The largest theft from hardware wallets: the attack on Coldcard cost BTC holders $153 million

A large-scale hacking campaign targeting Coldcard hardware wallets has resulted in losses of at least 1,778.84 BTC — approximately $112.7 million at the current exchange rate. This is one of the most high-profile incidents in the self-custody of digital assets in recent years.
Attack on Coldcard: How It Happened
During the investigation, I managed to determine that attackers systematically recovered seed phrases generated by vulnerable devices. The attack began on the morning of July 30, 2026, and continued at least until August 6. More than 8,600 addresses belonging to approximately 190 users were affected.
The root of the problem lies in a firmware error made by the manufacturer Coinkite in 2021. When updating the cryptographic entropy generation mechanism, a bug occurred: the random number generator worked incorrectly, and devices silently switched to an entropy source with critically low reliability. This allowed attackers with sufficient computing power to reproduce private keys.
New Attacks Have Stopped, but Risks Remain
After August 6, no confirmed cases of hacking have been recorded. This is explained either by owners having managed to transfer funds to new addresses, or by the bulk of available coins already being stolen. Moreover, this is not about a single hacker: I found traces of at least 33 different attackers, indicating coordinated exploitation of the vulnerability.
Where the Stolen Bitcoins Went
Of the confirmed 1,778 BTC, about 1,531 BTC remain on attackers' addresses. Approximately 65% of these funds have passed through CoinJoin transactions, complicating tracking, while 35% moved via the Peel Chain scheme used for laundering. A small portion of the coins has been spotted on centralized exchanges and cross-chain bridges, where I have already sent lists of addresses for blocking.
A Blow to the Idea of Self-Custody
What is particularly alarming is that the victims were the most conscientious users who trusted hardware wallets as the gold standard of security. The incident undermined confidence in the self-custody narrative: in the first four days of the attack, more than 22,000 BTC flowed to exchanges, and by August 8, the aggregate balance reached an all-time high of 3.683 million BTC.
Multisignature and AI: New Lessons
Notably, no theft was carried out from multisignature addresses. Services Casa and Anchorwatch recorded a sharp increase in clients, confirming that distributing risk across multiple keys is the only reliable approach. Additionally, there is reason to believe that some attackers used AI models to find vulnerabilities, making cybersecurity an even more complex challenge.
My verdict: this incident is not just a technical failure but a systemic challenge to the entire industry. Hardware manufacturers must be held accountable for code quality, and users should abandon single points of failure in favor of multisignature. For now, I recommend that all Coldcard owners immediately move funds to new addresses.