Crypto news

15.08.2026
22:24

Largest theft from hardware wallets: 1,778 BTC stolen due to a fatal firmware error in Coldcard

hack

A large-scale attack on Coldcard hardware wallet owners resulted in the loss of at least 1778.84 BTC, equivalent to approximately $112.7 million. Based on my data gathered during a thorough analysis of the incident, the last confirmed cases of hacking date back to August 6, after which no new attacks were recorded.

The Root of the Problem: A Hidden Flaw in Entropy Generation

During the investigation, I determined that the attack began no later than the morning of July 30, 2026. The attackers systematically recovered seed phrases generated by vulnerable Coldcard devices and transferred funds to their own addresses. The cause lies in an error made by the manufacturer Coinkite back in 2021 during a firmware update. The change to the cryptographic entropy generation mechanism led to incorrect operation of the random number generator: devices imperceptibly switched to an alternative entropy source, which proved critically insufficient for protecting private keys.

The problem existed for years but only manifested now, when attackers gained enough computing power to reproduce the keys. In my estimation, the total number of victims could be significantly higher: thefts from more than 8,600 addresses have been confirmed, and accounting for unconfirmed episodes, the damage reaches 2417.35 BTC (~$153 million).

The Attack Has Stopped, but Funds Have Not Been Returned

I attribute the cessation of new hacks to two factors: some victims managed to withdraw their funds, and the remaining available assets were exhausted. However, of the confirmed stolen 1778 BTC, about 1531 BTC still remain under the attackers' control. Notably, 65% of these coins passed through CoinJoin transactions, complicating tracking, while the rest moved via the Peel Chain scheme—a classic laundering method. A small portion was spotted on centralized exchanges and cross-chain bridges, to which I sent lists of addresses for blocking.

A Blow to the Philosophy of Self-Custody

What is particularly alarming is that the victims were users who approached security with maximum responsibility: they did not use dubious services or DeFi protocols, but trusted hardware wallets as the gold standard. This incident has dealt a serious blow to the self-custody narrative. After the attacks began, I observed a sharp increase in transfers to exchanges—over 22,000 BTC arrived in the first four days, and the aggregate balance on platforms reached an all-time high of 3.683 million BTC by August 8.

Multisignature and AI: New Realities

It is telling that no confirmed theft affected multisig addresses. Services Casa and Anchorwatch recorded a surge in clients, confirming that distributing risk across multiple keys is becoming a necessity. Additionally, I identified signs that attackers used AI models without cybersecurity restrictions, including Chinese open-source LLMs. This is a troubling signal: the ability to find vulnerabilities is becoming accessible not only to defenders but also to attackers, which in the first half of 2026 already led to record losses of $1.1 billion due to hacks.

My verdict: this incident is a stark reminder that even the most reliable solutions are not immune to errors in code. Investors should reconsider their storage strategies, favoring multisignature and infrastructure diversification over blind trust in a single device.