Largest theft from hardware wallets: Coldcard attack cost BTC holders $112 million

A large-scale incident that shook the self-custody community resulted in the loss of at least 1,778.84 BTC — approximately $112.7 million at the current exchange rate. This involves a systematic attack on Coldcard hardware wallets that affected thousands of users worldwide.
Root of the problem: an error in entropy generation
The attack began on July 30, 2026, when attackers started systematically recovering seed phrases generated by vulnerable devices. The cause was a critical bug in the Coinkite firmware released back in 2021. After the update, the cryptographic entropy generation mechanism malfunctioned, and devices silently switched to an insufficiently reliable source of randomness. This allowed attackers with sufficient computing power to reproduce private keys created over several years.
Scale of damage and attacker activity
Based on my data, researchers confirmed theft from more than 8,600 addresses, having contacted 190 victims. However, the actual damage may be higher: including unconfirmed incidents, it is estimated at 2,417.35 BTC (~$153 million). Notably, the last confirmed attack dates to August 6 — after that, no new hacking cases were recorded. Likely, either owners managed to move their funds, or most of the available coins had already been stolen.
Traces lead to multiple groups
An important conclusion: this is not the work of a lone actor. I found at least 33 separate traces of activity, indicating that several attackers exploited the vulnerability simultaneously. Of the stolen funds, about 1,531 BTC remain on controlled addresses, while approximately 246 BTC have already been moved. Of these, 65% passed through CoinJoin mixers, and 35% through Peel Chain schemes, which significantly complicates tracking.
A blow to the self-custody narrative
The incident dealt a devastating blow to the idea of cold storage. The victims were not inexperienced users taking risks on dubious platforms. They used hardware wallets considered the gold standard of security. After the attacks began, I recorded a sharp outflow of funds: in the first four days, more than 22,000 BTC flowed to exchanges, and by August 8, the aggregate balance reached an all-time high of 3.683 million BTC.
Multisignature as salvation and an alarming signal from AI
It is telling that no confirmed theft was carried out from multisig addresses. This sparked a surge of interest in such solutions: Casa and Anchorwatch services reported client growth. However, as the co-founder of Unchained rightly notes, the problem runs deeper — a single point of failure can exist anywhere, from an exchange to a hardware manufacturer.
Of particular concern is the possible use of AI by attackers. Some groups likely employed Chinese open-source LLMs without cybersecurity restrictions. This underscores the arms race: while American models are restricted, malicious actors gain access to powerful tools for finding vulnerabilities.
My analysis: this incident is not just a technical failure but a systemic challenge to the entire industry. It demonstrates that even the most reliable hardware can have hidden defects, and trust in a single device is becoming an anachronism. In the coming years, we will see an accelerated transition to multisignature solutions and stricter firmware audit standards. For BTC holders, this is a lesson: risk diversification is not an option but a necessity.