Advertisement 1

How a Canadian company's cold wallets were compromised in a $140 million bitcoin hack

Toronto-based Coinkite says software bug meant passwords were less secure than thought

Article content

Dozens of bitcoin investors around the world received a rude awakening last week after discovering they had collectively lost millions of dollars after their accounts with Toronto-based crypto storage company Coinkite Inc. were compromised. Within minutes, at least 1,600 bitcoins — worth about $140 million — were drained from users of the company’s cold wallets, according to research from New York-based digital asset firm Galaxy. So what exactly happened, how do cold wallets work and will those who lost money get it back? The Financial Post takes a closer look.

Article content
Advertisement 1
Story continues below
Article content

What is a cold wallet?

Article content
Article content
Article content

People store cryptocurrencies in different ways. Some leave it with a third party, such as a fintech or a cryptocurrency exchange. Others choose what is known as self-custody. Through this setup, individuals retain control of the private keys needed to access their bitcoin, usually with the help of either an online or offline wallet. Coinkite Inc. was founded in 2012 and has supplied investors with offline hardware wallets, which it calls Coldcards, for years. Each device looks like a tiny calculator with a screen and a keypad and stores the private keys needed to access bitcoin, which live on the online bitcoin network. Cold wallets are considered one of the industry’s most trusted methods for securing digital assets because they aren’t connected to the internet and in theory cannot be hacked into remotely.

Article content

How were the cold wallets compromised?

Article content

When investors purchase hardware wallets to secure their bitcoin, they are essentially provided with a unique private key which functions similar to a password that allows them to access their cryptocurrencies when required.

Article content
Advertisement 2
Story continues below
Article content

These keys are long, complex and randomly generated to ensure that hackers cannot guess them and access the bitcoin on the main bitcoin network.

Article content
Read More
  1. The Halewood operations site of Jaguar and Land Rover near Liverpool in Merseyside, England.
    Why a multibillion-dollar cyberattack in the U.K. is a warning shot for Canada
  2. Anthropic PBC's Mythos introduces a distinct challenge: AI capabilities in the hands of external malicious actors.
    Manuel Morales: How Canada's financial system should deal with the threat posed by Mythos
  3. Advertisement 1
    Story continues below
Article content

“Because the number of keys is so vast, normally the system works correctly,” said Jeremy Clark, an associate professor at Concordia University. Even if computers are making billions of guesses every second, they would have to run for the lifetime of the universe before they find anyone’s key.”

Article content

The issue with some of Coinkite’s wallets was that they didn’t actually provide investors with keys that were unique enough to withstand a hacking attack, because there was a bug in the software that the company overlooked.

Article content

“It’s like they told people that it was going to be a combination lock with 1 trillion numbers, but because of the bug, it just had a 1,000 numbers,” said Henry Kim, an associate professor at York University.
Coinkite, for its part, said on its website on Tuesday that the bug wasn’t in the parent code but instead “lived at a boundary between two unrelated submodules.”

Article content

How significant is this breach?

Article content

The roughly $140 million stolen — a figure that Coinkite has yet to confirm — is barely within the top 20 of all-time crypto hacks by dollar value, said Alex Thorn, head of research at Galaxy Digital. However, it’s the nature of the attack that makes this episode uniquely devastating, he said.

Advertisement 1
Advertisement 2
Advertisement
Article content

That’s because in this case, it was the people who took the extra steps to protect themselves who were affected. They purchased offline wallets and chose not to entrust their bitcoin to third parties or to store their keys online.

Article content

“The reason why this is upsetting for many people is that this is how you make sure your bitcoins are secure,” said Kim. “When you hear a case like this, it’s really jarring because you’re someone that could have done everything correctly and still have (lost) your bitcoins.”

Article content

While this may be the first known case of theft involving bitcoin linked to hardware-based offline wallets, there have been similar incidents in the past involving other types of wallets, Clark said. In at least four or five cases, software was released with a flawed random number generator, allowing attackers to steal bitcoin, he said.

Article content

“None of those previous incidents really changed things,” he said. “It makes you pause and reflect because the whole idea of self-custody is that you don’t have to trust anyone, but yourself. But this is a reminder that you are actually trusting the software, the hardware and the company that’s producing the software, and the coders.”

Article content
Advertisement 3
Story continues below
Article content

Who did it and will the victims get their money back?

Article content

Authorities have not identified the hackers were, but the early signs suggest that there could be multiple people behind the attack. If the hackers find a way to convert the bitcoin to money discreetly, they could potentially get away, but it won’t be easy, said Kim.

Article content

“The odd thing is that it’s hard to get the money back, but it’s also difficult to spend the money,” said Kim. “As long as it’s in crypto, we don’t know who stole them. But if those people want to turn that into real money, that’ when it’s possible to find out who that was. You have to be a sophisticated hacker to be able to escape detection.”

Article content

There have been previous examples where authorities were able to track the stolen bitcoin and eventually recover them. For example, in 2016, Bitfinex, a cryptocurrency exchange, was hacked and lost about 120,000 bitcoin. Authorities followed how the digital assets moved for years before eventually arresting a couple linked to the scandal and recovered 94,000 bitcoin.

Article content

Kim also doesn’t expect Coinkite to be on the hook for this breach because he suspects that the company, while selling their wallets, used language that would indemnify them from such incidents. They also did do their best to warn people about the incident after it was discovered, he said.

Article content
Advertisement 4
Story continues below
Article content

What comes next?

Article content

The incident might hurt confidence and lead to slower adoption among newcomers to bitcoin, said Jarret Vaughan, an adjunct professor at the UBC Sauder School of Business. But he also said that the bitcoin community tends to learn from its failures and incidents like these usually lead to better standards overall.

Article content

Vaughan said that Coinkite has been regarded as a highly trusted organization and that the theft appears to have stemmed from human error, referring to the bug in the system. However, the breach has certainly eroded confidence in the company’s Coldcard wallets across parts of the industry.

Article content

“Anyone who is using Coldcard now, even if you don’t have one of those vulnerabilities, from the people that I know in the industry, they’re moving away from it immediately,” he said.

Article content

In repsonse to the hack, a group of bitcoin supporters has been assembled to test other open source code across the ecosystem, said Thorn of Galaxy Digital, who noted that Coinkite’s inability to identify the bug reflected sloppy coding and a lack of sufficient review.

Article content

For its part, Coinkite said an AI-assisted review had not been able to catch the bug.

Article content

“We believe it’s important for the broader ecosystem to understand how this bug arose, and why it evaded detection, so they can avoid similar consequences,” the company  said.

Article content

• Email: nkarim@postmedia.com

Article content
Advertisement 2
Comments
You must be logged in to join the discussion or read more comments.
Join the Conversation

Postmedia is committed to maintaining a lively but civil forum for discussion. Please keep comments relevant and respectful. Comments may take up to an hour to appear on the site. You will receive an email if there is a reply to your comment, an update to a thread you follow or if a user you follow comments. Visit our Community Guidelines for more information.