Before moving directly to the relevance of this wallet class, let's touch on why so much distrust towards them has arisen by the end of the summer of 2026.
A wave of hacker attacks was conducted on the Coldcard hardware wallets from the Canadian company Coinkite. On the very first day, users were short 1082.65 $BTC worth over $70.2 million. In total, according to various estimates, losses amounted from 1778.84 $BTC to 2417.35 $BTC ($115-$153 million). But what caused such a massive leak of digital assets?
An Unnoticed Problem
The problem was in the seed phrase generation. By default, it should be created randomly. In reality, due to a firmware error, the seed phrase could be brute-forced (by enumerating combinations). The cryptographic entropy length indicator dropped from the required 128 bits to 72 bits for one subset of devices, and down to just 40 bits for another. The problem with the entropy source stemmed from accounting for certain typical data, including timestamp values, when using a software generator instead of the required hardware one, thereby increasing the threat to private keys. Interestingly, the vulnerability itself appeared a long time ago — in 2021. In other words, for a whole five years, attackers could hypothetically have exploited this, but only took concrete steps now. Note that the Coldcard device models were affected to varying degrees. The hardest hit were the older versions: Mk2 and Mk3.
Why is the level of entropy so important anyway? Here's an analogy: according to some estimates, 128 bits provide roughly this level of protection — if each star in our observable universe corresponded to one option, to get the right number you would have to go through all the stars in 340 trillion similar universes. Accordingly, reducing entropy by tens of bits reduces the number of combinations to be searched by many orders of magnitude.
Ultimately, Coinkite released a corrected firmware. Affected users had to create a new seed phrase, confirm the new wallet with a test transaction, and transfer their remaining bitcoins there.
Although the case directly involved Coldcard, all hardware wallets suffered a reputational blow. By the way, how did their representatives react to this incident?
Reaction from Trezor and Ledger
The recognized leaders in hardware wallet solutions are those from Trezor and Ledger. Each of them made an official statement regarding the Coldcard situation. Their essence was similar, but there were still distinctive nuances.
Trezor stated that their devices remain secure. Nevertheless, they made one significant caveat. If a wallet was initially created on a vulnerable Coldcard, and then a backup version was imported or restored onto a Trezor, the digital assets of such a user could be at risk. At the same time, the developers clarified that even older models like Safe 3 and Safe 5 are secure, as they use random selection using the Optiga Secure Element chip, while the newer Safe 7 version employs the TROPIC01 chip for this purpose. In both cases, the entropy length is 128 bits.
Ledger's CTO, Charles Guillemet, also dismissed any possibility of a threat to his company's devices. He stated that all the organization's technical solutions use a True Random Number Generator (TRNG) via the Secure Element chip. It provides an entropy length of 256 bits for each 24-word phrase.
Problems with hardware wallets lately have not been limited exclusively to the situation around Coldcard. In early August, the case with SafePal caused a lot of noise. What really happened?
SafePal User Data Leak
Between March 2025 and April 2026, data of nearly 40,000 SafePal customers was leaked. Fortunately for users, it did not contain anything specifically related to cryptocurrencies: seed phrases, private keys, or the digital assets themselves. However, the information included names, physical addresses, and contact details.
The problem was in a plugin used for tracking orders. It is presumed that attackers gained access to all the data in this manner. SafePal fixed the flaw and developed additional measures for security. Now, data in the processing system will be stored for only 90 days. Furthermore, the company deleted 30 websites and phishing links associated with the vulnerability.
Trezor Customer Data Leak
The aforementioned hardware cryptocurrency wallet manufacturer, Trezor, faced a similar problem in 2026. The developers reported that attackers had breached their partner — the logistics operator ShipMonk. As a result of the attack, data of approximately 14,000 Trezor customers, in full or in part, was compromised.
The main danger in the case of the ShipMonk hack lies not in the wallets becoming unsafe, but in the fact that the attackers, possessing users' personal data: their names, residential addresses, emails, phone numbers, and other information, can attempt to attack the victims in various ways through phishing and other methods.
The incidents with Coldcard, SafePal, and Trezor became known almost simultaneously, amplifying the negative effect on the crypto community's perception of hardware wallets. Perhaps it's the end for such cold storage solutions, or maybe we shouldn't jump to far-reaching conclusions?
Interpretation Problems
First, it is necessary to understand what specifically a cryptocurrency wallet is. It is not a place where bitcoins or other digital assets are directly located. They all exist exclusively on the blockchain, and a user gains access to them only by owning a private key. That is, a cryptocurrency wallet is a method for a user to interact with the blockchain, storing this crucial information.
Second, we need to consider all options for where one can store a seed phrase or the private key itself. Alas, none of them are perfect. You can write the mnemonic phrase on paper, but such an option is vulnerable to damage and loss. Of course, there is always the possibility to memorize/learn the phrase, but that is extremely unreliable. A good alternative to paper and one's own memory is special metal plates on which the seed phrase is engraved/assembled from letter tiles. These are sold by both renowned manufacturers like Ledger (Billfodl plate) and less known companies.
We won't delve in detail into all the risks of storing assets on hot wallets and crypto exchanges, as these methods are also susceptible to hacker attacks, viruses, and so on. Alas, cold hardware wallets, as it turns out, are also not a panacea for all vulnerabilities.
Third, the cases with SafePal and Coldcard affected specific technological solutions. All others suffered only from the ripple effect, but the cryptocurrency itself was not affected there in any way. Interestingly, amid the Coldcard problems, the number of Bitcoin network transactions also increased. Ironically, many users began moving their savings to centralized crypto exchanges (CEXs), that is, abandoning non-custodial storage in favor of custodial storage. Simply put, instead of finding a reliable method for self-custody of cryptocurrency, they entrusted this task to trading platforms.
Fourth, the problem of crypto storage exists, but there is a much more global one — the development of artificial intelligence (AI). The vulnerability in Coldcard existed for five years. However, only in 2026, using neural networks, attackers "broke through the defense." This was pointed out by Ledger's Director of Human Potential Management, Ian Rogers. In his opinion, the problem is not in the hardware wallets themselves, but in the fact that with the development of AI, the toolkit of attackers for finding vulnerabilities has expanded manifold.
It turns out that there are still no alternative solutions to hardware wallets in terms of security, simplicity, and convenience for the majority of users. This does not make them exceptional or ideal, but other solutions have no fewer shortcomings, sometimes even more. This is clearly seen in the example of transferring assets to CEXs in exchange for non-custodial storage amid negative news. That is, for some users, it is more convenient to entrust storage than to look for a complex, albeit secure, method. Moreover, the development of AI plays a dual role. On one hand, it helps developers strengthen protection; on the other hand, it helps fraudsters find flaws faster.
Conclusion
Ultimately, the cases of Coldcard and SafePal should be considered as isolated, specific situations. It makes no sense to write off all hardware wallets, as manufacturers approach the implementation of secure cryptocurrency storage differently. The development of artificial intelligence has a dual nature, as it not only helps strengthen the protection of crypto storage but also contributes to attackers finding new weak spots.





