Crypto news

15.08.2026
20:45

Attack on Coldcard: over 1700 BTC stolen — a lesson for the self-custody industry

hack

A large-scale campaign against Coldcard hardware wallet owners has resulted in losses of at least 1,778.84 BTC — about $112.7 million at the current exchange rate. My colleagues at Galaxy Research confirmed the theft of funds from more than 8,600 addresses by contacting 190 victims. However, the actual damage is likely higher: taking unconfirmed incidents into account, the figure could be 2,417.35 BTC (~$153 million). Importantly, no new confirmed hacks have been recorded since August 6.

The root of the problem lies in the 2021 firmware

The attack began on July 30, 2026. The attackers systematically recovered seed phrases generated by vulnerable devices. The cause was a critical error in Coinkite's 2021 firmware update. A change in the entropy generation mechanism led to a failure in the random number generator: devices silently switched to a source with insufficient cryptographic protection. The problem remained hidden for years but only surfaced now, when attackers gained the computing power to reproduce private keys.

Cessation of attacks and multiple traces

Galaxy links the halt of the attacks to two factors: the migration of funds to new addresses and the exhaustion of available assets. At the same time, it is clear that more than one group was involved — researchers identified at least 33 separate traces of activity, indicating that several attackers exploited the vulnerability simultaneously.

The fate of the stolen funds

Of the confirmed 1,778 BTC, about 1,531 BTC remain on the hackers' addresses, while 246 BTC have already been moved. Laundering was active: 65% of the funds went through CoinJoin, and 35% through Peel Chain schemes. Some bitcoins were spotted on exchanges and cross-chain bridges; Galaxy has provided lists of addresses to law enforcement and compliance companies.

A blow to the idea of self-custody

The incident strikes at the very narrative of self-custody. The victims are users who avoided risky DeFi and dubious exchanges, trusting hardware wallets. The market reaction was immediate: in the first four days, more than 22,000 BTC flowed to exchanges, and by August 8, the balance on centralized platforms reached an all-time high of 3.683 million BTC. This is a clear signal of panic and loss of trust.

Multisignature as a solution

Notably, no confirmed theft affected multisig addresses. Casa and Anchorwatch services reported a sharp increase in clients. As Unchained co-founder Dhruv Bansal rightly notes, the problem lies in a single point of failure, whether it be an exchange, a manufacturer, or the user themselves. Distributing risk across keys is becoming the new norm.

AI on the attackers' side

A troubling aspect is the possible use of AI. Galaxy suspects that some attackers used Chinese open-source LLMs without cybersecurity restrictions. Ironically, Bitcoin Red Team researchers, on the contrary, suffered from restrictions imposed by American AI companies. This underscores an arms race: AI democratizes vulnerability discovery, and the industry must adapt.

My conclusion: This incident is not just a hack, but a systemic failure of trust in hardware wallets. It serves as a reminder that even the most reliable solutions are not immune to code errors. I recommend that all Coldcard holders immediately migrate to multisignature schemes, and that the industry reconsider firmware audit standards. In the first half of 2026, crypto projects already lost $1.1 billion due to exploits, and this case could become a catalyst for stricter security requirements.