Largest theft from hardware wallets: hackers withdrew 1778 BTC from Coldcard

A large-scale incident involving Coldcard hardware wallets has shaken the crypto community: attackers managed to steal at least 1,778.84 BTC, equivalent to $112.7 million. My colleagues at Galaxy Research conducted a detailed analysis and confirmed that the attacks ceased after August 6, but the consequences of this hack will reverberate throughout the industry for a long time.
Timeline of the Coldcard attack
Researchers established contact with 190 victims and verified the theft of funds from more than 8,600 addresses. The real scale could be far more serious: accounting for unconfirmed episodes, the damage reaches 2,417.35 BTC (~$153 million). The attack began on the morning of July 30, 2026, when hackers started systematically recovering seed phrases generated by vulnerable devices.
The root of the problem lies in a 2021 firmware error from Coinkite. The manufacturer changed the cryptographic entropy generation mechanism, but the new random number generator worked incorrectly. Devices silently switched to a backup entropy source, which proved catastrophically weak for protecting private keys. The defect existed for years, but only now did hackers gain enough computing power to reproduce the keys.
Multiple attackers and the fate of stolen funds
An important finding: this was not the work of a lone actor. Galaxy discovered at least 33 separate traces of activity, indicating simultaneous exploitation of the vulnerability by several groups. Of the confirmed 1,778 BTC, about 1,531 BTC remain under the attackers' control, while approximately 246 BTC have already been moved.
Money laundering followed classic schemes: 65% of the funds passed through CoinJoin transactions, complicating tracking, while 35% moved across the blockchain via Peel Chain—a method where small micro-transactions are repeatedly separated from a large sum. Some bitcoins appeared on centralized exchanges and cross-chain bridges, and Galaxy has already provided lists of addresses to compliance departments and law enforcement agencies.
A blow to the self-custody narrative
The particular cynicism of the situation is that the victims were exemplary users: they did not engage with dubious exchanges, did not use risky DeFi protocols, and stored funds in "hardware" considered the gold standard of security. This incident dealt a serious blow to the self-custody philosophy. Unsurprisingly, in the first four days after the attacks began, more than 22,000 BTC flowed to exchanges, and by August 8, the aggregate balance on platforms reached an all-time high of 3.683 million BTC.
Notably, no confirmed theft affected multisignature addresses. Casa and Anchorwatch services report a sharp increase in clients transitioning to multisig storage. Unchained co-founder Dhruv Bansal rightly notes: the victory of custodial services here is beside the point—the problem lies in a single point of failure, whether it be an exchange, a manufacturer, or the user themselves.
AI as an attacker's tool
A troubling signal is the possible use of AI by hackers. Galaxy considers it highly likely that some attackers used Chinese open-source LLM models without cybersecurity restrictions. Meanwhile, Bitcoin Red Team researchers, who devoted efforts to auditing the codebase, faced obstacles instead: restrictions from American AI companies hinder the use of the most powerful models for defense.
My comment: This case is a wake-up call for the entire industry. For too long, we relied on the "impenetrability" of hardware wallets, forgetting that any software can contain hidden defects. The Coldcard incident should serve as a catalyst for revising security standards: key diversification, multisignature, and regular firmware audits are not paranoia but necessary hygiene. Given that in the first half of 2026 crypto projects already lost about $1.1 billion due to hacks, and the number of exploits reached a record high, the industry needs to act proactively rather than react after the fact.