Coldcard hack probe points to possible FBI lead on first wave attacker
Law enforcement may already have a concrete lead on the operator behind the first and largest wave of the July 2026 Coldcard wallet drains, according to reporting by Bitcoin Magazine. The report centers on 1,082.65 BTC taken in the initial wave, a tranche that remains untouched in the attacker’s address and is still being watched on-chain. Alex Thorn of Galaxy Research said publicly that the identity of the Wave 1 attacker may be known to authorities, while Block engineering lead Clay Garrett said Block’s investigation traced the sweep pattern to a paid account at a major blockchain services provider whose internal logs matched the theft workflow with unusual precision. The article also reconstructs the vulnerability that made the theft possible: a bug introduced in March 2021 during Coldcard’s migration to libngu that redirected randomness generation away from the STM32 hardware RNG and into MicroPython’s Yasmarang PRNG fallback. According to the report, that reduced effective entropy to roughly 40 bits on older models and around 72 bits on newer ones. As of early August, confirmed and estimated losses across multiple waves had exceeded 1,800 BTC from more than 5,000 addresses, with roughly $118 million confirmed stolen. The piece reviews claims of a possible insider “retirement attack,” but says public evidence remains insufficient to support that conclusion.








