Coinkite
Profile
Organisation tracking is available to eligible accounts.
Profile narrative
Coinkite, also known as Coinkite Inc, is a Canada-based company operating in the digital asset and cryptocurrency sector. The organisation built its reputation around secure Bitcoin-related services and hardware products, serving customers who required robust tools for managing and protecting their digital assets. Following prolonged regulatory pressure and repeated cyberattacks in its earlier years, Coinkite shifted its strategic focus toward hardware-based solutions, including standalone Bitcoin terminals and authentication tools designed to give users greater control over their private keys and transaction security. This pivot away from hosted wallet services reflected a broader industry recognition that software-only custody models faced escalating operational and legal risks.
The scale of Coinkite's impact became starkly visible in a major security incident disclosed in July 2026, when hackers exploited a software bug to reconstruct seed phrases from cold wallets hosted by the company. The breach resulted in Bitcoin losses estimated at over $110 million, affecting thousands of users across its platform. One identified victim, Johnathan Goodman, reported that three of his wallets were drained as a direct consequence of the vulnerability. In response to the incident, Coinkite issued warnings to its customers, committed to assisting affected users, and temporarily suspended its automated data-blanking process in order to comply with legal obligations related to the ongoing investigation. The company also initiated an ecosystem-wide security audit, which subsequently uncovered additional critical bugs, demonstrating a commitment to broader infrastructure review beyond the immediate exploit.
Prior to its transition, Coinkite had operated a secure online wallet service that allowed customers to store and transact in Bitcoin. This service became untenable after sustained distributed denial-of-service attacks stretching over multiple years, compounded by mounting regulatory scrutiny. The company eventually mandated that customers withdraw their funds within a specified period before terminating wallet access entirely, and it implemented automatic Bitcoin redistribution policies for inactive accounts. Alongside these measures, Coinkite discontinued its TOR and API services ahead of a full operational wind-down of its software offerings, citing the cumulative burden of cyberattacks and the diversion of resources toward legal defence and customer support. Leadership at the time publicly expressed frustration with the burdens of running a software-based service and emphasised the strategic logic of prioritising hardware products, where users retained direct custody of their assets.
No publicly available information within the provided sources specifies Coinkite's ownership structure, parent company relationships, or formal subsidiary arrangements. The organisation is identified as a Canada-based entity operating under the Coinkite Inc name, with its headquarters located in Canada. Its distinguishing attributes include a specialisation in high-security cryptocurrency infrastructure, a willingness to publicly disclose major vulnerabilities, and a documented capacity to undertake broad security audits following incidents. The combination of its hardware focus, its experience managing large-scale breaches, and its regulatory engagement positions Coinkite as a notable case study in the operational challenges facing custodial Bitcoin service providers.
Incidents
2 incidents linked to this organisation.