Cold Wallets Not as Secure as Thought: Software Flaw Exposes Thousands of Bitcoin
The security of cryptocurrency wallets relies heavily on their ability to generate and store unique private keys. However, in July 2026, a software flaw in certain Coldcard devices allowed attackers to drain thousands of Bitcoin from these wallets, despite them being offline and air-gapped.
The exploit was due to the devices producing weak or predictable private keys, which could be guessed by attackers. This highlights the importance of true randomness in generating private keys, as well as the potential for even 'cold' storage solutions to have vulnerabilities.
Cold wallets are designed to keep private keys isolated from any potential threats on a network, but the Coldcard bug showed that this isolation is not foolproof. The devices remained 'cold' throughout the attack, with attackers remotely triggering transactions and draining funds without ever having to physically access them.