Coin Bureau|10月 10, 2026 21:40
🚨SHOCKING: Hardware wallets have been hit by at least 10 incidents in 2026, and the two biggest drained an estimated $200 MILLION.
Here's the recap:
1. Coldcard (Jul): A 5-year-old bug made seed phrases guessable, letting attackers drain about $116 MILLION offline
2. CryptoBilis (Oct): Ledger paused this reseller's sales after an estimated $86 MILLION+ was drained from its buyers
3. Trezor (Sep): Its email provider was breached, sending fake security alerts to 347,000 users
4. Trezor (Aug): Its shipping partner leaked data on about 81,000 customers
5. SafePal (Aug): An order-tracking plug-in exposed nearly 40,000 customers' details
6. BitBox02 (Aug): Its own AI-assisted review found two severe firmware flaws
7. Tangem (Jul): Researchers bypassed the card's password with a laser
8. Trezor Safe 7 (Jun): A laser attack extracted secrets from its new chip, with funds not exposed
9. Ledger (Jan): Its payment partner Global-e leaked customer names and contact details
10. Postal scams (Feb): Fake Trezor letters with QR codes tried to steal recovery phrases
Only the Coldcard attack cracked seed phrases themselves, by exploiting weak randomness.
Share To
Timeline
HotFlash
APP
X
Telegram
CopyLink