Hardware wallets suffered at least 10 security incidents throughout 2026, with losses totaling $200 million. The breaches exposed persistent vulnerabilities across the custody sector that go beyond device firmware to supply chain, data storage and user behavior.
Coldcard's July incident proved the most destructive. A five-year-old bug in the device's random number generator made seed phrases guessable, allowing attackers to drain approximately $116 million in offline funds. This was the only incident where attackers directly compromised seed phrases through a cryptographic flaw in the hardware itself.
Ledger faced multiple problems. In October, the company paused sales through reseller CryptoBilis after customers reported drained funds tied to products purchased through that channel. In January, Ledger's payment processor Global-e leaked customer names and contact details, creating vulnerability to targeted phishing.
Trezor experienced three separate incidents. An August breach of its shipping partner exposed customer personal information to unauthorized parties. In September, attackers breached Trezor's email provider and sent fake security alerts to users, attempting to trick them into revealing recovery phrases. A June laser attack on the new chip in Trezor Safe 7 successfully extracted secrets, though no funds were directly compromised in that instance.
Safepal's order-tracking plugin exposed customer details in August. BitBox02 identified two severe firmware flaws through internal review in August, discovering them before attackers could exploit the vulnerabilities. Tangem's card password was bypassed in July using a laser attack, demonstrating the physical methods adversaries employ against hardware-based security.
February saw postal scams attempt to steal recovery phrases through fake Trezor letters containing malicious QR codes. The supply chain, data exposure, social engineering and firmware vulnerabilities collectively created a broad attack surface for hardware wallet users throughout 2026.
