{"id":49704,"date":"2026-08-18T16:02:05","date_gmt":"2026-08-18T16:02:05","guid":{"rendered":"https:\/\/cryptomag.finance\/?p=49704"},"modified":"2026-08-18T16:02:05","modified_gmt":"2026-08-18T16:02:05","slug":"hunting-down-the-coldcard-hacker-wave-1-thief-may-be-known-to-fbi","status":"publish","type":"post","link":"https:\/\/cryptomag.finance\/?p=49704","title":{"rendered":"Hunting Down the Coldcard Hacker. Wave 1 Thief May Be Known to FBI"},"content":{"rendered":"<p><a rel=\"nofollow\" href=\"https:\/\/bitcoinmagazine.com\/\">Bitcoin Magazine<\/a><br \/>\n<img decoding=\"async\" src=\"https:\/\/bitcoinmagazine.com\/wp-content\/uploads\/2026\/08\/tn-2.webp\" \/><br \/>\n<a rel=\"nofollow\" href=\"https:\/\/bitcoinmagazine.com\/technical\/hunting-down-the-coldcard-hacker-wave-1-thief-may-be-known-to-fbi\">Hunting Down the Coldcard Hacker. Wave 1 Thief May Be Known to FBI<\/a><\/p>\n<div><\/div>\n<p class=\"wp-block-paragraph\">Law enforcement may already know who emptied more than a thousand Bitcoin from Coldcard wallets in the first and largest wave of the July 2026 drains. Block\u2019s investigation believes they traced the attacker\u2019s on-chain sweeps to a paid account at a major blockchain data provider whose internal logs matched the theft pattern with \u201cextraordinary specificity.\u201d\u00a0<\/p>\n<p class=\"wp-block-paragraph\">PSA: The attack is ongoing, targeting weak private keys generated on devices as old as the MK2 with firmware 4.0.1 onwards. If you may have one, double-check and <a href=\"https:\/\/bitcoinmagazine.com\/news\/coldcard-security-risk-immediate-action-required\">move funds asap<\/a>. See <a href=\"https:\/\/blog.coinkite.com\/coldcard-mk3-seed-generation-warning\/\" target=\"_blank\" rel=\"noopener\">Coinkite advisory <\/a>and <a href=\"https:\/\/coldcard.com\/security\/status\" target=\"_blank\" rel=\"noopener\">status page<\/a>.\u00a0<\/p>\n<p class=\"wp-block-paragraph\">The coins from that wave\u2014<a href=\"https:\/\/www.galaxy.com\/insights\/research\/coldcard-exploit-abates-as-total-losses-climb-to-at-least-1700-btc\" target=\"_blank\" rel=\"noopener\">1,082.65 BTC<\/a>\u2014still sit untouched in the attacker\u2019s address, leaving hope that a clawback may be possible to the victims and rightful owners of that first wave of stolen bitcoin. The question now is, who is the hacker and whether the same lead points to a sophisticated outsider, or whether the five-year-old entropy bug that made the theft possible was something closer to the insider \u201cretirement attack\u201d Coinkite itself once warned about.<\/p>\n<h3 class=\"wp-block-heading\">What We Know<\/h3>\n<p class=\"wp-block-paragraph\"><a href=\"https:\/\/coldcardwatch.com\/\" target=\"_blank\" rel=\"noopener\">On July 30, 2026<\/a>, an attacker began systematically draining Bitcoin from Coldcard hardware wallets that had generated seeds under vulnerable firmware, a bug that was undiscovered for years. The first and largest wave alone moved 1,082.65 BTC. Subsequent waves followed, with estimates over 2k BTC. <a href=\"https:\/\/www.galaxy.com\/insights\/research\/coldcard-exploit-abates-as-total-losses-climb-to-at-least-1700-btc\" target=\"_blank\" rel=\"noopener\">Alex Thorn<\/a> at Galaxy Research has tracked the activity through a combination of on-chain pattern analysis and voluntary victim reports. As of early August, confirmed and estimated losses across multiple waves exceeded 1,800 BTC from more than 5,000 addresses, though exact final totals continue to be refined as new reports arrive. In dollar terms, roughly $118 million has been confirmed stolen.<\/p>\n<p class=\"wp-block-paragraph\">Thorn has publicly discussed the possibility that law enforcement already holds a concrete lead on the operator behind the largest tranche. In a <a href=\"https:\/\/www.youtube.com\/watch?v=XlvsJblW4Sg\" target=\"_blank\" rel=\"noopener\">Bitcoin Policy Institute segment hosted on the Bitcoin Magazine YouTube channel<\/a>, Thorn stated: \u201cWave one\u2019s identity, attacker identity, may be known to law enforcement.\u201d He added that Wave 1 remains the biggest single chunk identified so far, with the coins still sitting in the attacker\u2019s address, and noted that Wave 2\u2019s pattern looks similar enough that it could involve the same actor. Wave 2 adds another 76 or so bitcoin to the total.\u00a0<\/p>\n<p class=\"wp-block-paragraph\">The primary source for the claim that the hacker\u2019s identity might be known is Clay Garrett, engineering lead at Block working on Bitkey. On July 31, 2026, <a href=\"https:\/\/x.com\/clay_garrett\/status\/2083247006139503065\">Garrett posted the findings<\/a> from Block\u2019s investigation:<\/p>\n<p class=\"wp-block-paragraph\">\u201cDuring our investigation of the Coldcard drain yesterday, we identified an unusual pattern in the sweeps. That pattern led us to a hypothesis that has since been confirmed: the operator used a paid account at a well-known blockchain-services provider to query the source addresses and perform other related activity during the sweeps.\u201d<\/p>\n<p class=\"wp-block-paragraph\">\u201cWe contacted the provider directly. Their internal logs matched the suspected workflow with extraordinary specificity, including the number, timing and sequence of requests. The provider was supplying its standard services in response to requests that did not reveal their broader purpose. We have seen no evidence that the provider knowingly participated in or facilitated the suspected theft.\u201d Garrett said, and added that; \u201cWe are sharing the relevant information with the appropriate authorities. We will provide further updates when doing so will not interfere with the investigation.\u201d<\/p>\n<p class=\"wp-block-paragraph\">Thorn and others have noted that later, smaller waves show different operational patterns\u2014some rapid, opportunistic drains followed by quick laundering\u2014suggesting additional actors may have reverse-engineered the same weak seed space after the initial public disclosure. Self-reported confirmed drains appear to have slowed sharply after August 6, though many potentially vulnerable seeds generated on the affected firmware between 2021 and the July 2026 patch remain at risk until users migrate.<\/p>\n<h3 class=\"wp-block-heading\">A Retirement Attack?<\/h3>\n<p class=\"wp-block-paragraph\">The nature of the failure has led to conspiracy theories about insider attacks that Coinkite itself once discussed publicly. In October 2021, the official COLDCARD account defined a \u201cretirement attack\u201d as the scenario \u201cwhen the project makers could have a \u2018bug\u2019 in the entropy generation for later retrieval.\u201d The post is still available <a href=\"https:\/\/x.com\/COLDCARDwallet\/status\/1447213375398846473\">here<\/a>. The 2026 vulnerability produced exactly that outcome: seeds generated with far less entropy than intended, leaving them searchable years later. Some in the Bitcoin space now believe that the hack may have been an inside job at Coinkite, though others disagree and the evidence in the public record remains too scarce to know anything definitive. Further evidence will likely not come out for years, until litigation exposes it.<\/p>\n<figure class=\"wp-block-embed is-type-rich is-provider-x wp-block-embed-x\">\n<div class=\"wp-block-embed__wrapper\">\n<blockquote class=\"twitter-tweet\" data-width=\"550\" data-dnt=\"true\">\n<p lang=\"en\" dir=\"ltr\">It\u2019s when the project makers could have a \u201cbug\u201d in the entropy generation for later retrieval.<\/p>\n<p>\u2014 COLDCARD (@COLDCARDwallet) <a href=\"https:\/\/x.com\/COLDCARDwallet\/status\/1447213375398846473?ref_src=twsrc%5Etfw\">October 10, 2021<\/a><\/p><\/blockquote>\n<\/div>\n<\/figure>\n<p class=\"wp-block-paragraph\">The critical change entered the codebase on March 1, 2021, in a commit titled \u201cFirst pass w\/ libNgU\u201d (<a href=\"https:\/\/github.com\/Coldcard\/firmware\/commit\/b18723dddb6d751c39978e4364b56b2414f68b47\" target=\"_blank\" rel=\"noopener\">b18723dd<\/a>). That commit replaced remaining Trezor-derived cryptography and BIP-39 code with a new library, libngu, and rewired seed generation. The intended result was that the call for randomness resolved to the STM32 hardware\u2019s true random number generator. However, the bug redirected the call to MicroPython\u2019s software Yasmarang PRNG instead, resulting in an effective entropy collapse to roughly 40 bits on older models and around 72 bits on newer ones. That meant the Bitocin private keys generated were effectively guessable by modern computing hardware. This swap of cryptographic libraries was pushed to the codebase by <a href=\"https:\/\/github.com\/doc-hex\" target=\"_blank\" rel=\"noopener\">Doc-Hex<\/a>, also known as Peter Gray, the Chief Technical Officer of Coinkite.\u00a0<\/p>\n<p class=\"wp-block-paragraph\">The move was arguably driven by licensing pressure, according to Foundation Devices CEO and founder Zach Herbert, though <a href=\"https:\/\/x.com\/COLDCARDwallet\/status\/2083869491948101686\">Coinkite has denied this as a primary motivation for the code change<\/a>, saying, \u201cCOLDCARD had to make this change to move to libsecp256k1; the license change is irrelevant to this. libsecp256k1 is the standard library used by Bitcoin Core.\u201d<\/p>\n<p class=\"wp-block-paragraph\">Coldcard had been using Trezor-derived code under the GPLv3 open source license. After <a href=\"https:\/\/x.com\/zherbert\/status\/2082993276324319713\">Foundation Devices forked related material<\/a>, Coinkite sought to move remaining components to a more restrictive MIT + Commons Clause arrangement that limited commercial reuse. The rewrite was large and carried complex engineering goals; it was this integration that arguably left the silent failure in the entropy path.<\/p>\n<p class=\"wp-block-paragraph\">Skepticism about the migration away from the Trezor crypto library emerged as early as <a href=\"https:\/\/t.me\/coldcard\/41148\">April 7, 2021, by a member of the Coinkite Telegram group<\/a>, who wrote: \u201cdo we really want to replace the many-years-old TrezorCrypto code that has been heavily scrutinized by white hatters like Johoe and penetration tested by wallet.fail\u201d, adding \u201cswitch may be a talented pseudonymous coder, but their commit history sucks.\u201d The criticism, however, was insufficient and quickly waved away by NVK, who criticized the Trezor library as a \u201cshitcoin shitshow.\u201d Ironically, sharing that codebase with the broader crypto market, under an open license meant that Trezor\u2019s crypto library had much deeper code review than Libngu would ever get, even years later.\u00a0<\/p>\n<h3 class=\"wp-block-heading\">Switch and Peter Gray aka Doc-Hex<\/h3>\n<p class=\"wp-block-paragraph\">The swap of cryptographic libraries that introduced the bug was pushed to the codebase by <a href=\"https:\/\/github.com\/doc-hex\" target=\"_blank\" rel=\"noopener\">Doc-Hex<\/a>, the Chief Technical Officer of Coinkite, also known as Peter D. Gray. He replaced the GPLv3 Trezor cryptography library with Libngu, a little-known codebase created by so-called \u201cSwitch\u201d, a nym that, up until the creation of Libngu, had no obvious previous history. The Switch account appeared on X on <a href=\"https:\/\/x.com\/switck\/status\/1317230987294740480\">August 3, 2019<\/a> with a mention of DEFCON, the international hacker\u2019s conference, an event normally attended by cybersecurity engineers of all kinds.\u00a0<\/p>\n<p class=\"wp-block-paragraph\">On October 16, 2020, <a href=\"https:\/\/x.com\/switck\/status\/1317230987294740480\">Switch thanked Doc-Hex on X<\/a> for merging his code; \u201cThanks for merge<a href=\"https:\/\/x.com\/DocHex\"> @DocHex<\/a> \u2026 I\u2019m making yet another bitcoin library. Could be useful on<a href=\"https:\/\/x.com\/COLDCARDwallet\"> @COLDCARDwallet<\/a> someday.\u201d A few days later, <a href=\"https:\/\/x.com\/switck\/status\/1318909664281636867\">Switch tweeted out a link to Libngu<\/a>, proud to have built a \u201cuseful thing.\u201d\u00a0\u00a0<\/p>\n<p class=\"wp-block-paragraph\">However, here is where it gets weird. According to research by Bitcoin core contributor James O\u2019Beirne, Switch and Peter D. Gray have <a href=\"https:\/\/gist.github.com\/jamesob\/ca9b4ca384969b4cfd62813419854d69\" target=\"_blank\" rel=\"noopener\">signed code commits with the same GPG keys<\/a>. O\u2019Beirne demonstrated through GPG commit signatures that dozens of commits authored as switck were signed with the personal key of Peter D. Gray, Coinkite co-founder and CTO, who also operates as DocHex. Zach Herbert also claimed that phone numbers ending in the same two digits were tied to both the DocHex and switck X accounts (<a href=\"https:\/\/x.com\/zherbert\/status\/2084647957526167853\">post<\/a>). Additional researchers pointed to matching DNS registration patterns.<\/p>\n<p class=\"wp-block-paragraph\">Neither Gray nor Coinkite has publicly addressed the GPG-signature findings as of this writing, and they did not respond when asked to comment on the topic. The Switch account is still active to this day, having merged code changes to Libngu as recently as August 17th, 2026.<\/p>\n<p>Many in the Bitcoin industry are taking this as some sort of tangential evidence of wrongdoing. Why go out of your way to create a nym just for a particular cryptography library? This has been taken as some kind of evidence of malintent; however, a deeper analysis begs to differ. Had Gray really intended to rug Coldcard users with this RNG bug, would he really have been signing commits with his personal GPG key? Could someone be so cunning that they would hide a bug for years, waiting for its adoption to spread; yet at the same time forget to create a dedicated GPG signature for the throwaway nym? I don\u2019t think that tracks.\u00a0<\/p>\n<p class=\"wp-block-paragraph\">It is more likely that this was a random identity created at DEFCON by Gray, probably in a random bout of paranoia. An identity which he continued to use for certain projects over the years. Pseudonymous identities are not unusual in Bitcoin developer circles after all. Satoshi himself remains the most famous example. And so on its own, this connection between Gray and Switch arguably does not amount to much in the hunt for the Coldcard hacker.<\/p>\n<h3 class=\"wp-block-heading\">MicroPython Contributors<\/h3>\n<p class=\"wp-block-paragraph\">A handful of other open source developers have also been recently identified as having touched or influenced code that played a role in the Coldcard RNG bug.\u00a0<\/p>\n<p class=\"wp-block-paragraph\"><a href=\"https:\/\/x.com\/LaurentMT\/status\/2086142409025409221\">Data Analyst LaurentMT<\/a> has examined the MicroPython side of the RNG path. MicroPython is a lean and open-source implementation of Python 3, designed to run on microcontrollers and resource-constrained computers. The Coldcard firmware ultimately called MicroPython\u2019s Yasmarang pseudo-random number generator (PRNG) fallback as a result of the bug, leading to low-entropy generation.\u00a0<\/p>\n<p class=\"wp-block-paragraph\">The code changes to the PRNG logic in MicroPython began on August 20, 2020, with issue (<a href=\"https:\/\/github.com\/micropython\/micropython\/issues\/6347\" target=\"_blank\" rel=\"noopener\">#6347<\/a>) opened on GitHub by a user named \u2018mirko\u2019. He complained that his ESP32 hardware was always returning the same result when calling the \u2018random.choice()\u2019 function in the code in a certain way. Mirko expected random results instead. The GitHub issue logs a discussion over the following months about the proper way to handle the related logic and expected behavior, which Mirko revealed to have a counterintuitive design.\u00a0<\/p>\n<p class=\"wp-block-paragraph\">Laurent points out that \u201crobert-hh initialized a [<a href=\"https:\/\/github.com\/micropython\/micropython\/pull\/6362\" target=\"_blank\" rel=\"noopener\">Pull Request<\/a>] implementing the PRNG seeding change\u201d on August 22, 2020. Dpgeorge, a maintainer of MicroPython, later on October 29, 2020, merged a slightly modified version of that pull request to the master repository, implementing \u201cthe (UID+SysTick+RTC) to address some limitations in robert-hh\u2019s solution.\u201d<\/p>\n<p>The changes to this critical RNG-related code were thus on the <a href=\"https:\/\/github.com\/Coldcard\/firmware\/blob\/b18723dddb6d751c39978e4364b56b2414f68b47\/.gitmodules\" target=\"_blank\" rel=\"noopener\">master repository of MicroPython when Coldcard forked it to be used by Libngu<\/a>, yet before MicroPython had made an official new version release of the library. Apparently, it is considered risky to build on top of the master version of a software repository, which is likely to be evolving with code changes, rather than build on top of an official, stable release version. The new release of MicroPython did not come until <a href=\"https:\/\/github.com\/micropython\/micropython\/releases\/tag\/v1.14\" target=\"_blank\" rel=\"noopener\">February 3, 2021, with version v1.14<\/a>. To top it off, the RNG logic change was only briefly mentioned in the release announcement, saying \u201cthe urandom module will randomize its seed on import on stm32, esp8266, esp32 and rp2 ports.\u201d\u00a0\u00a0<\/p>\n<p class=\"wp-block-paragraph\">In an interview with Bitcoin Magazine, Laurent concluded in no ambiguous terms that \u201cwithout this modification the bug in Coldcard code would have been immediately detected.\u201d Commenting on the series of events that led to the bug, he also said that \u201cthere are a lot of \u2018coincidences\u2019 in this timeline,\u201d adding that \u201cwhile they don\u2019t prove anything, I don\u2019t see how an official investigation may completely ignore them.\u201d<\/p>\n<p class=\"wp-block-paragraph\">It is important to note that there is no evidence any of the developers mentioned above were intentionally trying to introduce the Coldcard RNG bug with these changes, and ultimately, it is Coinkite, the hardware wallet company, that is responsible for their implementation of the critical code. MicroPython is a large, widely used open-source project. Nevertheless, there are likely many lessons to be learned from what we might as well call \u2014 for the time being anyway \u2014 a tragic comedy of errors.\u00a0<\/p>\n<h3 class=\"wp-block-heading\">Why an Inside Job Appears Unlikely<\/h3>\n<p class=\"wp-block-paragraph\">Several factors cut against a deliberate, long-planned insider retirement attack. The \u2018switck\u2019 identity was poorly compartmentalized; the shared GPG key and other overlaps made attribution to Doc-Hex aka Peter Gray, relatively straightforward once researchers looked. The account had been largely abandoned for years. The MicroPython contributors operate in the open on a high-visibility project.<\/p>\n<p class=\"wp-block-paragraph\"><a href=\"https:\/\/www.citadel21.com\/the-paranoid-wallet\" target=\"_blank\" rel=\"noopener\">Hodlonaut\u2019s Citadel21<\/a> investigation and other technical reviews find no clear evidence that the entropy failure was intentional. Engineer Alekos Filini\u2019s <a href=\"https:\/\/gist.github.com\/afilini\/b7d13bd2d7deaf8f23d30213a801e3c5\" target=\"_blank\" rel=\"noopener\">technical report<\/a> on the bug explicitly tracks the technical facts, stating that \u201cMy goal is to purely present facts and NOT make any conclusions.\u201d Wizardsardine detailed on their <a href=\"https:\/\/wizardsardine.com\/blog\/coldcard-vuln-deep-dive\/\" target=\"_blank\" rel=\"noopener\">Technical autopsy<\/a><strong> <\/strong>multiple failed safeguards and describes the failure as sitting \u201cacross a submodule boundary, which is precisely where reviewers stop looking.\u201d\u00a0<\/p>\n<p class=\"wp-block-paragraph\">Steven Geller\u2019s <a href=\"https:\/\/www.steven-geller.com\/2026-08-02-coldcard-had-two-hardware-rngs-its-seeds-used-neither.html\" target=\"_blank\" rel=\"noopener\">technical deep dive<\/a> on the topic did not make any strong claims either way on the matter. <a href=\"https:\/\/github.com\/DK27ss\/ColdCard-38M-PoC\" target=\"_blank\" rel=\"noopener\">DK27ss proof-of-concept reconstruction of the bug<\/a> describes the issue as \u201ca chain of four flaws, each harmless in appearance.\u201d\u00a0<\/p>\n<p class=\"wp-block-paragraph\">If the drains had been a classic insider retirement attack, or a long con as some might call it, the conversation today would be quite different. The last time we saw a major long con hack in the Bitcoin industry was probably QuadrigaCX, a centralized Canadian exchange whose founder, Gerald Cotten, was reported \u201cdead in India\u201d in 2018 amid mysterious circumstances, not long after the missing funds were discovered. The founders are accused by the <a href=\"https:\/\/www.osc.ca\/quadrigacxreport\/\" target=\"_blank\" rel=\"noopener\">Ontario Securities Commission<\/a> of having misappropriated\u00a0the exchange users\u2019 deposits totaling almost 170 million CAD, over many years, before disappearing.\u00a0<\/p>\n<p class=\"wp-block-paragraph\">Instead, Coinkite\u2019s leadership remains publicly active, responding to the incident, shipping patched firmware, assisting user migrations, and <a href=\"https:\/\/coldcard.com\/security\/status\" target=\"_blank\" rel=\"noopener\">engaging on the technical details<\/a>. Coinkite\u2019s founders and operators are fairly well known and are still operating the company as of the time of writing; they have not disappeared at the same time as the funds went missing.<\/p>\n<p class=\"wp-block-paragraph\">Meanwhile, the wave 1 funds, totaling over 1000 BTC, are still collected in three addresses, watched by hundreds of engineers and likely law enforcement such as the FBI. Were Coinkite trying to do a 5D chess-style retirement attack, they would have been far more careful in their theft of the coins. They would not have pooled them all to a handful of addresses that are easy to track, and its founders would probably be \u2018mysteriously dead in India.\u2019<\/p>\n<p>While there are no conclusions and investigations will likely be ongoing for years, so far, evidence points to a cultural failure in the Bitcoin maximalist and self-custody community, a failure to broadly educate the users and influencers about good or bad etiquette in open-source culture, and frankly, arrogance on the part of Coinkite OG\u2019s who, in hindsight, were overconfident about their own capabilities.\u00a0<\/p>\n<p>This post <a rel=\"nofollow\" href=\"https:\/\/bitcoinmagazine.com\/technical\/hunting-down-the-coldcard-hacker-wave-1-thief-may-be-known-to-fbi\">Hunting Down the Coldcard Hacker. Wave 1 Thief May Be Known to FBI<\/a> first appeared on <a rel=\"nofollow\" href=\"https:\/\/bitcoinmagazine.com\/\">Bitcoin Magazine<\/a> and is written by <a rel=\"nofollow\" href=\"https:\/\/bitcoinmagazine.com\/authors\/juan-galt\">Juan Galt<\/a>.<\/p>","protected":false},"excerpt":{"rendered":"<p>Bitcoin Magazine Hunting Down the Coldcard Hacker. Wave 1 Thief May Be Known to FBI Law enforcement may already know who emptied more than a thousand Bitcoin from Coldcard wallets in the first and largest wave of the July 2026 drains. Block\u2019s investigation believes they traced the attacker\u2019s on-chain sweeps to a paid account at [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":49705,"comment_status":"","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"_exactmetrics_skip_tracking":false,"footnotes":""},"categories":[],"tags":[],"class_list":["post-49704","post","type-post","status-publish","format-standard","has-post-thumbnail"],"yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v28.2 - https:\/\/yoast.com\/product\/yoast-seo-wordpress\/ -->\n<title>Hunting Down the Coldcard Hacker. Wave 1 Thief May Be Known to FBI - Cryptomag<\/title>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/cryptomag.finance\/?p=49704\" \/>\n<meta property=\"og:locale\" content=\"en_US\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"Hunting Down the Coldcard Hacker. Wave 1 Thief May Be Known to FBI - Cryptomag\" \/>\n<meta property=\"og:description\" content=\"Bitcoin Magazine Hunting Down the Coldcard Hacker. Wave 1 Thief May Be Known to FBI Law enforcement may already know who emptied more than a thousand Bitcoin from Coldcard wallets in the first and largest wave of the July 2026 drains. Block\u2019s investigation believes they traced the attacker\u2019s on-chain sweeps to a paid account at [&hellip;]\" \/>\n<meta property=\"og:url\" content=\"https:\/\/cryptomag.finance\/?p=49704\" \/>\n<meta property=\"og:site_name\" content=\"Cryptomag\" \/>\n<meta property=\"article:published_time\" content=\"2026-08-18T16:02:05+00:00\" \/>\n<meta property=\"og:image\" content=\"https:\/\/bitcoinmagazine.com\/wp-content\/uploads\/2026\/08\/tn-2.webp\" \/>\n<meta name=\"author\" content=\"Crypto Magazine\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:creator\" content=\"@cryptomagz\" \/>\n<meta name=\"twitter:site\" content=\"@cryptomagz\" \/>\n<meta name=\"twitter:label1\" content=\"Written by\" \/>\n\t<meta name=\"twitter:data1\" content=\"Crypto Magazine\" \/>\n\t<meta name=\"twitter:label2\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data2\" content=\"13 minutes\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\\\/\\\/schema.org\",\"@graph\":[{\"@type\":\"Article\",\"@id\":\"https:\\\/\\\/cryptomag.finance\\\/?p=49704#article\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/cryptomag.finance\\\/?p=49704\"},\"author\":{\"name\":\"Crypto Magazine\",\"@id\":\"https:\\\/\\\/cryptomag.finance\\\/#\\\/schema\\\/person\\\/f749cd846c4f13ef717c12a20ce9d040\"},\"headline\":\"Hunting Down the Coldcard Hacker. Wave 1 Thief May Be Known to FBI\",\"datePublished\":\"2026-08-18T16:02:05+00:00\",\"mainEntityOfPage\":{\"@id\":\"https:\\\/\\\/cryptomag.finance\\\/?p=49704\"},\"wordCount\":2576,\"image\":{\"@id\":\"https:\\\/\\\/cryptomag.finance\\\/?p=49704#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/cryptomag.finance\\\/wp-content\\\/uploads\\\/tn-2-vkCQfu.webp\",\"inLanguage\":\"en-US\"},{\"@type\":\"WebPage\",\"@id\":\"https:\\\/\\\/cryptomag.finance\\\/?p=49704\",\"url\":\"https:\\\/\\\/cryptomag.finance\\\/?p=49704\",\"name\":\"Hunting Down the Coldcard Hacker. Wave 1 Thief May Be Known to FBI - Cryptomag\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/cryptomag.finance\\\/#website\"},\"primaryImageOfPage\":{\"@id\":\"https:\\\/\\\/cryptomag.finance\\\/?p=49704#primaryimage\"},\"image\":{\"@id\":\"https:\\\/\\\/cryptomag.finance\\\/?p=49704#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/cryptomag.finance\\\/wp-content\\\/uploads\\\/tn-2-vkCQfu.webp\",\"datePublished\":\"2026-08-18T16:02:05+00:00\",\"author\":{\"@id\":\"https:\\\/\\\/cryptomag.finance\\\/#\\\/schema\\\/person\\\/f749cd846c4f13ef717c12a20ce9d040\"},\"breadcrumb\":{\"@id\":\"https:\\\/\\\/cryptomag.finance\\\/?p=49704#breadcrumb\"},\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\\\/\\\/cryptomag.finance\\\/?p=49704\"]}]},{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/cryptomag.finance\\\/?p=49704#primaryimage\",\"url\":\"https:\\\/\\\/cryptomag.finance\\\/wp-content\\\/uploads\\\/tn-2-vkCQfu.webp\",\"contentUrl\":\"https:\\\/\\\/cryptomag.finance\\\/wp-content\\\/uploads\\\/tn-2-vkCQfu.webp\",\"width\":1200,\"height\":630},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\\\/\\\/cryptomag.finance\\\/?p=49704#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\\\/\\\/cryptomag.finance\\\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"Hunting Down the Coldcard Hacker. Wave 1 Thief May Be Known to FBI\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\\\/\\\/cryptomag.finance\\\/#website\",\"url\":\"https:\\\/\\\/cryptomag.finance\\\/\",\"name\":\"Cryptomag\",\"description\":\"\",\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\\\/\\\/cryptomag.finance\\\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"en-US\"},{\"@type\":\"Person\",\"@id\":\"https:\\\/\\\/cryptomag.finance\\\/#\\\/schema\\\/person\\\/f749cd846c4f13ef717c12a20ce9d040\",\"name\":\"Crypto Magazine\",\"image\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/2c24e7a3322cdb9140c7dde381c870ae2c527e0dc5af67ed7a7db042bb2e1d14?s=96&d=mm&r=g\",\"url\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/2c24e7a3322cdb9140c7dde381c870ae2c527e0dc5af67ed7a7db042bb2e1d14?s=96&d=mm&r=g\",\"contentUrl\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/2c24e7a3322cdb9140c7dde381c870ae2c527e0dc5af67ed7a7db042bb2e1d14?s=96&d=mm&r=g\",\"caption\":\"Crypto Magazine\"},\"sameAs\":[\"https:\\\/\\\/cryptomag.finance\",\"https:\\\/\\\/x.com\\\/cryptomagz\"],\"url\":\"https:\\\/\\\/cryptomag.finance\\\/?author=1\"}]}<\/script>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"title":"Hunting Down the Coldcard Hacker. Wave 1 Thief May Be Known to FBI - Cryptomag","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/cryptomag.finance\/?p=49704","og_locale":"en_US","og_type":"article","og_title":"Hunting Down the Coldcard Hacker. Wave 1 Thief May Be Known to FBI - Cryptomag","og_description":"Bitcoin Magazine Hunting Down the Coldcard Hacker. Wave 1 Thief May Be Known to FBI Law enforcement may already know who emptied more than a thousand Bitcoin from Coldcard wallets in the first and largest wave of the July 2026 drains. Block\u2019s investigation believes they traced the attacker\u2019s on-chain sweeps to a paid account at [&hellip;]","og_url":"https:\/\/cryptomag.finance\/?p=49704","og_site_name":"Cryptomag","article_published_time":"2026-08-18T16:02:05+00:00","og_image":[{"url":"https:\/\/bitcoinmagazine.com\/wp-content\/uploads\/2026\/08\/tn-2.webp","type":"","width":"","height":""}],"author":"Crypto Magazine","twitter_card":"summary_large_image","twitter_creator":"@cryptomagz","twitter_site":"@cryptomagz","twitter_misc":{"Written by":"Crypto Magazine","Est. reading time":"13 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"Article","@id":"https:\/\/cryptomag.finance\/?p=49704#article","isPartOf":{"@id":"https:\/\/cryptomag.finance\/?p=49704"},"author":{"name":"Crypto Magazine","@id":"https:\/\/cryptomag.finance\/#\/schema\/person\/f749cd846c4f13ef717c12a20ce9d040"},"headline":"Hunting Down the Coldcard Hacker. Wave 1 Thief May Be Known to FBI","datePublished":"2026-08-18T16:02:05+00:00","mainEntityOfPage":{"@id":"https:\/\/cryptomag.finance\/?p=49704"},"wordCount":2576,"image":{"@id":"https:\/\/cryptomag.finance\/?p=49704#primaryimage"},"thumbnailUrl":"https:\/\/cryptomag.finance\/wp-content\/uploads\/tn-2-vkCQfu.webp","inLanguage":"en-US"},{"@type":"WebPage","@id":"https:\/\/cryptomag.finance\/?p=49704","url":"https:\/\/cryptomag.finance\/?p=49704","name":"Hunting Down the Coldcard Hacker. Wave 1 Thief May Be Known to FBI - Cryptomag","isPartOf":{"@id":"https:\/\/cryptomag.finance\/#website"},"primaryImageOfPage":{"@id":"https:\/\/cryptomag.finance\/?p=49704#primaryimage"},"image":{"@id":"https:\/\/cryptomag.finance\/?p=49704#primaryimage"},"thumbnailUrl":"https:\/\/cryptomag.finance\/wp-content\/uploads\/tn-2-vkCQfu.webp","datePublished":"2026-08-18T16:02:05+00:00","author":{"@id":"https:\/\/cryptomag.finance\/#\/schema\/person\/f749cd846c4f13ef717c12a20ce9d040"},"breadcrumb":{"@id":"https:\/\/cryptomag.finance\/?p=49704#breadcrumb"},"inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":["https:\/\/cryptomag.finance\/?p=49704"]}]},{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/cryptomag.finance\/?p=49704#primaryimage","url":"https:\/\/cryptomag.finance\/wp-content\/uploads\/tn-2-vkCQfu.webp","contentUrl":"https:\/\/cryptomag.finance\/wp-content\/uploads\/tn-2-vkCQfu.webp","width":1200,"height":630},{"@type":"BreadcrumbList","@id":"https:\/\/cryptomag.finance\/?p=49704#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/cryptomag.finance\/"},{"@type":"ListItem","position":2,"name":"Hunting Down the Coldcard Hacker. Wave 1 Thief May Be Known to FBI"}]},{"@type":"WebSite","@id":"https:\/\/cryptomag.finance\/#website","url":"https:\/\/cryptomag.finance\/","name":"Cryptomag","description":"","potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/cryptomag.finance\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"en-US"},{"@type":"Person","@id":"https:\/\/cryptomag.finance\/#\/schema\/person\/f749cd846c4f13ef717c12a20ce9d040","name":"Crypto Magazine","image":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/secure.gravatar.com\/avatar\/2c24e7a3322cdb9140c7dde381c870ae2c527e0dc5af67ed7a7db042bb2e1d14?s=96&d=mm&r=g","url":"https:\/\/secure.gravatar.com\/avatar\/2c24e7a3322cdb9140c7dde381c870ae2c527e0dc5af67ed7a7db042bb2e1d14?s=96&d=mm&r=g","contentUrl":"https:\/\/secure.gravatar.com\/avatar\/2c24e7a3322cdb9140c7dde381c870ae2c527e0dc5af67ed7a7db042bb2e1d14?s=96&d=mm&r=g","caption":"Crypto Magazine"},"sameAs":["https:\/\/cryptomag.finance","https:\/\/x.com\/cryptomagz"],"url":"https:\/\/cryptomag.finance\/?author=1"}]}},"_links":{"self":[{"href":"https:\/\/cryptomag.finance\/index.php?rest_route=\/wp\/v2\/posts\/49704","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/cryptomag.finance\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/cryptomag.finance\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/cryptomag.finance\/index.php?rest_route=\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/cryptomag.finance\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=49704"}],"version-history":[{"count":0,"href":"https:\/\/cryptomag.finance\/index.php?rest_route=\/wp\/v2\/posts\/49704\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/cryptomag.finance\/index.php?rest_route=\/wp\/v2\/media\/49705"}],"wp:attachment":[{"href":"https:\/\/cryptomag.finance\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=49704"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/cryptomag.finance\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=49704"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/cryptomag.finance\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=49704"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}