More than 1,082 BTC stolen, still sitting untouched in the hacker’s address. A concrete lead traced back to a paid account with a blockchain data provider. And one question hanging in the air: are we dealing with a sophisticated outside attacker, or an insider who knew about the bug for years?
The Coldcard case is taking on a new dimension. According to investigators at Block and analysis from Alex Thorn at Galaxy Research, the identity of the hacker responsible for the first and most massive wave of drains may already be known to US law enforcement. A scenario that keeps alive the hope of eventual restitution for victims — provided the funds remain frozen.
Here is what we know, and what the on-chain data reveals about one of the most significant Bitcoin hacks of 2026.
1,082 BTC Stolen: A Digital Fingerprint That Betrays the Hacker
On July 30, 2026, an attacker began methodically draining Coldcard wallets that had generated their seeds under vulnerable firmware — an entropy bug that went undetected for five years, present as far back as the MK2 running firmware 4.0.1. The first wave, the most devastating, moved 1,082.65 BTC in a single coordinated sweep. Subsequent waves brought the estimated total to over 2,000 BTC, equivalent to approximately $118 million confirmed stolen at this stage.
It was the engineering team at Block, through Clay Garrett, that produced the strongest lead. As early as July 31, Garrett published the findings of his investigation: “We identified an unusual pattern in the sweeps. That pattern led us to a hypothesis since confirmed: the operator used a paid account with a well-known blockchain data service provider to query the source addresses and carry out other related activity during the drains.” Block contacted the provider, whose internal logs match the theft pattern with “extraordinary specificity.”
Alex Thorn, speaking during an appearance on Bitcoin Magazine’s YouTube channel, was explicit: “The identity of the Wave 1 attacker may be known to law enforcement.” The 1,082.65 BTC from Wave 1 remain untouched in the hacker’s address — a crucial detail that keeps the door open to a potential clawback for victims.

Entropy Bug or Insider Attack? The Question That Changes Everything
Behind the hunt for the hacker lies an even more unsettling question: who knew about this bug from the very beginning? The entropy vulnerability affecting private key generation on Coldcard MK2 devices and later versions (firmware 4.0.1 and above) lay dormant for five years. Coinkite itself had publicly raised the risk of a “retirement attack” — a scenario in which an insider exploits a backdoor upon leaving the company.
That hypothesis has not been ruled out. The surgical precision of the sweeps, the apparent foreknowledge of vulnerable addresses, and the use of a professional account with a blockchain data provider all point toward someone with advanced technical expertise — and potentially privileged access to internal information. Wave 2, which adds approximately 76 additional BTC to the total, follows a sufficiently similar pattern for Alex Thorn to consider that the same actor may be behind it.
The attack is still ongoing. Coinkite has issued an urgent advisory: any user of a Coldcard MK2 or later model running firmware 4.0.1 or above must check their funds and move them immediately. More than 5,000 addresses have been compromised according to current estimates, and reports of new victims continue to come in. The window to act is still open — but it is closing fast.