The Coldcard theft investigation has advanced after investigators reportedly traced the first wave of the July exploit to a paid blockchain service account. The attack drained more than 1,082 BTC, while the underlying seed-generation vulnerability has raised broader concerns about firmware security and self-custody risks.