Coldcard Theft Hits $70M as FBI May Identify Attackers

Add as a preferred source on Google

The Coldcard theft investigation has advanced after investigators reportedly traced the first wave of the July exploit to a paid blockchain service account. The attack drained more than 1,082 BTC, while the underlying seed-generation vulnerability has raised broader concerns about firmware security and self-custody risks.

Coldcard theft investigation has taken a new turn as the FBI may have identified attackers behind the first wave of the July 2026 Coldcard wallet exploit. The initial wave stole 1,082.65 BTC worth about $70.2 million based on the value of the transaction. The amount was originally estimated much lower overall.

According to Block engineer Clay Garrett, investigators identified the transaction pattern and traced it back to a paid account on a popular blockchain service provider. According to internal logs of the provider, the requests match with an unusual level of detail, including request number and exact timing. According to Block, the provider seemed to be unaware of any criminal activity and shared all available information with law enforcement.

Coldcard Theft
Source: Crypto Banter’s X Post

Galaxy Research mapped the initial wave, which involved 1,196 addresses being drained in the timeframe from 01:10:20 to 01:51:26 UTC on July 30. Stolen bitcoins were transferred to new addresses and have yet to move. Thorn says that the Wave 1 attacker’s identity is probably known by law enforcement already.

Also Read | Arbitrum Price Eyes $0.07637 as Buyers Return Amid BVNK’s USDC Expansion

Coldcard Theft Reveals Firmware Security Risks 

The coldcard theft incident stems from a seed-generation vulnerability affecting Coldcard devices and firmware released from 2021 onward. Specifically, a code update made in 2021 redirected random number generation to a software pseudo-random generator instead of the intended hardware generator. This significantly lowered the entropy and increased vulnerability of private keys to computational search.

The issue remained undetected until the attackers drained Coldcard wallets on July 30. The company informed its Mk3 customers about the vulnerability and later issued an update that revealed the vulnerability of some Mk4, Mk5, and Q wallets. Firmware updates cannot fix the seed generation process; users need to move funds to a new wallet.

Coldcard Theft Investigation Broadens as Questions Remain

The exploit has affected Bitcoin behavior. OKX reported record inflows to centralized exchanges after the incident, while The Block observed new Bitcoin addresses rising above 330,000 as users migrated funds. The event highlights the difference between counterparty risks and implementation risks, self-custody solves some issues, but it cannot eliminate security risks built into the flawed software.

The Coldcard Theft case also revived discussion of Coinkite’s “retirement attack” warning, describing a scenario where flawed entropy could enable later recovery. At the same time, Peter Gray and Coinkite have not reacted to the claims yet. Now it is time to attribute, track down, and recover the funds. Users should move.

Also Read | Ethereum Price Prediction: Can ETH Break $1,920 and Reach $2,000 Target?

Bena Ilyas

Bena Ilyas

Bena Ilyas is a Global News Correspondent and Market Analyst at Tronweekly with over four years of experience covering global cryptocurrency, blockchain, and Web3 developments. She has written 1,000+ articles for leading crypto news platforms, reporting on Bitcoin, Ethereum, altcoins, DeFi, and global crypto regulation, alongside Web3 trends, Layer 2 ecosystems, and AI-driven crypto use cases. Her work is based on verified sources and fact-based reporting for global market participants.

Articles: 2022