Pre-release security testing and incident-response support for hardware wallet manufacturers and custodians.
Added Aug 4, 2026
Hardware wallet manufacturers can ship key-generation flaws that remain undetected for years and expose every affected wallet to theft. Conventional code reviews may miss weaknesses involving entropy, device state, firmware behavior, and production hardware. When a flaw emerges, vendors must also identify affected devices, guide asset migration, preserve evidence, and manage recovery claims.
Offer fixed-scope laboratory audits that test wallet key generation across firmware versions and physical devices, followed by a signed findings report and remediation review. Add an incident-response package covering affected-device classification, safe migration procedures, evidence-preservation instructions, and ownership-verification workflows. Begin as an expert-led service and gradually productize the repeatable test harnesses and audit methodology.
A reported five-year flaw and active draining of weak wallets expose a visible gap between hardware wallet marketing claims and real-world key-generation assurance. Manufacturers, custodians, insurers, and large treasury holders now have a concrete reason to demand independent testing before trusting new firmware or devices.
Showing 1-5 of 5 signals
WHITE HAT DRAINS OF COLDCARD WALLETS BEGIN The white hat wallet drains of exploitable COLDCARD wallets are now underway, according to @coinjoined If your COLDCARD was compromised, do not destroy the device. It could be needed if a recovery process is established. If a white hat secures your coins before you move them yourself, any future claim may depend on proving ownership with your device and KYC records. Users without a way to verify ownership could face a much harder path to recovery.
+4 more signals