AI-Powered Attack Drains $112M in Bitcoin from Coldcard Hardware Wallets
A major security breach hit Coldcard hardware wallets after attackers exploited a firmware flaw dating back to March 2021, stealing over 1,778 BTC from more than 8,600 addresses. Verified losses are estimated at $112.7 million, making it the largest hardware wallet compromise on record. The attack began on July 30, 2026 and drained over 1,000 BTC in a 41-minute window, with no further malicious transactions detected after August 6. Analysts at Galaxy Research believe unrestricted AI tools may have helped attackers identify and weaponize the vulnerability. Coinkite released patched firmware by July 31, but wallets seeded on vulnerable firmware remain permanently compromised, requiring users to create new seed phrases and move funds immediately. The incident may pressure confidence in self-custody security and could increase demand for multisig solutions, which were unaffected.