Coldcard wallet theft probe progresses; FBI said to be closing in on initial attacker

AI Market Summary
Advances in the Coldcard wallet theft probe suggest law enforcement may have identified an initial attacker, but the disclosure reiterates that a firmware entropy flaw enabled brute-force key recovery across multiple attack waves totaling ~2,000 BTC. While a patch and migration guidance are available, ongoing uncertainty around affected devices and recoverability can weigh on market confidence in self-custody security and may elevate near-term risk premia for BTC holders using impacted hardware.
Impact level
● Medium
Affected assets
BTC/USDT+0.38%
AI Insight · BTC/USDTAI Insight
▼ Bearish
Trade now
⚠️ AI-generated insights are based on news content and are provided for informational purposes only. They do not constitute investment advice or represent the views of BingX. Investing involves risk. Please trade responsibly.
Huo Xing Cai Jing, citing Bitcoin Magazine, reported new developments in the investigation into a large-scale Coldcard hardware wallet crypto theft that occurred in July 2026. Investigators estimate about 1,082.65 BTC—roughly $118 million—from the first wave of attacks remains parked in addresses controlled by the perpetrator. The probe found the attacker used a paid account with a blockchain data services provider. Internal logs were said to show a "high degree of alignment" with the theft activity, and related leads have been passed to law enforcement. Alex Thorn, an analyst at Galaxy Research, said the identity of the first-wave attacker "may already be known to law enforcement." Later waves of attacks reportedly brought total losses to about 2,000 BTC. The second wave alone involved roughly 76 BTC and followed a similar operating pattern to the initial theft, pointing to possible involvement by the same actor. The incident is tied to an entropy-generation flaw introduced in a Coinkite code update in March 2021. The issue could cause certain devices—MK2 and newer models running firmware version 4.1 or higher—to generate weak private keys vulnerable to brute-force recovery. Coinkite has released patched firmware and advised users to migrate assets, while the full extent of the vulnerability's impact remains under review.