As a result of an attack on vulnerable Coldcard hardware wallets, malicious actors stole at least 1778.84 $BTC ($112.7 million). No new hacking incidents have been recorded after August 6, Galaxy Research reported.
New incidents of hackers exploiting vulnerabilities in the Coldcard hardware wallet have abated, though the tally of losses continues to climb as new victims come forward.https://t.co/Q1X191mcGi
— Galaxy Research (@glxyresearch) August 14, 2026
Attack on Coldcard
Researchers from the company contacted 190 victims and confirmed the theft of bitcoin from more than 8600 addresses. However, the final damage could be significantly higher: when considering unconfirmed episodes, the volume of stolen funds is estimated at 2417.35 $BTC or ~$153 million.

The attack began at least on the morning of July 30, 2026. Malicious actors systematically recovered seed phrases generated by vulnerable Coldcard devices and then transferred the funds to addresses under their control.
The cause was a software error. In 2021, Coldcard manufacturer Coinkite updated the device firmware, changing the mechanism for generating cryptographic entropy. Due to a bug, the new random number generator did not work correctly, and the devices silently switched to another entropy source, which proved critically insufficient for protecting private keys.
Essentially, the problem existed for several years but manifested only now: with sufficient computational resources, malicious actors were able to reproduce private keys created on vulnerable devices.
New Attacks Have Ceased
Galaxy notes that among the confirmed attack chains, the last one is dated August 6. After this date, new victims continue to come forward to the researchers, but no confirmed cases of further hacking have been found yet.
Researchers suggest the attacks ceased for two reasons: owners of vulnerable wallets managed to transfer funds to new addresses, or the majority of available funds had already been stolen. Experts recommend that users still storing bitcoin on single-signature Coldcards immediately move their assets to new addresses.
However, it appears this is not the work of a single malicious actor. Galaxy detected at least 33 additional traces of activity and considers it highly likely established that the vulnerability was used simultaneously by several attackers.
Most Bitcoin Remains with Hackers
Of the approximately 1778 $BTC confirmed as stolen, about 1531 $BTC are still held at addresses controlled by the malicious actors. Another approximately 246 $BTC have already been moved post-theft.
About 65% of these funds passed through CoinJoin transactions, which complicate tracing the origin of the coins. Another 35% continued moving across the blockchain, including via the Peel Chain scheme, widely used for cryptocurrency laundering. Its principle of operation involves repeatedly "peeling off" small microtransactions from a large sum, with the remaining main portion being transferred to a new address.
A small portion of the stolen bitcoin has been spotted on centralized exchanges and cross-chain bridges. Galaxy has shared address lists with exchanges, compliance and investigation companies, as well as law enforcement agencies.
A Blow to the Self-Custody Narrative
The incident's peculiarity lies not only in the scale of losses. The victims were predominantly users who took the idea of bitcoin self-custody most seriously.
Galaxy notes that the affected individuals did not send coins to dubious exchanges, did not use risky DeFi protocols, and did not attempt to profit from high-yield instruments. They stored bitcoin in hardware wallets, considered one of the most secure ways to hold cryptocurrency.
Consequently, the incident struck a blow to the very narrative of self-custody. According to Galaxy, after the attacks began, the number of small bitcoin transfers to exchanges increased, and over the first four days, more than 22,000 $BTC flowed into centralized platforms. By August 8, the cumulative balance on exchanges reached 3.683 million $BTC — a historical high.
Multisignature Instead of a Single Point of Failure
One unexpected consequence of the attack was growing interest in multisig wallets. Galaxy emphasizes that no confirmed theft occurred from addresses protected by multisignature.
Representatives of Casa and Anchorwatch services reported a sharp increase in new clients and volumes of bitcoin being transferred into multisignature storage. Unchained co-founder Dhruv Bansal believes it is incorrect to view what happened as a victory for custodial services over non-custodial solutions. In his opinion, the real problem is the existence of a single point of failure: it could be an exchange, a hardware wallet manufacturer, or the user themselves.
Thus, the incident rather forces a reconsideration of the very approach to self-custody. Instead of trusting a single device, users can distribute risk among several keys and independent infrastructure components.
AI May Have Assisted Attackers
A separate alarming aspect is related to the use of artificial intelligence. Galaxy believes that at least some of the attackers very likely used AI models without strict cybersecurity restrictions — particularly Chinese open-source LLMs.
Meanwhile, Bitcoin Red Team researchers, who began mass scanning the ecosystem's codebase for vulnerabilities after the attack, encountered the opposite problem: restrictions imposed by leading US AI companies hindered them from using the most powerful models for defense.
Galaxy noted that this is especially important against the backdrop of AI proliferation: the capabilities for finding and exploiting code errors are becoming more accessible not only to developers and researchers but also to malicious actors.
Recall that in the first half of 2026, crypto projects lost about $1.1 billion due to hacks, and the number of confirmed exploits set a record for a six-month period, as calculated by Blockaid.
end-content






