Bitcoin Forum
August 19, 2026, 07:06:07 PM *
News: Latest Bitcoin Core release: 31.1 [Torrent]
 
   Home   Help Search Login Register More  
Pages: [1]
  Print  
Author Topic: ZachXBT called out Hardware Wallets  (Read 95 times)
cryptoaddictchie (OP)
Legendary
*
Offline

Activity: 2898
Merit: 1618



View Profile
August 17, 2026, 08:04:28 AM
 #1

With regards to recent Coldcard and Safepal incidents. It seems that 8 cases has been recorded this year and one ongoing. An X Kol Zachxbt whose known to share compromise and hack incident shared his enthusiast and called out everyone one of them. Users make this feel unsafe! Are we expecting more news?



Quote
ZachXBT called every hardware wallet garbage on 16 July.

SafePal made it eight incidents on 16 August.

Every one of them, and how it broke 👇

→ SafePal : order-tracking plug-in
→ Trezor : fulfillment provider
→ Ledger : e-commerce partner
→ Coldcard : five year old firmware bug
→ Tangem : laser through the secure element
→ Trezor Safe 7 : laser through a different one
→ Injective SDK : hijacked npm maintainer
→ Postal phishing : printed letters with QR codes

7 of the 8 had nothing to do with the hardware.
https://x.com/0xchainink/status/2088974760931942643

▄▄███████████████████▄▄
▄███████████████████████▄
███████████████████████
████████▀▀▀▀██▀█▄▀███████
███▀▀██▄▄██▄██▌▄▄▄▄▄██
████▄█████▐██▀▄█▀▀█████
█████▌██▀▀▄█▀██▄██▄███
██▄▄▄▄███████████▐███████
████████▐█████████▀▀█████
███████▄██████▀█▄▄▄▄▄████
███████████████████████

▀███████████████████████▀
▀▀███████████████████▀▀

 Kings Game  
 
 🎰   🎲   ⚽ 
████
██
██
██
██
██
██
██
██
██
██
██
████
████████████████████████████


RAKEBACK
..UP TO 30%..
████████████████████████████
████
██
██
██
██
██
██
██
██
██
██
██
████
████
██
██
██
██
██
██
██
██
██
██
██
████
████████████████████████████
 
..500%..
WELCOME BONUS
+ 250 FREE SPINS
████████████████████████████
████
██
██
██
██
██
██
██
██
██
██
██
████

   WIN NOW     
PX-Z
Legendary
*
Offline

Activity: 2268
Merit: 1371


Wallet Transaction Notifier - @txnNotifierBot


View Profile
August 17, 2026, 10:58:00 AM
 #2

It seems like, day by day, hardware wallet users are becoming increasingly exposed to privacy risks due to data breaches involving companies and third-party services in the hardware wallet connected shits. Coldcard incident is not privacy related buts the worst one.

 
 b1exch.to 
  ETH      DAI   
  BTC      LTC   
  USDT     XMR    
.███████████▄▀▄▀
█████████▄█▄▀
███████████
███████▄█▀
█▀█
▄▄▀░░██▄▄
▄▀██▄▀█████▄
██▄▀░▄██████
███████░█████
█░████░█████████
█░█░█░████░█████
█░█░█░██░█████
▀▀▀▄█▄████▀▀▀
SFR10
Legendary
*
Offline

Activity: 3808
Merit: 4153



View Profile WWW
August 17, 2026, 11:57:20 AM
 #3

Are we expecting more news?
I wouldn't be surprised to see similar incidents against other hardware wallet manufacturers, but I really hope this is the last one, since even the privacy-related ones can endanger someone.
- Concerning what ZachXBT said last month, I remember he specifically named Ledger after it seemed he was referring to all HWs (FWIW, I don't consider all HWs as garbage and if you take precautions, the attack surface becomes way smaller, while there are going to be some workarounds as well).

Meuserna
Sr. Member
****
Offline

Activity: 351
Merit: 623


View Profile WWW
August 17, 2026, 05:47:54 PM
 #4

My hope is that all of this causes more people to take free and open source projects like SeedSigner, ShieldSigner, Krux, and Kern more seriously. These offer better security anyway, though they do require the user to learn a little more up front.

I think ShieldSigner is currently the best hardware wallet available at any price, and it's free plus the cost of a Raspberry Pi Zero, camera, LCD hat and case.

Go this route and you won't be on anybody's mailing list.

Take it a step further and generate your own random seed phrase so you'll know your seed isn't vulnerable to a ColdCard-style attack.

Yamane_Keto
Hero Member
*****
Offline

Activity: 952
Merit: 598



View Profile WWW
August 18, 2026, 03:01:17 PM
 #5

→ Tangem : laser through the secure element
→ Trezor Safe 7 : laser through a different one
Nanosecond laser pulse attacks are specialized attacks that require hardware wallet to be lost or stolen, sent to a specialized laboratory, and cost more than $200,000. The success of these attacks is almost impossible. SafePal, Trezor, Ledger are not attacks linked to physical devices.

▄███████████████████████▄
█████████████████████████
██████████▀▄▄▄▀██████████
███████████████████████
████████▀▀▄▄▄▀█████████
███████░░░█████░░░███████
██████░░░▐█████▌░░░██████
██████░░░▐█████▌░░░██████
██████░░░▐█████▌░░░██████
███████░░░█████░░░███████
████████▄▄▀▀▀▄█████████
█████████████████████████
▀███████████████████████▀
 
 Lock.com 
█▀▀











█▄▄
▀▀█











▄▄█
█▀▀











█▄▄
▀▀█











▄▄█
 
  Open  code isolated Crypto Wallet     Sign Up    
dkbit98
Legendary
*
Offline

Activity: 3052
Merit: 8817



View Profile WWW
August 18, 2026, 06:04:57 PM
Merited by DaveF (2)
 #6

ZachXBT is a silly social media clown, and according to him everything purchased with leak personal information is garbage.
If he thinks this data leaks are going to be restricted only to crypto and hardware wallets, than he is a bigger idiot than I thought.

▄▄██████▄░░░▄██████▄▄
██▀▀░░░░░░░░░░░░░▀▀██
▄▄██████▄▄██████▄▄
▄████▀▀▀▀█████▀▀▀▀████▄
▄███░░░▄▄░░░░░░▄▄░░░███▄
▄▄▄███░░░░██░░░░░░░██░░░░███▄▄▄
████████░░░░██░░░░░░░██░░░░████████
██████████░░░▀▀░░░░░░▀▀░░░██████████
████▀▀██████▄▄▄▄█████▄▄▄▄██████▀▀████
▀███▄░░▀▀███████████████████▀▀░░▄███▀
▀████▄▄░░░░▀▀▀▀▀▀▀▀▀▀▀▀▀░░░░▄▄████▀
▀███████▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄███████▀
▀▀█████████████████████▀▀
  
OrangeFren
  
██
██
██
██
██
██
██
██
██
██
██
  
▄▄█████▄▄
▄████▀▀▀████▄
███▀░░░░░░░▀███
███▀░░░▄█░░░░▀███
███░░░░░░░░░░███
███▄░░░▄█▄░░░▄███
███▄░░░░░░░▄███
▀████▄▄▄████▀
█████████
▐█████████▌
██████████
▐████▌▐████▌
▀▀▀█░░░█▀▀▀
 
bitbollo
Legendary
*
Offline

Activity: 4074
Merit: 4985


https://bit.ly/bitbollo


View Profile
Today at 02:42:15 PM
 #7

potentially hardware wallets offer more point of attack than a self custody solution.
I would see as non-sense any claims to "better entropy". I don't know how it can be possible to generate a number safer included in a range of 2^256 ... any number is already safe in this range unless you use a weak system to genearte it (or a rigged system like coldcards).
In this list I would not mix the various issues we have seen. Distributors leaks or lasers are completely different.
Probably more others could emerge in a secondary time. It has always been assumed that certain solutions are "safe" but probably it could be just an assumption Sad

▄▄████████████████████▄▄
▄███████▀▀██████▀▀███████▄
████████████████████████
████████▄▄██████▄▄██████

████████████████████████
██▄▄█████████████▄▄██████
██▀▀██████████████████▄▄██
██████▀▀██████████████▀▀██
██████████████████████████
██████▀▀██████▀▀████████
████████████████████████
▀███████▄▄██████▄▄███████▀
▀▀████████████████████▀▀
 
 DΞX.fo 
▄▄██████
█████████
██████████
█████████
██████████
█████████
▀▀██████

▄███████
▄██████████
████████████
█████████████
█████████████
|
▄▄█
▄████▀
▄███▀
▄██▀▄██
█████▀▀
███████
████████
▀██▄████
▄████▄▄
▄█████▀███
▄█████▀████
█████▀███████
▀██▀█████████
|..BTC......XMR...
..USDT.....LTC...
....Fees  0.8%.....
Pages: [1]
  Print  
 
Jump to:  

Powered by MySQL Powered by PHP Powered by SMF 1.1.19 | SMF © 2006-2009, Simple Machines Valid XHTML 1.0! Valid CSS!