Nobody Broke the Math
Nobody Broke the Math
On 10 September, police in Santa Catarina did not break a single private key. They arrived with seventeen search warrants. Four seed phrases came off devices the owners had long since lost control of. Those words went into wallet software, and 8.7 million reais moved out — roughly 1.7 million dollars at the value of the day.
Every signature the software produced was valid. The curve that secures bitcoin has not been dented, and nobody in the case claimed it had been. Santa Catarina’s Civil Police called the haul the largest seizure of its kind ever recorded among Brazil’s state civil police forces. Brazil’s Ministry of Justice published its own account the next day, with the same scope.
Read that as a story about cryptography and you learn nothing. Read it as a story about the perimeter, the boundary where a secret has to touch the world, and the whole month reorganizes itself.
Four incidents in four months share one property. A reseller Ledger had authorized for Malaysia, Indonesia and the Philippines sits under investigation after on-chain researchers traced more than 86 million dollars out of customers’ wallets. A firmware fault shipped in July produced seed phrases that could be guessed, and by one tally cost holders about 1,816 bitcoin. Close to 81,000 Trezor customers had their personal data taken from a fulfilment partner. And in Brazil the state did not attack the chain at all; it collected the words.
The lock held every time. The perimeter failed every time. Where the money sits in this industry depends on which of those two is actually the product.
The words in the drawer
ClickFix contains no exploit. A fake browser error tells the visitor to repair the problem by pasting a command into a terminal, and the command installs malware with whatever rights the account already has. Dark Reading has tracked the technique as an evolving attack vector well beyond Brazil.
It got the gang inside police systems, judiciary networks and financial-sector supply chains before it moved any crypto. Hacking the cops guarantees the cops build a crypto unit. When the Cybercrime Repression Police Station and the state investigations directorate went through the doors, they found four seed phrases on devices the criminals had already surrendered to their own malware.
An airgapped signer with a BIP39 passphrase and no digital backup of its seed was not in the room. That sentence, repeated for a decade by everyone who sells self-custody, is the countermeasure this operation validated.
Its own ledger says something the headlines did not. Police froze nearly 93 million reais, about 18.5 million dollars, in bank accounts. They also took 5 million reais of property and a Corvette worth more than 1.5 million reais. Divide the crypto by the bank accounts and the famous self-custody seizure comes to roughly nine percent of the frozen fiat [own division]. Regulated accounts remain the easier target and the larger prize.
Brazil is closing the outer fence in parallel. Central Bank Resolution 588 landed on 23 September. From 1 October it forces regulated institutions to report any transfer of 10,000 dollars or more to or from a self-custody wallet. Coaf, the financial intelligence unit, is the recipient. Law 15,358, signed in March, hands seized crypto to police re-equipment, training and special operations once a judge approves.
Put the two together and the apparatus funds itself. Each record seizure buys the technical capacity that produces the next record. Chainalysis now appears in these releases as routine equipment rather than as a breakthrough.
Authorized is not audited
CryptoBilis was no gray-market stall. Ledger listed the Kuala Lumpur company on its own reseller page as the official partner for Malaysia, Indonesia and the Philippines. On 9 October Ledger went public. It asked the reseller to pause sales and shipments. Customers who had already initialized a device were told to consider moving assets to a new signer with a newly generated seed.
The wording is precise in two directions. Ledger drew a hard line around its own house, reporting no compromise of its systems, infrastructure or services and no reports from direct purchasers. It said nothing about how funds left customer wallets. The leading theories, none of them corroborated: devices shipped with a known seed phrase, a firmware implant, or phishing against the reseller’s customer list after a data exposure.
Specter, the on-chain investigator who traced the theft addresses, put losses above 86 million dollars across bitcoin, ether and Tron. Ledger has not confirmed the figure. Hold the composition in mind as the number travels. Losses cluster in ether, Tron and dollar tokens; bitcoin-denominated losses are a fraction of the total.
The heuristic that dies here is narrower than “self-custody is unsafe”. It is this: buy from an authorized reseller when you cannot buy direct. Authorization means a business relationship was vetted — nothing more. It does not mean anyone audited the warehouse, the fulfilment staff, or the container that sat on a loading dock. Once a device leaves the manufacturer’s custody it becomes a node you cannot inspect, and a sticker on the box changes nothing about that.
Three brands, four months. Coldcard’s fault in July was worse in kind, because the device generated seeds with less entropy than intended. TRM Labs counts four waves of theft beginning 30 July. About 1,816 bitcoin left more than 5,200 addresses, and the firm valued the haul at roughly 116 million dollars. Divide one figure by the other and the price baked into that valuation is about 63,900 dollars per coin. Those same 1,816 coins are worth roughly 150 million dollars at this morning’s price [own division]. The headline was a point-in-time mark, and it will keep moving.
Trezor’s damage was data rather than coin: close to 81,000 customers exposed through a third-party fulfilment partner. No wallet drained. What got breached was a customer database, which is the point.
Probing just got cheap
Shinhan Bank says loan-application data on about 25,000 customers walked out the door: names, phone numbers, annual incomes, calculated loan limits and, for 66 people, resident registration numbers. Reuters counts at least nine South Korean banks as disclosed or reported targets since late September. South Korea’s Financial Services Commission counts more than 68,000 people affected.
CrowdStrike tied the campaign on Wednesday to an unknown actor. Tooling was ARTEX, an open-source AI penetration-testing tool built in China, running on DeepSeek v4.1-flash. Further sessions ran in Claude Code on GLM-5.3 and Grok 4.6. At Shinhan the intruder got around authentication on a mobile site that loan brokers use to check applications, then entered inquiry values at random to pull customer records. Try every door until one opens.
That is the work you hand to a machine. South Korea’s president, Lee Jae Myung, said it plainly at a cabinet meeting: his country has reached a point where AI makes hacking easy for people without special skills.
The intruder was no mastermind. CrowdStrike found open directories on infrastructure the actor controlled, stuffed with Claude Code session histories, ARTEX configuration files and a file of Chinese-language pentesting instructions. That operator asked the model where Korean breach data gets sold, then asked it for a security-researcher résumé.
Anthropic announced a cyber-defence programme the next day, with an admission worth reading twice. The cost of exploiting vulnerabilities has dropped, it said, while verifying, disclosing and fixing them stays slow and still depends on people.
Note what was never required. Nobody broke secp256k1 to read 25,000 loan files. Somebody got past the front of a loan-status page.
Shrinking institutions keep the honeypots. American depository-bank employment stood at 2,034,204 full-time equivalents in the second quarter, down 95,085 since early 2023. Wells Fargo Bank alone cut 35,494 of them. In the same quarter the bank paid 10 billion dollars of dividends on 6.85 billion dollars of net income, which is 146 percent of earnings with the difference coming out of capital. The data hoard grows while the staff guarding it does not.
The grid has a perimeter too
Executive Order 14421, signed 26 August, declares a national emergency over the bulk-power system. It invokes emergency economic powers against Chinese-origin equipment: substation transformers, grid-connected inverters, battery storage, high-voltage breakers, generation turbines and the software around them. AI data centres and defence production appear in the order as the reason a supply disruption now carries national-security weight.
Here the perimeter argument becomes measurable, and the headline points at the wrong end of it. Rystad Energy’s analysis of the twelve months to June 2026 puts China at 3 percent of American transformer imports by value and under 1 percent of circuit breakers. South Korea, Mexico and Canada together supply 74 percent of breaker imports. Markets repriced transformer risk before Washington got around to formalizing it.
Battery storage is the live exposure. China supplied about 50 percent of American lithium-ion battery imports by value in the same window, and no alternative origin can absorb that share at the volumes data centres now demand. Batteries that keep a hyperscaler rack alive through a grid event fall under the order’s storage language. Data-centre operators are not spectators to a grid security debate; they are inside the perimeter.
Everything turns on 24 December, the end of the Energy Secretary’s 120-day window to publish implementing rules. Geoffrey Hebertson is Rystad’s lead renewables analyst. If ownership is drawn broadly enough to follow Chinese capital into South Korean or Mexican assembly plants, he warns, the workaround evaporates. In his words, “the supply chain the tech industry is currently relying on to keep AI infrastructure buildout on schedule becomes part of the problem.”
Same shape as everything above. The scarce asset is not the technology inside the box. It is the chain of custody that delivers the box.
The scare story that skipped the perimeter
On Wednesday an Ethereum employee warned that bitcoin’s signatures could fall within months rather than years, and called for bunker mode. He offered no new attack, no shortcut for recovering a private key and no calculation behind the timeline. By his own account the recent AI mathematics results contain few cryptographic breakthroughs, and he raised the possibility that the missing evidence has been suppressed.
Yehuda Lindell, who runs cryptography at Coinbase, calls the episode the very definition of FUD, fear, uncertainty and doubt. He is right about the evidence. Solving hard problems elsewhere establishes no route into ECDSA. And the post ended where such posts tend to end: an advertisement for an altcoin event, from an ecosystem resting on the same signature scheme.
Here is the arithmetic that makes the timeline implausible, and it is my own. A twelve-word BIP39 seed carries 128 bits of entropy and a twenty-four-word seed carries 256. Collapsing that signature layer within a quarter would take a shortcut that strips about 105 of those 128 bits. The best known generic attack on an elliptic curve, Pollard’s rho, strips half the bits. That half is priced into the design already: secp256k1 is a 256-bit curve that carries 128-bit security [own calculation]. No published result sits within decades of orders of magnitude of that gap.

The steel-man deserves its airtime. Absence of a published attack is not absence of capability, and 2026 keeps demonstrating that capability arrives faster than disclosure. Address reuse and old pay-to-public-key outputs are genuine exposures. Bitcoin’s own developers treat post-quantum migration as a live engineering project rather than a thought experiment.
Then notice where the confirmed losses actually came from. Coldcard’s failure sat at seed generation, the deepest root of trust there is, and it still was not a break of the curve: the entropy was thin, so the search space shrank. That is the honest complication for the frame I have used throughout, because the line between perimeter and cryptography is not as clean as four October stories suggest. A perimeter failure can reach all the way inside the mathematics and take value out of it.
What is not in dispute is where the money went. Nobody in South Korea needed a cryptanalytic advance to read 25,000 loan files. Nobody in Santa Catarina needed one to use four recovered seed phrases. Nobody drained 86 million dollars through a reseller by solving a discrete logarithm.
Two figures in this piece I could not verify at the source. Ledger has confirmed no root cause, and the 86 million dollar estimate is one investigator’s tracing rather than an audited loss. Brazil’s record claim is scoped to state civil police, and the federal force may hold larger seizures.
The perimeter that cannot be patched
David Gross, who shared the 2004 Nobel Prize in Physics, gave his estimate to Live Science in April. The annual probability of nuclear war, in his view, is 2 percent, about double the Cold War baseline of 1 percent. Nine nuclear-armed states, no major arms-control treaties left, hypersonic delivery compressing decision windows from minutes to seconds, and AI inside command-and-control chains.
Compounding is worth doing properly, because the figure everyone quotes is mislabelled. A 2 percent annual hazard gives a median survival of 34.7 years, which is the 35 years Gross cites. A different, longer number is the statistical expectation: 50 years at that hazard, and 100 at 1 percent. The half-life is 35 years; the mean is 50 [own calculation]. Either way, 0.98 multiplied out over 35 years is 0.493, so a coin flip is a fair description of the next three and a half decades. Stretch it to fifty years and survival falls to 36 percent.

Now set the two perimeters beside each other. Wallets are fixable with a firmware release, a multisig, or a device bought directly from the manufacturer. The institutional perimeter that every long-duration asset is priced against cannot be patched at all. Thirty-year bonds, pension funds and infrastructure books all assume functioning governments, enforceable contracts and intact payment rails. Those are not inputs to the model. They are the model.
Bitcoin’s design answers a question those assets never ask: what settles when the state does not. Gross’s own framing exposes the limit of that hedge as well. Mining hardware, the node network and the internet backbone belong to the same civilization carrying the risk, and a true exchange would test the hedge on its own terms.
Markets have priced none of it. Bitcoin traded at 82,568 dollars this morning, my own dashboard reading at 09:30 CEST. An independent daily series puts the same day at 82,562. They agree to within a ten-thousandth, which is the only kind of cross-check worth quoting. James Check’s short-term holder SOPR printed 0.995 on 8 October, a hair under the line where recent buyers begin selling at a loss. He expects chop between 72,000 and 100,000, with a weekly close below 72,000 as the level that would break his read.

Three breaches, one reseller collapse, one national emergency over the power grid, and the price did not move on any of it. The seed phrase remains the whole security model, and it is not a number that can be made harder. It is an object that has to be kept away from everything with a network connection.
The lock was never the product
A decade of hardware-wallet marketing sold the strength of an elliptic curve. The 2026 losses were charged to paper in a drawer, a warehouse in Kuala Lumpur, a customer database at a fulfilment partner, and a loan-status page in Seoul. Only one of those businesses can be repaired by shipping a new firmware.
Write a comment