Crypto news

16.08.2026
01:44

Largest theft from hardware wallets: hackers withdrew 1778 BTC due to a fatal Coldcard bug

hack

A large-scale incident that shook the crypto community has received official confirmation: as a result of the exploitation of a critical vulnerability in Coldcard hardware wallets, attackers stole at least 1,778.84 BTC, equivalent to $112.7 million. Monitoring conducted by my team shows that after August 6, no new confirmed cases of hacking have been recorded, but this does not reduce the severity of what happened.

Attack on Coldcard: Timeline and Scale

During the investigation, contact was established with 190 victims and the theft of funds from more than 8,600 addresses was confirmed. At the same time, the real damage is likely significantly higher: taking into account unconfirmed episodes, losses could reach 2,417.35 BTC (~$153 million). The attack began on the morning of July 30, 2026, when attackers began systematically recovering seed phrases generated by vulnerable devices.

The root of the problem lies in an error made by the manufacturer Coinkite in 2021 during a firmware update. A change in the cryptographic entropy generation mechanism led to incorrect operation of the random number generator. Devices silently switched to an alternative entropy source, which proved critically insufficient to protect private keys. This time bomb existed for years, and only now, with sufficient computing power, were hackers able to reproduce the keys.

Cessation of Attacks and New Threats

The last confirmed chain of attacks dates to August 6. The attacks likely ceased either because owners managed to move funds to new addresses, or because most of the available assets had already been compromised. It is important to note that these were not lone actors—traces of at least 33 different attackers have been found, indicating coordinated exploitation of the vulnerability.

Of the confirmed stolen funds, about 1,531 BTC still remain on hackers' addresses. Laundering is in full swing: 65% went through CoinJoin transactions, and 35% are being moved using the Peel Chain scheme, which seriously complicates tracking. Some of the coins have already appeared on centralized exchanges and cross-chain bridges, where I and other analysts have sent lists of addresses for blocking.

Blow to the Self-Custody Narrative

This incident deals a devastating blow to the idea of self-custody. The victims are not inexperienced users taking risks on dubious platforms. They did everything right: they stored bitcoins in hardware wallets considered the gold standard of security. Nevertheless, a single point of failure in the form of the device manufacturer led to disaster. Notably, after the attacks began, a sharp outflow of funds to exchanges was observed: over the first four days, more than 22,000 BTC arrived, and by August 8, the aggregate balance on platforms reached an all-time high of 3.683 million BTC.

Multisignature and the Role of AI

Notably, not a single confirmed theft was carried out from multisig addresses. This has sparked a surge of interest in multisignature solutions—Casa and Anchorwatch services report a sharp increase in clients. However, as experts like Dhruv Bansal rightly note, the problem is not custodianship, but the presence of a single point of failure, whether it be an exchange, a manufacturer, or the user themselves. Distributing risk across multiple keys is becoming not just a recommendation, but a necessity.

The use of AI by attackers deserves special attention. According to my data, some hackers used Chinese open-source LLMs without cybersecurity restrictions. This is an alarming signal: while Bitcoin Red Team researchers face restrictions from leading American AI companies, attackers gain access to powerful tools for finding vulnerabilities. Against the backdrop of a record $1.1 billion in losses from hacks in the first half of 2026, this incident underscores that security in cryptocurrencies is not a static state, but a constant arms race.

My verdict: the Coldcard incident is not just another hack, but a systemic failure in the hardware wallet industry that will force a reassessment of audit standards and trust in manufacturers. I recommend that all users, even those not using Coldcard, reconsider their storage model and consider multisignature as a baseline level of protection.