Crypto news

16.08.2026
00:45

Largest theft from hardware wallets: 1700+ BTC leaked from Coldcard due to a fatal bug in the random number generator

hack

A large-scale incident involving Coldcard hardware wallets has shaken the community: confirmed damages from the attack on vulnerable devices have reached 1,778.84 BTC, equivalent to approximately $112.7 million. However, based on my data, the real picture may be far grimmer—including unconfirmed episodes, losses are estimated at 2,417.35 BTC (~$153 million).

Root of the Problem: A 2021 Error

The attack began on July 30, 2026, when attackers systematically recovered seed phrases generated by vulnerable devices. The cause is a critical bug in the Coinkite firmware released in 2021. The manufacturer changed the cryptographic entropy generation mechanism, but the new random number generator worked incorrectly. The devices silently switched to an alternative entropy source, which proved catastrophically weak for protecting private keys.

The problem existed for years but only surfaced now: with sufficient computing power, hackers were able to reproduce private keys created on these devices. This is a classic example of how a "dormant" vulnerability in trusted hardware turns into a time bomb.

Attacks Have Stopped, But Not Because Defense Won

The last confirmed chain of breaches dates to August 6. Since then, new victims have reached out to researchers, but no confirmed thefts have occurred. This is likely because owners managed to withdraw funds, or most available coins have already been stolen. It is important to note: this is not about a single attacker—Galaxy has identified at least 33 traces of activity, indicating coordinated exploitation of the vulnerability by multiple groups.

The Fate of Stolen Funds

Of the 1,778 BTC confirmed as stolen, about 1,531 BTC still remain on attackers' addresses. Approximately 65% of these coins have passed through CoinJoin transactions, which seriously complicate tracking. The remaining 35% are moving via the Peel Chain scheme—a classic laundering method where small transactions are repeatedly split off from a large sum. A small portion of the funds has been spotted on centralized exchanges and cross-chain bridges, to which Galaxy has already sent lists of addresses for blocking.

A Blow to the Self-Custody Ideology

This incident strikes not only at wallets but also at the very philosophy of self-custody. The victims are not newcomers taking risks on dubious platforms. They are disciplined users who trusted "hardware" considered the gold standard of security. The result is panic: in the first four days of the attack, more than 22,000 BTC flowed into exchanges, and the aggregate balance on platforms reached an all-time high of 3.683 million BTC by August 8.

Multisignature as a Lifeline

Notably, no confirmed theft has affected multisignature addresses. This has triggered a sharp surge in interest in multisig solutions—Casa and Anchorwatch services report an influx of clients. However, as Unchained co-founder Dhruv Bansal rightly notes, the problem runs deeper: a single point of failure can exist anywhere—from an exchange to a hardware manufacturer. Multisignature distributes risk but does not eliminate it entirely.

AI on the Side of Evil

A separate concern is the likely use of AI by attackers. Galaxy believes that some hackers used Chinese open-source LLMs without cybersecurity restrictions. This is ironic: Bitcoin Red Team researchers, by contrast, have found that restrictions from American AI companies prevent them from using the most powerful models for defense. We are entering an era where AI levels the playing field between defenders and attackers, and this incident is just the first warning bell.

My verdict: this is not just a technical failure but a systemic blow to trust in hardware wallets. Users with single-signature Coldcards should immediately migrate to new addresses, preferably with multisignature. In the context of record $1.1 billion losses from hacks in the first half of 2026, this case should serve as a catalyst for revising security standards in the industry.