Hackers drain 594 BTC from 500 wallets by exploiting weak seed phrases
Hackers have stolen 594 BTC from about 500 wallets, apparently by targeting weak or guessable seed phrases rather than exploiting a flaw in the wallets themselves.
Blockchain analysts at Atlas21 said the attackers swept 1,324 UTXOs (unspent transaction outputs) during the operation. The funds have not been sent to an exchange or a crypto mixer so far: 562 BTC now sits at a newly created address, with another 32 BTC parked at an intermediate address.
On-chain patterns show each transaction drained exactly one victim address. While 419 of the compromised addresses contained just a single UTXO, others held as many as 105 or 200 UTXOs. The median loss per victim was 0.41 BTC (about $26,500). A total of 110 victims lost more than 1 BTC, and the largest loss reached 29.9 BTC (nearly $2 million). No victim lost less than 0.15 BTC, leading security researchers to believe the attackers screened for wallets above a minimum balance.
The incident drew wider attention after a Reddit blogger reported his own theft. He said he bought a Coldcard hardware wallet in 2021, generated a 24-word seed phrase directly on the device, transferred funds in, then left the wallet untouched for years. In January last year, he purchased a second Coldcard and re-entered the old seed phrase "to verify that the words were correct." He said he never shared the phrase and used it only on Coldcard devices.
Coinkite has since acknowledged a security issue involving seed phrases generated on Coldcard Mk3 units. The company advised users who created a seed phrase on an Mk3 running firmware 4.0.1 (released in March 2021) or any later version to assume their funds may be compromised. Coinkite said the Mk4, Q, and Mk5 models are not affected.
For Mk3 owners, Coinkite recommends generating a unique BIP39 passphrase on the device and moving funds to a new wallet. The company added that the root cause of the vulnerability has not yet been identified. It is confirmed that none of the affected wallets were multisignature.
Atlas21 analysts argue the core issue may lie in weak seed phrases: users may have imported already compromised or easily guessable word combinations into their devices. Security experts said that, with "insufficient randomness" in seed phrase generation, private keys for individual UTXOs could be bruteforced—which appears to be what happened.
Separately, Singapore-based TripleA, a provider of payment infrastructure for stablecoins and other cryptocurrencies, recently disclosed it suffered a cyberattack, with losses estimated at $11.8 million.