Sales of Trezor, Onekey, and Bitbox Surge Amid Coldcard Crisis; Security Models Evolve

cryptonews.ruXuất bản vào 2026-08-26Cập nhật gần nhất vào 2026-08-26

Tóm tắt

Sales of Trezor, Onekey, and Bitbox hardware wallets surged significantly in August, driven by the security crisis involving Coldcard. These companies confirmed increased demand, particularly in North America where Coldcard had a strong presence. While specific figures weren't disclosed, Bitbox reported a roughly tenfold increase in credit card sales. Industry analysts note the incident prompted a wider discussion on hardware wallet security, leading manufacturers to review and enhance their security models and processes, such as seed phrase generation and entropy sources. The crisis underscored the importance of self-custody, with affected users seeking alternative wallets rather than abandoning the practice. Manufacturers like Trezor, Bitbox, and Onekey have implemented additional security checks and audits in response. The evolving threat landscape, accelerated by AI, is pushing the industry to focus on faster patch deployment, responsible disclosure, and user education. Security experts emphasize that maintaining security is a continuous, shared responsibility requiring users to keep all software and firmware updated. Meanwhile, reports emerged of another critical vulnerability in a major wallet's official firmware, though exploitation requires malicious host software. The industry remains vigilant, with companies investing in short, medium, and long-term security plans, including AI-assisted code review and independent penetration testing.

Of the 13 hardware wallet manufacturers contacted by Bitcoin.com News for comment, Trezor, Bitbox, and Onekey confirmed their sales increased sharply in August. Company Ledger declined to comment on its monthly sales, while Bitkey manufacturer Block—a publicly traded company—is only required to disclose information as part of its quarterly reports.

While none of the companies disclosed exact figures, Bitbox provided the most specific information, reporting that sales volume paid for by credit cards grew roughly tenfold compared to the baseline of previous weeks. This data does not include sales made using other payment methods.

"We saw a sharp increase in sales, primarily from North America, where Coldcard appears to have had the strongest presence," Bitbox CEO Douglas Bakkum told Bitcoin.com News.

A Positive Sign for Self-Custody

Meanwhile, Trezor reported it also saw a rise in sales, particularly for its bitcoin-only products. While the company did not provide specific numbers, its Head of Security, Jan Komařek, noted that this spike is an encouraging sign for the entire Bitcoin industry.

"The more interesting takeaway for us is the conclusion it leads to: it seems that people affected by the Coldcard situation sought another hardware wallet, rather than abandoning self-custody," he said, adding that this is "an encouraging conclusion: the response to a difficult moment was an effort to maintain control over one's own keys, not to relinquish it."

However, according to industry analysts, many hardware wallet users sent their funds to cryptocurrency exchanges or moved capital into ETFs, abandoning self-custody. In any case, it's unclear how extensive this migration was or whether it was merely a temporary measure, after which users returned to self-custody.

Onekey, while noting increased sales, pointed out that other factors may have influenced this, including individual product release cycles. According to the company, the Coldcard crisis sparked a much broader discussion about hardware wallet security issues that typically remain invisible to end-users, such as seed phrase generation.

However, the vulnerability in Coldcard's firmware triggered similar discussions and actions not only among end-users but also among hardware wallet manufacturers. Firstly, this incident prompted teams to re-evaluate their current security models.

What Wallet Manufacturers Have Already Done

Trezor reviewed its own seed phrase generation process with particular emphasis on addressing the vulnerability exploited in the Coldcard case; BitBox "once again thoroughly examined" the code of its random number generator, and Onekey reported conducting additional end-to-end checks of entropy and seed generation processes across its entire line of hardware wallets.

As Bitcoin.com News reported, separately and independently of the Coldcard incident, BitBox disclosed and fixed its own firmware bugs in August of this year. No reports of vulnerabilities were received. Meanwhile, in the same month, Trezor reported that nearly 14,000 of its customers were affected by a data breach at one of Trezor's delivery service providers.

In any case, the main battle for security is still ahead, as hardware wallets for bitcoin and other cryptoassets adapt to the new reality shaped by the development of artificial intelligence.

Two Things to Focus On

"Attackers are already operating at machine speed, so we need to act just as fast to stay ahead of them," stated Charles Guillemet, CTO of Ledger, adding that currently, defense is still evolving more slowly than attacks. At the very least, he said, the time gap between releasing a patch and its malicious use is shrinking.

The CTO emphasized that companies should now focus on two things: improving disclosure procedures and educating users.

"First, responsible disclosure principles must evolve: patches need to be released faster, disclosure timelines shortened, and migration strategies must assume that capable AI-using attackers are an integral part of the security model, not just additional enhancements," Guillemet said in an interview with Bitcoin.com News.

Furthermore, in his opinion, helping people understand how hardware wallets work "will be crucial for securing the industry."

Update Even Your Home Appliances

In a similar vein, in their "reflections on the implications of the Coldcard incident," the developers of the Blockstream Jade wallet urged hardware wallet users to keep their software up to date. Blockstream Jade just released a firmware update with a series of fixes. However, according to the team, beyond hardware wallets, users should keep their applications, operating systems, devices, routers, and even home appliances updated.

"Security is a continuous process, and you, as a user, must also participate in it," they emphasized, adding that the Coldcard bug was "an unfortunate case where updating" software and firmware "failed to secure users."

Meanwhile, Onekey added that hardware wallet security should be built on hardware-supported entropy and key storage, verifiable open-source software, independent security expertise, strict isolation of security-critical components, and user-verifiable transaction checks.

"As AI lowers the cost of software analysis and attack automation, the goal is to ensure that discovering one weakness in implementation does not undermine the entire security model," the wallet manufacturer stated.

Short-, Medium-, and Long-Term Security Plans

The companies themselves are already implementing short-term, medium-term, and long-term security changes. For example, Trezor, "as an immediate response to the Coldcard findings," is adding "additional correctness checks" of its own, internally generated device entropy when verifying whether external entropy is indeed being used.

"Beyond this, our analysis prompted us to strengthen internal testing and protection measures regarding the insecure test generator, as well as expand the ways to verify the call path of each individual entropy source," said Komařek, noting that the insecure generator is used exclusively for internal testing.

The company is also analyzing reports from independent security researchers and plans in the medium term to conduct a new penetration test of key firmware functions, to be performed by "an authoritative external security agency." Security audit reports are planned to be made public.

"In the long term, we will focus on staying ahead of AI-powered attacks, not just reacting to them," stated the head of security, while other wallet manufacturers also emphasized that they are already using AI to audit their code alongside bug bounty programs.

"Our Donjon research lab (a 'white hat' hacker lab) exists to try to hack our products before anyone else can, and internally we actively use Large Language Models (LLMs) to search for vulnerabilities in our own products," added Ledger's Guillemet.

Onekey reported it is currently focused on strengthening verification of security-critical code paths, firmware builds, entropy generation, and transaction signing flows, and in the medium term, its attention will be on transaction verification, with the Clear Signing solution in mind, relevant for many major cryptoassets beyond Bitcoin.

Shared Responsibility and New Critical Bugs

Meanwhile, security researchers from Block, the manufacturer of Bitkey, played a key role in assisting the Bitcoin and hardware wallet industry during the Coldcard crisis, as they actively engaged with the community, sharing important findings and coordinating response measures.

"We openly shared our findings both in public discussions on X and through private channels, as we believe that when security vulnerabilities affect the ecosystem, all manufacturers are obligated to act quickly," the company told Bitcoin.com News, adding that hardware wallets must maintain control over key security models.

While this article was being written, on August 26th, reports began circulating about another "critical vulnerability at a major hardware wallet manufacturer." Rob Segers, a Bitcoin security consultant and founder of Bitsaga, who discovered this bug alongside "several other high-severity bugs," reported that the unnamed manufacturer confirmed the existence of these bugs, "but a fix is already included in an upcoming release."

According to Segers, the critical vulnerability was found in the "official hardware wallet firmware, however, stealing funds requires malicious host software." This means the vulnerability could be exploited if a user, for example, downloads a fake wallet. Marek "Slush" Palatinus, co-founder of Trezor, confirmed that the discovered vulnerability does not concern his wallet. Meanwhile, Segers reported discovering two more vulnerabilities, for which he faced criticism for spreading panic.

Stay safe.

end-content

Câu hỏi Liên quan

QAccording to the article, which three hardware wallet manufacturers confirmed a sharp increase in sales in August?

AThe three hardware wallet manufacturers that confirmed a sharp increase in sales in August are Trezor, Bitbox, and Onekey.

QWhat was the main reason cited by Bitbox's CEO for the sales surge in North America?

ABitbox's CEO, Douglas Bakkum, stated that the sales surge in North America was largely due to the fact that Coldcard, a competing hardware wallet, had its strongest market presence there, leading affected users to seek alternatives.

QWhat action did Ledger's CTO suggest companies should focus on in response to AI-powered attacks?

ALedger's CTO, Charles Guillemet, suggested that companies should focus on two things: evolving responsible disclosure principles (releasing patches faster, shortening disclosure timelines) and educating users about how hardware wallets work.

QWhat did the developers of the Blockstream Jade wallet emphasize users should keep updated, beyond just their hardware wallets?

AThe developers of Blockstream Jade emphasized that users should keep not only their hardware wallet firmware updated, but also their apps, operating systems, devices, routers, and even home appliances, as security is a continuous process.

QWhat specific long-term security focus did Trezor's head of security mention regarding future threats?

ATrezor's head of security, Jan Čermák, stated that in the long term, the company will focus on 'staying ahead of AI-powered attacks, rather than reacting to them.'

Nội dung Liên quan

Cách thức triển khai 5G tại Nga: Đề xuất của Bộ Kỹ thuật số và lộ trình đến năm 2035

Bộ Truyền thông và Truyền thông Đại chúng Nga (MinTsifry) đã đề xuất kế hoạch triển khai mạng 5G, cho phép 4 nhà mạng lớn (Beeline, Megafon, MTS, T2) sử dụng trạm gốc và tần số hiện có của mạng LTE (4G), đồng thời cấp thêm dải tần mới 4.63–4.99 GHz. Đề xuất dựa trên nguyên tắc "trung lập công nghệ", cho phép sử dụng thiết bị nước ngoài đến hết ngày 1/9/2026 để khởi động dịch vụ 5G nhanh chóng. Dải tần mới sẽ hỗ trợ các dịch vụ công nghiệp như điều khiển thiết bị từ xa. Từ năm 2027, sẽ bắt đầu chuyển đổi dần sang thiết bị trạm gốc sản xuất trong nước, với mục tiêu đạt ít nhất 50% vào năm 2030 và hoàn tất vào cuối năm 2031. Theo lộ trình, 5G sẽ xuất hiện tại các thành phố có trên 1 triệu dân trước ngày 31/12/2027. Lịch trình chi tiết: 4 trung tâm khu vực vào cuối 2026, 16 thành phố vào 2027, 40 thành phố vào 2030 và 84 thành phố vào năm 2035. Ban đầu, việc triển khai ở chế độ "5G Ready" trên cơ sở hạ tầng hiện có sẽ chỉ mang lại cải thiện tốc độ tượng trưng. Tốc độ thực sự (nhanh hơn 4-10 lần so với LTE) chỉ đạt được sau khi triển khai dải tần mới với thiết bị chuyên dụng. Dải 4.63–4.99 GHz có nhược điểm là suy hao tín hiệu nhanh và khó xuyên tường, đòi hỏi mạng lưới trạm gốc dày đặc hơn, đồng thời không được tất cả điện thoại thông minh hỗ trợ. Việc triển khai 5G tại Nga bị trì hoãn lâu do Bộ Quốc phòng chiếm giữ dải tần "vàng" 3.4–3.8 GHz thường dùng cho 5G trên thế giới. Dải tần được chọn của Nga trùng lặp đáng kể với dải 4.8–5.0 GHz của Trung Quốc, tạo điều kiện sử dụng thiết bị chuyển tiếp từ Huawei và ZTE. Chất lượng mạng thực tế sẽ phụ thuộc vào tốc độ cung cấp thiết bị và tiến độ sản xuất trong nước. Một thách thức khác là sự hỗ trợ của các nhà sản xuất chip toàn cầu đối với dải tần đặc thù của Nga, điều này có thể ảnh hưởng đến danh mục thiết bị tương thích có sẵn cho người dùng.

cryptonews.ru1 giờ trước

Cách thức triển khai 5G tại Nga: Đề xuất của Bộ Kỹ thuật số và lộ trình đến năm 2035

cryptonews.ru1 giờ trước

Ngân hàng Dự trữ Liên bang Dallas tuyên bố phân bổ 700 tỷ USD khổng lồ! Điều này sẽ ảnh hưởng đến Bitcoin như thế nào?

Ngân hàng Dự trữ Liên bang Dallas cảnh báo rằng việc phổ biến các khoản tiền gửi được mã hóa (tokenized deposits) trong ngành ngân hàng có thể gây ra những hậu quả khó lường cho hệ thống tài chính. Các sản phẩm này, được phát hành bởi các ngân hàng được quản lý, chuyển tiền gửi truyền thống lên cơ sở hạ tầng blockchain, mang lại các tính năng như thanh toán tức thì. Tuy nhiên, cơ sở hạ tầng thanh toán dựa trên blockchain và hợp đồng thông minh có thể khiến khách hàng dễ dàng chuyển tiền đến các ngân hàng có lãi suất cao hơn trong vài giây, làm giảm sự "gắn bó" với ngân hàng và khiến tiền gửi nhạy cảm hơn với biến động lãi suất. Nghiên cứu ước tính nếu độ nhạy của tiền gửi với lãi suất tăng 10%, rủi ro lãi suất mà hệ thống ngân hàng Mỹ có thể gánh chịu có thể giảm khoảng 700 tỷ USD tính trên 10 năm. Việc tiền gửi dịch chuyển nhanh hơn có thể buộc các ngân hàng phải tìm đến các nguồn vốn tổng hợp đắt đỏ hơn, làm tăng chi phí vay cho người tiêu dùng và doanh nghiệp. Dù không trực tiếp thảo luận về Bitcoin, báo cáo gợi ý hai tác động tiềm tàng. Thứ nhất, việc ngân hàng áp dụng cơ sở hạ tạ tầng blockchain có thể hỗ trợ tính hợp pháp của các tài sản kỹ thuật số như Bitcoin. Thứ hai, những thay đổi cấu trúc trong hệ thống ngân hàng (như chi phí vay tăng, điều kiện tài chính thắt chặt) có thể gây áp lực bán ngắn hạn lên các tài sản rủi ro, bao gồm Bitcoin.

cryptonews.ru1 giờ trước

Ngân hàng Dự trữ Liên bang Dallas tuyên bố phân bổ 700 tỷ USD khổng lồ! Điều này sẽ ảnh hưởng đến Bitcoin như thế nào?

cryptonews.ru1 giờ trước

Công nghệ Blockchain có thể làm mất đi 700 tỷ USD tiềm năng tín dụng của các ngân hàng Hoa Kỳ

Ngành ngân hàng truyền thống đang tìm cách thích ứng với nền kinh tế số, xem tiền gửi được mã hóa (tokenized) là lựa chọn thay thế ổn định và được quản lý cho stablecoin. Tuy nhiên, một báo cáo mới từ Cục Dự trữ Liên bang Dallas (Fed Dallas) cảnh báo việc áp dụng rộng rãi công nghệ blockchain có thể gây ra mối đe dọa lớn cho hệ thống tài chính. Báo cáo chỉ ra rằng sự chuyển đổi hàng loạt sang tiền gửi được mã hóa có thể làm suy yếu nghiêm trọng khả năng cho vay của các ngân hàng Mỹ. Cốt lõi của ngân hàng truyền thống dựa vào quá trình chuyển đổi kỳ hạn, nơi các khoản tiền gửi ngắn hạn của khách hàng được sử dụng để tài trợ cho các tài sản dài hạn như thế chấp và cho vay doanh nghiệp. Tokenization đe dọa phá vỡ sự cân bằng này. Nếu khách hàng trở nên nhạy cảm hơn 10% với lãi suất nhờ tính minh bạch và tốc độ của blockchain, tiềm năng tín dụng của hệ thống ngân hàng Mỹ có thể giảm tới 700 tỷ USD. Tốc độ giao dịch gần như tức thời của tiền mã hóa cho phép vốn di chuyển nhanh chóng, và nếu điều này khiến tiền gửi rời khỏi ngân hàng nhanh hơn 10%, các tổ chức tín dụng có thể mất thêm 580 tỷ USD vốn. Để đối phó với nguy cơ rút tiền tức thời, các ngân hàng sẽ buộc phải tích trữ nhiều tài sản thanh khoản chất lượng cao hơn (như tiền mặt và trái phiếu kho bạc), thay vì cho vay vào nền kinh tế thực. Điều này sẽ thu hẹp nguồn tín dụng cho doanh nghiệp và hộ gia đình. Kết luận chính là: việc tích hợp tiền gửi được mã hóa mang lại trải nghiệm giống crypto cho khách hàng, nhưng đồng thời tước đi công cụ tạo ra lợi nhuận chính của ngân hàng - dựa trên việc giữ tiền của khách hàng trong thời gian dài - và dẫn đến những mâu thuẫn hệ thống.

cryptonews.ru1 giờ trước

Công nghệ Blockchain có thể làm mất đi 700 tỷ USD tiềm năng tín dụng của các ngân hàng Hoa Kỳ

cryptonews.ru1 giờ trước

Việc giảm số lượng giao dịch trên sổ cái XRP Ledger trùng với mức tăng khối lượng lên 521%

Khối lượng thanh toán trên sổ cái XRP Ledger (XRPL) đã tăng 521,1%, trùng hợp với sự cải thiện chung của thị trường tiền điện tử. Hiện tại, khối lượng thanh toán đạt 488,4 triệu XRP. Một điểm đáng chú ý là mặc dù khối lượng tăng mạnh, số lượng giao dịch thanh toán lại giảm 10,5% xuống còn 388.900 giao dịch. Điều này cho thấy quy mô trung bình của mỗi giao dịch đã tăng lên đáng kể, phản ánh hoạt động của các cá voi (người nắm giữ lượng XRP lớn). Các chỉ số khác cũng hỗ trợ cho sự gia tăng hoạt động: số tài khoản mới tăng 5,3% (khoảng 1.800 tài khoản), số người dùng hoạt động tăng mạnh 179,7% lên khoảng 485.700. Phí giao dịch bằng XRP tăng 16,1%. Tuy nhiên, số tài khoản tích cực lại giảm nhẹ 0,7% xuống 11.300. Về giá, XRP hiện đang được giao dịch trên mức trung bình động dài hạn khoảng 1,35 USD. Chỉ số Sức mạnh Tương đối (RSI) đã chạm trên 80 trước khi giảm về 70,5. Tóm lại, mức tăng khối lượng 521% là đáng kể nhưng không đồng nghĩa với việc sử dụng XRPL tăng gấp sáu lần. Sự kết hợp giữa khối lượng tăng và số giao dịch giảm cho thấy sự dịch chuyển của các khối lượng lớn hơn từ các nhà đầu tư tổ chức hoặc cá nhân có ảnh hưởng.

cryptonews.ru1 giờ trước

Việc giảm số lượng giao dịch trên sổ cái XRP Ledger trùng với mức tăng khối lượng lên 521%

cryptonews.ru1 giờ trước

Giao dịch

Giao ngay
活动图片