Largest theft from hardware wallets: Coldcard vulnerability cost BTC holders $112 million

A large-scale incident involving Coldcard hardware wallets has shaken the crypto community: attackers withdrew at least 1,778.84 BTC, equivalent to $112.7 million. According to my analysis of data obtained during the investigation, the attack affected more than 8,600 addresses, and this is far from the limit — taking into account unconfirmed episodes, the actual damage could reach 2,417.35 BTC (~$153 million).
The root of the problem: a hidden bug in entropy generation
The attack began on July 30, 2026, when hackers systematically recovered seed phrases generated by vulnerable devices. The cause lies in an error embedded in Coinkite's firmware back in 2021. The update changed the cryptographic entropy generation mechanism, but due to a bug, the random number generator worked incorrectly, imperceptibly switching to a source with critically insufficient protection of private keys. The problem existed for years, but only now, with the growth of computing power, has it become exploitable.
It is important to note that no new confirmed hacks have been recorded after August 6. This is explained either by the fact that owners managed to transfer their funds, or by the fact that most of the available assets had already been stolen. However, I emphasize: users who still store BTC on single-signature Coldcard wallets must immediately migrate to new addresses.
Traces lead to multiple attackers
This is not about a single attacker. My analysis has identified at least 33 separate traces of activity, indicating coordinated exploitation of the vulnerability by several groups. Of the confirmed 1,778 BTC, about 1,531 BTC remain on hacker-controlled addresses, while 246 BTC have already been moved. Notably, 65% of the funds passed through CoinJoin transactions, complicating tracking, and 35% through Peel Chain schemes, a classic laundering method.
A blow to the ideology of self-custody
The incident strikes at the very concept of self-custody. The victims are not inexperienced users, but those who deliberately avoided exchanges and DeFi risks, trusting hardware wallets. This triggered panic: in the first four days, more than 22,000 BTC flowed to exchanges, and by August 8, balances on centralized platforms reached an all-time high of 3.683 million BTC.
Multisignature as salvation
It is telling that no confirmed theft affected multisig addresses. Casa and Anchorwatch services are already reporting a sharp increase in clients. However, as Unchained co-founder Dhruv Bansal rightly notes, the problem is deeper — it is a single point of failure, whether it be an exchange, a manufacturer, or the user themselves. Distributing risk across multiple keys is becoming not a recommendation, but a necessity.
Special attention deserves the role of AI: some attackers likely used Chinese open-source LLMs without cybersecurity restrictions, making vulnerability discovery accessible to a wide range of people. Against the backdrop of a record $1.1 billion in losses from hacks in the first half of 2026, this case is an alarming signal for the entire industry.
My expert opinion: this incident is a turning point. It proves that even the "gold standard" of hardware storage is not immune to hidden defects. Investors should reconsider their strategies: multisignature and key diversification are not paranoia, but basic hygiene in a new reality where AI amplifies both defense and attacks.