The FBI likely already holds the identity of the perpetrator behind the theft of 1,082 BTC via the first wave of the Coldcard hardware vulnerability. Galaxy Research researcher Alex Thorn revealed that law enforcement may already know who is behind the exploit, although authorities have not yet released a public confirmation or filed official charges.
The perpetrator’s trail was detected thanks to an unusual finding by Block’s engineering lead, Clay Garrett. The attacker apparently used a paid account on an unnamed blockchain data provider service to query the source addresses targeted for the theft.
Precise Search Log Match
Upon inspection, internal logs from the data provider showed matches with the volume, timing, and sequence of the address search queries. This pattern had an extraordinarily high level of specificity. Block immediately forwarded these findings to the authorities, while emphasizing that the data provider was unaware it had facilitated the hack.
To date, all Bitcoin stolen in the first wave remains sitting in the associated wallet addresses. The stolen funds have not entered crypto exchanges or mixing services to obscure their origin. Given that the Bitcoin network lacks a protocol-level mechanism to freeze funds, these assets remain entirely secure under the perpetrator’s control and cannot be forcibly frozen by any party.
This theft case did not stop at a single wave. Public data compiled by Galaxy Research recorded a minimum total loss of 1,700 BTC across the entire series of attacks. Interestingly, subsequent waves of theft exhibited transaction patterns completely different from the initial attack. This difference in patterns indicates that other perpetrators may have also exploited the same vulnerability.
Firmware Update Does Not Patch Old Seeds
This security disaster stems from a vulnerability in the Coldcard Mk2 and Mk3 firmware version 4.0.1. The software generated seed phrases with insufficient entropy, leaving user wallets vulnerable to exploits. Other hardware variants, such as the Mk4, Mk5, and the Q series, were also affected by this issue, albeit on a smaller scale of vulnerability.
Although a firmware update was released by the manufacturer to prevent this vulnerability from recurring when the device generates a new seed, installing the latest firmware does not fix old seeds that were already created with low entropy from the beginning.
For users of affected Coldcard variants, updating the hardware alone does not guarantee the safety of their funds. Users are required to generate a new seed on the patched firmware and immediately transfer all remaining crypto assets to the new address. Failing to perform this wallet migration leaves the funds accessible to the attacker. As reported by crypto.news.
Disclaimer: This article is for informational and educational purposes only, not financial advice. Cryptocurrency assets are highly volatile and carry significant risk. Always do your own research (DYOR) and never invest more than you can afford to lose.




