The largest cold storage theft in history: hackers stole 1700+ BTC from Coldcard wallets

A large-scale attack on Coldcard hardware wallets resulted in the loss of at least 1,778.84 BTC — approximately $112.7 million at the current exchange rate. My colleagues at Galaxy Research have noted that new hacking incidents ceased after August 6, but that is little consolation for the victims.
Technical Background: An Error in Entropy Generation
During the investigation, I determined that the attack began as early as July 30, 2026. The attackers systematically recovered seed phrases generated by vulnerable devices. The root of the problem lies in a 2021 Coinkite firmware update. A change to the cryptographic entropy generation mechanism led to a critical bug: the random number generator malfunctioned, and devices silently switched to an entropy source insufficient to protect private keys.
This defect existed for years but only became apparent now, when attackers gained enough computing power to reproduce the keys. Researchers confirmed theft from more than 8,600 addresses, having contacted 190 victims. The actual damage may be higher — considering unconfirmed incidents, it is estimated at 2,417.35 BTC (~$153 million).
Attackers' Tactics and Current Situation
The attacks likely stopped because owners managed to withdraw funds or available assets have been exhausted. However, this is not about a single hacker — I have identified at least 33 traces of activity indicating simultaneous exploitation of the vulnerability by multiple groups. Of the confirmed 1,778 BTC, about 1,531 BTC still remain on the attackers' addresses. Meanwhile, 65% of the funds passed through CoinJoin to obscure traces, and 35% were moved using the Peel Chain scheme — a classic laundering technique. Some coins have been spotted on centralized exchanges and cross-chain bridges, and address lists have been provided to compliance departments and law enforcement agencies.
A Blow to the Self-Custody Ideology
What is especially alarming is that the victims were precisely those users who took the most responsible approach to self-custody. They did not use risky DeFi protocols or dubious exchanges, trusting hardware wallets as the gold standard of security. The incident dealt a serious blow to the self-custody narrative: in the first four days of the attack, more than 22,000 BTC flowed into exchanges, and by August 8, the aggregate balance reached an all-time high of 3.683 million BTC.
Multisignature and the Role of AI
Notably, no confirmed theft affected multisig addresses. Services like Casa and Anchorwatch report a sharp increase in clients, but, as Unchained co-founder Dhruv Bansal rightly points out, the problem is deeper — it is a single point of failure, whether it be an exchange, a manufacturer, or the user themselves. A separate alarming aspect is the likely use of unrestricted AI models, including Chinese open-source LLMs, to find vulnerabilities. This is a signal that the cybersecurity arms race is reaching a new level.
My Comment: This incident is not just a technical failure but a systemic challenge to the industry. It proves that even the most seemingly reliable solutions can contain hidden defects, and trust in a single device becomes a luxury. The shift to multisignature and risk diversification is no longer a recommendation but a necessity for anyone holding significant amounts of bitcoin.