The first sweep began July 30 and removed 1,083 BTC from 1,196 addresses within 41 minutes. Two weekend waves raised observed losses to 1,367 BTC across 4,585 addresses. The fourth wave lifted the possible total to about 1,816 BTC from more than 5,200 addresses. Thorn tracked activity across blocks 960,778 through 960,792.
Researchers counted 218 transactions that targeted 462 victim addresses. The wave averaged about 14 sweeps per block, compared with 0.3 during a pre-incident control period. The flaw traces to a March 2021 firmware build. That software sent seed generation to a predictable software randomizer rather than to the wallet chip’s hardware randomizer.
As a result, anyone who identifies the relevant range can reproduce affected keys offline. Coinkite released emergency firmware for all affected models after the flaw was discovered. The manufacturer also told users who created seeds with the flawed software to move funds. They must use wallet addresses generated from fresh seeds.
Also Read:
