For people who chose cold storage specifically to avoid internet exposure, the attack was shocking.
Jonathan Goodman, one of the victims, wrote on X, "My Bitcoin was in cold storage. My keys were on a ColdCard device kept in a safety deposit box that had never been connected to the internet."
Why does it matter?
Cold wallets are popular because keeping crypto off the internet is supposed to reduce exposure to online attacks. But the Coldcard breach has shown that separation from the web means little if the software that creates the wallet's keys is flawed.
As Aneirin Flynn, chief executive officer of cybersecurity technology firm Failsafe, told Bloomberg, "It exposes the fallacy of your crypto being offline. The device is just responsible for generating your passwords, and if the underlying math is broken then your passwords can be reverse-engineered."
Crypto transactions are generally irreversible, which makes stolen funds difficult to recover.
TRM Labs said crypto theft totaled $972 million in the first half of 2026, down from $2.3 billion in the same stretch last year. Even so, the number of hacks rose to 207, the highest ever recorded over a six-month period.
Supporters of cryptocurrency often point to financial independence and even the potential for some operations to support cleaner energy development, while critics cite major security risks and the heavy electricity demands tied to parts of the industry, especially Bitcoin mining.
What's being done?
Coinkite said fixed firmware is now available for every affected model and release track, while also warning that "funds controlled by seeds generated on affected firmware are at risk."
Users with affected devices cannot assume offline storage still protects them. It can still reduce some risks, but it cannot compensate for weak software design.
Recalling the moment he checked his wallet, Goodman said, "The moment it loaded I knew I was screwed because I saw red lines for withdrawals."