Crypto Prices

Investigation Progresses on Coldcard Theft: FBI Might Identify Initial 1,082 BTC Hacker

6 hours ago
2 mins read
5 views

Investigation into Coldcard Bitcoin Thefts

Recent reports indicate that investigators may have provided U.S. law enforcement with potentially crucial details for identifying the individual behind the initial wave of Coldcards Bitcoin thefts. Alex Thorn from Galaxy Research suggested that the identity of the attacker could possibly be in the hands of the FBI, although the bureau has yet to publicly verify this or make any official arrests related to the case.

The Impact of the Thefts

This first theft wave resulted in the loss of 1,082.65 BTC, drawn from wallets created with a compromised version of Coldcard firmware. With Bitcoin trading around $64,000, the value of the stolen coins is estimated to be close to $69 million instead of the previously reported $11.8 million.

Investigation Findings

Investigations led by Clay Garrett from Block Engineering revealed an unusual anomaly in the transaction patterns associated with the suspect’s activities. They discovered that the attacker appeared to have used a paid subscription from a blockchain data service to pinpoint and manipulate source addresses. By contacting the service provider, investigators matched the specifics of these queries—timing and sequence—to the purported thefts with remarkable accuracy.

Although Block Engineering shared pertinent findings with law enforcement, there remains no publicly available documentation, such as indictments or seizure filings, to substantiate claims against a particular individual.

Thorn’s cautious phrasing emphasizes that while a person’s identity may be known, this does not equate to having a confirmed suspect. Investigators still need to verify who operated the account, established ownership of the receiving wallets, and determine if enough evidence exists to file charges.

Status of the Stolen Funds

The funds from the initial theft still sit at various addresses, and they have not moved to any identifiable exchanges or mixers, thus remaining elusive. As previously highlighted in crypto.news, the stolen coins are not technically frozen since Bitcoin transactions cannot be undone at the protocol level. Any recovery would necessitate either access to private keys or cooperation for a lawful seizure.

Subsequent Thefts and Vulnerabilities

Galaxy Research’s findings suggest that at least 1,700 BTC have been lost across subsequent thefts, with a higher number reported based on differing methodologies by researchers. This divergence indicates that multiple actors may have exploited the identified vulnerabilities after they became public knowledge.

In line with earlier assessments of the incident, crypto.news noted that the theft resulted from weaknesses in seed generation and not from breaches to the Bitcoin protocol or physical device access. An advisory from Coinkite confirmed that flaws in firmware versions starting from 4.0.1 led to the generation of seeds lacking sufficient entropy.

Mitigation and Future Considerations

To mitigate these risks, updated firmware has now corrected the seed generation issues, though existing vulnerable seeds require users to generate entirely new ones and transfer their assets following verification of a test transaction. Coinkite is still conducting a formal technical review of the incident, while also facilitating independent checks.

This scenario has ignited discussions regarding the necessity for third-party audits of hardware wallets, as the future hinges on authorities successfully linking the suspect account to an individual and whether any remaining stolen funds will be recovered.

With questions surrounding the potential for court records to ultimately reflect an ongoing investigation, the outcome of this incident remains to be seen.

Popular