Keeping Your Bitcoin Riches Safe Has Never Been Harder

Finding a place to stash the keys to your cryptocurrency hoard has never been easier, thanks to options that run from putting them in a retired Swiss nuclear bunker to the humdrum use of digital-asset exchanges. It’s also never been harder to keep them safe from thieves.

Cold storage — using physical offline devices such as hard drives, safe-deposit boxes or USB sticks — is the gold standard in crypto security. To transfer Bitcoin or similar from your electronic wallet, you need to know the string of random words that makes up its de facto password, known as a seed phrase. And rather than write them down or keep them somewhere digital that’s connected to the internet, you store them in a place hackers can’t reach. Or at least that’s the theory.

Unfortunately, an attack last week has shown once again that no method is ever 100% reliable. Coinkite is a Canadian firm that hosts people’s Bitcoin wallets and has developed a physical device — Coldcard, which looks like a pocket calculator — to create customers’ private keys to those wallets and then keep them secure.

See more: Wall Street Is Buying Crypto's Plumbing, Not Its Ideology

But it was exploited by hackers who found a flaw in the way the company generated the seed phrases. Instead of completely random generation, the wallets had a failsafe that resulted in some keys using predictable information such as serial numbers. So the hackers were able to use that knowledge to brute force their way into thousands of online wallets. More than $100 million has been stolen from Coldcard users so far, despite their best efforts to keep their passwords hidden.

This isn’t the first time the physical storage of crypto keys has failed to keep wallets secure. There are many stories of people losing or forgetting passwords, falling for phishing scams, and the tale of a hard drive holding the keys to more than $500 million in Bitcoin ending up in a Welsh landfill site. Crypto owners surely know by now that this asset class comes with its own set of alarming security risks.

But it’s hard to say how Coinkite’s customers could have avoided this situation. Should every crypto trader be expected to pore over a cold-storage provider’s base computer code before they use it, for fear of being hacked? While many such companies have their systems vetted by security experts and proudly tout their certifications as evidence of surety, these are often just snapshots in time and no guarantee when technology is constantly evolving.