Self-custody and hardware wallets

Hardware wallet security is discussed almost entirely in absolutes: a device is either trusted or broken, a vendor either honest or compromised. The disclosure record does not support either register. What it shows is a series of specific, bounded findings — a flaw in one chip revision, a weakness reachable only with physical access, a firmware release that changed what the device would sign — each with a defined scope and a vendor response.

The scope is the part that matters to an owner and the part most reliably lost in coverage. A vulnerability requiring physical possession of the device is a different risk from one exploitable remotely. A flaw in seed generation on a particular batch is a different problem from a flaw in the secure element across a product line. Owners of an affected device need to know which one they are holding, and whether they need to move funds today or not at all.

We read vendor advisories and independent research against each other, because they routinely describe the same finding in incompatible language. Where a vendor and a researcher disagree about severity, we report the disagreement rather than picking the more comfortable version.

What we have published on this

What this section does not cover

We do not rank wallets or run affiliate links to any of them, and we do not publish exploit detail that would help someone attack a device an ordinary owner still holds funds on. Where a fix exists we say what it is and where it came from.

Related topics

September 29, 2026

Spain Clarifies Self-Custody Crypto Wallets Are Exempt From Form 721 Reporting

Spanish tax authorities say the foreign asset disclosure rule targets custodial…

September 29, 2026

Democrats Pushed Back on CLARITY Act, Drawing Blame from White House, Lummis

The Trump administration and a key GOP senator say Democratic opposition…

September 29, 2026

Corporate Clients Gain Broader Stablecoin Payment Access via Citi-Coinbase Deal

The bank will lean on Coinbase's infrastructure to offer corporate customers…

September 29, 2026

CFTC Approval Covers Only Full Collateral, Everything Else on the Docket Is Still Open

Five primary-source actions land the same week, and only one…

September 29, 2026

$50 Million Tied to Bitget Hackers Blocked by NEAR Intents

The cross-chain protocol reports intercepting funds tied to a laundering attempt…