{
  "id": 19487,
  "title": "How bitcoin cold wallets lost $70 million in an attack that never touched the devices",
  "url": "https://urgent.news/2026/08/01/how-bitcoin-cold-wallets-lost-70-million-in-an-attack-that-never",
  "topic": "finance",
  "section": "Finance & Markets",
  "published": "2026-08-01T05:55:46.000Z",
  "source": {
    "name": "CoinDesk",
    "slug": "coindesk",
    "url": "https://www.coindesk.com/tech/2026/08/01/how-bitcoin-cold-wallets-lost-usd70-million-in-an-attack-that-never-touched-the-devices"
  },
  "original_language": "en",
  "account": "On July 30, a significant theft of 1,196 Bitcoin wallets totaling approximately $70 million took place, with the majority of the stolen funds remaining untouched in four addresses. Galaxy Research mapped the entire attack, revealing that the transactions occurred in a 41-minute window across six blocks, with three intervening blocks containing no activity. This suggests that the transactions were broadcast in batches rather than continuously.\n\nThe theft occurred due to a flaw in the Coldcard hardware wallet firmware, which was supposed to generate unpredictable and secure keys for the wallets using a dedicated hardware randomness generator. However, an internal build setting caused the device to skip this generator and instead use a basic software substitute seeded from the chip's serial number and clock registers. This made the range of keys the device could produce countable, allowing attackers to systematically enumerate and determine potential seeds.\n\nDespite the attacker's successful theft, the majority of the drained wallets used the modern native segwit address format, while only a small percentage used older address formats. The operator is believed to have used a paid account at a well-known blockchain data provider to query the source addresses during the sweep, and their internal logs matched the suspected workflow with extraordinary specificity. Block has informed authorities about the incident, and Coldcard has warned owners of affected firmware models to move their funds to prevent further waves of attacks.",
  "summary": "Galaxy Research said weak seed generation let an attacker recreate likely private keys offline, sweep more than 1,000 BTC from nearly 1,200 wallets and continue searching without ever accessing the devices.",
  "key_points": [],
  "editors_take": null,
  "illustration": null,
  "coverage": {
    "outlets": 1,
    "also_reported_by": []
  },
  "ai_generated": true,
  "disclaimer": "Summaries, key points and the editor’s take are written by software from other outlets’ reporting and may contain errors — always check the linked original."
}