In the crypto world, we say: "not your keys, not your coins." That's why we buy hardware wallets, those mythical "cold safes," and think we can sleep soundly. But suddenly, in early August 2026, the market is shaken by the news - Coldcard, an icon of security and a wallet for Bitcoin "maximalists," has fallen victim to a "hacking attack." What happened? Are Ledger and Trezor also at risk? I asked an expert.
Photo: Everett Collection / Shutterstock
Many of you panicked. My phone was buzzing. "Janusz, what should I do? Will my Ledger be hacked? Is Trezor safe? How to live?" Calm down. We are lighting the torch of education. To explain to you what happened without spreading FUD, I contacted Łukasz Mikuła, a cybersecurity specialist and a member of our expert council. Łukasz analyzed the technical details and replied to me in a detailed email.
Today, based on information from him and the latest media reports, we break down the Coldcard affair into its components.
As of today (August 5, 2026): losses related to the Coldcard error may reach up to 130 million dollars (over 2000 BTC) from more than 7700 addresses. The count is still rising.
Let's start with the most important thing: no one broke Bitcoin's cryptography. No one physically hacked into the devices. The problem is much more insidious and relates to the moment when... you set up a wallet.
Łukasz Mikuła explained this phenomenon to me in two simple sentences in his email.
That's the gist of it. To describe the incident in more detail, we need to delve a little deeper. Your private key (I refer you to lesson 2 of our series) is actually a huge number. Łukasz reminds us that it has up to 78 digits in decimal notation, and for comparison, it is estimated that the number of all atoms on Earth is "only" 10⁵⁰. These are astronomical values that guarantee that no one will ever accidentally generate the same key as you.
And here we come to the drama of Coldcard. Analysis by Block's Bitcoin Engineering and Security team shows that the error lay in the software (firmware), which in certain situations ignored a proper hardware random generator, switching to a worse, ordinary software equivalent.
What’s the impact? Journalists from "CryptoSlate" are writing about the "randomness crash." Instead of an unimaginable number of combinations, the pool of possible wallets has shrunk so much that a hacker with a simple script on their computer could just check them one by one until they hit those belonging to clients. This was not an attack on your device in the drawer but an attack on the very process of your wallet's birth.
Nothing is hidden on-chain. Researchers from Galaxy Research have identified addresses belonging to the attacker. Interestingly, the scandal is taking a bizarre turn. As reported by CoinDesk, the hacker's wallet, which contains the stolen BTC, has become a public bulletin board. People are using the OP_RETURN function (which allows adding a short text to a Bitcoin transaction) to send the hacker small payments with messages.
Some plead: "You stole it, please return at least some."
Others engage in tougher negotiations: "Return 80% of my 5 BTC."
There are also opportunists offering the hacker money laundering services for a 10% commission.
Madness.
Coinkite (the maker of Coldcard) has issued an urgent statement. If you used Mk2 or Mk3 models, or newer Mk4, Q, Mk5 with old software - you are at risk. Here’s the key instruction. Be careful, as many make a mistake here:
A great summary of this situation is circulating on the internet: no secure storage will fix the problem if the password was weak from the start. Even if you kept the paper with those 12 or 24 words in a titanium safe underground, if those words were easily guessable by a computer, the hacker could still steal the money.
This is the key question. Could the Coldcard scandal be a prelude to Armageddon for the entire hardware wallet industry? CoinDesk quotes Vincent Bouzon, an expert from Ledger, who tries to calm things down: "This is a failure of one implementation, not a verdict on self-custody."
Bouzon adds that the alternatives are worse - software wallets are even riskier, and exchanges are just debt receipts, not true ownership.
And what does our expert, Łukasz Mikuła, say when I asked him directly: "Are Ledger and Trezor resilient?" Here’s what he replied:
Łukasz points to a fundamental problem: he cannot conduct a code audit, especially where the code is not open, and that’s how Ledger operates in key aspects. He can only "optimistically assume" that reputable brands will learn lessons from this. However, Łukasz’s most important conclusion is thought-provoking:
The lesson from this whole affair is simple and unpleasant: in the world of cryptocurrencies, the saying "not your keys, not your coins" gains new meaning. Today, it’s also important to add: it matters not only who holds the key but also who and how produced it for you.
You can find all the entries from my journal here. I also invite you to visit my Facebook. You can send emails to [email protected].
This content is provided for general informational purposes only and doesn't constitute financial, investment, legal, or tax advice. Any events, rewards, online promotions, or related information mentioned herein should not be considered a recommendation, solicitation, or invitation to purchase, sell, trade, or otherwise deal in any crypto assets. Crypto assets are highly volatile and may result in loss. The availability of WEEX services, products, and related events may vary by region. You are responsible for ensuring that your participation is in accordance with applicable local laws and regulations.












![[Contribution] Expanding Trade Territories and the Won Stablecoin: A Chance to Reshape the Game](/public-static/24_18140364e2.png?format=avif)
















