Galaxy Research, which has been mapping the extent of the exploit, reports that the breach affects approximately 7,300 addresses. While the firm has confirmed three distinct waves of attacks, a potential fourth wave is currently under review. Alex Thorn, head of firmwide research at Galaxy, noted that transaction patterns in this latest activity align with earlier incidents, though victim confirmation remains pending. Notably, about 90% of the pilfered Bitcoin remains stationary in attacker-controlled wallets, providing a window for law enforcement and exchanges to monitor the funds.
The security flaw stems from a 2021 firmware update that inadvertently bypassed the device's hardware-based random number generator. Instead, affected units—including the Mk3, Mk4, Mk5, and Q models—relied on a deterministic MicroPython fallback, which drastically reduced the entropy of generated seed phrases. Independent reviews by Block’s engineering team confirmed that this error created a predictable environment for attackers to compromise private keys.

Comments (0)
No comments yet. Be the first!