Hunting Down the Coldcard Hacker: Wave 1 Thief May Be Known to the FBI

The Bitcoin behind the largest Coldcard theft hasn’t moved a single satoshi since it was stolen. That stillness may be exactly what’s about to expose who took it.
On July 30, an attacker began systematically draining Bitcoin from wallets generated using vulnerable Coldcard hardware wallet firmware, a flaw that went undetected for years. The first and largest wave alone moved 1,082.65 BTC, and across multiple subsequent waves, confirmed and estimated losses now exceed 1,800 BTC pulled from more than 5,000 addresses, worth roughly $118 million at the time funds were taken. None of the first wave’s Bitcoin has surfaced at an exchange or a mixing service since.
Galaxy Research’s Alex Thorn has been tracking the theft through on-chain pattern analysis combined with voluntary reports from affected victims, and has said the identity of the first wave’s attacker may already be known to law enforcement. A separate lead reported by Bitcoin Magazine points to an unusual pattern in the attacker’s sweeps: the operator appears to have used a paid account at a well-known blockchain-data provider to query source addresses, and that provider’s internal logs reportedly matched the suspected workflow with unusual specificity, including the exact number, timing, and sequence of requests made.
The FBI has not publicly confirmed identifying a suspect, opening a case, making an arrest, or recovering any of the stolen funds, an important distinction from an identity merely being “known” to investigators. Establishing who actually operated the paid account, who controls the receiving wallets, and whether the evidence clears the bar for criminal charges are all separate steps that haven’t been confirmed as complete.
Later, smaller waves of the same firmware exploit show different operational patterns than the first, faster opportunistic drains followed by quick laundering, suggesting other actors independently found and exploited the same vulnerability after it became public rather than all activity tracing back to one operator.
Want to understand how investigators trace stolen Bitcoin through blockchain-data providers? Learn more in the Bitcoin Academy.
