How bitcoin cold wallets lost $70 million in an attack that never touched the devices

A security vulnerability in Coldcard hardware wallets allowed attackers to predict private keys by exploiting a flaw in the device's random number generation process. Because the keys were generated using predictable data rather than true randomness, attackers were able to drain $70 million in Bitcoin without ever needing physical access to the devices.
Why it matters
This incident undermines the fundamental premise of 'cold storage' security, proving that even offline hardware wallets are vulnerable if their internal software fails to generate truly random cryptographic keys.
Galaxy Research mapped the full event on Friday, finding 1,082.65 BTC swept between 01:10 and 01:51 UTC across six blocks, with three intervening blocks containing nothing, which suggests the transactions were broadcast in batches rather than continuously.
The proceeds sit in four addresses and have not moved. Early reporting captured only one of those addresses, which is why the figure has grown.
The size of the attack is much smaller than some of the bigger attacks this year, but the mechanism is what makes this unusually — and why the attack is such a big deal.
Get smarter about the news
Sign up free for a feed built around what you actually care about, Dive Deeper research on any story, and the full text of every article.
Create free accountAlready have an account? Sign in