Bitcoin Forum
August 18, 2026, 05:43:41 PM *
News: Latest Bitcoin Core release: 31.1 [Torrent]
 
   Home   Help Search Login Register More  
Pages: [1]
  Print  
Author Topic: ZachXBT called out Hardware Wallets  (Read 70 times)
cryptoaddictchie (OP)
Legendary
*
Offline

Activity: 2898
Merit: 1616



View Profile
August 17, 2026, 08:04:28 AM
 #1

With regards to recent Coldcard and Safepal incidents. It seems that 8 cases has been recorded this year and one ongoing. An X Kol Zachxbt whose known to share compromise and hack incident shared his enthusiast and called out everyone one of them. Users make this feel unsafe! Are we expecting more news?



Quote
ZachXBT called every hardware wallet garbage on 16 July.

SafePal made it eight incidents on 16 August.

Every one of them, and how it broke 👇

→ SafePal : order-tracking plug-in
→ Trezor : fulfillment provider
→ Ledger : e-commerce partner
→ Coldcard : five year old firmware bug
→ Tangem : laser through the secure element
→ Trezor Safe 7 : laser through a different one
→ Injective SDK : hijacked npm maintainer
→ Postal phishing : printed letters with QR codes

7 of the 8 had nothing to do with the hardware.
https://x.com/0xchainink/status/2088974760931942643

▄▄███████████████████▄▄
▄███████████████████████▄
███████████████████████
████████▀▀▀▀██▀█▄▀███████
███▀▀██▄▄██▄██▌▄▄▄▄▄██
████▄█████▐██▀▄█▀▀█████
█████▌██▀▀▄█▀██▄██▄███
██▄▄▄▄███████████▐███████
████████▐█████████▀▀█████
███████▄██████▀█▄▄▄▄▄████
███████████████████████

▀███████████████████████▀
▀▀███████████████████▀▀

 Kings Game  
 
 🎰   🎲   ⚽ 
████
██
██
██
██
██
██
██
██
██
██
██
████
████████████████████████████


RAKEBACK
..UP TO 30%..
████████████████████████████
████
██
██
██
██
██
██
██
██
██
██
██
████
████
██
██
██
██
██
██
██
██
██
██
██
████
████████████████████████████
 
..500%..
WELCOME BONUS
+ 250 FREE SPINS
████████████████████████████
████
██
██
██
██
██
██
██
██
██
██
██
████

   WIN NOW     
PX-Z
Legendary
*
Offline

Activity: 2268
Merit: 1367


Wallet Transaction Notifier - @txnNotifierBot


View Profile
August 17, 2026, 10:58:00 AM
 #2

It seems like, day by day, hardware wallet users are becoming increasingly exposed to privacy risks due to data breaches involving companies and third-party services in the hardware wallet connected shits. Coldcard incident is not privacy related buts the worst one.

 
 b1exch.to 
  ETH      DAI   
  BTC      LTC   
  USDT     XMR    
.███████████▄▀▄▀
█████████▄█▄▀
███████████
███████▄█▀
█▀█
▄▄▀░░██▄▄
▄▀██▄▀█████▄
██▄▀░▄██████
███████░█████
█░████░█████████
█░█░█░████░█████
█░█░█░██░█████
▀▀▀▄█▄████▀▀▀
SFR10
Legendary
*
Offline

Activity: 3808
Merit: 4153



View Profile WWW
August 17, 2026, 11:57:20 AM
 #3

Are we expecting more news?
I wouldn't be surprised to see similar incidents against other hardware wallet manufacturers, but I really hope this is the last one, since even the privacy-related ones can endanger someone.
- Concerning what ZachXBT said last month, I remember he specifically named Ledger after it seemed he was referring to all HWs (FWIW, I don't consider all HWs as garbage and if you take precautions, the attack surface becomes way smaller, while there are going to be some workarounds as well).

Meuserna
Sr. Member
****
Offline

Activity: 350
Merit: 622


View Profile WWW
August 17, 2026, 05:47:54 PM
 #4

My hope is that all of this causes more people to take free and open source projects like SeedSigner, ShieldSigner, Krux, and Kern more seriously. These offer better security anyway, though they do require the user to learn a little more up front.

I think ShieldSigner is currently the best hardware wallet available at any price, and it's free plus the cost of a Raspberry Pi Zero, camera, LCD hat and case.

Go this route and you won't be on anybody's mailing list.

Take it a step further and generate your own random seed phrase so you'll know your seed isn't vulnerable to a ColdCard-style attack.

Yamane_Keto
Hero Member
*****
Offline

Activity: 952
Merit: 596



View Profile WWW
Today at 03:01:17 PM
 #5

→ Tangem : laser through the secure element
→ Trezor Safe 7 : laser through a different one
Nanosecond laser pulse attacks are specialized attacks that require hardware wallet to be lost or stolen, sent to a specialized laboratory, and cost more than $200,000. The success of these attacks is almost impossible. SafePal, Trezor, Ledger are not attacks linked to physical devices.

▄███████████████████████▄
█████████████████████████
██████████▀▄▄▄▀██████████
███████████████████████
████████▀▀▄▄▄▀█████████
███████░░░█████░░░███████
██████░░░▐█████▌░░░██████
██████░░░▐█████▌░░░██████
██████░░░▐█████▌░░░██████
███████░░░█████░░░███████
████████▄▄▀▀▀▄█████████
█████████████████████████
▀███████████████████████▀
 
 Lock.com 
█▀▀











█▄▄
▀▀█











▄▄█
█▀▀











█▄▄
▀▀█











▄▄█
 
  Open  code isolated Crypto Wallet     Sign Up    
Pages: [1]
  Print  
 
Jump to:  

Powered by MySQL Powered by PHP Powered by SMF 1.1.19 | SMF © 2006-2009, Simple Machines Valid XHTML 1.0! Valid CSS!