Sales of Trezor, Onekey, and Bitbox Surge Amid Coldcard Crisis; Security Models Evolve

cryptonews.ruОпубліковано о 2026-08-26Востаннє оновлено о 2026-08-26

Анотація

Sales of Trezor, Onekey, and Bitbox hardware wallets surged significantly in August, driven by the security crisis involving Coldcard. These companies confirmed increased demand, particularly in North America where Coldcard had a strong presence. While specific figures weren't disclosed, Bitbox reported a roughly tenfold increase in credit card sales. Industry analysts note the incident prompted a wider discussion on hardware wallet security, leading manufacturers to review and enhance their security models and processes, such as seed phrase generation and entropy sources. The crisis underscored the importance of self-custody, with affected users seeking alternative wallets rather than abandoning the practice. Manufacturers like Trezor, Bitbox, and Onekey have implemented additional security checks and audits in response. The evolving threat landscape, accelerated by AI, is pushing the industry to focus on faster patch deployment, responsible disclosure, and user education. Security experts emphasize that maintaining security is a continuous, shared responsibility requiring users to keep all software and firmware updated. Meanwhile, reports emerged of another critical vulnerability in a major wallet's official firmware, though exploitation requires malicious host software. The industry remains vigilant, with companies investing in short, medium, and long-term security plans, including AI-assisted code review and independent penetration testing.

Of the 13 hardware wallet manufacturers contacted by Bitcoin.com News for comment, Trezor, Bitbox, and Onekey confirmed their sales increased sharply in August. Company Ledger declined to comment on its monthly sales, while Bitkey manufacturer Block—a publicly traded company—is only required to disclose information as part of its quarterly reports.

While none of the companies disclosed exact figures, Bitbox provided the most specific information, reporting that sales volume paid for by credit cards grew roughly tenfold compared to the baseline of previous weeks. This data does not include sales made using other payment methods.

"We saw a sharp increase in sales, primarily from North America, where Coldcard appears to have had the strongest presence," Bitbox CEO Douglas Bakkum told Bitcoin.com News.

A Positive Sign for Self-Custody

Meanwhile, Trezor reported it also saw a rise in sales, particularly for its bitcoin-only products. While the company did not provide specific numbers, its Head of Security, Jan Komařek, noted that this spike is an encouraging sign for the entire Bitcoin industry.

"The more interesting takeaway for us is the conclusion it leads to: it seems that people affected by the Coldcard situation sought another hardware wallet, rather than abandoning self-custody," he said, adding that this is "an encouraging conclusion: the response to a difficult moment was an effort to maintain control over one's own keys, not to relinquish it."

However, according to industry analysts, many hardware wallet users sent their funds to cryptocurrency exchanges or moved capital into ETFs, abandoning self-custody. In any case, it's unclear how extensive this migration was or whether it was merely a temporary measure, after which users returned to self-custody.

Onekey, while noting increased sales, pointed out that other factors may have influenced this, including individual product release cycles. According to the company, the Coldcard crisis sparked a much broader discussion about hardware wallet security issues that typically remain invisible to end-users, such as seed phrase generation.

However, the vulnerability in Coldcard's firmware triggered similar discussions and actions not only among end-users but also among hardware wallet manufacturers. Firstly, this incident prompted teams to re-evaluate their current security models.

What Wallet Manufacturers Have Already Done

Trezor reviewed its own seed phrase generation process with particular emphasis on addressing the vulnerability exploited in the Coldcard case; BitBox "once again thoroughly examined" the code of its random number generator, and Onekey reported conducting additional end-to-end checks of entropy and seed generation processes across its entire line of hardware wallets.

As Bitcoin.com News reported, separately and independently of the Coldcard incident, BitBox disclosed and fixed its own firmware bugs in August of this year. No reports of vulnerabilities were received. Meanwhile, in the same month, Trezor reported that nearly 14,000 of its customers were affected by a data breach at one of Trezor's delivery service providers.

In any case, the main battle for security is still ahead, as hardware wallets for bitcoin and other cryptoassets adapt to the new reality shaped by the development of artificial intelligence.

Two Things to Focus On

"Attackers are already operating at machine speed, so we need to act just as fast to stay ahead of them," stated Charles Guillemet, CTO of Ledger, adding that currently, defense is still evolving more slowly than attacks. At the very least, he said, the time gap between releasing a patch and its malicious use is shrinking.

The CTO emphasized that companies should now focus on two things: improving disclosure procedures and educating users.

"First, responsible disclosure principles must evolve: patches need to be released faster, disclosure timelines shortened, and migration strategies must assume that capable AI-using attackers are an integral part of the security model, not just additional enhancements," Guillemet said in an interview with Bitcoin.com News.

Furthermore, in his opinion, helping people understand how hardware wallets work "will be crucial for securing the industry."

Update Even Your Home Appliances

In a similar vein, in their "reflections on the implications of the Coldcard incident," the developers of the Blockstream Jade wallet urged hardware wallet users to keep their software up to date. Blockstream Jade just released a firmware update with a series of fixes. However, according to the team, beyond hardware wallets, users should keep their applications, operating systems, devices, routers, and even home appliances updated.

"Security is a continuous process, and you, as a user, must also participate in it," they emphasized, adding that the Coldcard bug was "an unfortunate case where updating" software and firmware "failed to secure users."

Meanwhile, Onekey added that hardware wallet security should be built on hardware-supported entropy and key storage, verifiable open-source software, independent security expertise, strict isolation of security-critical components, and user-verifiable transaction checks.

"As AI lowers the cost of software analysis and attack automation, the goal is to ensure that discovering one weakness in implementation does not undermine the entire security model," the wallet manufacturer stated.

Short-, Medium-, and Long-Term Security Plans

The companies themselves are already implementing short-term, medium-term, and long-term security changes. For example, Trezor, "as an immediate response to the Coldcard findings," is adding "additional correctness checks" of its own, internally generated device entropy when verifying whether external entropy is indeed being used.

"Beyond this, our analysis prompted us to strengthen internal testing and protection measures regarding the insecure test generator, as well as expand the ways to verify the call path of each individual entropy source," said Komařek, noting that the insecure generator is used exclusively for internal testing.

The company is also analyzing reports from independent security researchers and plans in the medium term to conduct a new penetration test of key firmware functions, to be performed by "an authoritative external security agency." Security audit reports are planned to be made public.

"In the long term, we will focus on staying ahead of AI-powered attacks, not just reacting to them," stated the head of security, while other wallet manufacturers also emphasized that they are already using AI to audit their code alongside bug bounty programs.

"Our Donjon research lab (a 'white hat' hacker lab) exists to try to hack our products before anyone else can, and internally we actively use Large Language Models (LLMs) to search for vulnerabilities in our own products," added Ledger's Guillemet.

Onekey reported it is currently focused on strengthening verification of security-critical code paths, firmware builds, entropy generation, and transaction signing flows, and in the medium term, its attention will be on transaction verification, with the Clear Signing solution in mind, relevant for many major cryptoassets beyond Bitcoin.

Shared Responsibility and New Critical Bugs

Meanwhile, security researchers from Block, the manufacturer of Bitkey, played a key role in assisting the Bitcoin and hardware wallet industry during the Coldcard crisis, as they actively engaged with the community, sharing important findings and coordinating response measures.

"We openly shared our findings both in public discussions on X and through private channels, as we believe that when security vulnerabilities affect the ecosystem, all manufacturers are obligated to act quickly," the company told Bitcoin.com News, adding that hardware wallets must maintain control over key security models.

While this article was being written, on August 26th, reports began circulating about another "critical vulnerability at a major hardware wallet manufacturer." Rob Segers, a Bitcoin security consultant and founder of Bitsaga, who discovered this bug alongside "several other high-severity bugs," reported that the unnamed manufacturer confirmed the existence of these bugs, "but a fix is already included in an upcoming release."

According to Segers, the critical vulnerability was found in the "official hardware wallet firmware, however, stealing funds requires malicious host software." This means the vulnerability could be exploited if a user, for example, downloads a fake wallet. Marek "Slush" Palatinus, co-founder of Trezor, confirmed that the discovered vulnerability does not concern his wallet. Meanwhile, Segers reported discovering two more vulnerabilities, for which he faced criticism for spreading panic.

Stay safe.

end-content

Пов'язані питання

QAccording to the article, which three hardware wallet manufacturers confirmed a sharp increase in sales in August?

AThe three hardware wallet manufacturers that confirmed a sharp increase in sales in August are Trezor, Bitbox, and Onekey.

QWhat was the main reason cited by Bitbox's CEO for the sales surge in North America?

ABitbox's CEO, Douglas Bakkum, stated that the sales surge in North America was largely due to the fact that Coldcard, a competing hardware wallet, had its strongest market presence there, leading affected users to seek alternatives.

QWhat action did Ledger's CTO suggest companies should focus on in response to AI-powered attacks?

ALedger's CTO, Charles Guillemet, suggested that companies should focus on two things: evolving responsible disclosure principles (releasing patches faster, shortening disclosure timelines) and educating users about how hardware wallets work.

QWhat did the developers of the Blockstream Jade wallet emphasize users should keep updated, beyond just their hardware wallets?

AThe developers of Blockstream Jade emphasized that users should keep not only their hardware wallet firmware updated, but also their apps, operating systems, devices, routers, and even home appliances, as security is a continuous process.

QWhat specific long-term security focus did Trezor's head of security mention regarding future threats?

ATrezor's head of security, Jan Čermák, stated that in the long term, the company will focus on 'staying ahead of AI-powered attacks, rather than reacting to them.'

Пов'язані матеріали

How 5G Will Be Launched in Russia: The Digital Ministry's Proposal and the Roadmap to 2035

Russia's Ministry of Digital Development has proposed a plan for launching 5G networks. It allows the "Big Four" mobile operators (Beeline, Megafon, MTS, T2) to deploy 5G on existing 4G/LTE base stations and frequencies, and will allocate them the new 4.63–4.99 GHz band. A key element is "technological neutrality," permitting the use of foreign equipment until September 2026. The new 4.63–4.99 GHz band is intended for more advanced services and industrial applications. However, a phased transition to Russian-made base stations will begin in 2027, with a target of at least 50% domestic equipment by 2030. The rollout timeline aims for 5G in cities with over 1 million people by the end of 2027, expanding to 84 cities by 2035. Initial "5G Ready" service, operating over existing infrastructure, will offer minimal speed improvements. Significant speed gains (4-10x over LTE) will require the new band and corresponding equipment. The plan addresses long-standing regulatory delays, including the military's hold on the global standard 3.4–3.8 GHz band. This forced Russia to adopt the 4.63–4.99 GHz range, overlapping with a Chinese band, making Chinese equipment a potential transitional solution. The success of the rollout will depend on equipment supply and the pace of production localization, while a challenge lies in smartphone compatibility with this non-standard frequency band.

cryptonews.ru1 год тому

How 5G Will Be Launched in Russia: The Digital Ministry's Proposal and the Roadmap to 2035

cryptonews.ru1 год тому

The Federal Reserve Bank of Dallas Announces a Colossal $700 Billion Allocation! How Will This Affect Bitcoin?

The Federal Reserve Bank of Dallas warns that the growing adoption of tokenized deposits in the banking sector could pose unforeseen risks to the financial system. Tokenized deposits, which transfer traditional bank deposits to blockchain infrastructure, offer features like instant settlement and programmable payments. While issued by regulated banks and maintaining deposit characteristics, they could enable customers to move funds between banks much faster in search of higher yields. This would significantly weaken banks' liquidity management and lending capacity. The Fed's analysis estimates that an increase in deposit interest rate sensitivity by 10% could reduce the interest rate risk banks can bear by approximately $700 billion over ten years. Similarly, a 10% shortening of the average deposit maturity could reduce the banking system's capacity to convert deposits into loans by about $580 billion. This acceleration of deposit movement could force banks to rely on more expensive wholesale funding, increasing borrowing costs for consumers and businesses and potentially making traditional banks resemble non-bank financial institutions. While the report does not directly address Bitcoin, the described shifts could have long-term implications. Firstly, the tokenization of deposits by banks could promote institutional adoption of blockchain-based financial infrastructure, indirectly legitimizing digital asset classes like Bitcoin. Secondly, faster-moving deposits and resulting higher funding costs could increase the price of liquidity in the financial system. This could create near-term headwinds for risk assets, including Bitcoin, due to tighter financial conditions and potential selling pressure. The report concludes that widespread adoption of this technology could impact many areas, from payment systems to monetary policy transmission mechanisms.

cryptonews.ru1 год тому

The Federal Reserve Bank of Dallas Announces a Colossal $700 Billion Allocation! How Will This Affect Bitcoin?

cryptonews.ru1 год тому

Торгівля

Спот
活动图片