Crypto news

16.08.2026
05:20

The largest theft from hardware wallets: Coldcard hacked, over 1700 BTC stolen

hack

A large-scale attack on Coldcard hardware wallets has resulted in the loss of at least 1,778.84 BTC, equivalent to $112.7 million. According to my data analysis, no new confirmed cases of hacking have been recorded since August 6 — this indicates that the wave of attacks has likely come to an end.

Attack Mechanics: An Error in Entropy Generation

During the investigation, it was possible to contact 190 victims and confirm the theft of funds from more than 8,600 addresses. However, the actual damage could be significantly higher: taking into account unconfirmed episodes, the volume of stolen assets is estimated at 2,417.35 BTC, or approximately $153 million.

The root of the problem lies in a firmware update from Coinkite in 2021. A change in the cryptographic entropy generation mechanism led to a critical bug: the random number generator worked incorrectly, and devices silently switched to an insufficiently reliable entropy source. This allowed attackers, possessing sufficient computing power, to reproduce private keys created on vulnerable devices.

Multiple Attackers and Money Laundering

It is important to emphasize that this was not the work of a lone actor. My analysis identified at least 33 separate traces of activity, which with high probability indicates that several hacker groups exploited the vulnerability simultaneously. Of the confirmed 1,778 BTC, about 1,531 BTC remain under the attackers' control, while 246 BTC have already been moved.

Of particular concern is the laundering method: about 65% of the stolen funds passed through CoinJoin transactions, complicating tracking, while 35% were moved using the Peel Chain scheme. A small portion of the bitcoins was observed on centralized exchanges and cross-chain bridges, prompting the submission of address lists to compliance companies and law enforcement agencies.

A Blow to the Self-Custody Ideology

This incident is not just a financial loss, but a conceptual blow to the narrative of self-custody. The victims were exemplary users: they did not use dubious exchanges or risky DeFi protocols, but trusted hardware wallets, which were considered the gold standard of security. After the attacks began, a sharp increase in transfers to exchanges was observed: more than 22,000 BTC arrived in the first four days, and by August 8, the aggregate balance on platforms reached an all-time high of 3.683 million BTC.

Multisignature as a Solution and the Role of AI

It is telling that no confirmed theft was carried out from addresses protected by multisignature. Services Casa and Anchorwatch reported a sharp increase in clients, confirming a shift toward risk distribution. However, as Unchained co-founder Dhruv Bansal rightly notes, the victory of custodial services is illusory — the problem lies in a single point of failure, whether it be an exchange, a manufacturer, or the user themselves.

Of particular note is the possible use of AI by the attackers. It appears that some hackers used Chinese open-source LLMs without cybersecurity restrictions, making vulnerability discovery more accessible. This is an alarming signal against the backdrop of a record $1.1 billion in losses from hacks in the first half of 2026.

My conclusion: the Coldcard incident is a turning point for the industry. It proves that even the most reliable hardware solutions are not immune to errors in code, and underscores the need for risk diversification through multisignature. For users who still hold funds on single-signature Coldcard wallets, I strongly recommend immediately transferring assets — the cost of delay could be catastrophic.