Doctorcrypto About RSS Subscribe
Doctorcrypto
HomeOpinion › Major bitcoin wallet flaw drains 594 BTC in 25-minute sweep
Opinion

Major bitcoin wallet flaw drains 594 BTC in 25-minute sweep

By Malik Sokolov · · 2 min read

A critical flaw in the way certain hardware wallets generated their random seed phrases allowed attackers to drain 594 BTC — worth roughly $38 million — in a single sweep that lasted just 25 minutes, according to security researchers investigating the incident.

How the Flaw Worked

At the heart of the vulnerability was a broken source of randomness. Bitcoin wallets rely on generating seed phrases with enough entropy that the resulting private keys are effectively impossible to guess. The affected devices, however, produced seeds with far less randomness than intended, shrinking the pool of possible keys to a range attackers could realistically search.

Once the flaw was understood, adversaries were able to systematically reconstruct private keys tied to wallets created with the faulty randomness. That transformed what should have been astronomically secure seeds into keys that could be brute-forced within a practical timeframe.

Seeds that were supposed to be impossible to guess became guessable — and $38 million vanished in less time than a lunch break.

A Rapid, Coordinated Drain

The speed of the theft underscores how prepared the attackers were. Rather than picking off individual wallets over days or weeks, they executed a coordinated sweep that emptied 594 BTC across affected addresses in about 25 minutes, suggesting the keys had already been precomputed before the transactions began.

Security analysts say the compressed timeline points to automation and advance planning. Victims had little to no window to react once the sweep started, and by the time the movement of funds was noticed on-chain, the bitcoin had already been consolidated and moved.

  • The total stolen amounted to 594 BTC, valued at about $38 million.
  • The sweep was completed in roughly 25 minutes.
  • The root cause was weak entropy during seed generation.

What Users Should Know

The incident is a stark reminder that the security of a hardware wallet depends entirely on the quality of its randomness. A device that stores keys offline offers little protection if the underlying seed was never truly unpredictable in the first place.

Users who suspect their wallets were generated with flawed randomness are being urged to move their funds to newly created wallets built on trusted, verified entropy sources. Researchers continue to examine the affected devices to determine the full scope of exposure and whether additional balances remain at risk.

Was this useful?👍 Yes👎 No