Crypto news

16.08.2026
05:40

Largest theft from hardware wallets: Coldcard vulnerability cost users $112 million

hack

A large-scale incident involving Coldcard hardware wallets has led to the loss of at least 1,778.84 BTC — equivalent to $112.7 million at the current exchange rate. My colleagues at Galaxy Research conducted a detailed analysis and confirmed that no new cases of hacking have been recorded since August 6.

Timeline of the attack and the root of the problem

The attack began on July 30, 2026. The attackers systematically recovered seed phrases generated by vulnerable devices and withdrew funds to addresses under their control. Researchers confirmed theft from more than 8,600 addresses, having contacted 190 victims. At the same time, the actual damage may be higher: taking into account unconfirmed episodes, the volume of stolen funds is estimated at 2,417.35 BTC (~$153 million).

The cause lies in an error made by Coinkite in 2021 during a firmware update. A change in the mechanism for generating cryptographic entropy led to incorrect operation of the random number generator. Devices silently switched to an alternative entropy source, which proved fatally insufficient for protecting private keys. The problem existed for years, but the attack could only be carried out now — the attackers required significant computing resources to reproduce the keys.

Cessation of attacks and multiple traces

The last confirmed chain of attacks dates to August 6. The halt in hacks is explained either by owners having managed to move their funds or by available assets having already been exhausted. Notably, there was not one but at least several attackers — Galaxy found 33 separate traces of activity, indicating parallel exploitation of the vulnerability.

The fate of the stolen funds

Of the confirmed 1,778 BTC, about 1,531 BTC remain at the attackers' addresses. Approximately 246 BTC have already been moved, with 65% passing through CoinJoin transactions that complicate tracking, and 35% moving via the Peel Chain scheme — a classic laundering method using micro-transactions. Some funds were spotted on centralized exchanges and cross-chain bridges; Galaxy provided lists of addresses to exchanges, compliance companies, and law enforcement.

A blow to the ideology of self-custody

The incident strikes at the very narrative of self-custody. The victims are users who took the most responsible approach to security: they did not use dubious exchanges or DeFi protocols but trusted hardware wallets as the gold standard of protection. After the attacks began, there was a surge of transfers to exchanges: more than 22,000 BTC flowed in over the first four days, and by August 8 the aggregate balance on platforms reached an all-time high of 3.683 million BTC.

Multisignature as a solution

It is telling that no confirmed theft was carried out from multisig addresses. Casa and Anchorwatch services recorded a sharp increase in clients and volumes of transferred funds. Unchained co-founder Dhruv Bansal rightly notes: the problem is not custodial services but a single point of failure — whether it be an exchange, a manufacturer, or the user themselves. The incident forces a rethink of storage approaches in favor of distributing risk across multiple keys.

The role of AI in the attack

Special attention deserves the likely use of AI. Galaxy suggests that some attackers used open Chinese LLMs without cybersecurity restrictions. The irony is that Bitcoin Red Team researchers, who test the ecosystem for vulnerabilities, faced the opposite problem — restrictions from American AI companies hindered their use of powerful models for defense. This underscores the duality of AI: it becomes a tool for both defense and attacks.

My comment: This incident is a wake-up call for the entire industry. Even the most trusted hardware wallets are not immune to code errors, and given that in the first half of 2026 crypto projects lost $1.1 billion due to hacks, it is obvious: security requires not blind faith in a single device but a multi-layered strategy. I recommend that all Coldcard owners immediately migrate to new addresses and seriously consider multisignature as the standard for significant amounts.