August 4, 2026. A hardware wallet thought to be nearly unbreakable just broke. An attacker drained roughly $38 million in Bitcoin from around 500 wallets in less than half an hour.
The Coldcard breach is now forcing a harder conversation about what actually keeps your coins safe. Charles Guillemet, Ledger's CTO, is pushing back against the panic reflex to just add more signatures to everything.
The attack exploited a flaw in how certain Coldcard hardware wallets generated cryptographic keys. About 594 BTC vanished, moved through 1,300 transaction chunks across 500 separate wallets before landing in a single address. The root cause traced back to firmware version 4, according to a technical report from Block's Bitcoin engineering team.
Guillemet's core argument is simple. People see a hardware wallet fail and immediately think "I need multisig." But complexity creates its own vulnerabilities. Adding more signatures to a wallet setup can introduce fresh problems instead of solving old ones.
He's pointing to Bitcoin Miniscript as a smarter path forward. It lets you build advanced spending rules, inheritance plans, and time-locked recovery keys without the full machinery of traditional multisig. Ledger already supports this approach.
The company's "clear signing" feature and support for the MuSig2 cryptographic standard are practical alternatives already baked into their hardware wallets. Both offer better security without the operational headache of managing multiple keys and signatures.
For most people, Guillemet says, a properly backed-up single-signature hardware wallet still makes the most sense. The real lesson isn't "add more signatures." It's "pick the right tool and use it correctly."
This material is informational only and does not constitute financial or investment advice. Always conduct your own research and consult a qualified financial advisor before making crypto decisions.

