Block exposes Coldcard attacker through data vendor logs
- Block engineers linked the Coldcard attacker to subscriber logs at a commercial data vendor.
- Hardware wallet teams are adopting automated AI code reviews to catch firmware bugs earlier.
- Developers split over forcing manual key generation versus keeping self-custody simple enough to rival ETFs.
The paper trail is closing in on the Coldcard hacker.
On August 20, 2026, Block engineering lead Clay Garrett revealed that investigative leads into the firmware exploit uncovered a distinct digital footprint. The attacker queried target wallet addresses using a paid subscription at an unnamed commercial data vendor prior to executing on-chain sweeps. Vendor system logs matched the exact sequence and timing of the thefts, prompting Block to hand matching subscriber records directly to federal law enforcement. Galaxy Digital research indicates the random number generator flaw drained over 1,000 Bitcoin from vulnerable seed generation routines.
Those stolen coins currently sit untouched in visible address clusters monitored by every major exchange. Protocol-level transactions remain irreversible, meaning asset recovery hinges on federal authorities using legal compulsion to secure physical control of the private keys once they confirm the subscriber's identity.
The exploit shattered the belief that open-source code alone guarantees protection against entropy flaws. Security researchers and regular users now flood hardware manufacturers with AI-generated bug reports. In response, Zach Herbert of Foundation Devices confirmed that wallet teams are integrating automated AI code reviews directly into firmware release pipelines to catch flaws before deployment.
The crisis has provoked a philosophical rift among hardware developers over baseline security standards. SeedSigner developers argue that hardware makers must require users to manually generate entropy through physical dice rolls to eliminate device-level randomness risks. Trezor and Blockstream developers countered that steep technical hurdles risk driving average users away from self-custody altogether and into custodial spot ETFs.
Industry consensus is consolidating around multi-vendor key quorums as the primary defense against single-device vulnerabilities. Users who distributed signing authority across distinct hardware architectures survived the Coldcard flaw without losing funds or executing emergency migrations.
Single-vendor trust in self-custody is officially dead.