[ccpw id="39382"]

The FBI may have identified the attacker behind the first wave of the July 2026 Coldcard hardware wallet exploit after investigators traced activity linked to the theft, Bitcoin Magazine reported, citing investigations by Block and Galaxy Research.
A key lead emerged from the attacker’s use of a paid blockchain data provider while moving stolen funds onchain. Block found that request patterns tied to the account closely aligned with records held in the provider’s internal logs.
The first attack wave resulted in the theft of 1,082.65 BTC, worth about $70.2 million at the time.
The broader Coldcard security issue involved a random-number-generation flaw introduced after a March 2021 code change routed wallet seed generation through the libNgU path. The flaw could make seeds and private keys generated under affected firmware vulnerable to brute-force recovery.
Researchers continue to track multiple waves of attacks.
Source: Bitcoin Magazine