Hackers steal 594 BTC from 500 wallets using weak seed phrases

iconBitMedia
Share
AI summary iconSummary
Today’s BTC news reports that hackers stole 594 BTC from 500 wallets by exploiting weak seed phrases on Coldcard Mk3 devices. The attackers drained 1,324 UTXOs, with individual losses ranging from 0.15 BTC to 29.9 BTC. Coinkite confirmed the vulnerability affects Coldcard Mk3 firmware versions 4.0.1 and above. Experts state the issue stems from poor seed randomness, not hardware flaws. BTC update: Singapore’s Triple-A also reported a separate theft of $11.8 million.

During the attack, the attackers withdrew 1,324 UTXOs (unspent transaction outputs, remaining bitcoins on wallets after certain transactions), according to Atlas21. The stolen coins have not yet been transferred to an exchange or a crypto mixer: 562 bitcoins are currently stored on a new address, and another 32 bitcoins are on an intermediate address.

Each of the attackers’ transactions emptied exactly one victim address. While 419 addresses had only one UTXO, some accumulated up to 105 or 200 UTXOs. The median loss per victim was 0.41 BTC (approximately $26,500); 110 victims lost more than 1 BTC, and the maximum loss reached 29.9 BTC (nearly $2 million). No victim lost less than 0.15 BTC—security experts believe the attackers filtered wallets by minimum balance.

The investigation into the incident began after one of the Reddit bloggers reported a cryptocurrency theft. According to the author, he purchased a Coldcard wallet in 2021; the 24-word seed phrase was generated directly on the device, funds were then sent to the wallet, followed by years of inactivity. In January last year, the Reddit user bought a second Coldcard and re-entered the old seed phrase “to verify that the words were correct.” The blogger claims he never shared the seed phrase with anyone and used it exclusively on the Coldcard.

Coinkite has acknowledged a security issue affecting seed phrases generated on Coldcard Mk3 devices. The manufacturer recommends that all users who created a seed phrase on an Mk3 device with firmware version 4.0.1, released in March 2021, or any later version, consider their funds compromised. The company stated that models Mk4, Q, and Mk5 are not affected by this issue.

Coinkite recommends that Mk3 owners generate a unique BIP-39 passphrase on the device and transfer funds to a new wallet. The company acknowledged that the cause of the vulnerability has not yet been identified. It is confirmed that none of the affected wallets are multisignature.

Blockchain analysts from Atlas21 suggest the issue is not with the hardware wallet itself, but with weak seed phrases. The affected users likely imported already compromised or easily guessable word combinations into their devices. Due to “insufficient randomness” in the generation of the seed phrases, private keys for individual UTXOs could be easily brute-forced, which attackers did, security experts explained.

Recently, Singapore-based company Triple-A, which provides businesses with infrastructure for payments in stablecoins and other cryptocurrencies, suffered a cyberattack. The damage is estimated at $11.8 million.


Disclaimer: The information on this page may have been obtained from third parties and does not necessarily reflect the views or opinions of KuCoin. This content is provided for general informational purposes only, without any representation or warranty of any kind, nor shall it be construed as financial or investment advice. KuCoin shall not be liable for any errors or omissions, or for any outcomes resulting from the use of this information. Investments in digital assets can be risky. Please carefully evaluate the risks of a product and your risk tolerance based on your own financial circumstances. For more information, please refer to our Terms of Use and Risk Disclosure.