
Bitbox credit-card sales ran roughly tenfold above baseline in August; Trezor and Onekey also saw jumps; a critical bug report surfaced Aug. 26.
NEWS CORP currently carries an Alpha Score of n/a, giving AlphaScala's model a neutral read on the setup.
Hardware wallet sales jumped in August after the Coldcard exploit, testing the manufacturers' ability to handle sharply higher demand. Trezor and Bitbox confirmed the increase to Bitcoin.com News; Onekey reported higher sales as well.
Bitbox was the most specific. Credit-card sales ran roughly tenfold above the baseline of the preceding weeks, the company said; purchases through other payment methods were not counted. The surge came mostly from North America, "where presumably Coldcard had its largest presence," CEO Douglas Bakkum told Bitcoin.com News.
Trezor's increase was most pronounced in its bitcoin-only products. Jan Komárek, Trezor's head of security, told Bitcoin.com News the spike was an encouraging sign for the whole Bitcoin industry. "To us, the more interesting point is what that suggests: it looks like people affected by the Coldcard situation went looking for another hardware wallet rather than giving up on self-custody," he said. The response, he added, was "the encouraging takeaway, that the response to a hard moment was to stay in control of their own keys, not to retreat from it."
Onekey also registered an increase, cautioning that individual product cycles could have contributed. The crisis fueled much greater discussion of hardware wallet security questions that are usually invisible to end users, such as seed phrase generation, Onekey said.
Ledger declined to comment on monthly sales. None of the companies disclosed exact figures. Block, the publicly listed maker of Bitkey, is bound by its quarterly reports.
Not every Coldcard user remained in self-custody. Analysts consulted by Bitcoin.com News said many sent funds to crypto exchanges or moved capital into ETFs. How large that migration was, and whether it was temporary, remains unclear.
The incident also pushed manufacturers to review their own security models. Trezor re-examined its seed generation against the specific failure mode exploited in the Coldcard case. Bitbox took "another detailed look" at its random number generator code. Onekey ran an additional end-to-end verification of the entropy and seed-generation paths across its hardware wallet lineup.
Separately, and unrelated to Coldcard, Bitbox disclosed and patched its own firmware bugs this August. No exploitation has been reported. In the same month, Trezor said almost 14,000 of its customers were affected by a data breach at one of its shipping providers.
The main security battle still lies ahead; hardware wallets for bitcoin and other crypto assets are adjusting to a new reality prompted by AI. "Attackers are already working at machine speed, so we need to as well to stay ahead of them," Charles Guillemet, Ledger's CTO, told Bitcoin.com News. Defense still moves slower than attackers, he said, and the window between a patch shipping and its weaponization is shrinking.
Guillemet said companies should focus on responsible disclosure and user education. "First, responsible disclosure needs to evolve with faster patching, shorter disclosure timelines, and migration strategies that assume capable, AI-assisted attackers are part of the security model rather than optional improvements," he said. Helping people understand hardware wallets, he added, "is going to be essential to keeping the industry safe."
Blockstream Jade's developers, in their "reflections on the Coldcard fallout," urged users to keep their software up to date; the wallet just released a firmware update with a number of fixes. "Maintaining security is an ongoing process, and you as a user must also participate," they stressed, adding that the Coldcard bug was "an unfortunate case where users could not be made safe by upgrading." The team said users should also keep their applications, operating systems, devices, routers and home appliances up to date.
Onekey said hardware wallet security should be built around hardware-backed entropy and key storage, verifiable open-source software, independent security review, strong separation of security-critical components, and clear user-facing transaction verification. "As AI lowers the cost of analyzing software and automating attacks, the goal is to make sure that discovering one implementation weakness is not enough to compromise the entire security model," Onekey said.
Trezor, "in direct response to the Coldcard findings," is adding "further sanity checks" on the device's internally generated entropy when verifying whether external entropy is genuinely used. Komárek said the review also led Trezor to strengthen internal testing and tripwires around the insecure test generator, which exists only for internal testing, and to extend how it verifies the call path of each individual entropy source.
Beyond the entropy checks, Trezor is working through reports from independent security researchers and, in the medium term, plans a new penetration test of core firmware features by "a well-regarded external security agency"; the audit reports are planned to be public. "Longer term, our focus is on staying ahead of AI-enabled attacks rather than reacting to them," Komárek said.
Ledger's Donjon research lab exists to try to break the company's products before anyone else can, Guillemet said, and internally Ledger makes "heavy use of LLMs to hunt for vulnerabilities in our own products." Onekey said it is strengthening reviews of security-critical code paths, firmware builds, entropy generation, and transaction-signing flows. Its medium-term focus is transaction verification, via its Clear Signing solution, which covers many major crypto assets outside bitcoin.
Block said its security researchers were instrumental in helping the hardware wallet industry during the Coldcard crisis, engaging with the community to share findings and coordinate response efforts. "We shared our findings transparently through both public X discussions and private channels because we believe that when security vulnerabilities affect the ecosystem, all manufacturers have a responsibility to act quickly," Block told Bitcoin.com News. Hardware wallets, Block added, should retain control over key security models.
On Aug. 26, reports surfaced of another "critical bug in a major hardware wallet vendor." Rob Segers, a Bitcoin security consultant and founder of Bitsaga, said he found the bug alongside "several other high-severity" issues, and that the undisclosed vendor confirmed the findings. "But a fix is already in an upcoming release," he said.
Segers said the critical bug sits in the "official hardware firmware but does require malicious host software" to steal funds, and that the bug could be exploited if a user downloads a fake wallet. Trezor co-founder Marek "Slush" Palatinus confirmed the reported bug is not about Trezor's wallet. He also reported two more bugs, a disclosure that drew criticism for spreading panic.
Drafted by a large language model from the source reporting linked above, then screened by automated publishing checks. It is not read by a journalist before publication. Some articles cite our Alpha Score. Verify prices and figures against the original source. Educational coverage, not personalized advice.