Crypto news

15.08.2026
22:45

Largest blow to self-custody: hackers drained 1700+ BTC from Coldcard hardware wallets

hack

A large-scale hacking campaign against Coldcard hardware wallets has resulted in losses of at least 1,778.84 BTC — equivalent to $112.7 million at the current exchange rate. According to my data analysis, the last confirmed attack dates back to August 6, with no new incidents recorded since.

Attack Details and Root Cause

During the investigation, contact was established with 190 victims, and the theft of funds from more than 8,600 addresses was confirmed. However, the actual damage may be significantly higher: accounting for unconfirmed episodes, the volume of stolen assets is estimated at 2,417.35 BTC (~$153 million). The attack began on the morning of July 30, 2026, when attackers systematically recovered seed phrases generated by vulnerable devices.

The root cause lies in a software error made by Coinkite in 2021. After a firmware update, the cryptographic entropy generation mechanism was changed, but due to a bug, the random number generator operated incorrectly, silently switching to an insufficiently reliable entropy source. This made private keys vulnerable to reproduction given sufficient computing power — the issue existed for years but only manifested now.

Cessation of Attacks and Multiple Trails

Galaxy Research suggests the attacks stopped for two reasons: either owners of vulnerable wallets managed to move funds to new addresses, or most of the available assets had already been stolen. Notably, this was not the work of a single attacker — at least 33 additional activity trails were detected, indicating that multiple attackers exploited the vulnerability simultaneously.

Fate of Stolen Funds

Of the confirmed 1,778 BTC, approximately 1,531 BTC still remain on hacker addresses, while about 246 BTC have already been moved. A significant portion of the funds — around 65% — passed through CoinJoin transactions, seriously complicating tracking. The remaining 35% continue to circulate across the blockchain, including the Peel Chain scheme used for laundering. A small share was spotted on centralized exchanges and cross-chain bridges, and address lists have already been handed over to law enforcement agencies.

Blow to the Self-Custody Ideology

This incident is particularly painful because the victims were users who took the most responsible approach to storage: they did not use dubious exchanges or risky DeFi protocols, but trusted hardware wallets — considered the gold standard of security. As a result, confidence in the self-custody narrative has been shaken: in the first four days after the attacks began, more than 22,000 BTC flowed into exchanges, and the aggregate balance on platforms reached an all-time high of 3.683 million BTC.

Rise of Multisignature and the Role of AI

Significantly, no confirmed theft was carried out from addresses protected by multisignature. Services Casa and Anchorwatch are already reporting a sharp increase in clients. As Unchained co-founder Dhruv Bansal rightly notes, the problem is not in custodial solutions, but in a single point of failure — whether it be an exchange, a manufacturer, or the user themselves. Separately, it is worth noting the possible use of AI models by attackers, including Chinese open-source LLMs, which underscores the growing accessibility of tools for finding vulnerabilities.

My comment: This case is a wake-up call for the entire industry. Against the backdrop of a record $1.1 billion in losses from hacks in the first half of 2026, the Coldcard attack demonstrates that even the most seemingly reliable solutions can contain hidden flaws. Investors should reconsider their approach to storage, distributing risks across multiple keys and independent components rather than relying on a single device.