Hackers steal over 1,700 BTC from vulnerable Coldcard wallets

In Crypto Regulations
August 15, 2026

Hackers steal over 1,700 BTC from vulnerable Coldcard wallets

Hackers stole at least 1,778.84 BTC ($112.7 million) by exploiting vulnerabilities in Coldcard hardware wallets. No new incidents have been recorded since August 6, Galaxy Research said.

Coldcard attack

The firm’s researchers contacted 190 victims and confirmed the theft of bitcoin from more than 8,600 addresses. The final loss may be significantly higher: including yet-unconfirmed episodes, the tally is estimated at 2,417.35 BTC, or about $153 million.

image
Source: Galaxy Research.

The attack began at least on the morning of July 30, 2026. The attackers systematically recovered seed phrases generated by vulnerable Coldcard devices, then moved funds to addresses they controlled.

A software bug was the cause. In 2021, Coldcard manufacturer Coinkite updated device firmware, changing the cryptographic entropy generation mechanism. Because of a bug, the new random number generator malfunctioned, and devices silently fell back to another entropy source that proved critically insufficient to protect private keys.

In effect, the flaw existed for several years but only surfaced now: with enough computing resources, attackers were able to reproduce private keys generated on vulnerable devices.

New attacks have stopped

Galaxy noted that the latest confirmed attack chain is dated August 6. Since then, new victims continue to contact the researchers, but no confirmed cases of further compromise have been found.

Researchers suggest two reasons for the pause: owners of vulnerable wallets moved funds to new addresses, or most of the accessible funds have already been stolen. For users still holding bitcoin on single-signature Coldcard wallets, experts recommend moving assets to new addresses immediately.

It also appears there was more than one attacker. Galaxy found at least 33 additional traces of activity and believes with high confidence that multiple actors exploited the vulnerability at the same time.

Most of the bitcoin remains with the hackers

Of the roughly 1,778 BTC confirmed stolen, about 1,531 BTC remain at addresses controlled by the attackers. Another ~246 BTC have already moved since the theft.

About 65% of those funds went through CoinJoin transactions, which complicate tracing. The remaining 35% continued moving on-chain, including via the peel chain pattern, widely used for money laundering. In this scheme, small microtransactions are repeatedly peeled off from a large sum, while the remaining bulk is sent to a new address.

A small share of the stolen bitcoin was spotted on centralized exchanges and cross-chain bridges. Galaxy shared address lists with exchanges, compliance and investigations firms, and law enforcement.

Blow to the self-custody narrative

The incident stands out not only for the scale of losses. The victims were mostly users who took bitcoin self-custody especially seriously.

Galaxy noted that victims did not send coins to dubious exchanges, use risky DeFi protocols, or chase high-yield instruments. They kept bitcoin in hardware wallets, long considered one of the safest ways to store cryptocurrency.

As a result, the incident dealt a blow to the self-custody narrative itself. According to Galaxy, after the attacks began, the number of small bitcoin transfers to exchanges increased, and more than 22,000 BTC flowed to centralized platforms in the first four days. By August 8, the combined balance on exchanges reached 3.683 million BTC — an all-time high.

Multisig over a single point of failure

One unexpected outcome was rising interest in multisig wallets. Galaxy emphasized that none of the confirmed thefts came from addresses protected by multisignature.

Representatives of Casa and Anchorwatch reported a sharp increase in new clients and in the amount of bitcoin moved into multisignature vaults. Unchained co-founder Dhruv Bansal said it is wrong to view what happened as a win for custodial services over non-custodial solutions. In his view, the real problem is the single point of failure — which could be an exchange, a hardware wallet maker, or the user.

The incident therefore encourages a rethink of self-custody itself. Rather than relying on a single device, users can distribute risk across multiple keys and independent infrastructure components.

AI may have helped the attackers

Another worrying aspect involves the use of artificial intelligence. Galaxy believes at least some attackers very likely used AI models without strict cybersecurity guardrails — in particular, Chinese open LLMs.

Meanwhile, Bitcoin Red Team researchers, who began broadly auditing the ecosystem’s codebase for vulnerabilities after the attack, faced the opposite problem: restrictions at leading U.S. AI companies hindered their use of the most powerful models for defense.

Galaxy noted that this is especially important as AI proliferates: the ability to find and exploit bugs in code is becoming more accessible not only to developers and researchers but also to attackers.

In the first half of 2026, crypto projects lost about $1.1 billion to hacks, and the number of confirmed exploits hit a record for a six-month period, according to Blockaid.

Avatar photo
/ Published posts: 919

Steven M. Crimmins is a cryptocurrency strategist and freelance writer who has followed the blockchain industry since Bitcoin’s early days. Known for his sharp analysis of altcoins and trading strategies, Steven provides Satoshi News Africa readers with market-focused content grounded in research. He is especially interested in how African traders are adopting crypto as an alternative to traditional markets. Steven is also a podcast host, where he discusses emerging technologies and investment trends.