Decrypt explores how the Coldcard exploit challenges conventional wisdom about air-gapped Bitcoin wallet security.
Security & Exploits ·
Air-gapped wallets maintain private keys in complete offline isolation, preventing direct internet or wireless connectivity and thereby reducing exposure to online attacks. Coldcard, a Bitcoin-only hardware wallet maker, recently experienced a firmware exploit that resulted in over $114 million in user losses, raising questions about the robustness of devices marketed as offering the highest security available for self-custody.
Air-gapped devices achieve isolation through physical separation from networks—no Wi-Fi, Bluetooth, or NFC connectivity—which theoretically shrinks the attack surface for hackers and malware. Several manufacturers including ELLIPAL, Keystone, Foundation Devices, and Blockstream produce air-gapped hardware wallets using methods such as QR codes or microSD cards for transaction signing, positioning these tools as among the strongest protection options for individuals controlling their own keys.
Yet the Coldcard incident demonstrates that offline architecture alone does not guarantee immunity from compromise. The exploit's scale and the involvement of a dedicated Bitcoin-hardware manufacturer suggest vulnerabilities may exist at the firmware or operational level that air-gapping architecture does not automatically prevent. Questions remain about whether similar risks affect other air-gapped wallet producers and what specific vectors enabled the Coldcard breach.