Hack of supposedly safe Bitcoin tool tries faith of the devoted


Digital crypto attacks have become more frequent this year, even as losses have declined. — Image by fabrikasimf on Magnific

Tim Lamb was vacationing in the Channel Islands with his family last week when news of the cryptocurrency hack reached him. He faced a quandary: whether to rush home and check on his Bitcoin, or finish the trip.

He waited.

By Saturday afternoon, his two Bitcoins, worth around US$130,000 (RM531,505), were gone.

The 38-year-old marketer thought he had done everything right. His Bitcoin was in "cold storage,” protected by an offline hardware wallet called Coldcard made by Toronto-based Coinkite Inc. The secret code for unlocking it had been stamped on a metal plate that was hidden inside a fake dictionary. But a software flaw in Coinkite’s device still allowed bad actors to fleece investors of an estimated US$130mil (RM531.51mil).

"It was just such a big shock because I thought that was so secure,” Lamb said in an interview.

While it’s not the first time investors have seen their tokens evaporate, Coinkite’s days-long hack is further undermining confidence in an industry already facing pressure on multiple fronts. Bitcoin is mired in a prolonged downturn, gambling apps and prediction markets are edging into its turf, AI stocks are stealing its thunder, and some committed cheerleaders are lowering their profile amid serious concerns about their physical safety.

Now, if the most secure treasure chest can be unlocked, is anything truly safe?

"This one hits different because the people affected by it, from the optics of it, did the right thing,” David Schwed, a crypto and digital asset security expert, said of the Coldcard hack. "You hear cold wallet and cold storage are the right thing and then their funds are gone.”

Digital crypto attacks have become more frequent this year, even as losses have declined. Hackers stole about US$972mil (RM3.97bil) in the first half of 2026, down from US$2.3bil (RM9.4bil) a year earlier, though the 207 incidents recorded were the highest for any six-month period on record, according to TRM Labs.

In an emailed statement, Coinkite declined to comment on loss figures reported by third-parties: "We're heads down helping affected customers," the company said.

The company has been urging users to update the firmware of their devices and transfer their Bitcoin to new wallets. In a post on X, Coinkite pointed users to the Coldcard GitHub page to find the latest software.

Secret codes

For devoted Bitcoin buyers, there’s a modus operandi that’s long been advocated. They stockpile the cryptocurrency over months or years, hold onto it, and never sell – no matter what happens with short-term price swings. And the Bitcoin should be self-custodied: secured by a hardware wallet beyond the purview of governments and financial institutions, accessible only with secret codes that allow holders to access and transfer assets.

Whether that’s still the right way is suddenly up for debate.

"If you’re simply looking for exposure to the asset class, there are better options than self-custody for most people,” said Schwed. He likened it to holding cash: few people would keep US$1mil (RM4.08mil) in a home safe rather than a bank. Using regulated exchanges or buying exchange-traded funds that hold Bitcoin are other options, he said, noting that they have teams of security professionals.

Of course, that strategy clashes with one of crypto’s oldest principles: "Not your keys, not your coins.” In other words, someone doesn’t really own Bitcoin unless that person is the only one in control of the credentials needed to access it.

Longtime crypto aficionados are quick to point out that there have also been numerous exchange failures, hacks and scandals far away from hardware wallets.

"What happened wasn’t about cold storage,” said Vincent Bouzon, director of product security at Ledger SAS, which manufactures its own product that competes with Coinkite’s. "If the cryptography is correct, cold storage is still the best solution.”

Hardware wallets like Coldcard and other cold storage options don’t actually store Bitcoin; they protect the private keys needed to authorise transactions.

A bug in certain versions of Coinkite’s firmware made some "seed phrases” used to generate those private keys more predictable than they should have been. As a result, hackers were able to guess some of the phrases and steal the Bitcoin controlled by affected wallets without needing to connect to the Coldcard devices.

The company said it had used artificial intelligence (AI) to review critical codebases, but it failed to detect the vulnerability.

Confidence eroding

Perhaps more than anything, the Coinkite episode is yet another hit to confidence in a fragile industry full of risks.

Bitcoin is down roughly half from its October peak, with no clear catalyst for recovery. The decline has triggered job cuts, business model revamps and losses for investors big and small. But that plunge in value hasn’t stopped a growing number of thefts, including the violent and frightening wrench attacks.

There were 52 such attacks worldwide in the first half of 2026, up 33% from the comparable period last year, according to blockchain security firm CertiK.

In one attempted wrench attack in Paris earlier this year, a crypto entrepreneur’s neighbours heard noises during the night and alerted the family before the criminals could go through with their plan, said the entrepreneur, asking not to be named because of safety concerns. Afterwards, the person conducted a comprehensive review of physical security, digital footprints, public information, home access, routines and travel patterns for everyone in the household.

"The most disturbing part was realising that this was not an abstract cyber risk, but a physical threat to my family, including our three very young children,” the person said.

Those with enough crypto wealth to become targets typically have sophisticated security practices not just for their homes, but for their holdings as well.

They often split or "shard” a 24-word recovery seed phrase into multiple pieces, storing each fragment in a different hiding place. Some even use specialist vault providers to stash the pieces in high-security facilities located in different countries.

For regular investors, those military-grade tactics are far out of reach.

Christian McClure, a 31-year-old restaurant manager from Colorado, spent six years squirrelling away savings into Bitcoin. By early August, McClure was nearing his goal of owning one-tenth of a coin – a small amount, but a symbolic milestone for many Bitcoin faithful.

In the blink of an eye, all of it was stolen in the Coinkite hack.

"It’s heartbreaking,” McClure said of his approximately US$6,000 (RM24,532) loss. "It’s not a massive amount of money. But it makes you feel violated, especially when you feel you did everything you were supposed to do.” – Bloomberg

Follow us on our official WhatsApp channel for breaking news alerts and key updates!

Next In Tech News

SEC settles charges over SpaceX, Klarna, pre-IPO share fraud
US SEC exempts certain data center bonds from key securitization rules
US court rules Meta, other tech firms must face thousands of lawsuits over social media addiction
Nvidia partners with Wall Street giants to raise $500 billion for AI buildout
US House Democrats press Anthropic, OpenAI about rogue AI agents
Analysis-Crypto bill faces long odds after Senate punts vote to September
Microsoft plans to unveil next-generation AI chip in September, The Information reports
GameStop weighing withdrawal of eBay bid, Bloomberg News reports
Intel plans $15 billion share sale as turnaround rally lifts stock
Unitree's Shanghai IPO more than 8,000 times oversubscribed by retail investors

Others Also Read