Three hardware wallet vendors disclosed critical security failures within a 20-day window in August 2026. Coldcard manufacturer Coinkite confirmed a firmware entropy bug, latent since March 2021, that enabled attackers to brute-force private keys and drain approximately 1,816 BTC ($116 million) f...
"Perhaps the hardest part about this is that I did everything right." — Jonathan Goodman, Coldcard user who lost 18.25 BTC (~C$1.6M)
Three hardware wallet vendors disclosed critical security failures within a 20-day window in August 2026. Coldcard manufacturer Coinkite confirmed a firmware entropy bug, latent since March 2021, that enabled attackers to brute-force private keys and drain approximately 1,816 BTC ($116 million) from more than 5,200 addresses. Separately, Trezor disclosed that fulfillment partner ShipMonk leaked personal data on 13,689 customers, and SafePal revealed an authorization flaw that exposed order data for 39,798 users. Combined: 53,487 hardware wallet buyers now have names, home addresses, and purchase records circulating in criminal channels.
The incidents arrive against a backdrop of escalating physical crypto crime. CertiK's Intel3D H1 2026 report documented 52 verified wrench attacks — kidnappings, home invasions, and forced transfers — with recorded exposure of $124.1 million, up 11.8x year-over-year. The correlation between leaked buyer databases and physical targeting is no longer theoretical. It is a documented attack chain.
On July 30, 2026, at approximately 01:31 UTC, an attacker began sweeping bitcoin from Coldcard-generated wallets. The first wave drained 594.5 BTC ($38 million) from 500 single-signature wallets across 1,324 UTXOs in approximately 25 minutes. Three additional waves followed through August 3. Galaxy Research placed confirmed losses at 1,719 BTC ($111 million) as of August 8, with a potential ceiling of 2,055 BTC ($130 million) as address identification continues. TRM Labs classified the incident as the third-largest crypto hack of 2026.
The root cause traced to a single code commit on March 1, 2021. Firmware version 4.0.1 switched seed generation from ckcc.rng_bytes — which correctly accessed the STM32 hardware true random number generator (TRNG) — to ngu.random.bytes, a library call that resolved to MicroPython's Yasmarang software pseudorandom number generator. According to Block's Bitcoin Engineering and Security teams, the effect was a collapse in effective key strength:
At 2⁴⁰ bits, brute-force recovery is computationally trivial. At 2⁷², it is feasible for well-resourced attackers using modern hardware, particularly GPU clusters and AI-accelerated search techniques. Every Coldcard model shipped between March 2021 and the July 31 patch is affected: Mk3, Mk4, Mk5, and Q.
The vulnerability carried an additional complication: updating firmware does not repair an existing seed. Any seed generated on affected firmware remains vulnerable. Users must generate an entirely new seed on patched firmware and transfer all funds.
Coinkite CEO NVK issued an open letter on July 31: "If you generated a seed using a Coldcard wallet, move your funds now, using our updated best practices, before reading further." NVK attributed part of the discovery speed to AI-assisted code analysis, stating: "We believe this is a sober reality of the new AI paradigm. AI-assisted code review can now find latent bugs at a speed that is outpacing even the industry's most seasoned experts." Security researchers pushed back on this characterization. According to reporting from Phemex, Bitcoin developer James O'Beirne raised the flawed randomness code with Coinkite in May 2025, more than 14 months before exploitation. He was told the issue would likely have surfaced earlier if it were real.
Coinkite released fixed firmware on July 31: Mk3 → v4.2.0; Mk4/Mk5 → v5.6.0 (standard) / v6.6.0X (Edge); Q → v1.5.0Q (standard) / v6.6.0QX (Edge).
The Coldcard exploit was a device failure. The Trezor and SafePal incidents were supply-chain data breaches — no private keys were compromised, but the exposed metadata creates a different and arguably more persistent category of risk.
On August 10, ShipMonk, Trezor's third-party fulfillment provider, informed Trezor of unauthorized access to its systems. The breach affected customers who ordered between May 10 and August 8, 2026, across seven countries: the United States, United Kingdom, Sweden, Colombia, Brazil, Italy, and Portugal. According to Trezor's official disclosure:
Trezor confirmed that its internal systems were not accessed and that no hardware wallet, private key, or recovery seed was touched. However, attackers immediately weaponized the data. Phishing campaigns targeted affected customers, attempting to trick them into entering 24-word recovery seeds on fraudulent websites. Trezor reported that fake security letters, designed to resemble official vendor correspondence, began arriving at victims' physical addresses.
In response, Trezor announced an accelerated rollout of an Anonymous Delivery option: packages routed through parcel lockers, neutral packaging, stripped sender details, and automatic deletion of shipping identifiers after delivery. EU launch is targeted for September 2026; US to follow by year-end.
SafePal disclosed that an authorization flaw in its order-tracking system exposed personal data for 39,798 customers. The affected records covered orders placed between March 2, 2025, and April 11, 2026, and included names, email addresses, shipping addresses, phone numbers, and purchase details. According to SafePal, seed phrases, private keys, wallet passwords, payment card numbers, and government identification were not compromised.
SafePal said it had taken down more than 30 fraudulent websites and phishing links targeting customers within days of the disclosure.
Across both incidents: 53,487 confirmed individuals whose hardware wallet purchase records are now in attacker databases. These are not random crypto users. They are verified cold-storage holders — a self-selecting population with a higher probability of holding substantial cryptocurrency balances.
The data breaches feed directly into a documented escalation in physical crypto crime. CertiK's Intel3D H1 2026 Wrench Attacks Report, published July 25, 2026, documented 52 verified incidents — a 33.3% increase over H1 2025. Financial exposure reached $124.1 million, an 11.8x increase from $10.5 million in the same period a year earlier.
The attack typology has shifted. According to CertiK:
Geographic concentration is extreme. Europe accounted for 39 of 52 incidents (79.6%). France alone recorded 33 incidents — 63.5% of all verified cases worldwide and 84.6% of European incidents.
The Ledger data breach of July 2020 serves as the precedent case study. That incident exposed the personal information of 270,000 customers, and the consequences extended for years: phishing campaigns, extortion emails demanding $700–$1,000 in Bitcoin, physically tampered replacement devices mailed to victims' homes, and SIM-swap attacks. According to security researcher Jameson Lopp, over 215 crypto-related violent attacks have been recorded globally since 2020. The 2020 Ledger breach is considered a contributing factor in many of them.
The Trezor and SafePal databases are smaller (53,487 vs. 270,000) but arrive into a threat environment that is qualitatively different from 2020. Wrench attack infrastructure — criminal networks specializing in physical crypto theft — now operates at scale. The correlation between customer database leaks and subsequent physical targeting is, according to CertiK, now a "documented operational pipeline."
The hardware wallet market is valued at approximately $720 million to $914 million in 2026, according to Coherent Market Insights and Mordor Intelligence, with a projected CAGR of 29–34% through 2031–2035. Ledger and Trezor hold a combined 70%+ market share. Ledger reports over 8 million devices sold; Trezor has shipped 2.4 million units.
The Coldcard exploit specifically has reignited debate around self-custody versus institutional custody and ETF-based exposure. CoinDesk reported that the incident "may push investors to ETFs," citing interviews with wealth advisors who described clients requesting portfolio shifts away from self-custody solutions in the weeks following the hack.
A CoinDesk opinion piece published August 17 argued: "The Coldcard hack proves reputation is not a security model." The piece contended that the Bitcoin community's historical reliance on vendor reputation and open-source transparency as security guarantees was insufficient absent mandatory third-party auditing and formal verification of entropy sources.
Memeburn's analysis categorized the five 2026 hardware wallet incidents and noted that four of five involved vendor data breaches (supply-chain exposure), while only the Coldcard exploit involved an actual device failure. The distinction matters: data breaches are operationally damaging but do not directly compromise funds. Firmware entropy failures do.
The August 2026 hardware wallet crisis is not a single event. It is three concurrent failures across the self-custody stack: a firmware defect that destroyed the mathematical foundation of key security, and two supply-chain breaches that exposed the physical identities of tens of thousands of cold-storage users. The damage from the Coldcard exploit is quantified at $116 million and counting. The damage from the data breaches is not yet quantifiable but feeds into a physical-attack pipeline that CertiK has documented at $124 million in H1 2026 alone.
The industry's response so far — patched firmware, anonymous delivery options, phishing-link takedowns — addresses symptoms. The structural question is whether a hardware wallet supply chain that relies on third-party fulfillment providers, ships devices to home addresses, and stores customer purchase records indefinitely is architecturally compatible with the security model it claims to provide. The data suggests the answer is no.