Three distinct failure modes hit the hardware wallet industry simultaneously in 2026. A firmware bug in Coldcard devices drained $116 million in Bitcoin from 5,200+ addresses. Supply-chain data breaches at third-party vendors exposed shipping records for more than 120,000 customers across Trezor,...
"We tracked 46 violent crypto attacks through late June. If attacks continue at the same pace, 2026 will surpass the full-year record." — Chainalysis, Violent Wrench Attacks Targeting Crypto Holders Report, August 2026
Three distinct failure modes hit the hardware wallet industry simultaneously in 2026. A firmware bug in Coldcard devices drained $116 million in Bitcoin from 5,200+ addresses. Supply-chain data breaches at third-party vendors exposed shipping records for more than 120,000 customers across Trezor, SafePal, and Ledger. And physical attacks — kidnappings, home invasions, and coerced transfers — stole $30 million in the first half of the year alone, according to Chainalysis, putting 2026 on pace to double the prior annual record.
The three vectors are connected. Stolen shipping data feeds targeting databases for physical attackers. Firmware vulnerabilities undermine the core value proposition of cold storage. And the $500 million class-action lawsuit filed against Ledger on August 27 signals that the legal system is beginning to assign liability for the downstream consequences of vendor data exposure. The hardware wallet market, valued at $720 million in 2026 according to Coherent Market Insights, faces its most consequential year.
Starting July 30, 2026, attackers drained approximately 1,816 BTC — valued at roughly $116 million at the time — from over 5,200 addresses linked to Coldcard hardware wallets. TRM Labs classified it as the largest hardware wallet exploit of 2026 and the third-largest crypto hack of the year.
The root cause was a firmware defect introduced in March 2021 that weakened seed randomness on certain Coldcard models. According to TRM Labs' post-mortem, the bug reduced effective key strength from 128 bits to as little as 40 bits — well within brute-force range without physical access to the device. Affected models included Mk2 and Mk3 units running firmware 4.0.1 through 4.1.9, plus older Mk4, Mk5, and Q models on pre-patch firmware.
The attack unfolded across four waves. In the most concentrated episode, on July 31, a single attacker drained 594 BTC ($38.3 million) from 500 single-signature wallets in 25 minutes. By August 4, TechCrunch reported that at least a dozen different attackers had exploited the same vulnerability, pushing cumulative losses past $130 million.
Coinkite, the company behind Coldcard, shipped firmware version 5.6.1 for Mk4/Mk5 and 1.5.1Q for the Q series on August 20. The update replaced the backup random number generator — swapping the Yasmarang algorithm for a SHA-256-based system — and now requires at least 65 key presses, 50 dice rolls, or 128 coin flips combined with device entropy for new seed creation. According to CoinDesk, Coinkite stated that AI-assisted fuzzing helped identify additional bugs during the rebuild.
A critical distinction: the firmware update does not retroactively secure existing seeds. Anyone who generated a seed on affected firmware between March 2021 and the July 2026 patch must create an entirely new seed and migrate funds. The vulnerability existed in deployed devices for over five years before exploitation.
While the Coldcard exploit targeted device-level cryptography, three separate supply-chain breaches in 2026 exposed the personal data — names, shipping addresses, phone numbers, email addresses — of hardware wallet customers.
Trezor / ShipMonk (August–September 2026). Trezor disclosed on August 14 that 13,689 customers had data partially or fully exposed through a breach at ShipMonk, its U.S. logistics provider. On September 4, Trezor expanded the disclosure to an additional 67,000 U.S. customers with orders between November 2019 and August 2021, bringing the total to approximately 80,689 affected individuals. According to The Hacker News, the breach was attributed to the ShinyHunters group exploiting CVE-2026-72898, a critical (CVSS 10.0) unauthenticated SQL injection vulnerability in Metabase's password-reset endpoint. Trezor stated it had "repeatedly requested and received written assurance confirming the deletion" of the data from ShipMonk, but the data was never actually deleted.
SafePal (August 2026). SafePal disclosed a breach affecting 39,798 customers who placed orders between March 2025 and April 2026. Exposed data included names, email addresses, shipping addresses, phone numbers, and purchase details, according to The Record.
Ledger / Global-e (January 2026). Ledger confirmed that customer order data was exposed through unauthorized access to Global-e, its third-party payments and e-commerce partner. The breach was caused by a misconfigured API key on the Ledger website. Exposed data included names, email addresses, postal addresses, and phone numbers. Ledger did not disclose the total number of affected customers, though the subsequent class-action complaint references up to 210,000 potentially affected users across multiple incidents.
Combined, these three breaches exposed data for at least 120,000 confirmed hardware wallet customers, with the Ledger class potentially representing significantly more. Four of the five major hardware wallet security incidents in 2026 involved third-party vendors, not the wallet manufacturers themselves. Only the Coldcard exploit involved an actual device vulnerability.
The connection between data breaches and physical violence is no longer theoretical. Chainalysis documented 46 violent crypto attacks through late June 2026, with $30 million in confirmed stolen funds. If the pace continues, 2026 will surpass 2025's full-year record of $58 million. Including attempted thefts, blocked transfers, and recovered funds, the gross exposure figure is far higher: Chainalysis estimated roughly $316 million in 2024, $180 million in 2025, and $107 million through mid-2026.
France is the epicenter. French Interior Minister Laurent Nuñez stated that authorities recorded 77 incidents — unlawful detention, kidnapping, extortion, or attempts — in the first six months of 2026, compared to 45 in all of 2025. In 2024, a French tax official in the Paris area allegedly stole and sold dossiers on high-net-worth crypto holders — including names, addresses, holdings, phone numbers, and tax records — to criminal intermediaries, according to reporting by CoinDesk and The Block. A separate breach at crypto tax-reporting company Waltio reportedly exposed data belonging to approximately 50,000 users.
The highest-profile attack occurred in January 2025: David Balland, co-founder of Ledger, was kidnapped with his wife from their home in central France. One of his fingers was severed and sent to associates as part of a ransom demand. France's GIGN tactical unit rescued both victims after 48 hours. The alleged mastermind was arrested in Morocco in June 2026, according to Decrypt.
Chainalysis found that relatives were targeted in more than 40% of documented French incidents. Home invasions now account for 37% of all documented attacks globally, up from 26% in 2023. Across all geographies, 93% of victims in France, 82% in Brazil, and 77% in the U.S. were local residents — indicating deliberate planning, not opportunistic crime.
Jameson Lopp, CTO of Casa and maintainer of a public database of known physical crypto attacks, stated to CoinDesk that France was responsible for 16 of the 23 publicly reported wrench attacks in early 2026.
On August 27, 2026, Ledger user Douglas Kim filed a class-action lawsuit in the Southern District of New York seeking at least $500 million in damages. Kim alleges that scammers used contact data obtained from Ledger's 2020 and 2023 data breaches to impersonate Ledger representatives and steal $1,948,074 in cryptocurrency from him in February 2025, according to the complaint reviewed by Protos.
Separately, on August 24, Hall Attorneys and Milberg filed a putative class action — also in SDNY — specifically concerning the December 2025 Global-e breach. That complaint proposes one North American class and two subclasses, alleging completed digital-asset losses exceeding $2.6 million.
The lawsuits test a legal theory with broad implications: whether hardware wallet manufacturers bear liability for downstream theft when customer data leaks from third-party vendors. Ledger sold over 8 million devices historically, with 3.5 million units shipped in 2024 alone, according to CoinLaw. The proposed Kim class covers up to 210,000 users.
Ledger has not publicly commented on the substance of either lawsuit as of September 15, 2026.
The converging failures have accelerated industry interest in custody architectures that reduce single-point-of-failure risk:
Multi-party computation (MPC). MPC wallets split a single private key into cryptographic shares held by separate parties, which jointly compute a signature without ever reconstructing the full key. Unlike hardware wallets, there is no single seed phrase to steal. ZenGo, Fireblocks, and institutional custody providers have promoted MPC as an alternative for both retail and enterprise users.
Multisignature setups. Multisig requires multiple independent keys to authorize a transaction. Bitcoin's native scripting supports multisig natively. Casa, the firm run by Lopp, uses a 2-of-3 or 3-of-5 multisig model with keys distributed across devices and geographies. The tradeoff: multisig exposes the signing policy in the transaction itself.
Threshold signature schemes (TSS). Vultisig, built by former THORChain developers, uses TSS to deliver multisig-level security without on-chain complexity. It eliminates seed phrases entirely.
Time-locked transactions. Some custody solutions now add mandatory waiting periods before transfers execute, providing a window to cancel coerced transactions. This directly addresses the wrench-attack vector.
The common thread: eliminating the seed phrase as a single point of compromise. Whether the attacker is a remote hacker brute-forcing weak entropy or a home invader with a weapon, the seed phrase remains the critical vulnerability in traditional hardware wallet architecture.
The hardware wallet market reached $720 million in 2026, according to Coherent Market Insights, growing at a 25.59% CAGR toward a projected $2.25 billion by 2031. Ledger leads with 31.7% market share, followed by Trezor at 18.4% and KeepKey at 8.7%, per CoinLaw estimates. North America accounts for 39.4% of the market.
Despite the security incidents, overall market growth has not stalled. Institutional demand for air-gapped signing devices and the growing installed base of self-custody users continue to drive sales. However, the composition of demand may shift. Institutional custody providers — Fireblocks, BitGo, Anchorage — increasingly offer managed key infrastructure that abstracts away the hardware wallet entirely.
The year's total crypto hack losses have passed $1.2 billion across 276 incidents, according to TRM Labs. The Coldcard exploit alone represents roughly 10% of that total.
The hardware wallet industry's security model assumed that air-gapped devices with locally generated seeds were sufficient for asset protection. The events of 2026 have demonstrated that this model fails on multiple levels: at the firmware layer (Coldcard), at the supply-chain layer (Trezor, SafePal, Ledger vendors), and at the physical security layer (wrench attacks enabled by leaked customer data). The three failure modes are not independent — breached shipping records become targeting data for physical attackers.
The $720 million hardware wallet market is not collapsing. Demand for self-custody tooling remains strong. But the product category is being reshaped. Custody solutions that depend on a single seed phrase stored on a single device face increasing competition from distributed key architectures that eliminate the seed as a single point of compromise. Whether the market reprices this risk through reduced sales, higher insurance premiums, or regulatory mandates for vendor security standards remains to be determined.