Key Takeaways: An offline Coldcard wallet was drained without physical access, proving air-gapped keys can still be guessable.
Key Takeaways: An offline Coldcard wallet was drained without physical access, proving air-gapped keys can still be guessable.

Attackers drained 1,367 BTC, about $86 million, from more than 4,500 Coldcard wallet addresses across three waves, exploiting a March 2021 firmware flaw that never required physical access to a single device.
"The attack is ongoing — move your funds off Coldcard-generated addresses immediately if you have not done so," Alex Thorn, head of research at Galaxy Research, said on X.
Galaxy traced the first wave to July 30, when 1,082.65 BTC was swept from 1,196 addresses in 41 minutes. A second wave added roughly 208 BTC from 1,912 addresses, and a third drained 207.73 BTC, lifting the tally to 1,367.05 BTC across 4,585 addresses. The stolen coins had sat untouched for an average of 3.18 years before being taken, a sign the victims were long-term holders.
The breach breaks the core promise of self-custody — that a key stored offline is unreachable — and has pushed some holders to move Bitcoin back onto exchanges, inverting the industry's "not your keys, not your coins" ethos.
Coinkite, the Canadian maker of the Coldcard, confirmed the flaw traced to a March 2021 firmware error in its pseudo-random number generator. Instead of routing seed-phrase generation through the device's hardware random-number generator, the bug pushed part of the process through a software-based generator tied to predictable values such as the chip's serial number and clock registers. That shrank the key space from cryptographically vast to countable, letting attackers generate candidate seeds, derive addresses, and check them against the public blockchain without touching a victim's device.
Coinkite initially warned users of Mk3 devices running firmware 4.0.1 or later, later expanding the advisory to certain Mk4, Mk5, and Coldcard Q builds. Emergency firmware updates were released, and CEO Rodolfo Novak apologized, taking "full accountability" for the bug. But updating firmware does not fix seeds generated on a vulnerable build; users must create a new seed and migrate funds. Jan3 CEO Samson Mow urged all Coldcard users to move their funds, while Block's Clay Garrett said a paid account was used to identify source addresses and the information has been passed to authorities.
The incident fits a broader 2026 pattern in which key-compromise events, though fewer in number, account for most dollar losses in crypto. Galaxy has flagged roughly 600 suspected attacker addresses to federal investigators and compliance firms. Bitcoin traded near $62,250 on Monday, down 1.4 percent, as the exploit added to bearish sentiment; Santiment data showed the positive-to-negative social commentary ratio falling to about 0.58, among the most negative readings the firm has tracked. For holders, the lesson is that a hardware wallet's strength rests on the randomness used for key generation — and that entropy verification, not brand reputation, is the real security boundary.
This article is for informational purposes only and does not constitute investment advice.