Coldcard黑客追踪:第一波盗币者或已被FBI锁定
Hunting Down the Coldcard Hacker. Wave 1 Thief May Be Known to FBI
加密安全重大事件,涉及硬件钱包漏洞、大规模盗币及执法进展,建议关注后续调查及受影响用户迁移资金。
Bitcoin Magazine
比特币杂志
Hunting Down the Coldcard Hacker. Wave 1 Thief May Be Known to FBI
追捕Coldcard黑客。第一波盗窃者可能已被FBI知晓
Law enforcement may already know who emptied more than a thousand Bitcoin from Coldcard wallets in the first and largest wave of the July 2026 drains. Block’s investigation believes they traced the attacker’s on-chain sweeps to a paid account at a major blockchain data provider whose internal logs matched the theft pattern with “extraordinary specificity.”
执法部门可能已经知道是谁在2026年7月第一波也是最大规模的盗窃中,从Coldcard钱包中清空了超过一千枚比特币。Block的调查认为,他们追踪到攻击者的链上扫荡行为,指向一家主要区块链数据提供商的付费账户,其内部日志与盗窃模式匹配度“异常精确”。
PSA: The attack is ongoing, targeting weak private keys generated on devices as old as the MK2 with firmware 4.0.1 onwards. If you may have one, double-check and move funds asap. See Coinkite advisory and status page.
公共安全提示:攻击仍在进行中,目标是那些在固件4.0.1及更高版本的老旧设备(如MK2)上生成的弱私钥。如果您可能拥有此类设备,请立即检查并转移资金。请参阅Coinkite公告和状态页面。
The coins from that wave—1,082.65 BTC—still sit untouched in the attacker’s address, leaving hope that a clawback may be possible to the victims and rightful owners of that first wave of stolen bitcoin. The question now is, who is the hacker and whether the same lead points to a sophisticated outsider, or whether the five-year-old entropy bug that made the theft possible was something closer to the insider “retirement attack” Coinkite itself once warned about.
那一波被盗的币——1,082.65 BTC——仍原封不动地留在攻击者的地址中,这让人们希望第一波被盗比特币有可能被追回给受害者和合法所有者。现在的问题是,黑客是谁,以及同样的线索是否指向一个复杂的外部攻击者,或者,使盗窃成为可能的五年熵漏洞,是否更接近Coinkite自己曾警告过的内部“退休攻击”。
What We Know
我们所知的情况
On July 30, 2026, an attacker began systematically draining Bitcoin from Coldcard hardware wallets that had generated seeds under vulnerable firmware, a bug that was undiscovered for years. The first and largest wave alone moved 1,082.65 BTC. Subsequent waves followed, with estimates over 2k BTC. Alex Thorn at Galaxy Research has tracked the activity through a combination of on-chain pattern analysis and voluntary victim reports. As of early August, confirmed and estimated losses across multiple waves exceeded 1,800 BTC from more than 5,000 addresses, though exact final totals continue to be refined as new reports arrive. In dollar terms, roughly $118 million has been confirmed stolen.
2026年7月30日,一名攻击者开始系统性地从在易受攻击的固件下生成种子的Coldcard硬件钱包中盗取比特币,这一漏洞多年未被发现。仅第一波也是最大的一波就转移了1,082.65 BTC。随后又有几波攻击,估计总损失超过2,000 BTC。Galaxy Research的Alex Thorn通过链上模式分析和受害者自愿报告相结合的方式追踪了这一活动。截至8月初,多波攻击的确认和估计损失已超过1,800 BTC,涉及5,000多个地址,尽管随着新报告的到来,最终确切总数仍在不断修正。以美元计算,已确认被盗金额约为1.18亿美元。
Thorn has publicly discussed the possibility that law enforcement already holds a concrete lead on the operator behind the largest tranche. In a Bitcoin Policy Institute segment hosted on the Bitcoin Magazine YouTube channel, Thorn stated: “Wave one’s identity, attacker identity, may be known to law enforcement.” He added that Wave 1 remains the biggest single chunk identified so far, with the coins still sitting in the attacker’s address, and noted that Wave 2’s pattern looks similar enough that it could involve the same actor. Wave 2 adds another 76 or so bitcoin to the total.
Thorn公开讨论了执法部门可能已经掌握了最大一笔资金背后操作者的具体线索的可能性。在比特币杂志YouTube频道上由比特币政策研究所主持的节目中,Thorn表示:“第一波的身份,攻击者的身份,可能已被执法部门知晓。”他补充说,第一波仍是迄今确认的最大单笔资金,这些币仍留在攻击者的地址中,并指出第二波的模式看起来足够相似,可能涉及同一行为者。第二波又增加了约76枚比特币到总损失中。
The primary source for the claim that the hacker’s identity might be known is Clay Garrett, engineering lead at Block working on Bitkey. On July 31, 2026, Garrett posted the findings from Block’s investigation:
关于黑客身份可能已知的说法,主要来源是Block公司负责Bitkey的工程主管Clay Garrett。2026年7月31日,Garrett发布了Block调查结果的帖子:
“During our investigation of the Coldcard drain yesterday, we identified an unusual pattern in the sweeps. That pattern led us to a hypothesis that has since been confirmed: the operator used a paid account at a well-known blockchain-services provider to query the source addresses and perform other related activity during the sweeps.”
“在我们昨天对Coldcard资金流失的调查中,我们发现了扫取操作中的异常模式。这一模式引导我们提出了一个假设,该假设随后得到证实:操作者使用了一家知名区块链服务提供商的付费账户,在扫取期间查询源地址并执行其他相关活动。”
“We contacted the provider directly. Their internal logs matched the suspected workflow with extraordinary specificity, including the number, timing and sequence of requests. The provider was supplying its standard services in response to requests that did not reveal their broader purpose. We have seen no evidence that the provider knowingly participated in or facilitated the suspected theft.” Garrett said, and added that; “We are sharing the relevant information with the appropriate authorities. We will provide further updates when doing so will not interfere with the investigation.”
“我们直接联系了该提供商。他们的内部日志与疑似工作流程的匹配度极高,包括请求的数量、时间和顺序。该提供商是在响应未透露其更广泛目的的请求时提供其标准服务。我们没有看到任何证据表明该提供商知情参与或协助了疑似盗窃行为。” Garrett表示,并补充说:“我们正在与相关当局分享相关信息。当这样做不会干扰调查时,我们将提供进一步更新。”
Thorn and others have noted that later, smaller waves show different operational patterns—some rapid, opportunistic drains followed by quick laundering—suggesting additional actors may have reverse-engineered the same weak seed space after the initial public disclosure. Self-reported confirmed drains appear to have slowed sharply after August 6, though many potentially vulnerable seeds generated on the affected firmware between 2021 and the July 2026 patch remain at risk until users migrate.
Thorn和其他人指出,后来较小规模的扫取显示出不同的操作模式——一些快速、机会主义的资金流失随后迅速洗钱——这表明在最初公开披露后,可能有其他行为者逆向工程了相同的弱种子空间。自报的确认资金流失在8月6日后似乎急剧放缓,尽管在2021年至2026年7月补丁之间受影响的固件上生成的许多潜在易受攻击的种子,在用户迁移之前仍面临风险。
A Retirement Attack?
退休攻击?
The nature of the failure has led to conspiracy theories about insider attacks that Coinkite itself once discussed publicly. In October 2021, the official COLDCARD account defined a “retirement attack” as the scenario “when the project makers could have a ‘bug’ in the entropy generation for later retrieval.” The post is still available here. The 2026 vulnerability produced exactly that outcome: seeds generated with far less entropy than intended, leaving them searchable years later. Some in the Bitcoin space now believe that the hack may have been an inside job at Coinkite, though others disagree and the evidence in the public record remains too scarce to know anything definitive. Further evidence will likely not come out for years, until litigation exposes it.
这种失败的性质引发了关于内部攻击的阴谋论,Coinkite本身曾公开讨论过这一点。2021年10月,官方COLDCARD账户将“退休攻击”定义为“项目制造者可能在熵生成中留有‘漏洞’以供日后检索”的情景。该帖子仍可在此处查看。2026年的漏洞恰好产生了这种结果:生成的种子熵远低于预期,使它们在多年后可被搜索到。比特币领域的一些人现在认为,这次黑客攻击可能是Coinkite的内部人员所为,尽管其他人不同意,公开记录中的证据仍然太少,无法确定任何结论。进一步的证据可能要到多年后诉讼揭露时才会出现。
It’s when the project makers could have a “bug” in the entropy generation for later retrieval.
这是项目制作者在熵生成过程中可能存在的“漏洞”,影响后续的恢复。
— COLDCARD (@COLDCARDwallet) October 10, 2021
— COLDCARD (@COLDCARDwallet) 2021年10月10日
The critical change entered the codebase on March 1, 2021, in a commit titled “First pass w/ libNgU” (b18723dd). That commit replaced remaining Trezor-derived cryptography and BIP-39 code with a new library, libngu, and rewired seed generation. The intended result was that the call for randomness resolved to the STM32 hardware’s true random number generator. However, the bug redirected the call to MicroPython’s software Yasmarang PRNG instead, resulting in an effective entropy collapse to roughly 40 bits on older models and around 72 bits on newer ones. That meant the Bitocin private keys generated were effectively guessable by modern computing hardware. This swap of cryptographic libraries was pushed to the codebase by Doc-Hex, also known as Peter Gray, the Chief Technical Officer of Coinkite.
关键变更于2021年3月1日进入代码库,提交标题为“First pass w/ libNgU”(b18723dd)。该提交用新库libngu替换了剩余的Trezor派生密码学和BIP-39代码,并重新连接了种子生成。预期结果是随机性调用指向STM32硬件的真随机数生成器。然而,该漏洞将调用重定向到MicroPython的软件Yasmarang PRNG,导致旧型号的有效熵崩溃至约40位,新型号约72位。这意味着生成的比特币私钥实际上可被现代计算硬件猜测。这次密码学库的替换由Doc-Hex(即Coinkite首席技术官Peter Gray)推入代码库。
The move was arguably driven by licensing pressure, according to Foundation Devices CEO and founder Zach Herbert, though Coinkite has denied this as a primary motivation for the code change, saying, “COLDCARD had to make this change to move to libsecp256k1; the license change is irrelevant to this. libsecp256k1 is the standard library used by Bitcoin Core.”
据Foundation Devices首席执行官兼创始人Zach Herbert称,此举可以说是由许可压力驱动的,尽管Coinkite否认这是代码更改的主要动机,称“COLDCARD必须进行此更改以迁移到libsecp256k1;许可证变更与此无关。libsecp256k1是Bitcoin Core使用的标准库。”
Coldcard had been using Trezor-derived code under the GPLv3 open source license. After Foundation Devices forked related material, Coinkite sought to move remaining components to a more restrictive MIT + Commons Clause arrangement that limited commercial reuse. The rewrite was large and carried complex engineering goals; it was this integration that arguably left the silent failure in the entropy path.
Coldcard一直使用Trezor派生代码,遵循GPLv3开源许可证。在Foundation Devices分叉相关材料后,Coinkite寻求将剩余组件迁移到更严格的MIT + Commons Clause安排,限制商业重用。重写规模庞大,承载了复杂的工程目标;正是这种集成可能留下了熵路径中的静默故障。
Skepticism about the migration away from the Trezor crypto library emerged as early as April 7, 2021, by a member of the Coinkite Telegram group, who wrote: “do we really want to replace the many-years-old TrezorCrypto code that has been heavily scrutinized by white hatters like Johoe and penetration tested by wallet.fail”, adding “switch may be a talented pseudonymous coder, but their commit history sucks.” The criticism, however, was insufficient and quickly waved away by NVK, who criticized the Trezor library as a “shitcoin shitshow.” Ironically, sharing that codebase with the broader crypto market, under an open license meant that Trezor’s crypto library had much deeper code review than Libngu would ever get, even years later.
对从Trezor加密库迁移的怀疑最早出现在2021年4月7日,由Coinkite Telegram群组成员提出,他写道:“我们真的想替换多年历史的TrezorCrypto代码吗?该代码已受到像Johoe这样的白帽黑客的严格审查,并经过wallet.fail的渗透测试”,并补充说“switch可能是一位有才华的匿名编码者,但他们的提交历史很糟糕。”然而,批评不足,很快被NVK挥手驳回,他批评Trezor库是“垃圾币烂摊子”。讽刺的是,在开放许可证下与更广泛的加密市场共享该代码库意味着Trezor的加密库比Libngu获得了更深入的代码审查,即使在多年后也是如此。
Switch and Peter Gray aka Doc-Hex
Switch和Peter Gray(又名Doc-Hex)
The swap of cryptographic libraries that introduced the bug was pushed to the codebase by Doc-Hex, the Chief Technical Officer of Coinkite, also known as Peter D. Gray. He replaced the GPLv3 Trezor cryptography library with Libngu, a little-known codebase created by so-called “Switch”, a nym that, up until the creation of Libngu, had no obvious previous history. The Switch account appeared on X on August 3, 2019 with a mention of DEFCON, the international hacker’s conference, an event normally attended by cybersecurity engineers of all kinds.
引入该漏洞的加密库替换是由Coinkite的首席技术官Doc-Hex(又名Peter D. Gray)推送到代码库的。他用Libngu替换了GPLv3许可的Trezor加密库,Libngu是一个鲜为人知的代码库,由化名为“Switch”的人创建,而在Libngu出现之前,这个化名几乎没有明显的历史记录。Switch账号于2019年8月3日在X平台上出现,提及了国际黑客大会DEFCON,该活动通常吸引各类网络安全工程师参加。
更进一步:量化金融体系
看懂新闻只是起点——沿量化金融路径,把它变成能交付的工程能力