By Interestana AI Editorial — AI-drafted, human-overseen. How we report
Bitcoin Wallet Flaw Drains $38 Million in 25 Minutes

A significant security flaw in a widely used bitcoin hardware wallet has resulted in the theft of 594 bitcoin, valued at approximately $38 million, occurring within a rapid 25-minute timeframe. The vulnerability, identified as a randomness bug, compromised the generation of wallet seed phrases, which are intended to be cryptographically secure and virtually impossible to guess. This flaw allowed attackers to predict and subsequently access user funds. The exploit was reportedly carried out by a single entity, demonstrating the concentrated impact of the vulnerability. The affected hardware wallet model has not been publicly disclosed by the researchers who identified the bug, citing ongoing investigations and the need to protect user security while a fix is developed and deployed.
Researchers from Ledger Donjon, a security research team, detailed the exploit in a post on X (formerly Twitter), explaining that the bug affected the random number generator (RNG) used in the wallet's seed phrase creation process. This RNG is crucial for ensuring that each seed phrase is unique and unpredictable, serving as the master key to a user's bitcoin holdings. When the RNG fails to produce truly random numbers, it creates predictable patterns that can be exploited by malicious actors. The attackers were able to leverage these predictable patterns to derive the private keys associated with compromised wallets, thereby gaining unauthorized access to the bitcoin stored within them. The speed at which the funds were drained underscores the urgency of the situation and the potential for widespread damage if the vulnerability affects a large number of users.
This incident highlights the persistent challenges in securing digital assets, particularly within the cryptocurrency space, where the immutability of transactions means stolen funds are often irrecoverable. Hardware wallets are generally considered one of the most secure methods for storing bitcoin, as they keep private keys offline, isolated from internet-connected devices that are more susceptible to malware and hacking. However, flaws in the underlying hardware or firmware can undermine these security measures. The specific nature of this bug, related to the fundamental process of seed generation, suggests a deep-seated issue that requires careful remediation by the wallet manufacturer.
While the exact number of affected users and wallets remains unclear, the swiftness and scale of the theft indicate a sophisticated attack that exploited a critical weakness. The cryptocurrency community is awaiting further details from the researchers and the hardware wallet manufacturer regarding the affected product and the steps being taken to mitigate the risk. Users of hardware wallets are consistently advised to keep their firmware updated and to be vigilant about any security advisories issued by their wallet providers. The incident serves as a stark reminder of the importance of robust security practices and the ongoing need for vigilance in the management of digital assets.
Original source — read the full reporting at the publisher:
Read on CoinDeskGet the weekly AI digest
AI news + new model releases, weekly. Drafted by our agents, reviewed by humans.