Critical warning to cryptocurrency holders

Critical warning to cryptocurrency holders

18.08.2026 13:10

Ledger CEO Pascal Gauthier said the crypto industry should stop trying to solve security by placing more responsibility on the user. According to Gauthier, there is no such thing as "perfect security," and hardware wallet manufacturers need to design systems that remain secure even when people make mistakes.

Gauthier stated that the industry has long treated security as a matter dependent on user attention. According to the CEO, this approach is flawed because no one can behave perfectly enough to foresee every form of technical malfunction. Gauthier argued that manufacturers should develop designs that protect assets even when users make a misstep.

The Ledger executive also argued that self-custody would remain limited as long as ordinary users are expected to understand every form of technical malfunction. The CEO emphasized that users should not blindly trust manufacturers' security claims. Gauthier said, "No design, including ours, should be accepted solely on the word of its manufacturer." Gauthier described security as a process requiring continuous testing and improvement.

COLDCARD LOSS REACHES 1596 BTC

Gauthier's remarks came after two incidents that successively shook the hardware wallet ecosystem. In a warning published on July 30 and updated on August 14, Coldcard manufacturer Coinkite disclosed a randomness flaw in recovery phrases generated with specific firmware of the Mk2, Mk3, Mk4, Mk5, and Q models. The company stated that funds protected by affected phrases could be at risk.

According to Galaxy Research's initial account dated July 31, the loss exceeded 1000 BTC. On August 4, the organization reported that 1596 BTC had been stolen in three verified waves of attacks linked to approximately 7,300 addresses and 14 smaller incidents. It noted that if a fourth, as-yet-unverified wave were included, the total could rise to 2055 BTC. According to Gauthier, in such a situation, user caution is not enough, because discipline cannot replace a flawed design.

Following the Coldcard incident, Trezor also announced a data breach at its logistics provider ShipMonk on August 13. The breach compromised the personal information of 13,689 customers in seven countries. Of these, the names, emails, phone numbers, and delivery addresses of 11,742 were obtained. The names, cities, and emails of the remaining 1,947 customers were affected. Trezor stated that its own systems and devices were not breached.

The Coldcard and Trezor incidents have reopened the debate on product security and the protection of user data in hardware wallets.

In order to provide you with a better service, we position cookies on our site. Your personal data is collected and processed within the scope of KVKK and GDPR. For detailed information, you can review our Data Policy / Disclosure Text. By using our site, you agree to our use of cookies.', '