Skip to main content
AVOID.NET

Coinkite

avoid.net/coinkite15/100·72% conf.
[AI-DRAFTED · AWAITING VERIFICATION]

Auto-generated score, not yet verified against the scoring model. Under review — treat as indicative, not a verdict.

Summary

Coinkite Inc. is a small, privately held Toronto-based Bitcoin hardware company that manufactures the Coldcard wallet. A firmware defect introduced into Coldcard seed generation in March 2021 went undetected for roughly five years — including, per public claims from the developer who flagged it, a specific warning to Coinkite in May 2025 that was dismissed — until attackers began draining wallets on July 30, 2026, ultimately taking an estimated 1,816 BTC (roughly $116–155 million) from more than 5,200 victims. Coinkite has publicly apologized and shipped fixed firmware, but now faces credible, still-unfiled class-action and product-liability litigation threats from law firms in Canada and the UK, alongside separate allegations — unconfirmed by the company — that its own CTO authored the flawed code.

Have evidence about Coinkite?

Timeline(10 events)

2013

Coinkite Inc. is incorporated in Toronto by Rodolfo Novak and Peter Gray, following earlier collaboration on Bitcoin projects from around 2011.

Ivey Business School Coinkite Profile

March 2021

A firmware change routes Coldcard seed generation through a software library ('libngu') instead of the device's hardware random-number generator, reportedly stemming from a commit made around this time.

Cryptopolitan / CoinDesk reporting on Coinkite CTO code linkage

March 2021

Coinkite publishes firmware version 4.0.0 ('All New Code, Same Great Features'), the first release containing the vulnerable seed-generation code; the flaw persists through firmware 4.1.9.

Coinkite Blog

May 2025

Bitcoin developer James O'Beirne says he flagged the suspicious 'libngu' randomness-handling library to Coinkite during a firmware audit and was told the issue would probably have surfaced already if it were real; Coinkite has not confirmed the specifics of this account.

CoinDesk / Phemex Academy

30 July 2026

Exploitation begins; an initial wave drains roughly 594 BTC (~$38 million) from about 500 Coldcard wallets within 25–41 minutes. Coinkite publishes its first Coldcard Security Advisory the same day.

Coinkite Blog / TRM Labs

1 August 2026

Coinkite updates its security advisory with expanded technical guidance and mitigation steps for affected users.

Coinkite Blog

August 2026

Total attack losses across four waves reach an estimated 1,816 BTC (~$116 million) from over 5,200 addresses by August 3; blockchain monitors Galaxy Research and Elliptic later put combined losses as high as roughly $130-155 million. CEO Rodolfo Novak publicly apologizes and says the company takes 'full accountability for the firmware bug.'

TRM Labs / TechCrunch / Globe and Mail

August 2026

Coinkite reverses its customer data-deletion policy, citing the security incident and anticipated legal proceedings; the company had previously routinely erased customer records beyond email and country of residence.

Cryptopolitan

August 2026

James O'Beirne publishes analysis alleging that GPG-signed commits to the vulnerable library are traceable to Coinkite CTO Peter Gray, the same person he says dismissed his May 2025 warning; Coinkite does not publicly respond to the claim.

Cryptopolitan / Bitcoin Ethereum News

August 2026

Toronto firm WeirFoulds LLP (with London's Edmonds Marshall McMahon) and UK firms Fieldfisher and Irwin Mitchell publish legal guidance for victims outlining product-liability and negligence claims against Coinkite, plus asset-tracing options; 117 Partners begins organizing victims for potential coordinated claims. No class-action suit is confirmed as filed as of this period.

WeirFoulds / Globe and Mail

model: claude-code-investigator

generated: 9/11/2026, 11:23:31 PM

last updated: 9/11/2026, 11:23:30 PM

avoid.net — verified advice for a post-truth world