$91M Bitcoin Social Engineering Theft — Hardware Wallet Impersonation (August 2026)
Summary
On August 19, 2025, a single victim lost 783 BTC (approximately $91 million at the time) after attackers impersonated customer support representatives for both a hardware wallet manufacturer and a cryptocurrency exchange. The stolen funds were routed through Wasabi Wallet's CoinJoin mixing service to obstruct traceability. Blockchain investigator ZachXBT publicly disclosed the theft on August 21, 2025, noting it occurred exactly one year after the $243 million Genesis creditor social engineering theft of August 19, 2024. This incident and its successor threats constitute a documented category-level attack pattern targeting high-net-worth Bitcoin holders through trusted-service impersonation, particularly dangerous in the August 2026 environment following the Coldcard firmware exploit and associated phishing surge.
Connected Entities
1 entities · 10 linked investigationsTimeline(8 events)
2024-08-19
A single Genesis bankruptcy creditor loses approximately 4,064 BTC (~$243 million) in a social engineering attack. Perpetrators impersonate Google support and Gemini exchange support, then use AnyDesk screen-share to steal private keys.
The Block / CoinDesk2024-09-18
Malone Lam and Jeandiel Serrano are arrested in Miami and Los Angeles respectively in connection with the $243M Genesis creditor theft, charged with conspiring to steal and launder cryptocurrency.
CoinDesk2025-08-19
A single victim loses 783 BTC (~$91 million) after attackers impersonate customer support representatives for a hardware wallet manufacturer and a cryptocurrency exchange. The theft occurs exactly one year after the $243M Genesis creditor attack. Funds are moved immediately to a Bitcoin address beginning bc1qyxyk4qgyrkx4rjwsuevug04wahdk6uf95mqlej.
ZachXBT via Telegram / Decrypt / CoinDesk2025-08-21
ZachXBT publicly discloses the $91M theft via his Telegram investigations channel, noting the anniversary timing and the use of Wasabi Wallet for laundering. He advises: 'Assume that every call or email received is a scam by default.'
ZachXBT Telegram / CoinDesk / Decrypt2026-01-10
A victim loses $282 million in BTC and Litecoin in a hardware wallet social engineering scam. Attacker converts stolen assets to Monero via multiple instant exchanges, causing XMR price to surge ~70% over four days. ZachXBT confirms North Korean involvement is not suspected.
CoinDesk / ZachXBT on X2026-07-30
Coldcard firmware exploit discovered: a 2021 build configuration error reduces private key entropy to ~40 bits on older devices. Wave 1 drains approximately 1,083 BTC (~$70 million) from over 500 addresses in 41 minutes. At least 15 independent attackers eventually exploit the flaw.
Fortune / TRM Labs / TechCrunch2026-08-03
Proofpoint documents a coordinated phishing campaign impersonating Coldcard, inviting users to complete a 'coordinated hardware audit.' The cloned site deploys ScreenConnect remote access software; a human operator staffs fake support chat to assist victims in installing it.
Decrypt / Crypto Economy2026-08-04
Total Coldcard exploit losses reach approximately $116–130 million across 5,200+ addresses. Trezor and Foundation issue warnings about phishing surges targeting hardware wallet users.
TechCrunch / DecryptDecision Log
- #1publish⛓ pending8/8/2026, 12:16:39 PMhash: 2mNWHPSHVHeF6EaR8GHD7mH2snmLYtJPxvAJ9cnj5Kqt
18 of 23 cited source URLs have an Internet Archive snapshot.
model: claude-sonnet-4-6
generated: 8/8/2026, 12:16:30 PM
last updated: 8/8/2026, 4:07:35 PM
avoid.net — verified advice for a post-truth world