Coldcard Hacker May Be Known to Authorities After Major Bitcoin Theft
Cryptocurrency trading is speculative and your capital is at risk when you trade. We may earn affiliate commissions from some of the products on this page - at no extra cost to you.

Highlights:
- Investigators may have a new lead that could help identify the Coldcard Hacker behind the first theft wave.
- The first attacker drained 1,082.65 BTC from wallets that generated seeds using vulnerable firmware.
- Affected users still need new wallet seeds because firmware updates cannot secure private keys that are already exposed.
Investigators may have given U.S. authorities information that could help identify the attacker behind the first Coldcard theft wave. Galaxy Research’s Alex Thorn said law enforcement may already know the identity of the first-wave attacker. However, the FBI has not confirmed identifying a suspect or announced any arrest, charges, Bitcoin seizure, or recovery.
Coldcard Theft Case Update: FBI May Have Identified First-Wave Attackers
According to Bitcoin Magazine, investigations by Block and Galaxy Research indicate that the FBI may have identified the attackers behind the first wave of the July 2026 Coldcard hardware wallet exploit, in… pic.twitter.com/Is9Y3WsgxH
— Wu Blockchain (@WuBlockchain) August 19, 2026
The first wave drained 1,082.65 BTC from wallets that generated seeds using vulnerable firmware. Researchers are still tracking the funds because they remain at addresses linked to the first-wave attacker. The wallets remain important to investigators because their transaction history could help trace activity connected to the stolen Bitcoin.
Block engineering lead Clay Garrett said investigators found unusual activity while examining the attacker’s onchain sweeps. They linked the activity to a paid account at an unnamed blockchain data provider. The operator allegedly used the account to query source addresses during the wallet sweeps. Block contacted the provider to compare those requests with its internal records.
1/ During our investigation of the Coldcard drain yesterday, we identified an unusual pattern in the sweeps. That pattern led us to a hypothesis that has since been confirmed: the operator used a paid account at a well-known blockchain-services provider to query the source… https://t.co/l5McyhhcNn
— Clay Garrett (@clay_garrett) July 31, 2026
Garrett said the provider’s logs matched the number, timing and sequence of the suspected requests. Block then shared relevant information with authorities. Neither company disclosed whether the account contained subscriber, payment, or other identifying records. Block also found no evidence that the provider knowingly helped the operator steal Bitcoin.
Public evidence does not identify who controlled the paid account during the first theft wave. Investigators must connect the account to whoever controlled the addresses that received the 1,082.65 BTC. They must also establish whether the account records identify the person who conducted the onchain activity.
Coldcard Hacker Probe Focuses on the Wallet Flaw
Investigators and security researchers are also examining the software flaw that exposed vulnerable wallet seeds. A March 2021 update replaced Trezor-derived cryptographic components with libngu and changed how affected devices generated seeds. Coinkite CTO Peter Gray, also known as Doc-Hex, pushed the library change into the codebase.
Coldcard intended the process to collect randomness from the STM32 hardware random number generator. However, a software error directed the request to MicroPython’s Yasmarang pseudo-random number generator. The error reportedly reduced entropy to about 40 bits on older models and around 72 bits on newer devices. The smaller seed space made vulnerable private keys easier to search with modern computing hardware.
Researchers also examined reported links between Gray and the pseudonymous developer known as “switck.” Bitcoin Core contributor James O’Beirne connected commits from both identities through the same GPG signing key. Other researchers have also reported additional connections between the two identities. However, that evidence does not establish that Gray deliberately created the flaw or participated in the Bitcoin theft.
Thanks for merge @DocHex … I’m making yet another bitcoin library. Could be useful on @COLDCARDwallet someday.
— switck (@switck) October 16, 2020
Affected Users Still Need to Move Their Funds
Users with vulnerable seeds must generate new ones because firmware updates cannot secure existing exposed private keys. Affected users should install corrected firmware before creating new seeds with the repaired randomness process. They must then transfer their Bitcoin from vulnerable addresses to addresses generated from those replacement seeds.
In a related development, hardware wallet maker BitBox has released a firmware update to fix two serious security flaws. One flaw could let a malicious host install harmful firmware on unconfigured BitBox02 Multi and BitBox02 Nova devices. The second could lock Bitcoin to an unintended Silent Payments address and let an attacker demand payment for recovery assistance. BitBox said it has received no reports of attackers exploiting either flaw or causing users to lose funds.
We just released the Dixence security update.
During our internal audits, we were able to discover and fix multiple security issues in the BitBox firmware.
We recommend our users to update their BitBoxApp and device firmware through the BitBoxApp settings.…
— BitBox (@BitBoxSwiss) August 17, 2026
Best Crypto Exchange
- Over 90 top cryptos to trade
- Regulated by top-tier entities
- User-friendly trading app
- 30+ million users
eToro is a multi-asset investment platform. The value of your investments may go up or down. Your capital is at risk. Don’t invest unless you’re prepared to lose all the money you invest. This is a high-risk investment, and you should not expect to be protected if something goes wrong.







