← Back
Cold Storage Collapsed

Coinkite bug allows $140 million bitcoin theft

A software flaw in Toronto-based Coinkite’s cold wallets led to a $140 million bitcoin heist, draining 1,600 bitcoins from user accounts.
By
Physical cryptocurrency tokens rest on a smartphone screen showing digital asset prices.
Foto: Symbolbild | fpmarkets.com · Symbolbild (Bildsuche: hacked cryptocurrency vault security) - nicht das Originalfoto der Quelle.
The essentials
  • Hackers exploited a bug in Coinkite's Coldcard wallets, which compromised the randomness of generated private keys.
  • The breach affected investors who chose self-custody, a method meant to protect against theft.

At 1:47 a.m. on a quiet Monday, a group of investors across three continents began receiving alerts. Their Coinkite Coldcard devices, meant to be offline and un-hackable, had been breached. Within hours, nearly 1,600 bitcoins — worth around $140 million — vanished from multiple accounts, according to Galaxy Digital research. This sudden loss caught many off guard, with users scrambling to understand what had gone wrong and how to recover what had been taken.

The flaw in the code

Coinkite, a company that has sold Coldcard hardware wallets since 2012, claimed the wallets were secure by design. But a software bug in their key generation system made the passwords easier to guess. Instead of offering trillions of possible combinations, the compromised keys only had a few thousand. This critical vulnerability allowed attackers to bypass the expected security measures and access user funds with far greater ease than intended. The flaw, which went unnoticed for years, meant that what was supposed to be a near-uncrackable system was suddenly vulnerable to brute-force attacks.

“It’s like saying the lock has a million possible settings, but it only has a thousand,” said Henry Kim, a York University associate professor. “Once you narrow it down, brute force works.” Kim’s analogy underscores the gravity of the situation — what was meant to be an impenetrable safeguard turned out to be a simple target for those with the right tools and enough computing power.

The irony of self-custody

This breach hit the most vigilant of crypto investors — those who rejected exchanges and cloud storage in favor of Coldcards. The attack exposed the hidden trust placed in the companies and coders managing the keys. Many of these investors had chosen self-custody precisely to avoid putting their money in the hands of any third party. They believed they were taking full control, but this incident showed how much reliance is still required on the company’s code and hardware.

“The whole point is you don’t need to trust anyone but yourself,” said Concordia University’s Jeremy Clark. “But this is a reminder that self-custody still requires trust in the software and the company.” Clark’s words highlight a deeper issue — the illusion of total control in cryptocurrency can be deceptive. Users may own their keys, but the integrity of those keys still depends on the company that creates them.

Chances of recovery remain slim

Authorities have yet to identify the culprits. But tracing the movement of 1,600 bitcoins may help track the hackers. Kim said converting the stolen coins to fiat discreetly won’t be easy — but not impossible. Coinkite has not offered compensation, and the stolen amount ranks outside the top 20 biggest crypto hacks by value. The company’s response so far has been minimal, with no public apology or plan for compensating victims. Galaxy Digital’s research points to the complexity of recovering such a large sum, especially given the anonymity of the transactions on the Bitcoin blockchain.

The company’s website briefly mentioned the flaw, describing it as a bug in a boundary between two unrelated submodules. No further details have been shared. This lack of transparency has left many users frustrated and questioning whether more could have been done to prevent the breach in the first place. While Coinkite’s acknowledgment of the flaw is a step forward, it does little to address the losses users have already suffered.

The float check

Coinkite has not confirmed the exact amount stolen, leaving victims unsure whether full recovery is possible.

Frequently asked questions

How did hackers get into Coinkite's wallets?

A software bug in the wallet's key generation system made private keys easier to guess, allowing brute-force attacks to steal bitcoins.

How many bitcoins were stolen?

Hackers drained 1,600 bitcoins, which were valued at about $140 million at the time of the theft.

Can victims get their money back?

Authorities have not identified the culprits, and Coinkite has not offered compensation. Recovery chances remain uncertain.

Based on reporting by Financial Post, compiled by the Tradingbird newsroom. Published 05 Aug 2026, 17:51.
Topics: Crypto · Deals · Earnings

Related

£1m a year for Pollock? Unrealistic in rugby · Markets ·

Bitcoin fork risks replay attacks · Markets ·

NY Sues Kalshi Over $36B in Illegal Gambling, Says Platform Violates State Law · Markets ·

HMRC scrutiny shakes Premier League transfer window · Markets ·

90.2% of $1.5B hack funds untraceable · Markets ·

Read this in: English · Arabiy · Deutsch · Espanol · Italiano · Portugues · Russkij · Turkce