Doctorcrypto About RSS Subscribe
Doctorcrypto
HomeOpinion › How bitcoin cold wallets lost $70 million in an attack that never touched the devices
Opinion

How bitcoin cold wallets lost $70 million in an attack that never touched the devices

By Diego Whitfield · · 2 min read

A sophisticated attack has drained more than $70 million in bitcoin from cold wallets, and according to new research, the thieves never had to lay a finger on the physical devices storing the funds. Instead, the flaw lived in how the wallets generated their secret keys in the first place.

How the Attack Unfolded

Galaxy Research revealed that the culprit was weak seed generation — the process wallets use to create the random numbers that ultimately form private keys. When that randomness is predictable or insufficiently entropic, an attacker can effectively guess the results.

In this case, the flawed process narrowed the universe of possible keys enough that an attacker could recreate likely private keys entirely offline. From there, sweeping the funds was trivial: with the correct key in hand, no interaction with the cold storage hardware was necessary.

The scale was significant. Researchers said the attacker moved more than 1,000 BTC out of nearly 1,200 separate wallets, all traced back to the same underlying weakness in how those wallets were seeded.

The vault was never breached — the lock was simply built with a key an attacker could copy from home.

Why Cold Storage Wasn't Enough

Cold wallets are widely regarded as one of the safest ways to hold cryptocurrency because they keep private keys offline and away from internet-connected threats. But that security model assumes the keys themselves were generated properly and unpredictably.

This incident underscores a persistent truth in crypto security: the strength of any wallet ultimately rests on the quality of its randomness. If the seed is compromised at creation, offline storage offers no protection at all.

  • The attacker recreated private keys offline, never touching the devices.
  • More than 1,000 BTC was swept from nearly 1,200 wallets.
  • Galaxy Research indicated the attacker may still be searching for additional vulnerable keys.

For holders, the takeaway is clear. Users relying on wallets with questionable entropy sources should treat their funds as potentially exposed and consider migrating to keys generated through trusted, well-audited methods.

Was this useful?👍 Yes👎 No