Crypto news

16.08.2026
06:39

Largest theft from hardware wallets: hackers stole more than 1,700 BTC from Coldcard

hack

A large-scale attack on Coldcard hardware wallets has resulted in the loss of at least 1,778.84 BTC, equivalent to $112.7 million. Monitoring conducted by my analytical team shows that new confirmed cases of hacking ceased after August 6, but the full picture of the damage is not yet clear.

Attack Mechanics: The Root of the Problem in the 2021 Firmware

During the investigation, contact was established with 190 victims, and the theft of funds from more than 8,600 addresses was confirmed. If unconfirmed incidents are taken into account, the actual volume of stolen assets could reach 2,417.35 BTC or ~$153 million. The attack began on July 30, 2026, when attackers systematically recovered seed phrases generated by vulnerable devices.

The cause lies in an error made by the manufacturer Coinkite during a firmware update in 2021. A change to the cryptographic entropy generation mechanism led to incorrect operation of the random number generator. Devices silently switched to an insufficient entropy source, making private keys vulnerable to reproduction given sufficient computing power. The problem existed for years but only now became known to attackers.

Attackers' Tactics and Current Status of Funds

It is important to emphasize that this is not a single hacker. The analysis identified at least 33 separate traces of activity, indicating coordinated exploitation of the vulnerability by multiple groups. Of the confirmed 1,778 BTC, approximately 1,531 BTC still remain on the attackers' addresses. Notably, 65% of the stolen funds passed through CoinJoin transactions, significantly complicating tracking, while another 35% were moved using the Peel Chain scheme—a classic laundering method in which small transactions are repeatedly separated from a large amount.

Some of the bitcoins were observed on centralized exchanges and cross-chain bridges. Address lists have already been provided to compliance services, exchanges, and law enforcement agencies for blocking and investigation.

A Blow to the Self-Custody Narrative

This incident is not just a financial loss. The victims are precisely those users who approached security most responsibly: they did not use dubious exchanges, avoided risky DeFi protocols, and trusted hardware wallets as the gold standard of protection. Now the very principle of self-custody has faced a serious test. After the attacks began, a sharp influx of funds to exchanges was observed: more than 22,000 BTC arrived in the first four days, and by August 8, the aggregate balance on platforms reached an all-time high of 3.683 million BTC.

Multisignature as a Solution and the Role of AI

It is telling that no confirmed theft was carried out from addresses protected by multisignature. Casa and Anchorwatch services recorded a sharp increase in clients moving assets into multisig vaults. As Unchained co-founder Dhruv Bansal rightly notes, the problem is not custodial versus non-custodial solutions, but the presence of a single point of failure—whether it be an exchange, a manufacturer, or the user themselves.

Special attention deserves the possible use of AI by attackers. There is reason to believe that some groups used open Chinese LLMs without strict cybersecurity restrictions. This is an alarming signal: tools for finding and exploiting vulnerabilities are becoming available not only to defenders but also to attackers.

My conclusion: this attack is a critical lesson for the entire industry. Even the most reliable-looking hardware can contain hidden defects that manifest years later. The Coldcard incident should push users to reconsider storage strategies in favor of risk distribution, and manufacturers toward more thorough audits of cryptographic implementations. In the first half of 2026, crypto projects already lost about $1.1 billion due to hacks, and this case only confirms the record level of threats.