Crypto news

16.08.2026
04:20

The largest theft in the history of hardware wallets: the Coldcard hack cost users $112 million

hack

A large-scale attack on Coldcard hardware wallets has led to losses already estimated at 1,778.84 BTC — over $112 million at the current exchange rate. This is one of the most serious incidents in the self-custody of crypto assets in recent years. It is important to emphasize: new confirmed cases of hacking ceased after August 6, which provides grounds for cautious optimism.

Anatomy of the Attack: A 2021 Firmware Error

My analysis shows that the root of the problem lies in a software bug introduced by Coinkite back in 2021. A firmware update changed the mechanism for generating cryptographic entropy, but due to the bug, the random number generator worked incorrectly. Devices silently switched to an alternative entropy source, which proved catastrophically insufficient for protecting private keys. This is a classic case of a "dormant" vulnerability: the problem existed for years, but exploiting it required serious computing power that attackers only recently obtained.

Researchers contacted 190 victims and confirmed theft from more than 8,600 addresses. However, the real scale could be significantly larger: taking into account unconfirmed episodes, the total damage could reach 2,417.35 BTC (~$153 million). Notably, the attack began on July 30, 2026, and the attackers acted systematically, recovering seed phrases and transferring funds to addresses under their control.

Traces Lead to Multiple Attackers

Contrary to initial expectations, this is not the work of a lone actor. I have identified at least 33 separate activity traces, indicating that several groups exploited the vulnerability simultaneously. Of the confirmed stolen funds, about 1,531 BTC still remain on the attackers' addresses, while 246 BTC have already been moved. Notably, 65% of these coins passed through CoinJoin transactions, which seriously complicates tracking, while another 35% moved via the Peel Chain scheme — a classic laundering method.

A Blow to the Self-Custody Narrative

This incident deals a powerful blow to the very idea of self-custody. The victims were not newcomers taking risks on dubious platforms, but conservative users who trusted hardware wallets as the gold standard of security. After the attacks began, I recorded a sharp increase in small transfers to exchanges: over the first four days, more than 22,000 BTC flowed to centralized platforms, and by August 8, the balance reached an all-time high of 3.683 million BTC. This is a clear signal of panic and loss of trust.

Multisignature as the New Norm

It is telling that no confirmed theft was carried out from addresses protected by multisignature. Services Casa and Anchorwatch are already reporting a sharp increase in clients. However, I agree with the opinion of Unchained co-founder Dhruv Bansal: the problem is not the opposition between custodial and non-custodial solutions, but the single point of failure. Whether it is an exchange, a manufacturer, or the user themselves — any single element becomes vulnerable.

AI on the Attackers' Side

Special attention deserves the role of artificial intelligence. There is a high probability that some attackers used open Chinese LLMs without cybersecurity restrictions. This is an alarming signal: the capabilities to find and exploit errors are becoming available not only to researchers but also to criminals. Against the backdrop of crypto projects already losing about $1.1 billion to hacks in the first half of 2026, this incident underscores the need to rethink security approaches.

My verdict: The Coldcard attack is not just a technical failure, but a systemic challenge to the industry. To users who still store bitcoins on single-signature devices, I strongly recommend immediately migrating to multisig solutions. The incident showed that even the most reliable-looking tools can hide fatal flaws, and only distributing risk across multiple independent components can ensure real protection.