8, the aggregate balance on platforms reached an all-time high of 3.683 million BTC.

Multisignature as salvation and a troubling signal from AI

It is telling that no confirmed theft was carried out from multisignature addresses. This caused a sharp increase in interest in multisig solutions — services Casa and Anchorwatch reported a significant influx of clients. However, as Unchained co-founder Dhruv Bansal rightly notes, the opposition between custodial and non-custodial solutions is secondary. The root problem is a single point of failure, whether it be an exchange, a device manufacturer, or the user themselves. Distributing risk across multiple keys is the only sensible path.

Separately, the possible use of AI by attackers is alarming: some hackers likely used Chinese open-source LLMs without cybersecurity restrictions. This highlights a troubling trend: vulnerability search tools are becoming accessible not only to defenders but also to attackers. Against the backdrop of a record $1.1 billion in losses from hacks in the first half of 2026, this incident is a stark reminder that even the "safest" solutions require reconsideration.

My verdict: the Coldcard incident is not just a technical failure, but a systemic challenge to the entire industry. Trust in hardware wallets has been undermined, and it can only be restored through code transparency and widespread adoption of multisignature. Investors should reconsider their storage strategies, not relying on a single "bulletproof" device.