Three hardware wallet vendors — Coinkite (Coldcard), Trezor, and SafePal — disclosed separate security failures within a 23-day window ending August 16, 2026. The incidents collectively exposed 53,487 customer records containing names and home addresses, drained $116 million in Bitcoin through a ...
"The most dangerous thing in crypto isn't a smart-contract exploit. It's a verified list of people who own a hardware wallet, complete with the address where it was delivered." — Jason Jiang, CertiK Head of Investigations
Three hardware wallet vendors — Coinkite (Coldcard), Trezor, and SafePal — disclosed separate security failures within a 23-day window ending August 16, 2026. The incidents collectively exposed 53,487 customer records containing names and home addresses, drained $116 million in Bitcoin through a firmware entropy flaw, and coincided with a record surge in physical attacks against crypto holders that reached $124.1 million in financial exposure during H1 2026, according to CertiK.
The convergence is not coincidental. As on-chain security hardens — multi-signature wallets, hardware signing devices, zero-knowledge proofs — attackers are shifting from code exploits to supply-chain data theft and physical coercion. The hardware wallet industry, built on the premise that cold storage is the safest way to hold crypto, now faces a paradox: its customer databases have become target lists.
The $760 million hardware wallet market, projected to reach $4.33 billion by 2034 according to Straits Research, must reconcile a fundamental tension between shipping physical products (which requires addresses) and protecting customers from the consequences of that data leaking.
Between July 30 and August 16, 2026, three hardware wallet makers disclosed incidents affecting different parts of the security stack:
Coldcard (Coinkite) — Firmware Exploit, July 30: Attackers exploited a seed-generation flaw present since firmware version 4.0.0 (March 2021). A build configuration error caused devices to bypass the STM32 hardware random number generator, falling back to a deterministic software pseudorandom number generator. This reduced effective key entropy enough for attackers to brute-force private keys remotely. Starting July 30, 1,816 BTC (~$116 million) was drained from over 5,200 addresses across four attack waves. The first wave alone extracted 1,082.65 BTC ($70.2 million) from 1,196 addresses in 41 minutes, according to TRM Labs. Affected models include Mk2, Mk3, Mk4, Mk5, and Q — any device where the seed was generated between March 2021 and the patch date.
Trezor (via ShipMonk) — Third-Party Data Breach, August 10–13: Trezor's U.S. fulfillment partner ShipMonk notified the company on August 10 that unauthorized actors had accessed customer order data by exploiting a vulnerability in Metabase, a third-party analytics platform. The breach occurred on August 6. Trezor disclosed publicly on August 13. Exposed: 11,742 customers with full records (name, email, phone, shipping address) and 1,947 customers with partial records (name, city, email). Total affected: 13,689 customers across the United States, United Kingdom, Sweden, Colombia, Brazil, Italy, and Portugal who received orders between May 10 and August 8, 2026.
SafePal — Order-Tracking Plugin Flaw, August 16: An authorization flaw in SafePal's order-tracking plugin allowed unauthorized external access to customer order data. A separate misconfiguration prevented old records from being deleted on schedule between September 2025 and April 2026, expanding the exposure window. Affected: 39,798 customers who placed orders between March 2, 2025, and April 11, 2026. Exposed data includes names, email addresses, shipping addresses, phone numbers, and purchase details. SafePal confirmed on August 16 that it had remediated the vulnerability, engaged a third-party auditor, reduced data retention to 90 days, and taken down over 30 phishing websites linked to the breach.
In both the Trezor and SafePal cases, wallet firmware, private keys, and seed phrases were not compromised. The danger is different: verified proof that a specific person owns a hardware wallet, delivered to a specific address.
The Coldcard incident is distinct from the Trezor and SafePal breaches. It was not a data leak — it was a cryptographic failure in seed generation that persisted undetected for over five years.
According to TRM Labs' analysis, the root cause was a build configuration error introduced in firmware version 4.0.1, released March 2021. The error rerouted seed generation away from the device's dedicated STM32 hardware random number generator to a software-based pseudorandom number generator. The result: seeds generated on affected firmware had reduced entropy, making private keys derivable through brute-force computation.
The attack unfolded in four waves starting July 30, 2026:
Total: approximately 1,816 BTC (~$116 million at the time of theft). TRM Labs noted that stolen funds pooled at a small number of attacker-controlled addresses with minimal laundering — no mixing or layering detected as of mid-August. Transaction patterns suggest multiple attackers may be involved; TRM has not attributed the theft to a specific actor.
Coinkite released a firmware update and urged all users who generated seeds between March 2021 and the patch to treat those seeds as compromised, generate new seeds on updated hardware, and migrate funds. The company has not disclosed how many devices shipped with affected firmware during the five-year window.
TechCrunch reported the total across all related thefts may exceed $130 million when including smaller wallets not captured in the initial four-wave analysis.
The data breaches land in a threat environment where physical attacks against crypto holders are already at unprecedented levels.
CertiK data (H1 2026):
Chainalysis data (H1 2026):
The discrepancy between CertiK's $124.1 million figure and Chainalysis's $30 million reflects methodology: CertiK's number includes ransom demands, victim transfers, frozen assets, and failed demands. Chainalysis counts confirmed theft only.
Geographic concentration: France accounts for 30 of 52 incidents in the CertiK dataset (57.7%). Chainalysis documented incidents across at least 14 countries, with the UK, US, Brazil, Netherlands, and South Africa recording multiple cases. Chainalysis linked France's concentration to an alleged breach involving tax records that exposed information about high-net-worth crypto holders.
Escalation in tactics: Attackers increasingly target family members rather than the crypto holder directly, using relatives as leverage. The January 2025 kidnapping of Ledger co-founder David Balland — who had a finger severed before being rescued in a 230-officer operation — remains a reference point. The kidnappers demanded €10 million in cryptocurrency. Chainalysis flagged a growing correlation between attack timing and cryptocurrency price surges.
Hardware wallets require physical delivery. Physical delivery requires names and addresses. This creates an inherent data vulnerability that software wallets do not share.
The 2020 Ledger breach — which exposed over 270,000 customer records including physical addresses — established the template. That data dump, released publicly in December 2020, fueled years of phishing campaigns. In 2021, criminals mailed physically tampered "replacement" Ledger devices to addresses from the dump, complete with shrink-wrapped packaging and fake letterhead instructing victims to enter recovery phrases on modified hardware.
Six years later, the supply-chain attack surface has not narrowed. The Trezor breach originated at ShipMonk, a fulfillment partner. The SafePal breach originated in an order-tracking plugin. Neither incident involved the wallet vendor's core systems. Both resulted in the same outcome: verified lists of hardware wallet owners with home addresses.
The three largest hardware wallet vendors by market share — Ledger (31.7%), Trezor (18.4%), and SafePal (3.4%), according to CoinLaw's 2026 market data — have now all experienced customer data breaches. Ledger has sold over 8 million devices. Trezor shipped 2.4 million devices in 2024 alone.
The common thread across all three vendors is third-party dependency. Ledger's 2020 breach came through a marketing database provider. Trezor's 2026 breach came through a shipping partner's analytics tool. SafePal's came through an order-tracking plugin. Hardware wallet vendors control their firmware and secure elements but delegate fulfillment, analytics, and order management to third parties whose security standards they do not fully control.
The hardware wallet market was valued at approximately $760 million in 2026, according to Straits Research, with projected growth to $4.33 billion by 2034 at a 24.33% CAGR. The top three vendors — Ledger, Trezor, and KeepKey — collectively control 58.8% of the global market.
Vendor responses to the August incidents:
None of the three vendors has announced structural changes to their fulfillment or data-handling architecture — such as shipping through anonymized intermediaries, offering P.O. box delivery by default, or end-to-end encrypting order data so that fulfillment partners cannot access plaintext addresses.
The hardware wallet industry faces a structural problem that firmware updates cannot fix. The product requires physical delivery, and physical delivery generates data that, when leaked, converts a security tool into a targeting mechanism. The August 2026 breaches at Trezor and SafePal added 53,487 records to a cumulative pool of over 323,000 exposed hardware wallet customers across three vendors. The Coldcard exploit demonstrated that even air-gapped devices can fail at the most fundamental level — key generation — when firmware quality controls lapse.
The market is growing. Demand for self-custody is not declining. But the gap between the on-chain security that hardware wallets provide and the off-chain security of the supply chains that deliver them is widening. Until vendors treat customer data protection with the same rigor they apply to secure elements, the industry's security proposition remains incomplete.