Coinkite
Incident posture
Timeline
Summary
Hackers exploited a software bug to reconstruct seed phrases and stole Bitcoin from thousands of cold wallets hosted by Coinkite, resulting in losses estimated at over $110 million. One victim, Johnathan Goodman, reported that three of his wallets were drained. Coinkite warned customers about the bug, said it was working to help affected users, and suspended its automated data-blanking process due to legal obligations. The company also launched an ecosystem-wide security audit that uncovered additional critical bugs.
Motives
Detailed motive labels are available to members.
TTPs
Detailed technique labels are available to members.
Description
On July 29, between 9:36 pm and 9:43 pm, hackers executed a series of withdrawals that drained the Bitcoin holdings of multiple Coinkite customers, including victim Johnathan Goodman who observed his three wallets emptied within that window. The theft affected thousands of cold wallets hosted by the Canada‑based company Coinkite, which were supposed to be secured by physical hardware keys. Galaxy Research estimated that approximately $110 million worth of Bitcoin had been stolen from around 5,000 wallets, a figure that later rose to at least 7,300 wallets by the following Monday. Investigators determined that the attackers exploited a software bug that allowed them to reconstruct wallet seed phrases, thereby bypassing the offline protection intended by the hardware keys.
Coinkite issued a warning to its customers on July 30, informing them that the breach stemmed from a software vulnerability enabling seed‑phrase reconstruction. The company stated that it was working to help affected customers and would conduct a post‑mortem analysis at an unspecified future date. Coinkite declined to provide its own loss estimate, telling Bloomberg that it could not independently confirm the total losses reported by third parties. In parallel, the firm launched an ongoing ecosystem‑wide security audit that employed frontier AI models and uncovered numerous critical bugs in key software components across its ecosystem.
The incident underscored broader security shortcomings in the largely unregulated cryptocurrency sector, prompting Coinkite to enter full damage‑control mode while the audit continued. On August 8, 2026, Coinkite published an update on customer data retention, explaining that legal obligations arising from the security incident required the preservation of records relevant to ongoing and anticipated legal proceedings. Consequently, the company temporarily suspended its automated data‑blanking process, meaning that customer records that would have been routinely deleted under its standard schedule are now retained until further notice.
Sources
Sources available to members: 1 source.