Crypto news

16.08.2026
06:20

The biggest blow to self-custody: the Coldcard hack resulted in the loss of over 1700 BTC

hack

A large-scale campaign targeting owners of Coldcard hardware wallets has resulted in the confirmed theft of at least 1,778.84 BTC, equivalent to $112.7 million. Monitoring shows that no new successful hacks have been recorded since August 6, but this does not diminish the severity of the incident for the entire ecosystem.

Attack on Coldcard

During the investigation, I managed to establish direct contact with 190 victims, and the draining of more than 8,600 addresses has been confirmed. The actual damage is likely higher: accounting for unconfirmed episodes, losses reach 2,417.35 BTC, or approximately $153 million. The attack began on the morning of July 30, 2026, when attackers started systematically recovering seed phrases generated by vulnerable devices.

The root of the problem lies in the Coinkite firmware update in 2021. A change in the cryptographic entropy generation mechanism led to a critical bug: the random number generator worked incorrectly, and devices imperceptibly switched to an entropy source insufficient to protect private keys. The defect went unnoticed for years, but with sufficient computing power, attackers were able to reproduce the keys.

Cessation of attacks and new threats

The last confirmed chain of hacks dates to August 6. Apparently, the attacks ceased either because victims moved funds to new addresses or because available assets have already been exhausted. Nevertheless, I strongly recommend that anyone still holding bitcoins on single-signature Coldcard wallets immediately migrate to new addresses. It is important to note: this is not the work of a single hacker — I have found at least 33 separate traces of activity, indicating that several groups exploited the vulnerability simultaneously.

Fate of the stolen funds

Of the confirmed 1,778 BTC, about 1,531 BTC remain on the attackers' addresses, while approximately 246 BTC have already been moved. A significant portion — 65% — passed through CoinJoin transactions, seriously complicating tracking. Another 35% is moving through Peel Chain schemes, a classic laundering method. Some funds have been spotted on centralized exchanges and cross-chain bridges; I have already provided lists of addresses to exchanges, compliance companies, and law enforcement.

Blow to the self-custody narrative

The incident strikes at the very idea of self-custody. The victims are not careless users, but those who approached security with maximum responsibility: no dubious exchanges, risky DeFi protocols, or hype tools. They trusted hardware wallets as the gold standard. The market reaction is telling: in the first four days of the attacks, more than 22,000 BTC flowed into exchanges, and by August 8, balances reached an all-time high of 3.683 million BTC.

Multisignature as a solution

Notably, no confirmed theft affected multisig addresses. Services Casa and Anchorwatch report a sharp increase in clients, and Dhruv Bansal of Unchained rightly notes: the problem is not custodial versus non-custodial solutions, but a single point of failure — whether it be an exchange, a manufacturer, or the user themselves. The incident forces a rethink: distributing risk across multiple keys and independent components becomes not a luxury, but a necessity.

AI as an escalation factor

Of particular concern is the likely use of AI by the attackers. I believe that some groups used open Chinese LLMs without cybersecurity restrictions. The irony is that Bitcoin Red Team researchers, who test the ecosystem for vulnerabilities, face the opposite: restrictions from American AI companies prevent them from using the most powerful models for defense. This highlights the dual nature of AI: the ability to exploit errors becomes available not only to defenders, but also to attackers.

My verdict: this incident is not just a technical failure, but a systemic challenge. In the context of record $1.1 billion in losses from hacks in the first half of 2026, it should serve as a catalyst for revising security standards in the industry. Self-custody is not dying, but it must evolve toward multisignature and risk diversification.