FBI May Be Closing In on Attackers in Coldcard Theft: 1,082 BTC Stolen
The FBI may have identified the first wave of attackers in the Coldcard theft; as the investigation, supported by Block’s data provider logs, tracks the loss of 1,082.65 BTC, warnings have been issued regarding the libngu vulnerability and new attack waves.
According to information reported by Bitcoin Magazine, the FBI may have identified the perpetrators of the first wave of attacks targeting Coldcard hardware wallets in July 2026. The claim is based on investigations conducted by Block and Galaxy Research. However, this development does not mean the identity of the attackers has been finalized.
In the first and largest wave of attacks, 1,082.65 Bitcoin (BTC) was stolen from wallets. The value of the stolen assets was calculated to be approximately $11.8 million. Block’s investigation revealed that the attackers used a paid blockchain data provider’s account while conducting on-chain transfers. The provider’s internal logs matched the attackers’ request patterns with extraordinary precision.
Funds stolen in the Coldcard attack have still not been moved
The Bitcoin from this wave of attacks remains in the attackers’ addresses and untouched. This leaves a possibility for the stolen assets to be returned to victims and their rightful owners. Authorities continue to track multiple waves of attacks. Therefore, the FBI’s potential identification does not mean the risk has ended for Coldcard users.
At the root of the problem is the libngu library, which was added to the system in 2021. It is stated that the library created a vulnerability in the random number generation (RNG) mechanism that generates private keys, potentially leading to the compromise of keys on numerous devices. According to the warning, the risk covers devices as old as the MK2 and firmware versions 4.0.1 and above. Coldcard users are urged to check their devices and move any funds that may be at risk without delay.