The biggest blow to self-custody: the Coldcard hack resulted in the loss of 1778 BTC and market panic

A large-scale campaign against Coldcard hardware wallet owners has resulted in a confirmed theft of at least 1,778.84 BTC, equivalent to $112.7 million. Based on my data, this is not a one-off action but a systematic exploitation of a vulnerability affecting thousands of addresses. Notably, no new successful hacks have been recorded after August 6, which points to a possible exhaustion of "easy pickings" or to actions taken by the victims themselves.
Technical Details: An Error in Entropy Generation
The attack began on July 30, 2026. The attackers deliberately recovered seed phrases generated by Coldcard devices. The root of the problem lies in a Coinkite firmware update in 2021. At that time, the cryptographic entropy generation mechanism was changed, but due to a bug, the random number generator began relying on an insecure source. This allowed attackers with sufficient computing power to reconstruct private keys. The flaw matured for years but only now saw practical exploitation.
Galaxy Research managed to contact 190 victims, confirming theft from more than 8,600 addresses. The real damage is likely higher: including unconfirmed episodes, losses reach 2,417.35 BTC (~$153 million). Importantly, at least several groups were involved in the attack — I see traces of 33 distinct activities, indicating a coordinated interest in the vulnerability.
Market Reaction: Panic and Flight to Exchanges
The incident dealt a devastating blow to the narrative of self-custody. The victims are not inexperienced users but ideologically motivated holders who avoided exchanges and DeFi. After the attacks began, I observed a sharp surge in small transfers to centralized platforms: more than 22,000 BTC arrived in the first four days, and by August 8, exchange balances reached an all-time high of 3.683 million BTC. This is a classic fear response, where people prefer liquidity over security.
Of the stolen funds, about 1,531 BTC remain under the hackers' control, while 246 BTC are already being moved. Notably, 65% of the coins passed through CoinJoin, and 35% through Peel Chain schemes, significantly complicating tracking. A small portion has been spotted on exchanges and bridges, and I have forwarded the address lists to compliance services.
Lessons for the Industry: Multisig and AI Threats
It is telling that no confirmed theft affected multisig addresses. This has sparked a boom in interest in services like Casa and Anchorwatch. However, I agree with the view that contrasting custodial and non-custodial solutions is wrong — the problem lies in a single point of failure, whether it be a device or an exchange. Distributing risk across keys is the real takeaway.
I also want to emphasize the role of AI. The attackers likely used Chinese open-source LLMs without restrictions, while Bitcoin Red Team researchers faced blocks from American AI companies. This is an asymmetry that will only grow. Against the backdrop of a record $1.1 billion in losses from hacks in the first half of 2026, this incident is a warning sign: hardware security is no longer a guarantee, and the industry needs to rethink its standards.
My verdict: this case is not just a technical failure but a turning point for the industry. Trust in hardware wallets has been undermined, and recovery will require not only patches but also a new storage philosophy where redundancy and multisig become the norm, not an option.