Analysis: What the Coldcard Flaw Means for What a Hardware Wallet Actually Guarantees
A hardware wallet makes three promises. The Coldcard entropy failure broke the one nobody thought to verify — and the one a user cannot check after the fact.
Searches every incident record, jurisdiction page, glossary term and guide.
A hardware wallet makes three promises. The Coldcard entropy failure broke the one nobody thought to verify — and the one a user cannot check after the fact.
| Disclosed | Incident | Chain | Reported impact | Status |
|---|---|---|---|---|
| Bybit Cold Wallet Compromise, February 2025: What Happened & What to Check | Ethereum | approx. US$1.5 billion(FBI (IC3 Public Service Announcement), 26 Feb 2025) | Resolved | |
| Radiant Capital Signing Compromise, October 2024: What Happened & What to Check | Arbitrum, BNB Chain | approx. US$50 million(Radiant Capital, 17 Oct 2024) | Contained | |
| WazirX Multisig Compromise, July 2024: What Happened & What to Check | Ethereum | approx. US$234.9 million(WazirX, 18 Jul 2024) | Contained | |
| DMM Bitcoin Unauthorised Outflow, May 2024: What Happened & What to Check | Bitcoin | 4,502.9 BTC(DMM Bitcoin, 31 May 2024) | Resolved | |
| Munchables Insider Key Compromise, March 2024: What Happened & What to Check | Blast | approx. US$62 million (returned)(Munchables, 26 Mar 2024) | Resolved | |
| Orbit Chain Bridge Compromise, December 2023: What Happened & What to Check | Ethereum, Orbit Chain | approx. US$81.5 million(Orbit Chain, 1 Jan 2024) | Contained |
Ukraine has also been aligning its approach with MiCA as part of the broader EU accession process, so the framework is a moving one.
As ofThe substantive question in France is now the transition of nationally registered PSANs into MiCA authorisation, and the AMF publishes the register of who holds what.
As ofThe Dutch registration regime was notably strict in practice, and the transition to European authorisation has been the main development.
As ofOfficial communication has consisted mainly of cautions that virtual currencies are not recognised and that firms offering them are not licensed domestically. Central bank work on distributed ledger technology has proceeded on a separate track from any retail crypto authorisation.
As ofMore than $57m was reported lost across three protocols to price-feed manipulation in July — the same failure mode, three times, in…
A governance bypass at BonkDAO was reported to have moved $21.2m — the fourth governance-path failure in our records, and the same…
Two more cross-chain bridges failed on message validation in July, taking a reported $20.5m combined — the fifth and sixth bridge validation…
Following a memorandum of understanding in March, the two agencies published a joint interpretation — the first substantive coordination on a boundary…
Treasury Secretary Scott Bessent has said the Department is proceeding with "deliberate speed" toward final rules under the GENIUS Act, moving US…
Alongside full MiCA enforcement, DAC8 extends the EU's automatic exchange of information framework to crypto-assets — changing what tax authorities receive, not…
Cold storage describes where a key is held. It says nothing about how a transaction gets approved — which is where several…
An audit badge tells you almost nothing. The scope section tells you nearly everything — which commit was reviewed, which contracts were…
Most deployed contracts are upgradeable, which means someone can change what they do to funds already held. That control chain is public…
"Regulated" is not a property a firm can assert about itself. It means a named authority, a named permission category, and an…
Who writes here, and what they are working on
Contributor · Ann Arbor, United States
AJ Vicens joined Conisec in 2026 as a contributor, compiling incident records from primary sources — official post-mortems, status pages and on-chain evidence —…
Contributor · Washington, D.C., United States
Jenna McLaughlin joined Conisec in 2026 as a contributor, writing on crypto regulation and maintaining jurisdiction records, working from regulators' own publications rather than…
Contributor · London, United Kingdom
Jordan Robertson joined Conisec in 2026 as a contributor, covering exchange and protocol incidents, with a focus on what a reader can verify for…
Newsroom
Conisec Staff is the byline on factual records compiled and verified by the newsroom rather than written by a single named reporter — Incident…
No tool on Conisec asks for a seed phrase, a private key, a signature or a wallet connection. Nothing on this site connects to a wallet.
Still unsure about something? Ask us — or read how we source and verify, our editorial guidelines and what we will never ask you for.