FBI · Bitcoin · YouTube · Bitcoin Magazine
Wave 1 Thief May Be Known to FBI
Compiled by KHAO Editorial — aggregated from 1 source. See llms.txt for citation guidance.
◌ Single Source
Law enforcement may already know who emptied more than a thousand Bitcoin from Coldcard wallets in the first and largest wave of the July 2026 drains.
Key facts
- The new release of MicroPython did not come until February 3, 2021, with version v1.14
- The code changes to the PRNG logic in MicroPython began on August 20, 2020, with issue ( #6347 ) opened on GitHub by a user named ‘mirko
- Laurent points out that “robert-hh initialized a [ Pull Request ] implementing the PRNG seeding change” on August 22, 2020
- On October 16, 2020, Switch thanked Doc-Hex on X for merging his code; “Thanks for merge … the reporter is making yet another bitcoin library
Summary
The coins from that wave— 1,082.65 BTC —still sit untouched in the attacker’s address, leaving hope that a clawback may be possible to the victims and rightful owners of that first wave of stolen bitcoin. On July 30, 2026, an attacker began systematically draining Bitcoin from Coldcard hardware wallets that had generated seeds under vulnerable firmware, a bug that was undiscovered for years. As of early August, confirmed and estimated losses across multiple waves exceeded 1,800 BTC from more than 5,000 addresses, though exact final totals continue to be refined as new reports arrive. Thorn has publicly discussed the possibility that law enforcement already holds a concrete lead on the operator behind the largest tranche.