Bitcoin Cold Wallets Drained $70M Via Weak Seed Generation
A recent attack on Bitcoin cold wallets has drained over $70 million from nearly 1,200 wallets without physical access. The exploit targeted weak seed generation, which allowed the attacker to recreate private keys offline.
Galaxy Research's investigation found that the attack did not rely on hardware vulnerabilities or network intrusions. Instead, it exploited predictable or low-quality random number generators used in seed phrase creation.
The attacker could compute likely private keys, scan the Bitcoin ledger for matching addresses, and drain them remotely before anyone noticed.
This incident highlights the importance of entropy in securing cryptocurrency wallets. Weak randomness can lead to insecure key pairs, making it possible for attackers to pre-compute tables of possible keys and automate the process of sweeping funds.