$140M Hack Prompts Bitcoin Users to Re-evaluate Self-Custody
A major vulnerability in bitcoin wallets manufactured by a Toronto-based company has brought renewed scrutiny to the security of investments in cryptocurrency after hackers exploited the weakness to steal more than $140-million worth of bitcoin in the past week.
Bitcoin enthusiasts say that the hack, which took advantage of a coding error in hardware wallets made by Coinkite Inc., has shaken the cryptocurrency community and raised doubts over the best way for holders to store their assets.
“There is a lot of soul-searching and re-evaluating going on. The bug was just shockingly bad,” said Eric Chennells, a Vancouver-based cybersecurity analyst and cloud computing consultant.
Coinkite didn’t respond on Tuesday to The Globe and Mail’s questions.
Many users who see bitcoin as a way to be freed from the constraints of traditional financial systems have believed that self-custody – holding their own bitcoin in a wallet, rather than on an exchange or other centralized platform – is the safest way to store the cryptocurrency. That belief has been strengthened by high-profile cases such as the 2019 collapse of Canadian crypto exchange QuadrigaCX, which the Ontario Securities Commission said had led to user losses of at least $169-million.
Financial regulators have flagged risks around crypto asset custody. In a notice in February, the Canadian Investment Regulatory Organization noted that “historical failures in the crypto sector, including losses due to hacking, fraud, inadequate governance, and insolvency, have demonstrated that custody arrangements are a critical point of investor vulnerability.”
Many in the bitcoin community have advised directly holding crypto, said Mr. Chennells, regardless of whether such concentration of risk is appropriate for an individual investor.
“The problem is the community can tend to pressure people in one direction – ideological purity that you should only self-custody,” he said.
Despite their name, hardware wallets don’t actually store bitcoin. The cryptocurrency exists digitally on a type of distributed ledger, known as a blockchain, with entries to that ledger validated and confirmed by a network of computers. Bitcoin wallets have complex private keys which are used to authorize transactions. Anyone with access to those keys has effective control over the associated bitcoin.
“Cold” wallets store crypto keys offline and can be as simple as a private key recorded on a piece of paper. Hardware wallets add a layer of security by keeping private keys on a dedicated device, requiring users to enter a PIN or password to authorize transactions.
A strong recommendation from a cryptocurrency-literate friend was enough to convince Jon Goodman, a Toronto-based author and former personal trainer, to use Coinkite’s Coldcard Mk3 hardware wallet for a sizable bitcoin position he had built up over about a year and a half of steady investing. The bitcoin, one of his four “investment pillars,” alongside real estate, stocks and his personal brand, was part of a strategy to “make sure my family is looked after and we sleep well at night,” he said in an interview.
In just seven minutes on the evening of July 29, his wallets were emptied of more than 18 bitcoin, worth in excess of $1.6-million. New York-based Galaxy Research estimated on Monday that a total of 1,596 bitcoin has been stolen from Coldcard wallets, worth more than $140-million.
A blog post that Coinkite’s support team shared with Mr. Goodman indicated that hackers had discovered a vulnerability in the part of the Coldcard wallet code used to create seed phrases – a combination of words used as a kind of master key for the wallet. While seed phrases are meant to be generated with a high degree of randomness from a huge pool of potential seeds, a coding error introduced in 2021 made seed phrases much easier to guess.
The blog post said that attackers could use the easily-guessed seed phrases to determine wallet keys and find ones containing bitcoin, without requiring access to hardware wallets.
In a social media post, Mr. Goodman said he never shared his seed phrase with anybody and had kept his devices disconnected from the internet, with his Coldcard wallet stored in a safety deposit box. He has filed police reports and a report with the Ontario Securities Commission.
“I think that there is a very legitimate chance that whoever is responsible for this will be caught and arrested,” he told The Globe and Mail. “I think that there’s almost no chance that any of the funds are going to be recovered . . . There’s just very little precedent.”
In a blog post dated Sunday, Coinkite said it had been working directly with customers and “walking through recovery options together.” It said it had also destroyed the remaining inventory of vulnerable Coldcard wallets, and had issued software patches to prevent the bug from affecting new seed generation.
“We also believe this vulnerability is a warning for every company building Bitcoin hardware and software, not only us,” Coinkite said in another post on Monday. “We’re publishing this now, while the details are still fresh, because other companies need time to check their own code to prevent potential further loss.”
Recent artificial-intelligence-assisted reviews of the Coldcard software code did not catch the vulnerability, the company said.
Mr. Chennells said bitcoin holders concerned about security vulnerabilities could consider diversifying their exposure. “Hold some in ETFs, some in a smaller vault, some in mining or ecosystem companies,” he said.
“People have to make individual choices based on their risk tolerances and knowledge and principles.”
Some investors may have already begun to diversify. In response to questions from The Globe, Arturo Rossi, a spokesman for crypto exchange Kraken, said that the trading platform had seen “a meaningful increase in bitcoin deposits during the event.”
Mr. Goodman says he intends to keep his holdings of a bitcoin fund within his TFSA, but is unlikely to rebuild the crypto pillar of his portfolio.
“I’m not going to buy any more bitcoin. I’m not going to do cold storage again.”
This article was first reported by The Globe and Mail






