A roughly $116 million hardware wallet exploit has turned self-custody back into the central question for Bitcoin holders, after security researchers linked the largest hardware wallet breach of 2026 to vulnerable Coldcard devices. According to a TRM Labs analysis, the attack drained roughly $116 million, while Galaxy Research later confirmed losses of $112.7 million across more than 8,600 addresses, totaling 1,778 BTC.
The root cause was a firmware bug introduced by Coinkite in version 4.0.1, shipped in March 2021. The update accidentally rerouted seed phrase generation from a hardware random number generator to a software-based pseudorandom number generator, making keys more predictable and easier to replicate. Coinkite issued a security advisory on July 30, 2026, and released patched firmware the next day, but researchers warn the patch does not fix seeds already created on vulnerable firmware.
Galaxy Research assessed that attackers likely used unrestricted AI models to discover and exploit the vulnerability, pointing to open-source models such as Kimi K3. Rob Hamilton, CEO of Anchorwatch, said U.S. AI lab safety policies prevented defenders from using similar frontier tools, forcing security researchers to rely on the same open-source models as attackers.
The attacks began on July 30, 2026, and swept over 1,000 BTC from more than 1,000 addresses within 41 minutes. No thefts were recorded from multisignature wallets. Of the stolen funds, 1,531 BTC remains unmoved in attacker-controlled addresses, while about 246 BTC has been moved, with 65% routed through Coinjoin mixing transactions.
Despite the custody scare, U.S. spot Bitcoin ETFs recorded around $854 million in inflows over five days, suggesting institutional demand for regulated Bitcoin exposure remains firm.