Masterplan: Villains steal 38 million dollars in Bitcoin in 25 minutes

Symbolbild Hacker, Bitcoin

Bitcoin are considered safe by many when they are in their wallet. However, hackers have now emptied 500 wallets.

It sounds like the plot of a movie but is real. In one of the largest Bitcoin heists of all time, several wallets were emptied. The criminals managed to grab Bitcoin worth around 38 million US dollars (about 33 million euros). This was possible due to a security flaw at a wallet provider, whose random encryption was not so random after all.

Start video
In Germany, there are over 400 USB sticks protruding from walls – What is the ‘Dead Drops’ project?

What happened? According to the magazine Dexerto, a devastating incident occurred at the company Coldcard. Coldcard is a provider of hardware wallets. These are essentially small devices that store the access keys for Bitcoin. These devices do not have internet access and are thus protected from hacking attacks. They are only used when connected to the PC to facilitate access to the respective wallet.

The provider has several variants of the model, and the Mk3 version had quite a serious flaw.

In fact, the wallets are usually protected with the devices using a chain of words consisting of 24 random terms. However, in the Mk3 version, there was a faulty – the chip responsible for greater randomness was skipped during password generation.

Recommended editorial content

At this point you will find external content from Twitter that complements the article.

I consent to external content being displayed to me. Personal data can be transmitted to third party platforms. Read more about our privacy policy.
Link to the Twitter content

Brute Force could crack 500 wallets

This meant that the underlying basis for the code (the “seed”) was created by simpler software that used the serial number of the chip and the current time. This information was not secret. Therefore, hackers could then commission an artificial intelligence to simply try a large number of possible combinations (“Brute Force”) to obtain the passwords associated with the wallets.

The flaw existed for over 5 years. The entire operation of emptying the wallets only took 25 minutes, after which the 500 wallets were emptied, and the Bitcoin was transferred.

The anonymity of transactions in Bitcoin is considered one of its great strengths but also one of its biggest security risks since purchases cannot be traced – and thefts like this one cannot either.
That AI is not only suitable for hacking but also to earn legal money, is proven by a 19-year-old – who now explains AI to boomers for 100,000 dollars a year.

This is an AI-powered translation. Some inaccuracies might exist.