Writing · August 2026
The safest place in crypto just got robbed.
For years, the standard advice in crypto — mine included — has ended the same way: get your coins off the exchange and onto a hardware wallet. Cold storage. The vault. The safest place there is. This month, attackers drained roughly $116 million in bitcoin from the vault.
Starting July 30, about 1,816 BTC was pulled from more than 5,200 addresses tied to Coldcard hardware wallets — devices people bought specifically because they take security seriously. Nobody picked locks. Nobody stole devices. According to TRM Labs' analysis, a firmware bug dating back to 2021 weakened the randomness used to generate some wallets' seeds — cutting effective key strength from 128 bits down to as little as 40. At 40 bits, an attacker doesn't need your device. They just need computers and patience, and they had both.
I want to be careful here, because the wrong lesson is easy to take.
The wrong lesson is "hardware wallets don't work." They do. Cold storage is still the right architecture, the same way a locked toolbox is still better than tools in the truck bed. The flaw wasn't the idea. The flaw was in one implementation, at one point in time — and in the assumption thousands of us make every day: I bought the right device, so I'm done.
That assumption is the actual vulnerability. I know it personally. I lost 9 BTC in my early years not because I owned bad tools, but because I trusted my setup instead of verifying it.
The device is not the security. The habits are. A table saw doesn't square the cut — the carpenter does.
So here's what this month's news actually teaches, in the form I'd give any of my students.
Your seed's birthday is load-bearing forever
Your seed was generated once, one way, on one firmware version — and that moment matters for as long as the wallet holds anything. If you own a hardware wallet, any brand, find out when your seed was generated and on what firmware. Vendors publish advisories; almost nobody reads them. Read them. If your seed was created in a window covered by a known flaw, migrating to a fresh wallet isn't paranoia. It's maintenance.
Concentration is a choice
One seed protecting everything means one bad firmware week costs you everything. Splitting holdings across wallets — even imperfectly — turns a catastrophe into an incident.
Your name is part of your attack surface now
In the same month, SafePal disclosed a breach exposing order records — names, home addresses, contact details — for nearly 40,000 hardware-wallet customers. No coins were touched. They didn't need to be. A list of people who verifiably own cold-storage devices, with home addresses, is a phishing campaign waiting to happen. If you've ever ordered a wallet to your house, treat every "urgent security update" email as hostile until proven otherwise. No legitimate company will ever ask for your recovery phrase. Not once. Not ever.
The attackers are scaling faster than the defenders
TRM reports AI adoption across crypto crime rose about 40% year over year, and industry leaders are warning that autonomous agents could make today's billion-dollar hacking years look small. What used to require a skilled attacker choosing a target now runs as software against everyone at once. The era where "I'm too small to bother with" counted as a security strategy is over. The brute-forcing of those weak Coldcard seeds is what automated, patient attacking looks like — and it's the least of what's coming.
The unglamorous thing
None of this is a reason to leave crypto, and it's certainly not a reason to move everything back to an exchange — custody risk didn't get smaller this month either. It's a reason to do the unglamorous thing: verify your own setup while nothing is wrong. Check your firmware history. Read your vendor's advisories. Assume the email is a phish. Split what shouldn't be concentrated.
The vault is still worth having. But a vault you've never inspected is just a box you haven't been robbed from yet.
Verify everything — especially the thing you were told was safe.
— Jon Tetreault, August 2026. The habits, tools, and checks behind this piece are what I teach in Crypto Security Mastery.