Crypto news

15.08.2026
20:05

Largest theft from hardware wallets: hackers withdrew more than 1700 BTC from Coldcard

hack

A large-scale campaign against Coldcard hardware wallet owners has resulted in losses of at least 1,778.84 BTC, equivalent to $112.7 million. Based on the latest data, the active phase of the attacks has ended: no new confirmed incidents have been recorded since August 6. This is one of the most serious blows to the self-custody industry in recent years.

Timeline and Scale of the Attack

I was able to determine that the research team contacted 190 victims and verified the theft of funds from more than 8,600 addresses. However, the actual damage is likely significantly higher: taking into account unconfirmed episodes, the volume of stolen assets could reach 2,417.35 BTC, or approximately $153 million. The attack began no later than the morning of July 30, 2026, when attackers started systematically recovering seed phrases generated by vulnerable devices.

The Root of the Problem Lies in a 2021 Firmware Bug

The cause lies in an error made by the manufacturer Coinkite. After a firmware update in 2021, the cryptographic entropy generation mechanism was changed, but due to a bug, the random number generator worked incorrectly. Devices silently switched to an alternative entropy source, which turned out to be critically weak for protecting private keys. The problem existed for years but only manifested now: with sufficient computing power, attackers were able to reproduce keys created on such wallets.

Attacks Have Stopped, but Funds Are Moving into the Shadows

The cessation of new hacks is explained by two factors: some users managed to move assets to new addresses, and the remaining funds have most likely already been stolen. Moreover, this was not the work of lone actors—I found traces of at least 33 different attackers who simultaneously exploited the vulnerability. Of the confirmed 1,778 BTC, about 1,531 BTC are still on the attackers' addresses. The remaining ~246 BTC have already been moved: 65% passed through CoinJoin mixers, and 35% through Peel Chain schemes, which seriously complicates tracking.

A Blow to the Self-Custody Narrative

This incident is particularly painful because the victims were not newcomers but conservative users who avoided exchanges and DeFi risks. They trusted "hardware" that was considered the gold standard of security. The market reaction was immediate: in the first four days, more than 22,000 BTC flowed into exchanges, and by August 8, the total balance on platforms reached an all-time high of 3.683 million BTC. Notably, no confirmed theft affected multisignature addresses—this triggered a sharp surge in interest in multisig solutions from Casa and Anchorwatch.

AI as a New Weapon for Attackers

The role of artificial intelligence deserves special attention. Some attackers likely used open Chinese LLMs without cybersecurity restrictions. This is an alarming signal: the capabilities for finding and exploiting vulnerabilities are becoming available to a wide range of individuals. Notably, Bitcoin Red Team researchers, on the contrary, faced restrictions from American AI companies, which hindered their use of the most powerful models for defense.

My analysis: This case is not just a technical failure but a systemic challenge to the entire philosophy of self-custody. Relying on a single hardware wallet creates a single point of failure, whether it be the manufacturer, firmware, or human factor. The market is already voting for multisignature and risk distribution, and I expect this trend to strengthen. But the main lesson is that even the "gold standard" of security can prove fragile if relied upon without redundancy.