Crypto news

15.08.2026
15:59

Critical Coldcard Hack: 1,778 BTC Stolen, Attack Exposes Fundamental Risks of Self-Custody

hack

A large-scale campaign against Coldcard hardware wallet owners has resulted in the largest incident in the field of self-custody of digital assets. According to my data, the confirmed damage from the attack, which began on July 30, 2026, amounts to at least 1,778.84 BTC — approximately $112.7 million at the current exchange rate. At the same time, actual losses are likely higher: taking into account unconfirmed episodes, the figure could be 2,417.35 BTC (~$153 million).

Root of the problem: defective entropy generator

Analysis shows that the cause was a critical bug in the Coinkite firmware released in 2021. The update changed the cryptographic entropy generation mechanism, but due to the bug, the random number generator worked incorrectly, imperceptibly switching to an insufficiently reliable source. This allowed attackers with serious computing power to reproduce private keys created on vulnerable devices. The problem existed for years, but exploitation only began now.

Timeline and scale of the attack

Researchers contacted 190 victims and confirmed the theft of funds from more than 8,600 addresses. The last confirmed chain of attacks dates to August 6, after which no new hacking cases were recorded. This is explained either by users managing to withdraw funds or by the available pool of assets being exhausted. It is important to emphasize: the attack was not isolated — at least 33 traces of activity were detected, indicating simultaneous exploitation of the vulnerability by several groups.

Movement of stolen funds

Of the confirmed 1,778 BTC, about 1,531 BTC still remain on the attackers' addresses. The remaining 246 BTC have already been moved: 65% went through CoinJoin transactions, which seriously complicate tracking, and 35% followed the Peel Chain scheme, classic for laundering. A small portion was spotted on centralized exchanges and cross-chain bridges, so address lists have already been provided to compliance departments and law enforcement agencies.

Blow to the self-custody narrative

The incident strikes not only at wallets but also at the very idea of self-custody. The victims are not inexperienced users but people who took a maximally responsible approach to security: they did not use dubious DeFi protocols and did not chase yields. They trusted a hardware wallet considered the gold standard. The market reaction was immediate: in the first four days after the attack, more than 22,000 BTC flowed into exchanges, and by August 8, the aggregate balance on platforms reached an all-time high of 3.683 million BTC.

Multisignature as the new standard

Notably, not a single confirmed theft was carried out from multisig addresses. This has triggered a sharp surge in interest in multisignature solutions — Casa and Anchorwatch services report significant client inflows. However, as Unchained co-founder Dhruv Bansal rightly notes, contrasting custodial and non-custodial services is incorrect. The essence of the problem is a single point of failure, whether it be an exchange, a manufacturer, or the user themselves. The incident forces a rethink: distributing risk across multiple keys and independent infrastructure components is becoming not an option but a necessity.

Role of AI in the attack

Special attention deserves the likely use of AI. Some of the attackers, apparently, used Chinese open-source LLMs without cybersecurity restrictions. This is an alarming signal: the capabilities for finding and exploiting vulnerabilities are becoming available not only to researchers but also to malicious actors. Notably, the Bitcoin Red Team, which began a mass review of the ecosystem's codebase, faced the opposite problem — restrictions from American AI companies hindered the use of the most powerful models for defense.

My conclusion: this incident is not just a technical failure but a systemic challenge to the entire industry. It demonstrates that even the most seemingly reliable solutions can contain hidden defects, and trust in a single device is a risk that can no longer be ignored. Against the backdrop of a record $1.1 billion in losses from hacks in the first half of 2026, this case should serve as a catalyst for transitioning to multi-layered security schemes.