A Growing Crisis in Hardware Security
A significant security event is currently unfolding, targeting Bitcoin users who utilized a specific firmware version on their hardware wallets. Analysts have identified a series of coordinated ‘weeps’—automated attacks designed to drain funds from victim addresses—that have been occurring since late July. The scale of the theft is staggering, with the total amount of stolen Bitcoin potentially reaching 1,816 BTC, a figure valued at approximately $114 million.
The Root Cause: A Predictable Seed Generation
The vulnerability does not stem from a direct hack of a user’s private key through traditional means, but rather from a flaw in how certain devices generated their security seeds. Investigations reveal that a firmware build released in March 2021 contained a critical error: it directed the seed generation process to a predictable software-based randomizer instead of the device’s intended hardware-based random number generator.
This mistake made the resulting private keys reproducible. Essentially, anyone capable of calculating the range of the flawed randomizer could recreate the exact same keys offline, allowing them to access and move funds without needing physical access to the user’s device.
The Mechanics of the Attack
- Targeted Addresses: The attacks primarily affect single-signature wallet setups, leaving multisig (multi-signature) configurations untouched.
- The ‘Replace-by-Fee’ Battle: In the most recent wave, attackers have been utilizing Bitcoin’s ‘eplace-by-fee’ feature. This allows an attacker to submit a transaction with a higher fee than the victim’s pending transaction, effectively jumping the queue in the mempool to steal the funds before the owner can react.
- Pattern Recognition: Researchers identified the attack by observing an unprecedented spike in transaction activity within specific blocks, noting a rate of sweeps significantly higher than normal network activity.
How to Protect Your Assets
For users of affected hardware wallets, immediate action is required to secure digital assets. Experts recommend the following steps:
- Audit Your Funds: Check any addresses generated using firmware from the March 2021 period.
- Migrate Assets: Move all funds to a new, fresh address generated with updated, secure firmware.
- Emergency Defense: If you detect an unauthorized transaction in the mempool, attempt to outbid the attacker by increasing the transaction fee immediately to secure the coins.
The manufacturer has previously released emergency firmware updates to address this specific flaw, but only for users who update their devices and migrate their funds to new, secure seeds.







