The investigation into the large-scale Coldcard hardware wallet thefts from July 2026 has moved forward, according to Bitcoin Magazine, with a significant portion of the stolen bitcoin from the first wave still sitting on addresses linked to the attackers. The report said roughly 1,082.65 BTC, valued at about $118 million by the cited estimate, has not been moved out of those wallets. Investigators also found that the attacker used a paid account at a blockchain data service provider, and internal logs were said to closely match the theft pattern. Those leads have already been handed to law enforcement. Galaxy Research analyst Alex Thorn said the identity of the first-wave attacker may already be known to authorities. The report also linked the broader incident to an entropy-generation flaw introduced by Coinkite in a March 2021 code update. That bug affected some devices using MK2 and later models running firmware version 4.1 or above, producing weak private keys whose seeds could be brute-forced. Coinkite has released patched firmware and urged users to move assets, while the full scope of the flaw is still under review.
The investigation into the large-scale Coldcard hardware wallet thefts in July 2026 has made progress, according to Bitcoin Magazine. Roughly 1,082.65 BTC from the first wave of attacks, estimated in the report at about $118 million, remains parked in addresses controlled by the attacker.
Investigators found that the attacker used a paid account from a blockchain data service provider. Internal logs were described as closely matching the theft pattern, and the leads have been passed to law enforcement.
Alex Thorn, an analyst at Galaxy Research, said the identity of the first-wave attacker may already be in the hands of law enforcement.
Later attack waves accounted for about 2,000 BTC in losses
The report said later waves of attacks led to the theft of about 2,000 BTC in total. The second wave alone involved around 76 BTC, and its operating pattern resembled the first wave, suggesting the same actor may have been involved.
Bug traced to a March 2021 code update
The incident was traced back to a code update introduced by Coinkite in March 2021. That update created an entropy-generation flaw, causing some devices using MK2 and later models with firmware version 4.1 and above to generate weak private keys. The seeds could then be brute-forced.
Coinkite has released patched firmware and advised users to move their assets, though the full scope of the vulnerability is still being assessed.
This article was originally published by Bit.Fan. For more cryptocurrency news and market insights, visit www.bit.fan. Disclaimer:
The market information, project data, and third-party content displayed on this platform are for industry information sharing only and do not constitute any form of investment advice or return commitment.
Cryptocurrency trading carries high risks. Users should fully assess their risk tolerance and make independent decisions. All profits, losses, and legal responsibilities are borne by the users themselves.