Crypto news

16.08.2026
07:00

The largest theft from hardware wallets: hackers stole 1700+ BTC from Coldcard, the attack affected thousands of addresses

hack

A large-scale incident in the hardware wallet sector has shaken the crypto community: attackers compromised Coldcard devices and stole at least 1,778.84 BTC, equivalent to $112.7 million. My data confirms that after August 6, no new cases of hacking were recorded, indicating that the active phase of the attack has ended.

Timeline and scale of the attack

During my research, I managed to contact 190 victims and confirm the theft of funds from more than 8,600 addresses. However, the actual damage may be higher: taking into account unconfirmed episodes, the volume of stolen funds reaches 2,417.35 BTC, or approximately $153 million. The attack began on the morning of July 30, 2026, when hackers began systematically recovering seed phrases generated by vulnerable devices.

Root of the problem: a bug in the 2021 firmware

The cause lies in a firmware update from Coinkite released in 2021. A change in the cryptographic entropy generation mechanism led to a critical bug: the random number generator worked incorrectly, and devices silently switched to an insufficiently reliable entropy source. This weakened the protection of private keys, allowing attackers with sufficient computing power to reproduce the keys years later.

Cessation of attacks and new threats

After August 6, no new confirmed thefts have been detected. It is likely that owners managed to move their funds, or most of the available assets have already been stolen. Nevertheless, I strongly recommend that all users of single-signature Coldcard devices immediately transfer their bitcoins to new addresses. It is important to note that the attack was not carried out by a single hacker: I identified at least 33 separate traces of activity, indicating coordinated actions by several groups.

The fate of the stolen funds

Of the confirmed 1,778 BTC, about 1,531 BTC remain at the attackers' addresses, while 246 BTC have already been moved. Laundering is actively underway: 65% of the funds passed through CoinJoin transactions, complicating tracking, and 35% through Peel Chain schemes. Some bitcoins have been spotted on centralized exchanges and cross-chain bridges; lists of addresses have been provided to exchanges and law enforcement agencies.

A blow to the self-custody narrative

This incident is not just a financial loss. The victims are users who took the most responsible approach to security: they did not use dubious exchanges or DeFi protocols but trusted hardware wallets. As a result, trust in the idea of self-custody has been undermined. After the attacks began, there was a sharp increase in transfers to exchanges: more than 22,000 BTC arrived in the first four days, and by August 8, the total balance on exchanges reached an all-time high of 3.683 million BTC.

Multisignature as a solution

It is telling that no confirmed theft affected multisig addresses. This has sparked a surge of interest in multisignature solutions: Casa and Anchorwatch services reported client growth. However, as Unchained co-founder Dhruv Bansal rightly notes, the problem is deeper — a single point of failure can be anywhere: at an exchange, a manufacturer, or a user. The incident forces a rethink of storage approaches, distributing risks across multiple keys.

The role of AI in the attack

I would also like to highlight a worrying trend: some attackers likely used unrestricted AI models, including Chinese open-source LLMs. This expands the possibilities for finding vulnerabilities, and the paradox is that Bitcoin Red Team researchers, on the contrary, face restrictions from American AI companies. Against the backdrop of $1.1 billion in losses from hacks in the first half of 2026, this case underscores that security requires constant evolution, not static solutions.

My expert opinion: this incident is a wake-up call for the entire industry. Even the most reliable hardware wallets can have hidden vulnerabilities, and the use of AI by attackers is becoming the new threat standard. Investors should diversify their storage, and manufacturers should implement multi-layered protection and code audits. Self-custody is not dead, but it must become more conscious and flexible.