All NewsEducationTV
Equities & FundsCrypto & Digital AssetsAI & TechnologyBusiness & CorporateUS Politics & PolicyGeopolitics & Global RiskMacro, Rates & FXCommodities & EnergyEuropean Politics & MarketsAsia-PacificReal Estate & Property
Story archiveAll categories
← All Stories

Coldcard Exploit Highlights Risks in Air-Gapped Bitcoin Wallets

Created at 3 Aug · 8:46 PM1 source↑ Market-relevant
IN SHORT

A firmware flaw in Coldcard, a popular air-gapped Bitcoin wallet, led to over $114 million in user losses. The exploit underscores that even offline wallets are vulnerable to hardware, firmware, and random number generation flaws, emphasizing the need for diversified storage.

✉Newsletter

PiQ Daily

Pick your topics. Get only what matters, on your cadence.

Key Numbers

$114 millionuser losses from Coldcard exploit
March 2021firmware error introduced
2017Coldcard introduced

Who's Involved

Coldcard
Bitcoin hardware wallet maker targeted by exploit
Galaxy Research
Researchers who detailed the Coldcard exploit
ELLIPAL
Maker of air-gapped Titan wallets
Keystone
Maker of air-gapped wallets using QR codes
Foundation Devices
Maker of Bitcoin-focused Passport wallet
Blockstream
Maker of Jade wallet supporting air-gapped transactions
Coldcard Exploit Highlights Risks in Air-Gapped Bitcoin Wallets

↳ Why This Matters

The Coldcard exploit demonstrates that even the most secure offline cryptocurrency storage methods can be compromised by internal flaws, underscoring the inherent risks in self-custody and the critical importance of robust security practices and diversification for digital asset holders.

Key facts

  • Air-gapped wallets are designed to be completely isolated from the internet and wireless networks.
  • A firmware exploit affecting Coldcard wallets has led to over $114 million in user losses.
  • The vulnerability was caused by a firmware build error that reduced the pool of possible values for seed phrases.
  • This reduced randomness made private keys vulnerable to guessing, including by AI.
  • Even air-gapped wallets rely on the security of their hardware, firmware, and random number generation practices.
  • Security experts recommend against holding all cryptocurrency in a single wallet to mitigate risks.

Air-gapped cryptocurrency wallets, designed to remain completely disconnected from the internet and wireless networks, offer a high level of security for private keys. However, a recent exploit affecting Coldcard, a prominent Bitcoin hardware wallet, has resulted in user losses exceeding $114 million, highlighting that even these offline solutions are not entirely immune to threats.

The exploit, disclosed in late July 2026, stemmed from a firmware build error introduced in March 2021. This error significantly reduced the randomness of the seed phrases generated by affected Coldcard wallets, making the private keys more predictable and vulnerable to guessing, including through AI-powered attacks. This reduced security directly compromises the control of users' digital assets.

While air-gapped wallets like those from ELLIPAL, Keystone, Foundation Devices, and Blockstream aim to minimize the attack surface by avoiding direct online connections, their security ultimately depends on the integrity of their hardware, firmware, and random number generation processes. The Coldcard incident, which saw losses grow from approximately $88 million to nearly $114 million within days, has prompted many users to move their Bitcoin to safer addresses.

Security experts emphasize that an air gap is a crucial layer of defense against online threats but does not guarantee complete safety. They advise users to diversify their holdings across multiple wallets and platforms to avoid single points of failure, as human error or design flaws can still lead to significant financial losses.

Frequently asked questions

An air-gapped wallet is a type of cryptocurrency wallet that is designed to never connect to the internet or any wireless networks, keeping private keys completely isolated from online threats.

A firmware build error in Coldcard wallets reduced the randomness of seed phrase generation, making private keys more predictable and vulnerable to guessing by attackers.

No, air-gapped wallets offer strong protection against online attacks. However, they are not immune to flaws in hardware, firmware, or random number generation, as demonstrated by the Coldcard incident.

Security experts recommend diversifying holdings across multiple wallets and platforms to avoid single points of failure and to protect against potential exploits or loss of access.

What Happens Next

01Users continue to migrate funds from potentially vulnerable Coldcard wallets.
02Further analysis of the Coldcard firmware vulnerability is expected.

Get the newsletter.

Pick the topics you actually care about. We'll email when there's news worth your time, on the cadence you choose. Cancel any time from your account.

Cadence

How It Developed

Air-gapped wallets are designed to remain disconnected from the internet to protect private keys.
Coldcard, a Bitcoin hardware wallet maker, experienced a firmware exploit.
The exploit resulted in user losses totaling over $114 million in Bitcoin.
The flaw stemmed from a firmware build error that reduced the randomness of seed phrase generation.
Security experts noted that air-gapped wallets are not immune to vulnerabilities in hardware, firmware, or random number generation.
Users were advised to avoid single points of failure and consider diversifying their crypto holdings.

Sources

T1
What Is an Air-Gapped Bitcoin Wallet? Why the Coldcard Exploit Changes the Conversation About Offline SecurityDecrypt

Related Stories

Coldcard flaw highlights hardware wallet testing gap: Kraken security chief
3 Aug · 4:21 AM
Bitcoin, Ether Fall as Coldcard Exploit Continues
3 Aug · 10:56 AM
Coldcard Bitcoin Hack Losses Exceed $114 Million
3 Aug · 1:16 PM
Solo Bitcoin miner nets $200,000 as Coldcard exploit rattles holders
3 Aug · 11:26 AM
Bitcoin Falls Below $63,000 Amid Coldcard Exploit, Ignoring Macro Gains
3 Aug · 6:21 AM