Of the 13 hardware wallet manufacturers Bitcoin.com News contacted for comment, Trezor, Bitbox, and Onekey confirmed that their sales jumped in August. Ledger declined to comment on its monthly sales, while publicly listed Bitkey’s manufacturer, Block, is bound by its quarterly reports.
While none of the companies disclosed the exact numbers, Bitbox was the most specific, saying that its credit-card sales jumped roughly tenfold compared with the baseline in the preceding weeks. This doesn’t include sales made through other payment methods.
“We have seen a surge in sales, mostly coming from North America, where presumably Coldcard had its largest presence,” Bitbox CEO Douglas Bakkum told Bitcoin.com News.
An Encouraging Sign for Self-Custody
Meanwhile, Trezor said it also saw an increase in sales, notably in sales of its bitcoin-only products. While the company didn’t specify the numbers, its Head of Security, Jan Komárek, pointed out that this spike is an encouraging sign for the whole Bitcoin industry.
“To us, the more interesting point is what that suggests: it looks like people affected by the Coldcard situation went looking for another hardware wallet rather than giving up on self-custody,” he said, adding that this is “the encouraging takeaway, that the response to a hard moment was to stay in control of their own keys, not to retreat from it.”
However, according to industry analysts, many hardware wallet users sent their funds to crypto exchanges or moved their capital to ETFs, abandoning self-custody. In either case, it is unclear how large this migration was or whether it was only a temporary measure before users returned to self-custody.
Onekey, while also registering an increase in sales, noted that this might also have been affected by other factors, including individual product cycles. According to the company, the Coldcard crisis fueled much greater discussion about hardware wallet security questions that are usually invisible to end users, such as seed phrase generation.
However, the Coldcard firmware exploit fueled similar discussions and actions not only among end users but also among hardware wallet manufacturers. First, the incident prompted the teams to review their current security models.
What Wallets Have Already Done
Trezor reviewed its own seed generation specifically against the failure mode that was exploited in the Coldcard case; BitBox took “another detailed look” at its own random number generator code, while Onekey said it conducted an additional end-to-end verification of the entropy and seed-generation paths across its hardware wallet lineup.
As reported by Bitcoin.com News, separately and unrelated to Coldcard, Bitbox disclosed and patched its own firmware bugs this August. No exploitation has been reported. Meanwhile, in the same month, Trezor disclosed that almost 14,000 of its customers were affected by a data breach at one of Trezor’s shipping providers.
In either case, the main security battle still lies ahead as hardware wallets for bitcoin and other crypto assets adjust to the new reality prompted by AI.
Two Things to Focus on
“Attackers are already working at machine speed, so we need to as well to stay ahead of them,” Charles Guillemet, Ledger’s CTO, said, adding that defence currently still moves slower than attackers. At least, according to him, the window between a patch shipping and it being weaponised is shrinking.
The CTO emphasised that companies should now focus on two things: improving disclosure and user education.
“First, responsible disclosure needs to evolve with faster patching, shorter disclosure timelines, and migration strategies that assume capable, AI-assisted attackers are part of the security model rather than optional improvements,” Guillemet told Bitcoin.com News.
Also, according to him, helping people understand hardware wallets “is going to be essential to keeping the industry safe.”
Upgrade Even Your Home Appliances
On the same note, in their “reflections on the Coldcard fallout,” the developers of the Blockstream Jade wallet urged hardware wallet users to keep their software up to date. Blockstream Jade just released a firmware update with a number of fixes. However, according to the team, besides hardware wallets, users should keep their applications, operating systems, devices, routers, and even home appliances up to date.
“Maintaining security is an ongoing process, and you as a user must also participate,” they stressed, adding that the Coldcard bug was “an unfortunate case where users could not be made safe by upgrading” their software and firmware.
Meanwhile, Onekey added that hardware wallet security needs to be built around hardware-backed entropy and key storage, verifiable open-source software, independent security review, strong separation of security-critical components, and clear user-facing transaction verification.
“As AI lowers the cost of analyzing software and automating attacks, the goal is to make sure that discovering one implementation weakness is not enough to compromise the entire security model,” the wallet manufacturer said.
Short-, Medium- and Long-Term Security Plans
The companies themselves are already implementing short-, medium- and long-term security changes. For example, Trezor, “in direct response to the Coldcard findings,” is adding “further sanity checks” on the device’s own internally generated entropy when verifying whether external entropy is genuinely used.
“Beyond that, our review has led us to strengthen our internal testing and tripwires around the insecure test generator, and to extend how we verify the call path of each individual entropy source,” Komárek said, noting that the insecure generator exists only for internal testing.
The company is also working through reports from independent security researchers and, in the medium term, is planning a new penetration test of core firmware features, carried out by “a well-regarded external security agency.” Security audit reports are planned to be public.
“Longer term, our focus is on staying ahead of AI-enabled attacks rather than reacting to them,” the Head of Security said, as other wallet manufacturers have also stressed that they’re already using AI to review their code, alongside bounty programs.
“Our Donjon research lab (white hat hacker lab) exists to try to break our products before anyone else can, and internally we make heavy use of LLMs to hunt for vulnerabilities in our own products,” Ledger’s Guillemet added.
Onekey said it is now focused on strengthening reviews of security-critical code paths, firmware builds, entropy generation, and transaction-signing flows, while, in the medium term, its focus is going to be on transaction verification, referring to the Clear Signing solution, relevant for many major crypto assets outside bitcoin.
Common Responsibility and New Critical Bugs
Meanwhile, the security researchers at Bitkey’s manufacturer, Block, were instrumental in helping the Bitcoin and hardware wallet industry during the Coldcard crisis, as they actively engaged with the community to share critical findings and coordinate response efforts.
“We shared our findings transparently through both public X discussions and private channels because we believe that when security vulnerabilities affect the ecosystem, all manufacturers have a responsibility to act quickly,” the company told Bitcoin.com News, adding that hardware wallets should retain control over key security models.
While writing this article, on Aug. 26, reports about another “critical bug in a major hardware wallet vendor” started circulating. Rob Segers, a Bitcoin security consultant and founder of Bitsaga, who found the bug alongside “several other high-severity” bugs, said that the undisclosed vendor confirmed these bugs, “but a fix is already in an upcoming release.”
According to Seger, the critical bug was found in the “official hardware firmware but does require malicious host software” to steal the funds. This means the bug could be exploited if a user, for example, downloads a fake wallet. Marek “Slush” Palatinus, co-founder of Trezor, confirmed that the reported bug is not about this wallet. Meanwhile, Seger reported that he had found two more bugs, drawing criticism for spreading panic.
Stay safe.
news.bitcoin.com