Largest theft from hardware wallets: Coldcard attack cost $112 million

A large-scale campaign against Coldcard hardware wallet owners has led to the loss of at least 1,778.84 BTC, equivalent to approximately $112.7 million. Monitoring conducted by my analytical team shows that no new confirmed hacking cases have been recorded since August 6 — the attackers appear to have completed the active phase.
Attack Mechanics: Vulnerability in Key Generation
During the investigation, contact was established with 190 victims and theft of funds from more than 8,600 addresses was confirmed. The real scale of the damage is likely higher: accounting for unconfirmed episodes, losses could reach 2,417.35 BTC (~$153 million). The root of the problem lies in an error embedded in Coinkite's firmware back in 2021. The update changed the entropy generation mechanism, but due to a bug, the random number generator worked incorrectly, imperceptibly switching to a source with critically low entropy. This made private keys predictable for attackers with sufficient computing power.
Why the Attacks Stopped
The cessation of new hacks is explained by two factors: some users managed to move funds to new addresses, and the remaining available amounts had already been withdrawn. It is important to emphasize: this is not about a single hacker. I found traces of at least 33 different attackers, indicating coordinated or parallel exploitation of the vulnerability. To anyone still holding bitcoins on single-signature Coldcard wallets, I strongly recommend migrating to new wallets immediately.
Laundering and Market Reaction
Of the confirmed stolen funds, about 1,531 BTC remain on the attackers' addresses, while 246 BTC have already been moved. A significant portion — 65% — passed through CoinJoin to obscure traces, while the remaining 35% moved via the Peel Chain scheme, typical of laundering. Small amounts were spotted on exchanges and cross-chain bridges; address lists have been provided to compliance services and law enforcement agencies.
The incident dealt a serious blow to the self-custody narrative. The victims are disciplined users who avoided risky DeFi tools. Panic triggered an inflow of funds to exchanges: more than 22,000 BTC arrived in the first four days, and by August 8, balances reached an all-time high of 3.683 million BTC.
Lessons and Conclusions
It is telling that no theft was committed from multisignature addresses. Casa and Anchorwatch services recorded a sharp increase in clients, confirming a shift toward risk distribution. However, as Unchained co-founder Dhruv Bansal rightly notes, the problem is deeper — it is a single point of failure, whether it be an exchange, a manufacturer, or the user themselves. Separately, the likely use of AI models by attackers should be highlighted, which lowers the entry barrier for cybercriminals.
My analysis: this case is a wake-up call for the entire industry. Even the "gold standard" of hardware wallets proved vulnerable due to a single error in code. Investors should reconsider storage strategies, favoring multisignature, and manufacturers should tighten audits of cryptographic components. In the first half of 2026, losses from hacks already amounted to $1.1 billion, and the current incident only exacerbates this alarming trend.