Loading market data...

Coldcard Wallet Exploit Drains Millions in Bitcoin via Weak Seed Generation

Coldcard Wallet Exploit Drains Millions in Bitcoin via Weak Seed Generation

The 25-minute heist

Galaxy Research tracked the core theft to a single 25-minute window on July 30. During that time, the attacker drained funds from hundreds of addresses in rapid succession. The speed and precision suggest automated scripts rather than manual intervention. The total stolen amount is in the tens of millions, though the exact figure may rise as more addresses are identified.

" Translation: "

25 Dakikalık Soygun

Galaxy Research, ana hırsızlığı 30 Temmuz'da tek bir 25 dakikalık zaman dilimine kadar izledi. Bu süre zarfında saldırgan, yüzlerce adresten hızlı bir şekilde fonları boşalttı. Hız ve hassasiyet, manuel müdahaleden ziyade otomatik betiklerin kullanıldığını gösteriyor. Toplam çalınan miktar on milyonlarca dolar olsa da, daha fazla adres tespit edildikçe kesin rakam artabilir.

" Third paragraph: "

Weak seeds, big consequences

The vulnerability stems from weak seed generation in certain Coldcard models. When a wallet's seed phrase is generated with insufficient entropy, an attacker can brute-force or predict the private keys. In this case, the attacker appears to have identified and targeted wallets with such weak seeds. The exploit did not affect all Coldcard users, only those whose seeds were generated under specific conditions.

" Translation: "

Zayıf Seed'ler, Büyük Sonuçlar

Güvenlik açığı, belirli Coldcard modellerinde zayıf seed üretiminden kaynaklanıyor. Bir cüzdanın seed ifadesi yetersiz entropi ile üretildiğinde, bir saldırgan özel anahtarları kaba kuvvet veya tahmin yoluyla elde edebilir. Bu durumda, saldırgan bu tür zayıf seed'lere sahip cüzdanları tespit edip hedef almış görünüyor. İstismar, tüm Coldcard kullanıcılarını etkilemedi; yalnızca belirli koşullar altında seed'leri üretilenleri etkiledi.

" Fourth paragraph: "

The broader fallout

Galaxy Research's analysis eventually linked roughly 1,196 addresses to the exploit. That number includes both the directly drained addresses and potentially related wallets. The incident raises questions about hardware wallet security standards and the responsibility of manufacturers to ensure robust entropy sources.

" Translation: "

Daha Geniş Etkiler

Galaxy Research'in analizi sonunda yaklaşık 1.196 adresi bu istismarla ilişkilendirdi. Bu sayı, doğrudan boşaltılan adresleri ve potansiyel olarak ilgili cüzdanları içeriyor. Olay, donanım cüzdanı güvenlik standartları ve üreticilerin sağlam entropi kaynakları sağlama sorumluluğu hakkında soruları gündeme getiriyor.

" Fifth paragraph: "

What comes next

Coldcard has not yet released a public statement or patch. Affected users are urged to move funds to new wallets with securely generated seeds. Security researchers are likely to publish a detailed breakdown of the exploit in the coming days. Law enforcement may also get involved given the scale of the theft.

" Translation: "

Sırada Ne Var?

Coldcard henüz resmi bir açıklama veya yama yayınlamadı. Etkilenen kullanıcıların, güvenli bir şekilde üretilmiş seed'lere sahip yeni cüzdanlara fonlarını taşımaları öneriliyor. Güvenlik araştırmacılarının önümüzdeki günlerde istismarın ayrıntılı bir analizini yayınlaması bekleniyor. Hırsızlığın boyutu göz önüne alındığında, kolluk kuvvetleri de devreye girebilir.

" Now meta description: "An attacker exploited weak seeds from certain Coldcard hardware wallets to steal tens of millions in bitcoin on July 30. Galaxy Research says the core heist lasted 25 minutes and later linked 1,196 addresses to the exploit." Translation: "Bir saldırgan, 30 Temmuz'da bazı Coldcard don