Homeజాతీయ వార్తలుMillions stolen from Bitcoin wallets hosted by Canada-based company

Millions stolen from Bitcoin wallets hosted by Canada-based company

Coinkite
In a statement on its website, Coinkite confirmed that funds were still at risk. Adobe Stock

Article content

Hackers have absconded with more than US$100 million ($140 million CAD) worth of Bitcoin from thousands of supposedly secure accounts in recent days, setting up another scandal for investors who have been repeatedly preyed upon by thieves in the sector.

National Post

THIS CONTENT IS RESERVED FOR SUBSCRIBERS

Enjoy the latest local, national and international news.

  • Exclusive articles by Conrad Black, Barbara Kay and others. Plus, special edition NP Platformed and First Reading newsletters and virtual events.
  • Unlimited online access to National Post.
  • National Post ePaper, an electronic replica of the print edition to view on any device, share and comment on.
  • Daily puzzles including the New York Times Crossword.
  • Support local journalism.

SUBSCRIBE FOR MORE ARTICLES

Enjoy the latest local, national and international news.

  • Exclusive articles by Conrad Black, Barbara Kay and others. Plus, special edition NP Platformed and First Reading newsletters and virtual events.
  • Unlimited online access to National Post.
  • National Post ePaper, an electronic replica of the print edition to view on any device, share and comment on.
  • Daily puzzles including the New York Times Crossword.
  • Support local journalism.

REGISTER / SIGN IN TO UNLOCK MORE ARTICLES

Create an account or sign in to continue with your reading experience.

  • Access articles from across Canada with one account.
  • Share your thoughts and join the conversation in the comments.
  • Enjoy additional articles per month.
  • Get email updates from your favourite authors.

THIS ARTICLE IS FREE TO READ REGISTER TO UNLOCK.

Create an account or sign in to continue with your reading experience.

  • Access articles from across Canada with one account
  • Share your thoughts and join the conversation in the comments
  • Enjoy additional articles per month
  • Get email updates from your favourite authors

Sign In or Create an Account

or

Article content

The latest missing money stems from a software flaw in what’s known as a “cold” Bitcoin wallet hosted by Canada-based Coinkite Inc. Cold wallets have physical hardware associated with them alongside private passwords, or “keys,” intended to add an extra layer of security beyond the typical lengthy codes that nonetheless frequently get hacked.

Article content

Article content

Article content

Yet, Coinkite notified users late last week that some wallets using its Coldcard devices had been compromised. By Monday, more than 1,755 tokens worth around US$110 million had been drained from 5,000 wallets, according to Galaxy Research.

Article content

By signing up you consent to receive the above newsletter from Postmedia Network Inc.

Article content

The breach led to an understandable level of hysteria on social media, not to mention those whose Bitcoin was suddenly, inexplicably gone.

Article content

“The moment it loaded I knew I was screwed because I saw red lines for withdrawals,” Jonathan Goodman, one of the victims, told Bloomberg News. “Between 9:36 and 9:43 p.m. on July 29th, all three of my wallets were completely drained.”

Article content

Goldman says he lost US$1.6 million due to the attack.

Article content

Here is how the hack happened, according to cryptocurrency experts and Coinkite itself.

Article content

A flaw in the software of the Coldcard devices meant that the generated “seed phrase” — a long string of words used to gain access to a wallet — was predictable, according to a report from Block Inc.’s engineering team.

Article content

The core of the issue was how Coinkite implemented the random-number generator when producing the phrases, according to Block. True randomness is a critical component of cryptographic security, but Coldcard wallets had a fallback mechanism that resulted in keys being generated using simpler values, such as the device serial numbers.

Article content

Article content

The result was that attackers have been able to systematically recalculate and drain user wallets. Reports on Friday placed losses at around US$38 million, but the figures quickly climbed over the weekend into Monday.

Article content

“It’s a reminder that self-custody is only as strong as the processes used to generate and protect private keys,” said Ayesha Kiani, chief operating officer at digital-asset investment firm Monarq Asset Management.

Article content

In a statement on its website, Coinkite confirmed that funds were still at risk. The company offered a new version of special software for customers, after some had gotten locked out of their devices.

Article content

The attack has drawn widespread attention online, with influencers to company executives weighing in on the implications.

Article content

“It exposes the fallacy of your crypto being offline,” said Aneirin Flynn, chief executive officer of cybersecurity technology firm Failsafe. “The device is just responsible for generating your passwords, and if the underlying math is broken then your passwords can be reverse-engineered.”

Article content

For 2026 so far, the amount of crypto stolen is down from last year. The first half of the year has seen total losses reach US$972 million, less than half of the US$2.3 billion stolen during the first half of 2025, according to a TRM Labs report published last month. Still, the total number of hacks climbed to 207, the highest recorded in any six-month period.

Read More

RELATED ARTICLES

LEAVE A REPLY

Please enter your comment!
Please enter your name here

Most Popular

Recent Comments