Offline Is Not Enough: What the $114 Million Cold Wallet Sweep Teaches Us About Key Generation
An attacker emptied 1,196 bitcoin wallets in 41 minutes without ever touching a single device. The wallets were air gapped. The keys were not truly random. Here is what that means for anyone who relies on offline storage.
Article record
Why it matters
What this means for organisations holding critical data
An attacker emptied 1,196 bitcoin wallets in 41 minutes without ever touching a single device. The wallets were air gapped. The keys were not truly random. Here is what that means for anyone who relies on offline storage.
Original reporting
Galaxy Research, reported by CoinDesk, BleepingComputer and CBC News, 30 July to 3 August 2026. Surfaced in discussion on LinkedIn by Alex Sverdlov.
Vendor disclosure by Coinkite, manufacturer of the Coldcard hardware wallet.
Read the original CoinDesk reportOn 30 July 2026 an attacker swept roughly 1,083 bitcoin, worth about $70 million, out of 1,196 addresses in a single 41 minute burst. Later waves pushed the running total past 1,800 bitcoin and more than 5,200 addresses, with estimates approaching $114 million. Not one of those wallets was hacked in the way most people imagine. The devices were never touched, never connected and never compromised.
The flaw was in how the keys were created. According to Coinkite, seeds generated on certain Coldcard hardware produced around 40 bits of entropy instead of the intended 128. A seed phrase that should have been unguessable became something a well resourced attacker could enumerate offline, at leisure, and then sweep in one automated pass. Galaxy Research noted that every sweep paid an identical hardcoded 30 satoshis per virtual byte and left no change output, which is the signature of a tool rather than a person.
Why This Matters Beyond Bitcoin
Air gapping is one of the strongest controls available. It is also the control most often misunderstood. Physical separation removes the network path. It does nothing about the quality of the secret the separation is protecting. If the key material is predictable, the attacker does not need a path at all. They can reconstruct the secret on their own hardware and arrive at the front door holding a valid credential.
Every organisation that keeps an offline copy of critical data faces the same question. Was the encryption key generated with real, verifiable entropy, on hardware that has been audited, by a process that can be evidenced? If the answer is uncertain, the offline copy is not as safe as the diagram suggests.
Three Things Went Wrong at Once
- Weak randomness at creation. A defect in firmware reduced entropy by orders of magnitude. Owners had no visible symptom and no way to tell a weak seed from a strong one.
- No key rotation path. Long term holders generated a seed once, years ago, and never revisited it. A latent defect stayed live for as long as the funds did.
- No detection. The first sweep completed roughly 30 hours before the vendor disclosed the flaw. There was no monitoring layer that could have flagged mass enumeration in advance.
How Offline Secure Storage® Approaches This
Physical disconnection is the foundation of Offline Secure Storage®, not the entirety of it. Data sits at Layer 1, physically disconnected at the hardware level, so an attacker who owns the production estate still cannot reach it. That control only holds if the cryptography around it is sound, so the model pairs separation with three further requirements.
Keys are generated on audited hardware with hardware backed entropy, not on general purpose devices with firmware of unknown provenance. Access is granted only within a nominated window, which means enumeration has no standing target to hit. Every session is logged, so a pattern of unusual retrieval attempts is visible rather than invisible.
The point is simple. Offline is the control that removes the network. Verifiable key generation is the control that removes the shortcut around it. You need both.
Firevault Insight
Mark Fermor, Founder of Firevault, puts it plainly. Air gapping without key hygiene is a locked door with the key cut from a published template. The 2026 cold wallet sweeps are the clearest demonstration yet that resilience is not a single control, it is a chain, and the chain is only as strong as the weakest assumption inside it.
For business, this incident should prompt one specific review. Identify where irreplaceable data is held offline, then establish who generated the encryption keys, on what hardware, with what entropy source, and when they were last rotated. If any part of that cannot be evidenced, the offline copy carries a risk that no amount of physical separation will resolve.
Key Takeaways
- Air gapping protects the path, not the secret. Weak key generation defeats physical separation entirely.
- Entropy must be evidenced. Insist on audited hardware and a documented entropy source for any key protecting crown jewel data.
- Rotate on a schedule. A key generated once and never revisited turns a future defect into a present loss.
- Windows beat availability. Data that is only reachable during a nominated access window gives an automated attacker almost nothing to work with.
- Log every session. The sweeps took 41 minutes. Detection has to operate on that timescale, which means retrieval activity must be recorded and reviewed.
Sources: Galaxy Research, Coinkite disclosure, CoinDesk, BleepingComputer, CBC News.
Sources
Where this reporting comes from
How Firevault would handle this
Physical disconnection removes the path an attacker needs
Offline Secure Storage® holds a clean copy of your data on hardware that is physically disconnected, so an intrusion cannot reach it, encrypt it or delete it.






