Cold Wallets Exposed: $70M Bitcoin Heist Highlights Entropy Vulnerability
A recent attack on Bitcoin cold wallets has exposed a previously unknown vulnerability in the security of self-custody solutions. According to Galaxy Research, an attacker was able to drain over $70 million from nearly 1,200 wallets without ever physically accessing them.
The exploit targeted weak seed generation, which allowed the attacker to recreate private keys offline. This was possible because the wallets were created using predictable or low-quality random number generators. The attacker could then scan the Bitcoin ledger for matching addresses and drain the funds remotely.
This incident highlights a critical flaw in self-custody solutions: the security of wallet infrastructure is only as strong as the entropy behind its key pairs. Galaxy's research underscores that seed generation is often treated as an afterthought, with some wallets relying on pseudo-random number generators seeded from device sensors or user input timing.