Investigators may have given U.S. authorities information capable of identifying an attacker responsible for the first Coldcard theft wave, Bitcoin Magazine reported on Aug. 18.
Summary
- Block traced the first Coldcard sweep to a paid blockchain data account used during theft.
- Galaxy said the first wave removed 1,082.65 BTC, with the associated funds remaining unmoved afterward.
- No FBI statement confirms an attacker’s identity, arrest, charges, seizure, or recovery of stolen funds.
- At least 1,700 BTC was stolen across multiple waves, according to Galaxy’s latest public estimate.
- Existing vulnerable seeds remain unsafe after firmware updates and require migration into newly generated wallets.
Galaxy Research’s Alex Thorn said the first wave attacker’s identity “may be known to law enforcement.” His statement was cautious, and the FBI has not publicly confirmed identifying a suspect, opening a case, making an arrest or recovering any stolen Bitcoin.
The first wave removed 1,082.65 BTC from wallets generated using vulnerable Coldcard firmware. At Bitcoin’s recent price near $64,000, those coins would be worth approximately $69 million, not $11.8 million.
Block found an offchain trail from the first sweep
Block engineering lead Clay Garrett said investigators found an unusual pattern in the attacker’s onchain sweeps. The operator allegedly used a paid account at an unnamed blockchain data provider to query source addresses and perform related activity.
The account could contain payment, access or subscriber records. However, no public evidence establishes which records were retained, who controlled the account or whether the service received accurate identifying information.
Block also said it found no evidence that the provider knowingly assisted the theft. The company appeared to have supplied ordinary services without knowing how the information would be used.
FBI identification remains an unconfirmed possibility
Bitcoin Magazine’s report linked the investigative lead to the FBI, but no FBI statement confirms the claim. No criminal complaint, indictment, seizure filing or forfeiture action was located in the public record.
Thorn’s wording is therefore important. An identity that “may be known” is not the same as a verified suspect or charged defendant. Investigators must still establish who operated the account, who controlled the receiving addresses and whether the evidence supports criminal charges.
The first wave funds remain visible at associated addresses. As crypto.news previously reported, the largest attacker’s unmoved balance had not entered a known exchange or mixer.
Those coins are not frozen. Bitcoin transactions cannot be reversed or blocked at the protocol level. Recovery would require control of the private keys, voluntary return, or a later transfer through an intermediary able to comply with a lawful seizure order.
Coldcard losses extend beyond one attacker
Galaxy’s latest public research page lists losses of at least 1,700 BTC across multiple waves. Other totals remain higher because researchers use different address clusters, confirmation standards and victim reports.
Later theft waves displayed different transaction patterns. Researchers have therefore cautioned that more than one actor may have exploited the weak seed space after information about the flaw became public.
This distinction means identifying the first operator would not necessarily resolve every theft. Galaxy has distributed suspected addresses to investigators, exchanges and analytics companies, but no agency has announced a recovery.
In related coverage, crypto.news’ earlier technical review found that the incident involved weak seed generation rather than compromise of the Bitcoin protocol or physical access to devices.
Vulnerable users must still migrate their funds
Coinkite’s advisory says affected Mk2 and Mk3 firmware generated seeds with inadequate entropy beginning with version 4.0.1. Seeds created on certain Mk4, Mk5 and Q releases were also exposed, although their entropy reduction was less severe.
Fixed firmware prevents the same defect when generating new seeds. Installing an update does not repair an existing vulnerable seed. Users must update first, create a completely new seed and move their funds after verifying a test transaction.
Coinkite’s current status says its formal technical postmortem remains in progress. It also says targeted independent checks have occurred but do not establish that every fixed firmware binary received a complete audit.
The incident has prompted calls for independent hardware audits. The immediate questions now concern whether authorities can connect the paid account to a person, whether the first wave funds move, and whether court records eventually confirm an investigation.






