Nearly $114 million in Bitcoin vanished in a matter of days from Coldcard, one of the hardware wallets that has been considered the most secure since 2017. The total loss has risen rapidly from the initial estimate of $88 million first reported by Galaxy Research data.
The attack occurred in several consecutive waves. A total of 1,196 user wallet addresses were completely drained, with the fourth wave alone sucking up 448 BTC. Yet, since its introduction by the company Coinkite in 2017, Coldcard has been positioned as a Bitcoin-only wallet immune to online attacks through the implementation of an air-gapped system.
This system ensures that the user’s private keys remain entirely offline. Transaction signing is only performed via physical intermediaries such as microSD cards or QR code scans, without ever touching Wi-Fi networks, Bluetooth connections, or NFC. This approach differs significantly from popular hardware wallets like Ledger and Trezor, which generally still rely on USB cable connections or Bluetooth connections to a computer.
Why Internet-Free Defenses Could Be Breached
The problem triggering this hundred-million-dollar loss turned out to be embedded in the wallet’s blueprint itself. The Coinkite team revealed an error in the firmware build they had distributed since March 2021. This bug caused some Coldcard units to generate seed phrases from a pool of values much smaller than the standard requirement.
This vulnerability reduced the level of randomness that forms the foundation of private key protection. When the variation of numbers shrank drastically, the sequence of seed phrases protecting the funds became vulnerable to guessing, especially by hackers utilizing AI assistance. This case serves as proof that the security of air-gapped wallets - which compete in the market with brands like ELLIPAL Titan, Keystone, Foundation Passport, and Blockstream Jade - is never absolute. Their security still depends on the quality of the hardware, firmware, random number generators, and the standard practices of the manufacturing team.
The Real Limits of the Verification Slogan
This incident exposes the weak point of the self-reliance ethos in the crypto world. Commenting on the hack, Jameson Lopp highlighted that the Coldcard exploit shows the real limits of the popular mantra on the Bitcoin network, namely ‘don’t trust, verify’. In practice, hardware wallet users still place their fate in the security and integrity of the manufacturer, simply because humans are prone to making manufacturing errors.
In the wake of this series of incidents, many Coldcard users have taken a U-turn. Instead of sticking to the principle of self-custody for their crypto keys, they have started moving their remaining Bitcoin to centralized exchanges in search of protection - an anomaly amidst the self-custody trend that has long been a hallmark of the crypto community.
As reported by Decrypt.
Disclaimer: This article is for informational and educational purposes only, not financial advice. Cryptocurrency assets are highly volatile and carry significant risk. Always do your own research (DYOR) and never invest more than you can afford to lose.