FBI identified attackers behind July 2026 Coldcard hardware wallet exploit that stole 1,082.65 BTC ($11.8M) via RNG vulnerability in libngu library.
Security & Exploits ·
According to reporting by Bitcoin Magazine, investigations from Block and Galaxy Research suggest that law enforcement may have identified those responsible for the initial phase of the July 2026 Coldcard hardware wallet breach, in which attackers obtained 1,082.65 BTC valued at roughly $11.8 million. Block's analysis determined that the attackers leveraged an account at a paid blockchain data provider while moving stolen funds onchain, with that provider's internal logs exhibiting patterns that aligned with the attackers' activity. The underlying vulnerability stemmed from a random number generator flaw in the libngu library, which was integrated into Coldcard devices starting in 2021, creating conditions under which a substantial portion of private keys could potentially be compromised.
Authorities continue investigating additional attack waves beyond the first. The identification mechanism appears to hinge on tracking blockchain activity footprints and data provider access logs rather than direct attribution through traditional means. Several details remain unclear: the specific investigative methods that led to potential identification, the identities or locations of suspected attackers, and how many subsequent waves of attacks have been detected or partially resolved.