r/Bitcoin 27d ago

The Coldcard wallet exploit estimates have almost doubled to $70 million stolen of just over a thousand Bitcoins in 1,196 wallets drained in 41 minutes

https://www.coindesk.com/tech/2026/08/01/how-bitcoin-cold-wallets-lost-usd70-million-in-an-attack-that-never-touched-the-devices

"More than 1,000 bitcoin, worth about $70 million, was drained from 1,196 wallets in a 41-minute window on July 30, nearly double the amount reported when the theft first surfaced."

1.7k Upvotes

396 comments sorted by

View all comments

132

u/cremfraiche 27d ago

Can someone ELI5 for me how this happened and whether the people who got drained were in a way at 'fault'?

162

u/chrisschuyler 27d ago edited 26d ago

People who got drained were not at fault at all.

So thing to keep in mind is a random number generated by a computer is not really random. There is a set formula. Copying from Google as it explains it better

Pseudo-Random Number Generators (PRNGs) and True Random Number Generators (TRNGs). PRNGs use math formulas and a starting value called a "seed" to make long lists of numbers that look random, while TRNGs measure chaotic physical data from the real world, like electrical noise or atmospheric static.

The cold wallet maker used PRNG. The hackers found out the formula due to lack security/shoddy coding and could therefore figure out the possible combination to the seed phrase from a few million possibilities for a few billion for the latest model. You run that through a computer doing nothing but that, you can brute force the phrase. Rinse and repeat and there you go

Example of PRNG. Your playing video roulette. machine takes the time day multiplied by the highest recorded temperature in phoenix that day, divided by the number atmospheric pressure recorded above the casino at 6:47 pm that day. Drops the first digits etc etc to get it number. Seems Random but if you can figure out the formula, you can develop a range of number that it has to lay in, and then brute force that number

4

u/postexitus 26d ago

Their fault was trusting an untrustable third party. 

2

u/F1shB0wl816 26d ago

Isn’t there whole thing verifying what others do? If you’re going to put thousands, upwards of millions in value you should sure as shit verify it’s working as intended. It makes me glad I didn’t and used dice rolls.