Coldcard Hackers May Be Known to Law Enforcement, Investigation Finds
In July 2026, an attacker began systematically draining Bitcoin from Coldcard hardware wallets that had generated seeds under vulnerable firmware. The first and largest wave alone moved 1,082.65 BTC.
According to Block's investigation, the attacker used a paid account at a major blockchain data provider to query source addresses and perform related activity during the sweeps. Internal logs from the provider matched the theft pattern with 'extraordinary specificity,' including the number, timing, and sequence of requests.
The question now is who the hacker is and whether they are a sophisticated outsider or an insider with knowledge of the entropy bug that made the theft possible. The 2021 vulnerability produced exactly that outcome: seeds generated with far less entropy than intended, leaving them searchable years later.
Alex Thorn at Galaxy Research has tracked the activity through on-chain pattern analysis and voluntary victim reports. As of early August, confirmed and estimated losses across multiple waves exceeded 1,800 BTC from more than 5,000 addresses, though exact final totals continue to be refined as new reports arrive. In dollar terms, roughly $118 million has been confirmed stolen.
The primary source for the claim that the hacker's identity might be known is Clay Garrett, engineering lead at Block working on Bitkey. He stated that during their investigation of the Coldcard drain, they identified an unusual pattern in the sweeps and contacted the provider directly. Their internal logs matched the suspected workflow with extraordinary specificity.