594 BTC vanished in a single 25-minute sweep because a hardware wallet was generating seed phrases that were never truly random to begin with.

A critical flaw discovered in a major Bitcoin hardware wallet has already drained $38 million from unsuspecting holders, and the method of attack is the kind that keeps cryptographers up at night. The wallet's random number generator, the engine responsible for making your seed phrase statistically impossible to guess, was broken. That means seeds it generated were not random. They were patterned. And someone figured out the pattern.

How the Attack Worked

Seed phrases derive their security from entropy, pure randomness that makes brute-forcing them computationally impossible. When that entropy is compromised, the math collapses entirely. Attackers do not need to guess billions of combinations. They need to guess from a dramatically smaller pool of predictable outputs.

Once the flaw was identified, the sweep was surgical. 594 BTC moved out of affected wallets in 25 minutes flat. No phishing. No social engineering. No user error. Just math working against wallets that were silently vulnerable from the moment they were set up.

Why This Is Worse Than a Standard Exploit

Most crypto hacks require the victim to do something wrong: click a bad link, sign a malicious transaction, connect to a rogue site. This one did not. Holders who followed every best practice, wrote down their seed phrase, kept it offline, never shared it, were still exposed. The vulnerability lived inside the device they trusted most.

That distinction matters enormously. It means affected users had no behavioral warning signs to look back on. No moment where they made a mistake. Their security was an illusion from day one.

The Scope Is Still Unknown

The $38 million figure reflects confirmed losses so far. Security researchers have not yet established how many wallets were produced with the flawed firmware, which generation of devices is affected, or whether the attacker has exhausted their target list. The 25-minute window suggests automation, meaning whoever built this tool can run it again.

What You Should Do Right Now

If you own a hardware wallet, the immediate priority is identifying whether your device and firmware version fall within the affected range. Do not wait for official guidance to trickle through support channels.

If your wallet is confirmed vulnerable, do not simply transfer funds from the compromised device to a new address generated by the same hardware. Generate a fresh seed on a verified, patched device and move funds from there.

Hardware wallets have long been positioned as the gold standard of self-custody. This incident is a direct challenge to that assumption. Watch for the official patch timeline, watch for the confirmed device list, and treat any hardware wallet with unverified firmware as a liability until proven otherwise.