Investigators believe the FBI may have identified the individual behind the first wave of thefts tied to the Coldcard hardware wallet exploit that has drained bitcoin from thousands of addresses since late July. The first wave alone accounted for roughly 1,082.65 BTC, worth about $11.8 million at the time, while Galaxy Research's running tally across all four waves of the exploit has climbed to approximately 1,816 BTC, or roughly $116 million, pulled from more than 5,200 addresses.
The vulnerability traces back to a firmware update Coinkite shipped for its Coldcard devices in March 2021, version 4.0.1, which altered how the wallet generated seed phrases. According to research published by TRM Labs, the flawed code rerouted randomness generation away from the device's dedicated hardware random number generator and toward a software-based pseudorandom generator instead, weakening the entropy behind affected wallets' private keys years before the theft was discovered.
How Investigators Tracked the Money
Separate investigations by Block and Galaxy Research found that the attacker behind the first wave relied on a paid account at a major blockchain data provider while moving the stolen funds, and that the provider's internal logs matched the attacker's on-chain activity pattern with what investigators described as extraordinary specificity. That overlap is reportedly what has brought law enforcement closer to identifying the individual responsible, even though the FBI has not publicly confirmed an identification or filed any charges.
Related: Georgia Man Deported From Fiji Over Alleged $165M Crypto Ponzi Scheme
Multiple Attackers, Multiple Waves
Transaction pattern analysis suggests more than one attacker may be involved across the exploit's four separate theft waves, meaning identifying the first-wave actor would not necessarily resolve the rest of the case. Investigators are continuing to trace the later waves, which together account for the bulk of the roughly $116 million total.
A Reminder That Self-Custody Bugs Can Sit Dormant for Years
The exploit's five-year gap between the flawed 2021 firmware update and its exploitation in mid-2026 underscores a risk specific to hardware wallets: a subtle randomness bug can sit undetected in supposedly audited, widely trusted devices for years before anyone actually tries to exploit it at scale. For self-custody users, the case is likely to renew scrutiny of how thoroughly hardware wallet firmware updates are reviewed before shipping, and how quickly vulnerabilities are disclosed once found.