Crypto news

16.08.2026
00:05

Largest theft from hardware wallets: hackers withdrew 1700+ BTC from Coldcard due to a critical vulnerability

hack

A large-scale incident that shook the Bitcoin maximalist community has received official confirmation: as a result of exploiting a vulnerability in Coldcard hardware wallets, attackers stole at least 1,778.84 BTC, equivalent to $112.7 million. Monitoring shows that no new confirmed hacking cases have been recorded since August 6, but this is no reason for premature reassurance.

Anatomy of the attack: the root of the problem lies in entropy generation

I managed to get in touch with a team of analysts who conducted a deep investigation and identified 190 affected users, confirming the theft of funds from more than 8,600 addresses. The real picture may be even darker: taking into account unconfirmed episodes, the total damage is estimated at 2,417.35 BTC (about $153 million).

The root cause lies in a firmware update from Coinkite in 2021. The change to the cryptographic entropy generation mechanism led to a critical bug: the random number generator worked incorrectly, imperceptibly switching to an insufficiently reliable entropy source. This made private keys vulnerable to reproduction given sufficient computing power. The problem existed for years, but only now have attackers been able to exploit it.

Cessation of attacks and multiple traces

The attacks began on July 30, 2026, but after August 6, the chains of hacks broke off. Likely reasons are that users moved funds to new addresses, or the available assets have already been exhausted. It is important to note that this is not the work of a single hacker: at least 33 separate activity traces have been detected, indicating coordinated exploitation of the vulnerability by several groups.

The fate of the stolen funds

Of the confirmed 1,778 BTC, about 1,531 BTC still remain on addresses controlled by the attackers. The remaining 246 BTC have already been moved: 65% went through CoinJoin transactions, which complicate tracking, while 35% moved via the Peel Chain scheme, a classic laundering method. Some of the funds have been spotted on centralized exchanges and cross-chain bridges, and lists of addresses have already been handed over to law enforcement agencies and compliance companies.

A blow to the self-custody narrative

This incident is not just a financial loss, but an existential challenge to the ideology of self-custody. The affected users were exemplary custodians: no dubious exchanges, no risky DeFi protocols. They trusted hardware wallets, considered the gold standard of security. The result is panic in the market: in the first four days after the attacks began, more than 22,000 BTC flowed into exchanges, and the aggregate balance reached an all-time high of 3.683 million BTC by August 8.

Multisignature as a solution and the role of AI

Notably, no confirmed theft affected multisig addresses. Services Casa and Anchorwatch are recording a sharp increase in clients, but, as Unchained co-founder Dhruv Bansal rightly notes, the problem is deeper—it is a single point of failure, whether it be an exchange, a manufacturer, or the user themselves.

Of particular note is the possible use of AI in the attacks. There is reason to believe that some of the attackers used Chinese open-source LLMs without cybersecurity restrictions. The irony is that Bitcoin Red Team researchers, on the contrary, faced obstacles due to strict restrictions from American AI companies. This is a troubling signal: AI democratizes not only defense, but also attacks.

My analysis: This case is a watershed moment for the industry. It demonstrates that even the most reliable hardware solutions are not immune to errors in the software supply chain. Investors should reconsider their storage strategy, viewing multisignature not as an option, but as a necessity. In conditions where AI amplifies the capabilities of attackers, risk diversification becomes the only reasonable approach.