GSM Cellphones Ltd 750x150 250129_left

GSM Cellphones Ltd 750x150 250129_left

HomeBusinessCanadian Firm Loses Over $100M in Major Bitcoin Breach

Canadian Firm Loses Over $100M in Major Bitcoin Breach

Canadian Firm Loses Over $100M in Major Bitcoin Breach

Hackers have stolen more than US$100 million — roughly $140 million Canadian — in Bitcoin from thousands of accounts after finding a flaw in security devices sold by a Canada-based company.

 

The company, Coinkite Inc., makes “cold” Bitcoin wallets, a type of storage that uses physical hardware and private passwords to keep funds offline and, in theory, safer from hackers. Coinkite told users late last week that some wallets using its Coldcard devices had been compromised.

 

Read More On Our Daily Stock Market Reports – Markets Close Mixed: TSX Pulls Back While U.S. Indexes Extend Their Recovery; Semiconductor Rotation Remains in Focus

By Monday, more than 1,755 tokens worth about US$110 million had been drained from 5,000 wallets, according to Galaxy Research.

 

Victims describe watching funds disappear

Jonathan Goodman, one of the people affected, Told Bloomberg News he knew something was wrong the moment he checked his account and saw withdrawal alerts.

 

“The moment it loaded I knew I was screwed because I saw red lines for withdrawals,” Goodman said. He said all three of his wallets were drained within a seven-minute span on the night of July 29, costing him US$1.6 million.

 

Tim Lamb, managing director at EquityEdge Studio, said in a post on X that he lost two Bitcoin he had set aside for his children. He called the loss a “terrible blow” and asked authorities to track down those responsible.

 

Flaw traced to random number generator

According to a report from Block Inc.’s engineering team, the problem stemmed from how Coldcard devices generated a “seed phrase,” a long string of words used to unlock a wallet. The phrase was supposed to be random, but a flaw in Coinkite’s software meant it could sometimes be predicted.

 

Block’s report said the issue came down to how Coinkite built the random-number generator used to create the phrases. When that system failed, the devices fell back on simpler values, including device serial numbers, to generate keys. That allowed attackers to work out the keys and empty wallets.

 

Losses were estimated at around US$38 million on Friday, but climbed quickly through the weekend and into Monday.

 

Ayesha Kiani, chief operating officer at Monarq Asset Management, said the incident is a reminder that keeping control of your own crypto is only as secure as the process used to create and protect the private keys.

 

Coinkite confirmed on its website that funds remained at risk and released new software for affected customers, some of whom had been locked out of their own devices.

Incident raises questions about “offline” security

Aneirin Flynn, chief executive of cybersecurity firm Failsafe, said the breach undercuts the idea that offline storage is inherently safe.

 

“It exposes the fallacy of your crypto being offline,” Flynn said. “The device is just responsible for generating your passwords, and if the underlying math is broken then your passwords can be reverse-engineered.”

 

Crypto theft overall is down this year compared to last. A report published last month by TRM Labs found US$972 million in crypto was stolen in the first half of 2026, less than half the US$2.3 billion stolen over the same period in 2025. But the number of separate hacking incidents rose to 207, the highest total recorded in any six-month period.

 

For Goodman, the breach has changed how he thinks about the technology altogether. He said he does not plan to keep investing in Bitcoin or using cold wallets.

 

“If it really is this complicated and technical, perhaps it’s not worth doing,” he said. “Nobody knows how basically anything works.”

 

 

 

 

 

This article was first reported by Bloomberg