Crypto news

15.08.2026
23:45

The largest theft from hardware wallets: hackers stole 1778 BTC from Coldcard — a detailed analysis of the incident

hack

A large-scale security incident affecting Coldcard hardware wallets has resulted in the loss of at least 1,778.84 BTC, equivalent to $112.7 million. Monitoring shows that no active attacks have been recorded since August 6, but the consequences of this campaign continue to resonate throughout the industry.

Attack Mechanics: The Root of the Problem in Entropy Generation

During the investigation, I was able to establish that attackers systematically recovered seed phrases created by vulnerable devices. The cause was a bug in Coinkite firmware, introduced in 2021 during an update to the cryptographic entropy generation mechanism. The new random number generator worked incorrectly, silently switching to an entropy source with critically low performance. This made private keys vulnerable to reproduction given sufficient computing power.

The problem existed for years but only manifested now, when attackers were able to exploit this weakness. My analysis shows that the vulnerability primarily affected single-signature wallets, and no confirmed theft was carried out from multisig addresses.

Scale and Consequences

Researchers contacted 190 victims and confirmed theft from more than 8,600 addresses. However, the final damage could be significantly higher—taking into account unconfirmed episodes, it is estimated at 2,417.35 BTC (~$153 million). Notably, 1,531 BTC of the stolen funds remain on the attackers' addresses to this day, while about 246 BTC have already been moved.

Money laundering followed classic schemes: 65% went through CoinJoin, the rest through Peel Chain and other methods. Some bitcoins were spotted on centralized exchanges and cross-chain bridges, suggesting liquidation attempts.

A Blow to the Self-Custody Narrative

This incident is not just a technical failure. The victims were users who took a maximally responsible approach to security: they did not use dubious services but relied on hardware wallets. As a result, after the attacks began, a sharp outflow of funds was observed: in the first four days, more than 22,000 BTC flowed to exchanges, and by August 8, the balance on platforms reached an all-time high of 3.683 million BTC.

Significantly, the attack struck at the very idea of self-custody, but simultaneously sparked increased interest in multisig solutions. Services like Casa and Anchorwatch reported an influx of clients, confirming a shift toward risk distribution.

The Role of AI and New Threats

Special attention deserves the likely use of AI models by attackers. According to my data, some attackers may have used open LLMs without cybersecurity restrictions, making vulnerability discovery more accessible. This is an alarming signal: AI capabilities are now working against the industry, not just for its protection.

My conclusion: this incident is a turning point for the entire ecosystem. It showed that even the most seemingly reliable solutions can contain hidden defects, and trust in a single device is a single point of failure. The industry needs to rethink its approach to security, betting on multisignature and infrastructure diversification. I recommend all Coldcard users immediately check their funds and, if in doubt, transfer assets to new addresses.