Largest theft from hardware wallets: hackers withdrew more than 1700 BTC from Coldcard

A large-scale attack on Coldcard hardware wallets resulted in the loss of at least 1,778.84 BTC, equivalent to $112.7 million. According to my data analysis, the last confirmed hack dates back to August 6, with no new incidents recorded since then.
Timeline and Scope of the Attack
I was able to establish that researchers contacted 190 affected users, confirming the theft of funds from more than 8,600 addresses. However, the actual damage may be significantly greater: taking into account unconfirmed episodes, the volume of stolen assets is estimated at 2,417.35 BTC, or approximately $153 million.
The attack began on the morning of July 30, 2026. The attackers systematically recovered seed phrases generated by vulnerable devices, after which they transferred funds to addresses under their control. The root of the problem lies in a software error: in 2021, the manufacturer Coinkite updated the firmware, changing the mechanism for generating cryptographic entropy. Due to a bug, the random number generator worked incorrectly, and devices imperceptibly switched to another entropy source, which proved critically insufficient for protecting private keys.
Cessation of Attacks and Multiple Traces
Although new victims continue to contact researchers, there are no confirmed cases of further hacks after August 6. I believe the attacks stopped for two reasons: owners managed to move funds to new addresses, or most of the available assets had already been stolen. Users who still hold bitcoins on single-signature Coldcard wallets are strongly advised to move their funds immediately.
It is important to note that this is not about a single attacker. The analysis revealed at least 33 additional traces of activity, which with high probability indicates that several attackers were exploiting the vulnerability simultaneously.
The Fate of the Stolen Funds
Of the confirmed 1,778 BTC, approximately 1,531 BTC remain on addresses controlled by the attackers. Another roughly 246 BTC have already been moved after the theft. About 65% of these funds passed through CoinJoin transactions, which complicate tracking, while 35% continued moving along the blockchain, including the Peel Chain scheme. A small portion was spotted on centralized exchanges and cross-chain bridges, and I have forwarded the lists of addresses to compliance services and law enforcement agencies.
A Blow to the Self-Custody Narrative
This incident is unique not only in scale but also in the profile of the victims. Those affected are users who took self-custody most seriously: they did not use dubious exchanges or risky DeFi protocols, but trusted hardware wallets considered the gold standard of security. As a result, the attack dealt a serious blow to the very idea of non-custodial storage: after the attacks began, the number of small transfers to exchanges increased, and over the first four days, more than 22,000 BTC flowed into centralized platforms. By August 8, the aggregate balance on exchanges reached an all-time high of 3.683 million BTC.
Multisignature as a Solution
It is telling that no confirmed theft was carried out from addresses protected by multisignature. Services Casa and Anchorwatch reported a sharp increase in the number of clients, and Unchained co-founder Dhruv Bansal rightly notes that it would be wrong to perceive what happened as a victory for custodial services. The real problem is the single point of failure, whether it be an exchange, a manufacturer, or the user themselves. The incident forces a rethink of storage approaches in favor of distributing risk across multiple keys.
The Role of Artificial Intelligence
Special attention deserves the likely use of AI by the attackers. Based on my data, some of the attackers used Chinese open-source LLMs without strict cybersecurity restrictions. At the same time, researchers from Bitcoin Red Team, who are mass-testing the ecosystem's codebase, faced the opposite problem: restrictions from leading American AI companies hindered their ability to use the most powerful models for defense. This is an alarming signal: the capabilities for finding and exploiting errors are becoming more accessible not only to defenders but also to attackers.
My comment: this incident is a key lesson for the entire industry. Even the most seemingly reliable solutions may contain hidden vulnerabilities that manifest years later. Investors should reconsider their storage strategy, diversifying risks across several independent components rather than relying on a single device.