A critical flaw in a widely used hardware wallet allowed attackers to sweep roughly 594 BTC — worth about $38 million — from affected users in a coordinated operation that lasted just 25 minutes, according to security researchers.
How the Flaw Worked
At the heart of the incident is a weakness in how certain wallets generated the randomness needed to create seed phrases. A seed phrase is the master key that controls all funds in a wallet, and its security depends entirely on being effectively impossible to predict. When the randomness that produces these seeds is flawed, the pool of possible keys shrinks dramatically, turning a theoretically unguessable secret into something an attacker can brute-force.
Researchers say the bug reduced the entropy — the measure of unpredictability — behind the affected seeds. That meant funds that owners believed were locked behind cryptographically secure keys were, in reality, sitting behind combinations that determined adversaries could compute and drain.
When the randomness fails, an "impossible to guess" key becomes just another number waiting to be found.
A Rapid, Coordinated Sweep
The theft was notable not only for its scale but for its speed. Attackers appear to have precomputed vulnerable keys in advance, then moved to empty the wallets in a tightly compressed 25-minute window. Such timing suggests the operation was automated and planned, designed to grab as much value as possible before victims or exchanges could react.
Blockchain's transparency is a double-edged sword here. While the movement of the stolen 594 BTC is visible on-chain, recovering the funds is another matter entirely, as bitcoin transactions are irreversible once confirmed.
What Users Should Do
Security experts are urging anyone who may have used the affected wallet or generation method to treat their existing seeds as compromised.
- Move any remaining funds to a new wallet generated with a trusted, properly audited source of randomness.
- Never reuse a seed phrase suspected of being tied to the vulnerable software or device.
- Monitor official channels from the wallet provider for patches and guidance.
The episode is a stark reminder that self-custody security is only as strong as the tools that generate the keys. As the ecosystem matures, incidents like this underscore why entropy quality and independent audits remain foundational — not optional — for any product that safeguards digital assets.
