Skip to Content News Archives Economy Energy Oil & Gas Renewables Electric Vehicles Mining Commodities Agriculture Real Estate Mortgages Mortgage Rates Finance Banking Insurance Fintech Cryptocurrency Work Wealth Smart Money Wealth Management Investor Personal Finance Family Finance Retirement Taxes High Net Worth FP Comment Executive Women Puzzmo Newsletters Financial Times Business Essentials More Innovation Information Technology FP500 Podcasts Small Business Lives Told Tails Told Shopping Financial Post Store Obituaries Place a Notice Advertising Advertising With Us Advertising Solutions Postmedia Ad Manager Sponsorship Requests Classifieds Place a Classifieds ad Working Profile Settings My Subscriptions Saved Articles My Offers Newsletters Customer Service FAQ News Economy Energy Mining Real Estate Finance Work Wealth Investor FP Comment Executive Women Puzzmo Newsletters Financial Times Business Essentials This advertisement has not loaded yet, but your article continues below.HomePMN BusinessHackers Target Bitcoin's Safest Hiding Place in Ongoing AttackHackers have found a software flaw in a brand of “cold” Bitcoin wallet — considered one of the safest places to store cryptocurrency — and are siphoning tens of millions of dollars in an ongoing attack.Author of the article: You can save this article by registering for free here. Or sign-in if you have an account.(Bloomberg) — Hackers have found a software flaw in a brand of “cold” Bitcoin wallet — considered one of the safest places to store cryptocurrency — and are siphoning tens of millions of dollars in an ongoing attack.THIS CONTENT IS RESERVED FOR SUBSCRIBERS ONLYSubscribe now to read the latest news in your city and across Canada.Exclusive articles from Barbara Shecter, Joe O'Connor, Gabriel Friedman, and others.Daily content from Financial Times, the world's leading global business publication.Unlimited online access to read articles from Financial Post, National Post and 15 news sites across Canada with one account.National Post ePaper, an electronic replica of the print edition to view on any device, share and comment on.Daily puzzles, including the New York Times Crossword.SUBSCRIBE TO UNLOCK MORE ARTICLESSubscribe now to read the latest news in your city and across Canada.Exclusive articles from Barbara Shecter, Joe O'Connor, Gabriel Friedman and others.Daily content from Financial Times, the world's leading global business publication.Unlimited online access to read articles from Financial Post, National Post and 15 news sites across Canada with one account.National Post ePaper, an electronic replica of the print edition to view on any device, share and comment on.Daily puzzles, including the New York Times Crossword.REGISTER / SIGN IN TO UNLOCK MORE ARTICLESCreate an account or sign in to continue with your reading experience.Access articles from across Canada with one account.Share your thoughts and join the conversation in the comments.Enjoy additional articles per month.Get email updates from your favourite authors.THIS ARTICLE IS FREE TO READ REGISTER TO UNLOCK.Create an account or sign in to continue with your reading experience.Access articles from across Canada with one accountShare your thoughts and join the conversation in the commentsEnjoy additional articles per monthGet email updates from your favourite authorsSign In or Create an AccountLate last week, Canada-based Coinkite Inc. notified users of its Coldcard devices that a security flaw in the keys that protect their cryptocurrency had compromised some wallets. By Monday, roughly 1,367 Bitcoin worth some $86 million had been drained from more than 4,500 wallets, according to Galaxy Research.Coldcard is a brand of hardware device that allows users to secure their Bitcoin in so-called cold wallets. These wallets are supposed to be the safest place to keep cryptocurrency because they are isolated from the internet.Get the latest headlines, breaking news and columns.By signing up you consent to receive the above newsletter from Postmedia Network Inc.A welcome email is on its way. If you don't see it, please check your junk folder.The next issue of Top Stories will soon be in your inbox.We encountered an issue signing you up. Please try againHowever, a flaw in the software of the Coldcard devices meant that the generated “seed phrase” — a long string of words used to gain access to a wallet — was predictable, according to a report from Block Inc.’s engineering team.“It exposes the fallacy of your crypto being offline,” said Aneirin Flynn, chief executive officer of cybersecurity technology firm Failsafe. “The device is just responsible for generating your passwords, and if the underlying math is broken then your passwords can be reverse-engineered.”For some users, news of the attacks was at first unfathomable. Jonathan Goodman, one of the victims, said he figured it didn’t impact him, but he checked his wallet anyway.“The moment it loaded I knew I was screwed because I saw red lines for withdrawals,” he told Bloomberg. “Between 9:36 and 9:43 p.m. on July 29th, all three of my wallets were completely drained.”The core of the issue was how Coinkite implemented the random-number generator when producing the phrases, according to Block. True randomness is a critical component of cryptographic security, but Coldcard wallets had a fallback mechanism that resulted in keys generated using deterministic values such as the device serial numbers.The result was that attackers have been able to systematically recalculate and drain user wallets. Reports on Friday placed losses at around $38 million, but the figures quickly climbed over the weekend.In a statement on its website, Coinkite confirmed that funds controlled by seeds generated on affected firmware are at risk. Fixed firmware is now available for every affected model and release track, it said.The attack has drawn widespread attention online, with influencers to company executives weighing in on the implications.For 2026 so far, the amount of crypto stolen is down from last year. The first half of the year has seen total losses reach $972 million, less than half of the $2.3 billion stolen during the first half of 2025, according to a TRM Labs report published last month. Still, the total number of hacks climbed to 207, the highest recorded in any six-month period.This advertisement has not loaded yet.Notice for the Postmedia NetworkThis website uses cookies to personalize your content (including ads), and allows us to analyze our traffic. Read more about cookies here. By continuing to use our site, you agree to our Terms of Use and Privacy Policy.
Hackers Target Bitcoin’s Safest Hiding Place in Ongoing Attack
Full Article
Original Source
Read the full article at Financialpost →KhanList aggregates and links to publicly available news content. We do not host full articles from third-party sources. Always verify important information with original sources.