and translate the text.
The first paragraph after the heading: "The initial wave was surgical. On-chain analysts, including Alex Thorn at Galaxy Research, tracked the activity through pattern analysis and voluntary victim reports. Thorn said law enforcement may already know the identity of the Wave 1 attacker."
Translation: "最初の波は外科的でした。Galaxy ResearchのAlex Thornを含むオンチェーンアナリストは、パターン分析と被害者からの自発的な報告を通じてこの活動を追跡しました。Thorn氏は、法執行機関がすでに第1波の攻撃者の身元を把握している可能性があると述べました。"
Then: "Later waves look different. Smaller, faster, and with distinct operational patterns, they suggest other actors reverse-engineered the weak seed space after the vulnerability became public. Self-reported confirmed drains slowed sharply after August 6, but that doesn't mean the threat is gone. Many potentially vulnerable seeds generated on the affected firmware remain at risk."
Translation: "その後の波は様相が異なります。より小規模で、より迅速で、明確な運用パターンを持ち、脆弱性が公になってから他の攻撃者が弱いシードスペースをリバースエンジニアリングしたことを示唆しています。8月6日以降、自己報告による確認済みの流出は急激に減少しましたが、脅威が去ったわけではありません。影響を受けたファームウェアで生成された潜在的に脆弱なシードの多くは、依然としてリスクにさらされています。"
Paragraph 3: "Clues from the investigation" - "調査からの手がかり" or "調査で得られた手がかり"
Then: "Clay Garrett, engineering lead at Block (Bitkey), reported that the attacker used a paid account at a blockchain-services provider. Internal logs matched the theft pattern with 'extraordinary specificity,' Garrett said, and the information was shared with authorities. That detail narrows the field — whoever pulled this off left a digital trail that points to a real-world identity."
Translation: "Block(Bitkey)のエンジニアリングリードであるClay Garrett氏は、攻撃者がブロックチェーンサービスプロバイダーの有料アカウントを使用したと報告しました。内部ログは盗難パターンと「極めて特異に」一致したとGarrett氏は述べ、その情報は当局と共有されました。この詳細により、犯人の範囲は狭まりました。この犯行を行った人物は、実在の身元を指し示すデジタルの痕跡を残したことになります。"
Then: "Still, the full scope is murky. Confirmed and estimated losses exceed 1,800 BTC from more than 5,000 addresses, with total estimated losses over 2,000 BTC. The gap between confirmed and estimated is a reminder that many victims haven't come forward yet."
Translation: "それでも、全容は不明瞭です。確認済みおよび推定の損失は5,000以上のアドレスから1,800 BTCを超え、推定総損失は2,000 BTCを超えています。確認済みと推定の差は、多くの被害者がまだ名乗り出ていないことを示しています。"
Paragraph 4: "A bug Coinkite knew about" - "Coinkiteが知っていたバグ"
Then: "This isn't a novel attack vector. Back in October 2021, Coinkite discussed a 'retirement attack' — a scenario where project makers could plant a bug in entropy generation for later retrieval. That description matches the 2026 vulnerability almost exactly. The company talked about the risk publicly, but the bug still made it into firmware and stayed there for years."
Translation: "これは新しい攻撃ベクトルではありません。2021年10月にCoinkiteは「リタイアメント攻撃」— プロジェクト製作者が後で回収するためにエントロピー生成にバグを仕込む可能性があるシナリオ — について議論しました。その説明は2026年の脆弱性とほぼ正確に一致します。同社はこのリスクを公に話しましたが、バグは依然としてファームウェアに組み込まれ、何年もそこに残りました。"
Paragraph 5: "Who's behind it?" - "背後にいるのは誰か?"
Then: "Some in the Bitcoin space suspect an inside job at Coinkite. The evidence so far is circumstantial — no definitive link has been established. But the combination of a long-standing entropy flaw, the attacker's apparent access to paid blockchain services, and the precise targeting of Coldcard devices keeps that question open."
Translation: "ビットコインコミュニティの一部はCoinkiteの内部犯行を疑っています。これまでの証拠は状況的なものに過ぎず、決定的な関連性は確立されていません。しかし、長年のエントロピーの欠陥、攻撃者が有料のブロックチェーンサービスを利用していた形跡、そしてColdcardデバイスへの正確な標的化の組み合わせにより、その疑問は未解決のままです。"
Then: "The next concrete step is likely forensic: whether law enforcement acts on the identity clues Thorn and Garrett pointed to, and whether Coinkite ships a firmware update that forces users to rotate seeds. Until then, anyone holding Bitcoin on a Coldcard generated with older firmware has a decision to make."
Translation: "次の具体的なステップは、おそらくフォレンジック(法医学的)です。法執行機関がThorn氏とGarrett氏が指摘した識別の手がかりに基づいて行動するかどうか、そしてCoinkiteがユーザーにシードのローテーションを強制するファームウェアアップデートを提供するかどうかです。それまでは、古いファームウェアで生成されたColdcardにビットコインを保有している人は、決断を迫られるでしょう。"
Now, the meta description: Original: "A