During a recent spend from multisig, the coldcard component was usb connected to the labtop. Was the air-gapped nature of the coldcard compromised? Should I rebuild the wallet? Thanks
Your wallet can only be considered compromised if your private keys leaked to an internet-connected computer. That didn't happen in this case. If you don't like connecting your Coldcard to your computer, you might consider buying a Coldpower Adapter. It's a little device that takes power from a 9-volt battery and gives your Coldcard the juice it needs to do its work without connecting it to a computer or laptop. You can purchase it from the official store.
Now the question that needs to be asked here is what type of computer was it connected to. Coldcard is an airgapped hardware wallet and good one. But in general time, the problem is if a device or let me say a hardware wallet is connected to a device or computer that is not totally airgapped then it also seizes to be airgapped.
The computer you connect your Coldcard to doesn't need to be airgapped. Use it with a power-only cable and it can't transmit any data. It only uses the power to run the Coldcard. Additionally, you bring the signed transaction from your Coldcard via a Micro SD card to be broadcasted on the internet-connected computer.