Crypto news

15.08.2026
17:05

Attack on Coldcard: Over 1,700 BTC stolen, and the idea of self-custody has been shaken

hack

The large-scale incident involving Coldcard hardware wallets turned out to be far more serious than initially assumed. During a targeted attack, attackers withdrew at least 1,778.84 BTC, equivalent to approximately $112.7 million. My colleagues at Galaxy Research confirmed the theft of funds from more than 8,600 addresses, having contacted 190 victims. However, the actual damage may be even higher: if unconfirmed episodes are taken into account, the volume of stolen funds reaches 2,417.35 BTC — about $153 million.

The Root of the Problem: An Entropy Generation Bug

The attack began no later than the morning of July 30, 2026. The attackers systematically recovered seed phrases that were generated by vulnerable Coldcard devices. The cause was a critical firmware error introduced by Coinkite in 2021 during an update to the cryptographic entropy mechanism. Due to the bug, the random number generator operated incorrectly, and devices silently switched to an entropy source with insufficient protection for private keys. The problem existed for years but only manifested now, when attackers gained sufficient computing power to reproduce the keys.

Attacks Have Stopped, But the Threat Has Not Disappeared

The last confirmed chain of hacks dates to August 6. After that date, new victims continue to reach out to researchers, but there are no confirmed cases of further theft. I believe this is due either to users having managed to move funds to new addresses, or to the fact that most available coins have already been stolen. Nevertheless, I recommend that anyone still holding bitcoins on single-signature Coldcard wallets immediately move their assets.

It is important to note that this is not the work of a single hacker. Galaxy has identified at least 33 separate traces of activity, indicating that several groups of attackers exploited the vulnerability simultaneously.

The Fate of the Stolen Funds

Of the confirmed 1,778 BTC, about 1,531 BTC remain on the attackers' addresses, while 246 BTC have already been moved. Approximately 65% of these funds have passed through CoinJoin transactions, which seriously complicates tracking. Another 35% are moving across the blockchain, including the Peel Chain scheme, where small transactions are repeatedly separated from large sums. Some coins have been spotted on centralized exchanges and cross-chain bridges. Galaxy has already provided lists of addresses to exchanges, compliance companies, and law enforcement.

A Blow to the Idea of Self-Custody

This incident is unique not in scale but in the profile of its victims. Those affected are not newcomers who took risks on dubious platforms. They are disciplined users who trusted hardware wallets as the gold standard of security. They did not use DeFi protocols or chase yields. And here is the result — their funds were stolen.

The consequences are already being felt: in the first four days after the attacks began, more than 22,000 BTC flowed into exchanges, and by August 8, the aggregate balance on centralized platforms reached an all-time high of 3.683 million BTC. This is a clear signal of panic and a loss of trust in self-custody.

Multisignature as a Solution

It is telling that no confirmed theft was carried out from addresses protected by multisignature. Services Casa and Anchorwatch have already reported a sharp increase in clients. Unchained co-founder Dhruv Bansal rightly notes: the problem is not custodial versus non-custodial solutions, but a single point of failure — whether it be an exchange, a manufacturer, or the user themselves. The incident forces a reassessment of approach: distributing risk across multiple keys and independent components is the new reality.

AI on the Attackers' Side

Separately concerning is the role of artificial intelligence. Galaxy believes that some attackers used AI models without cybersecurity restrictions, including Chinese open-source LLMs. Ironically, researchers at Bitcoin Red Team, while testing the ecosystem for vulnerabilities, encountered the opposite problem: restrictions on American AI companies prevent them from using the most powerful models for defense. This is an important signal: the capabilities for finding and exploiting errors are becoming more accessible to attackers than to defenders.

My conclusion: this incident is not just a technical failure, but a systemic challenge to the industry. In the first half of 2026, crypto projects lost about $1.1 billion due to hacks, and this case has become the most striking reminder that even the most reliable tools can contain hidden defects. Self-custody is not dead, but it requires a new level of awareness — and perhaps multisignature will become the de facto standard for serious holders.