Block engineers trace COLDCARD attacker to blockchain services provider.
Clay Garrett, engineering lead for
@blocks Bitkey, shared that during their investigation of the COLDCARD drain, Block's team identified an unusual pattern in the sweeps that led them to a breakthrough.
The attacker used a paid account at a well-known blockchain services provider to query the targeted addresses and perform related activity during the theft.
Block contacted the provider directly and their internal logs "matched the suspected workflow with extraordinary specificity, including the number, timing and sequence of requests."
Garrett noted there is no evidence the provider knowingly participated in or facilitated the theft, stating it "was supplying its standard services in response to requests that did not reveal their broader purpose."
The team is now sharing the information with authorities and will provide further updates when doing so won't interfere with the investigation.
This is a significant development as it means the attacker left an identifiable trail through a service that maintains account records, potentially giving law enforcement a direct lead.