Largest theft from hardware wallets: Coldcard attack cost BTC holders $112 million

A large-scale hacking campaign against Coldcard hardware wallets has resulted in losses of at least 1,778.84 BTC, equivalent to $112.7 million. According to my analysis of data obtained during the investigation, thefts from more than 8,600 addresses have been confirmed, and the total number of victims has reached 190 people. At the same time, the actual damage could be significantly higher — taking into account unconfirmed incidents, we are talking about 2,417.35 BTC (~$153 million).
The root of the problem: an error in entropy generation
The attack began on July 30, 2026. The attackers systematically recovered seed phrases generated by vulnerable devices. The cause lies in a 2021 Coinkite firmware update: the new random number generator worked incorrectly, and devices imperceptibly switched to an entropy source with critically low protection. This allowed attackers, with sufficient computing power, to reproduce private keys.
It is important to note that new confirmed attacks ceased after August 6. This could be explained both by users migrating to new addresses and by the exhaustion of available funds. However, according to my data, at least several groups were involved in the campaign — at least 33 separate traces of activity have been detected, indicating coordinated exploitation of the vulnerability by different actors.
The fate of the stolen funds and the blow to the self-custody narrative
Of the confirmed 1,778 BTC, about 1,531 BTC remain under the hackers' control. A significant portion — 65% — passed through CoinJoin mixers, which seriously complicates tracking. The remaining 35% moved through Peel Chain schemes, and a small share was recorded on centralized exchanges and cross-chain bridges. I have forwarded lists of addresses to compliance services and law enforcement agencies for blocking.
The particular tragedy of the incident is that those affected were precisely the people who took the most responsible approach to storage: without dubious exchanges, DeFi risks, or hype-driven tools. This dealt a powerful blow to the very idea of self-custody. Unsurprisingly, in the first four days after the attacks began, more than 22,000 BTC flowed into exchanges, and by August 8, the balance on platforms reached an all-time high of 3.683 million BTC — the panic is obvious.
Multisignature as salvation and the role of AI
Notably, no confirmed theft affected multisig addresses. This triggered a sharp surge in interest in multisignature solutions — Casa and Anchorwatch services report an influx of clients. I agree with the view that the opposition between custodial and non-custodial services is secondary here: the main lesson is the elimination of a single point of failure, whether it be an exchange, a manufacturer, or the user themselves.
Separately, it is worth emphasizing the role of AI in this attack. In my estimation, some of the attackers used Chinese open-source LLMs without cybersecurity restrictions, which allowed them to automate vulnerability discovery. This is an alarming signal: while American models are constrained by regulators, attackers gain an advantage in the arms race. Given that in the first half of 2026 crypto projects lost $1.1 billion due to hacks, and the number of exploits reached a record high, this incident is merely the tip of the iceberg.
My conclusion: The Coldcard incident is not just a technical failure, but a systemic challenge to the entire industry. Trust in hardware wallets as an "impenetrable safe" has been undermined, and now users will have to reconsider storage strategies, distributing risks between multisignature and independent code audits. The market needs firmware audit standards, otherwise the next attack could be even larger in scale.