FBI May Be on Trail of Perpetrators of Coldcard Bitcoin Theft
The FBI may have identified the perpetrators who stole more than one thousand Bitcoin in July 2026 through a vulnerability in Coldcard hardware wallets. Research by Block and Galaxy Research indicates that the attackers used a paid account with a major blockchain data provider during the theft, and the provider’s internal logs closely reflected the attack pattern. The 1,082.65 BTC stolen, worth approximately $11.8 million, remains untouched on the attacker’s address.
Bitcoin is available at Bitvavo and OKX.
In brief:
- The FBI may have identified those responsible for the first wave of the Coldcard hack through logs from a blockchain data provider.
- The vulnerability lies in the random number generator of Coldcard devices running firmware version 4.0.1, released in March 2021.
- Coinkite has released corrected firmware for all affected models, but existing seeds are not restored by it.
How the attackers may have been traced
According to Block’s research, the attackers used a paid account with a known blockchain data provider to analyse on-chain transactions while draining the wallets. The provider’s internal logs corresponded with great accuracy to the pattern of requests associated with the theft. This may give law enforcement a direct link to the perpetrators’ identity.
The 1,082.65 BTC taken during the first wave remains untouched on the attacker’s address for now. That gives victims some hope that recovery may still be possible. Meanwhile, investigations into several later attack waves are still ongoing.
A bug in the random number generator
The cause of the theft lies in a vulnerability in the random number generator of Coldcard devices. The flaw was introduced through the libngu library in 2021 and affects devices running firmware version 4.0.1 and later. As a result, private keys generated by a large number of devices could be cracked.
According to Coinkite’s security advisory, seeds created on Mk2 and Mk3 devices with firmware between versions 4.0.1 and 4.1.9 are vulnerable, unless at least fifty independent dice roll inputs were used during creation. On Mk4, Mk5 and Q models, the impact is less severe but still serious: those devices generated seeds with only around 72 bits of entropy instead of the expected 128 bits.
Coinkite stresses on its status page that a firmware update does not restore the existing seed. Users with a vulnerable seed must manually migrate their funds to a newly generated seed on corrected firmware. Corrected versions are available for all affected models: Mk2 and Mk3 from version 4.2.0, Mk4 and Mk5 standard from 5.6.0, and Q standard from version 1.5.0Q.
Attack is still ongoing
The attacks are not over. Coldcard devices older than the MK2 running firmware 4.0.1 or newer remain a target. Anyone still holding funds in a vulnerable seed is urged to move them as soon as possible.
The question of whether the perpetrators are insiders or external attackers remains open. Coinkite had previously warned of a so-called retirement attack, in which an internal actor could exploit knowledge of a hidden vulnerability upon leaving. Whether the current investigation points in that direction has yet to be confirmed.
Not financial advice. The Latest Crypto News provides educational and informational content only. Crypto-assets are highly volatile and you can lose your entire investment. Always do your own research. Read our full disclaimer.
Affiliate disclosure. Some links on this site are affiliate links. If you sign up with a partner through one of them, we may earn a commission at no extra cost to you. This never influences our reporting. See our editorial guidelines.