TL;DR

  • The register includes publicly documented security failures in wallet software, hardware or their distribution channels disclosed between January 2020 and August 2026, where the failure could expose keys or funds, plus the pre-2020 weak-entropy cases disclosed within the window. Each entry is sourced to the vendor's advisory or the disclosing researcher's write-up, and every impact figure is quoted with its instrument and a confidence label. The register is not complete and does not measure how often any class of failure occurs.
  • Twelve entries meet the method, summarised in the table and detailed in the entry notes, ordered by public disclosure date. The pattern to read for: in this register, the same root causes appear across different vendors and years.
  • Three root-cause classes account for eight of the twelve entries, and for every row in this register that reports drained or stolen funds: randomness weaker than believed at key generation, code changed in the supply chain against the vendor's intent, and secrets reachable by software or people that should never have touched them. In the incidents described below, the vendors' own advisories and reports place the flaw in vendor code or infrastructure, where ordinary user habits could not detect it, and each class has a structural defence with trade-offs of its own.
  • Three defences map to the three classes: adding your own entropy at key generation, verifying updates and applying them on the advisory's timetable, and arranging holdings to remove a specific single point of failure, such as reliance on one device, secret or vendor. Each reduced exposure in specific entries of this register, and each adds costs or risks of its own.
在一个街区

The Wallet Vulnerability Ledger is a dated register of documented security failures in crypto wallet software, hardware and their distribution channels that records, for each incident, the affected products and versions, the disclosure date, the technical root cause, the patched status, any reported impact with its source, and a confidence label, so that implementation risk can be assessed from published evidence.

Method: what this register includes, and how

快速解答

The register includes publicly documented security failures in wallet software, hardware or their distribution channels disclosed between January 2020 and August 2026, where the failure could expose keys or funds, plus the pre-2020 weak-entropy cases disclosed within the window. Each entry is sourced to the vendor's advisory or the disclosing researcher's write-up, and every impact figure is quoted with its instrument and a confidence label. The register is not complete and does not measure how often any class of failure occurs.

Inclusion requires three things: a wallet tool or its delivery pipeline at fault (exchange breaches, phishing and other compromise of individual users, and protocol exploits belong to other academy reports), public documentation from the vendor or the disclosing researcher, and relevance to key or fund exposure. Physical-extraction research is included where it demonstrated practical key recovery or tampering on a shipped device, because holders base custody decisions on those properties. Policy controversies without a demonstrated technical flaw, such as the 2023 debate over Ledger Recover, Ledger's subscription key-recovery service, are noted only as context, since a debate is evidence about architecture rather than about a defect.

Why one customer-data breach is in a vulnerability register. The July 2020 Ledger e-commerce database breach exposed no keys and no device. It is included under a separate class, data exposure, because the leaked names, postal addresses and phone numbers gave criminals a list of known hardware-wallet customers to target, and Ledger itself reported the phishing wave that followed (Ledger, 13 January 2021). The register treats it as an attack enabler rather than a wallet flaw, and the class label keeps that distinction visible. Readers who want a register of technical flaws only can drop the data-exposure row without affecting the rest.

Two levels of classification. Each row carries a broad category and, after the colon, a root-cause class. The categories separate four kinds of failure. Implementation bugs are defects in a vendor's or tool's own code or firmware, which a corrected release can fix for new use, although keys already generated on the weak code have to be replaced: seven entries, covering the weak-key-generation, secret-handling and protocol-implementation classes. Supply-chain attacks are changes an attacker made to code or to a distribution channel against the vendor's intent: two entries, Ledger Connect Kit and Trust Wallet 2.68, where the category and the root-cause class coincide. Architectural weaknesses are properties of a hardware design for which the vendor states no firmware fix in shipped units and which are mitigated by other measures, such as a passphrase: the two Trezor physical-extraction entries. User compromise, in which an attacker deceives a holder or takes over the holder's own device, is outside the method; it appears only through the Ledger 2020 data exposure, recorded as an enabler of user-targeted phishing. The categories are this register's editorial reading of the vendor and researcher accounts cited in each row. Some boundaries are open to argument: Milk Sad is classed as an implementation bug on the disclosing team's account, while the maintainers, according to the disclosure, regarded the seeding behaviour as documented, which would make it a design choice.

Dates. Every row is dated by its first public disclosure as given in the cited source. Where the sources also give an exposure or exploitation window, such as the dates keys were logged, wallets were created or funds were drained, the row or its entry note records it. For the Trezor Safe 3 the row uses the date of public reporting, 14 March 2025, and its note gives the earlier date on the vendor's page.

What the register does not show. The register is a documented selection, and it is not complete. It contains the incidents that met the three inclusion tests and that this edition's source checks, on 23 and 24 September 2026, found documented in an acceptable source; incidents that were never disclosed, were documented only in sources the method excludes, or sit outside wallet tools are absent. It does not measure frequency or likelihood: the number of entries in a class reflects what was disclosed, found and documented, and says nothing reliable about how often that kind of failure occurs, which vendors are more prone to it, or which custody architecture avoids it. Vulnerability records also age quickly: patched status and loss figures are as of each row's cited source, and later editions may add, correct or reclassify entries.

Confidence labels. Verified: the affected versions, dates and patched status come from the vendor's advisory or the disclosing researcher's primary write-up, and any loss figure in the row comes from that same source. Qualified: the flaw is verified, and the loss or population figure comes from a named third party (a tracker, a research desk, a reporter's tally) or is an estimate its author described as such. Disputed: a material claim in the row, usually the causal link between the flaw and a theft, is contested by a primary source. Unsupported: the claim could not be traced to an acceptable source; this edition removed such claims rather than print them.

Impact figures deserve their standing caution: loss attribution on-chain is estimation, tallies differ between trackers and cut-off dates, and this register quotes the instrument with the figure every time. Anonymous forums were not used anywhere in this report.

The register, 2020 to mid-2026

快速解答

Twelve entries meet the method, summarised in the table and detailed in the entry notes, ordered by public disclosure date. The pattern to read for: in this register, the same root causes appear across different vendors and years.

DisclosedProduct and affected versionsCategory: classRoot causePatched statusReported impact and sourceConfidence
31 Jan 2020Trezor One and Model T, all units of the period (STM32F205 and STM32F427 microcontrollers)Architectural weakness: physical extractionVoltage glitching read the encrypted seed from flash, then the PIN was brute-forced; about 15 minutes of physical accessNot fixable in firmware; vendor mitigation is the passphrase, which is never stored on the deviceResearch demonstration; no theft attributed (Kraken Security Labs; Trezor response)Verified
29 Jul 2020Ledger e-commerce and marketing database (not devices or Ledger Live)User compromise (enabler): data exposurePer Ledger's statement, unauthorised access through an API key to customer records from 25 June 2020Access closed 14 July 2020; data later published on 20 December 2020About 1 million email addresses; 9,500 records with name, address and phone at first report; about 272,000 such records in the December dump; no keys or funds affected (Ledger statements, 29 July 2020 and 13 January 2021)Verified
19 Aug 2022Slope mobile wallet for Solana, iOS and Android versions 2.2 and 2.2.1Implementation bug: secret handlingPer Slope's own forensic report, error-logging (Sentry) filters failed and private keys were sent unencrypted to Slope's logging serverLogging server shut down 3 August 2022; apps removed from stores 5 August 2022Keys of 6,811 wallets found in the logs; assets valued at around 4 million USDC drained from 9,229 wallets on 2 August 2022, of which 1,444 (15 percent) appeared in the logs; the auditors found "no conclusive evidence linking" the logging flaw to the exploit, so the causal link is disputed (Slope incident report with OtterSec and SlowMist, 19 August 2022)Disputed
15 Sep 2022Profanity, Ethereum vanity-address generator (all versions; the unrelated ERADICATE tool was not affected)Implementation bug: weak key generationPer 1inch's disclosure, a 32-bit random seed behind 256-bit private keys, so any Profanity address is recoverable by brute forceTool unmaintained; no patch; keys cannot be repaired, only abandoned1inch's contributors estimated that "tens of millions of dollars" could be stolen; outside researchers attributed the Wintermute loss of 20 September 2022, reported at 160 million dollars, to Profanity, and Wintermute did not specify the cause at the time (1inch disclosure, 15 September 2022; as reported by Blockworks, 20 September 2022)Qualified
9 Feb 2023OneKey Mini hardware wallet (firmware of the period; no fixed version number was published in the sources found)Implementation bug: protocol implementationPer Unciphered's own conference slides, a man-in-the-middle device placed between the processor and the secure element made the firmware treat the secure element as unprovisioned, so the processor wrote its protection key to it again; press reports citing Unciphered described the channel as unencrypted and the mnemonic as extractable in under a second once the device was openedOneKey stated that the flaw, which needed physical access and specialised equipment, had been fixed by update and that it paid Unciphered a bounty (10,000 dollars, per Fortune), as reportedNo users affected, per OneKey's statement as reported; no theft attributed (Unciphered, HITBSecConf2023 slides; Fortune, 9 February 2023; The Block, 10 February 2023)Qualified
25 Apr 2023Trust Wallet browser extension, all wallets created between its 14 November 2022 launch and the 21 November 2022 fix (CVE-2023-31290)Implementation bug: weak key generationPer Ledger Donjon's disclosure, the WebAssembly build seeded a Mersenne Twister generator with 32 bits, so about 4 billion mnemonics covered every possible walletFixed 21 November 2022 after report of 17 November 2022; public disclosure 25 April 2023About 30 million dollars in affected wallets at peak per the discoverer's monitoring, about 100,000 dollars remaining at disclosure; Trust Wallet committed to reimburse thefts, per the disclosure (Ledger Donjon disclosure, 25 April 2023)Verified for the flaw; qualified for the figures
8 Aug 2023Libbitcoin Explorer (bx) versions 3.0.0 to 3.6.0, the bx seed command (CVE-2023-39910, "Milk Sad")Implementation bug (disputed by the maintainers): weak key generationPer the disclosing team, Mersenne Twister seeded with 32 bits of clock time, so every seed lay in a keyspace of about 4 billionNot patched by the maintainers, who, according to the disclosure, regarded the behaviour as documented and disputed that it was a defect; the disclosing team advises abandoning such seedsOver 900,000 dollars stolen at August 2023 prices, most of it on 12 July 2023, with over 2,600 vulnerable wallets found on-chain, estimated by the disclosing team (milksad.info disclosure, 8 August 2023)Qualified
14 Nov 2023BitcoinJS 0.1.3 and earlier and derived web wallets, keys generated 2011 to 2015 ("Randstorm")Implementation bug: weak key generationPer Unciphered, a silent SecureRandom failure fell back to browser Math.random, which gave far less than the required entropyNot patchable (Unciphered: "you can't patch a private key"); migration only; coordinated disclosure ran from January 2022"Potentially affects millions" of wallets generated in the window and over one million users alerted, per Unciphered; no dollar figure in the disclosure and thefts not attributed (Unciphered, 14 November 2023)Qualified
14 Dec 2023Ledger Connect Kit npm library versions 1.1.5, 1.1.6 and 1.1.7Supply-chain attackPer Ledger's report, a former employee's npm (NPMJS) account was taken over by phishing, and Ledger says that access "was not properly revoked"; the account was used to publish a drainer inside the library used by many dAppsPer Ledger: fixed version deployed within 40 minutes of Ledger becoming aware; about five hours from compromise to complete resolution; active draining confined to under two hoursLedger's report states no total; trackers reported about 484,000 dollars (Lookonchain via CoinDesk, 14 December 2023) and at least 600,000 dollars (SlowMist, December 2023)Verified for the flaw; qualified for the figures
14 Mar 2025 (public reporting; vendor page dated 12 Nov 2024)Trezor Safe 3 (Safe 5, Model One and Model T not affected by this finding)Architectural weakness: physical extractionPer Trezor's vulnerability page, voltage glitching on the microcontroller could bypass the firmware-integrity check, enabling a tampered device in the supply chain or after theftNo fix for shipped Safe 3 units stated; Trezor states the Safe 5 is not affected; passphrase and buying from official channels are the stated mitigationsResearch demonstration by Ledger Donjon; no theft attributed (Trezor vulnerability page; The Block, 14 March 2025)Qualified
30 Dec 2025Trust Wallet browser extension version 2.68 (mobile apps and other versions not affected)Supply-chain attackPer Trust Wallet, developer GitHub secrets exposed in the November 2025 "Sha1-Hulud" npm supply-chain attack gave an attacker the extension source code and the Chrome Web Store API key; a tampered 2.68, published outside the vendor's review process, harvested decrypted seed phrases on unlock, 24 to 26 December 2025Fixed in 2.69, released 26 December 2025, which Trust Wallet describes as the verified clean 2.67 code re-released; malicious domain suspendedAbout 8.5 million dollars in assets associated with 17 attacker-controlled addresses and 2,520 drained addresses, per the vendor, with a reimbursement programme the vendor describes as voluntary (Trust Wallet, 30 December 2025, updated 17 July 2026)Verified as vendor-reported
30 Jul 2026Coldcard Mk2 and Mk3 firmware 4.0.1 to 4.1.9; Mk4 and Mk5 before 5.6.0 (Edge before 6.6.0X); Q before 1.5.0Q (Edge before 6.6.0QX)Implementation bug: weak key generationPer Coinkite's advisory and Block Engineering's analysis, a disabled hardware RNG left a deterministic fallback generator in use; Mk4, Mk5 and Q added only a 32-bit reseed; seeds from 50 or more dice rolls not affectedFixed in 4.2.0, 5.6.0, 1.5.0Q and the matching Edge builds; existing seeds must be replaced, updating alone does not repair themCoinkite's advisory gives no theft total or wallet count. Third-party estimate: Galaxy Research puts thefts it confirmed with high confidence at 1,778.84 BTC (about 112.7 million dollars) from more than 8,600 addresses, based on on-chain analysis and direct contact with 190 victims; its separate possible upper figure of 2,417.35 BTC (about 153 million dollars) adds medium-confidence sets and a suspected but unconfirmed fourth wave, and it reports no confirmed attack wave after 6 August 2026 (Galaxy Research, 14 August 2026)Verified for the flaw; qualified for the figures

Entry notes, with the original disclosure for each row.

1. Trezor One and Model T, physical extraction. Kraken Security Labs reported the attack to SatoshiLabs on 30 October 2019 and published on 31 January 2020; SatoshiLabs' response of the same day states that a strong passphrase fully mitigates it. Source: https://blog.kraken.com/product/security/kraken-identifies-critical-flaw-in-trezor-hardware-wallets and https://blog.trezor.io/our-response-to-the-read-protection-downgrade-attack-28d23f8949c6

2. Ledger customer-data breach, data exposure. Ledger's 29 July 2020 statement gives the API-key vector, the 25 June exploitation date, the 14 July discovery and the counts; its 13 January 2021 update records the 20 December 2020 public dump, a separate exposure that Ledger attributes to "rogue" members of Shopify's support staff, and 216 phishing sites taken down. Source: https://www.ledger.com/addressing-the-july-2020-e-commerce-and-marketing-data-breach and https://www.ledger.com/blog/update-efforts-to-protect-your-data-and-prosecute-the-scammers

3. Slope, secret handling. Slope's 19 August 2022 forensic report, prepared with OtterSec and SlowMist, is the primary document. It confirms that private keys reached Slope's Sentry server unencrypted and gives the version and date windows. It also states that only 15 percent of drained wallets appear in those logs and that the audit firms found "no conclusive evidence linking the application monitoring vulnerability to the August 2nd 2022 exploit". The row is therefore marked disputed on causation: the logging of keys is established by Slope's own report, and the theft mechanism is not. Source: https://slope-finance.medium.com/slope-wallet-sentry-vulnerability-digital-forensics-and-incident-response-report-d7a5904e5a39

4. Profanity, weak key generation. 1inch's 15 September 2022 disclosure gives the 32-bit seed and the proof of concept. The Wintermute attribution is an inference by outside security researchers, as reported by Blockworks, which also reported that Wintermute's chief executive did not specify the cause at the time and said the firm remained solvent. This register found no Wintermute statement confirming the vector, so the loss figure stays qualified. Source: https://1inch.com/blog/post/a-vulnerability-disclosed-in-profanity-an-ethereum-vanity-address-tool and https://blockworks.com/news/wintermute-whacked-by-160m-hack-exploiting-known-vulnerability

5. OneKey Mini, protocol implementation. The researchers' own account is Unciphered's slide deck "KeyBleed: Attacking the OneKey Mini" (Eric Michaud and Tom Smith), published in the materials of HITBSecConf2023 in Phuket, August 2023. It describes a man-in-the-middle attack between the secure element and the processor that makes the firmware believe the secure element has not been provisioned, so that the processor writes its protection key to the secure element again, and it lists the fixes Unciphered suggested, including allowing provisioning only once and tying seed encryption to the PIN. The slides give no firmware versions or dates. The public demonstration was first reported by Fortune on 9 February 2023 from a preview of Unciphered's video, which Cointelegraph dates to 10 February. The vendor side of the row rests on press reports of OneKey's statements: Fortune quotes founder Yishi Wang as saying the vulnerability, "which required physical access [and] specialized equipment, has now been fixed" and reports a 10,000 dollar bounty, and The Block and Cointelegraph report OneKey's statements that the patch was updated and nobody was affected. No OneKey advisory page could be found for this edition, and OneKey's firmware repository lists no published security advisories, so the fixed version and the no-victims statement remain qualified. Source: https://conference.hitb.org/hitbsecconf2023hkt/materials/D2T1%20-%20KeyBleed%20-%20Attacking%20the%20OneKey%20Mini%20-%20Eric%20Michaud.pdf ; vendor statements as reported: https://fortune.com/crypto/2023/02/09/cyber-firm-cracks-onekey-crypto-wallets-in-video-raises-questions-hardware-security/ , https://www.theblock.co/post/210665/security-firm-unciphered-hacked-into-popular-hardware-wallet-onekey and https://cointelegraph.com/news/onekey-says-it-s-fixed-the-flaw-that-got-its-hardware-wallet-hacked-in-1-second

6. Trust Wallet extension 2022, weak key generation. The discoverer, Ledger Donjon, published the full technical account on 25 April 2023 with the report, fix and bounty dates. Trust Wallet's own postmortem page has since been removed (it returns HTTP 410, Gone), so the reimbursement total that earlier drafts quoted from it is dropped as unsupported. Source: https://www.ledger.com/blog/funds-of-every-wallet-created-with-the-trust-wallet-browser-extension-could-have-been-stolen

7. Milk Sad, weak key generation. The disclosing team's write-up gives CVE-2023-39910, the version range, the 12 July 2023 theft event, the loss estimate at August 2023 prices and, as the disclosure reports it, the maintainers' position that the behaviour was documented and was not a defect. Source: https://milksad.info/disclosure.html

8. Randstorm, weak key generation. Unciphered's 14 November 2023 disclosure covers the JSBN SecureRandom failure, the affected library versions and dependants, the 2011 to 2015 window and the coordinated-disclosure timeline. It gives no dollar total. Source: https://www.unciphered.com/blog/randstorm-you-cant-patch-a-house-of-cards

9. Ledger Connect Kit, supply chain. Ledger's 20 December 2023 incident report is the primary document for versions, vector, timeline and remediation. It states that the former employee fell victim to a phishing attack and that the employee's NPMJS access "was not properly revoked", which Ledger says it regrets, and it states no loss figure; the two tallies in the table are third-party estimates that differ by cut-off and method. Source: https://www.ledger.com/blog/security-incident-report ; tallies: https://www.coindesk.com/business/2023/12/14/ledger-exploit-drained-484k-upended-defi-former-staffer-linked-to-malicious-code and https://slowmist.medium.com/supply-chain-attack-on-ledger-connect-kit-analyzing-the-impact-and-preventive-measures-1005e39422fd

10. Trezor Safe 3, physical extraction. Trezor's vulnerability page for Ledger Donjon's evaluation (dated 12 November 2024) confirms the bypass of the Safe 3's supply-chain countermeasures and that the Safe 5 is not affected; public reporting followed on 14 March 2025, the date the register uses. The attack needs physical possession and lab equipment. Source: https://trezor.io/vulnerability/donjon-s-trezor-safe-3-evaluation and https://www.theblock.co/post/346018/trezor-discloses-vulnerability-safe-3-crypto-wallet-rival-ledger

11. Trust Wallet extension 2.68, supply chain. Trust Wallet's 30 December 2025 community update (updated 17 July 2026) is the vendor account of cause, window, fixed version, loss and reimbursement; the support notice of 29 December 2025 gives the upgrade instruction. Earlier vendor posts cited about 7 million dollars; the later figure of about 8.5 million dollars is used here as the vendor's updated number. The update also says 2.69 is the verified clean 2.67 code re-released, and that claims received exceed the verified affected addresses, so verification was continuing. Source: https://trustwallet.com/blog/announcements/trust-wallet-browser-extension-v268-incident-community-update and https://support.trustwallet.com/support/solutions/articles/67000750069-security-notice-trust-wallet-browser-extension-version-2-68-vulnerability

12. Coldcard, weak key generation. Coinkite's advisory of 30 July 2026 (updated 1 August 2026) gives the affected and fixed versions, the dice-roll rule and the migration steps, and gives no theft totals or affected-wallet counts. Block's engineering analysis of the same date explains the mechanism (the disabled hardware RNG, the deterministic fallback, the 32-bit reseed on Mk4, Mk5 and Q) and states that Mk1 and Mk2/Mk3 firmware up to 3.2.2 are outside the regression. The BTC and dollar figures come from Galaxy Research's report of 14 August 2026, which says that direct contact with 190 victims, together with on-chain analysis, confirmed with high confidence that 1,778.84 BTC (about 112.7 million dollars) was stolen from more than 8,600 addresses. The same report gives a possible upper figure of 2,417.35 BTC (about 153 million dollars) that also counts medium-confidence sets of possible thefts and a suspected but unconfirmed fourth wave; the register keeps the two figures apart and does not treat either as a complete count. Galaxy reports that none of the confirmed, high-confidence attack waves occurred after 6 August 2026, that attackers were active from at least the early morning of 30 July 2026, and, by its own account, that the faulty random number generator firmware was deployed on 17 March 2021. These are third-party estimates, not vendor-confirmed figures. Source: https://blog.coinkite.com/coldcard-mk3-seed-generation-warning/ , https://engineering.block.xyz/blog/predictable-rng-fallback-and-32-bit-reseed-in-coldcard-firmware and https://www.galaxy.com/insights/research/coldcard-exploit-abates-as-total-losses-climb-to-at-least-1700-btc

Five entries reward a closer look. The Coldcard case, covered fully in the academy's State of Crypto Self-Custody report, sits at the register's centre because the vendor advisory and an independent engineering analysis document its mechanism in unusual detail: affected generations were not equally exposed (Mk2 and Mk3 on version 4 firmware produced effectively deterministic output given device identifiers and timing, while later models kept about 32 bits of reseed), and seeds created with 50 or more user-supplied dice rolls sat outside the vulnerable set entirely (Coinkite advisory, 30 July 2026; Block Engineering, 30 July 2026). For holders, that fact is the part of the Coldcard record they can act on.

The Ledger Connect Kit attack is the clearest supply-chain specimen in this register: the flaw sat in a JavaScript library outside any device or app, and users of many unrelated applications met a drainer because one library they had never heard of was replaced upstream, through a former employee's npm account, taken over by phishing, whose access Ledger says had not been properly revoked (Ledger, 20 December 2023). Two years later the Trust Wallet 2.68 incident repeated the shape at the browser-store layer: according to Trust Wallet, its own extension was replaced with a tampered build using a Chrome Web Store key exposed in the Sha1-Hulud supply-chain attack, and version 2.69 replaced it on 26 December 2025 (Trust Wallet, 30 December 2025).

Slope is the secret-handling specimen, and also the register's lesson in evidential care: the forensic report established that private keys reached a logging server in plain text, and also that most of the drained wallets never appeared in those logs, so the register records the logging of keys as verified and the theft mechanism as disputed (Slope, 19 August 2022). Profanity and Milk Sad bracket the weak-entropy family from the tooling side, both reduced to 32 bits of effective randomness by the way their generators were seeded (1inch, 15 September 2022; Milk Sad disclosure, 8 August 2023), Trust Wallet's 2022 extension used the same 32-bit Mersenne Twister seeding in a mainstream product (Ledger Donjon, 25 April 2023), and Randstorm showed the class latent in browser wallets built on early BitcoinJS between 2011 and 2015 (Unciphered, 14 November 2023). The Trezor physical-extraction research, in 2020 and again in 2025, rounds out the map: with possession and equipment, seeds unprotected by a passphrase were recoverable from the Trezor One and Model T of the period (Kraken Security Labs, 31 January 2020), which is why the academy's guide to passphrases and physical security exists.

Timeline of all twelve wallet security incidents from 2020 to 2026: Trezor One and Model T physical extraction research and the Ledger customer-data breach in 2020; Slope seed logging and the Profanity weak-key break in 2022; the OneKey Mini disclosure, the Trust Wallet extension weak-key flaw, Milk Sad, Randstorm and the Ledger Connect Kit supply-chain attack in 2023; the Trezor Safe 3 physical extraction research and the Trust Wallet 2.68 extension supply-chain compromise in 2025; and the Coldcard seed-generation flaw in 2026, each shown as a numbered marker at its disclosure date with a numbered key and coloured by class as weak key generation, supply chain, secret handling, physical extraction, protocol implementation or data exposure
Figure 1. The register on a timeline, coloured by root-cause class, showing all twelve entries. In this register the same classes appear across different vendors and years.

What do the incidents have in common?

快速解答

Three root-cause classes account for eight of the twelve entries, and for every row in this register that reports drained or stolen funds: randomness weaker than believed at key generation, code changed in the supply chain against the vendor's intent, and secrets reachable by software or people that should never have touched them. In the incidents described below, the vendors' own advisories and reports place the flaw in vendor code or infrastructure, where ordinary user habits could not detect it, and each class has a structural defence with trade-offs of its own.

The weak-generation class has the most entries in this register, five of twelve, and its members rhyme. Profanity seeded with 32 bits; bx seeded with 32 bits from a timestamp; Trust Wallet's 2022 extension seeded a Mersenne Twister with 32 bits; the Randstorm-era browsers gathered too little entropy; Coldcard's firmware fell back to a deterministic generator that its hardware was meant to replace (Block Engineering, 30 July 2026). In each of these five disclosures the wallet worked normally and the weakness stayed invisible until someone searched the reduced keyspace, in Randstorm's case years later. A key is exactly as strong as the randomness that made it, and the register records this property failing silently in hobbyist tools and flagship hardware alike.

The supply-chain class has two entries in this register. It scales: one compromised library, publishing key or update channel reaches every downstream user of that component at once. Connect Kit reached users through a dependency that most dApps loaded dynamically from a CDN; Trust Wallet 2.68 reached them through the browser store's own update mechanism. Ledger deployed a genuine fixed version within 40 minutes of becoming aware, and its report puts active draining at under two hours (Ledger, 20 December 2023); the tampered Trust Wallet build harvested seed phrases from 24 to 26 December 2025, when version 2.69 replaced it (Trust Wallet, 30 December 2025).

The secret-handling class is the simplest in mechanism: keys reaching log files, which Slope's own report confirms happened in its app, is its example, although the same report did not establish that this caused the August 2022 thefts. The Ledger customer-data breach sits beside it under its own label, data exposure, as a reminder that vendors hold data about holders even when they never hold keys, and that the data leaks to the same criminal market and is used to target the people on the list.

What the incidents say about user behaviour. The register supports a bounded conclusion, stated incident by incident. In the Coldcard case the flaw was in the vendor's key-generation firmware: a holder who created a seed on official firmware without dice rolls had no practical way to detect the weakness from the device's behaviour, because the device and its addresses worked normally (Coinkite advisory, 30 July 2026). Trust Wallet 2.68 reached users through the vendor's own store update and captured seed phrases when they unlocked the extension (Trust Wallet, 30 December 2025). Connect Kit victims met malicious signing requests inside dApps they had chosen to use, served through a library they had not chosen (Ledger, 20 December 2023). Slope's report states that affected versions of the official app sent private keys to its logging server, and the same report found no conclusive link between that flaw and the thefts (Slope, 19 August 2022). The disclosures do not describe what each victim did beyond that, so the register cannot show that every affected user followed good practice in every respect. What it shows is a category of exposure that originates in vendor code or infrastructure, which habits such as guarding a seed phrase do not address, and which is reduced mainly by how keys are generated, how updates are taken and how control is structured.

Diagram of three root-cause classes with their defences: weak key generation, with Profanity, Milk Sad, Randstorm, Trust Wallet 2022 and Coldcard 2026, defended by user-supplied entropy such as dice rolls; supply-chain compromise, with Ledger Connect Kit 2023 and Trust Wallet 2.68 in 2025, defended by verified updates from official channels taken on the advisory's timetable; and secret handling, with Slope 2022 and the Ledger 2020 customer-data exposure shown alongside, defended by designs that remove a specific single point of failure, such as one device, secret or vendor; each defence shown with its limits, including the implementation, coordination, provider availability and recovery risks that multisig and MPC add, and a note that in the Coldcard, Trust Wallet 2.68, Connect Kit and Slope incidents the vendors' own advisories and reports place the flaw in vendor code or infrastructure
Figure 2. Three root-cause classes account for eight of the twelve entries, each shown with a structural defence. Each defence has limits: dice entropy depends on fair rolls entered correctly, slower updates leave a known flaw open for longer, and distributed designs add coordination and recovery risk.

What actually protects a holder from flaws in vendor code?

快速解答

Three defences map to the three classes: adding your own entropy at key generation, verifying updates and applying them on the advisory's timetable, and arranging holdings to remove a specific single point of failure, such as reliance on one device, secret or vendor. Each reduced exposure in specific entries of this register, and each adds costs or risks of its own.

Against weak generation, the defence is participation. Devices and tools that accept user-supplied entropy, dice rolls being the traditional form, let the holder contribute randomness that does not depend on the device's own generator, and the Coldcard record shows the practice working: seeds from 50 or more fair, independent rolls were outside the vulnerable set (Coinkite advisory, 30 July 2026). The practice has limits: too few rolls, biased dice or rolls entered incorrectly weaken it, and it relies on the device processing the input as documented. Where participation is impractical, generation on a widely reviewed tool, offline, with the method documented, is the fallback position. The guide to seed phrases explains the entropy arithmetic.

Against supply-chain compromise, the defence is verification plus timing. Ledger puts the time from the npm compromise to complete resolution at about five hours, and its report says most dApps loaded the library dynamically from a CDN, which is how the tampered file reached them (Ledger, 20 December 2023); the tampered Trust Wallet build was live for about two days, and Trust Wallet says only extension version 2.68 was affected (Trust Wallet, 30 December 2025). For holders this translates to applying updates from official channels promptly when an advisory calls for it, taking routine updates without racing to be first, and treating the update moment, when software legitimately asks for new trust, as a high-attention moment in routine maintenance. Delay has a cost too: a slower routine update leaves a known flaw open for longer. Watch the vendor's advisory channel; hours mattered in the Connect Kit and Trust Wallet 2.68 timelines.

Architecture, incident by incident. Some entries show a single point of failure that a distributed design could have reduced, and each such design carries risks of its own. In the Coldcard case, a wallet whose control required keys generated independently on devices from different vendors, as in a multisig quorum, would not have depended on one vendor's generator alone: a weak seed on one device would have exposed one key of the quorum. In the Trust Wallet 2.68 case, a quorum in which the extension held only one key would have limited what a harvested seed phrase gave the attacker. Connect Kit worked by tricking users into signing approvals, permits and transfers (Ledger, 20 December 2023), which a quorum reduces only if the other signers inspect and refuse the request. A threshold (MPC) arrangement typically generates its key shares in distributed form, so that no single device holds the full key; where the design works this way it removes the single-device point of failure, and if all the shares are generated and used by one vendor's software it still depends on that vendor's randomness, code and update channel. Multisig and MPC designs add risks of their own: implementation bugs in the multisig or threshold software, coordination between devices or parties, dependence on a provider's availability where one is involved, and a recovery process that is more complex and can itself fail. A single hardware or software wallet keeps advantages these designs give up: fewer components to configure and update, no coordination between signers, and recovery from one backup. A custodial account moves key generation and storage to a third party, which shifts exposure to flaws of this kind onto the custodian's systems and adds counterparty and access risk. Which arrangement suits a given holder depends on circumstances this register does not assess. The academy's guides to multisig and to threshold cryptography and MPC set out those trade-offs. This report's publisher builds MPC-based self-custody technology and has a commercial interest in these designs. No arrangement removes every class of failure recorded here, and none of them is categorically superior; the useful question for any implementation is which single point of failure it removes and what it adds in its place.

Frequently asked questions

Does this register mean hardware wallets are unsound?

It means they are software, in a case. The register also shows the ecosystem's correction machinery working: disclosures, bounties, fixed firmware and reimbursements all appear in it. Isolation from the internet remains a real security property; the register bounds what it does and does not cover.

Which vendor has the best record?

The register cannot say, and no dataset of this size could: absence from it may mean sound engineering, less scrutiny or less deployment. What it supports is class-level conclusions, and the class-level lessons, entropy, verified updates and architecture, hold whichever vendor you run.

Why does the Coldcard row give a loss figure if the vendor did not?

Because readers will meet the figure elsewhere and should know where it comes from. Coinkite's advisory states the affected firmware and the remedy and nothing about totals. The 1,778.84 BTC and 112.7 million dollar figures are Galaxy Research's estimates of funds stolen from more than 8,600 addresses, which its report of 14 August 2026 says were confirmed with high confidence through on-chain analysis and direct contact with 190 victims. Galaxy gives a separate possible upper figure of 2,417.35 BTC that adds medium-confidence sets and a suspected but unconfirmed fourth wave; the register quotes the two separately and does not add them together. The row labels both as third-party estimates, and the Crypto Wallet Security guide uses the same labelling.

Was Ledger Recover a security vulnerability?

This register found no vendor advisory or researcher disclosure demonstrating a flaw in it, so the 2023 episode appears only as context in the method. Ledger describes the service as splitting the Secret Recovery Phrase into three shares with Shamir Secret Sharing, computed inside the device's secure element under the user's PIN, and held by three backup providers (Coincover, EscrowTech and Ledger), any two of which can restore it (Ledger, 25 July 2023); Ledger sells it as a subscription that device owners sign up for. The debate it prompted was about trust in device firmware, since a feature that exports encrypted shares of the seed shows that firmware can be written to move seed material off the device with the user's approval. That is information about an architecture, which the method keeps separate from a demonstrated defect.

What should I do if my wallet's vendor discloses a flaw?

Read the advisory itself before the coverage of it, establish whether your device generation and firmware version are affected, and follow the vendor's remediation. If key material may be exposed, note that in the Coldcard and Milk Sad entries the advisories called for moving funds to a fresh, soundly generated seed, because updating software does not repair a weak key. The academy's guide on how to respond if your crypto is hacked or stolen covers the general drill. If funds have already been taken, reporting routes include the local police, the FBI's Internet Crime Complaint Center (IC3) in the United States, Report Fraud (formerly Action Fraud) in England, Wales and Northern Ireland, and Police Scotland on 101 (City of London Police, December 2025). A report does not guarantee recovery, and the FBI has warned that companies claiming they can recover lost crypto for an up-front fee are a known follow-on fraud (FBI IC3, 11 August 2023).

How are new entries and corrections handled?

Each edition carries a dated last-reviewed line, and any entry added follows the same template and method. Corrections to any figure follow the sources; where trackers disagree, the register quotes both, as it does for the Connect Kit tallies.

Sources and further reading

Primary sources for this edition. Each URL was loaded and checked on 23 or 24 September 2026, as dated below.

To cite this report: Bron Academy Editorial, The Wallet Vulnerability Ledger, last reviewed 6 October 2026, bron.org/academy.

快速测验:它粘住了吗?

提出了一些检查基本原理的问题。下面是带有解释的答案,除了你未来的作品集之外,没有人给你评分。

1/7问题
What connects Profanity, Milk Sad, the 2022 Trust Wallet extension and the Coldcard flaw?

这有帮助吗?