The Seven-Minute Heist
The attack was fast. Starting at 9:36 pm, the wallets were drained one by one. By 9:43 pm, the funds had moved. The speed suggests an automated script or pre-planned access. Goodman had no time to react. The attacker emptied every wallet in that short window, leaving no trace of how they got in.
Security Measures That Failed
Goodman had followed what many consider the gold standard for cryptocurrency storage. The Coldcard wallet is designed to be air-gapped — it never connects to the internet. He stored it in a safety deposit box, adding a physical layer of protection. Despite these precautions, the attacker managed to access the private keys and move the funds. The breach raises questions about the limits of offline storage. If a wallet that never touched the internet can be drained, what hope is there for less careful users?
The Unanswered Question
How the attacker gained access remains a mystery. The wallet had never been online, so a remote hack seems impossible. Physical theft




