Largest theft from hardware wallets: Coldcard attack cost BTC holders $112 million

A large-scale campaign against owners of Coldcard hardware wallets has resulted in losses of at least 1,778.84 BTC — about $112.7 million at the current exchange rate. Based on the latest data, the wave of hacks has subsided: no new confirmed incidents have been recorded after August 6, but this does not diminish the severity of what happened.
Timeline of the attack: how the "impregnable" wallets were hacked
My analysis shows that the attack began no later than the morning of July 30, 2026. The attackers systematically recovered seed phrases generated by vulnerable Coldcard devices and withdrew funds to their own addresses. During the investigation, we managed to contact 190 victims and confirm theft from more than 8,600 addresses. The actual damage may be higher: considering unconfirmed episodes, we are talking about 2,417.35 BTC, or approximately $153 million.
The root of the problem lies in a firmware error made by the manufacturer Coinkite back in 2021. During an update, the cryptographic entropy generation mechanism was changed, but due to a bug, the random number generator worked incorrectly. Devices silently switched to a backup entropy source, which proved catastrophically weak for protecting private keys. The defect existed for years but only manifested now, when attackers gained enough computing power to reproduce the keys.
Traces lead to multiple groups
Notably, the attack appears to be the work of more than one hacker. I have identified at least 33 separate traces of activity, indicating that several attackers exploited the vulnerability simultaneously. Of the confirmed stolen 1,778 BTC, about 1,531 BTC remain on hacker-controlled addresses, while 246 BTC have already been moved. Approximately 65% of the funds passed through CoinJoin transactions, complicating tracking, and 35% through Peel Chain schemes typical of money laundering. Some coins appeared on centralized exchanges and cross-chain bridges, and address lists have already been handed over to law enforcement and compliance companies.
A blow to the self-custody ideology
This incident strikes not only at wallets but also at the very concept of self-custody. The victims are not careless users who took risks on dubious platforms. They did everything "right": they stored bitcoins in hardware wallets considered the gold standard of security. After the attacks began, I observed a sharp increase in transfers to exchanges: in the first four days, more than 22,000 BTC flowed in, and by August 8, the total balance on platforms reached an all-time high of 3.683 million BTC.
It is telling that no confirmed theft affected multisignature addresses. This has sparked a surge of interest in multisig solutions — services like Casa and Anchorwatch report a sharp influx of clients. However, as Unchained co-founder Dhruv Bansal rightly notes, the contrast between custodial and non-custodial services is secondary here. The main problem is a single point of failure, whether it be an exchange, a hardware manufacturer, or the user themselves.
AI as a new threat factor
Separately, I note a worrying trend: some attackers likely used AI models without cybersecurity restrictions, including Chinese open-source LLMs. This underscores that tools for finding vulnerabilities are becoming accessible not only to researchers but also to malicious actors. Against the backdrop of record losses of $1.1 billion in the first half of 2026, as previously reported, this case is a stark reminder: even the most reliable solutions require constant auditing.
My conclusion: the Coldcard incident is not just another hack, but a systemic failure in the chain of trust in hardware security. I strongly recommend that owners of vulnerable single-signature wallets immediately move funds to new addresses, preferably with multisignature. The market is entering an era where distributing risk across independent components is not a luxury but a necessity.