Industry Insight·6 August 2026

Offline Is Not Enough: What the $114 Million Cold Wallet Sweep Teaches Us About Key Generation

An attacker emptied 1,196 bitcoin wallets in 41 minutes without ever touching a single device. The wallets were air gapped. The keys were not truly random. Here is what that means for anyone who relies on offline storage.

Mark Fermor
Mark FermorDirector & Co-Founder, Firevault
4 min read
Share
Matte black bitcoin hardware wallet on a steel workbench beside an unplugged cable, scattered dice and a printed seed phrase card, lit in magenta and cyan
Industry Insight

Article record

Industry InsightCategory
6 August 2026Published
4 min readReading time
Mark FermorWritten by
Matte black bitcoin hardware wallet on a steel workbench beside an unplugged cable, scattered dice and a printed seed phrase card, lit in magenta and cyan

Why it matters

What this means for organisations holding critical data

An attacker emptied 1,196 bitcoin wallets in 41 minutes without ever touching a single device. The wallets were air gapped. The keys were not truly random. Here is what that means for anyone who relies on offline storage.

Original reporting

Galaxy Research, reported by CoinDesk, BleepingComputer and CBC News, 30 July to 3 August 2026. Surfaced in discussion on LinkedIn by Alex Sverdlov.

Vendor disclosure by Coinkite, manufacturer of the Coldcard hardware wallet.

Read the original CoinDesk report

On 30 July 2026 an attacker swept roughly 1,083 bitcoin, worth about $70 million, out of 1,196 addresses in a single 41 minute burst. Later waves pushed the running total past 1,800 bitcoin and more than 5,200 addresses, with estimates approaching $114 million. Not one of those wallets was hacked in the way most people imagine. The devices were never touched, never connected and never compromised.

The flaw was in how the keys were created. According to Coinkite, seeds generated on certain Coldcard hardware produced around 40 bits of entropy instead of the intended 128. A seed phrase that should have been unguessable became something a well resourced attacker could enumerate offline, at leisure, and then sweep in one automated pass. Galaxy Research noted that every sweep paid an identical hardcoded 30 satoshis per virtual byte and left no change output, which is the signature of a tool rather than a person.

Why This Matters Beyond Bitcoin

Air gapping is one of the strongest controls available. It is also the control most often misunderstood. Physical separation removes the network path. It does nothing about the quality of the secret the separation is protecting. If the key material is predictable, the attacker does not need a path at all. They can reconstruct the secret on their own hardware and arrive at the front door holding a valid credential.

Every organisation that keeps an offline copy of critical data faces the same question. Was the encryption key generated with real, verifiable entropy, on hardware that has been audited, by a process that can be evidenced? If the answer is uncertain, the offline copy is not as safe as the diagram suggests.

Three Things Went Wrong at Once

  • Weak randomness at creation. A defect in firmware reduced entropy by orders of magnitude. Owners had no visible symptom and no way to tell a weak seed from a strong one.
  • No key rotation path. Long term holders generated a seed once, years ago, and never revisited it. A latent defect stayed live for as long as the funds did.
  • No detection. The first sweep completed roughly 30 hours before the vendor disclosed the flaw. There was no monitoring layer that could have flagged mass enumeration in advance.

How Offline Secure Storage® Approaches This

Physical disconnection is the foundation of Offline Secure Storage®, not the entirety of it. Data sits at Layer 1, physically disconnected at the hardware level, so an attacker who owns the production estate still cannot reach it. That control only holds if the cryptography around it is sound, so the model pairs separation with three further requirements.

Keys are generated on audited hardware with hardware backed entropy, not on general purpose devices with firmware of unknown provenance. Access is granted only within a nominated window, which means enumeration has no standing target to hit. Every session is logged, so a pattern of unusual retrieval attempts is visible rather than invisible.

The point is simple. Offline is the control that removes the network. Verifiable key generation is the control that removes the shortcut around it. You need both.

Firevault Insight

Mark Fermor, Founder of Firevault, puts it plainly. Air gapping without key hygiene is a locked door with the key cut from a published template. The 2026 cold wallet sweeps are the clearest demonstration yet that resilience is not a single control, it is a chain, and the chain is only as strong as the weakest assumption inside it.

For business, this incident should prompt one specific review. Identify where irreplaceable data is held offline, then establish who generated the encryption keys, on what hardware, with what entropy source, and when they were last rotated. If any part of that cannot be evidenced, the offline copy carries a risk that no amount of physical separation will resolve.

Key Takeaways

  • Air gapping protects the path, not the secret. Weak key generation defeats physical separation entirely.
  • Entropy must be evidenced. Insist on audited hardware and a documented entropy source for any key protecting crown jewel data.
  • Rotate on a schedule. A key generated once and never revisited turns a future defect into a present loss.
  • Windows beat availability. Data that is only reachable during a nominated access window gives an automated attacker almost nothing to work with.
  • Log every session. The sweeps took 41 minutes. Detection has to operate on that timescale, which means retrieval activity must be recorded and reviewed.

Sources: Galaxy Research, Coinkite disclosure, CoinDesk, BleepingComputer, CBC News.

Sources

Where this reporting comes from

01
Original reportPrimary coverage referenced in this analysisView original article

About the author

Mark Fermor

Mark Fermor

Director & Co-Founder

Co-founder of Firevault, focused on offline secure storage and protecting individuals and businesses from fraud, fines, loss and damage. Speaker, owner and advisor.

How Firevault would handle this

Physical disconnection removes the path an attacker needs

Offline Secure Storage® holds a clean copy of your data on hardware that is physically disconnected, so an intrusion cannot reach it, encrypt it or delete it.

HardwareYour data sits on dedicated encrypted hardware
DisconnectOffline by default, connected only when you say so
CommandAccess windows and retrieval under your control
LocationHeld in a secure Firevault Bunker

Share this article

Industry Insight6 August 20264 min read

Offline Is Not Enough: What the $114 Million Cold Wallet Sweep Teaches Us About Key Generation

An attacker emptied 1,196 bitcoin wallets in 41 minutes without ever touching a single device. The wallets were air gapped. The keys were not truly random. Here is what that means for anyone who relies on offline storage.

Offline Is Not Enough: What the $114 Million Cold Wallet Sweep Teaches Us About Key Generation
Mark Fermor
Published by Mark Fermor, Director & Co-Founder

    Your privacy matters

    We use cookies to keep the site running smoothly and to understand how you use it. You are in control. Privacy Charter · Cookie Policy