September 20, 2026
Atlas21
ITA
podcast
news interviews learn feature industry opinion
Atlas21 B2B

Menu

Main categories

news interviews learn feature industry opinion

Secondary destinations

podcast Atlas21 B2B

Search Atlas21

Atlas21
  • ‎
No Result
View All Result
Atlas21
No Result
View All Result
Atlas21
Home Bitcoin

594 bitcoin drained in fifteen minutes: what we know so far

Federico Rivi by Federico Rivi
July 30, 2026
in Bitcoin, Feature
594 bitcoin svuotati in quindici minuti: cosa sappiamo finora
Share on FacebookShare on TwitterShare on Linkedin

In the early hours of 30 July an automated operation swept 500 single-sig addresses across four consecutive blocks. Evidence points to weak private keys generated at birth. No multisig wallet and no taproot address was among the victims.

At 01:36 UTC on Thursday 30 July, block 960188 of the Bitcoin blockchain contained the first 63 transactions of what, fifteen minutes later, would prove to be one of the most surgical thefts ever observed on-chain. Across four consecutive blocks – 960188 to 960191 – 500 transactions swept 500 distinct addresses: 1,324 UTXOs totalling 594.5 BTC, approximately 38 million dollars at current prices. By 01:51 UTC it was already over: in the same block confirming the final sweeps, the attacker had consolidated 562 BTC into a new address, where they remain at the time of writing.

Atlas21’s analysis of mempool.space data reveals the profile of a meticulously planned operation. Each sweep transaction corresponds to one victim address: 419 addresses held a single UTXO, but one had accumulated 200 and another 105 – a pattern typical of someone receiving recurring purchases or automated withdrawals from an exchange always to the same address. The median loss per victim was 0.41 BTC (roughly 26,500 dollars); 110 victims lost more than 1 BTC and the hardest hit lost 29.9, nearly 2 million dollars. One figure stands out: no victim lost less than 0.15 BTC. This suggests the attacker may have filtered targets by minimum balance. The entire operation cost approximately 0.044 BTC in fees.

The first public alarm came from a victim. At 13:19 UTC a user posted on Reddit a thread titled “Full panic – one of my wallets was drained”. Their account was reconstructed in the comments: a Coldcard bought in 2021, a 24-word mnemonic seed phrase generated on the device, savings transferred onto it and then years of silence. In January 2025 they bought a second Coldcard and re-entered the 2021 mnemonic, “to make sure the words were right”. The seed, they explained, had never touched a computer – only the device, a watch-only wallet on Sparrow, and automated withdrawals from an exchange always to the same address. That night the address was swept along with the other 499.

Four hours later, the alarm

At 17:35 UTC Kevin Loaec, co-founder of Wizardsardine (the company behind the Liana wallet), publicly asked his followers with a Coldcard to check their balances: “Hoping this is a nothing-burger but doing my job here.” An hour and a half later the tone shifted: “This is not a drill.” Confirmation came from well-known names in the ecosystem: grubles, a community veteran, confirmed one case; Jameson Lopp reported partial thefts – wallets from which only some UTXOs had been taken, not the entire balance. Loaec noted that among the victims were “multiple real and known bitcoiners”: the theory of a single careless user no longer held.

The word Coldcard was by then at the centre of the conversation. NVK, founder and CEO of Coinkite, the company that makes the device, responded at 18:10: “No need to panic – someone loaded a compromised seed onto a Coldcard and/or their seed leaked. This is part of a broader attack involving 500 private keys from different wallets.” At this point no evidence exists of a flaw in Coldcard’s random number generator.

The weak entropy hypothesis

The first systematic on-chain analysis came from Rob Hamilton, CEO of AnchorWatch: 1,324 UTXOs swept, he noted, dated from 2021 to 2026, all from single-sig addresses, not one taproot. His conclusion: “At first glance, it appears there was faulty entropy in wallet generation somewhere along the path.” This is also the hypothesis that holds up best against our own data. If private keys were generated with a weak random number generator – in a software library, a secure element, a specific production batch of devices, or a specific firmware version – an attacker can recompute them one by one without needing to compromise the victims’ devices directly.

It has happened before: in 2023 the Milk Sad case exposed wallets created with Libbitcoin Explorer, which used the timestamp as its sole source of entropy, and the Randstorm disclosure revealed that millions of browser wallets generated between 2011 and 2015 with BitcoinJS were potentially recomputable. Just three weeks ago, on 10 July, security firm Coinspect disclosed Ill Bloom: five wallet implementations with weak seed generation, 5.1 million dollars already stolen and a coordinated sweep of 431 wallets within hours on 27 May. The structural resemblance to the 30 July operation is clear, even though Coinspect excludes hardware wallets from the Ill Bloom scope and no researcher has so far linked the two events.

Loaec pushed the theory further: a weak RNG “in a library or in the secure element itself” and an attacker who understands the vulnerability but does not know Bitcoin deeply – to the point of using a script “written with AI” that derives only BIP84 paths (native segwit) to a limited depth. That would explain the partial thefts reported by Lopp. The on-chain data collected by Atlas21 confirms the picture almost entirely, with one nuance: 490 of the 500 swept addresses are indeed native segwit, but there are also 5 legacy addresses and 5 nested segwit. The structure of the attack itself – one transaction per address rather than one per wallet – is consistent with someone who possesses individual recomputed private keys rather than fully reconstructed seeds. The data also allow one hypothesis to be ruled out, at least for some victims: nonce reuse in signatures, the vector that has drained wallets after outgoing transactions in the past, cannot apply to dormant wallets that have never signed anything.

Until the exact cause is known, the countermeasures circulating in recent hours should be taken for what they are: risk reduction, with a margin of uncertainty. Loaec warns that even passphrases and dice-rolled seed generation are not certain guarantees while the vector remains unknown, and recommends multisig, preferably multi-vendor: whatever happened, not a single multisig is among the 1,324 stolen UTXOs. Lopp is asking anyone who discovers shortfalls to report them in order to widen the sample. Anyone holding funds on single-sig wallets generated under even questionable conditions – particularly between 2021 and today – has a concrete reason to migrate to a new setup with a seed generated elsewhere.

562 BTC remain unmoved on the consolidation address, with another 32 on the intermediate address. The attacker has not yet moved a single satoshi toward an exchange or mixer: the next movement of those funds will be the first real trace of who holds those keys.

Previous Post

Pavel Durov and the price of non-compliant communication

Next Post

Coldcard bug, weak seeds generated since 2021: “Funds are at risk, move them now”

Latest News

Facciata del Conseil d’État al Palais Royal di Parigi con bandiere francesi
Bitcoin

Conseil d’État rejects suspension of DAC8 decree

by Newsroom
September 17, 2026
0

The court rejects Bull Bitcoin and Paymium’s request for lack of urgency, without examining the decree’s legality.

Read moreDetails
stablecoin
Industry

Deutsche Bank prepares digital asset custody

by Newsroom
September 17, 2026
0

The service is planned by the end of 2026 for European institutional and corporate clients

Read moreDetails
View of an industrial power plant through a chain-link fence at sunrise, symbolizing energy and industry
Bitcoin

Ethiopia cuts electricity for Bitcoin miners to 23%

by Newsroom
September 17, 2026
0

According to Bloomberg, EEP cut supplies to prioritise households and producers

Read moreDetails
View of the US Capitol Building in Washington D.C. during sunset, highlighting its iconic architecture
Bitcoin

US House committee advances strategic Bitcoin reserve

by Newsroom
September 17, 2026
0

The bill requires Bitcoin in the reserve to be held for at least 20 years

Read moreDetails
Non sei indagato, ma i tuoi spostamenti sono già tracciati.
Industry

You are not under investigation, but your movements are already tracked.

by Lucia Mozzato
September 15, 2026
0

Flock Safety sells an easy promise to share: helping police recover a stolen car, locate a missing person, solve a...

Read moreDetails
Atlas21

© 2026 Atlas21

Navigate Site

  • Editorial Policy
  • Cookie Policy
  • Privacy Policy
  • Team
  • Podcast
  • Home redesign preview

Follow Us

Atlas21
News Interviews Learn Feature Industry Opinion Podcast Atlas21 B2B

Social

X Instagram Nostr LinkedIn YouTube

Contact us

[email protected] Privacy Cookie

The rabbit hole has no bottom.

© 2026 Atlas21. All rights reserved.

No Result
View All Result
  • Bitcoin 101
    • What Is Bitcoin? A Complete Guide
    • Bitcoin Security: A Complete Guide
    • Bitcoin Privacy: A Complete Guide
    • Lightning Network: A Complete Guide
    • Bitcoin Mining: A Complete Guide
    • Advanced Bitcoin: A Technical Guide
  • Learn
  • Latest News
  • Interviews
  • Opinion
  • Feature
  • Podcast
  • B2B Services
  • About Us
  • Contacts

© 2026 Atlas21

We use cookies to ensure that we give you the best experience on our website. If you continue to use this site, we will assume that you are happy with it.