At 1:47 a.m. on a quiet Monday, a group of investors across three continents began receiving alerts. Their Coinkite Coldcard devices, meant to be offline and un-hackable, had been breached. Within hours, nearly 1,600 bitcoins — worth around $140 million — vanished from multiple accounts, according to Galaxy Digital research. This sudden loss caught many off guard, with users scrambling to understand what had gone wrong and how to recover what had been taken.
The flaw in the code
Coinkite, a company that has sold Coldcard hardware wallets since 2012, claimed the wallets were secure by design. But a software bug in their key generation system made the passwords easier to guess. Instead of offering trillions of possible combinations, the compromised keys only had a few thousand. This critical vulnerability allowed attackers to bypass the expected security measures and access user funds with far greater ease than intended. The flaw, which went unnoticed for years, meant that what was supposed to be a near-uncrackable system was suddenly vulnerable to brute-force attacks.
“It’s like saying the lock has a million possible settings, but it only has a thousand,” said Henry Kim, a York University associate professor. “Once you narrow it down, brute force works.” Kim’s analogy underscores the gravity of the situation — what was meant to be an impenetrable safeguard turned out to be a simple target for those with the right tools and enough computing power.
The irony of self-custody
This breach hit the most vigilant of crypto investors — those who rejected exchanges and cloud storage in favor of Coldcards. The attack exposed the hidden trust placed in the companies and coders managing the keys. Many of these investors had chosen self-custody precisely to avoid putting their money in the hands of any third party. They believed they were taking full control, but this incident showed how much reliance is still required on the company’s code and hardware.
“The whole point is you don’t need to trust anyone but yourself,” said Concordia University’s Jeremy Clark. “But this is a reminder that self-custody still requires trust in the software and the company.” Clark’s words highlight a deeper issue — the illusion of total control in cryptocurrency can be deceptive. Users may own their keys, but the integrity of those keys still depends on the company that creates them.
Chances of recovery remain slim
Authorities have yet to identify the culprits. But tracing the movement of 1,600 bitcoins may help track the hackers. Kim said converting the stolen coins to fiat discreetly won’t be easy — but not impossible. Coinkite has not offered compensation, and the stolen amount ranks outside the top 20 biggest crypto hacks by value. The company’s response so far has been minimal, with no public apology or plan for compensating victims. Galaxy Digital’s research points to the complexity of recovering such a large sum, especially given the anonymity of the transactions on the Bitcoin blockchain.
The company’s website briefly mentioned the flaw, describing it as a bug in a boundary between two unrelated submodules. No further details have been shared. This lack of transparency has left many users frustrated and questioning whether more could have been done to prevent the breach in the first place. While Coinkite’s acknowledgment of the flaw is a step forward, it does little to address the losses users have already suffered.

