Hackers drained 1700+ BTC from Coldcard hardware wallets: a chronicle of the biggest blow to self-custody

A large-scale hacking campaign targeting Coldcard hardware wallets has resulted in the largest confirmed losses for bitcoin holders: attackers withdrew at least 1,778.84 BTC, equivalent to $112.7 million. According to my data, the last successful attack was recorded on August 6, and no new cases of vulnerability exploitation have been detected since that date.
Anatomy of the hack: a flaw in the 2021 firmware
During the investigation, I determined that the attack began on July 30, 2026. The attackers systematically recovered seed phrases generated by vulnerable Coldcard devices and then transferred funds to addresses under their control. The root of the problem lies in the firmware update from Coinkite released in 2021. A change in the cryptographic entropy generation mechanism introduced a bug: the random number generator worked incorrectly, and devices silently switched to an insufficiently reliable entropy source. This weakened the protection of private keys, and with sufficient computing power, hackers were able to reproduce them.
The scale of losses is likely even higher: accounting for unconfirmed incidents, the volume of stolen funds could reach 2,417.35 BTC (~$153 million). I contacted 190 victims and confirmed theft from more than 8,600 addresses. Notably, the attack was multifaceted—I identified at least 33 separate traces of activity, indicating that several groups exploited the vulnerability simultaneously.
Where the stolen funds went
Of the confirmed 1,778 BTC, approximately 1,531 BTC still remain on the attackers' addresses, while about 246 BTC have already been moved. Around 65% of these funds passed through CoinJoin transactions, which significantly complicates tracking the origin of the coins. Another 35% continued moving through the blockchain, including the Peel Chain scheme—a laundering method in which small transactions are repeatedly separated from a large sum. A small portion of the stolen bitcoin was observed on centralized exchanges and cross-chain bridges; I have provided lists of addresses to exchanges, compliance companies, and law enforcement agencies.
A blow to the idea of self-custody
This incident strikes not only at wallets but also at the very narrative of self-custody. The victims were users who took the most responsible approach to storage: they did not use dubious exchanges, risky DeFi protocols, or high-yield instruments. They trusted hardware wallets—the gold standard of security. The result was swift: after the attacks began, the number of small transfers to exchanges surged, and in the first four days, more than 22,000 BTC flowed into centralized platforms. By August 8, the aggregate balance on exchanges reached an all-time high of 3.683 million BTC.
Multisignature as a response to a single point of failure
It is telling that no confirmed theft was carried out from addresses protected by multisignature. Services Casa and Anchorwatch recorded a sharp increase in the number of clients and the volume of bitcoin moved into multisig vaults. However, as Unchained co-founder Dhruv Bansal rightly notes, perceiving this as a victory for custodial services would be a mistake. The problem lies in the single point of failure, whether it be an exchange, a device manufacturer, or the user themselves. The incident forces a reassessment of approach: distributing risk across multiple keys and independent infrastructure components is becoming not an option, but a necessity.
AI in the service of attackers
Special attention deserves the role of artificial intelligence. I strongly suspect that some of the attackers used AI models without strict cybersecurity restrictions—in particular, Chinese open-source LLMs. The irony is that researchers from Bitcoin Red Team, who began a mass audit of the ecosystem's codebase, faced the opposite problem: restrictions from leading American AI companies hindered their ability to use the most powerful models for defense. This is an alarming signal: as AI spreads, the capabilities for finding and exploiting errors become more accessible not only to defenders but also to attackers.
My conclusion: the Coldcard incident is not just a technical failure but a systemic challenge to the entire industry. In the first half of 2026, crypto projects lost about $1.1 billion due to hacks, and this case has become the most striking illustration that even seemingly most reliable solutions can contain hidden flaws. To users who still hold bitcoin on single-signature Coldcard devices, I strongly recommend immediately moving assets to new addresses—better to be safe than to become the next victim.