Crypto news

15.08.2026
21:05

Attack on Coldcard: how a vulnerability in the random number generator led to the loss of $112 million in BTC

hack

A large-scale campaign against Coldcard hardware wallet users has resulted in the largest incident in the Bitcoin self-custody space in recent years. Based on my data, the confirmed damage amounts to at least 1,778.84 BTC, equivalent to $112.7 million, but actual losses could be significantly higher—up to 2,417.35 BTC (~$153 million) when accounting for unconfirmed episodes.

Root of the problem: a 2021 firmware bug

The attack began on July 30, 2026, when attackers systematically recovered seed phrases generated by vulnerable devices. The cause lies in a Coinkite firmware update released in 2021. Due to a bug in the new random number generator, devices silently switched to an alternative entropy source, which proved critically weak for protecting private keys.

The problem existed for years, but only now, with growing computational power, have attackers been able to reproduce the private keys. It is important to emphasize: this is not a single hacker. Galaxy Research identified at least 33 separate traces of activity, indicating coordinated exploitation of the vulnerability by multiple groups.

Current situation and fund movements

The last confirmed attack dates to August 6, after which no new breach cases have been recorded. However, of the stolen funds, approximately 1,531 BTC remain on attackers' addresses, while 246 BTC have already been moved. Notably, 65% of the stolen coins passed through CoinJoin transactions, complicating tracking, while 35% went through the Peel Chain scheme used for laundering.

A blow to the self-custody narrative

This incident is not just a financial loss. The victims were exemplary proponents of self-custody: they did not use dubious exchanges or DeFi protocols but trusted a hardware wallet as the gold standard of security. As a result, confidence in this model has been undermined: within the first four days of the attacks, more than 22,000 BTC flowed to exchanges, and by August 8, the balance on centralized platforms reached an all-time high of 3.683 million BTC.

Multisignature as a solution and the role of AI

Significantly, no confirmed theft affected multisig addresses. Services Casa and Anchorwatch report a sharp increase in clients, confirming that distributing risk across multiple keys is becoming the new security standard. At the same time, Galaxy points to a troubling trend—some attackers used AI models to find vulnerabilities, making such exploits more accessible to cybercriminals.

My conclusion: this case is a wake-up call for the entire industry. Even the most reliable hardware is not immune to software errors, and a single point of failure—whether a device or an exchange—carries catastrophic risks. Investors should reconsider their approach to storage, diversifying not only assets but also security infrastructure.