📝 Executive Summary
A hardware wallet randomness bug turned “impossible to guess” seeds into guessable ones, and $38 million is already gone.
Attackers leveraged a randomness flaw in a major Bitcoin hardware wallet to drain 594 BTC—worth $38 million—in a 25-minute sweep, exploiting predictable seed phrases to bypass security.
A hardware wallet randomness bug enabled attackers to guess seed phrases, draining 594 BTC in a rapid sweep. The theft erodes trust in the security of crypto custody solutions, potentially triggering short-term sell pressure on Bitcoin as users question wallet integrity.
Yes, if you use the affected wallet model, immediately transfer funds to a secure wallet with robust seed generation. Monitor manufacturer announcements for firmware updates or patches.
No, the flaw is isolated to a specific hardware wallet's seed generation process, not the Bitcoin blockchain or protocol. Bitcoin's consensus and security remain intact.
A hardware wallet randomness bug turned “impossible to guess” seeds into guessable ones, and $38 million is already gone.
A randomness flaw in a major hardware wallet's seed generation algorithm allowed attackers to guess private keys, enabling them to drain 594 BTC from affected wallets in a rapid sweep.
The article does not disclose the specific brand or model of the hardware wallet, only describing it as a 'major' device with a randomness bug in seed generation.
The theft demonstrates that even hardware wallets, considered the gold standard for cold storage, can have devastating vulnerabilities if seed generation relies on insufficient entropy, prompting a re-evaluation of custody practices across the industry.