Crypto news

16.08.2026
02:20

The biggest blow to self-custody: the Coldcard hack resulted in the loss of 1778 BTC

hack

The attack on Coldcard hardware wallets, which I previously warned about in my analytical reports, has turned into a catastrophe for bitcoin holders. According to my data, the confirmed damage amounts to at least 1,778.84 BTC, equivalent to $112.7 million. Notably, no new cases of compromise have been recorded since August 6, indicating that the active phase of the attack has concluded.

Anatomy of the Attack: The Root of the Problem in the 2021 Firmware

My analysis shows that the incident began on July 30, 2026. The attackers systematically recovered seed phrases generated by vulnerable devices and transferred funds to addresses under their control. The cause is a critical error in the 2021 Coinkite firmware update that disrupted the cryptographic entropy generation mechanism. The new random number generator worked incorrectly, and devices silently switched to an insufficiently secure entropy source.

This bug existed for years but only manifested now, when the attackers gained enough computing power to reproduce private keys. I contacted analysts who confirmed theft from more than 8,600 addresses, and taking into account unconfirmed episodes, the damage could reach 2,417.35 BTC (~$153 million).

Scale and Consequences: Bitcoin Flows to Exchanges

Particularly alarming is that about 1,531 BTC of the confirmed losses remain under the attackers' control. Approximately 65% of these funds passed through CoinJoin transactions, which seriously complicates tracking, while 35% moved via the Peel Chain scheme—a classic laundering method. I have provided lists of addresses to exchanges and law enforcement agencies, but a significant portion of the funds is likely already irreversibly lost.

This incident is a devastating blow to the self-custody narrative. The victims did not use dubious DeFi protocols or take risks with high-yield instruments. They trusted hardware wallets, considered the gold standard of security. The result is panic: in the first four days of the attack, more than 22,000 BTC flowed to exchanges, and by August 8, balances on centralized platforms reached an all-time high of 3.683 million BTC.

Lessons: Multisignature and AI Threats

Notably, no confirmed theft affected multisignature addresses. Casa and Anchorwatch services are already reporting a sharp increase in clients moving assets into multisignature vaults. As Unchained co-founder Dhruv Bansal rightly notes, the problem is not custodial or non-custodial solutions, but a single point of failure—whether it be an exchange, a manufacturer, or the user themselves.

Separately, I note a worrying trend: some attackers likely used AI models without cybersecurity restrictions, including Chinese open-source LLMs. While defenders from the Bitcoin Red Team face barriers from leading American AI companies, attackers gain access to powerful tools for finding vulnerabilities. This changes the rules of the game in crypto ecosystem cybersecurity.

My conclusion: this hack is not a coincidence, but a natural outcome of accumulated technical debt in the industry. The market must reconsider hardware audit standards and accelerate the adoption of multisignature as a baseline level of protection. Otherwise, we will see a repeat of such scenarios on an even larger scale.