00:00
The Financial Ways
The Financial Ways
USD/RUB
EUR/RUB
Cryptocurrency

FBI May Hold Digital Trail to $69 Million Coldcard Theft

Investigators have reportedly uncovered a link between the initial wave of the Coldcard wallet thefts and a paid blockchain data account, potentially providing U.S. authorities with the information needed to identify the perpetrator behind the $69 million in Bitcoin that vanished during the attack.

FBI May Hold Digital Trail to $69 Million Coldcard Theft

Block engineering lead Clay Garrett confirmed that his team identified an unusual pattern in the attacker’s on-chain activity. By tracing the sweep of 1,082.65 BTC, investigators discovered that the perpetrator utilized a paid account at a third-party blockchain data provider to query source addresses. Internal logs from this provider matched the timing and sequence of the thefts with high precision, and this data has been turned over to federal authorities.

While Galaxy Research’s Alex Thorn suggested that the identity of the first-wave attacker may be known to law enforcement, the FBI has not publicly confirmed an arrest, indictment, or the recovery of any stolen assets. The stolen funds remain unmoved at their original addresses, and because Bitcoin transactions are irreversible, their recovery depends entirely on law enforcement intervention or the voluntary return of the private keys. The breach, which stems from a flaw in seed generation across various Coldcard firmware versions, has resulted in at least 1,700 BTC in total losses. Experts warn that because later theft waves exhibited different patterns, multiple actors may have exploited the vulnerability, meaning the identification of the first attacker will not necessarily resolve the entire case. Users of affected Mk2, Mk3, and Mk4 devices are urged to migrate funds to newly generated wallets, as firmware updates alone cannot secure seeds created with inadequate entropy.

Share

Comments (0)

Leave a comment

No comments yet. Be the first!