Remote Attack Drains $70M From Cold Storage Wallets

How bitcoin cold wallets lost $70 million in an attack that never touched the devices
The information provided does not include the underlying details needed to write a factual news story. Beyond the headline and the stated loss amount, there are no specifics describing who was affected, when it happened, how the attack worked, what evidence supports the conclusion, or which wallets and operational processes were involved.
To produce a clean, accurate article “based strictly on the provided description” and “without speculation,” the following minimum facts are required:
- Victim details: individual, company, exchange, custodian, or group of users affected.
- Timeline: date of discovery, date(s) of unauthorized transactions, and any disclosures.
- Attack vector: what “never touched the devices” means in practice (e.g., seed phrase compromise, address replacement, signing workflow manipulation, supply-chain issue, social engineering).
- Mechanism of loss: how funds moved on-chain (transaction type, destination, whether consolidations occurred).
- Attribution and evidence: source of the $70 million figure and any on-chain analysis or official statements.
- Security model: what “cold wallet” setup was used (hardware wallet, air-gapped computer, multisig, institutional custody).
- Response: steps taken after discovery (incident response, law enforcement, freezing attempts if any, user notifications).
If you paste the raw content (even as bullet points, a link excerpt, or notes), I can turn it into a structured news article that explains what happened, why it matters, and the broader context—while staying strictly within the sourced facts and avoiding hype or guesswork.
