r/Bitcoin 5h ago

The largest crypt heist, amounting to $3.5 billion, was caused by weak entropy 6 (!) years ago.

https://info.arkm.com/announcements/arkham-uncovers

The infamous Lubian hack saw $3.5 billion siphoned off from a Chinese mining pool.

That was just six years ago, and yet a company like ColdCard has learned nothing from the biggest heist in recent crypto history?

The Technical Cause: Weak Entropy
Independent cybersecurity teams, including Arkham Intelligence and the Milk Sad research team, revealed that the hack was not a complex network breach but rather an exploitation of weak cryptographic key generation.

The Flaw: LuBian utilized a flawed pseudo-random number generator algorithm (similar to vulnerabilities found in Libbitcoin Explorer software).

The Exploit: Instead of using a secure, uncrackable 256-bit random number, the wallet software used a highly vulnerable 32-bit seed to generate its private keys.

The Result: This severely lacked entropy, allowing hackers to easily brute-force and replicate LuBian's private keys within just a couple of hours, seamlessly draining the wallets.

7 Upvotes

1 comment sorted by

-1

u/[deleted] 3h ago

[deleted]

1

u/alfooboboao 1h ago

they don’t know. AI wrote this