← Back

security

Major Bitcoin Wallet Flaw Drains 594 BTC in 25-Minute Sweep

A vulnerability in a hardware wallet's randomness generator allowed attackers to predict seed phrases, resulting in the theft of 594 BTC worth approximately $38 million in a brief attack.

AS1 NewsSource: coindesk.com

securityhardware-walletcryptosecuritybitcoinvulnerabilitycyberattackcoldstorage
BTC$77,771.00+1.44%

A critical flaw in a hardware wallet's randomness process has been exploited, enabling attackers to generate predictable seed phrases. Over a span of 25 minutes, they drained a total of 594 BTC from affected wallets, equating to roughly $38 million at current prices. The vulnerability turned what should have been 'impossible to guess' seed phrases into guessable ones, exposing a significant security weakness.

The incident underscores the importance of robust randomness in hardware wallet security. The compromised wallets were likely generated using a flawed process, which allowed attackers to reproduce seed phrases and access the stored funds. This breach highlights the risks associated with hardware wallet vulnerabilities and the need for rigorous security audits.

The cause appears to be a bug in the wallet's randomness algorithm, which failed to produce sufficiently unpredictable seed phrases. This flaw was exploited swiftly, demonstrating how critical secure random number generation is for safeguarding crypto assets.

While the specific wallet model involved has not been publicly disclosed, the event raises concerns about hardware wallet security standards across the industry. Users are advised to verify the integrity of their seed generation processes and consider hardware wallets with proven security track records.

This incident may prompt further scrutiny and updates in hardware wallet security protocols, potentially leading to improved standards and user confidence in cold storage solutions. The event serves as a reminder of the ongoing need for vigilance in crypto security practices.

negative

The breach highlights critical security vulnerabilities in hardware wallets, potentially prompting industry-wide security improvements.