Key facts
- Air-gapped wallets are designed to be completely isolated from the internet and wireless networks.
- A firmware exploit affecting Coldcard wallets has led to over $114 million in user losses.
- The vulnerability was caused by a firmware build error that reduced the pool of possible values for seed phrases.
- This reduced randomness made private keys vulnerable to guessing, including by AI.
- Even air-gapped wallets rely on the security of their hardware, firmware, and random number generation practices.
- Security experts recommend against holding all cryptocurrency in a single wallet to mitigate risks.
Air-gapped cryptocurrency wallets, designed to remain completely disconnected from the internet and wireless networks, offer a high level of security for private keys. However, a recent exploit affecting Coldcard, a prominent Bitcoin hardware wallet, has resulted in user losses exceeding $114 million, highlighting that even these offline solutions are not entirely immune to threats.
The exploit, disclosed in late July 2026, stemmed from a firmware build error introduced in March 2021. This error significantly reduced the randomness of the seed phrases generated by affected Coldcard wallets, making the private keys more predictable and vulnerable to guessing, including through AI-powered attacks. This reduced security directly compromises the control of users' digital assets.
While air-gapped wallets like those from ELLIPAL, Keystone, Foundation Devices, and Blockstream aim to minimize the attack surface by avoiding direct online connections, their security ultimately depends on the integrity of their hardware, firmware, and random number generation processes. The Coldcard incident, which saw losses grow from approximately $88 million to nearly $114 million within days, has prompted many users to move their Bitcoin to safer addresses.
Security experts emphasize that an air gap is a crucial layer of defense against online threats but does not guarantee complete safety. They advise users to diversify their holdings across multiple wallets and platforms to avoid single points of failure, as human error or design flaws can still lead to significant financial losses.
