Crypto news

15.08.2026
21:25

Largest theft from hardware wallets: hackers stole 1778 BTC due to a fatal bug in Coldcard

hack

A large-scale incident involving Coldcard hardware wallets has resulted in the loss of at least 1,778.84 BTC, equivalent to $112.7 million. My colleagues at Galaxy Research have confirmed the theft of funds from more than 8,600 addresses, having contacted 190 victims. However, the actual damage is likely higher: taking unconfirmed episodes into account, the figure could be 2,417.35 BTC (~$153 million). It is important to note that no new confirmed hacks have been recorded since August 6.

The root of the problem — an error in entropy generation

The attack began on July 30, 2026. The attackers systematically recovered seed phrases generated by vulnerable devices. The cause lies in a Coinkite firmware update in 2021: a change in the cryptographic entropy generation mechanism led to a critical bug. The random number generator malfunctioned, and devices silently switched to an entropy source insufficient for protecting private keys. The problem existed for years, but only now, with sufficient computing power, were hackers able to reproduce the keys.

Cessation of attacks and traces of multiple attackers

Galaxy suggests that the attacks subsided for two reasons: either owners managed to move their funds, or most of the available assets have already been stolen. To users still holding bitcoins on single-signature Coldcard wallets, I strongly recommend immediately moving their funds. Notably, this is not about a single hacker — researchers have found at least 33 additional traces of activity, indicating that several groups were exploiting the vulnerability simultaneously.

The fate of the stolen funds

Of the confirmed 1,778 BTC, about 1,531 BTC remain on the attackers' addresses. Approximately 246 BTC have already been moved, with 65% passing through CoinJoin transactions, which complicate tracking, and 35% following the Peel Chain scheme, typical for laundering. A small portion has been spotted on exchanges and cross-chain bridges; Galaxy has already provided lists of addresses to exchanges and law enforcement.

A blow to the idea of self-custody

The particular tragedy of the incident is that the victims were users who took the most responsible approach to storage: no dubious exchanges, risky DeFi protocols, or hype tools. They trusted hardware wallets — the gold standard of security. This dealt a serious blow to the self-custody narrative: in the first four days of the attacks, more than 22,000 BTC flowed into exchanges, and by August 8, the aggregate balance reached an all-time high of 3.683 million BTC.

Multisignature as a solution

It is telling that no confirmed theft was carried out from multisig addresses. Services Casa and Anchorwatch report a sharp increase in clients, and Unchained co-founder Dhruv Bansal rightly notes: the problem is not custodial vs. non-custodial solutions, but a single point of failure. Whether it is an exchange, a manufacturer, or the user themselves — any single element becomes a vulnerability. Distributing risk across multiple keys — that is the lesson of this incident.

AI on the attackers' side

A troubling aspect is the likely use of unrestricted AI models, including Chinese open-source LLMs. This highlights a growing gap: while American companies impose strict frameworks for protection, researchers from Bitcoin Red Team face obstacles, while attackers gain access to powerful tools for finding exploits. Against the backdrop of a record $1.1 billion in losses from hacks in the first half of 2026, this case is a wake-up call for the entire industry.

My analysis: this incident is not just a technical failure, but a systemic challenge. It demonstrates that even the most reliable solutions can contain hidden defects, and trusting a single device is a risky strategy. The market needs hardware audit standards and incentives for multisig adoption, otherwise we will see a repeat of similar catastrophes.