TLDR
- The first Coldcard attack wave stole 1,082.65 BTC.
- Block traced the attacker to a paid blockchain data provider account.
- The provider’s logs reportedly matched the theft pattern with “extraordinary specificity.”
- More than 1,800 BTC was stolen across multiple Coldcard attack waves.
- The first-wave funds remain unmoved across three monitored addresses.
U.S. law enforcement may have identified the attacker behind the first and largest wave of the July 2026 Coldcard hardware wallet theft, after investigators traced an operational mistake linked to the movement of stolen Bitcoin. The first wave drained 1,082.65 BTC, while total losses across all known waves have exceeded 1,800 BTC from more than 5,000 addresses.
Block’s investigation found that the first-wave attacker used a paid account with a major blockchain data provider while preparing on-chain sweeps. Internal provider logs reportedly matched the timing, number and sequence of the attacker’s blockchain queries with what investigators described as “extraordinary specificity.”
Block Investigation Points to First-Wave Attacker
Block, which develops the Bitkey wallet, has passed information from its investigation to the relevant authorities. Clay Garrett, lead engineer on the Bitkey project, said the attacker appears to have queried source addresses through a paid blockchain data account before transferring funds from affected Coldcard wallets.
The blockchain data provider has not been accused of participating in the theft. The service appears to have provided normal access to its platform, while account records may have created a link between the on-chain activity and an identifiable customer.
Galaxy Research head Alex Thorn has also said that “the identity of the attacker in wave 1 could be known to law enforcement.” His statement remains an assessment based on the investigation rather than confirmation that the FBI has publicly identified or arrested a suspect.
Investigators also see similarities between the first attack and a second wave involving about 76 BTC. Later thefts appear smaller and faster, raising the possibility that other attackers began exploiting the weakness after details of the vulnerability became known.
Coldcard Vulnerability Exposes Weak Bitcoin Private Keys
The attacks stem from a weakness in how some Coldcard devices generated the random numbers used to create seed phrases. The problem was introduced into firmware in March 2021 and remained undetected for nearly five years.
Affected firmware used a software-based random number generator instead of relying fully on the STM32 microcontroller’s hardware random source. The resulting entropy reportedly fell to around 40 bits on older devices and 72 bits on newer models, making some generated private keys more predictable than intended.
Attackers with enough computing resources could potentially reconstruct vulnerable seed phrases and gain control of Bitcoin stored at corresponding addresses. The issue affects devices dating back to older Coldcard models, including some MK2 wallets running firmware from version 4.0.1 onward.
The attack remains active, and users who may have generated keys with affected firmware have been advised to check Coldcard’s guidance and move funds where necessary.
More Than 1,800 BTC Stolen Across Multiple Waves
The first-wave funds remain one of the main focuses of the investigation. The 1,082.65 BTC taken during that phase has not moved since the theft and remains concentrated across three addresses under close monitoring.
The lack of movement leaves open the possibility of recovering some funds if law enforcement can connect the addresses to an identified attacker or regulated service. Recovery, however, has not been confirmed, and ownership of the stolen Bitcoin remains with the victims unless authorities successfully regain control.
Across all known waves, attackers have taken more than 1,800 BTC, with reported losses exceeding $118 million at the time of assessment.







