▼ Bear
Impact
100 · High
Cold card firmware vulnerability leads to 11.4 billion won in damages... Limitations of air-gapped wallets
BTC
Decrypt · 2d agoView original ↗

Air-gapped wallets are non-custodial hardware wallets that are physically isolated from all wireless communication, including Wi-Fi, Bluetooth, and NFC, as well as the internet. Their main advantage is that the private keys are not exposed to the online environment, which significantly reduces the attack surface against malware or remote hacking attempts. Some of the leading manufacturers include ELLIPAL, which uses QR codes, Keystone, Foundation Devices (Passport), Blockstream (Jade), and CoinKite, which produces cold cards. In contrast, Ledger and Trezor connect via USB or Bluetooth, and therefore do not strictly qualify as air-gapped wallets.
The Coldcard, launched in 2017, supports offline signing using a microSD card and QR codes, and has long been considered one of the most security-focused Bitcoin hardware wallets. However, on the last day of July 2026, the manufacturer, CoinKite, revealed that some Coldcard devices were generating seed phrases with a much smaller entropy pool than intended due to a firmware build error introduced in March 2021. This means that the randomness required for protecting private keys was significantly reduced, making it possible for attackers to potentially guess private keys more quickly using AI or specialized software.
Galaxy Research analyzed that this Coldcard exploit unfolded in multiple waves. The observed losses initially amounted to approximately $8.8 million, but within a few days, the Bitcoin losses ballooned to nearly $11.4 million. Following the researchers' warnings, many Coldcard users moved their Bitcoin from the affected addresses, but concerns remain that other vulnerable addresses could still be targeted.
This incident highlights the supply chain risks inherent in hardware wallets, rather than the limitations of the air-gapped method itself. Even though the wallet is not connected to the internet, users ultimately rely on the manufacturer's firmware quality, random number generation logic, and software development practices. While air-gapping provides a crucial layer of defense, it does not guarantee that the device is completely free from vulnerabilities.
Security experts repeatedly emphasize that cryptocurrency holders should avoid single points of failure, meaning they should not store all their assets in one place. They also remind users of the fundamental principles of securely storing recovery phrases, always verifying transaction details before signing, and paying attention to the physical security of the device.
This is an AI summary. Read the full article at the source.