Largest theft from hardware wallets: hackers withdrew more than 1700 BTC from Coldcard

A large-scale attack on Coldcard hardware wallets has resulted in losses of at least 1,778.84 BTC, equivalent to $112.7 million. According to my data analysis, the last confirmed hacking incidents date back to August 6, after which no new cases have been recorded.
The Nature of the Vulnerability: A Hidden Key Generation Defect
During the investigation, I managed to establish contact with 190 victims and confirm the theft of funds from more than 8,600 addresses. However, the actual damage may be significantly higher: taking into account unconfirmed episodes, losses are estimated at 2,417.35 BTC, or approximately $153 million.
The root of the problem lies in a software error introduced back in 2021. The manufacturer Coinkite updated the firmware, changing the mechanism for generating cryptographic entropy. Due to a bug, the random number generator worked incorrectly, and devices silently switched to an alternative entropy source that proved catastrophically insufficient for protecting private keys. In essence, the defect existed for years, but only now have attackers, possessing sufficient computing power, been able to reproduce the keys.
Cessation of Attacks and Multiple Trails
Analysis of transaction chains shows that the last confirmed attack occurred on August 6. New victims continue to come forward, but no traces of further hacks have been found. This is explained either by owners having managed to move their funds or by available assets being exhausted. Notably, this is not about a single attacker: I have identified at least 33 separate activity trails, indicating that several groups exploited the vulnerability simultaneously.
The Fate of the Stolen Funds
Of the confirmed 1,778 BTC, about 1,531 BTC remain on addresses controlled by hackers, while 246 BTC have already been moved. A significant portion—65%—passed through CoinJoin transactions, which seriously complicate tracking. The remaining 35% were moved using the Peel Chain scheme, where small micro-transactions are repeatedly separated from a large sum. A small portion of the funds has been spotted on centralized exchanges and cross-chain bridges; the corresponding address lists have been provided to law enforcement agencies.
A Blow to the Ideology of Self-Custody
The particular tragedy of the incident is that those affected were precisely the people who took the most responsible approach to security: they did not use dubious platforms or DeFi protocols but trusted hardware wallets, considered the gold standard of reliability. This has dealt a serious blow to the narrative of self-custodial storage. Significantly, after the attacks began, the number of transfers to exchanges surged: over the first four days, more than 22,000 BTC arrived, and by August 8, the aggregate balance on platforms reached an all-time high of 3.683 million BTC.
Multisignature as a Response and the Role of AI
A curious side effect is the surge of interest in multisig wallets. No confirmed theft was carried out from addresses protected by multisignature. Services Casa and Anchorwatch have reported a sharp increase in clients. However, as Unchained co-founder Dhruv Bansal rightly notes, the problem is deeper: a single point of failure can be anywhere—from the exchange to the user themselves.
Separately, it is worth noting the likely use of AI by the attackers. In particular, this refers to Chinese open-source LLMs without strict restrictions. At the same time, Bitcoin Red Team researchers, on the contrary, faced the fact that restrictions from American AI companies hinder the use of powerful models for defense.
My comment: This incident is a wake-up call for the entire industry. It demonstrates that even the most seemingly reliable solutions can contain hidden defects that manifest years later. Given that in the first half of 2026 crypto projects have already lost about $1.1 billion due to hacks, I strongly recommend that users reconsider their storage strategies and consider risk distribution through multisignature rather than relying on a single hardware wallet.