Loading market data...

Coldcard Hack Drains $88.6M in Bitcoin as Galaxy Research Ties Breach to 2021 Seed Flaw

Coldcard Hack Drains $88.6M in Bitcoin as Galaxy Research Ties Breach to 2021 Seed Flaw

and

. We need to translate each paragraph. First paragraph: "A Canadian entrepreneur lost 18.25 Bitcoin — worth roughly $1.6 million — from a Coldcard hardware wallet in under seven minutes on July 29, 2026. The theft is part of a much larger pattern: Galaxy Research has identified three suspected attack waves targeting Coldcard-generated addresses, draining 1,367.05 BTC (about $88.6 million) from 4,585 source addresses. The vulnerability, the firm says, traces back to a 2021 flaw in the code that generates seed phrases, with attackers allegedly using AI to brute-force affected seeds." Translation: "一名加拿大企业家在 2026 年 7 月 29 日不到七分钟内从 Coldcard 硬件钱包中损失了 18.25 个比特币(约合 160 万美元)。这起盗窃案是一个更大模式的一部分:Galaxy Research 已识别出三波疑似攻击浪潮,针对 Coldcard 生成的地址,从 4,585 个源地址中盗取了 1,367.05 BTC(约 8860 万美元)。该公司表示,该漏洞追溯到 2021 年生成种子短语的代码缺陷,攻击者据称使用人工智能暴力破解受影响的种子。" We need to keep numbers and facts. Use "约合" for roughly. "under seven minutes" -> "不到七分钟". "part of a much larger pattern" -> "是一个更大模式的一部分". "three suspected attack waves" -> "三波疑似攻击浪潮". "targeting Coldcard-generated addresses" -> "针对 Coldcard 生成的地址". "draining" -> "盗取". "source addresses" -> "源地址". "traces back to" -> "追溯到". "flaw in the code that generates seed phrases" -> "生成种子短语的代码缺陷". "with attackers allegedly using AI to brute-force affected seeds" -> "攻击者据称使用人工智能暴力破解受影响的种子". Second paragraph: "The Canadian victim's wallet was emptied fast — 18.25 BTC gone in less than seven minutes. That speed points to a precomputed list of vulnerable seeds rather than a real-time crack. Galaxy Research's on-chain analysis shows the stolen Bitcoin hasn't moved since; it sits in attacker-controlled addresses. The firm hasn't confirmed whether insufficient randomness in the seed generation is the root cause, but its findings rely entirely on on-chain data." Translation: "加拿大受害者的钱包很快被清空——不到七分钟内 18.25 BTC 不翼而飞。这种速度表明攻击者使用的是预先计算好的易受攻击种子列表,而非实时破解。Galaxy Research 的链上分析显示,被盗的比特币此后一直没有移动,仍存放在攻击者控制的地址中。该公司尚未确认种子生成过程中随机性不足是否是根本原因,但其调查结果完全依赖于链上数据。" Note: "precomputed list" -> "预先计算好的列表". "real-time crack" -> "实时破解". "on-chain analysis" -> "链上分析". "hasn't moved since" -> "此后一直没有移动". "sits in attacker-controlled addresses" -> "存放在攻击者控制的地址中". "insufficient randomness" -> "随机性不足". "root cause" -> "根本原因". "rely entirely on on-chain data" -> "完全依赖于链上数据". Third paragraph: "Coldcard's default seed-generation method is described in the device's manual as 'involves the most trust' yet also 'low risk to users.' The 2021 code flaw apparently made some seeds predictable enough that AI-assisted brute-forcing became feasible. Alternatives exist — users can combine the hardware's output with dice rolls to remove trust in the hardware — but most users likely followed the default path. Galaxy hasn't publicly identified which specific Coldcard firmware versions are affected, but the attack waves suggest a broad exposure." Translation: "Coldcard 的默认种子生成方法在设备手册中被描述为“涉及最多的信任”,但也“对用户风险较低”。2021 年的代码缺陷显然使一些种子变得可预测,以至于 AI 辅助暴力破解成为可能。存在替代方案——用户可以将硬件输出与掷骰子相结合,以消除对硬件的信任——但大多数用户可能遵循了默认路径。Galaxy 尚未公开确认哪些具体的 Coldcard 固件版本受到影响,但攻击浪潮表明暴露范围广泛。" We need to preserve quotes. Use Chinese quotes “”. Also "dice rolls" -> "掷骰子". "remove trust" -> "消除信任". "broad exposure" -> "暴露范围广泛". Fourth paragraph: "The drained holdings had sat dormant for an average of 3.18 years, meaning most victims were long-term holders — the kind of users who buy a hardware wallet and forget about it. The 4,585 source addresses span three distinct attack waves, though Galaxy hasn't said when the first wave began. The Canadian entrepreneur's case is the most recent confirmed victim, but the total haul of 1,367.05 BTC makes this one of the larger hardware-wallet breaches on record." Translation: "被盗的资产平均已闲置 3.18 年,这意味着大多数受害者是长期持有者——即购买硬件钱包后便将其遗忘的用户