Crypto news

15.08.2026
23:25

Attack on Coldcard: Over 1,700 BTC stolen, and this is just the tip of the iceberg

hack

A large-scale campaign against Coldcard hardware wallet owners has turned into the biggest incident of the year in the realm of crypto self-custody. Based on my data, the confirmed damage amounts to at least 1,778.84 BTC, equivalent to $112.7 million. However, the real picture is far more alarming: factoring in unconfirmed episodes, losses could reach 2,417.35 BTC, or about $153 million.

Systemic failure in key generation

The attack began on July 30, 2026. Attackers deliberately recovered seed phrases created by Coldcard devices and transferred funds to their own addresses. The root of the problem lies in a 2021 firmware update from Coinkite. A change to the entropy generation mechanism led to a critical flaw: the random number generator worked incorrectly, and devices silently switched to an insufficiently reliable entropy source. This allowed attackers to reproduce private keys given sufficient computing power.

It is important to emphasize: the vulnerability existed for years but only manifested now. The last confirmed attack is dated August 6, after which no new cases of compromise were recorded. Likely, owners managed to withdraw funds, or hackers exhausted the available pool. Moreover, this is not about a single attacker—I see at least 33 parallel traces of activity, indicating coordinated exploitation of the vulnerability by several groups.

The fate of the stolen funds

Of the confirmed 1,778 BTC, about 1,531 BTC remain under hacker control to this day. Approximately 246 BTC have already been moved, with 65% passing through CoinJoin transactions, which seriously complicate tracking. The remaining 35% moved via the Peel Chain scheme—a classic laundering technique where small transactions are peeled off from a large sum. Some funds have been spotted on centralized exchanges and cross-chain bridges, and I have passed address lists to compliance departments and law enforcement agencies.

A blow to the self-custody narrative

This incident strikes at the very essence of the "not your keys, not your coins" idea. The victims are not novices taking risks on dubious platforms. They used hardware wallets considered the gold standard of security. The result is panic: in the first four days of the attacks, more than 22,000 BTC flowed into exchanges, and by August 8, the balance on centralized platforms reached an all-time high of 3.683 million BTC.

Notably, no confirmed theft affected multisignature addresses. Services like Casa and Anchorwatch report a sharp increase in clients. However, I agree with the view that contrasting custodial and non-custodial solutions is a false dilemma. The problem lies in a single point of failure, whether it be an exchange, a manufacturer, or the user themselves. Distributing risk across multiple keys and independent components is the only sensible way forward.

AI as an escalation factor

I would separately note the likely use of AI by attackers. Some groups appear to have used Chinese open-source LLMs without strict cybersecurity restrictions. This is an alarming signal: while American AI companies impose restrictions, researchers from Bitcoin Red Team face the opposite problem—they lack powerful models for defense. In an era of widespread AI, vulnerability discovery becomes accessible not only to defenders but also to malicious actors.

My conclusion: this incident is not a one-off mistake but a systemic challenge to the entire industry. Against the backdrop of a record $1.1 billion in losses from hacks in the first half of 2026, the Coldcard attack demonstrates that security is not a static product but a continuous process of auditing and adaptation. Investors should reconsider their storage schemes, and manufacturers should invest in independent code reviews before hackers do.