A Daily Network publication
Explore the network
Digital Capital Daily
Independent Intelligence on Institutional Digital Assets
Wednesday, August 19, 2026The Morning Brief →Sign in
Custody & Infrastructure

Coldcard's $100M hack: the air-gap's blind spot

The wallet never touched the internet, yet it was drained. The vulnerability was in how its seed phrase was created.

On July 29, Jonathan Goodman had done everything right. His Coldcard hardware wallet never touched the internet. It sat in a safe deposit box. The seed phrase, shared with no one, sat in a second box. Then every wallet he owned was emptied anyway. Goodman, a Toronto entrepreneur, reported losing 18.25 bitcoin. At the time of the theft, that was just over $1.17 million. “Perhaps the hardest part about this is that I did everything right,” he wrote Aug. 1 on X.

His loss was one thread in a much larger attack. Galaxy Research has high confidence that 1,596 bitcoin were stolen. The theft spread across about 7,300 addresses. At that moment the haul was worth over $100 million. Galaxy’s Alex Thorn estimated on Aug. 4 that at least 15 different attackers were working the same flaw. None of them needed physical access to a device.

The seed phrase is generated by code, and that code turned out to be the weak point. Coinkite, Coldcard’s maker, shipped it with a bug that went unnoticed for years. The device’s security premise — secrets that never leave the chip, no network port to attack — collapsed at the one point nobody audited: how the randomness was created.

Cold storage's unverified layer

Hardware wallets sit between paper and software. They are harder to hack than a hot wallet and harder to lose than paper. But they carry a hidden risk: the user must trust the device to make keys correctly in the first place. Crypto’s own maxim, “don’t trust, verify,” was not applied to that step for Coldcard. The largest known theft from a hardware wallet followed, at a cost of $100 million.

For RIAs and family offices in self-custody, the Coldcard case points to a less glamorous approach. Key generation should be independently verified. Multi-signature setups should survive one compromised device. Or hand keys to a qualified custodian whose entire infrastructure gets audited. Air-gapped storage has been treated as the gold standard; it is only as strong as the firmware that creates the seed. “Air-gapped systems help, but they are not a perfect fix,” Bobby Gray of TEXITcoin told CoinDesk. “Security has to begin with how the keys are generated and continue through every part of the custody process.”

The wider custody market faces the same question. As institutions push more assets onchain, they will reach for hardware-style security for private keys. A hardware wallet can anchor trust, but it cannot replace verification. The code that generates keys, the randomness source, the firmware update process — every layer needs an audit trail. Coldcard failed at exactly that step, and $100 million in user funds paid the price.

The answer is not to blacklist one vendor. It is to treat key generation as part of the audit, not a given. A single bad seed should not be able to empty a custody operation. The next breach may not arrive over the internet. It will arrive through a gap in the chain that nobody thought to verify.

Sources & further reading
CoinDesk
More from Digital Capital Daily
ETPs & Funds

Neuberger Berman puts a credit fund on Securitize's rails

The filing landed just as Securitize reported record assets and shrinking fees, raising the question of who collects when the wrapper is a commodity.
The Wrap

Stablecoin oversight is becoming a dollar funding problem

The Treasury's GENIUS Act definitions and a BIS-IMF paper decide which institutions absorb the dollar pressure that stablecoin demand creates.
Elsewhere in the networkAll titles →
Every weekday · 6:30 a.m. ET

The Morning Brief

The private wealth industry in four minutes, every weekday at 6:30 a.m. ET. Free.