According to PANews, last weekend, a massive theft occurred in the crypto market, with 1755.95 bitcoins, worth over 110 million USD, quietly siphoned from thousands of addresses. The attacker completed the major fund transfer (over 70 million USD) about 30 hours before the official warning was released.
The attacker exploited a firmware vulnerability that had existed for about 5 years, remotely emptying thousands of single-signature wallets without physical contact with the device, phishing, or malware.

This incident stemmed from a five-year-old vulnerability. In March 2021, Coldcard released a firmware update (starting from version 4.0.1). This update contained a small programming error:
Where it was supposed to call the "hardware true random number generator," it inadvertently took another path—using the pseudorandom number generator (PRNG) in the software. Pseudorandom numbers sound impressive, but they are essentially numbers that "look random" calculated using a fixed formula. If someone knows the starting point of this formula (such as the device's serial number, startup time, etc.), they can deduce all the numbers it could potentially generate.
The result is:
There should have been about 2128 possibilities (a colossal number), but the actual effective possibilities were drastically reduced to only about 240 (which modern computers can brute-force). Thus, thousands of people were stolen from without any awareness.
The scariest aspect of this event is that most people regard hardware wallets as the last line of security for their crypto assets, capable of storing private keys offline, which has been recognized as the safest choice. After this incident, the previously generated old seeds cannot be repaired through firmware updates and remain at risk of theft (they must generate a brand new seed and migrate funds). A large number of retail investors have thus moved their funds back to centralized exchanges. On July 31 alone, centralized exchanges had a net inflow of about 11,163 bitcoins (over 11,000 coins). The main flows were: River (+3,679 coins), Binance (+3,224 coins), Kraken (+2,848 coins), OKX (+1,291 coins). Centralized entities received about 15,205 BTC from unknown addresses/retail investors. Additionally, data from CryptoQuant also shows that the total of small transactions (less than 1 BTC) reached about 39,600 BTC on the same day, nearing the levels after the FTX collapse; deposits of less than 10 BTC in exchanges reached 7,300 BTC, the highest since February this year.
This incident serves as a very important warning: In the crypto world, there has never been a solution that is absolutely secure. Security is more like a river that needs continuous maintenance rather than a sealed box. Trust must be continuously validated.
1. Treat seeds as "something that needs regular check-ups"
- Old seeds do not equal everlasting safety: even if the device is fine now, the seed generated years ago may have risks due to the firmware or entropy source quality at that time.
- Recommended practice: Evaluate whether to generate a new seed and migrate every 1-2 years. Particularly after major security incidents (like this one), actively changing seeds is more proactive than passively waiting.
- During migration, use a "small amount test → confirm accuracy → full amount transfer" process to reduce operational risks.
2. Establish a mechanism for continuous attention to "firmware and device status"
1. Do not "buy and then just throw it in the drawer."
2. Regularly (for example, every quarter) check the official website or reliable channels for:
- Any security announcements
- Whether the firmware version is outdated
- Any unusual discussions in the community
3. Subscribe to official email lists, GitHub updates, or follow reliable security researcher accounts to turn "passively waiting for notifications" into "active monitoring."
3. Use "layering + rotation" instead of single reliance
1.Single-point hardware wallets are static containers; multisig is a dynamic system.
2. Practical recommendations:
- For large funds, use 2-of-3 or 3-of-5 multisig, distributing keys across different brands and physical locations.
- Regularly rotate one of the keys (for instance, change one every year).
- Use hot wallets or exchanges for small daily funds, only putting large amounts into cold storage.
3. This way, even if one key has issues, the overall system can still survive.
4. Entropy sources should be "diversified," not solely reliant on one
1. The root of this vulnerability is "insufficient randomness in entropy."
2. Dynamic management practices:
- Proactively add personal entropy sources (dice, manual random input) when generating seeds.
- Different devices should generate using different methods.
- For important wallets, consider the "seed splitting + different entropy sources recombination" plan.
3. Do not place all hopes on "this brand's hardware will definitely produce true randomness."
5. Establish a personal "security calendar" and checklist
You can create a simple periodic check-up:
6. Incorporate "monitoring" and "alerting" into daily routines
- Use on-chain monitoring tools (such as your own node or reliable address monitoring services) to keep an eye on important addresses.
- Set alerts for unusual transactions.
- Before significant operations, confirm that the device, firmware, and backups are all in good health.
7. A shift in mindset: from "set it and forget it" to "ongoing maintenance"
True dynamic security is accepting that "nothing is forever safe" and then focusing on:
- How to discover risks faster
- How to reduce the impact of single point failures
- How to keep the system operational even when parts fail
免责声明:本文章仅代表作者个人观点,不代表本平台的立场和观点。本文章仅供信息分享,不构成对任何人的任何投资建议。用户与作者之间的任何争议,与本平台无关。如网页中刊载的文章或图片涉及侵权,请提供相关的权利证明和身份证明发送邮件到support@aicoin.com,本平台相关工作人员将会进行核查。




