---
title: "Offline Is Not Enough: What the $114 Million Co… | Firevault"
description: "An attacker emptied 1,196 bitcoin wallets in 41 minutes without ever touching a single device. The wallets were air gapped. The keys were not truly random.…"
lang: en-GB
json-ld: |
  [
    {
      "@context": "https://schema.org",
      "@type": "Organization",
      "@id": "https://fire-vault.com/#organization",
      "name": "Firevault",
      "legalName": "Firevault Limited",
      "url": "https://fire-vault.com",
      "logo": {
        "@type": "ImageObject",
        "url": "https://fire-vault.com/logo.png",
        "width": 200,
        "height": 60
      },
      "foundingDate": "2025-03",
      "description": "Protect what matters with Offline Secure Storage and control what moves with Control by Firevault. Physically disconnected, always reachable by you.",
      "address": {
        "@type": "PostalAddress",
        "addressCountry": "GB",
        "addressLocality": "United Kingdom"
      },
      "contactPoint": [
        {
          "@type": "ContactPoint",
          "contactType": "customer service",
          "email": "hello@fire-vault.com",
          "availableLanguage": "English",
          "areaServed": [
            "GB",
            "EU",
            "US",
            "AE"
          ]
        }
      ],
      "sameAs": [
        "https://www.linkedin.com/company/firevault",
        "https://x.com/firevaultuk"
      ],
      "slogan": "Disconnect to Protect",
      "knowsAbout": [
        "Offline Secure Storage",
        "Physical Air Gap Data Protection",
        "Ransomware Protection",
        "Data Sovereignty",
        "GDPR Compliance",
        "NIS2 Compliance"
      ]
    },
    {
      "@context": "https://schema.org",
      "@type": "WebSite",
      "@id": "https://fire-vault.com/#website",
      "name": "Firevault",
      "alternateName": [
        "Firevault",
        "Firevault UK",
        "Firevault Limited"
      ],
      "url": "https://fire-vault.com",
      "publisher": {
        "@id": "https://fire-vault.com/#organization"
      },
      "inLanguage": "en-GB",
      "description": "Protect what matters with Offline Secure Storage and control what moves with Control by Firevault. Physically disconnected, always reachable by you.",
      "potentialAction": {
        "@type": "SearchAction",
        "target": {
          "@type": "EntryPoint",
          "urlTemplate": "https://fire-vault.com/learn?q={search_term_string}"
        },
        "query-input": "required name=search_term_string"
      }
    },
    {
      "@context": "https://schema.org",
      "@type": "WebPage",
      "@id": "https://fire-vault.com/news/cold-wallet-seed-entropy-flaw-offline-is-not-enough#webpage",
      "url": "https://fire-vault.com/news/cold-wallet-seed-entropy-flaw-offline-is-not-enough",
      "name": "Offline Is Not Enough: What the $114 Million Co…",
      "description": "An attacker emptied 1,196 bitcoin wallets in 41 minutes without ever touching a single device. The wallets were air gapped. The keys were not truly random.…",
      "isPartOf": {
        "@id": "https://fire-vault.com/#website"
      },
      "about": {
        "@id": "https://fire-vault.com/#organization"
      },
      "primaryImageOfPage": {
        "@type": "ImageObject",
        "url": "https://fire-vault.com/hero-images/cold-wallet-seed-entropy-2026-vibrant.jpg"
      },
      "inLanguage": "en-GB",
      "breadcrumb": {
        "@id": "https://fire-vault.com/news/cold-wallet-seed-entropy-flaw-offline-is-not-enough#breadcrumb"
      }
    },
    {
      "@context": "https://schema.org",
      "@type": "BreadcrumbList",
      "@id": "https://fire-vault.com/news/cold-wallet-seed-entropy-flaw-offline-is-not-enough#breadcrumb",
      "itemListElement": [
        {
          "@type": "ListItem",
          "position": 1,
          "name": "Home",
          "item": "https://fire-vault.com"
        },
        {
          "@type": "ListItem",
          "position": 2,
          "name": "Learn",
          "item": "https://fire-vault.com/learn"
        },
        {
          "@type": "ListItem",
          "position": 3,
          "name": "Knowledge Vault",
          "item": "https://fire-vault.com/learn/knowledge"
        },
        {
          "@type": "ListItem",
          "position": 4,
          "name": "Offline Is Not Enough: What the $114 Million Cold Wallet Sweep Teaches Us About Key Generation",
          "item": "https://fire-vault.com/news/cold-wallet-seed-entropy-flaw-offline-is-not-enough"
        }
      ]
    },
    {
      "@context": "https://schema.org",
      "@type": "NewsArticle",
      "headline": "Offline Is Not Enough: What the $114 Million Cold Wallet Sweep Teaches Us About Key Generation",
      "description": "An attacker emptied 1,196 bitcoin wallets in 41 minutes without ever touching a single device. The wallets were air gapped. The keys were not truly random. Here is what that means for anyone who relies on offline storage.",
      "url": "https://fire-vault.com/news/cold-wallet-seed-entropy-flaw-offline-is-not-enough",
      "image": [
        {
          "@type": "ImageObject",
          "url": "https://fire-vault.com/hero-images/cold-wallet-seed-entropy-2026-vibrant.jpg",
          "width": 1200,
          "height": 1200
        },
        {
          "@type": "ImageObject",
          "url": "https://fire-vault.com/hero-images/cold-wallet-seed-entropy-2026-vibrant.jpg",
          "width": 1200,
          "height": 900
        },
        {
          "@type": "ImageObject",
          "url": "https://fire-vault.com/hero-images/cold-wallet-seed-entropy-2026-vibrant.jpg",
          "width": 1200,
          "height": 675
        }
      ],
      "thumbnailUrl": "https://fire-vault.com/hero-images/cold-wallet-seed-entropy-2026-vibrant.jpg",
      "author": {
        "@type": "Person",
        "name": "Mark Fermor",
        "jobTitle": "Director & Co-Founder",
        "worksFor": {
          "@id": "https://fire-vault.com/#organization"
        },
        "url": "https://fire-vault.com/why-oss/about"
      },
      "publisher": {
        "@type": "NewsMediaOrganization",
        "name": "Firevault",
        "url": "https://fire-vault.com",
        "logo": {
          "@type": "ImageObject",
          "url": "https://fire-vault.com/logo.png",
          "width": 600,
          "height": 60
        }
      },
      "datePublished": "2026-08-06T19:36:26.108733+00:00",
      "dateModified": "2026-08-28T08:03:22.256672+00:00",
      "mainEntityOfPage": {
        "@type": "WebPage",
        "@id": "https://fire-vault.com/news/cold-wallet-seed-entropy-flaw-offline-is-not-enough"
      },
      "inLanguage": "en-GB",
      "articleSection": "Industry Insight",
      "wordCount": 786,
      "keywords": "Offline, Industry Insight, data breach, cyber security, offline secure storage, data protection, physical air gap",
      "articleBody": "Original reporting Galaxy Research , reported by CoinDesk, BleepingComputer and CBC News, 30 July to 3 August 2026. Surfaced in discussion on LinkedIn by Alex Sverdlov. Vendor disclosure by Coinkite, manufacturer of the Coldcard hardware wallet. Read the original CoinDesk report On 30 July 2026 an attacker swept roughly 1,083 bitcoin, worth about $70 million, out of 1,196 addresses in a single 41 ",
      "dateline": "United Kingdom",
      "speakable": {
        "@type": "SpeakableSpecification",
        "cssSelector": [
          "h1",
          ".article-summary",
          "h2"
        ]
      },
      "isAccessibleForFree": true,
      "copyrightHolder": {
        "@id": "https://fire-vault.com/#organization"
      },
      "copyrightYear": 2026
    },
    {
      "@context": "https://schema.org",
      "@type": "FAQPage",
      "mainEntity": [
        {
          "@type": "Question",
          "name": "What happened in the 2026 cold wallet sweeps?",
          "acceptedAnswer": {
            "@type": "Answer",
            "text": "An attacker exploited weak seed generation in certain hardware wallets to reconstruct private keys offline, emptying 1,196 addresses of about 1,083 bitcoin in 41 minutes on 30 July 2026. Later waves took the running total past 5,200 addresses and roughly $114 million."
          }
        },
        {
          "@type": "Question",
          "name": "How were air gapped devices drained without being touched?",
          "acceptedAnswer": {
            "@type": "Answer",
            "text": "The devices were never accessed. A firmware defect reduced seed entropy from 128 bits to around 40 bits, which made the private keys computationally enumerable on the attacker's own hardware."
          }
        },
        {
          "@type": "Question",
          "name": "Does this mean offline storage is unsafe?",
          "acceptedAnswer": {
            "@type": "Answer",
            "text": "No. It means physical separation must be paired with verifiable key generation. Offline storage removes the network path to the data, but a predictable encryption key gives an attacker a way around that path entirely."
          }
        },
        {
          "@type": "Question",
          "name": "What should organisations check in their own offline backups?",
          "acceptedAnswer": {
            "@type": "Answer",
            "text": "Establish who generated the encryption keys, on what audited hardware, using which entropy source, and when they were last rotated. If any of that cannot be evidenced, the offline copy carries unquantified risk."
          }
        }
      ]
    }
  ]
---

Recent Breaches 

Breaches 

[2026 PowerSchool 62.4M records ](/learn/breaches)[2026 DISA Global Solutions 3.3M records ](/learn/breaches)[2026 Globe Life 850K records ](/learn/breaches)[2026 Lidl GB Customer contact data ](/learn/breaches)[2026 Asahi Group Production systems disrupted ](/learn/breaches)[2026 Kido International 8K records ](/learn/breaches)[2026 Collins Aerospace (RTX) Check-in and boarding disruptio... ](/learn/breaches)[2026 Jaguar Land Rover Production and IT systems disru... ](/learn/breaches)[2026 Peter Green Chilled Order and logistics data ](/learn/breaches)[2026 Adidas UK Customer contact details ](/learn/breaches)[2026 PowerSchool 62.4M records ](/learn/breaches)[2026 DISA Global Solutions 3.3M records ](/learn/breaches)[2026 Globe Life 850K records ](/learn/breaches)[2026 Lidl GB Customer contact data ](/learn/breaches)[2026 Asahi Group Production systems disrupted ](/learn/breaches)[2026 Kido International 8K records ](/learn/breaches)[2026 Collins Aerospace (RTX) Check-in and boarding disruptio... ](/learn/breaches)[2026 Jaguar Land Rover Production and IT systems disru... ](/learn/breaches)[2026 Peter Green Chilled Order and logistics data ](/learn/breaches)[2026 Adidas UK Customer contact details ](/learn/breaches)

[View All →](/learn/breaches)

[![Firevault - offline secure storage, physically disconnected from the internet](/assets/logo-color-DBVl0KCg.png)](/)

Products

Solutions

[Why OSS](/why-oss)

More

[Help](/help)[Get started](/get-started)

Overview

Why This Matters Beyond BitcoinThree Things Went Wrong at OnceHow Offline Secure Storage® Appr…Firevault InsightKey TakeawaysMore Resources

[Knowledge Vault](/learn/knowledge)/ [Insight](/learn/knowledge?filter=insight)

Insight · Industry Insight · 6 August 2026 

# Offline Is Not Enough: What the $114 Million Cold Wallet Sweep Teaches Us About Key Generation

An attacker emptied 1,196 bitcoin wallets in 41 minutes without ever touching a single device. The wallets were air gapped. The keys were not truly random. Here is what that means for anyone who relies on offline storage.

![Mark Fermor](/assets/mark-fermor-aWtKNSv7.jpg)

Mark Fermor Director & Co-Founder, Firevault 

4 min read 

Share 

[](https://www.linkedin.com/sharing/share-offsite/?url=https%3A%2F%2Ffire-vault.com%2Fnews%2Fcold-wallet-seed-entropy-flaw-offline-is-not-enough)[](https://twitter.com/intent/tweet?url=https%3A%2F%2Ffire-vault.com%2Fnews%2Fcold-wallet-seed-entropy-flaw-offline-is-not-enough&text=Offline%20Is%20Not%20Enough%3A%20What%20the%20%24114%20Million%20Cold%20Wallet%20Sweep%20Teaches%20Us%20About%20Key%20Generation%0A%0AAn%20attacker%20emptied%201%2C196%20bitcoin%20wallets%20in%2041%20minutes%20without%20ever%20touching%20a%20single%20device.%20The%20wallets%20were%20air%20gapped.%20The%20keys%20were%20not%20truly%20random.%20Here%20is%20what%20that%20means%20for%20anyone%20who%20relies%20on%20offline%20storage.)[](https://www.facebook.com/sharer/sharer.php?u=https%3A%2F%2Ffire-vault.com%2Fnews%2Fcold-wallet-seed-entropy-flaw-offline-is-not-enough)[](mailto:?subject=Offline%20Is%20Not%20Enough%3A%20What%20the%20%24114%20Million%20Cold%20Wallet%20Sweep%20Teaches%20Us%20About%20Key%20Generation&body=An%20attacker%20emptied%201%2C196%20bitcoin%20wallets%20in%2041%20minutes%20without%20ever%20touching%20a%20single%20device.%20The%20wallets%20were%20air%20gapped.%20The%20keys%20were%20not%20truly%20random.%20Here%20is%20what%20that%20means%20for%20anyone%20who%20relies%20on%20offline%20storage.%0A%0Ahttps%3A%2F%2Ffire-vault.com%2Fnews%2Fcold-wallet-seed-entropy-flaw-offline-is-not-enough)

![Matte black bitcoin hardware wallet on a steel workbench beside an unplugged cable, scattered dice and a printed seed phrase card, lit in magenta and cyan](/hero-images/cold-wallet-seed-entropy-2026-vibrant.jpg)

Matte black bitcoin hardware wallet on a steel workbench beside an unplugged cable, scattered dice and a printed seed phrase card, lit in magenta and cyan

Why it matters

## What this means for organisations holding critical data

An attacker emptied 1,196 bitcoin wallets in 41 minutes without ever touching a single device. The wallets were air gapped. The keys were not truly random. Here is what that means for anyone who relies on offline storage.

In this analysis

1.  01 [Why This Matters Beyond Bitcoin](#section-0)
2.  02 [Three Things Went Wrong at Once](#section-1)
3.  03 [How Offline Secure Storage® Appr…](#section-2)
4.  04 [Firevault Insight](#section-3)

**On this page**[Why This Matters Beyond Bitcoin](#section-0)[Three Things Went Wrong at Once](#section-1)[How Offline Secure Storage® Appr…](#section-2)[Firevault Insight](#section-3)

Original reporting

**Galaxy Research**, reported by CoinDesk, BleepingComputer and CBC News, 30 July to 3 August 2026. Surfaced in discussion on LinkedIn by Alex Sverdlov.

Vendor disclosure by Coinkite, manufacturer of the Coldcard hardware wallet.

[Read the original CoinDesk report](https://www.coindesk.com/tech/2026/08/01/how-bitcoin-cold-wallets-lost-usd70-million-in-an-attack-that-never-touched-the-devices)

On 30 July 2026 an attacker swept roughly 1,083 bitcoin, worth about $70 million, out of 1,196 addresses in a single 41 minute burst. Later waves pushed the running total past 1,800 bitcoin and more than 5,200 addresses, with estimates approaching $114 million. Not one of those wallets was hacked in the way most people imagine. The devices were never touched, never connected and never compromised.

The flaw was in how the keys were created. According to Coinkite, seeds generated on certain Coldcard hardware produced around 40 bits of entropy instead of the intended 128. A seed phrase that should have been unguessable became something a well resourced attacker could enumerate offline, at leisure, and then sweep in one automated pass. Galaxy Research noted that every sweep paid an identical hardcoded 30 satoshis per virtual byte and left no change output, which is the signature of a tool rather than a person.

## Why This Matters Beyond Bitcoin

Air gapping is one of the strongest controls available. It is also the control most often misunderstood. Physical separation removes the network path. It does nothing about the quality of the secret the separation is protecting. If the key material is predictable, the attacker does not need a path at all. They can reconstruct the secret on their own hardware and arrive at the front door holding a valid credential.

Every organisation that keeps an offline copy of critical data faces the same question. Was the encryption key generated with real, verifiable entropy, on hardware that has been audited, by a process that can be evidenced? If the answer is uncertain, the offline copy is not as safe as the diagram suggests.

## Three Things Went Wrong at Once

-   **Weak randomness at creation.** A defect in firmware reduced entropy by orders of magnitude. Owners had no visible symptom and no way to tell a weak seed from a strong one.
-   **No key rotation path.** Long term holders generated a seed once, years ago, and never revisited it. A latent defect stayed live for as long as the funds did.
-   **No detection.** The first sweep completed roughly 30 hours before the vendor disclosed the flaw. There was no monitoring layer that could have flagged mass enumeration in advance.

## How Offline Secure Storage® Approaches This

Physical disconnection is the foundation of [Offline Secure Storage](/offline-secure-storage)®, not the entirety of it. Data sits at Layer 1, physically disconnected at the hardware level, so an attacker who owns the production estate still cannot reach it. That control only holds if the cryptography around it is sound, so the model pairs separation with three further requirements.

Keys are generated on audited hardware with hardware backed entropy, not on general purpose devices with firmware of unknown provenance. Access is granted only within a nominated window, which means enumeration has no standing target to hit. Every session is logged, so a pattern of unusual retrieval attempts is visible rather than invisible.

The point is simple. Offline is the control that removes the network. Verifiable key generation is the control that removes the shortcut around it. You need both.

## Firevault Insight

Mark Fermor, Founder of Firevault, puts it plainly. Air gapping without key hygiene is a locked door with the key cut from a published template. The 2026 cold wallet sweeps are the clearest demonstration yet that resilience is not a single control, it is a chain, and the chain is only as strong as the weakest assumption inside it.

For business, this incident should prompt one specific review. Identify where irreplaceable data is held offline, then establish who generated the encryption keys, on what hardware, with what entropy source, and when they were last rotated. If any part of that cannot be evidenced, the offline copy carries a risk that no amount of physical separation will resolve.

## Key Takeaways

-   **Air gapping protects the path, not the secret.** Weak key generation defeats physical separation entirely.
-   **Entropy must be evidenced.** Insist on audited hardware and a documented entropy source for any key protecting [crown jewel data](/oss-for-business).
-   **Rotate on a schedule.** A key generated once and never revisited turns a future defect into a present loss.
-   **Windows beat availability.** Data that is only reachable during a nominated access window gives an automated attacker almost nothing to work with.
-   **Log every session.** The sweeps took 41 minutes. Detection has to operate on that timescale, which means retrieval activity must be recorded and reviewed.

_Sources: Galaxy Research, Coinkite disclosure, CoinDesk, BleepingComputer, CBC News._

Sources

## Where this reporting comes from

01 

**Original report**Primary coverage referenced in this analysis [View original article](https://www.coindesk.com/tech/2026/08/01/how-bitcoin-cold-wallets-lost-usd70-million-in-an-attack-that-never-touched-the-devices)

About the author

![Mark Fermor](/assets/mark-fermor-aWtKNSv7.jpg)

### Mark Fermor

[](https://www.linkedin.com/in/mfermor)

Director & Co-Founder

Co-founder of Firevault, focused on offline secure storage and protecting individuals and businesses from fraud, fines, loss and damage. Speaker, owner and advisor.

The Firevault view**Offline Secure Storage® keeps a clean copy beyond the reach of an attacker.**[Why #OSS →](/why-oss)

Control systems and access**Cut the physical paths attackers and third parties depend on.**[Explore Control →](/solutions/control)

Get started**Get started, or talk to a member of the team.**[Get started →](/get-started)

How Firevault would handle this

## Controls an auditor can physically verify

Firevault gives you physical separation, named custody and evidenced access, so compliance claims about isolation and control are things you can show, not just assert.

[Get started](/get-started)[Talk to the team](/demo)

**Custody**Named, access-controlled hardware in a Firevault Bunker 

**Evidence**Access windows and retrieval events are recorded 

**Separation**Physical isolation that satisfies offline copy requirements 

**Jurisdiction**Stored where your regulatory position requires 

Related Reading

## You may also find these useful

[

![When Access Fails: Continuity Needs Offline Secure Storage](https://zomvctmqpgirvjnvawlz.supabase.co/storage/v1/object/public/article-images/when-the-grid-fails-offline-secure-storage-business-continuity-2026.jpg)

Industry Insight 

### When Access Fails: Continuity Needs Offline Secure Storage

Fire and grid failure are only one of six ways organisations lose access to their own records. A practical case for holding critical material offline, whatever the cause.

18 Aug 2026 9 min 







](/news/when-the-grid-fails-offline-secure-storage-business-continuity)[

![The Minnesota Water Attacks: Why Connectivity Is Becoming Critical Infrastructure's Biggest Risk](/hero-images/minnesota-water-attacks-2026-vibrant.jpg)

Industry Insight 

### The Minnesota Water Attacks: Why Connectivity Is Becoming Critical Infrastructure's Biggest Risk

More than 30 US water and wastewater utilities were targeted in a coordinated cyber attack on operational technology. The lesson for critical infrastructure is that unnecessary connectivity is now the risk itself.

31 Jul 2026 5 min 







](/news/minnesota-water-attacks-connectivity-critical-infrastructure-risk)[

![Rogue AI Agents: A Firevault Commentary on the Hugging Face Incident](/hero-images/rogue-ai-agents-2026-vibrant.jpg)

Industry Insight 

### Rogue AI Agents: A Firevault Commentary on the Hugging Face Incident

Firevault commentary on the first fully autonomous AI hack. Our take on what boards should do, informed by Joe Tidy's BBC reporting.

29 Jul 2026 4 min 







](/news/rogue-ai-agents-hugging-face-opinion-2026)[

![CI Fortify from CISA recommends that the operators of critical infrastructure must prepare themselves for forced isolation and quick recovery](/__l5e/assets-v1/a89fcfee-ebb3-4b8f-be73-99ddac829a76/cisa-ci-fortify-isolation-recovery-1778147922771-2x.jpg)

Industry Insight 

### CI Fortify from CISA recommends that the operators of critical infrastructure must prepare themselves for forced isolation and quick recovery

Insights from Mark Fermor on OT, ICS, and the underlying storage layer.

7 May 2026 7 min 







](/news/cisa-ci-fortify-isolation-recovery-firevault)[

![Data Integrity Attacks and Air Gap Defence](/__l5e/assets-v1/2afceeb3-5499-4aa5-9b5c-e555af9b8ab8/the-silent-threat-data-integrity-attacks-and-the-air-gap-defence-1771693250462-2x.jpg)

Industry Insight 

### Data Integrity Attacks and Air Gap Defence

Data integrity attacks, a stealthier cousin to traditional ransomware, are on the rise, posing a significant threat to organisational trust and operational continuity. This article explores the growing danger of data manipulation and highlights how physically air-gapped storage offers an uncompromised defence.

21 Feb 2026 5 min 







](/news/the-silent-threat-data-integrity-attacks-and-the-air-gap-defence)[

![Firmware Attacks and the Air Gap Defence](/__l5e/assets-v1/05135422-b1ae-4dcf-8de5-66b7067ec7ae/the-silent-sabotage-firmware-attacks-and-the-air-gap-imperative-1771434041117-2x.jpg)

Industry Insight 

### Firmware Attacks and the Air Gap Defence

Firmware attacks are a sophisticated and increasingly prevalent threat, capable of bypassing traditional security measures. This article explores the growing danger of these low-level compromises and highlights the critical role of physical air-gapped storage in providing an unbreachable last line of defence.

18 Feb 2026 5 min 







](/news/the-silent-sabotage-firmware-attacks-and-the-air-gap-imperative)

## Suggested Reading

-   [What is Offline Secure Storage The foundation of physical disconnection ](/how-it-works/offline-secure-storage)
-   [Why Offline Secure Storage The case for physical control ](/why-oss)
-   [Ransomware Defence Hold gold copies offline ](/oss-for-ransomware-recovery)
-   [Control Physical path control for IT and OT ](/solutions/control)
-   [Knowledge Vault All articles, guides and whitepapers ](/learn/knowledge)
-   [Book a Demo See Firevault in action ](/demo)

[Back to Knowledge Vault](/learn/knowledge)