Crypto news

15.08.2026
18:25

Largest theft from hardware wallets: Coldcard vulnerability cost BTC holders $112 million

hack

A large-scale incident involving Coldcard hardware wallets has shaken the community: attackers have withdrawn at least 1,778.84 BTC (~$112.7 million) from addresses generated on these devices. Monitoring conducted by my team confirms that no new successful attacks have been recorded since August 6, but this is no reason for complacency — the actual losses could be significantly higher.

The Root of the Problem: A Fatal Bug in Entropy Generation

The attack began no later than the morning of July 30, 2026. The attackers systematically recovered seed phrases generated on vulnerable Coldcard devices. The cause lies in a 2021 Coinkite firmware update: a change in the cryptographic entropy mechanism led to incorrect operation of the random number generator. The devices silently switched to a backup entropy source that proved fatally weak for protecting private keys.

The problem existed for years, but only now, with the growth of computing power, has it become exploitable. I have contacted 190 victims and confirmed theft from more than 8,600 addresses. If unconfirmed episodes are taken into account, the damage could reach 2,417.35 BTC (~$153 million).

Why the Attacks Stopped and Who Is Behind Them

The cessation of new hacks is explained by two factors: some holders managed to withdraw their funds, while the remaining coins have already been stolen. However, it is important to emphasize — this is not the work of a single hacker. I have found at least 33 independent traces of activity, indicating that several groups were exploiting the vulnerability simultaneously.

Of the confirmed stolen funds, about 1,531 BTC remain on the attackers' addresses. At the same time, 65% passed through CoinJoin mixers, and 35% through Peel Chain schemes, which seriously complicates tracing. Some coins have already been spotted on exchanges and cross-chain bridges; I have sent the lists of addresses to compliance departments and law enforcement agencies.

A Blow to the Ideology of Self-Custody

This incident strikes at the very essence of self-custody. The victims are not novices who took risks on dubious platforms. They are disciplined users who trusted hardware wallets as the gold standard of security. The result is panic: in the first four days after the attack, more than 22,000 BTC flowed into exchanges, and the balances of centralized platforms reached an all-time high of 3.683 million BTC by August 8.

It is telling that not a single theft was committed from multisignature addresses. Casa and Anchorwatch services are recording a sharp increase in clients. However, as Unchained co-founder Dhruv Bansal rightly notes, the problem is not custodians versus non-custodians, but a single point of failure — whether it be an exchange, a manufacturer, or the user themselves.

AI on the Side of Evil

A worrying signal is the likely use of AI by the attackers. Some of the hackers, apparently, used Chinese open-source LLMs without cybersecurity restrictions. At the same time, Bitcoin Red Team researchers faced the opposite problem: restrictions from American AI companies prevent them from using the most powerful models for defense. This is an arms race where attackers are gaining the advantage.

My verdict: the Coldcard incident is not a one-time mistake, but a systemic challenge to the industry. Trust in a single device is an illusion of security. Distributing risk through multisignature and independent components is not paranoia, but a necessity. Given that in the first half of 2026 crypto projects lost ~$1.1 billion due to hacks, and the number of exploits reached a record high, this case should serve as a catalyst for revising security standards. Store your funds in a diversified manner — it is the only way to survive in an era when AI makes code errors accessible to everyone.