Skip to Content News Archives Economy Energy Oil & Gas Renewables Electric Vehicles Mining Commodities Agriculture Real Estate Mortgages Mortgage Rates Finance Banking Insurance Fintech Cryptocurrency Work Wealth Smart Money Wealth Management Investor Personal Finance Family Finance Retirement Taxes High Net Worth FP Comment Executive Women Puzzmo Newsletters Financial Times Business Essentials More Innovation Information Technology FP500 Podcasts Small Business Lives Told Tails Told Shopping Financial Post Store Obituaries Place a Notice Advertising Advertising With Us Advertising Solutions Postmedia Ad Manager Sponsorship Requests Classifieds Place a Classifieds ad Working Profile Settings My Subscriptions Saved Articles My Offers Newsletters Customer Service FAQ News Economy Energy Mining Real Estate Finance Work Wealth Investor FP Comment Executive Women Puzzmo Newsletters Financial Times Business Essentials HomeCybersecurityCryptocurrencyHackers hit bitcoin's safest hiding place in ongoing attackThe attack has drawn widespread attention online, with influencers to company executives weighing in on the implicationsAuthor of the article:Last updated 1 hour ago You can save this article by registering for free here. Or sign-in if you have an account.Perhaps the most offensive part to affected Bitcoin holders is that they thought they were using the safest option out there to protect their investments. Photo by SEBASTIEN BOZON/AFP via Getty ImagesHackers have absconded with more than US$100 million worth of Bitcoin from thousands of supposedly secure accounts in recent days, setting up another scandal for investors who have been repeatedly preyed upon by thieves in the sector.Subscribe now to read the latest news in your city and across Canada.Exclusive articles from Barbara Shecter, Joe O'Connor, Gabriel Friedman, and others.Daily content from Financial Times, the world's leading global business publication.Unlimited online access to read articles from Financial Post, National Post and 15 news sites across Canada with one account.National Post ePaper, an electronic replica of the print edition to view on any device, share and comment on.Daily puzzles, including the New York Times Crossword.Subscribe now to read the latest news in your city and across Canada.Exclusive articles from Barbara Shecter, Joe O'Connor, Gabriel Friedman and others.Daily content from Financial Times, the world's leading global business publication.Unlimited online access to read articles from Financial Post, National Post and 15 news sites across Canada with one account.National Post ePaper, an electronic replica of the print edition to view on any device, share and comment on.Daily puzzles, including the New York Times Crossword.Create an account or sign in to continue with your reading experience.Access articles from across Canada with one account.Share your thoughts and join the conversation in the comments.Enjoy additional articles per month.Get email updates from your favourite authors.Create an account or sign in to continue with your reading experience.Access articles from across Canada with one accountShare your thoughts and join the conversation in the commentsEnjoy additional articles per monthGet email updates from your favourite authorsSign In or Create an AccountorThe latest missing money stems from a software flaw in what’s known as a “cold” Bitcoin wallet hosted by Canada-based Coinkite Inc. Cold wallets have physical hardware associated with them alongside private passwords, or “keys,” intended to add an extra layer of security beyond the typical lengthy codes that nonetheless frequently get hacked.Yet, Coinkite notified users late last week that some wallets using its Coldcard devices had been compromised. By Monday, more than 1,755 tokens worth around US$110 million had been drained from 5,000 wallets, according to Galaxy Research.Get the latest headlines, breaking news and columns.By signing up you consent to receive the above newsletter from Postmedia Network Inc.A welcome email is on its way. If you don't see it, please check your junk folder.The next issue of Top Stories will soon be in your inbox.We encountered an issue signing you up. Please try againThe breach led to an understandable level of hysteria on social media, not to mention those whose Bitcoin was suddenly, inexplicably gone.“The moment it loaded I knew I was screwed because I saw red lines for withdrawals,” Jonathan Goodman, one of the victims, told Bloomberg News. “Between 9:36 and 9:43 p.m. on July 29th, all three of my wallets were completely drained.”Goodman says he lost US$1.6 million due to the attack.Here is how the hack happened, according to cryptocurrency experts and Coinkite itself.A flaw in the software of the Coldcard devices meant that the generated “seed phrase” — a long string of words used to gain access to a wallet — was predictable, according to a report from Block Inc.’s engineering team.The core of the issue was how Coinkite implemented the random-number generator when producing the phrases, according to Block. True randomness is a critical component of cryptographic security, but Coldcard wallets had a fallback mechanism that resulted in keys being generated using simpler values, such as the device serial numbers.The result was that attackers have been able to systematically recalculate and drain user wallets. Reports on Friday placed losses at around US$38 million, but the figures quickly climbed over the weekend into Monday. Bitcoin was little changed at around US$63,800.“It’s a reminder that self-custody is only as strong as the processes used to generate and protect private keys,” said Ayesha Kiani, chief operating officer at digital-asset investment firm Monarq Asset Management.In a statement on its website, Coinkite confirmed that funds were still at risk. The company offered a new version of special software for customers, after some had gotten locked out of their devices.The attack has drawn widespread attention online, with influencers to company executives weighing in on the implications. An inflatable monkey holding a Bitcoin sits on display during the Bitcoin 2026 conference in Las Vegas, Nevada, US, on Tuesday, April 28, 2026. Photo by Ian Maule/Bloomberg“It exposes the fallacy of your crypto being offline,” said Aneirin Flynn, chief executive of cybersecurity technology firm Failsafe. “The device is just responsible for generating your passwords, and if the underlying math is broken then your passwords can be reverse-engineered.”For 2026 so far, the amount of crypto stolen is down from last year. The first half of the year has seen total losses reach US$972 million, less than half of the US$2.3 billion stolen during the first half of 2025, according to a TRM Labs report published last month. Still, the total number of hacks climbed to 207, the highest recorded in any six-month period.Perhaps the most offensive part to affected Bitcoin holders is that they thought they were using the safest option out there to protect their investments.Tim Lamb, managing director at EquityEdge Studio, pleaded with authorities to find the culprits in an X post, saying the two Bitcoin he held were intended to give his children “a good start in life,” calling the losses a “terrible blow.”For Goodman, the incident highlighted how much “blind faith” he has put in the technology he uses. He would not be investing in Bitcoin or using cold wallets going forward, he said.“If it really is this complicated and technical, perhaps it’s not worth doing,” Goodman said. “Nobody knows how basically anything works.”—With assistance from Muyao Shen. Join the Conversation This website uses cookies to personalize your content (including ads), and allows us to analyze our traffic. Read more about cookies here. By continuing to use our site, you agree to our Terms of Use and Privacy Policy.
Hackers hit bitcoin's safest hiding place in ongoing attack
Hackers have absconded with more than US$100 million worth of Bitcoin from thousands of supposedly secure accounts in recent days. Read here
Coinkite's Coldcard lost $110M; seed generator used device serials instead of randomness. For enterprise crypto custody, the breach signals self-custody security depends on implementation—favoring multi-sig institutional vaults over hardware wallets.










