{"id":77325,"date":"2026-08-26T18:43:44","date_gmt":"2026-08-26T18:43:44","guid":{"rendered":"https:\/\/crowdfundjunction.com\/blog\/trezor-onekey-bitbox-sales-spike-amid-coldcard-crisis-security-models-evolve-bitcoin-news\/"},"modified":"2026-08-26T18:43:44","modified_gmt":"2026-08-26T18:43:44","slug":"trezor-onekey-bitbox-sales-spike-amid-coldcard-crisis-security-models-evolve-bitcoin-news","status":"publish","type":"post","link":"https:\/\/crowdfundjunction.com\/blog\/trezor-onekey-bitbox-sales-spike-amid-coldcard-crisis-security-models-evolve-bitcoin-news\/","title":{"rendered":"Trezor, Onekey, Bitbox Sales Spike Amid Coldcard Crisis; Security Models Evolve \u2013 Bitcoin News"},"content":{"rendered":"<p><b>(Originally posted on : Bitcoin News )<\/b><br \/>\n<\/p>\n<div>\n<div class=\"@container mb-[25px] rounded-sm overflow-clip py-0.5 pr-0.5 pl-2.5 bg-success-100\">\n<div class=\"flex flex-col gap-m overflow-clip rounded-[6px] !bg-success-10 p-3 @[420px]:p-m\">\n<h2 class=\"m-0 flex items-center gap-s text-[19px] !text-[#1c1c1c] md:text-[20px]\"><svg xmlns=\"http:\/\/www.w3.org\/2000\/svg\" width=\"16\" height=\"10\" viewbox=\"0 0 16 10\" fill=\"none\" class=\"shrink-0 text-success-100\" aria-hidden=\"true\"><path d=\"M1 1.5h14\" stroke=\"currentColor\" stroke-width=\"2.5\" stroke-linecap=\"round\"\/><path d=\"M1 8.5h10\" stroke=\"currentColor\" stroke-width=\"2.5\" stroke-linecap=\"round\"\/><\/svg><span>Key Takeaways<\/span><\/h2>\n<ul class=\"m-0 flex list-none flex-col gap-m pl-0\">\n<li class=\"m-0 flex items-start gap-s !text-[#434248]\"><span class=\"mt-2 size-2 shrink-0 rounded-full bg-success-100\" aria-hidden=\"true\"\/><span class=\"text-body\">Hardware wallet sales surged as Bitcoiners sought alternatives rather than abandoning self-custody.<\/span><\/li>\n<li class=\"m-0 flex items-start gap-s !text-[#434248]\"><span class=\"mt-2 size-2 shrink-0 rounded-full bg-success-100\" aria-hidden=\"true\"\/><span class=\"text-body\">Artificial intelligence (AI)-powered attacks are pushing hardware wallet makers toward faster patching, stronger disclosure and better user education.<\/span><\/li>\n<li class=\"m-0 flex items-start gap-s !text-[#434248]\"><span class=\"mt-2 size-2 shrink-0 rounded-full bg-success-100\" aria-hidden=\"true\"\/><span class=\"text-body\">Users are encouraged to keep all their software up to date, even on home appliances, as new severe bugs emerge.<\/span><\/li>\n<\/ul>\n<\/div>\n<\/div>\n<p>Of the 13 hardware wallet manufacturers Bitcoin.com News contacted for comment, Trezor, Bitbox, and Onekey confirmed that their sales jumped in August. Ledger declined to comment on its monthly sales, while publicly listed Bitkey\u2019s manufacturer, Block, is bound by its quarterly reports.<\/p>\n<p>While none of the companies disclosed the exact numbers, Bitbox was the most specific, saying that its credit-card sales jumped roughly tenfold compared with the baseline in the preceding weeks. This doesn\u2019t include sales made through other payment methods.<\/p>\n<p>\u201cWe have seen a surge in sales, mostly coming from North America, where presumably Coldcard had its largest presence,\u201d Bitbox CEO Douglas Bakkum told Bitcoin.com News.<\/p>\n<h2>An Encouraging Sign for Self-Custody<\/h2>\n<p>Meanwhile, Trezor said it also saw an increase in sales, notably in sales of its bitcoin-only products. While the company didn\u2019t specify the numbers, its Head of Security, Jan Kom\u00e1rek, pointed out that this spike is an encouraging sign for the whole Bitcoin industry.<\/p>\n<p>\u201cTo us, the more interesting point is what that suggests: it looks like people affected by the Coldcard situation went looking for another hardware wallet rather than giving up on self-custody,\u201d he said, adding that this is \u201cthe encouraging takeaway, that the response to a hard moment was to stay in control of their own keys, not to retreat from it.\u201d<\/p>\n<p>However, according to industry analysts, many hardware wallet users sent their funds to crypto exchanges or moved their capital to ETFs, abandoning self-custody. In either case, it is unclear how large this migration was or whether it was only a temporary measure before users returned to self-custody.<\/p>\n<p>Onekey, while also registering an increase in sales, noted that this might also have been affected by other factors, including individual product cycles. According to the company, the Coldcard crisis fueled much greater discussion about hardware wallet security questions that are usually invisible to end users, such as seed phrase generation.<\/p>\n<p>However, <a href=\"https:\/\/news.bitcoin.com\/featured\/the-coldcard-exploit-explained-who-lost-bitcoin-and-whos-at-risk\/\">the Coldcard firmware exploit<\/a> fueled similar discussions and actions not only among end users but also among hardware wallet manufacturers. First, the incident prompted the teams to review their current security models.<\/p>\n<h2>What Wallets Have Already Done<\/h2>\n<p>Trezor reviewed its own seed generation specifically against the failure mode that was exploited in the Coldcard case; BitBox took \u201canother detailed look\u201d at its own random number generator code, while Onekey said it conducted an additional end-to-end verification of the entropy and seed-generation paths across its hardware wallet lineup.<\/p>\n<p>As reported by Bitcoin.com News, separately and unrelated to Coldcard, Bitbox <a href=\"https:\/\/blog.bitbox.swiss\/en\/bitbox-08-2026-dixence-update\/\" target=\"_blank\" rel=\"noopener noreferrer\">disclosed and patched its own firmware<\/a> bugs this August. No exploitation has been reported. Meanwhile, in the same month, Trezor disclosed that <a href=\"https:\/\/news.bitcoin.com\/security\/trezor-shipping-provider-exposes-13689-crypto-customers-to-scams\/\">almost 14,000 of its customers were affected<\/a> by a data breach at one of Trezor\u2019s shipping providers.<\/p>\n<p>In either case, the main security battle still lies ahead as hardware wallets for bitcoin and other crypto assets adjust to the new reality prompted by AI.<\/p>\n<h2>Two Things to Focus on<\/h2>\n<p>\u201cAttackers are already working at machine speed, so we need to as well to stay ahead of them,\u201d Charles Guillemet, Ledger\u2019s CTO, said, adding that defence currently still moves slower than attackers. At least, according to him, the window between a patch shipping and it being weaponised is shrinking.<\/p>\n<p>The CTO emphasised that companies should now focus on two things: improving disclosure and user education.<\/p>\n<p>\u201cFirst, responsible disclosure needs to evolve with faster patching, shorter disclosure timelines, and migration strategies that assume capable, AI-assisted attackers are part of the security model rather than optional improvements,\u201d Guillemet told Bitcoin.com News.<\/p>\n<p>Also, according to him, helping people understand hardware wallets \u201cis going to be essential to keeping the industry safe.\u201d<\/p>\n<h2>Upgrade Even Your Home Appliances<\/h2>\n<p>On the same note, in their <a href=\"https:\/\/x.com\/BlockstreamJade\/status\/2092288442440855919\" target=\"_blank\" rel=\"noopener noreferrer\">\u201creflections on the Coldcard fallout,\u201d<\/a> the developers of the Blockstream Jade wallet urged hardware wallet users to keep their software up to date. Blockstream Jade just released a firmware update with a number of fixes. However, according to the team, besides hardware wallets, users should keep their applications, operating systems, devices, routers, and even home appliances up to date.<\/p>\n<p>\u201cMaintaining security is an ongoing process, and you as a user must also participate,\u201d they stressed, adding that the Coldcard bug was \u201can unfortunate case where users could not be made safe by upgrading\u201d their software and firmware.<\/p>\n<p>Meanwhile, Onekey added that hardware wallet security needs to be built around hardware-backed entropy and key storage, verifiable open-source software, independent security review, strong separation of security-critical components, and clear user-facing transaction verification.<\/p>\n<p>\u201cAs AI lowers the cost of analyzing software and automating attacks, the goal is to make sure that discovering one implementation weakness is not enough to compromise the entire security model,\u201d the wallet manufacturer said.<\/p>\n<h2>Short-, Medium- and Long-Term Security Plans<\/h2>\n<p>The companies themselves are already implementing short-, medium- and long-term security changes. For example, Trezor, \u201cin direct response to the Coldcard findings,\u201d is adding \u201cfurther sanity checks\u201d on the device\u2019s own internally generated entropy when verifying whether external entropy is genuinely used.<\/p>\n<p>\u201cBeyond that, our review has led us to strengthen our internal testing and tripwires around the insecure test generator, and to extend how we verify the call path of each individual entropy source,\u201d Kom\u00e1rek said, noting that the insecure generator exists only for internal testing.<\/p>\n<p>The company is also working through reports from independent security researchers and, in the medium term, is planning a new penetration test of core firmware features, carried out by \u201ca well-regarded external security agency.\u201d Security audit reports are planned to be public.<\/p>\n<p>\u201cLonger term, our focus is on staying ahead of AI-enabled attacks rather than reacting to them,\u201d the Head of Security said, as other wallet manufacturers have also stressed that they\u2019re already using AI to review their code, alongside bounty programs.<\/p>\n<p>\u201cOur Donjon research lab (white hat hacker lab) exists to try to break our products before anyone else can, and internally we make heavy use of LLMs to hunt for vulnerabilities in our own products,\u201d Ledger\u2019s Guillemet added.<\/p>\n<p>Onekey said it is now focused on strengthening reviews of security-critical code paths, firmware builds, entropy generation, and transaction-signing flows, while, in the medium term, its focus is going to be on transaction verification, referring to the Clear Signing solution, relevant for many major crypto assets outside bitcoin.<\/p>\n<h2>Common Responsibility and New Critical Bugs<\/h2>\n<p>Meanwhile, the security researchers at Bitkey\u2019s manufacturer, Block, were instrumental in helping the Bitcoin and hardware wallet industry <a href=\"https:\/\/news.bitcoin.com\/security\/how-bitcoin-hardware-wallets-supported-users-during-the-coldcard-crisis\/\">during the Coldcard crisis<\/a>, as they actively engaged with the community to share critical findings and coordinate response efforts.<\/p>\n<p>\u201cWe shared our findings transparently through both public X discussions and private channels because we believe that when security vulnerabilities affect the ecosystem, all manufacturers have a responsibility to act quickly,\u201d the company told Bitcoin.com News, adding that hardware wallets should retain control over key security models.<\/p>\n<p>While writing this article, on Aug. 26, reports about another <a href=\"https:\/\/x.com\/BitsagaRob\/status\/2092548411287355611\" target=\"_blank\" rel=\"noopener noreferrer\">\u201ccritical bug in a major hardware wallet vendor\u201d<\/a> started circulating. Rob Segers, a Bitcoin security consultant and founder of Bitsaga, who found the bug alongside \u201cseveral other high-severity\u201d bugs, said that the undisclosed vendor confirmed these bugs, \u201cbut a fix is already in an upcoming release.\u201d<\/p>\n<p>According to Seger, the critical bug was found in the \u201cofficial hardware firmware but does require malicious host software\u201d to steal the funds. This means the bug could be exploited if a user, for example, downloads a fake wallet. Marek \u201cSlush\u201d Palatinus, co-founder of Trezor, <a href=\"https:\/\/x.com\/slush\/status\/2092598161076285772\" target=\"_blank\" rel=\"noopener noreferrer\">confirmed that the reported bug is not about this wallet<\/a>. Meanwhile, Seger reported that he had found two more bugs, drawing criticism for spreading panic.<\/p>\n<p>Stay safe.<\/p>\n<\/p><\/div>\n<p><a href=\"https:\/\/news.bitcoin.com\/crypto-news\/trezor-onekey-bitbox-sales-spike-amid-coldcard-crisis-security-models-evolve\/\">Source link <\/a><br \/>\n<br \/><\/p>\n","protected":false},"excerpt":{"rendered":"<p>(Originally posted on : Bitcoin News ) Key Takeaways Hardware wallet sales surged as Bitcoiners sought alternatives rather than abandoning self-custody. Artificial intelligence (AI)-powered attacks are pushing hardware wallet makers toward faster patching, stronger disclosure and better user education. Users are encouraged to keep all their software up to date, even on home appliances, as [&hellip;]<\/p>\n","protected":false},"author":3947362405,"featured_media":77326,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"om_disable_all_campaigns":false,"_monsterinsights_skip_tracking":false,"_monsterinsights_sitenote_active":false,"_monsterinsights_sitenote_note":"","_monsterinsights_sitenote_category":0},"categories":[32],"tags":[],"_links":{"self":[{"href":"https:\/\/crowdfundjunction.com\/blog\/wp-json\/wp\/v2\/posts\/77325"}],"collection":[{"href":"https:\/\/crowdfundjunction.com\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/crowdfundjunction.com\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/crowdfundjunction.com\/blog\/wp-json\/wp\/v2\/users\/3947362405"}],"replies":[{"embeddable":true,"href":"https:\/\/crowdfundjunction.com\/blog\/wp-json\/wp\/v2\/comments?post=77325"}],"version-history":[{"count":0,"href":"https:\/\/crowdfundjunction.com\/blog\/wp-json\/wp\/v2\/posts\/77325\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/crowdfundjunction.com\/blog\/wp-json\/wp\/v2\/media\/77326"}],"wp:attachment":[{"href":"https:\/\/crowdfundjunction.com\/blog\/wp-json\/wp\/v2\/media?parent=77325"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/crowdfundjunction.com\/blog\/wp-json\/wp\/v2\/categories?post=77325"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/crowdfundjunction.com\/blog\/wp-json\/wp\/v2\/tags?post=77325"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}