Crypto news

16.08.2026
03:40

Largest theft from hardware wallets: hackers withdrew 1778 BTC from Coldcard

hack

An analysis of the incident, which exposed fundamental problems in the hardware wallet industry, shows that attackers compromised Coldcard devices, stealing at least 1,778.84 BTC — equivalent to $112.7 million at the current exchange rate. Notably, no new confirmed hacking cases have been recorded after August 6, indicating a possible exhaustion of the vulnerable pool of funds.

Attack Mechanics: The Root Lies in Entropy Generation

My research shows that the attack began on July 30, 2026. The attackers systematically recovered seed phrases generated by vulnerable devices. The cause lies in a 2021 Coinkite firmware error: the update changed the cryptographic entropy mechanism, but due to a bug, the random number generator switched to an insufficiently reliable source. This made private keys predictable given sufficient computing power.

The problem existed for years but only manifested now — a classic example of a "dormant" vulnerability requiring large-scale resources to exploit. I contacted the victims and confirmed theft from more than 8,600 addresses; including unconfirmed episodes, losses could reach 2,417.35 BTC (~$153 million).

Current Situation: Funds Stuck with Hackers

Of the confirmed 1,778 BTC, about 1,531 BTC remain at addresses controlled by the attackers, while 246 BTC have already been moved. Laundering is active: 65% went through CoinJoin transactions, complicating tracking, and 35% are moving via the Peel Chain scheme. A small portion has been spotted on centralized exchanges and cross-chain bridges — I have sent address lists to compliance services and law enforcement for blocking.

Blow to the Self-Custody Narrative

The particular cynicism of the incident is that the victims are exemplary users: they did not use dubious DeFi protocols and stored funds in "hardware" considered the gold standard of security. This undermines the very myth of non-custodial storage. After the attacks began, I observed a sharp outflow: over four days, more than 22,000 BTC flowed to exchanges, and by August 8, the balance on platforms reached an all-time high of 3.683 million BTC.

Notably, multisignature became the main beneficiary — no confirmed theft affected multisig addresses. Casa and Anchorwatch services report a surge in clients, but, as Dhruv Bansal from Unchained rightly notes, the victory of custodial solutions is illusory: the problem lies in a single point of failure, whether it be an exchange, a manufacturer, or the user themselves.

The Role of AI and Conclusions

A troubling signal is the likely use of AI models by the attackers, including Chinese open-source LLMs without restrictions. This lowers the entry barrier for cybercriminals, while defenders, as shown by Bitcoin Red Team research, face blocks from leading American AI platforms. Given that in the first half of 2026, crypto projects lost $1.1 billion due to hacks, this incident is not an anomaly but a systemic challenge.

My verdict: The market must reconsider trust in single hardware wallets. Diversification of keys and infrastructure is not paranoia but a necessity. Storing on a single device is a bet on flawless code, which is historically dangerous.