$130 Million Gone Because the Randomness Was Predictable: Which Hardware Wallet You Can Still Buy
The Coldcard flaw proved the most respected wallet is not the safest. Which vendor has which track record – and why now is the wrong moment to pause your savings plan.

There are two kinds of bitcoin holder this week. One checks the price every morning. The other checks whether the coins are still there.
The reason is a device that spent years being called the safest thing you could buy for bitcoin: the Coldcard. Since 31 July 2026, more than $116 million has drained from over 5,200 addresses, with some tallies now reaching roughly $130 million. And here is the sting: the victims are not the careless ones. They are the careful ones. Offline, cold storage, seed stamped into steel, never photographed — and emptied anyway.
This article answers three questions. What actually happened? Which manufacturer can you still buy in good conscience? And why would switching off your savings plan right now be the most expensive mistake of your year?
What actually happened at Coldcard
The Coldcard, made by Canadian firm Coinkite, has been the connoisseur's wallet for years: bitcoin only, no compromises, a fiercely loyal community. But in firmware 4.0.0, shipped since March 2021, the device bypassed its own randomness chip when generating a seed phrase and reached for a predictable software substitute instead. For five years, unnoticed.
Anyone who generated a seed on the device in that window did not receive a random sequence. They received a computable one — a lock whose key can be filed down by anyone who knows the flaw. The rest is compute.
On 31 July, roughly 594 BTC left about 500 wallets in 25 minutes. By 2 August the total stood at 1,367 BTC. A fourth sweep on 3 August took another 449 BTC. The Mk2, Mk3, Mk4, Mk5 and Q models may all be affected, depending on which firmware was running when the seed was created.
The order of events is everything. The device was not hacked. The randomness that invented your key was. A firmware update cannot repair a seed that already exists. Anyone affected has to generate a new one and move everything.
Timeline and technical detail: 594 BTC gone in 25 minutes — the Coldcard flaw explained and the fourth sweep.
The lesson: track record beats spec sheet
Every hardware wallet advertises the same vocabulary. Secure element, open source, air gap, PIN, passphrase. Those features sit on almost every spec sheet and compare about as usefully as engine horsepower.
What is not on any spec sheet: how a manufacturer has behaved, over years, when something went wrong. That is the criterion now. And on it, the market reorders itself.
Coinkite (Coldcard)
An excellent technical reputation, uncompromisingly bitcoin-focused, one of the most loyal user bases in the market. And a key-generation flaw nobody caught for five years — the worst category there is, because it cannot be healed retroactively. Coinkite responded with corrected firmware and told users to move funds to newly generated wallets. For new buyers, the sensible position right now is to wait for the independent post-mortem.
Ledger
The French market leader has the longest incident list in the business. With one qualifier that the outrage usually drowns out: not one of those incidents ever broke the hardware itself.
- July 2020: a breach of the online shop exposing more than a million customer records. To this day the raw material for phishing letters and counterfeit "replacement devices".
- May 2023: the Ledger Recover row. The option to split the seed into encrypted shards contradicted the promise many people thought they had bought.
- December 2023: the Connect Kit exploit. Malicious code reached dApps through a former employee's phished npm account; roughly $484,000 drained — from dApp users, not from wallet holders.
- January 2026: customer data again, this time via shop partner Global-e.
A Ledger owner need not fear that the firmware will take their balance. They need to fear a very convincing letter arriving in the post — because their delivery address has been traded since 2020.
Tangem
The counter-design, and from today's vantage point the most interesting one. Tangem uses cards rather than a device with a screen, a cable and a battery. The key is generated inside a secure element certified to Common Criteria EAL6+ and never leaves the card. No USB port, no on-device firmware updates, no battery to die on you — and therefore far less surface to attack. Backup is not a slip of paper in a folder but a set of two or three paired cards.
The track record reads as unspectacular, which is exactly the point: independent reviews by Kudelski Security (2018), Riscure (2023) and Cure53 (2026), none of which found a vulnerability. Across more than a million cards shipped, no systematic compromise has surfaced. That is not a guarantee. But it is the kind of boring, checkable history that counts for more after a week like this than any feature on a box.
Disclosure: CryptoTicker runs partner programmes with some of the providers named here. The assessment above follows the publicly documented incident record, not the commercial relationship. Where our view diverges from that relationship — as with Coldcard and Ledger — we say so.
Prices, supported coins and ratings in detail: our hardware wallet comparison.
Three rules that follow from this week
Rule 1: buy on history, not on features
Before you order, search the manufacturer's name alongside "incident", "breach" or "vulnerability". You are not hoping for zero results — every serious vendor has some. You are reading the response. How fast was the disclosure? Was it complete? Did an independent audit follow? A manufacturer who dissects its own failures in public is safer than one whose file merely looks empty.
Rule 2: never rely on a single source of randomness
Coldcard was a randomness failure. If you would rather not leave entropy entirely to the device, there are two robust routes: generate the seed from dice rolls, which several devices support. Or run a multisig across two different brands. In a 2-of-3 setup spanning two manufacturers, a vendor-wide firmware defect stops being a total loss and becomes an inconvenience.
Rule 3: look, instead of hoping
Cold storage tempts you not to look for years. Book a quarterly appointment: check balances through a block explorer — the public address is enough, and you enter your seed nowhere — skim the vendor's firmware changelog, verify where the backup lives. Fifteen minutes, four times a year. That is the entire price.
And now the part almost everyone gets wrong in weeks like this
Bitcoin trades around $64,100 on 5 August 2026. The news flow is grim: a hardware wallet disaster, two perp DEXs drained in July, the first US spot ETF closing its doors. The reflex is always the same — pause the savings plan, "until this settles down".
It is the reflex that ruins your average entry price over the years. A savings plan is not a market instrument. It is an instrument against your own mood, and its entire value is created in exactly the months you want to switch it off. Anyone who paused in 2022 missed the cheapest stretch of the cycle and restarted in summer 2024 at markedly higher prices. The market takes a summer break. Your savings plan does not.
Our pick: Coinbase — but not through the savings-plan button
For European investors, Coinbase is the obvious choice right now. Since June 2026 its European business has run under a MiCA licence based in Luxembourg, consolidating its previous national authorisations, including the German one. Since the last MiCA transition period expired on 1 July 2026, that is precisely what separates the exchanges that stay from the ones that leave. Add clean SEPA rails, local-language support and a tax export the common tools can actually read.
And now the part providers rarely put in the advertising: the convenient recurring-buy button is the most expensive way to buy on Coinbase.
| Route | Effective cost per purchase | Effort |
|---|---|---|
| Recurring buy in the Coinbase app | around 2.5 percent (fee plus spread) | set once, runs itself |
| Card payment | an additional 3.49 percent | minimal — and worth nothing |
| Limit order via Coinbase Advanced | from 0.6 percent (maker) | two minutes a month |
On €200 a month that is roughly €60 a year — for exactly the same result in your portfolio. Two minutes a month, priced at sixty euros. Convenience rarely costs that much.
The workflow that gives you both: a standing SEPA transfer into your Coinbase account, one limit order a month in Coinbase Advanced, then withdraw to your own wallet. The convenience lives in the standing order, not in the buy button.
Providers side by side — fees, minimum instalment, execution frequency, withdrawal costs: our guide to buying bitcoin. And on who still operates under regulation in Europe after MiCA: regulated crypto exchanges compared.
What to take away
The Coldcard incident did not prove that self-custody is a mistake. It proved that self-custody is a vendor decision — and that the decision rests on documented history, not on reputation inside the bubble.
If you do only three things this week, do these:
- Establish your exposure. Using a Coldcard with a seed generated on the device after March 2021? Then create a new wallet today, on corrected firmware or another manufacturer's device, and move everything. Do not send a test amount and wait — the flaw is public, and so are the addresses.
- Confirm or change your custody vendor on track record. Not on the feature list, not on price. On incident history and response behaviour. The hardware wallet comparison does the research for you.
- Keep the savings plan running — and while you are in there, move it from the app to a monthly limit order. Five minutes of work, around sixty euros a year.
And the larger lesson, the one that outlives this week: security in crypto is rarely a question of technology. It is almost always a question of selection. Choose your provider on verifiable history rather than on promises, and you have already left most of the risk behind — with your wallet as much as with your exchange.
(As of 5 August 2026. This article is not investment advice. Prices and fee models change — check current terms with the provider before every purchase.)





























