The July 29 attack
The Canadian victim's wallet was emptied fast — 18.25 BTC gone in less than seven minutes. That speed points to a precomputed list of vulnerable seeds rather than a real-time crack. Galaxy Research's on-chain analysis shows the stolen Bitcoin hasn't moved since; it sits in attacker-controlled addresses. The firm hasn't confirmed whether insufficient randomness in the seed generation is the root cause, but its findings rely entirely on on-chain data.
Translation:Útok z 29. července
Peněženka kanadské oběti byla vyprázdněna rychle – 18,25 BTC zmizelo za méně než sedm minut. Tato rychlost ukazuje spíše na předem vypočítaný seznam zranitelných seedů než na prolomení v reálném čase. On-chain analýza Galaxy Research ukazuje, že ukradené bitcoiny se od té doby nepohnuly; zůstávají na adresách kontrolovaných útočníky. Firma nepotvrdila, zda je nedostatečná náhodnost generování seedů hlavní příčinou, ale její zjištění se zcela opírají o on-chain data.
Next:How the vulnerability works
Coldcard's default seed-generation method is described in the device's manual as 'involves the most trust' yet also 'low risk to users.' The 2021 code flaw apparently made some seeds predictable enough that AI-assisted brute-forcing became feasible. Alternatives exist — users can combine the hardware's output with dice rolls to remove trust in the hardware — but most users likely followed the default path. Galaxy hasn't publicly identified which specific Coldcard firmware versions are affected, but the attack waves suggest a broad exposure.
Translation:Jak zranitelnost funguje
Výchozí metoda generování seedů Coldcardu je v manuálu zařízení popsána jako „vyžaduje největší důvě




