Crypto news

16.08.2026
03:20

Largest theft from hardware wallets: Coldcard attack cost users $112 million

hack

A large-scale hacking campaign targeting Coldcard hardware wallets has resulted in losses of at least 1,778.84 BTC, equivalent to $112.7 million. My data analysis shows this is one of the most severe attacks on self-custody devices in the industry's history.

Attack Mechanics: An Error in Entropy Generation

The attackers systematically recovered seed phrases generated by vulnerable devices starting July 30, 2026. The root of the problem lies in a 2021 Coinkite firmware update that changed the cryptographic entropy generation mechanism. Due to a bug, the random number generator malfunctioned, imperceptibly switching to an entropy source with critically insufficient protection for private keys.

What is particularly telling is that the issue existed for years but only manifested now—as attackers' computing power grew, they were able to reproduce private keys. This is a warning signal for the entire industry: vulnerabilities in hardware can lie dormant for years.

Scale and Consequences

Researchers confirmed theft from more than 8,600 addresses, having contacted 190 victims. The actual damage could reach 2,417.35 BTC (~$153 million) including unconfirmed incidents. The attacks ceased after August 6, but approximately 1,531 BTC of the stolen funds remain under the attackers' control. Notably, 65% of the stolen coins passed through CoinJoin transactions, while 35% went through Peel Chain schemes, significantly complicating tracking.

A Blow to the Self-Custody Narrative

The incident deals a devastating blow to the idea of self-custody. The victims are not inexperienced users, but those who approached storage most responsibly: avoiding dubious exchanges, risky DeFi protocols, and hype-driven tools. They trusted hardware wallets as the gold standard of security. The result is a mass exodus: in the first four days of the attacks, more than 22,000 BTC flowed into exchanges, and the aggregate balance on centralized platforms reached an all-time high of 3.683 million BTC by August 8.

Multisignature as a Solution and the Role of AI

It is telling that no confirmed theft was carried out from addresses protected by multisignature. Services like Casa and Anchorwatch are already seeing a sharp increase in clients. However, as Unchained co-founder Dhruv Bansal rightly notes, the problem runs deeper—it is a single point of failure, whether it be an exchange, a manufacturer, or the user themselves. A separate alarming aspect is the possible use by attackers of Chinese open-source LLMs without cybersecurity restrictions, expanding the threat horizon in the AI era.

My conclusion: this incident is not merely a technical failure, but a systemic challenge to the industry. Relying on a single device is no longer acceptable, and the shift to multisignature schemes is not a trend but a necessity. In the first half of 2026, crypto projects already lost about $1.1 billion due to hacks, and this case only confirms that security requires risk diversification at all levels.