The biggest blow to self-custody: the Coldcard hack cost 1,778 BTC

A large-scale attack on Coldcard hardware wallets resulted in losses of 1,778.84 BTC, equivalent to approximately $112.7 million. According to my analysis of data obtained during the investigation, the attackers exploited a critical vulnerability in entropy generation, calling into question the reliability of even the most "secure" storage methods.
Anatomy of the attack: the root of the problem in the 2021 firmware
Researchers confirmed the theft of funds from more than 8,600 addresses, having contacted 190 victims. However, the actual damage may be higher: taking into account unconfirmed episodes, it is estimated at 2,417.35 BTC (~$153 million). The attack began on July 30, 2026, when hackers began systematically recovering seed phrases generated by vulnerable devices.
The cause lies in an error made by Coinkite in 2021 during a firmware update. The modified cryptographic entropy generation mechanism worked incorrectly, leading to the use of an insufficiently reliable source of randomness. This allowed attackers with sufficient computing power to reproduce private keys. Notably, the problem existed for years but only manifested itself now, highlighting the hidden risks in long-term asset storage.
Cessation of attacks and multiple traces
The last confirmed chain of attacks dates to August 6. After this date, no new episodes were recorded, likely because owners transferred funds or most of the available coins had already been stolen. It is important to note that not one but at least several attackers were involved — Galaxy discovered 33 separate traces of activity, indicating coordinated exploitation of the vulnerability.
The fate of the stolen funds
Of the confirmed 1,778 BTC, about 1,531 BTC remain on hackers' addresses, while 246 BTC have already been moved. About 65% of these funds passed through CoinJoin transactions, which complicate tracking, and 35% through Peel Chain schemes, typical for laundering. Some coins were spotted on centralized exchanges and cross-chain bridges, to which lists of addresses for blocking have already been sent.
A blow to the self-custody narrative
This incident is not just a financial loss. The victims were exemplary proponents of self-custody: they did not use dubious services but trusted hardware wallets. As a result, trust in this model has been undermined. After the attacks began, a sharp increase in transfers to exchanges was observed: more than 22,000 BTC arrived in four days, and by August 8, the balance on platforms reached an all-time high of 3.683 million BTC. This shows how fear of vulnerability can reverse the trend toward decentralization.
Multisignature as a solution
It is telling that no confirmed theft was carried out from multisig addresses. Casa and Anchorwatch services recorded a surge of interest in such solutions. However, as Unchained co-founder Dhruv Bansal rightly notes, the problem is not custodianship but a single point of failure — whether it be an exchange, a manufacturer, or the user themselves. The incident forces a rethink of storage approaches in favor of distributing risk across multiple keys.
The role of AI in the attack
Special attention deserves the possible use of AI. Galaxy suggests that some attackers used Chinese open-source LLMs without cybersecurity restrictions. This is an alarming signal: AI capabilities for finding vulnerabilities are becoming available not only to defenders but also to attackers. At the same time, Bitcoin Red Team researchers faced the opposite problem — restrictions from American AI companies hinder the use of powerful models for protection.
My comment: This case is a wake-up call for the entire industry. Even the most reliable hardware wallets are not absolute protection if their firmware contains hidden defects. I believe that in the future we will see stricter audit standards and a transition to multisig solutions as the new security standard. The $112 million in losses is the price the market pays for excessive overconfidence.