tags.
Let's translate paragraph by paragraph.
First paragraph: "A Canadian entrepreneur lost 18.25 Bitcoin — worth roughly $1.6 million — from a Coldcard hardware wallet in under seven minutes on July 29, 2026. The theft is part of a much larger pattern: Galaxy Research has identified three suspected attack waves targeting Coldcard-generated addresses, draining 1,367.05 BTC (about $88.6 million) from 4,585 source addresses. The vulnerability, the firm says, traces back to a 2021 flaw in the code that generates seed phrases, with attackers allegedly using AI to brute-force affected seeds."
Translation: "فقد رجل أعمال كندي 18.25 بيتكوين — بقيمة تقارب 1.6 مليون دولار — من محفظة كولدكارد للأجهزة في أقل من سبع دقائق في 29 يوليو 2026. وتعد هذه السرقة جزءًا من نمط أكبر بكثير: حددت أبحاث جالاكسي ثلاث موجات هجوم مشتبه بها استهدفت عناوين تم إنشاؤها بواسطة كولدكارد، مما أدى إلى استنزاف 1,367.05 بيتكوين (حوالي 88.6 مليون دولار) من 4,585 عنوانًا مصدرًا. وتقول الشركة إن الثغرة تعود إلى خلل عام 2021 في الكود الذي يولد عبارات البذرة، حيث يُزعم أن المهاجمين استخدموا الذكاء الاصطناعي لاختراق البذور المتأثرة."
We need to keep numbers as is, and "BTC" we can keep as "بيتكوين" or "BTC"? Usually in Arabic crypto articles they use "BTC" or "بيتكوين". We'll use "بيتكوين" for consistency, but maybe keep the abbreviation? Actually the instruction says keep facts and numbers accurate, so we can write "18.25 بيتكوين" and "1,367.05 بيتكوين". Also "Coldcard" and "Galaxy Research" as proper nouns.
Second paragraph: "The Canadian victim's wallet was emptied fast — 18.25 BTC gone in less than seven minutes. That speed points to a precomputed list of vulnerable seeds rather than a real-time crack. Galaxy Research's on-chain analysis shows the stolen Bitcoin hasn't moved since; it sits in attacker-controlled addresses. The firm hasn't confirmed whether insufficient randomness in the seed generation is the root cause, but its findings rely entirely on on-chain data."
Translation: "تم إفراغ محفظة الضحية الكندية بسرعة — فقد اختفت 18.25 بيتكوين في أقل من سبع دقائق. تشير هذه السرعة إلى قائمة محسوبة مسبقًا من البذور الضعيفة بدلاً من اختراق في الوقت الفعلي. يُظهر تحليل أبحاث جالاكسي على السلسلة أن البيتكوين المسروق لم يتحرك منذ ذلك الحين؛ فهو موجود في عناوين يسيطر عليها المهاجمون. لم تؤكد الشركة ما إذا كان عدم كفاية العشوائية في توليد البذور هو السبب الجذري، لكن استنتاجاتها تعتمد كليًا على بيانات السلسلة."
Third paragraph: "Coldcard's default seed-generation method is described in the device's manual as 'involves the most trust' yet also 'low risk to users.' The 2021 code flaw apparently made some seeds predictable enough that AI-assisted brute-forcing became feasible. Alternatives exist — users can combine the hardware's output with dice rolls to remove trust in the hardware — but most users likely followed the default path. Galaxy hasn't publicly identified which specific Coldcard firmware versions are affected, but the attack waves suggest a broad exposure."
Translation: "يوصف أسلوب التوليد الافتراضي للبذور في كولدكارد في دليل الجهاز بأنه 'يتضمن أكبر قدر من الثقة' ولكنه أيضًا 'منخفض المخاطر للمستخدمين'. يبدو أن الخلل البرمجي لعام 2021 جعل بعض البذور قابلة للتنبؤ بما يكفي لدرجة أن الاختراق بمساعدة الذكاء الاصطناعي أصبح ممكنًا. توجد بدائل — يمكن للمستخدمين الجمع بين مخرجات الجهاز ورمي النرد لإزالة الثقة في الجهاز — لكن معظم المستخدمين اتبعوا على الأرجح المسار الافتراضي. لم تحدد جالاكسي علنًا إصدارات البرامج الثابتة الخاصة بكولدكارد المتأثرة، لكن موجات الهجوم تشير إلى تعرض واسع النطاق."
Fourth paragraph: "The drained holdings had sat dormant for an average of 3.18 years, meaning most victims were long-term holders — the kind of users who buy a hardware wallet and forget about it. The 4,585 source addresses span three distinct attack waves, though Galaxy hasn't said when the first wave began. The Canadian entrepreneur's case is the most recent confirmed victim, but the total haul of 1,367.05 BTC makes this one of the larger hardware-wallet breaches on record."
Translation: "كانت الأصول المستنزفة خاملة لمدة متوسطها 3.18 سنة، مما يعني أن معظم الضحايا كانوا من حاملي العملات على المدى الطويل — النوع من المستخدمين الذين يشترون محفظة أجهزة وينسونها. تمتد العناوين المصدر البالغ عددها 4,585 عبر ثلاث موجات هجوم متميزة، على الرغم من أن جالاكسي لم يذكر متى بدأت الموجة الأولى. حالة رجل الأعمال الكندي هي أحدث ضحية مؤكدة، لكن إجمالي المبلغ المسروق البالغ 1,367.05 بيتكوين يجعل هذا واحدًا من أكبر اختراقات محافظ الأجهزة المسجلة."
Fifth paragraph: "Coldcard has not issued a public statement about the vulnerability as of Aug. 2, 2026. Galaxy Research's analysis remains preliminary — it hasn't definitively confirmed insufficient randomness, and the firm says its conclusions are based solely on on-chain patterns. The stolen Bitcoin hasn't moved, leaving open the question of whether the attackers will try to launder it or hold. For now, users who generated seeds using Coldcard's default method after 2021 may want to consider migrating to a new wallet — or at least adding dice-roll entropy."
Translation: "لم يصدر كولدكارد بيانًا عامًا حول الثغرة حتى 2 أغسطس 2026. لا يزال تحليل أبحاث جالاكسي أوليًا — لم يؤكد بشكل قاطع عدم كفاية