How a Canadian company's cold wallets were compromised in a $140 million bitcoin hack
Toronto-based Coinkite says software bug meant passwords were less secure than thought

Dozens of bitcoin investors around the world received a rude awakening last week after discovering they had collectively lost millions of dollars after their accounts with Toronto-based crypto storage company Coinkite Inc. were compromised. Within minutes, at least 1,600 bitcoins — worth about $140 million — were drained from users of the company’s cold wallets, according to research from New York-based digital asset firm Galaxy. So what exactly happened, how do cold wallets work and will those who lost money get it back? The Financial Post takes a closer look.
What is a cold wallet?
People store cryptocurrencies in different ways. Some leave it with a third party, such as a fintech or a cryptocurrency exchange. Others choose what is known as self-custody. Through this setup, individuals retain control of the private keys needed to access their bitcoin, usually with the help of either an online or offline wallet. Coinkite Inc. was founded in 2012 and has supplied investors with offline hardware wallets, which it calls Coldcards, for years. Each device looks like a tiny calculator with a screen and a keypad and stores the private keys needed to access bitcoin, which live on the online bitcoin network. Cold wallets are considered one of the industry’s most trusted methods for securing digital assets because they aren’t connected to the internet and in theory cannot be hacked into remotely.
How were the cold wallets compromised?
When investors purchase hardware wallets to secure their bitcoin, they are essentially provided with a unique private key which functions similar to a password that allows them to access their cryptocurrencies when required.
These keys are long, complex and randomly generated to ensure that hackers cannot guess them and access the bitcoin on the main bitcoin network.
“Because the number of keys is so vast, normally the system works correctly,” said Jeremy Clark, an associate professor at Concordia University. Even if computers are making billions of guesses every second, they would have to run for the lifetime of the universe before they find anyone’s key.”
The issue with some of Coinkite’s wallets was that they didn’t actually provide investors with keys that were unique enough to withstand a hacking attack, because there was a bug in the software that the company overlooked.
“It’s like they told people that it was going to be a combination lock with 1 trillion numbers, but because of the bug, it just had a 1,000 numbers,” said Henry Kim, an associate professor at York University.
Coinkite, for its part, said on its website on Tuesday that the bug wasn’t in the parent code but instead “lived at a boundary between two unrelated submodules.”
How significant is this breach?
The roughly $140 million stolen — a figure that Coinkite has yet to confirm — is barely within the top 20 of all-time crypto hacks by dollar value, said Alex Thorn, head of research at Galaxy Digital. However, it’s the nature of the attack that makes this episode uniquely devastating, he said.
That’s because in this case, it was the people who took the extra steps to protect themselves who were affected. They purchased offline wallets and chose not to entrust their bitcoin to third parties or to store their keys online.
“The reason why this is upsetting for many people is that this is how you make sure your bitcoins are secure,” said Kim. “When you hear a case like this, it’s really jarring because you’re someone that could have done everything correctly and still have (lost) your bitcoins.”
While this may be the first known case of theft involving bitcoin linked to hardware-based offline wallets, there have been similar incidents in the past involving other types of wallets, Clark said. In at least four or five cases, software was released with a flawed random number generator, allowing attackers to steal bitcoin, he said.
“None of those previous incidents really changed things,” he said. “It makes you pause and reflect because the whole idea of self-custody is that you don’t have to trust anyone, but yourself. But this is a reminder that you are actually trusting the software, the hardware and the company that’s producing the software, and the coders.”
Who did it and will the victims get their money back?
Authorities have not identified the hackers were, but the early signs suggest that there could be multiple people behind the attack. If the hackers find a way to convert the bitcoin to money discreetly, they could potentially get away, but it won’t be easy, said Kim.
“The odd thing is that it’s hard to get the money back, but it’s also difficult to spend the money,” said Kim. “As long as it’s in crypto, we don’t know who stole them. But if those people want to turn that into real money, that’ when it’s possible to find out who that was. You have to be a sophisticated hacker to be able to escape detection.”
There have been previous examples where authorities were able to track the stolen bitcoin and eventually recover them. For example, in 2016, Bitfinex, a cryptocurrency exchange, was hacked and lost about 120,000 bitcoin. Authorities followed how the digital assets moved for years before eventually arresting a couple linked to the scandal and recovered 94,000 bitcoin.
Kim also doesn’t expect Coinkite to be on the hook for this breach because he suspects that the company, while selling their wallets, used language that would indemnify them from such incidents. They also did do their best to warn people about the incident after it was discovered, he said.
What comes next?
The incident might hurt confidence and lead to slower adoption among newcomers to bitcoin, said Jarret Vaughan, an adjunct professor at the UBC Sauder School of Business. But he also said that the bitcoin community tends to learn from its failures and incidents like these usually lead to better standards overall.
Vaughan said that Coinkite has been regarded as a highly trusted organization and that the theft appears to have stemmed from human error, referring to the bug in the system. However, the breach has certainly eroded confidence in the company’s Coldcard wallets across parts of the industry.
“Anyone who is using Coldcard now, even if you don’t have one of those vulnerabilities, from the people that I know in the industry, they’re moving away from it immediately,” he said.
In repsonse to the hack, a group of bitcoin supporters has been assembled to test other open source code across the ecosystem, said Thorn of Galaxy Digital, who noted that Coinkite’s inability to identify the bug reflected sloppy coding and a lack of sufficient review.
For its part, Coinkite said an AI-assisted review had not been able to catch the bug.
“We believe it’s important for the broader ecosystem to understand how this bug arose, and why it evaded detection, so they can avoid similar consequences,” the company said.
• Email: nkarim@postmedia.com







Postmedia is committed to maintaining a lively but civil forum for discussion. Please keep comments relevant and respectful. Comments may take up to an hour to appear on the site. You will receive an email if there is a reply to your comment, an update to a thread you follow or if a user you follow comments. Visit our Community Guidelines for more information.