Hack Drains $110M from Coinkite Cold Wallets; Security Alert

Hackers exploited a software bug to rebuild seed phrases and drain over $110M in Bitcoin from Coinkite cold wallets. The breach affected thousands of hardware wallets and triggered an AI-driven security audit.

.
Hack Drains $110M from Coinkite Cold Wallets; Security Alert

2 Minutes

Follow on Google

Massive Bitcoin Theft Hits Coinkite Cold Wallets

Hackers have stolen more than $110 million in Bitcoin from thousands of cold wallets tied to Canadian firm Coinkite, highlighting persistent risks in self-custody and hardware wallet ecosystems. Despite users holding physical hardware keys and believing their funds were secure, attackers accessed wallets by exploiting a software vulnerability that allowed reconstruction of seed phrases.

Timeline and scope of the breach

According to public reports, one victim, Jonathan Goodman, said all three of his cold wallets were emptied within a seven-minute window — between 9:36 and 9:43 PM on July 29. Research group Galaxy Research estimates roughly $110 million in Bitcoin was withdrawn from about 5,000 wallets last week, a figure that rose to at least 7,300 wallets by the following Monday. The incident underscores systemic security gaps in the decentralized crypto industry.

How the attackers reconstructed seed phrases

Coinkite warned customers on July 30 that attackers were abusing a software bug to rebuild seed phrases — the mnemonic word lists that serve as master keys for cold or offline wallets. By reconstructing these seed phrases, attackers could bypass hardware wallet protections and transfer Bitcoin out of supposedly secure wallets.

Company response and ongoing investigation

Coinkite has said it is working with affected users and has launched an ecosystem-level security audit. The company is leveraging advanced AI-driven models during the investigation and claims these reviews have already uncovered multiple critical bugs in key software components. Coinkite declined to provide an exact damage estimate and deferred a full loss assessment to a later date.

Legal and operational consequences

As a result of legal obligations and the need to preserve evidence for potential litigation, Coinkite has temporarily suspended the automated deletion of user data; those records will be retained until further notice. This measure aims to support investigations and any future legal claims by victims.

What users should do now

Users should assume at-risk wallets may be compromised. Recommended steps include moving remaining funds to new hardware wallets with fresh seed phrases generated in a secure environment, using multi-signature setups, and monitoring blockchain addresses for suspicious activity. This breach is a stark reminder that even hardware wallets and cold storage depend on robust software integrity and secure seed management.

Zoya Akhtar
"I’m Zoya, and crypto is my playground. I dive deep into blockchain trends, DeFi, and how digital assets shape our future economy."

Leave a Comment

Comments

No comments yet. Be the first.