TLDR
Block traced the first Coldcard theft wave to a paid blockchain data account used during the attack.
Galaxy Research says the first wave removed 1,082.65 BTC, worth about $69 million at recent prices.
The FBI has not confirmed identifying a suspect, making an arrest, or recovering any stolen funds.
At least 1,700 BTC has been stolen across multiple theft waves tied to the same firmware flaw.
Users with vulnerable seeds must update firmware, create new seeds, and move their funds to stay safe.
Investigators may have identified the person behind the first wave of a Bitcoin theft involving Coldcard hardware wallets. Bitcoin Magazine reported the update on August 18.
Galaxy Research analyst Alex Thorn said law enforcement may already know who carried out the first attack. His comment was careful and stopped short of confirming anything.
The FBI has not made a public statement about the case. No arrest, charge, or fund seizure has been announced so far.
The first wave of the theft removed 1,082.65 Bitcoin from wallets created with flawed firmware. At recent prices near $64,000 per coin, that amount is worth roughly $69 million.
How investigators traced the theft
Block engineering lead Clay Garrett said his team found an unusual pattern in how the attacker searched for wallet data. The person allegedly used a paid account with a blockchain data provider during the theft.
Block contacted that provider. Internal records reportedly matched the timing and pattern of the suspicious activity closely.
Garrett said Block passed the information along to authorities. It remains unclear what records the provider kept or who controlled the account.
Block said it found no sign the data provider knew how its service was being used. The company appears to have offered normal services without awareness of any theft.
What “may be known” actually means
Thorn’s wording leaves room for doubt. A name that investigators suspect is not the same as someone formally charged with a crime.
No criminal complaint, indictment, or forfeiture filing tied to the case has turned up in public records. Authorities would still need to confirm who controlled both the account and the wallet addresses.
The Bitcoin from the first wave has not moved since it was taken. It also has not shown up at any known exchange or mixing service.
Bitcoin transactions cannot be reversed once confirmed. Getting the funds back would require the private keys, a voluntary return, or a transfer through a service able to follow a legal order.
The Coldcard theft was not limited to one attacker or one event. Galaxy Research says at least 1,700 Bitcoin has been stolen across several separate waves.
Later thefts showed different patterns than the first one. This has led researchers to think more than one person may have used the same weakness.
Coinkite, the company behind Coldcard, said certain firmware versions created wallet seeds with weak randomness. This affected some Mk2, Mk3, Mk4, Mk5, and Q devices starting with version 4.0.1.
New firmware fixes the flaw for wallets made after the update. It does not repair wallets already generated using the weak method.
Coinkite has told users to update their firmware, create a brand new seed, and move their funds. It recommends testing with a small transaction first.
Coinkite says its full technical review of the incident is still underway. Independent checks have taken place but have not confirmed every piece of updated firmware.
The case remains open. What happens next depends on whether authorities can link the data account to a real person and whether the stolen funds ever move.