hardware wall2026-09-30 10:11:12Crypto hardware wallets compared for 2026: Ledger, Trezor, QR devices and Bitcoin-only modelsCointelegraph has published a broad 2026 comparison of crypto hardware wallets, sorting devices by security model, connectivity, usability and recovery design rather than by branding alone. The guide covers multi-asset wallets, QR-based signers, NFC wallet cards and Bitcoin-only devices, while also explaining what hardware wallets can and cannot protect against. The publication said it hands-on tested Trezor Safe 7, Ledger Stax, Flex, Nano Gen5, Nano X, Nano S Plus and Coinkite’s Opendime across Linux and macOS setups, using both official and third-party software. Other products in the roundup were included based on public information. Among the tested devices, Cointelegraph said Ledger Stax showed noticeable input lag tied to its wraparound screen, making PIN entry slower and less reliable than on cheaper touchscreen models. The article also highlights trade-offs across the market: Bluetooth and USB models for broader compatibility, QR wallets that avoid live data links during signing, NFC cards that sacrifice on-device verification, and Bitcoin-only wallets that narrow functionality in exchange for a smaller attack surface. It also points to a July 2026 Coinkite warning over flawed Coldcard firmware and an Aug. 24 update from Galaxy Research’s Alex Thorn linking about 1,789 BTC in thefts from 8,865 addresses to that issue.250
Bitcoin2026-09-28 15:10:58Ledger CTO says hidden public keys do not remove Bitcoin’s quantum riskLedger Chief Technology Officer Charles Guillemet said he disagrees with the view that only about 30% of Bitcoin is exposed to quantum-computing risk while the remaining roughly 70% is safe because it is protected by public-key hashes. Citing Glassnode data, he noted that about 30.2% of BTC has already exposed spending public keys on-chain, but argued that this figure captures only what is visible in a static on-chain state. Public keys that have not appeared on-chain may still exist in xpubs, devices, PSBT files, logs, or backups. He also said that once a Bitcoin transaction is initiated, the public key becomes visible before the transaction is confirmed. Guillemet further cited research from Google Quantum AI saying that, under a high-speed quantum computer model that does not currently exist, an attack against secp256k1 could be completed in about nine minutes. On that basis, he said hiding public keys alone cannot solve the quantum threat and that Bitcoin will ultimately need to migrate to post-quantum cryptography.230
Ledger2026-09-28 14:49:31Ledger CTO Questions Claim That Only 30% of Bitcoin Faces Quantum RiskLedger Chief Technology Officer Charles Guillemet said the idea that only about 30% of Bitcoin is exposed to quantum-computing risk, while the remaining roughly 70% stays safe because public keys are protected by hashes, is flawed. He was responding to earlier Glassnode data showing that around 30.2% of BTC has already exposed spending public keys on-chain. Guillemet argued that this figure captures only the blockchain’s static state and does not account for public keys that may still exist in xpubs, devices, PSBT files, logs, or backups. He also noted that once a Bitcoin transaction is initiated, the public key becomes visible before confirmation. Citing research from Google Quantum AI, Guillemet said that under the assumption of a fast quantum computer that does not yet exist today, an attack against secp256k1 could be completed in about nine minutes. On that basis, he said hiding public keys alone is not enough to solve Bitcoin’s quantum-risk problem and that the network will ultimately need to migrate to post-quantum cryptography.220
OneKey2026-09-18 01:37:12OneKey founder Yishi Wang on AI-driven security, the Bybit hack, and how hardware wallets stay aliveOneKey founder Yishi Wang used a wide-ranging interview to map out how he entered crypto, how OneKey found its first users during DeFi Summer, and why he thinks AI has sharply compressed the timeline for both attackers and defenders. Speaking with Beca in an interview published by MarsBit, Wang said he first bought Bitcoin in 2013 while studying civil engineering, then later moved from ByteDance into crypto after deciding the industry offered faster feedback loops and a stronger personal conviction. He said OneKey’s early traction came in 2020, when larger on-chain users wanted hardware protection but found existing wallet setups cumbersome. Wang argued that local user experience improvements and open-source design helped OneKey win those users. He also described mistakes during the company’s growth phase, including nearly a year of product shortages and what he called premature design and over-optimization. A large part of the discussion focused on security. Wang said AI has cut the time needed to build a full attack chain from roughly two months with two or three senior researchers to two weeks with one security engineer in one recent case handled by OneKey’s Anzen Labs. He also walked through his reading of the $1.5 billion Bybit theft, saying the failure was not in the multisig contract, cold wallet, or Ledger device itself, but in a compromised Safe frontend engineer and a blind-signing flow that failed to show the real action being approved.550
data breach2026-09-11 21:45:05Law Firm Cyberattacks Rise as Stolen Files Surface on the Dark Web, With Crypto Firms Facing Similar BreachesInternational law firm Greenberg Traurig said an unauthorized actor accessed a limited set of documents and posted them on the dark web, according to a Thursday Reuters report. The incident adds to a broader rise in cyberattacks against law firms, a sector that increasingly holds sensitive client records and case materials. Reuters said BakerHostetler handled nearly 60 cybersecurity incidents involving law firms in 2025, almost twice the number it handled in 2024. In a report released earlier this year, the firm said its 2026 Data Security Incident Response Report drew on more than 1,250 incidents across industries in 2025, with phishing making up 30% of cases. Reuters also pointed to recent disclosures by Taft Stettinius & Hollister, Herbert Smith Freehills Kramer, WilmerHale, Goodwin Procter, and Quinn Emanuel. The article also linked the legal sector’s troubles to recent breaches disclosed by crypto companies including Coinbase, Ledger, SafePal, and Trezor, each involving some form of customer information exposure while companies said wallet credentials, funds, or private keys were not affected where specified.210
Ledger2026-09-10 00:27:43Ledger names Oded Blatman as CIO and CSOLedger SAS, the crypto hardware wallet maker, has hired Oded Blatman as chief information officer and chief security officer, according to Bloomberg. The appointment puts the company’s internal technology systems and security functions under a single executive. Blatman previously worked at blockchain company Fireblocks. In his new role, he will oversee cyber and infrastructure security, product security, physical and workplace security, internal IT, and enterprise risk management. The move combines several operational and security responsibilities into one leadership post at Ledger.680
Ledger2026-09-08 22:23:22Ledger and Trezor urge private reporting for hardware wallet flawsHardware wallet makers Ledger and Trezor are calling on security researchers to follow responsible disclosure practices by reporting vulnerabilities privately before making details public. According to Cointelegraph, Ledger’s chief technology officer said artificial intelligence has lowered the barrier to finding bugs, but argued that publishing technical details before a patch is available amounts to "trading other people’s risk for attention." He cited 90 days as a common default remediation window, while adding that the timeline can be adjusted based on the severity of the flaw. Trezor’s head of security said that such a deadline also represents a commitment on the vendor’s side. The comments come as hardware wallet security remains under close scrutiny. The report noted that losses tied to the Coldcard theft case have exceeded $100 million, while a data breach involving a Trezor shipping service provider affected tens of thousands of customers.760
vulnerability2026-09-07 14:38:25Ledger, Trezor Call for Responsible Vulnerability Disclosure as AI Lowers Exploitation CostLedger and Trezor have jointly called for more responsible disclosure of security vulnerabilities, citing AI's role in reducing the cost and difficulty of finding and exploiting flaws. Trezor security chief Jan Komárek singled out the recent theft of 4,000 BTC from Liquid Network as a violation of responsible disclosure principles.890