Loading market data...

Coldcard Hack Drains $88.6M in Bitcoin as Galaxy Research Ties Breach to 2021 Seed Flaw

Coldcard Hack Drains $88.6M in Bitcoin as Galaxy Research Ties Breach to 2021 Seed Flaw

The July 29 attack

" -> "

29 जुलाई का हमला

" Paragraph: "The Canadian victim's wallet was emptied fast — 18.25 BTC gone in less than seven minutes. That speed points to a precomputed list of vulnerable seeds rather than a real-time crack. Galaxy Research's on-chain analysis shows the stolen Bitcoin hasn't moved since; it sits in attacker-controlled addresses. The firm hasn't confirmed whether insufficient randomness in the seed generation is the root cause, but its findings rely entirely on on-chain data." Translation: "कनाडाई पीड़ित का वॉलेट तेजी से खाली किया गया — 18.25 BTC सात मिनट से भी कम समय में गायब हो गया। यह गति वास्तविक समय में क्रैक करने के बजाय संवेदनशील सीड्स की पहले से गणना की गई सूची की ओर इशारा करती है। Galaxy Research के ऑन-चेन विश्लेषण से पता चलता है कि चुराए गए बिटकॉइन तब से नहीं हिले हैं; यह हमलावर-नियंत्रित पतों में बैठा है। फर्म ने पुष्टि नहीं की है कि सीड जनरेशन में अपर्याप्त यादृच्छिकता मूल कारण है, लेकिन इसके निष्कर्ष पूरी तरह से ऑन-चेन डेटा पर आधारित हैं।" Next: "

How the vulnerability works

" -> "

भेद्यता कैसे काम करती है

" Paragraph: "Coldcard's default seed-generation method is described in the device's manual as 'involves the most trust' yet also 'low risk to users.' The 2021 code flaw apparently made some seeds predictable enough that AI-assisted brute-forcing became feasible. Alternatives exist — users can combine the hardware's output with dice rolls to remove trust in the hardware — but most users likely followed the default path. Galaxy hasn't publicly identified which specific Coldcard firmware versions are affected, but the attack waves suggest a broad exposure." Translation: "Coldcard की डिफ़ॉल्ट सीड-जनरेशन विधि को डिवाइस के मैनुअल में 'सबसे अधिक भरोसे वाली' फिर भी 'उपयोगकर्ताओं के लिए कम जोखिम' बताया गया है। 2021 की कोड खराबी ने स्पष्ट रूप से कुछ सीड्स को इतना पूर्वानुमानित बना दिया कि AI-सहायता प्राप्त ब्रूट-फोर्सिंग संभव हो गई। विकल्प मौजूद हैं — उपयोगकर्ता हार्डवेयर के आउटपुट को पासा रोल के साथ जोड़कर हार्डवेयर पर भरोसा हटा सकते हैं — लेकिन अधिकांश उपयोगकर्ताओं ने संभवतः डिफ़ॉल्ट मार्ग का पालन किया। Galaxy ने सार्वजनिक रूप से यह नहीं बताया है कि कौन से विशिष्ट Coldcard फर्मवेयर संस्करण प्रभावित हैं, लेकिन हमले की लहरें व्यापक जोखिम का सुझाव देती हैं।" Next: "

Who was hit

" -> "

कौन प्रभावित हुआ

" Paragraph: "The drained holdings had sat dormant for an average of 3.18 years, meaning most victims were long-term holders — the kind of users who buy a hardware wallet and forget about it. The 4,585 source addresses span