The whole point of an air-gapped hardware wallet is that it never touches the internet. Your keys stay offline, safe from hackers, malware, and all the digital gremlins that haunt crypto holders at night. Coldcard, one of the most trusted names in Bitcoin self-custody, built its reputation on exactly that promise.

That promise just took a serious hit. A firmware vulnerability present in Coldcard devices since March 2021 has been exploited to drain approximately 1,367 BTC, worth roughly $88.6 million to $89 million, from more than 4,500 wallets. The exploit didn’t require internet access to the device. It targeted the randomness used to generate recovery seeds, making them predictable enough for an attacker to reproduce offline.

How the exploit worked

The vulnerability existed in Coldcard firmware versions 4.0.0 through 5.0.3. A critical firmware change made in March 2021 inadvertently caused the device to default to a predictable software Random Number Generator for seed generation instead of utilizing the hardware-based True Random Number Generator, fundamentally undermining the wallet’s security premise. Security experts at Block investigated and revealed the predictable fallback behavior, enabling attackers to enumerate plausible seeds and access user funds without needing physical access to the devices or any network activity.