Coinkite Wallet Hack Exposes $88M BTC Heist
A significant security breach was reported in late July 2026 involving Coinkite's hardware wallets, resulting in the theft of approximately $88.6 million worth of BTC. The incident affected more than 4,500 addresses, with attackers exploiting a firmware flaw introduced in March 2021 that reduced entropy in recovery seed phrases to around 72 bits. According to Galaxy Research data, three successive waves of asset extraction occurred between July 30 and August 1, 2026, covering 1,367 BTC.
ZachXBT, a well-known blockchain investigator, declined to trace the stolen funds, citing previous instances of non-payment and lack of bounty rewards from assisted projects and influencers. In a public statement, ZachXBT stated that he focuses on ecosystems that value his work, and since 'Bitcoin maxis' do not contribute financially or support his efforts, he has less obligation to help in such cases.
Coinkite has issued an emergency security notice recommending users migrate funds to new wallets with updated firmware or unaffected devices. The company confirmed that updating firmware alone cannot fix recovery seeds created under reduced entropy parameters. Affected users must complete manual balance transfers before further automated executions occur on vulnerable addresses.