Interestana
Home/News/Bitcoin Cold Wallets Lost $70 Million in Seed Generation Attack
CoinDesk3 min read

By Interestana AI Editorial — AI-drafted, human-overseen. How we report

Bitcoin Cold Wallets Lost $70 Million in Seed Generation Attack

Bitcoin Cold Wallets Lost $70 Million in Seed Generation Attack

An estimated $70 million in Bitcoin was lost due to a sophisticated attack that exploited vulnerabilities in the seed generation process of cold wallets, according to a report by Galaxy Research. The attacker successfully recreated private keys offline for nearly 1,200 wallets, enabling the theft of over 1,000 Bitcoin (BTC) without ever needing to physically access the compromised hardware devices. This method bypassed traditional security measures designed to protect private keys stored offline, highlighting a critical flaw in the initial setup of these wallets.

The attack targeted the process by which users generate their wallet's seed phrase, a sequence of words that can be used to derive the private keys. Weaknesses in the random number generation used during this process meant that the attacker could predict or systematically generate likely seed phrases. Once a plausible seed phrase was identified, the attacker could derive the corresponding private keys and initiate transactions to transfer the Bitcoin to their own addresses. This allowed for a large-scale sweep of multiple wallets that shared similar seed generation vulnerabilities.

Galaxy Research indicated that the attacker continued to search for and exploit additional vulnerable wallets even after the initial thefts. The scale of the loss, exceeding 1,000 BTC, underscores the significant financial implications of such exploits. The report did not specify the exact date of the attack or the particular wallet models affected, but it emphasized that the security of the cold wallet devices themselves remained intact. The breach occurred at the cryptographic level of key derivation, rather than through a compromise of the hardware's physical security or its connection to the internet.

This incident serves as a stark reminder of the importance of robust seed phrase generation practices in cryptocurrency security. Users are advised to ensure they are using hardware wallets with strong, cryptographically secure random number generators and to follow best practices for seed phrase management, including storing them securely and offline. The attack's success in bypassing hardware security by targeting the initial key generation process suggests a need for enhanced scrutiny of the entire lifecycle of private key management, from creation to storage and usage.

Original source — read the full reporting at the publisher:

Read on CoinDesk

Get the weekly AI digest

AI news + new model releases, weekly. Drafted by our agents, reviewed by humans.

Read next