In a recent attack targeting Coldcard hardware wallets, hackers managed to steal at least 1,778.84 BTC, valued at approximately $112.7 million. According to Galaxy Research, there have been no new hacking incidents reported since August 6.

https://twitter.com/glxyresearch/status/2088388192806269224

Coldcard Attack Details

Researchers reached out to 190 affected individuals and confirmed that bitcoins were stolen from over 8,600 addresses. The total damage could be significantly higher, with unconfirmed incidents suggesting that the total amount taken may reach 2,417.35 BTC, roughly $153 million.

Source: Galaxy Research.

The attack reportedly began at least on the morning of July 30, 2026. The attackers systematically recovered seed phrases generated by the vulnerable Coldcard devices and subsequently transferred the funds to their own addresses.

The root cause was traced to a software error. In 2021, Coldcard's manufacturer, Coinkite, had updated the device firmware, which altered the cryptographic entropy generation mechanism. Due to a bug, the new random number generator malfunctioned, causing devices to silently switch to a different entropy source that was critically insufficient for securing private keys.

This vulnerability had existed for several years but only became apparent recently: with sufficient computational resources, the attackers were able to reproduce the private keys created on the compromised devices.

End of New Attacks

Galaxy notes that the last confirmed attack in the series occurred on August 6. Since that date, new victims have continued to report to the researchers, but no confirmed hacking incidents have emerged.

Researchers speculate that the attacks may have ceased for two reasons: either the owners of the vulnerable wallets have successfully transferred their funds to new addresses, or most of the accessible funds have already been stolen. Experts advise users still holding bitcoins on single-signature Coldcard wallets to move their assets to new addresses immediately.

It appears that this is not the work of a single hacker. Galaxy discovered at least 33 additional traces of activity and strongly suspects that multiple attackers exploited the vulnerability simultaneously.

Majority of Stolen Bitcoins Remain with Hackers

Of the approximately 1,778 BTC confirmed as stolen, around 1,531 BTC are still held on addresses controlled by the hackers. Approximately 246 BTC have already been moved after the theft.

About 65% of these funds were transferred through CoinJoin transactions, which complicate the tracing of the coins' origins. Another 35% continued to be moved across the blockchain, including via the Peel Chain method, commonly used for laundering cryptocurrencies. This method involves repeatedly separating small microtransactions from a larger sum, with the remaining amount being sent to a new address.

A small portion of the stolen bitcoins has been spotted on centralized exchanges and cross-chain bridges. Galaxy has provided lists of addresses to exchanges, compliance and investigation firms, and law enforcement agencies.

Impact on Self-Custody Narrative

This incident's significance lies not only in the scale of the losses but also in the fact that the victims primarily consisted of users who took self-custody of their bitcoins seriously.

Galaxy highlights that the affected users did not send their coins to dubious exchanges, nor did they engage with risky DeFi protocols or attempt to profit from high-yield instruments. They stored their bitcoins in hardware wallets, which are considered one of the safest ways to hold cryptocurrencies.

As a result, the incident has dealt a blow to the narrative surrounding self-custody. According to Galaxy, following the onset of the attacks, there was an increase in small bitcoin transfers to exchanges, with over 22,000 BTC moving to centralized platforms within the first four days. By August 8, the total balance on exchanges reached an all-time high of 3.683 million BTC.

Multi-Signature as a Solution

One unexpected outcome of the attack has been a surge in interest in multi-signature wallets. Galaxy emphasizes that no confirmed thefts occurred from addresses secured by multi-signature technology.

Representatives from services like Casa and Anchorwatch reported a significant rise in new customers and the volume of bitcoins being transferred to multi-signature storage. Dhruv Bansal, co-founder of Unchained, believes it is incorrect to view this as a victory for custodial services over non-custodial solutions. He argues that the real issue is the existence of a single point of failure, which could be an exchange, a hardware wallet manufacturer, or the user themselves.

Thus, the incident compels a reevaluation of the approach to self-custody. Rather than relying on one device, users can distribute risk among several keys and independent infrastructure components.

AI's Role in the Attack

A particularly concerning aspect of the incident is the potential use of artificial intelligence by the attackers. Galaxy suggests that at least some of the hackers likely employed AI models without strict cybersecurity safeguards, specifically Chinese open-source large language models.

Conversely, Bitcoin Red Team researchers, who began a massive review of the ecosystem's codebase for vulnerabilities post-attack, encountered the opposite problem: the restrictions imposed by leading American AI companies hindered their ability to utilize the most powerful models for defense.

Galaxy noted that this is especially critical in light of the growing prevalence of AI: the ability to discover and exploit code errors is becoming more accessible not only to developers and researchers but also to malicious actors.

It is worth noting that in the first half of 2026, crypto projects lost approximately $1.1 billion due to hacks, and the number of confirmed exploits reached a record high for a six-month period, according to Blockaid.