Loading market data...

Weak Seed Generation Led to Theft of Over 1,000 BTC from Cold Wallets, Galaxy Research Finds

Weak Seed Generation Led to Theft of Over 1,000 BTC from Cold Wallets, Galaxy Research Finds

An attacker stole more than 1,000 bitcoin from nearly 1,200 wallets without ever touching the physical cold storage devices, according to a report from Galaxy Research. The breach relied on weak seed generation — a flaw that let the attacker recreate private keys offline and sweep funds from wallets that were supposed to be secure.

How the attack worked

The attacker never needed to access the hardware wallets themselves. Instead, Galaxy Research found that the seed phrases used to generate the wallets were created with insufficient randomness. That weakness allowed the attacker to reconstruct the private keys entirely offline, then use them to move the bitcoin out of the wallets.

Cold wallets are designed to keep private keys offline, but if the seed generation process is predictable, the keys can be recreated without ever touching the device. That's what happened here. The attacker didn't need to hack the hardware or intercept a transaction — they just needed to guess the seeds.

Scope of the theft

Galaxy Research's analysis puts the total haul at more than 1,000 BTC, taken from roughly 1,200 wallets. The exact value fluctuates with bitcoin's price, but at current rates that's tens of millions of dollars. The report doesn't name the wallet manufacturer or the specific victims, but it notes the attack targeted wallets that relied on weak seed generation.

The attacker didn't stop after the initial sweep. Galaxy Research says the same actor kept searching for more vulnerable wallets after the first round of thefts. That suggests the attacker had automated tools to scan for wallets with predictable seeds and continued to exploit the same weakness.

What the report means for cold wallet users

Cold wallets are often marketed as unhackable because the private keys never touch the internet. But this case shows that the security of a cold wallet depends on how its seed phrase is generated. If the seed is created with a weak random number generator or a predictable algorithm, the keys can be compromised without any physical access.

Galaxy Research's findings don't name a specific product or company, so it's unclear which wallets were affected. The report does serve as a warning: not all cold wallets are created equal, and users should verify that their device uses a strong, truly random seed generation process.

No arrests have been reported, and the stolen bitcoin hasn't been recovered. The attacker's continued scanning means more wallets could still be at risk. Galaxy Research hasn't said whether it shared its findings with law enforcement or the wallet makers involved.