Fear Strikes the Crypto Street: Coldcard Hacked - Are Ledger and Trezor Safe?
In the crypto world, we say: "not your keys, not your coins." That's why we buy hardware wallets, those mythical "cold safes," and think we can sleep soundly. But suddenly, in early August 2026, the market is shaken by the news - Coldcard, an icon of security and a wallet for Bitcoin "maximalists," has fallen victim to a "hacking attack." What happened? Are Ledger and Trezor also at risk? I asked an expert.
Photo: Everett Collection / Shutterstock
Many of you panicked. My phone was buzzing. "Janusz, what should I do? Will my Ledger be hacked? Is Trezor safe? How to live?" Calm down. We are lighting the torch of education. To explain to you what happened without spreading FUD, I contacted Łukasz Mikuła, a cybersecurity specialist and a member of our expert council. Łukasz analyzed the technical details and replied to me in a detailed email.
Today, based on information from him and the latest media reports, we break down the Coldcard affair into its components.
As of today (August 5, 2026): losses related to the Coldcard error may reach up to 130 million dollars (over 2000 BTC) from more than 7700 addresses. The count is still rising.
What happened? The anatomy of a "hack" that wasn't a hack
Let's start with the most important thing: no one broke Bitcoin's cryptography. No one physically hacked into the devices. The problem is much more insidious and relates to the moment when... you set up a wallet.
Łukasz Mikuła explained this phenomenon to me in two simple sentences in his email.
- In short, it was about the fact that when setting up a wallet on Coldcard, a random private key was not generated, but it was possible to guess what keys those wallets could generate. And someone ran a script and generated the same wallets that Coldcard's customers had...
That's the gist of it. To describe the incident in more detail, we need to delve a little deeper. Your private key (I refer you to lesson 2 of our series) is actually a huge number. Łukasz reminds us that it has up to 78 digits in decimal notation, and for comparison, it is estimated that the number of all atoms on Earth is "only" 10⁵⁰. These are astronomical values that guarantee that no one will ever accidentally generate the same key as you.
- The idea is that if only I know my secret big number, it acts like an unpredictable, super-complex password. And that's OK - writes Łukasz - The problem is where that number comes from. When you configure a hardware wallet, the device uses a Random Number Generator (RNG) to create that key (represented by 12 or 24 seed words).
And here we come to the drama of Coldcard. Analysis by Block's Bitcoin Engineering and Security team shows that the error lay in the software (firmware), which in certain situations ignored a proper hardware random generator, switching to a worse, ordinary software equivalent.
- In programming, there are ready-made components that ensure that the drawing is always random... but in the case of ColdCard, such a component was turned off. It is unclear why - simply at a certain point in the wallet software code, the randomness module was assigned a value of "0," which means it was turned off. Perhaps this is the result of a lack of communication within the programming team, or maybe something else. And the most surprising thing is that the device had a proper random generator on board, it just never used it - explains Łukasz Mikuła.
What’s the impact? Journalists from "CryptoSlate" are writing about the "randomness crash." Instead of an unimaginable number of combinations, the pool of possible wallets has shrunk so much that a hacker with a simple script on their computer could just check them one by one until they hit those belonging to clients. This was not an attack on your device in the drawer but an attack on the very process of your wallet's birth.
Who is behind this and the hacker's graffiti
Nothing is hidden on-chain. Researchers from Galaxy Research have identified addresses belonging to the attacker. Interestingly, the scandal is taking a bizarre turn. As reported by CoinDesk, the hacker's wallet, which contains the stolen BTC, has become a public bulletin board. People are using the OP_RETURN function (which allows adding a short text to a Bitcoin transaction) to send the hacker small payments with messages.
Some plead: "You stole it, please return at least some."
Others engage in tougher negotiations: "Return 80% of my 5 BTC."
There are also opportunists offering the hacker money laundering services for a 10% commission.
Madness.
Were you a Coldcard customer? This is urgent, act now!
Coinkite (the maker of Coldcard) has issued an urgent statement. If you used Mk2 or Mk3 models, or newer Mk4, Q, Mk5 with old software - you are at risk. Here’s the key instruction. Be careful, as many make a mistake here:
- Simply updating the software is not enough - warns Łukasz Mikuła - It needs to be done, but it only patches the hole for the future and does not change the key, which may already be compromised. Therefore, you must create a new wallet - generate a new seed phrase, and not log in with the old one on another hardware wallet - and transfer funds there.
A great summary of this situation is circulating on the internet: no secure storage will fix the problem if the password was weak from the start. Even if you kept the paper with those 12 or 24 words in a titanium safe underground, if those words were easily guessable by a computer, the hacker could still steal the money.
-- Price
Will Ledger and Trezor also crack? How to live?
This is the key question. Could the Coldcard scandal be a prelude to Armageddon for the entire hardware wallet industry? CoinDesk quotes Vincent Bouzon, an expert from Ledger, who tries to calm things down: "This is a failure of one implementation, not a verdict on self-custody."
Bouzon adds that the alternatives are worse - software wallets are even riskier, and exchanges are just debt receipts, not true ownership.
And what does our expert, Łukasz Mikuła, say when I asked him directly: "Are Ledger and Trezor resilient?" Here’s what he replied:
- It’s a tough question - professional curiosity does not allow me to say that something is "safe" without at least glancing at the code... besides, in one of our initial conversations, I mentioned that there is no perfect place to store cryptocurrencies, and each has its pros and cons, and I still stand by that.
Łukasz points to a fundamental problem: he cannot conduct a code audit, especially where the code is not open, and that’s how Ledger operates in key aspects. He can only "optimistically assume" that reputable brands will learn lessons from this. However, Łukasz’s most important conclusion is thought-provoking:
- I wouldn’t assume now that we can expect a wave of attacks on hardware wallets, but certainly, attackers, especially organized groups with great technological backing, will also be watching such solutions, so a responsible task lies ahead for wallet manufacturers.
The lesson from this whole affair is simple and unpleasant: in the world of cryptocurrencies, the saying "not your keys, not your coins" gains new meaning. Today, it’s also important to add: it matters not only who holds the key but also who and how produced it for you.
You can find all the entries from my journal here. I also invite you to visit my Facebook. You can send emails to janusz.krypto@bankier.pl.
This content is provided for general informational purposes only and doesn't constitute financial, investment, legal, or tax advice. Any events, rewards, online promotions, or related information mentioned herein should not be considered a recommendation, solicitation, or invitation to purchase, sell, trade, or otherwise deal in any crypto assets. Crypto assets are highly volatile and may result in loss. The availability of WEEX services, products, and related events may vary by region. You are responsible for ensuring that your participation is in accordance with applicable local laws and regulations.
You may also like

Georgia, Cryptocurrency and Sanctions: How a British Schoolboy Uncovered Russia's Shadow Network

Balanced v1 to Be Discontinued on December 1, 2026

How to Pay for Telegram Premium with Crypto and Other Methods in Russia in 2026

Why locked liquidity does not mean a token is safe

Coinbase CEO Says Misjudgment Over X Profile Change Led to Meme Coin Crash

The ICON Network will permanently shut down on December 31, 2026, and fully migrate to SODAX

Track Markets At a Glance: New WEEX Price Widgets for iOS & Android
To streamline your market data access, WEEX has officially launched "Market Watchlist" desktop widgets

Major Upgrade on Web: 10+ Advanced Chart Styles for Deeper Market Insights
To deliver more powerful and professional analysis tools, WEEX has rolled out a major upgrade to its web trading charts—now supporting up to 14 advanced chart styles.

Eve of Martian Colonization: Musk, Narrative Leverage, and a Trillion-Dollar Industry Rail

Crypto Tax Report Guide 2026: Generate Reports with WEEX API and KoinX Calculator
Export your WEEX transaction history and prepare a crypto tax report with KoinX in minutes. Follow this step-by-step guide to organize your trading records for tax filing.

New: Estimated Liquidation Price on App Candlestick Charts
WEEX has introduced a new Estimated Liquidation Price (Est. Liq. Price) feature on the candlestick chart to help traders better manage risk and identify safe ranges for their positions.

WEEX AI Trading Hackathon Guide: Find Your WEEX UID and Register
From now to February 2026, WEEX is launching AI Wars: WEEX Alpha Awakens, the world’s first global crypto AI trading hackathon. Come your UID and register for the WEEX Global AI Trading Hackathon.

New feature launch: Customisable Trading Page Layouts
You can now customise your trading page just the way you like it! The new customisable layout of our trading pages gives you full control over how your workspace looks and feels.

WEEX OTC Lists 200+ Trading Pairs
The WEEX OTC platform now supports 200+ new trading pairs, letting you buy crypto directly with your local currency—quick, simple, and secure.

Historical B/S Indicators for Candlestick Charts
WEEX just got smarter! Review past trades and refine your strategies with our brand-new feature: Historical B/S (Buy/Sell) markers for candlestick charts!

SQD adds validated onchain data to Google Cloud BigQuery

Term Finance closes Meta Vaults after estimated $8.5M attack

CryptoQuant's Risk for Bitcoin: Ki Young Ju Identifies the Main Threat to Bitcoin

Judicial Investigation Agency Raids Properties of Alias 'Gato's' Children in Costa Rica Case Expansion

Goldman Sachs backs crypto stocks amid Bitcoin breakout

Fixed-term deposits in dollars: what you earn by investing $2,000

Bitcoin Spot Demand: The Signal That Hadn't Reappeared Since the October 2025 Record

Cofund Maps Over 24 Bitcoin Covenant Use Cases

Purchase of Cryptocurrency Through Intermediaries Will Be Available to Unqualified Investors

Saudi Arabia Leads Mecca Agreement, Oil Dollar System Faces New Trust Test

$1 Billion in 48 Hours: X Prepares Crypto Trading Function on Feed

The forex complex: How retail traders are adapting to volatile 2026 markets

Trump Beats the Fed: How Trading Boom Explodes in the UAE

LayerZero Unveils ATLAS Exchange Engine









