Loading market data...

Weak Seed Generation Led to Theft of Over 1,000 BTC from Cold Wallets, Galaxy Research Finds

Weak Seed Generation Led to Theft of Over 1,000 BTC from Cold Wallets, Galaxy Research Finds

How the attack worked

->

공격 방식

The attacker never needed to access the hardware wallets themselves. Instead, Galaxy Research found that the seed phrases used to generate the wallets were created with insufficient randomness. That weakness allowed the attacker to reconstruct the private keys entirely offline, then use them to move the bitcoin out of the wallets.

->

공격자는 하드웨어 지갑 자체에 접근할 필요가 없었습니다. 대신 갤럭시 리서치는 지갑 생성에 사용된 시드 문구가 충분한 무작위성 없이 생성되었다는 점을 발견했습니다. 이 취약점으로 인해 공격자는 완전히 오프라인에서 개인 키를 재구성한 다음 이를 사용하여 지갑에서 비트코인을 옮길 수 있었습니다.

Cold wallets are designed to keep private keys offline, but if the seed generation process is predictable, the keys can be recreated without ever touching the device. That's what happened here. The attacker didn't need to hack the hardware or intercept a transaction — they just needed to guess the seeds.

->

콜드월렛은 개인 키를 오프라인으로 유지하도록 설계되었지만, 시드 생성 과정이 예측 가능하다면 장치에 전혀 접촉하지 않고도 키를 재생성할 수 있습니다. 이번 사건이 바로 그 경우입니다. 공격자는 하드웨어를 해킹하거나 거래를 가로챌 필요 없이 시드를 추측하기만 하면 되었습니다.

Scope of the theft

->

도난 규모

Galaxy Research's analysis puts the total haul at more than 1,000 BTC, taken from roughly 1,200 wallets. The exact value fluctuates with bitcoin's price, but at current rates that's tens of millions of dollars. The report doesn't name the wallet manufacturer or the specific victims, but it notes the attack targeted wallets that relied on weak seed generation.

->

갤럭시 리서치의 분석에 따르면 총 탈취액은 약 1,200개의 지갑에서 빼낸 1,000 BTC 이상입니다. 정확한 가치는 비트코인 가격에 따라 변동하지만, 현재 시세로는 수천만 달러에 달합니다. 보고서는 지갑 제조사나 특정 피해자를 명시하지 않았지만, 이 공격이 취약한 시드 생성에 의존하는 지갑을 대상으로 했다고 밝혔습니다.

The attacker didn't stop after the initial sweep. Galaxy Research says the same actor kept searching for more vulnerable wallets after the first round of thefts. That suggests the attacker had automated tools to scan for wallets with predictable seeds and continued to exploit the same weakness.

->

공격자는 초기 탈취 후에도 멈추지 않았습니다. 갤럭시 리서치는 동일한 공격자가 첫 번째 도난 이후에도 더 취약한 지갑을 계속 찾았다고 말합니다. 이는 공격자가 예측 가능한 시드를 가진 지갑을 스캔하는 자동화 도구를 보유하고 동일한 취약점을 계속 악용했음을 시사합니다.

What the report means for cold wallet users

->

콜드월렛 사용자에게 주는 의미

Cold wallets are often marketed as unhackable because the private keys never touch the internet. But this case shows that the security of a cold wallet depends on how its seed phrase is generated. If the seed is created with a weak random number generator or a predictable algorithm, the keys can be compromised without any physical access.

->

콜드월렛은 개인 키가 인터넷에 노출되지 않기 때문에 해킹이 불가능하다고 종종 홍보됩니다. 그러나 이번 사례는 콜드월렛의 보안이 시드 문구가 어떻게 생성되는지에 달려 있음을 보여줍니다. 시드가 약한 난수 생성기나 예측 가능한 알고리즘으로 생성된다면 물리적 접근 없이도 키가 손상될 수 있습니다.

Galaxy Research's findings don't name a specific product or company, so it's unclear which wallets were affected. The report does serve as a warning: not all cold wallets are created equal, and users should verify that their device uses a strong, truly random seed generation process.

->

갤럭시 리서치의 조사 결과는 특정 제품이나 회사를 명시하지 않아 어떤 지갑이 영향을 받았는지 불분명합니다. 이 보고서는 경고 역할을 합니다: 모든 콜드월렛이 동일하게 만들어지는 것이 아니므로, 사용자는 자신의 장치가 강력하고 진정한 무작위 시드 생성 과정을 사용하는지 확인해야 합니다.

No arrests have been reported, and the stolen bitcoin hasn't been recovered. The attacker's continued scanning means more wallets could still be at risk. Galaxy Research hasn't said whether it shared its findings with law enforcement or the wallet makers involved.

->

체포된 사람은 보고되지 않았으며, 도난당한 비트코인은 아직 회수되지 않았습니다. 공격자의 지속적인 스캔으로 인해 더 많은 지갑이 여전히 위험에 처할 수 있습니다. 갤럭시 리서치는 조사 결과를 법 집행 기관이나 관련 지갑 제조사와 공유했는지 여부를 밝히지 않았습니다.

Now meta description: "Galaxy Research reports that an attacker stole over 1,000 BTC from nearly 1,200 cold wallets by exploiting weak seed generation, without ever touching the devices." -> Korean: "갤럭시 리서치가 약한 시드 생성을 악용해 장치에 접촉하지 않고 약 1,200개의 콜드월렛에서 1,000 BTC 이상을 훔친 공격에 대해 보고했습니다." We'll put that in meta. Now we need to output JSON. Ensure valid JSON with double quotes and escaped quotes if any.