Skip to Content News Archives Economy Energy Oil & Gas Renewables Electric Vehicles Mining Commodities Agriculture Real Estate Mortgages Mortgage Rates Finance Banking Insurance Fintech Cryptocurrency Work Wealth Smart Money Wealth Management Investor Personal Finance Family Finance Retirement Taxes High Net Worth FP Comment Executive Women Puzzmo Newsletters Financial Times Business Essentials More Innovation Information Technology FP500 Podcasts Small Business Lives Told Tails Told Shopping Financial Post Store Obituaries Place a Notice Advertising Advertising With Us Advertising Solutions Postmedia Ad Manager Sponsorship Requests Classifieds Place a Classifieds ad Working Profile Settings My Subscriptions Saved Articles My Offers Newsletters Customer Service FAQ News Economy Energy Mining Real Estate Finance Work Wealth Investor FP Comment Executive Women Puzzmo Newsletters Financial Times Business Essentials HomeCybersecurityFinanceCryptocurrencyHow a Canadian company's cold wallets were compromised in a $140 million bitcoin hackToronto-based Coinkite says software bug meant passwords were less secure than thought You can save this article by registering for free here. Or sign-in if you have an account.Dozens of bitcoin investors around the world collectively lost millions of dollars after their accounts with crypto storage company Coinkite Inc. were compromised last week. Photo by Getty Images/iStockphotoDozens of bitcoin investors around the world received a rude awakening last week after discovering they had collectively lost millions of dollars after their accounts with Toronto-based crypto storage company Coinkite Inc. were compromised. Within minutes, at least 1,600 bitcoins — worth about $140 million — were drained from users of the company’s cold wallets, according to research from New York-based digital asset firm Galaxy. So what exactly happened, how do cold wallets work and will those who lost money get it back? The Financial Post takes a closer look.Subscribe now to read the latest news in your city and across Canada.Exclusive articles from Barbara Shecter, Joe O'Connor, Gabriel Friedman, and others.Daily content from Financial Times, the world's leading global business publication.Unlimited online access to read articles from Financial Post, National Post and 15 news sites across Canada with one account.National Post ePaper, an electronic replica of the print edition to view on any device, share and comment on.Daily puzzles, including the New York Times Crossword.Subscribe now to read the latest news in your city and across Canada.Exclusive articles from Barbara Shecter, Joe O'Connor, Gabriel Friedman and others.Daily content from Financial Times, the world's leading global business publication.Unlimited online access to read articles from Financial Post, National Post and 15 news sites across Canada with one account.National Post ePaper, an electronic replica of the print edition to view on any device, share and comment on.Daily puzzles, including the New York Times Crossword.Create an account or sign in to continue with your reading experience.Access articles from across Canada with one account.Share your thoughts and join the conversation in the comments.Enjoy additional articles per month.Get email updates from your favourite authors.Create an account or sign in to continue with your reading experience.Access articles from across Canada with one accountShare your thoughts and join the conversation in the commentsEnjoy additional articles per monthGet email updates from your favourite authorsSign In or Create an AccountorBreaking business news, incisive views, must-reads and market signals. Weekdays by 9 a.m.By signing up you consent to receive the above newsletter from Postmedia Network Inc.A welcome email is on its way. If you don't see it, please check your junk folder.The next issue of Posthaste will soon be in your inbox.We encountered an issue signing you up. Please try againPeople store cryptocurrencies in different ways. Some leave it with a third party, such as a fintech or a cryptocurrency exchange. Others choose what is known as self-custody. Through this setup, individuals retain control of the private keys needed to access their bitcoin, usually with the help of either an online or offline wallet. Coinkite Inc. was founded in 2012 and has supplied investors with offline hardware wallets, which it calls Coldcards, for years. Each device looks like a tiny calculator with a screen and a keypad and stores the private keys needed to access bitcoin, which live on the online bitcoin network. Cold wallets are considered one of the industry’s most trusted methods for securing digital assets because they aren’t connected to the internet and in theory cannot be hacked into remotely.When investors purchase hardware wallets to secure their bitcoin, they are essentially provided with a unique private key which functions similar to a password that allows them to access their cryptocurrencies when required.These keys are long, complex and randomly generated to ensure that hackers cannot guess them and access the bitcoin on the main bitcoin network.“Because the number of keys is so vast, normally the system works correctly,” said Jeremy Clark, an associate professor at Concordia University. Even if computers are making billions of guesses every second, they would have to run for the lifetime of the universe before they find anyone’s key.”The issue with some of Coinkite’s wallets was that they didn’t actually provide investors with keys that were unique enough to withstand a hacking attack, because there was a bug in the software that the company overlooked.“It’s like they told people that it was going to be a combination lock with 1 trillion numbers, but because of the bug, it just had a 1,000 numbers,” said Henry Kim, an associate professor at York University. Coinkite, for its part, said on its website on Tuesday that the bug wasn’t in the parent code but instead “lived at a boundary between two unrelated submodules.”The roughly $140 million stolen — a figure that Coinkite has yet to confirm — is barely within the top 20 of all-time crypto hacks by dollar value, said Alex Thorn, head of research at Galaxy Digital. However, it’s the nature of the attack that makes this episode uniquely devastating, he said.That’s because in this case, it was the people who took the extra steps to protect themselves who were affected. They purchased offline wallets and chose not to entrust their bitcoin to third parties or to store their keys online.“The reason why this is upsetting for many people is that this is how you make sure your bitcoins are secure,” said Kim. “When you hear a case like this, it’s really jarring because you’re someone that could have done everything correctly and still have (lost) your bitcoins.”While this may be the first known case of theft involving bitcoin linked to hardware-based offline wallets, there have been similar incidents in the past involving other types of wallets, Clark said. In at least four or five cases, software was released with a flawed random number generator, allowing attackers to steal bitcoin, he said.“None of those previous incidents really changed things,” he said. “It makes you pause and reflect because the whole idea of self-custody is that you don’t have to trust anyone, but yourself. But this is a reminder that you are actually trusting the software, the hardware and the company that’s producing the software, and the coders.”Authorities have not identified the hackers were, but the early signs suggest that there could be multiple people behind the attack. If the hackers find a way to convert the bitcoin to money discreetly, they could potentially get away, but it won’t be easy, said Kim.“The odd thing is that it’s hard to get the money back, but it’s also difficult to spend the money,” said Kim. “As long as it’s in crypto, we don’t know who stole them. But if those people want to turn that into real money, that’ when it’s possible to find out who that was. You have to be a sophisticated hacker to be able to escape detection.”There have been previous examples where authorities were able to track the stolen bitcoin and eventually recover them. For example, in 2016, Bitfinex, a cryptocurrency exchange, was hacked and lost about 120,000 bitcoin. Authorities followed how the digital assets moved for years before eventually arresting a couple linked to the scandal and recovered 94,000 bitcoin.Kim also doesn’t expect Coinkite to be on the hook for this breach because he suspects that the company, while selling their wallets, used language that would indemnify them from such incidents. They also did do their best to warn people about the incident after it was discovered, he said.The incident might hurt confidence and lead to slower adoption among newcomers to bitcoin, said Jarret Vaughan, an adjunct professor at the UBC Sauder School of Business. But he also said that the bitcoin community tends to learn from its failures and incidents like these usually lead to better standards overall.Vaughan said that Coinkite has been regarded as a highly trusted organization and that the theft appears to have stemmed from human error, referring to the bug in the system. However, the breach has certainly eroded confidence in the company’s Coldcard wallets across parts of the industry.“Anyone who is using Coldcard now, even if you don’t have one of those vulnerabilities, from the people that I know in the industry, they’re moving away from it immediately,” he said.In repsonse to the hack, a group of bitcoin supporters has been assembled to test other open source code across the ecosystem, said Thorn of Galaxy Digital, who noted that Coinkite’s inability to identify the bug reflected sloppy coding and a lack of sufficient review.For its part, Coinkite said an AI-assisted review had not been able to catch the bug.“We believe it’s important for the broader ecosystem to understand how this bug arose, and why it evaded detection, so they can avoid similar consequences,” the company said. Join the Conversation This website uses cookies to personalize your content (including ads), and allows us to analyze our traffic. Read more about cookies here. By continuing to use our site, you agree to our Terms of Use and Privacy Policy.