Engineers at Block say they traced the operator behind the first wave of the Coldcard hack, the one that carried off 1,082.65 BTC. The attacker queried the target addresses from a paid account at a blockchain data provider before sweeping them. That provider’s internal logs line up with the theft timeline in unusual detail. The coins from that first wave have still not moved.
Key Takeaways
- The first wave took 1,082.65 BTC, roughly $70M at the time of the theft.
- A paid account at a data provider left a usable trail of queries.
- That wave’s coins sit on three watched addresses, which keeps a court-ordered clawback on the table.
A Paid Account Left the Prep Work Visible
Clay Garrett runs engineering on the Bitkey wallet at Block, the listed company Jack Dorsey founded. He laid out the workflow in the thread he posted from his own account the day after the sweeps began. The operator had opened a paid account at a widely used blockchain data provider and leaned on it to query source addresses before draining them.
Block went to the provider directly. The internal logs it pulled back match the suspected workflow down to the count, timing and sequence of queries. The provider itself was doing nothing unusual, and none of the incoming requests carried anything that would have exposed their purpose.
That detail changes what kind of case this is. The theft itself left nothing usable behind, since the $70M that vanished in 41 minutes on July 30 never required physical access to a single device. The mistake sits in the preparation, not the execution.
Block says it handed the material to the relevant authorities. No name has been made public so far, no charges have been announced, no seizure has been confirmed. Read the word identification carefully here, because it is doing a lot of work for very little confirmed fact.
Still, the finding moves the whole file. For three weeks the Coldcard hack read as a pure cryptography problem, run by someone methodical and invisible. It now reads as an ordinary investigation, with a billable customer, a payment trail and a third party holding the connection history.
The 1,082 Coins Are Parked on Three Watched Addresses
The first wave accounts for 1,082.65 BTC, close to $70M on the day it happened. Those funds sit across three addresses that have recorded no movement since. The stillness is exactly what makes the case workable for investigators. Untouched coins mean the operator has not yet found a route out that they trust, and every week of inaction narrows the options further.
The second wave took only 76 BTC, and every wave combined now exceeds 1,800 BTC spread over more than 5,000 addresses, worth about $118M. We already covered the path where the final bill climbs past $151 million, and the counter has not settled yet.
The split between waves matters more than the totals. Coins from the later waves have already started moving, which cuts the odds of getting them back. The first wave stays seizable for as long as it sits still.
Set against the month’s other incidents, the contrast is sharp. The leak that exposed 13,689 Trezor buyers through its shipper hit customer records, not keys. Here the key itself was reconstructible, which puts the Coldcard hack in a category of its own.
A clawback still needs several conditions to land at once. It takes a court with jurisdiction, a holder someone can actually reach, and funds that are still frozen on the day the ruling comes down. The three addresses tick the last box today, and that is the only one investigators have any grip on.
Also on Cryptonomic:
- Bitcoin Jumps to $69,749 as Treasury Doubles Bond Buybacks
- Polymarket Blocked in South Korea Over Gambling
- SEC Proposal Opens $75M Token Sales Each Year
A Software Generator Slipped Into the Firmware in March 2021
The technical root traces back to a firmware build dated March 2021. From that release on, the device pulled its randomness from a predictable software generator instead of the secure hardware generator sitting inside the STM32 microcontroller. The shape of the failure is not new either, since the BTCPay Server flaw that drained Lightning nodes also came down to a software defect nobody spotted for months.
The damage shows up in entropy bits. Older models landed near 40 bits and newer ones near 72, when a properly generated recovery phrase has to stay far outside computational reach. A 40-bit seed becomes enumerable, and that is precisely what happened here.
An entropy bug has the particular quality of producing no visible symptom until someone goes looking. Devices keep signing, transactions confirm, backups restore, and the weakness only surfaces when an attacker decides to rebuild keys from the same defect.
For holders, the operational lesson is about verification rather than branding. A device with a serious reputation shipped keys built on thin randomness for more than four years, and the market never noticed. The Coldcard hack invented nothing, it simply walked through a window that stayed open too long.
The market has already answered in its own way. The concentration that pushed 90 wallets past 10,000 BTC shows where custody drifts once confidence in a consumer model cracks. What comes next depends on what the authorities do with the logs Block handed over.
Follow the story on Cryptonomic.


