Crypto news

16.08.2026
01:25

Largest theft from hardware wallets: Coldcard hack cost 2417 BTC

hack

A large-scale incident with Coldcard hardware wallets has shaken the crypto community: the confirmed damage from the attack has already reached 1,778.84 BTC, equivalent to approximately $112.7 million. However, this is just the tip of the iceberg—taking into account unconfirmed episodes, losses could reach 2,417.35 BTC, or about $153 million. Notably, no new cases of hacking have been recorded since August 6, which suggests that the active phase of the attack has concluded.

Anatomy of the Attack: A 2021 Firmware Error

My analysis shows that the root of the problem lies in the Coinkite firmware update released in 2021. Engineers changed the mechanism for generating cryptographic entropy, but due to a software bug, the random number generator worked incorrectly. Devices silently switched to an alternative entropy source, which proved fatally weak for protecting private keys. This allowed attackers with sufficient computing power to reproduce seed phrases and withdraw funds from more than 8,600 addresses belonging to 190 victims.

Multiple Attackers and Money Laundering

It is important to emphasize that this was not the work of a single individual. Analysis of transaction chains has revealed at least 33 separate traces of activity, indicating coordinated exploitation of the vulnerability by several groups. Of the stolen funds, about 1,531 BTC still remain on the attackers' addresses, while 246 BTC have already been moved. Notably, 65% of the stolen coins passed through CoinJoin mixers, and 35% through Peel Chain sequences, which seriously complicates their tracking. A small portion of the funds has been spotted on centralized exchanges and cross-chain bridges, and I have forwarded the lists of addresses to compliance services and law enforcement agencies.

A Blow to the Self-Custody Narrative

This incident deals a devastating blow to the very idea of non-custodial storage. The victims are not inexperienced users chasing hype. They adhered to best practices: they used hardware wallets and avoided dubious exchanges and DeFi protocols. Nevertheless, a single point of failure in the form of a vulnerable device nullified all their efforts. The market reaction was immediate: in the first four days after the attacks began, more than 22,000 BTC were deposited into exchanges, and the aggregate balance reached an all-time high of 3.683 million BTC. This is a clear signal of panic and loss of trust.

Multisignature as a Salvation and the Role of AI

It is telling that no confirmed theft was carried out from multisig addresses. Services Casa and Anchorwatch have reported a sharp increase in clients, confirming a shift toward risk distribution. However, I believe that perceiving this as a victory of custodial solutions over non-custodial ones would be a mistake. The problem is deeper: any single point of failure, whether it be an exchange or a specific manufacturer, is dangerous. Separately, I would note a troubling aspect—the use of AI models by attackers, especially Chinese open-source LLMs. This lowers the entry barrier for cybercriminals and makes finding vulnerabilities in code accessible to the masses.

My conclusion: this hack is not just a technical failure, but a systemic challenge to the entire industry. It demonstrates that even the most seemingly reliable solutions can contain hidden defects that manifest over years. I recommend that all Coldcard users immediately migrate to new addresses and seriously consider multisignature as a security standard, not a luxury.