
Cybercriminals have successfully stolen over one hundred million dollars worth of cryptocurrency from thousands of digital wallets hosted by the Canadian firm Coinkite. The attackers managed to bypass security measures that relied on physical hardware keys, which were intended to provide robust protection for offline storage solutions known as cold wallets.
Victims reported seeing immediate signs of compromise shortly after logging in. Johnathan Goodman described noticing red withdrawal lines appear instantly upon loading his account interface. Between 9:36 pm and 9:43 pm on July 29, all three of his specific wallets were completely emptied within a short window.
Analysts from Galaxy Research estimate that approximately fifty thousand affected accounts lost funds during the incident last week. This figure subsequently rose to at least seven thousand by Monday as more victims came forward or data was verified. The breach underscores ongoing vulnerabilities within an industry often characterised by limited regulatory oversight and inconsistent security standards.
Coinkite acknowledged a software bug on July 30 that allowed hackers to reconstruct seed phrases, which serve as master keys for accessing offline wallets. While the company stated it is working to assist affected customers, officials refused to provide specific loss figures until an independent post-mortem could be conducted at a later date.
The firm confirmed it cannot independently verify total losses or validate numbers reported by third parties without direct access to verified data. In response to the incident, Coinkite initiated a comprehensive security audit across its ecosystem using frontier artificial intelligence models. This review has already identified numerous critical bugs within key software systems used throughout the broader industry.
Following the breach, the company entered damage control mode while investigating the severity of the slipup. An update published on their website today regarding customer data retention noted that legal obligations arising from the security incident required the suspension of automated data-blanking processes. Consequently, records that would normally be deleted under standard schedules will now be retained until further notice to preserve evidence relevant to ongoing and anticipated legal proceedings.
The following content has been published by Stockmark.IT. All information utilised in the creation of this communication has been gathered from publicly available sources that we consider reliable. Nevertheless, we cannot guarantee the accuracy or completeness of this communication.
This communication is intended solely for informational purposes and should not be construed as an offer, recommendation, solicitation, inducement, or invitation by or on behalf of the Company or any affiliates to engage in any investment activities. The opinions and views expressed by the authors are their own and do not necessarily reflect those of the Company, its affiliates, or any other third party.
The services and products mentioned in this communication may not be suitable for all recipients, by continuing to read this website and its content you agree to the terms of this disclaimer.






