Largest theft from hardware wallets: hackers stole 1778 BTC from Coldcard

A large-scale attack on Coldcard hardware wallets resulted in the loss of at least 1,778.84 BTC — approximately $112.7 million at the current exchange rate. My colleagues at Galaxy Research have noted that no new confirmed cases of hacking have occurred since August 6, but this does not diminish the severity of what happened.
Attack Mechanics: A Bug in the 2021 Firmware
Researchers contacted 190 victims and confirmed the theft of funds from more than 8,600 addresses. Including unconfirmed incidents, the damage could reach 2,417.35 BTC, or ~$153 million. The attack began on the morning of July 30, 2026: attackers systematically recovered seed phrases generated by vulnerable devices.
The root of the problem lies in a software error. In 2021, Coinkite updated the Coldcard firmware, changing the mechanism for generating cryptographic entropy. Due to a bug, the random number generator worked incorrectly, and devices silently switched to another, critically weak source of entropy. This made private keys vulnerable to reproduction given sufficient computing power. The issue had been brewing for years but only manifested now.
Cessation of Attacks and Multiple Trails
Galaxy notes that the last confirmed chain of attacks dates to August 6. The cessation is likely related to owners moving funds to new addresses or the fact that most available coins have already been stolen. Moreover, this is not about a single hacker: at least 33 additional activity trails have been found, indicating that several groups exploited the vulnerability simultaneously. To anyone still holding bitcoins on single-signature Coldcard wallets, I strongly recommend evacuating assets immediately.
The Fate of Stolen Funds
Of the confirmed 1,778 BTC, about 1,531 BTC remain on attackers' addresses, while 246 BTC have already been moved. Notably, 65% of the funds passed through CoinJoin transactions, complicating tracking, and 35% through Peel Chain schemes typical of laundering. Some coins have been spotted on centralized exchanges and cross-chain bridges; Galaxy has already shared address lists with exchanges and law enforcement.
A Blow to the Self-Custody Narrative
The incident strikes at the very idea of self-custody. The victims are users who approached storage with maximum responsibility: no dubious exchanges, risky DeFi, or hype-driven tools. They trusted hardware wallets as the gold standard of security. After the attacks began, there was a sharp surge in small transfers to exchanges: more than 22,000 BTC arrived in the first four days, and by August 8, exchange balances reached an all-time high of 3.683 million BTC.
Multisignature as the Answer
It is telling that no confirmed theft affected multisignature addresses. Services like Casa and Anchorwatch are recording a surge in new clients, and Unchained co-founder Dhruv Bansal rightly emphasizes: the problem is not custodial vs. non-custodial solutions, but a single point of failure. Whether it is an exchange, a manufacturer, or the user themselves, any single element can become a vulnerability. The incident forces a rethink: distributing risk across multiple keys and independent infrastructure components becomes not an option, but a necessity.
A Warning Sign: AI in the Hands of Attackers
I would also note the use of AI. Galaxy associates some of the attacks with high probability to Chinese open-source LLMs without strict cybersecurity restrictions. The paradox is that Bitcoin Red Team researchers, while auditing the ecosystem's codebase, encountered the opposite problem: the limits of American AI companies prevent them from using the most powerful models for defense. This is a dangerous trend: the ability to find and exploit errors is becoming more accessible to attackers than to defenders.
In the context of the first half of 2026, when crypto projects lost about $1.1 billion to hacks and the number of exploits hit a record, this case is another reminder: security is not a static product, but an ongoing process. My advice is to diversify risks and not rely on a single device as a panacea.