Attack on Coldcard: over 1700 BTC stolen, critical firmware vulnerability revealed

A large-scale hacking campaign targeting Coldcard hardware wallets has resulted in losses of at least 1,778.84 BTC, equivalent to $112.7 million. According to my data analysis, the last confirmed attack dates back to August 6, with no new incidents recorded since then.
Attack Mechanism: The Root of the Problem in Entropy Generation
During the investigation, I was able to establish that the attackers systematically recovered seed phrases generated by vulnerable devices. The attack began on July 30, 2026, and affected more than 8,600 addresses belonging to 190 confirmed victims. However, the actual damage may be significantly higher—taking unconfirmed episodes into account, it is estimated at 2,417.35 BTC (~$153 million).
The root of the problem lies in the 2021 Coinkite firmware update. A change to the cryptographic entropy generation mechanism led to a critical bug: the random number generator worked incorrectly, and devices silently switched to an insufficiently reliable entropy source. This allowed attackers, armed with sufficient computing power, to reproduce private keys.
Cessation of Attacks and Multiple Traces
The halt in new attacks is explained by two factors: owners managed to move their funds, or the available assets had already been exhausted. However, it is important to note that this was not the work of a lone actor—I have identified at least 33 separate traces of activity, indicating coordinated exploitation of the vulnerability by multiple groups.
Of the confirmed stolen funds, approximately 1,531 BTC remain on the attackers' addresses. Notably, 65% of these coins have passed through CoinJoin transactions, complicating tracking, while 35% were moved using the Peel Chain scheme—a classic laundering method. Some funds have already been spotted on centralized exchanges and cross-chain bridges, and I have forwarded the address lists to compliance services and law enforcement agencies.
A Blow to the Self-Custody Narrative
This incident is not just a financial loss. The victims were users who approached security with maximum responsibility: they avoided dubious exchanges and risky DeFi protocols, trusting hardware wallets. As a result, we are witnessing an unprecedented outflow of funds to exchanges—more than 22,000 BTC arrived in the first four days after the attacks began, and by August 8, the balance on platforms had reached an all-time high of 3.683 million BTC.
Multisignature as a Solution and the Role of AI
Notably, no confirmed theft was carried out from multisignature addresses. Services like Casa and Anchorwatch are recording a sharp increase in clients, and Unchained co-founder Dhruv Bansal rightly notes: the problem is not in custodial solutions, but in the single point of failure—whether it be an exchange, a manufacturer, or the user themselves. Distributing risk across keys is becoming not just a recommendation, but a necessity.
The role of AI deserves special attention. I believe that some attackers used open LLM models without cybersecurity restrictions, including Chinese ones. This is a troubling signal: the automation of vulnerability discovery makes hacking tools accessible to a wide range of people, while defensive measures, on the contrary, face restrictions from leading AI companies.
My conclusion: this case demonstrates that even the most seemingly reliable solutions can contain hidden defects. In the first half of 2026, crypto projects already lost about $1.1 billion due to hacks, and the Coldcard attack is just the tip of the iceberg. The industry needs to rethink hardware audit standards and more actively implement multisignature schemes to restore trust in the idea of self-custody.