New developments have occurred in the investigation surrounding the theft of Coldcard's hardware wallet in July 2026. Bitcoin media quoted information that the United States Federal Bureau of Investigation (FBI) might have identified the perpetrators of the first attack. The case had previously resulted in the theft of 1082.65 bitcoin, amounting to approximately US$ 11.8 million of the text.

The scale of stolen funds is clear.

The incident was one of the cases of greater interest in the area of encryption security in July because of the large size of the assets affected and the fact that they were targeted at security incidents related to the hardware wallet. Available information indicates that the focus of the investigation was on the first route of the attack and on the chain traces of the transfer of stolen funds.

  • Number of stolen: 1082.65 BTC
  • Reference amount: approximately $11.8 million
  • Target: First round of attackers

The service log on the chain became the clue.

It was reported that Block and Galaxy Research were involved in the investigation. Two agencies found that the attackers had used a paid block chain data service provider when moving stolen bitcoin. The investigators believe that the internal log records of the service provider, which correspond to the pattern of operations of the attackers, constitute one of the important clues to identification.

This means that while the attackers try to conceal the path through the transfer of funds through the chain, the use of external data tools may leave a comparable record of behaviour. For law enforcement authorities, secondary data that are not part of the chain often help to narrow the scope of clearance.

The rest of the wave is still being tracked.

The progress currently disclosed was mainly directed at the first attacker, while other attacks associated with the Coldcard incident were still being tracked. This means that the overall investigation of the case has not yet been completed and that it cannot be considered at this stage that all the individuals involved have been targeted.

From the information made publicly available, the focus of the follow-up to this case remains on the tracking of the remaining funds and on whether there is a link between the different attacks and the same organization or concerted action.