Investigators probing the large-scale theft of Bitcoin from vulnerable Coldcard hardware wallets may have uncovered information capable of identifying the attacker behind the first and largest wave, although the FBI has not publicly confirmed a suspect, arrest or recovery of funds.
The development follows an investigation led by Clay Garrett, engineering lead at Block working on its Bitkey Bitcoin wallet. According to an August 18 report from Bitcoin Magazine, Garrett’s team discovered an unusual pattern while examining transactions that drained 1,082.65 BTC from 1,196 addresses during a roughly 41-minute period on July 30. Researchers concluded that the attacker had used a paid account at a major blockchain data provider to query source addresses and perform other activity connected to the theft. Block subsequently contacted the provider, whose internal records reportedly matched the timing, number and sequence of requests associated with the attack with “extraordinary specificity.”
That creates an important investigative trail outside Bitcoin’s blockchain. A paid service account can potentially contain subscriber, payment, access or network information that law enforcement could use alongside on-chain evidence to identify its operator. Galaxy Research head Alex Thorn said during a Bitcoin Magazine discussion that the identity of the first-wave attacker “may be known to law enforcement.” Block has said relevant information was passed to appropriate authorities. As of August 19, there has been no publicly announced arrest, indictment, seizure or recovery connected to the first-wave attacker.
The stolen first-wave funds remain unmoved. At Bitcoin prices around $64,000, the 1,082.65 BTC position is worth roughly $69 million. Researchers have identified additional waves beyond the initial July 30 sweep. Galaxy has estimated that at least 1,700 BTC was stolen across the incident, while other researchers have published higher figures. Across all known waves, attackers have taken more than 1,800 BTC from more than 5,000 addresses, with reported losses exceeding $118 million. A second wave involving roughly 76 BTC displayed characteristics sufficiently similar to the first that researchers have considered the possibility of the same attacker, though that connection has not been established.
The theft originated from a flaw affecting seed generation in versions of Coldcard firmware. The problem was introduced into firmware in March 2021 and remained undetected for nearly five years. Affected firmware used a software-based random number generator instead of relying fully on the STM32 microcontroller’s hardware random source. The resulting entropy reportedly fell to around 40 bits on older devices and 72 bits on newer models, making some generated private keys more predictable than intended. The issue affects devices dating back to older Coldcard models, including some MK2 wallets running firmware from version 4.0.1 onward. The weakness existed in how some Coldcard devices generated the secret information controlling users’ Bitcoin, rather than in the Bitcoin network itself. Coinkite has released firmware addressing the flaw, but installing patched firmware does not repair recovery phrases that were generated using vulnerable software. Owners of potentially affected wallets must generate a new seed using corrected firmware and migrate their Bitcoin to addresses controlled by the new keys.
The investigative breakthrough also illustrates the limits of relying solely on blockchain pseudonymity. Bitcoin transactions can be followed indefinitely on-chain, but attribution often depends on connecting those transactions with off-chain infrastructure. If the paid blockchain-data account can ultimately be tied to the person controlling the first-wave addresses, investigators could gain their strongest attribution evidence yet. Recovering the Bitcoin would remain a separate challenge, however, particularly while the 1,082.65 BTC remains under the attacker’s control and has not moved through a regulated intermediary capable of responding to a seizure order.