Crypto Times Logo Black
Google News Follow Banner
  • News
    • Market
    • Bitcoin
    • Ethereum
    • Altcoins
    • Regulations & Policies
    • DeFi News
    • Blockchain News
    • Industry
  • Exclusive
    ExclusiveShow More
    Binance Account Rental Scam: How Fraudsters Lure Crypto Users with Promises of Easy Money
    Binance Account Rental Scam: How Fraudsters Lure Crypto Users with Promises of Easy Money
    80% of Major SpaceX Investors Deal With Crypto
    80% of Major SpaceX Investors Deal With Crypto
    SEC Cancels Crypto Meeting Why Rulemaking Just Hit Another Wall
    SEC Cancels Crypto Meeting: Why Rulemaking Just Hit Another Wall
    Internet Computer (ICP) Tops Blockchain Transactions Chart: Here’s What It's Actually Doing
    Internet Computer (ICP) Tops Blockchain Transactions Chart: Here’s What It’s Actually Doing
    Ethereum’s Staking War Why EIP-8361 Has DeFi Leaders Fighting Back
    Ethereum’s Staking War: Why EIP-8361 Has DeFi Leaders Fighting Back
  • Opinion
    OpinionShow More
    The Architecture of Trust Same Routes, New Risks in Global Tokenisation
    The Architecture of Trust: Same Routes, New Risks in Global Tokenisation
    The Architecture of Trust What 4,000 Years of Trade Teach Us About RWA Tokenisation
    The Architecture of Trust: What 4,000 Years of Trade Teach Us About RWA Tokenisation
    One P2P Trade, Months of Limbo Why Innocent Indian Crypto Users Keep Paying the Price
    One P2P Trade, Months of Limbo: Why Innocent Indian Crypto Users Keep Paying the Price
    CLARITY Act The Bill Exists, the Deal Does Not, Trump Has to Wait
    CLARITY Act: The Bill Exists, the Deal Does Not, Trump Has to Wait
    The Execution Gap: Why the Next Breakthrough in Financial AI is Human Behavior
    The Execution Gap: Why the Next Breakthrough in Financial AI is Human Behavior
  • Learn
    • Explained
    • How To
    • Insights
  • Videos
  • More
    • About Us
    • Our Authors
    • Contact Us
    • Editorial Policy
The Crypto TimesThe Crypto Times
  • All News
  • Market
  • Bitcoin
  • Ethereum
  • Altcoins
  • Regulations & Policies
  • Blockchain
  • DeFi
  • Industry
  • Exclusive
  • Opinion
Search
  • News
    • Market
    • Bitcoin
    • Ethereum
    • Altcoins
    • Regulations & Policies
    • Blockchain
    • DeFi
    • Industry
    • Exclusive
    • Opinion
  • Learn
    • Explained
    • How To
    • Insights
  • Quick Links
    • About Us
    • Our Authors
    • Contact Us
    • Editorial Policy
    • AI Policy
    • Sponsored & Advertorial Policy
  • Videos
  • Glossary
Follow US
© 2026 By Crypto Times. All Rights Reserved.
Bitcoin News

Block and Galaxy Research Give Lead to Law Enforcement in $112M Coldcard Bitcoin Theft

Fresh reports note that Block’s engineering team traced unusual on-chain activity patterns from the first wave to a paid account at a major blockchain data services provider.

Written By Gopal Solanky
Edited by Divya Mistry
Published 1 hour ago·Updated 19 minutes ago
Make The Crypto Times preferred on GoogleGoogle
Block and Galaxy Research Give Lead to Law Enforcement in $111M Coldcard Bitcoin Theft

Investigations into a major series of Bitcoin thefts from Coldcard hardware wallets have advanced to the point where law enforcement agencies may already possess identifying information on the operator behind the largest initial wave of drains. 

Fresh reports note that Block’s engineering team traced unusual on-chain activity patterns from the first wave to a paid account at a major blockchain data services provider. The provider’s internal logs matched the number, timing, and sequence of the attacker’s queries with extraordinary specificity, according to public statements by Clay Garrett, engineering lead for Block’s Bitkey. 

AI Summary
Show
Coldcard seed‑generation flaw exposes hardware‑wallet industry’s reliance on firmware integrity, prompting sector‑wide security audits.
Law enforcement leveraging blockchain analytics sets precedent for tracking crypto thefts, enhancing regulatory cooperation.
Over $112 million stolen highlights need for mandatory entropy standards in wallet seed generation across crypto ecosystem.

As first reported by Bitcoin Magazine, Block contacted the provider, confirmed the match, found no evidence the provider knowingly participated, and shared the relevant information with appropriate authorities.

Galaxy Research has similarly provided lists of attacker-controlled addresses to law enforcement agencies, compliance firms, and exchanges in hopes of freezing any funds that reach centralized platforms. As of mid-August 2026, the bulk of stolen bitcoin remains largely unmoved.

The thefts, which began on July 30, 2026, exploited a long-standing defect in how certain Coldcard devices generated wallet seeds. Confirmed losses stand at least at 1,778.84 BTC (approximately a little over $112 million at then-prevailing prices) across more than 8,600 addresses, based on direct reports from 190 victims to Galaxy Research. Additional medium-confidence activity could push the total higher. 

According to a July 31 public statement by Clay Garrett, Engineering Lead for Bitkey at Block, the company’s Bitcoin engineering and security teams identified an unusual pattern in the on-chain sweeps during their investigation of the first wave of Coldcard drains. That pattern led them to a confirmed hypothesis that the operator had used a paid account at a well-known blockchain-services provider to query the source addresses and carry out related activity. 

Block contacted the provider directly and found that its internal logs matched the suspected workflow with extraordinary specificity, including the number, timing, and sequence of requests. Garrett stated that the provider was supplying only its standard services and that Block had seen no evidence the company knowingly participated in or facilitated the theft. The relevant information has been shared with the appropriate authorities, with further updates to be provided only when doing so will not interfere with the ongoing investigation. 

Origins of the Firmware Defect

The root cause of the Coldcard exploit was a seed-generation defect introduced during a March 2021 firmware change. Coinkite, the Canadian manufacturer of Coldcard, has confirmed on its official security status page that a defect affected releases beginning with firmware version 4.0.1. The intended path used the device’s dedicated hardware true random number generator (TRNG) on the STM32 chip. Instead, due to a build-configuration and symbol-resolution issue involving the libngu library and the MicroPython software, seed generation resolved to a weak software pseudorandom number generator.

According to Coinkite’s historical disclosure records, the change occurred during the 2021 libNgU migration. The macro MICROPY_HW_ENABLE_RNG was defined as zero, which excluded the hardware path, while a library guard that checked only for the macro’s existence (rather than its value) failed to catch the error. The result was seeds with far lower entropy than the designed 128 bits: approximately 40 bits on affected Mk2 and Mk3 devices and around 72 bits on Mk4, Mk5, and Q models.

Independent technical analysis of the open-source firmware, including a public proof-of-concept repository examining the commit history, corroborates that the March 1, 2021 commit shifted the call from the hardware RNG function to the libngu path, collapsing the effective search space enough for computational regeneration of private keys matching on-chain addresses. No physical access to devices was required. Fixed firmware versions (Mk2/Mk3 4.2.0 or later; Mk4/Mk5 5.6.0 or later; Q 1.5.0Q or later, and corresponding Edge builds) correct future seed generation but do not repair existing affected seeds.

Coinkite has stated that updating the device alone is insufficient; users must migrate funds to new seeds generated under the corrected firmware, preferably with additional entropy such as dice rolls.

Timeline and Scale of the Thefts

As timely reported by The Crypto Times, attackers began systematically regenerating candidate seeds and sweeping funds on July 30, 2026. The first and largest wave drained approximately 1,082 BTC from more than 1,000 addresses within a roughly 41-minute window. Subsequent waves followed in the ensuing days, with Galaxy Research identifying multiple distinct attacker footprints—initially a handful of coordinated operators, later estimated at least 15 separate actors exploiting the same weakness independently.

By August 14, 2026, Galaxy Research reported high-confidence confirmation of 1,778.84 BTC stolen, with no verified attacker activity after August 6. Of the confirmed total, roughly 1,531 BTC remained unmoved in attacker addresses. A portion of the moved funds entered CoinJoin mixing or continued through peel-chain transactions, while a small amount reached exchanges or bridges.

Galaxy Research noted that victims were predominantly retail Bitcoin holders using single-signature Coldcard setups for long-term cold storage. No confirmed losses from properly implemented multisignature wallets were reported in their analysis.

Ongoing Investigations and User Guidance

Block’s identification of the paid blockchain data provider account represents the clearest public lead linking specific operational behavior to the first-wave operator. Galaxy Research head of research Alex Thorn has noted in discussions that the Wave 1 attacker’s identity may already be known to law enforcement as a result of such investigative work. Both firms have coordinated with authorities and the broader community to attribute losses and track funds.

Coinkite’s official guidance remains clear: any seed generated on affected firmware should be treated as compromised unless at least 50 fair, independent private dice rolls were used during creation (providing the intended entropy). Users are directed to install verified fixed firmware, generate a new seed, and carefully migrate funds following the company’s published migration process. Coinkite has also adjusted its customer data-retention practices in light of potential legal proceedings.

The incident underscores the critical importance of robust entropy in key generation and the limits of relying solely on hardware isolation. While the active exploitation phase appears to have abated, residual risk persists for any unmigrated affected seeds. Authorities continue to work with the information shared by researchers, leaving open the possibility of further developments regarding recovery of the still-largely-unmoved first-wave funds.

Also read: Maya Protocol Hit by $1.7M Exploit in First Major Breach Since 2023

Disclaimer: The information researched and reported by The Crypto Times is for informational purposes only and is not a substitute for professional financial advice. Investing in crypto assets involves significant risk due to market volatility. Always Do Your Own Research (DYOR) and consult with a qualified Financial Advisor before making any investment decisions.

Follow The Crypto Times on Google News to Stay Updated!      Google News

TAGGED:BlockchainCrypto Hack
Share This Article
Whatsapp Whatsapp LinkedIn Telegram Copy Link

Latest News

India Arrests 13 Over Fake Apple Support Crypto Scam
India Arrests 13 Over Fake Apple Support Crypto Scam
Chinese Nasdaq Firm Zhibao Just Bought 2,380 Bitcoin in $154.7M Deal
Chinese Nasdaq Firm Zhibao Just Bought 2,380 Bitcoin in $154.7M Deal
SpaceX Faces 319M-Share Unlock After Reclaiming $135 IPO Price
SpaceX (SPCX) Faces 319M Share Unlock After Reclaiming $135 IPO Price 
Cathie Wood's ARK Buys $1.34M in Block, $899K in Cloudflare as Fintech Bet Grows
Cathie Wood’s ARK Buys $1.34M in Block, $899K in Cloudflare as Fintech Bet Grows
Bitcoin Nears Potential Accumulation Phase as 8 of 12 Capitulation Signals Hit
Bitcoin Nears Potential Accumulation Phase as 8 of 12 Capitulation Signals Hit

Find Us on Socials

You may also like

Maya Protocol Hit by $1.7M Exploit in First Major Breach Since 2023

Maya Protocol Hit by $1.7M Exploit in First Major Breach Since 2023

Metaplanet Commits 2,100 BTC & $2.5M to Form Nasdaq-Listed Superplanet 

Metaplanet Commits 2,100 BTC & $2.5M to Form Nasdaq-Listed Superplanet 

Bitcoin Price Diverges from Global M2 Growth as Analysts Examine the Gap

Bitcoin Price Diverges from Global M2 Growth as Analysts Examine the Gap

Strive Adds 79 BTC, Bitcoin Holdings Reach 20,246

Strive Adds 79 BTC, Bitcoin Holdings Reach 20,246

The Crypto Times Logo PNG

Providing real-time, accurate Crypto reporting. Your trusted source for Crypto News and Research.

Stay Updated

All News
Exclusive
Opinions
Learn
Videos
Glossary

Company

About Us
Our Authors
Editorial Policy
AI Policy
Advertorial Policy

Get In Touch

Contact Us
Career

Find Us on Socials

X-twitter Linkedin Telegram Youtube Instagram

© 2026 The Crypto Times | A BITROCK TECHNOLOGIES L.L.C. Company.

DMCA.com Protection Status
  • Terms and Conditions
  • Disclaimer
  • Privacy Policy
  • Cookie policy
Do Not Sell or Share My Personal Information