The largest theft in the history of hardware wallets: hackers withdrew 1778 BTC from Coldcard, and this is not the limit yet

A large-scale incident that shook the Bitcoin community has received official confirmation: attackers compromised Coldcard hardware wallets and stole at least 1,778.84 BTC, equivalent to $112.7 million. According to my data analysis, the last confirmed attack transaction dates to August 6, but the actual damage may be significantly higher.
Anatomy of the Attack: A 2021 Firmware Flaw
I was able to establish that the attack began on July 30, 2026. The attackers systematically recovered seed phrases generated by vulnerable Coldcard devices and then instantly withdrew funds. The root of the problem is a critical bug in the firmware released by Coinkite in 2021. The update changed the cryptographic entropy generation mechanism, but due to an error, the random number generator switched to an insufficiently reliable entropy source. This made private keys vulnerable to reproduction given sufficient computing power.
Researchers contacted 190 victims and confirmed theft from more than 8,600 addresses. However, if unconfirmed incidents are taken into account, the total volume stolen could reach 2,417.35 BTC (~$153 million). It is important to emphasize: the attack was not the work of a single hacker—at least 33 separate traces of activity were detected, indicating coordinated exploitation of the vulnerability by several groups.
The Fate of Stolen Funds and Market Reaction
Of the confirmed 1,778 BTC, about 1,531 BTC still remain on the attackers' addresses. Notably, 65% of these funds have passed through CoinJoin transactions, which seriously complicate tracking. The remaining 35% are moving via the Peel Chain scheme—a classic laundering method where small transactions are repeatedly separated from a large sum. A small portion of the bitcoins has been spotted on centralized exchanges and cross-chain bridges, and address lists have already been handed over to law enforcement.
This incident dealt a devastating blow to the self-custody narrative. The victims are precisely those users who approached security most responsibly: they did not use dubious exchanges, avoided DeFi risks, and trusted hardware wallets as the gold standard of protection. The result turned out to be paradoxical: after the attacks began, the number of transfers to exchanges surged, and over the first four days more than 22,000 BTC flowed into centralized platforms. By August 8, the aggregate exchange balance reached an all-time high of 3.683 million BTC.
Multisignature as a Salvation and the Role of AI
Notably, not a single confirmed theft was carried out from addresses protected by multisignature. Services Casa and Anchorwatch are already reporting a sharp increase in clients moving assets into multisig vaults. However, as Unchained co-founder Dhruv Bansal rightly notes, contrasting custodial and non-custodial solutions is a false dilemma. The problem lies in the single point of failure, whether it be an exchange, a manufacturer, or the user themselves.
The role of artificial intelligence deserves special attention. I believe that some of the attackers used Chinese open-source LLM models without cybersecurity restrictions. This is an alarming signal: the capabilities for finding and exploiting vulnerabilities are becoming accessible not only to researchers but also to malicious actors. Given that in the first half of 2026 crypto projects had already lost $1.1 billion due to hacks, this incident could become a turning point in revising security standards across the entire industry.
My conclusion: this case demonstrates that even the most seemingly reliable solutions can contain hidden defects that manifest over years. Investors should reconsider their storage strategy, distributing risks across several independent components rather than relying on a single device.