CRYPTONEA 24
Cryptonea 24

Crypto wallet: what it is, where it came from, and how it actually works

Why a wallet contains not a single coin, how twelve words generate all your keys, how a randomness bug emptied wallets in 2013 and again in 2026, and what to check before you trust an app or a device.

Data as of 4 October 2026

Contents
  1. The problem: ownership without a bank
  2. Where the idea came from
  3. August 2013: when signatures gave the keys away
  4. How it works, from zero
  5. One real example: block 170
  6. The numbers that matter
  7. Bitcoin and Ethereum: same idea, different details
  8. Compared with the alternatives
  9. What it trades away
  10. How to choose a wallet
  11. What has gone wrong
  12. Common misconceptions
  13. The open questions
  14. The risks for the reader
  15. Where to go next
  16. Sources

A crypto wallet is an app or a device that keeps your keys safe. Through those keys you see your balance, send transactions and sign in to applications on a blockchain (a public, shared ledger of transactions kept by a network of computers) [1].

The name is misleading. Coins are never inside the wallet. According to Ethereum's documentation, what you actually hold is private keys, while the funds always stay recorded on the network's ledger [2]. The same source notes that wallet providers do not have custody of your funds [1].

That sounds like a detail, but it changes everything. If the coins are not in the wallet, you do not lose them when your phone breaks. You lose them when you lose the key, or when someone else gets hold of it. The problem to solve is a secret that nobody else may ever learn and that must never be lost.

This article explains where the idea came from, how a phrase of a few words becomes an address, what kinds of wallet exist and what each one trades away. It also covers what has gone wrong from 2013 to today and how to assess a wallet before you use it. The article is informational and is not investment advice.

The problem: ownership without a bank

At a bank, ownership is proven by the bank's records. If you forget your password, the bank identifies you and gives you access again. A network with no central operator has nobody to do that job. It needs a way to prove ownership with mathematics alone.

Bitcoin's answer is set out in the paper Satoshi Nakamoto published: "We define an electronic coin as a chain of digital signatures" [3]. Each owner passes the coin to the next by digitally signing two things: the fingerprint of the previous transaction and the public key of the next owner [3].

Three terms matter here. A private key is a secret number that only you should know. A public key is derived from the private key and can be seen by anyone. A digital signature is a mathematical result that only the private key can produce but anyone can check with the public key.

Nakamoto noted that signatures solve only part of the problem. Most of the benefit is lost if a trusted third party is still needed to stop the same coin from being spent twice, and that part is handled by the network [3]. Proof of ownership, however, always stays with the key.

That is why the book Mastering Ethereum calls it a misconception that wallets contain coins. Strictly speaking, a wallet holds only keys and works more like a keychain [4]. The same text describes the hard side: if you lose your data before making a backup, you lose access to your funds [4].

Where the idea came from

Public key cryptography predates Bitcoin by three decades. In November 1976, Whitfield Diffie and Martin Hellman published "New Directions in Cryptography" in IEEE Transactions on Information Theory (volume IT-22, issue 6) [5]. Their proposal was a pair of keys: one that can be published and one that stays secret.

The two researchers were named recipients of the 2015 ACM A.M. Turing Award, for the paper that introduced public key cryptography [6]. Ron Rivest, Adi Shamir and Leonard Adleman built the first practical implementation of public key encryption, and Rivest says the Diffie and Hellman paper is what stimulated their work [6].

Bitcoin took this idea and turned it into a mechanism of ownership. Nakamoto's paper was published on 31 October 2008 [3].

Early wallets had a practical problem. The Bitcoin reference software generated every key at random. To avoid needing a new backup after every transaction, it kept a pool of 100 keys in reserve [7].

The fix was deterministic wallets (wallets that derive all their keys from a single starting value). As the relevant specification notes, they do not need backups nearly as often [7]. On 11 February 2012, Pieter Wuille created BIP-32, the proposal for "hierarchical deterministic" wallets, in which many chains of keys are derived from one shared root [7].

The next step was about people rather than machines. BIP-39 was assigned on 10 September 2013, written by Marek Palatinus, Pavol Rusnák, Aaron Voisine and Sean Bowe [8]. Their proposal turned the starting value into a series of words that can be written down on paper.

Two of those authors, Palatinus and Rusnák, founded Trezor. The company states that the Trezor Model One launched on 29 July 2014 and presents it as the first hardware wallet (a device dedicated to keeping keys) [9]. According to the company, the first prototypes were add-on boards with a screen, two buttons and a USB port, attached to a Raspberry Pi [9]. The first device sold for 1 BTC, with a metal version at 3 BTC [10].

August 2013: when signatures gave the keys away

On Sunday 11 August 2013, the developer Mike Hearn sent a message to the Bitcoin developers' mailing list. He wrote that Android's implementation of the SecureRandom class, the mechanism that produced "secure" random numbers, had severe flaws [11]. As a result, every private key generated on Android phones and tablets was weak [11].

Bitcoin's digital signatures contain a value called R. Hearn reported that in some signatures this value was repeated. The repetition allowed anyone to work out the private key and steal the money [11].

The same day, Bitcoin.org published an alert. It said that a component of Android had critical weaknesses that made every wallet created on Android up to that point vulnerable to theft [12]. Its incomplete list included Bitcoin Wallet, blockchain.info wallet, BitcoinSpinner and Mycelium [12]. The alert added a sentence worth remembering: "Apps where you don't control the private keys at all are not affected" [12].

The fix was not a simple patch. The new version of Bitcoin Wallet bypassed SecureRandom and read random numbers directly from the system's /dev/urandom [11]. The app also had to carry out key rotation: create new keys and new addresses, mark the old ones as insecure and ask the user for a fresh backup [12].

On the forums, users had already noticed that more than 55 BTC had been stolen, a few hours after a wallet signed a transaction with the faulty generator [13]. The warning signs were older. Repeated R values had been spotted as early as January by Nils Schneider, who had not linked them to SecureRandom [14]. Hearn later clarified that Schneider's case came from a prototype hardware wallet, not from an Android phone [15].

That is what the documents show. What follows is our reading.

No coin ever "left" a phone. The coins sat on the blockchain the whole time, and what leaked was the keys, through the very signatures the users had published. That is why the fix could not be only an app update. The money had to move to brand-new keys, because a key that has been exposed cannot be "repaired".

The sentence about apps that do not control keys also shows the price. Those who left their keys with a third party escaped this risk, but took on a different one, as we will see. The same class of failure, poor randomness when the key is created, returned in 2026 in hardware wallets, with far larger losses.

How it works, from zero

Picture the blockchain as a huge wall of glass safe-deposit boxes, visible to everyone. Anyone can see how much each box holds, and anyone can drop money through its slot. To open a box, though, you need a signature that can only be produced with one specific key. The wallet is your keyring and your pen: it contains no boxes, it contains keys, and it knows how to sign.

The chain has three links. First comes the private key, which on Ethereum is made up of 64 hexadecimal characters [2]. From it the public key is derived, using the ECDSA digital signature algorithm [2]. The path runs one way: the public key comes from the private key, but the private key cannot be found from the public one [2].

Finally, the public key passes through a hash (a function that turns any data into a short string of fixed length). On Ethereum, the address (the "box number" you give out to get paid) is the last 20 bytes of the Keccak-256 hash of the public key, with the prefix 0x [2].

When you send money, the wallet builds the transaction and signs it with the private key. The network's nodes (computers that keep a copy of the blockchain and check transactions) verify the signature with the public key. As Nakamoto wrote, the payee can verify the signatures and so confirm the whole chain of ownership [3].

The recovery phrase: randomness in human form

A recovery phrase is 12 to 24 words from which the wallet can regenerate all your keys. The process is defined in BIP-39 and has four steps [8].

First, the device generates entropy (pure randomness) of 128 to 256 bits. Next, it computes the SHA-256 hash of that value and keeps its first bits as a checksum (a check value that lets a typing error be caught). It then splits the whole into groups of 11 bits. Each group stands for a number from 0 to 2,047, meaning one word from a list of 2,048 words [8].

The phrase produces the seed (the binary value from which the keys are derived). The conversion uses the PBKDF2 function, which applies the HMAC-SHA512 algorithm 2,048 times and returns a 512-bit result [8]. The user can also add a passphrase (an extra password phrase). Every passphrase gives a valid but different wallet [8].

The specification makes clear that the method is not meant for phrases the user makes up, the so-called "brainwallets" [8]. The phrase must come from machine randomness, not human imagination.

A tree of keys

From the seed, BIP-32 derives not one key but many, organised in branches that grow from one root [7]. One backup therefore covers every address you will ever use. The same mathematical structure allows public keys to be calculated without revealing the private keys [7]. "Watch-only" wallets rely on this: they can see balances but cannot spend.

One phrase, one seed, endless keys: each branch of the tree corresponds to a different network or account, and all of them are recovered from the same words.
One phrase, one seed, endless keys: each branch of the tree corresponds to a different network or account, and all of them are recovered from the same words.

From phrase to address, with real data

To show that the process is deterministic, we ran it on a phrase that is published as a test phrase and must therefore never be used for money. The phrase is the word "abandon" eleven times followed by the word "about". We ran Python's mnemonic and bip_utils libraries on 4 October 2026 (our calculation).

The checksum is valid, and the entropy behind the phrase is 128 zero bits. That zero entropy is exactly why the phrase is unsafe. The resulting seed begins 5eb00bbddcf06908 (our calculation).

On Bitcoin's path m/84'/0'/0'/0/0, the public key is 0330d54fd0dd420a6e5f8d3624f5f3482cae350f79d5f0753bf5beef9c2d91af3c and the address is bc1qcr8te4kr609gcawutmrza0j4xv80jy8z306fyu (our calculation). The result matches the official test vector of the BIP-84 specification exactly [16].

On Ethereum's path m/44'/60'/0'/0/0, the same phrase gives the address 0x9858EfFD232B4033E47d90003D41EC34EcaEda94 (our calculation).

Anyone, on any computer, will get the same results. That is what recovery means: no copy of your wallet is "stored" anywhere, because the wallet is recalculated from the words every time.

Where the analogy breaks down

The safe-deposit analogy breaks at one critical point. A key here is not an object but information. It can be copied without you noticing, and the copy is as powerful as the original.

There is no locksmith to change the lock. The only way to "change the lock" is to move the money to new keys, as Android users were forced to do in 2013 [12].

One real example: block 170

On 12 January 2009, in Bitcoin's block 170, the first person-to-person transaction was recorded. Satoshi Nakamoto sent 10 BTC to Hal Finney, a cryptographer and the first person other than Nakamoto to run the Bitcoin software [17]. A block is a batch of transactions added to the blockchain.

The transaction is 275 bytes in size. Its input is 50 BTC, its output is also 50 BTC, and the transaction fee is zero [18].

We followed the transaction step by step from its raw data, as published in hexadecimal form [19]. First, Nakamoto's wallet picked an earlier output worth 50 BTC that belonged to him. It then created two new outputs. Decoding the amounts from the data, we find 10.00000000 BTC for Finney and 40.00000000 BTC as "change" back to Nakamoto himself (our calculation).

Next, the wallet signed the transaction with the private key. The signature is visible in the input data as a string beginning 3044 (our calculation). Finally, the nodes verified the signature.

The transaction's identifier is a hash too. We ran the 275 bytes through the SHA-256 function twice and reversed the byte order. The result was exactly f4184fc596403b9d638783cf57adfe4c75c605f6356fbc91338530e9831e9e16, the identifier that blockchain explorers display (our calculation) [20].

Seventeen years later, the transaction is still public and can be verified by anyone, exactly as it was signed.

The numbers that matter

The length of the phrase depends on the entropy. 128 bits give 12 words and 256 bits give 24 words [8].

The possible combinations are astronomical. Twelve words from a list of 2,048 give 2,048 to the power of 12, that is 2^132 or about 5.4 × 10^39 combinations. Of those, about 3.4 × 10^38 (2^128) have a valid checksum (our calculation). A 256-bit number can take about 1.16 × 10^77 values (our calculation).

Security, however, is not decided by how large the space of choices is. It is decided by whether the choice within it was genuinely random.

The checksum is small. The specification itself states that it misses one in 256 random errors [8]. That applies to a 24-word phrase, whose checksum has 8 bits. In a 12-word phrase the checksum has 4 bits, so a random wrong word slips through one time in 16 (our calculation).

Converting the phrase to a seed uses 2,048 iterations of PBKDF2 [8]. An Ethereum address is 20 bytes, written as 40 hexadecimal characters plus 0x, so 42 characters in total [2].

None of these numbers is a rule enforced by the network. They are specifications that wallet makers choose to follow, which is why they can evolve. The authors of BIP-39 themselves proposed SLIP-0039 as its successor [8].

Bitcoin and Ethereum: same idea, different details

Both networks use key pairs and the same recovery phrase. They differ in how the public key becomes an address and in the path through the key tree.

Bitcoin Ethereum
Curve and signature The secp256k1 elliptic curve, on which BIP-32 is defined [7] ECDSA [2]
From public key to address Encoding per BIP-84 for SegWit addresses (a newer address format) [16] Last 20 bytes of the Keccak-256 hash [2]
Address format Starts with bc1q [16] 0x and 40 hexadecimal characters [2]
Path in our example m/84'/0'/0'/0/0 [16] m/44'/60'/0'/0/0 (our calculation)

The practical consequence is that the same phrase can produce different addresses in different wallets if they use a different path. The money is not lost in that case, but the wallet may not "see" it until the right path is set.

Compared with the alternatives

The basic distinction is who holds the keys. In a custodial wallet (a wallet run by a custodian, such as an account at an exchange), the company holds the keys and you hold a claim against it.

The best-known example of what that means is FTX. On 8 November 2022 it halted withdrawals, and on 11 November 2022 it filed for bankruptcy together with Alameda Research and about 130 affiliated companies [21][22]. Its terms of service stated that title to assets remained with the customer. Even so, according to reports, customer funds had been lent to Alameda [21].

In non-custodial wallets you hold the keys yourself. They may sit in an app on a phone or computer, or in a device that keeps the keys offline [1].

A multisig wallet (a multiple-signature wallet) requires more than one signature for every transfer. A smart contract wallet (a wallet that is a program on the blockchain) sets its own rules for checks and recovery. On Ethereum, the core contract of the ERC-4337 standard went live on 1 March 2023. Ethereum's documentation states that more than 26 million such wallets have been created through it [23].

Type Who holds the keys What you gain What you take on
Custodial (exchange) The company Account recovery, convenience The company's risk (FTX, 2022) [21]
App (hot wallet) You, on an internet-connected device Convenience The risk of malware and of the app itself
Hardware wallet You, on a dedicated device Keys stay offline [1] Cost of the device, responsibility for the phrase
Multisig Several key holders No single key is enough Complexity, reliance on the signing environment
Smart contract wallet Rules in a program [23] Programmable recovery and limits Reliance on the contract's code

No row of the table is the "right" one. Each choice moves risk from one place to another, and the incidents we record below show where things went wrong each time.

What it trades away

Self-custody means full control and full responsibility together. There is no customer service desk that can restore a key, and losing data without a backup means losing access [4].

How much money has been lost this way is not known precisely, because nobody can tell a lost key from an owner who simply is not selling. In June 2020, Chainalysis estimated that about 3.7 million BTC had not moved for five years or more. Glassnode estimated that about 3 million BTC are lost for good [24]. Both figures are model estimates, not measurements.

The second trade-off concerns convenience. The more isolated a key is, the more cumbersome it becomes to use. The easier it is to use, the more places there are from which it can leak.

How to choose a wallet

The criteria, one by one

A secure element (a chip designed to resist physical attacks) matters when someone gets the device into their hands. In January 2020, Kraken Security Labs showed that it could extract the encrypted seed from the Trezor One and Trezor Model T with about 15 minutes of physical access, by opening the case and using specialised equipment [25]. Kraken's chief security officer traced the problem to the devices' microcontroller [26].

Open source code in the firmware (the software that runs inside the device) and in the app lets independent researchers check what the device does. Manufacturers differ on this. Ledger, unlike some competitors, does not publish all of its code [27]. The Coldcard firmware code is public on GitHub [28]. Trezor describes its design as open source [29]. Open source does not guarantee the absence of bugs, as we will see, but it makes checking possible.

Supply-chain protection decides whether the device that reaches you is the one that left the factory. Trezor mentions security seals on the packaging and on the device, and recommends buying only from the official store or from authorised resellers [29].

Backup options decide what happens if the device is lost. The Trezor Safe 3, for example, supports 12-, 20- and 24-word phrases and a backup system split into several parts [29]. In 2023 Ledger proposed a different approach, a recovery service run through third parties, which provoked a strong reaction [27].

Supported coins and connectivity concern what you will actually do with the device. The maker of the Trezor Safe 3 cites support for thousands of coins and tokens (digital units issued on top of a blockchain) and a USB-C connection. An iPhone user should note that on iOS the device does not support sending or initial setup [29].

The screen may be the most underrated criterion. If you confirm the transaction on the device's own screen, you see what you are signing independently of the computer [29]. Its importance became clear in 2025, when Bybit's signers saw something on a tampered interface that differed from what they actually signed [30].

We do not list prices, because they change by country and by promotion, and the sources we checked did not agree. Each company's track record is set out in detail in the section on what has gone wrong.

An example of reading a specification sheet

The table shows how an official product page reads against the criteria; it is not a selection or a recommendation. It includes only details we confirmed on the manufacturer's official page as of 4 October 2026. For other devices, such as Ledger's range, the sources we found disagreed with each other on models, prices and certification levels, so we do not list them here.

Criterion Trezor Safe 3, according to the manufacturer [29]
Secure element Yes, EAL6+ certified chip
Open source The manufacturer describes an open-source design
Packaging protection Security seals on packaging and device
Backup 12, 20 or 24 words, and a backup split into several parts
Connectivity USB-C, no sending or setup on iOS
Screen 0.96-inch monochrome OLED, confirmation on the device
Support Thousands of coins and tokens

Setting one up safely

Buy only from the official store or an authorised reseller, never second-hand. When the device arrives, check that the seals are intact before connecting it [29].

Next, let the device generate the recovery phrase itself. Do not use a phrase someone gave you, or a phrase you found printed in the box. Write the phrase on paper or metal and keep it offline.

Do not photograph it, and never type it into a computer or phone. No legitimate manufacturer will ask you for it. In 2024, people who had obtained contact details of Trezor customers sent messages asking for exactly that [31].

In 2025, users who logged in to the tampered version of a browser extension lost funds [32]. In 2022, a mobile app was sending users' phrases, in readable form, to an error-logging server [33].

Before moving significant amounts, do a test recovery with the phrase you wrote down, to make sure you recorded it correctly. If you use a passphrase, remember that without it the phrase alone is not enough.

Update the firmware only from official sources. Bear in mind, though, that an update does not fix a key that was created on faulty firmware. After the 2026 incident, Coldcard's maker advised creating new keys and moving the money [28].

What it protects against and what it does not

A hardware wallet protects against the private key ending up on a computer that may be infected. It does not protect against the following.

It does not protect you when you hand your phrase to someone posing as support [31]. It does not protect you when you sign something you cannot read or that is shown to you in tampered form [30]. It does not protect you when software you trust with your keys has been tampered with [32]. Older chips may not withstand an attack by someone with physical access [25].

Nor does it protect you when the key itself was generated with insufficient randomness [28]. It does not protect against physical coercion. And it does not protect against losing the phrase, which is final.

The companies

The table covers the companies whose products or services are mentioned in this article, as described by our sources. We do not give funding details, because we did not confirm them from primary sources.

Company Related product or service What the sources state
Trezor Company s.r.o. Trezor hardware wallet Part of SatoshiLabs Group [29]
Ledger SAS Ledger hardware wallet, Ledger Recover, Connect Kit Legal form as given in coverage of the 2026 leak [34]
Coinkite Coldcard hardware wallet Canadian manufacturer [35]
Trust Wallet App and browser extension Owned by Binance [36]
Safe{Wallet} Multisig platform The Safe Ecosystem Foundation confirmed the findings on the 2025 attack [30]

What has gone wrong

August 2013: Android's randomness

The incident is described in detail above. A bug in Android's random number generator made every key created on the platform weak [11][12]. Users reported the theft of more than 55 BTC [13]. It was dealt with through new app versions and key rotation [12].

January 2020: a physical attack on the Trezor One and Model T

Kraken Security Labs extracted the encrypted seed from both devices with about 15 minutes of physical access and by opening the case [25]. It had given Trezor full details on 30 October 2019 [25]. According to Kraken's chief security officer, the problem lay in the microcontroller, which is why the vulnerability persisted even though Trezor knew of it. Trezor advised users for whom physical access is a risk to use a passphrase [26].

2020: Ledger's customer data

Ledger announced that an attacker had gained access to its e-commerce and marketing database through a third party's API key [37]. When the full database appeared publicly in December 2020, it became clear that about 272,000 records with name, address and phone number had been stolen, on top of more than 1 million email addresses [37].

On 23 December 2020, Shopify informed Ledger that members of its support team had illegally exported customer transaction records in April and June 2020 [37]. The keys were not affected. Home addresses, however, showed who probably held crypto and where they lived.

August 2022: Slope on Solana

About 8,000 wallets were drained. The Solana Foundation said the affected addresses had at some point been created, imported or used in Slope's mobile wallet app [38]. The security firm OtterSec found that the app was sending recovery phrases to a Sentry server, where they were stored in readable form [33]. Losses were put at about 4 million dollars [39]. SlowMist noted that it could not be proven with certainty that the cause lay with Slope [40].

November 2022: FTX

The exchange halted withdrawals on 8 November and filed for bankruptcy on 11 November 2022 [21][22]. It was not an attack on customers' keys, because customers did not hold keys. It was the loss of access to money that someone else was keeping.

May 2023: the Ledger Recover controversy

On 16 May 2023, Ledger announced a subscription service. The service would split an encrypted copy of the phrase into three pieces, held by Ledger, Coincover and EscrowTech [42]. One of Ledger's co-founders explained that the device sends the encrypted pieces to different companies only if the user subscribes to the service [41].

Criticism focused on the fact that the service's code was not open and therefore could not be checked [27]. On 23 May, chief executive Pascal Gauthier announced that the service would not launch before its code was published [27].

December 2023: the Ledger Connect Kit

On 14 December 2023, at 2:37 a.m. Pacific time, malicious versions 1.1.5, 1.1.6 and 1.1.7 of the @ledgerhq/connect-kit library were published. The library is used by many applications to connect to wallets. The fixed version 1.1.8 was published at 5:18 a.m. [43].

According to Ledger, a former employee had fallen for phishing (fraud using fake messages), and the attackers gained access to their NPM account [44]. Ledger's devices themselves were not believed to be affected [44].

Losses are reported differently. One source puts them at about 484,000 dollars [45], while SlowMist speaks of at least 600,000 dollars [46].

January 2024: Trezor's support portal

On 17 January 2024, unknown parties gained access to the support ticketing platform that a third-party provider runs for Trezor. Names or nicknames and email addresses of up to 66,000 contacts who had reached support since December 2021 were exposed [31].

Trezor confirmed 41 cases in which the attackers asked users for their recovery phrase [31]. The company said it alerted every user who received such a message within an hour of the incident [47].

February 2025: Bybit and Safe{Wallet}

The attackers compromised the computer of a developer at the multisig platform Safe{Wallet}. Two days before the attack, they modified the JavaScript code hosted in the platform's AWS S3 storage, targeting Bybit's Ethereum multisig cold wallet [30].

On 21 February 2025, Bybit's signers approved a transfer that looked normal, but the interface had been tampered with [30]. The FBI attributed the theft, about 1.5 billion dollars, to North Korea, in activity it calls "TraderTraitor" [48]. The keys were not stolen. They were used by their rightful holders to sign something they could not see.

December 2025: the Trust Wallet extension

Version 2.68 of the Trust Wallet extension for Chrome was published on 24 December 2025, after passing the Chrome Web Store's review [32]. SlowMist judged that the malicious code had been added to the app's own codebase, not through an outside library [32].

The company identified 2,596 affected addresses [32] and confirmed losses of about 7 million dollars, committing to refund all affected users [49]. Trust Wallet is owned by Binance [36]. Completion of the refund process has not been reported in the sources we examined.

January 2026: Ledger and Global-e

Unknown parties copied customer data from Global-e, an e-commerce partner of Ledger. The data included names, postal addresses, email addresses, phone numbers and order details, but not payment details [34]. The reports we examined do not give the number of customers affected.

July 2026: Coldcard's entropy

On 30 July 2026, according to reports, about 594 BTC, worth about 38 million dollars, moved within roughly 25 minutes from about 500 addresses that had been dormant for years. The same day, Coinkite issued an advisory for the Coldcard Mk3 running firmware versions 4.0.1 through 5.0.3. It stated that, according to its early analysis, the Mk4, Q and Mk5 were not affected. At that point the company had not confirmed whether the movement of coins was linked to the advisory [50].

The next day, the company released fixed firmware and updated its advisory, telling owners of the Mk3, Mk4, Mk5 and Q to update their devices [51]. The security advisory in the firmware repository now states that versions from 2021 to July 2026 produced poor entropy. It advises replacing every secret created in that period and moving the money. It treats keys as trustworthy only from versions 5.6.0 (Mk4, Mk5), 1.5.0Q (Q), 4.2.0 (Mk3) and 6.6.0 (Edge) onwards [28].

The actual strength of the keys is reported differently. Coinkite's preliminary estimate was about 72 bits, against a target of 128 bits [52]. TRM Labs reports that on some devices the strength fell to as little as 40 bits, a level at which, it notes, keys could be found by trial without physical access to the device [53]. 40 bits correspond to about 1.1 × 10^12 possible values (our calculation).

Losses grew as the count went on. TRM Labs puts them at about 1,816 BTC, worth about 116 million dollars, from more than 5,200 addresses [53]. Coinkite's chief executive, Rodolfo Novak, apologised publicly and said the company accepts full responsibility [35]. He also said the attack was likely helped by artificial intelligence [51]. No outcome has been reported on compensation or legal claims as of 4 October 2026.

Of the twelve incidents, only two concerned how keys were created (2013 and 2026). The rest concerned customer data, third-party software, physical access, the signing screen, a custodian's collapse and the design of a recovery service.
Of the twelve incidents, only two concerned how keys were created (2013 and 2026). The rest concerned customer data, third-party software, physical access, the signing screen, a custodian's collapse and the design of a recovery service.

Common misconceptions

"My coins are in my wallet." They are not. They sit on the network's ledger, and the wallet holds the keys [2][4].

"If my phone or device breaks, I have lost the money." Not if you have the recovery phrase. All the keys are recalculated from it in any compatible wallet [8][7]. You lose the money only if you lose the phrase as well.

"The wallet company can restore my access." With a non-custodial wallet it cannot, because it does not have the keys. This became clear in 2013, when apps that did not control keys were unaffected by the bug [12]. The exceptions are optional recovery services, like the one Ledger proposed, which change who you have to trust [27].

"A hardware wallet cannot be hacked." The incidents show otherwise. There have been physical attacks on older chips [25], keys generated with insufficient randomness [28] and signatures given on tampered interfaces [30].

"My exchange account is my wallet." It is a claim against a company. FTX showed what that means when the company cannot pay [21].

"The address is the public key." On Ethereum, the address is part of the hash of the public key, not the key itself [2].

"A fifth of all bitcoin has been lost." That figure refers to bitcoin that has not moved for five years, according to a 2020 estimate. Another estimate gives a lower number [24].

The open questions

Who you trust when you cannot see the code. The 2023 Ledger Recover controversy showed that a copy of the phrase can, at the user's choice, leave the device in encrypted form [41]. Critics, as CoinDesk reported, argued that without open code nobody can check the security of that mechanism [27]. Pascal Gauthier responded by committing to publish the code first [27]. The question goes beyond Ledger: how much trust does a device demand when it promises that no trust is needed?

Recovery phrases or rules in code. Ethereum's documentation argues that smart contract wallets improve both user experience and security by allowing recovery and control rules at the account level [23]. Our view at CRYPTONEA 24 is that this shift does not remove risk but relocates it: from a person who loses a piece of paper to code that may contain a bug.

Artificial intelligence in attackers' hands. Coinkite's Rodolfo Novak judged that the 2026 attack was likely helped by artificial intelligence, which can spot hidden bugs faster than experts [51][35]. If so, bugs that sat unseen for years in open-source firmware may be found first by people who will not report them.

What a signature is worth if it cannot be read. In the Bybit case, the investigations by Sygnia and Verichains, as shared by the exchange's chief executive, showed that the malicious code targeted the signing environment itself [30]. The cryptography worked flawlessly. What failed was the gap between what the human sees and what the machine signs, and that problem remains open.

The risks for the reader

The first risk is the simplest: losing the recovery phrase without a backup means losing access, and nobody can restore it [4]. The second is the reverse: if someone else gets the phrase, they have the same power you do. That holds whether they got it through phishing, through software that leaks it, or from a photo on your phone [31][32][33].

Some risks are outside your control. Your key may have been generated with faulty randomness, as happened in 2013 and 2026 [12][28]. An interface may show you something different from what you are signing [30]. A custodian may halt withdrawals [21]. A data leak from a store may link your name and address to holding crypto [37][34].

The rules that govern crypto and the services around it can also change. Finally, a signed and confirmed transfer is not cancelled: if you send to the wrong address or sign something you did not understand, the movement usually cannot be reversed.

The five points where a key is exposed: its creation, the writing down of the phrase, storage, signing, and the person who decides what to sign.
The five points where a key is exposed: its creation, the writing down of the phrase, storage, signing, and the person who decides what to sign.

Where to go next

If you want to see how the network uses these signatures to agree on a shared ledger, continue with the Crypto 101 articles on Bitcoin and on proof of work. For devices, continue with the hardware wallets section, with its setup guides and our detailed reviews by manufacturer.

Sources

  1. P: Ethereum.org, Ethereum wallets, ethereum.org/wallets, undated (project source)
  2. P: Ethereum.org, Ethereum accounts, ethereum.org/developers/docs/accounts, undated (project source)
  3. P: Satoshi Nakamoto, Bitcoin: A Peer-to-Peer Electronic Cash System, bitcoin.org/bitcoin.pdf, October 2008
  4. S: Andreas M. Antonopoulos and Gavin Wood, Mastering Ethereum, ch. 5: Wallets, cypherpunks-core.github.io/ethereumbook, 2018
  5. P: Whitfield Diffie and Martin E. Hellman, New Directions in Cryptography, ee.stanford.edu/~hellman/publications/24.pdf, November 1976
  6. S: Communications of the ACM, Diffie and Hellman, 2015 Turing Award, cacm.acm.org, 2016
  7. P: Pieter Wuille, BIP-32: Hierarchical Deterministic Wallets, bips.dev/32, February 2012
  8. P: Marek Palatinus, Pavol Rusnák, Aaron Voisine, Sean Bowe, BIP-39: Mnemonic code for generating deterministic keys, bips.dev/39, September 2013
  9. P: Trezor, A decade of pioneering: 10 years since Trezor's first hardware wallet, trezor.io/blog, July 2024 (manufacturer source)
  10. S: Forbes, Bitcoin Hardware Wallets Just Turned 10 Years Old, forbes.com, August 2024
  11. P: Mike Hearn, Android key rotation (bitcoin-development list), lists.w3.org/Archives/Public/public-webpayments/2013Aug/0031, August 2013
  12. P: Bitcoin.org, Android Security Vulnerability, bitcoin.org/en/alert/2013-08-11-android, August 2013
  13. S: The Hacker News, Warning: Android Bitcoin wallet apps vulnerable to theft, thehackernews.com, August 2013
  14. S: The Register, Android bug batters Bitcoin wallets, theregister.com, August 2013
  15. S: TechNewsWorld, Android Flaw Could Empty Bitcoin Wallets, technewsworld.com, August 2013
  16. P: Pavol Rusnák, BIP-84: Derivation scheme for P2WPKH based accounts, github.com/bitcoin/bips, December 2017
  17. S: Spark, Bitcoin Timechain Milestones, spark.money, undated
  18. S: BTCnu, First ever bitcoin transaction, btcnu.nl, 2020
  19. S: learnmeabitcoin, TXID, learnmeabitcoin.com, 2026
  20. P: Blockstream Explorer, Transaction f4184fc5…9e16, blockstream.info, January 2009
  21. S: Steptoe, FTX: An Explainer on What Happened and What's Next, steptoe.com, November 2022
  22. P: US House Committee on Oversight (minority), Letter regarding FTX, oversightdemocrats.house.gov, November 2022
  23. P: Ethereum.org, Account abstraction, ethereum.org/roadmap/account-abstraction, undated (project source)
  24. S: Decrypt, Lost Bitcoin: 3.7 million Bitcoin are probably gone forever, decrypt.co, 2020
  25. S: Decrypt, Kraken hacked Trezor's Bitcoin wallets in just 15 minutes, decrypt.co, January 2020
  26. S: The Block, Kraken Security Labs: Hackers can exploit Trezor hardware wallets, theblock.co, January 2020
  27. S: CoinDesk, Crypto Wallet Provider Ledger Delays Key-Recovery Service After Uproar, coindesk.com, May 2023
  28. P: Coinkite, COLDCARD firmware: Security Advisory, github.com/coldcard/firmware, October 2026 (manufacturer source)
  29. P: Trezor, Trezor Safe 3, trezor.io/trezor-safe-3, October 2026 (manufacturer source)
  30. S: BleepingComputer, Lazarus hacked Bybit via breached Safe{Wallet} developer machine, bleepingcomputer.com, February 2025
  31. S: BleepingComputer, Trezor support site breach exposes personal data of 66,000 customers, bleepingcomputer.com, January 2024
  32. S: The Hacker News, Trust Wallet Chrome Extension Breach Caused $7 Million Crypto Loss, thehackernews.com, December 2025
  33. S: The Block, Slope wallet provider saved user seed phrases in plain text, theblock.co, August 2022
  34. S: SiliconANGLE, Ledger confirms leak of customer data from third-party Global-e hack, siliconangle.com, January 2026
  35. S: WeirFoulds LLP and Edmonds Marshall McMahon, The Coldcard Exploit: Why Victims May Have Two Routes to Recovery, weirfoulds.com, August 2026
  36. S: CoinDesk, Users of Binance-owned Trust Wallet lose $7 million to hacked Chrome extension, coindesk.com, December 2025
  37. P: Ledger, Update: Efforts to Protect Your Data and Prosecute the Scammers, ledger.com/blog, December 2020 (manufacturer source)
  38. S: The Register, Solana, Phantom blame Slope after millions stolen from 8,000 wallets, theregister.com, August 2022
  39. S: TechCentral.ie, Auditors blame massive $4m cryptocurrency heist on leaky logging technology, techcentral.ie, August 2022
  40. S: SlowMist, Analysis of a large-scale attack on Solana, part 2, slowmist.medium.com, August 2022
  41. S: The Block, Ledger defends crypto wallet recovery tool, theblock.co, May 2023
  42. S: Ryder, Every Ledger Hack Since 2020 and What Each Changed, ryder.id, 2026
  43. S: Blockaid, Attack Report: Ledger Connect Kit, blockaid.io, December 2023
  44. S: TechCrunch, Supply chain attack targeting Ledger crypto wallet leaves users hacked, techcrunch.com, December 2023
  45. S: The Cyber Express, Ledger Cyberattack Leads To Loss Of USD 484,000, thecyberexpress.com, December 2023
  46. S: SlowMist, Supply Chain Attack on Ledger Connect Kit, slowmist.medium.com, December 2023
  47. S: No Bullshit Bitcoin, Trezor Warns of Phishing Campaign Following Potential Support Contact Leak, nobsbitcoin.com, January 2024
  48. S: Security Affairs, FBI: North Korea-linked TraderTraitor is responsible for $1.5 Billion Bybit hack, securityaffairs.com, February 2025
  49. P: Trust Wallet, Update on the Browser Extension v2.68 incident, x.com/TrustWallet, December 2025 (manufacturer source)
  50. S: Bitcoin.com News, Coinkite Warns Coldcard Mk3 Owners After Reports of $38M Bitcoin Loss, news.bitcoin.com, July 2026
  51. S: Bitcoin Magazine, Coinkite Releases Fixed Firmware After Coldcard Bug; AI Likely Involved, bitcoinmagazine.com, July 2026
  52. S: BitcoinWell, COLDCARD Vulnerability: What Owners Need to Know, bitcoinwell.com, July 2026
  53. S: TRM Labs, The Largest Hardware Wallet Exploit of 2026, trmlabs.com, August 2026

This article is educational and for general information. The facts in crypto move quickly, so verify them before you act on anything here. This is not financial advice.

This article is educational and for general information. The facts in crypto move quickly, so verify them before you act on anything here. This is not financial advice.