Progress has emerged in the investigation into the July 2026 mass theft from Coldcard hardware wallets (offline crypto storage devices). About 1,082.65 BTC, worth roughly $118 million, from the first attack wave remains in attacker-controlled addresses, and investigators found that the perpetrator used a paid account at a blockchain data service provider whose internal logs closely matched the theft pattern. Those leads have been handed to law enforcement. Galaxy Research analyst Alex Thorn said the first-wave attacker may already be known to investigators. Later attack waves accounted for about 2,000 BTC in additional stolen funds, including around 76 BTC in the second wave, which followed a similar operating pattern and may have involved the same actor. The incident was traced to an entropy-generation flaw (weak randomness in key creation) introduced in a Coinkite code update in March 2021, causing some MK2 and later devices running firmware version 4.1 and above to generate low-strength private keys (secret wallet access codes) whose seeds could be brute-forced. Coinkite has released patched firmware and urged users to move assets, but the scope of the impact is still being assessed.