Receipt

Fri 28 Aug 2026

Five hardware wallet incidents were disclosed between January and August 2026 across Ledger, Trezor, SafePal, and Coldcard. Four of the five — including SafePal's exposure of 39,798 customers' names and home addresses via an order-tracking plug-in and Trezor's breach of 14,000 records through a fulfillment partner — compromised customer metadata through third-party logistics integrations, not through cryptographic key failure. The sole exception, Coldcard's July 2026 firmware flaw that drained 594 BTC (~$38 million), was the opposite failure: a genuine key-generation defect. Self-custody secures private keys; it does not secure the supply chain that surrounds them — and that supply chain produces a directly actionable map of who holds assets and where they live.

Not submitted.

FAILED
public
Advanced
proof format
opentimestamps
status
failed
privacy
public
created
2026-08-28 04:01:29 UTC