Air-Gap Myth: Coldcard Exploit Drains $114M in $BTC From Wallets Built to Skip the Internet 🧊
Back to feed

Air-Gap Myth: Coldcard Exploit Drains $114M in $BTC From Wallets Built to Skip the Internet 🧊

An exploit targeting Coldcard hardware wallets has resulted in losses totaling $114 million in $BTC and counting, raising fresh concerns about the security of air-gapped Bitcoin storage. Coldcard, a Bitcoin-only hardware wallet made by Coinkite, supports offline transaction signing through microSD cards and optional QR codes, and is among the most widely used devices marketed as fully air-gapped. The incident underscores that even wallets designed to remain physically isolated from the internet can be exposed through compromised firmware.

Air-gapped wallets are a category of non-custodial, self-custody wallets engineered to stay permanently disconnected from the internet and all wireless communication, including Wi-Fi, Bluetooth, and NFC. Because the devices never connect to online networks directly, they are intended to present a smaller attack surface for hackers, malware, and phishing attempts. Crypto wallets do not store the underlying assets themselves; they store the public and private cryptographic keys used to access funds recorded on a blockchain. A public key functions like an account number that others can use to send crypto, while a private key acts as a digital signature authorizing outgoing transactions. Custodial wallets, such as those provided by centralized exchanges like Coinbase, leave key management to a third party, whereas non-custodial or self-custody wallets place that responsibility entirely on the user.

Several hardware wallet manufacturers build devices specifically for air-gapped operation. ELLIPAL's Titan wallets and Keystone devices both rely on QR codes instead of USB or Bluetooth connections. Foundation Devices produces the Bitcoin-focused Passport wallet, and Blockstream's Jade wallet supports fully air-gapped $BTC transactions using QR codes. Coldcard, based in Canada, has been a prominent player in the Bitcoin-only hardware wallet segment for years. Other wallet formats include paper wallets, which consist of printed or handwritten copies of a private key or recovery phrase, as well as software and mobile wallet applications.

On July 31, small Bitcoin holders moved coins on-chain at a rate not seen since the collapse of FTX, according to CryptoQuant data, a level of activity that coincided with reporting around the Coldcard exploit and subsequent losses. Coldcard has not publicly confirmed the full scope of the breach, and affected users have reported varying outcomes depending on firmware versions and operational practices. The phrase "not your keys, not your coins," a staple of crypto self-custody culture, frames the trade-off: users who hold their own private keys accept full responsibility for securing them.

Air-gapped designs rely on the assumption that physically isolating signing devices from networked systems neutralizes remote attack vectors, a principle that the Coldcard exploit has now tested in practice. Losses continue to be tallied as investigators and users review affected devices, and the episode is likely to inform security reviews across the broader hardware wallet industry.

Mentioned Coins

$BTC
Share:
Publishercryptonewsroom.xyz
Published—
CategorySecurity

Disclaimer: This content is for information and entertainment purposes only. It does not constitute financial, investment, legal, or tax advice. Always do your own research and consult with qualified professionals before making any financial decisions.

See our Terms of Service, Privacy Policy, and Editorial Policy.