Air-Gapped Myth SHATTERS

The hardware wallet many Bitcoin holders trusted as their safest vault just turned into a single point of failure that let attackers drain nearly $89 million in minutes.

Story Snapshot

  • Hackers stole about 1,367 Bitcoin, worth up to $89 million, from Coldcard users in three waves of attacks.
  • A firmware bug dating back to 2021 made some Coldcard seed phrases weak and predictable, even without physical access.
  • Galaxy Research traced a 41-minute sweep of 1,196 addresses for about $70 million as the core event.
  • The incident shattered the idea that “air-gapped” hardware wallets are automatically safe self-custody.

A trusted cold wallet turns into an open door

Coldcard built its reputation as a “Bitcoin-only,” air-gapped hardware wallet for serious holders who wanted to stay far away from hacked exchanges and shady apps.

The device came from Canadian maker Coinkite and aimed squarely at the crowd that believes, with reason, that self-custody is the only way to keep the government, banks, and woke corporates away from their money.

That is exactly what made what followed so shocking: the danger came not from a hostile third party, but from the tool they trusted most.

Security teams now say a flaw in Coldcard’s firmware, present in certain versions since March 2021, quietly weakened the “seed phrases” that protect users’ Bitcoin.

Instead of always using the device’s dedicated hardware random number generator to create those seeds, some devices fell back to a software generator that produced numbers that were too predictable for serious cryptography.

That mistake turned a supposedly unique secret into something that a determined attacker could brute-force offline, with no phishing and no malware needed.

The first wave: 41 minutes, 1,196 addresses, about $70 million

The attack moved from theory to painful reality just before dawn on July 30, 2026. Galaxy Research tracked an on-chain sweep where an attacker drained 1,082.65 Bitcoin from 1,196 addresses in a 41-minute window, worth around $70 million at the time.

Fox Business and other outlets reported the same pattern: more than 1,000 Bitcoin, gone from more than 1,200 Coldcard-generated wallets in less than an hour. For many victims, their coins had sat untouched for years, and then vanished in a single automated blast.

On-chain forensics showed a tight, almost machine-like operation. Funds jumped from hundreds of separate wallets into a small number of attacker-controlled addresses. Researchers said the pattern matched a single entity who already knew the victims’ seeds, rather than a broad phishing wave.

That alignment with the known firmware bug pushed experts toward one clear explanation: someone had figured out how to reverse engineer the flawed seed generation and was now draining any wallet that used it.

Two more waves push losses toward $89 million

The first sweep was not the end. Galaxy Research and multiple news outlets later described three waves of theft tied to the same Coldcard issue. A second wave on July 31 hit roughly 500 Coldcard wallets, draining about 594 Bitcoin—around $38 million—in less than half an hour.

A third wave, identified around August 1–2, pulled another roughly 208 Bitcoin from nearly 1,900 addresses. By the time researchers added everything up, attackers had taken about 1,367 Bitcoin from 4,585 addresses, worth close to $89 million.

Coldcard’s maker, Coinkite, responded with an emergency warning to users. The company said the vulnerability tied back to a firmware integration error and affected seeds generated on certain Mk3, Mk4, Mk5, and Q devices before specific fixed versions.

That advisory did two things at once. It confirmed the bug was real and went back years. It also made clear that not every Coldcard ever sold was at risk, but the damaged trust landed on the entire brand.

What this means for self-custody and common-sense security

This hack is a wake-up call for anyone who believed buying a hardware wallet ended the security conversation. The heart of in-money is simple: do not rely on fragile central points of control, and do not trust black-box systems you cannot audit.

The Coldcard flaw violated that principle. It turned a single firmware decision made in 2021 into a hidden risk for thousands of savers who thought they had opted out of systemic failure.

The lesson is not “self-custody is bad.” Galaxy’s report and follow-up coverage stress that the only wallets untouched by this exploit were those whose seeds never relied on the flawed generator in the first place. That is the kind of redundancy a cautious saver should demand.

Sources:

crypto.news, cryptopolitan.com, finance.yahoo.com, dextools.io, youtube.com, kucoin.com