Coldcard theft probe advances as 1,082.65 BTC remains in attacker wallets

Progress has emerged in the investigation into the July 2026 mass theft from Coldcard hardware wallets (offline crypto storage devices). About 1,082.65 BTC, worth roughly $118 million, from the first attack wave remains in attacker-controlled addresses, and investigators found that the perpetrator used a paid account at a blockchain data service provider whose internal logs closely matched the theft pattern. Those leads have been handed to law enforcement. Galaxy Research analyst Alex Thorn said the first-wave attacker may already be known to investigators. Later attack waves accounted for about 2,000 BTC in additional stolen funds, including around 76 BTC in the second wave, which followed a similar operating pattern and may have involved the same actor. The incident was traced to an entropy-generation flaw (weak randomness in key creation) introduced in a Coinkite code update in March 2021, causing some MK2 and later devices running firmware version 4.1 and above to generate low-strength private keys (secret wallet access codes) whose seeds could be brute-forced. Coinkite has released patched firmware and urged users to move assets, but the scope of the impact is still being assessed.

The information on this website is generated using AI and we cannot guarantee its accuracy. Please use it as reference information only.