Menu
Browse

Cyber Incident Victim: Coinkite Inc

Date

Jul 2026

Location

Canada

Status

Ongoing

Updated

2026-08-11 21:23

Timeline
Occurred
Jul 2026
Discovered
Jul 2026
Disclosed
Aug 2026
Resolved
Pending
Summary

Hackers exploited a software vulnerability in Coinkite’s system to reconstruct the seed phrases of its cold‑wallet customers, allowing them to drain Bitcoin worth over $100 million from thousands of accounts. The breach prompted the company to alert users, suspend its automatic data‑blanking routine to preserve records for potential legal proceedings, and launch an ecosystem‑wide security audit that uncovered additional critical bugs. Coinkite stated it is working to assist affected customers while declining to provide its own loss estimate pending verification.

CIA Posture Motives Tactics, Techniques & Procedures
Available to members 0 motives 1 technique
Threat Actors Type Location
0 actors Available to members Available to members

Description

On July 29, between 9:36 pm and 9:43 pm, victims observed red lines for withdrawals and saw their cold wallets emptied, as described by Johnathan Goodman who reported that all three of his wallets were drained in that window. The theft targeted cold wallets hosted by the Canada‑based company Coinkite, which were supposed to be secured by a physical hardware key. Hackers exploited a software bug that allowed them to reconstruct wallet seed phrases, the master keys that restore access to offline Bitcoin holdings. Galaxy Research estimated that around $110 million worth of Bitcoin had been taken from roughly 5,000 wallets during the initial wave of the attack. By the following Monday the number of affected wallets had risen to at least 7,300, according to the same estimate. The incident was reported by Bloomberg and highlighted as a significant breach of the supposedly impenetrable security model used for cold storage.

Cyber Incident Image

On July 30 Coinkite issued a warning to its customers that hackers were exploiting the software bug that enabled seed‑phrase reconstruction. The company told Bloomberg it was working to help affected customers but declined to provide its own loss estimate, saying it would conduct a post‑mortem at an unspecified future date. Coinkite stated that it was not in a position to independently confirm total losses or to validate the specific figures being reported by third parties and would not speculate on a number it could not verify directly. In response to the breach the firm launched an ongoing ecosystem‑wide security audit, employing frontier AI models to examine key software systems across the cryptocurrency ecosystem. The audit revealed numerous critical bugs in those systems, underscoring broader weaknesses beyond the immediate incident. Coinkite entered full damage‑control mode while continuing to investigate the root cause of the slipup. On August 8, 2026 the company published an update on customer data retention, explaining that legal obligations arising from the security incident required the temporary suspension of its automated data‑blanking process. As a result, customer records that would normally have been erased under the standard schedule are now being retained until further notice. The company emphasized that this retention measure is intended to preserve potential evidence for ongoing and anticipated legal proceedings.

Sources
Sources available to members
1 source