Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

The reported $130 million in Coldcard-related thefts is an estimate, not a final audited loss total. Galaxy Research put losses near that level on August 7, 2026; TechCrunch had reported an approximately $130 million estimate on August 4. The incident reports point to a seed-generation failure—not proof that one hardware-wallet brand is universally safer than the other.

What the reported Coldcard incident involved

A hardware wallet can keep signing keys offline and still be at risk if the recovery seed was generated from weak or predictable randomness. A seed is the starting secret from which a wallet derives its keys; if an attacker can predict or reconstruct it, the attacker may be able to derive those keys without physically taking the wallet.

In an August 2, 2026 explanation, Ledger attributed the reported Coldcard problem to firmware falling back from hardware randomness to a software generator seeded with values that could be reconstructed from the device. That is Ledger’s company-authored account, not an independent technical finding. The exact affected Coldcard models, firmware ranges, and remediation steps must be checked against Coinkite’s current advisory; those details are not established here.

Galaxy Research’s August 7 report estimated at least 15 independent attackers and tracked losses near $130 million. TechCrunch’s August 4 report cited a similar estimate from blockchain security researchers. Both figures describe a developing incident and on-chain estimates; neither should be read as a proven or audited final total.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

How Coldcard and Ledger compare on security

There is no responsible single score that settles which brand is safer. Security depends on the specific device and firmware, how its seed is generated and protected, the update process, and how the owner handles the recovery phrase and computer or phone used with the wallet.

Security area What the cited material establishes What it does not establish
Seed generation Ledger’s August 2, 2026 account says its devices use a true random number generator (TRNG) in a Secure Element and claims 256 bits of entropy for a 24-word recovery phrase. The same Ledger account attributes the Coldcard incident to a firmware fallback to software-generated randomness. These are Ledger’s product and incident claims, not an independent, like-for-like test of current Coldcard and Ledger models. The exact affected Coldcard models and firmware versions are not stated here.
Seed storage and isolation Ledger Donjon’s published threat model says Ledger seed material is stored in Secure Element non-volatile memory and is not available to applications through an operating-system API. This describes Ledger’s documented design; it is not a complete security assessment of every device, firmware release, or attack path.
Physical and supply-chain attacks A Ledger Donjon bulletin from 2018 documented a Nano S supply-chain attack scenario requiring prior physical access. The bulletin said the scenario did not extract the seed or private keys from the Secure Element. A protection against that particular scenario does not rule out other attack classes or establish comparative security against Coldcard.
Transparency and review Ledger publishes Secure Element architecture and threat-model material; its historical bulletin also publicly described an issue and countermeasures. Public source code alone does not prove a product secure, and proprietary components alone do not prove it insecure. The cited materials do not provide an independent, current, model-by-model ranking.
Firmware and user response The reported incident makes the seed-generation behavior of the device firmware material to security. The current Coinkite advisory’s affected scope and migration procedure are not established here. No blanket remediation instruction can safely be inferred.

Was Ledger affected by the Coldcard incident?

The reports and Ledger’s explanation describe the incident as involving Coldcard seed generation. The material cited here does not report that Ledger was affected by that incident. That is narrower than a guarantee that Ledger devices are immune to compromise: Ledger’s own materials describe particular design protections and threat models, not a universal security warranty.

Ledger CTO Charles Guillemet wrote in Ledger’s August 2 company publication: “Cryptography is hard. Implementing it securely is harder. And the part almost nobody thinks about, generating high quality randomness, is where the whole thing lives or dies.” He also wrote, “This week’s Coldcard incident made that visible in the most expensive way possible.” These are remarks from Ledger’s executive in Ledger’s own account, not independent expert consensus.

What to do if you may have generated an affected Coldcard seed

Start with Coinkite’s current security advisory and follow its instructions for the precise model, firmware, and seed-generation circumstances it identifies. Do not assume that installing firmware updates by itself makes a recovery seed generated under a potentially vulnerable process safe. A replacement device also does not make an old, potentially exposed seed safe; any migration must address the seed and derived funds according to Coinkite’s verified guidance.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

What matters more than the brand label

The incident is a reminder that “offline” describes only part of a wallet’s security. A useful assessment looks at the complete chain: whether randomness is generated correctly, whether key material remains isolated, how firmware is built and updated, what independent review or certification actually covers, and whether the owner protects the recovery phrase and connected devices. A feature or architecture claim matters, but it cannot substitute for evidence about the particular implementation and threat model.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.