Bitcoin cold wallets drained of $70M via weak seed generation
Galaxy Research says an attacker recreated private keys offline and swept over 1,000 BTC from nearly 1,200 wallets.

A new report from Galaxy Research describes how an attacker managed to steal roughly $70 million in bitcoin from cold wallets without ever touching the physical devices. The attack relied on weak seed generation, which allowed the attacker to recreate likely private keys offline.
According to the research, the attacker swept more than 1,000 BTC from nearly 1,200 wallets. The process did not require access to the hardware or software wallets themselves, as the compromised keys were generated from predictable or insufficient randomness.
Key findings
- Over 1,000 BTC stolen, valued at about $70 million at current prices.
- Nearly 1,200 wallets were affected.
- The attacker recreated private keys offline and continued scanning for vulnerable wallets.
Galaxy Research emphasized that the attack did not exploit a bug in cold wallet hardware or software, but rather the way some users generate and store their seed phrases. Weak or reused randomness in key generation is a known risk in cryptocurrency security.
The findings serve as a reminder that cold storage is only as secure as the randomness and handling of the underlying seed. Users are generally advised to use hardware wallets that generate keys from high-entropy sources and to verify the generation process.