Hackers made away with more than $100 million worth of Bitcoin from thousands of supposedly secured “cold” wallets hosted by Canada-based company Coinkite.
As Bloomberg reports, the hackers managed to infiltrate the wallets despite clients having a physical hardware key associated with their accounts, which was supposed to provide nearly impenetrable security.
“The moment it loaded I knew I was screwed because I saw red lines for withdrawals,” one of the victims, Johnathan Goodman, told Bloomberg. “Between 9:36 and 9:43 pm on July 29th, all three of my wallets were completely drained.”
Crypto insights company Galaxy Research estimated that around $110 million worth of Bitcoin had been drained from around 5,000 wallets last week, a figure that grew to at least 7,300 by Monday.
The incident highlights persistent lapses in security plaguing the largely unregulated cryptocurrency industry.
In the case of Coinkite, it was a particularly egregious lapse in security. The firm warned its customers on July 30 that hackers were exploiting a software bug that allowed them to reconstruct wallet “seed phrases,” which are sequences of random words that act as a master key to “cold” — or offline — wallets.
Coinkite promised in an email to Bloomberg in a followup story that it was racing to get a full picture of the embarrassing situation, saying it was working on “helping affected customers.” However, the company refused to estimate the scale of the losses, vowing to conduct a “post-mortem” at an unspecified future date.
“We’re not in a position to independently confirm total losses or validate the specific figures being reported by third parties,” the company told Bloomberg. “We won’t speculate on a number we can’t verify directly.”
The company also kicked off an “ongoing ecosystem-wide security audit” which has revealed “numerous critical bugs in key software systems across the ecosystem using frontier AI models.”
The cryptocurrency firm has since gone into full damage control mode as it investigates the major slipup.
In an “update on customer data retention” published on its website today, the company said that “due to legal obligations arising from the security incident, including the preservation of records that may be relevant to ongoing and anticipated legal proceedings, we have temporarily suspended our automated data-blanking process.”
“This means that customer records that would otherwise have been blanked under our standard schedule will be retained until further notice,” the company wrote.
More on crypto: Trump Boasts That He Can Profit Off Presidency as Much as He Wants: “I Found Out That Nobody Cared”
The post Hackers Figure Out a Trick to Steal Bitcoin From Cold Wallets, Grab $110 Million appeared first on Futurism.




