Massive Bitcoin Theft Hits Coinkite Cold Wallets
Hackers have stolen more than $110 million in Bitcoin from thousands of cold wallets tied to Canadian firm Coinkite, highlighting persistent risks in self-custody and hardware wallet ecosystems. Despite users holding physical hardware keys and believing their funds were secure, attackers accessed wallets by exploiting a software vulnerability that allowed reconstruction of seed phrases.
Timeline and scope of the breach
According to public reports, one victim, Jonathan Goodman, said all three of his cold wallets were emptied within a seven-minute window — between 9:36 and 9:43 PM on July 29. Research group Galaxy Research estimates roughly $110 million in Bitcoin was withdrawn from about 5,000 wallets last week, a figure that rose to at least 7,300 wallets by the following Monday. The incident underscores systemic security gaps in the decentralized crypto industry.
How the attackers reconstructed seed phrases
Coinkite warned customers on July 30 that attackers were abusing a software bug to rebuild seed phrases — the mnemonic word lists that serve as master keys for cold or offline wallets. By reconstructing these seed phrases, attackers could bypass hardware wallet protections and transfer Bitcoin out of supposedly secure wallets.

Company response and ongoing investigation
Coinkite has said it is working with affected users and has launched an ecosystem-level security audit. The company is leveraging advanced AI-driven models during the investigation and claims these reviews have already uncovered multiple critical bugs in key software components. Coinkite declined to provide an exact damage estimate and deferred a full loss assessment to a later date.
Legal and operational consequences
As a result of legal obligations and the need to preserve evidence for potential litigation, Coinkite has temporarily suspended the automated deletion of user data; those records will be retained until further notice. This measure aims to support investigations and any future legal claims by victims.
What users should do now
Users should assume at-risk wallets may be compromised. Recommended steps include moving remaining funds to new hardware wallets with fresh seed phrases generated in a secure environment, using multi-signature setups, and monitoring blockchain addresses for suspicious activity. This breach is a stark reminder that even hardware wallets and cold storage depend on robust software integrity and secure seed management.




Leave a Comment
Comments
No comments yet. Be the first.