‹ BackNewsHardware wallet

Hardware wallet

Trezor says ShipMonk breach exposed 67,000 more US users, taking total above 80,000
Trezor Updates ShipMonk Breach: 67,000 More US Users Exposed
Ledger Hit with Class Action Over 2023 Data Breach Disclosure
Ledger Hit with US Class Action Over 2023 Security Breach, Customer Data Leak Led to Crypto Theft
Ledger Hit with Class Action in New York Over Incomplete Disclosure of Security Breach
Coolbit Technologies withdraws $23 million Nasdaq IPO plan
Ledger’s September wallet sale spotlights Nano X and Flex Neptune Blue at 20% off
Coldcard
2026-08-31 00:12:42

Coldcard entropy flaw shakes self-custody confidence, but experts still favor holding your own keys

A flaw tied to entropy handling in Coldcard hardware wallets has triggered Bitcoin losses and reignited a core debate in crypto: whether users are still better off keeping assets in self-custody after a wallet failure of this scale. According to the report, the issue stemmed from a deep firmware bug that remained hidden for five years and affected private-key generation on Coldcard Mk3 devices. During a code migration from Python to C, developers unintentionally disabled the built-in secure random number generator, causing the device to fall back to a highly insecure algorithm and reducing cryptographic entropy from 256 bits to just 22 bits. Speakers at Bitcoin Asia said the incident exposed weak spots in vendor maintenance, including code review, bug bounty design, and broader management practices. Even so, they argued that centralized exchanges still carry greater counterparty risk than hardware defects. The discussion centered on multi-vendor multisig setups using devices from different manufacturers, along with passphrase protections and modern coordination tools such as Liana, Unchained, and Casa. The report also said development teams are increasingly turning to AI-assisted code auditing to scan large legacy codebases and catch logic errors earlier. In that view, the Coldcard incident has damaged trust, but it has also pushed the ecosystem toward stricter security practices rather than away from self-custody.

860
Coldcard entropy flaw shakes self-custody confidence, but experts still favor holding your own keys