Cold wallets, also known as hardware wallets, have returned to the centre of the debate on crypto asset security following a string of incidents involving manufacturers and suppliers in the sector. Although these devices are considered one of the safest ways to store Bitcoin and other digital assets, recent cases show that the risks now extend beyond internet connectivity.

In under a month, three episodes involving Coldcard, Trezor and SafePal resulted in the theft of more than US$110 million in Bitcoin and the exposure of personal data belonging to more than 53,000 users, according to a survey by DSec Labs, a Brazilian company specialising in blockchain infrastructure and digital asset security.

The company's assessment is that criminals are widening their focus to cover the entire self-custody chain. This includes not only the physical device, but also the software used to generate keys, logistics suppliers, order systems and the personal information of those who purchase this type of equipment.

"For a long time, the market focused the discussion on the difference between leaving assets on an exchange or storing them in a cold wallet. Recent attacks show that the analysis needs to be broader," says Guilherme Campos, co-founder and COO of DSec Labs. According to him, security involves "key generation, the device, the software, the backup, the suppliers and even the personal information linked to the purchase of the equipment".

The most serious case cited by the company involves Coldcard, a hardware wallet made by Canadian company Coinkite. A flaw in the seed phrase generation process reduced the randomness of keys in certain models, making some combinations more predictable. In practice, this allowed criminals to test possible keys until they found addresses holding a balance.

Coinkite itself published an alert stating that seeds generated in affected firmware versions could be at risk if they had not been created with additional randomness, such as 50 private dice rolls, and without a strong BIP-39 passphrase. The company also said that newer models were affected by a lower-than-expected entropy level before the fixes were applied.

Recent reports have cited losses that vary depending on the stage of the investigation. CoinDesk initially reported a theft of around 594 BTC, valued at approximately US$38 million, linked to a key-generation flaw in Coldcard wallets. Days later, the same coverage reported that the attack had spread to thousands of addresses, with losses nearing US$89 million.

Leaks expose users to scams and physical threats

In the Trezor and SafePal cases, the problem did not involve direct access to private keys or user funds, but rather the exposure of personal data. Even so, this type of leak is considered sensitive because it identifies people who bought hardware wallets and may therefore hold crypto assets in self-custody.

Trezor said that a breach at a logistics supplier exposed customer data, including names, emails, phone numbers and delivery addresses in some cases. According to the DSec Labs release, around 13,700 customers were affected.

The company stated that wallets, private keys and user funds were not compromised. The risk, however, lies in the use of this information for phishing attempts, fake support contacts, extortion or in-person approaches.

SafePal also confirmed a recent incident. According to Reuters, the company disclosed in August a leak affecting 39,798 customers, exposing order information including names, addresses and purchase data. The company said passwords, private keys, seed phrases and funds were not compromised.

For DSec Labs, the concern is that this data could enable more targeted attacks. With a name, phone number, address and device model, criminals can simulate messages about mandatory updates, device recalls, vulnerability fixes or security checks. The goal is usually to trick the victim into disclosing the seed phrase, which grants full access to the wallet.

"A private key does not need to appear directly in a leak for there to be a significant risk. When data allows criminals to identify who owns a wallet and where that person lives, they gain enough information to build much more targeted digital or physical attacks," says Toni Farias, CPTO of DSec Labs.

The warning carries extra weight because incidents involving suppliers and purchase data are not new to the sector. One example experts point to is the Ledger leak of 2020, when an e-commerce flaw exposed around 1 million email addresses and 272,000 physical addresses, data that continued to be used in scams in the years that followed.

Self-custody requires more than just keeping the wallet offline

The incidents do not mean cold wallets have stopped being a safe option, but they do reinforce that self-custody depends on broader procedures. Protection does not lie only in keeping the device disconnected, but in how the key is generated, how the backup is stored, how the equipment is purchased and how the user reacts to suspicious contacts.

DSec Labs says artificial intelligence could make this scenario more dangerous, by allowing criminals to analyse leaked databases, cross-reference personal data and produce more convincing messages at scale. This does not mean AI can break Bitcoin's cryptography, but it can exploit existing vulnerabilities and make scams harder to spot.

"Artificial intelligence does not break a correctly generated key. It amplifies vulnerabilities that already exist and makes attacks faster, more personalised and harder to identify," says Farias.

In response to this scenario, DSec Labs developed ColdKit, a solution aimed at offline storage of the information needed to control a Bitcoin wallet. The idea is to reduce the exposure of sensitive data to phones, computers, apps, the cloud and other internet-connected environments.

The company itself, however, says no solution should be treated as invulnerable. Security still depends on correct key generation, physical protection of the backup and user behaviour.

Recommendations include following official manufacturer announcements, never sharing the seed phrase with supposed support teams, being wary of contacts about security flaws, avoiding storing recovery words in photos, emails or the cloud, running test transactions and considering additional mechanisms for large amounts, such as multi-signature setups.

"Attacks are likely to keep migrating to the least protected points in the chain. As manufacturers strengthen devices, criminals turn to suppliers, personal data and the user's own behaviour," says Leonardo Maximiliano, co-founder and CEO of DSec Labs.

Want to invest in the world's biggest cryptocurrency? At MB, you can get started in a few clicks, safely and transparently. Do not put off a promising wallet — do more with your money. Open your account and invest in bitcoin now!