More than 1,082 BTC stolen, still sitting untouched in the hacker’s address. A concrete lead traced back to a paid account with a blockchain data provider. And one question hanging in the air: are we dealing with a sophisticated outside attacker, or an insider who knew about the bug for years?

The Coldcard case is taking on a new dimension. According to investigators at Block and analysis from Alex Thorn at Galaxy Research, the identity of the hacker responsible for the first and most massive wave of drains may already be known to US law enforcement. A scenario that keeps alive the hope of eventual restitution for victims — provided the funds remain frozen.

Here is what we know, and what the on-chain data reveals about one of the most significant Bitcoin hacks of 2026.

1,082 BTC Stolen: A Digital Fingerprint That Betrays the Hacker

On July 30, 2026, an attacker began methodically draining Coldcard wallets that had generated their seeds under vulnerable firmware — an entropy bug that went undetected for five years, present as far back as the MK2 running firmware 4.0.1. The first wave, the most devastating, moved 1,082.65 BTC in a single coordinated sweep. Subsequent waves brought the estimated total to over 2,000 BTC, equivalent to approximately $118 million confirmed stolen at this stage.

It was the engineering team at Block, through Clay Garrett, that produced the strongest lead. As early as July 31, Garrett published the findings of his investigation: “We identified an unusual pattern in the sweeps. That pattern led us to a hypothesis since confirmed: the operator used a paid account with a well-known blockchain data service provider to query the source addresses and carry out other related activity during the drains.” Block contacted the provider, whose internal logs match the theft pattern with “extraordinary specificity.”

Alex Thorn, speaking during an appearance on Bitcoin Magazine’s YouTube channel, was explicit: “The identity of the Wave 1 attacker may be known to law enforcement.” The 1,082.65 BTC from Wave 1 remain untouched in the hacker’s address — a crucial detail that keeps the door open to a potential clawback for victims.

Coldcard Bitcoin Hack - Wave 1 investigation

Entropy Bug or Insider Attack? The Question That Changes Everything

Behind the hunt for the hacker lies an even more unsettling question: who knew about this bug from the very beginning? The entropy vulnerability affecting private key generation on Coldcard MK2 devices and later versions (firmware 4.0.1 and above) lay dormant for five years. Coinkite itself had publicly raised the risk of a “retirement attack” — a scenario in which an insider exploits a backdoor upon leaving the company.

That hypothesis has not been ruled out. The surgical precision of the sweeps, the apparent foreknowledge of vulnerable addresses, and the use of a professional account with a blockchain data provider all point toward someone with advanced technical expertise — and potentially privileged access to internal information. Wave 2, which adds approximately 76 additional BTC to the total, follows a sufficiently similar pattern for Alex Thorn to consider that the same actor may be behind it.

The attack is still ongoing. Coinkite has issued an urgent advisory: any user of a Coldcard MK2 or later model running firmware 4.0.1 or above must check their funds and move them immediately. More than 5,000 addresses have been compromised according to current estimates, and reports of new victims continue to come in. The window to act is still open — but it is closing fast.

Risk Warning : Trading financial instruments and/or cryptocurrencies carries a high level of risk, including the possibility of losing all or part of your investment. It may not be suitable for all investors. Cryptocurrency prices are highly volatile and can be influenced by external factors such as financial, regulatory, or political events. Margin trading increases financial risks.

CFDs (Contracts for Difference) are complex instruments with a high risk of rapid capital loss due to leverage. Between 74% and 89% of retail investor accounts lose money when trading CFDs. You should assess whether you understand how CFDs work and whether you can afford to take the high risk of losing your money.

Before engaging in financial or cryptocurrency trading, you must be fully informed about the associated risks and fees, carefully evaluate your investment objectives, level of experience, and risk tolerance, and seek professional advice if needed. InvestX.fr and the InvestX application may provide general market commentary, which does not constitute investment advice and should not be interpreted as such. Please consult an independent financial advisor for any investment-related questions. InvestX.fr disclaims any liability for errors, misinvestments, inaccuracies, or omissions and does not guarantee the accuracy or completeness of the information, texts, graphics, links, or other materials provided.

Some of the partners featured on this site may not be regulated in your country. It is your responsibility to verify the compliance of these services with local regulations before using them.

Get 6200 USDT with Bitget ! 🔥

Don't miss out on this offer !
Create your account now to unlock this exclusive reward
Open a Bitget account
close-link
Click Me