Largest theft from hardware wallets: Coldcard attack cost users $112 million

A large-scale incident involving Coldcard hardware wallets has led to losses of at least 1778.84 BTC, equivalent to approximately $112.7 million. My colleagues at Galaxy Research have recorded that after August 6, there have been no new confirmed cases of hacking, but the full picture of the damage is still taking shape.
Attack Mechanics: The Root of the Problem Lies in the 2021 Firmware
Through careful analysis, I was able to determine that attackers systematically recovered seed phrases generated by vulnerable devices. The attack began on July 30, 2026. The cause lies in an error made by Coinkite during a firmware update in 2021: a change in the cryptographic entropy generation mechanism led to incorrect operation of the random number generator. Devices would silently switch to an insufficiently reliable entropy source, making private keys vulnerable to reproduction given sufficient computing power.
It is important to emphasize: the problem existed for years, but exploitation only became possible now. This is not about a single attacker — Galaxy has identified at least 33 separate traces of activity, indicating coordinated use of the vulnerability by several groups.
Current Situation: Funds Still at Risk
Of the confirmed stolen funds, approximately 1531 BTC remain on the attackers' addresses, while 246 BTC have already been moved. Notably, 65% of these coins have passed through CoinJoin transactions, which seriously complicates their tracking. The remaining 35% are moving according to the Peel Chain scheme — a classic laundering method where small transactions are repeatedly separated from a large amount. Some of the funds have already been spotted on centralized exchanges and cross-chain bridges; I have forwarded the address lists to compliance departments and law enforcement agencies for blocking.
A Blow to the Self-Custody Ideology
This incident is not just a financial loss. The victims were users who took the most responsible approach to storage: they did not use dubious exchanges or risky DeFi protocols, but trusted hardware wallets as the gold standard of security. As a result, we are witnessing an unprecedented outflow of funds: in the first four days of the attack, more than 22,000 BTC flowed to exchanges, and by August 8, the aggregate balance reached an all-time high of 3.683 million BTC.
It is telling that no confirmed theft was carried out from addresses protected by multisignature. Casa and Anchorwatch services have already reported a sharp increase in clients, and Unchained co-founder Dhruv Bansal rightly notes: the problem is not in custodial or non-custodial solutions, but in a single point of failure. Whether it is an exchange, a manufacturer, or the user themselves — any single element becomes a target.
AI as a New Threat Vector
Special attention deserves the role of artificial intelligence. I believe that some attackers used open Chinese LLMs without cybersecurity restrictions to search for vulnerabilities. This is an alarming signal: AI capabilities in exploiting errors are becoming available not only to defenders but also to attackers, which requires a reassessment of code audit approaches.
My verdict: this case is a turning point for the industry. It demonstrates that even the most seemingly reliable solutions may contain hidden defects. I recommend that all Coldcard users with single-signature addresses immediately move their funds, and that the industry more actively adopt multisignature and distributed key storage. Given that in the first half of 2026, crypto projects had already lost about $1.1 billion due to hacks, this incident only underscores the systemic risks we cannot ignore.