Chain INK identified ten security incidents affecting hardware wallets since early 2026, causing nearly $200 million in losses. Coldcard was hit on July 30 by a firmware flaw exploiting an insufficient random number generator, resulting in approximately $111 million stolen from over 5,200 wallets. Ledger faces since October 9 a supply chain attack through reseller CryptoBilis, with $87 million drained from 98 devices. Data leaks from Trezor, SafePal, and Ledger partners exposed personal information of over 120,000 customers, enabling massive phishing campaigns. Technical vulnerabilities were also discovered in Tangem, Trezor Safe 7, and BitBox devices, questioning the supremacy of self-custody in favor of regulated exchanges.
Source: Read the original article

