
1. A shared hardware vulnerability
In July 2026, vulnerabilities were disclosed one after another in hardware security modules (HSMs), the core components that protect funds, in two very different payment fields: Coldcard, a cryptocurrency wallet, and FeliCa, the technology widely used for e-money and other services.
2. Reverse-engineering cryptographic keys due to unique design choices
In both products, unique design approaches and flaws in older specifications backfired, drastically reducing the number of possible candidates for cryptographic keys that should have been impossible to crack. This made it far easier for attackers to work out the keys, and in Coldcard's case, it led to the theft of a large amount of crypto assets.
3. The difficulty of a fundamental fix and the importance of design
Both cases share the same problem: because keys generated under older versions remain in use, the flaws cannot be fixed with a software update, and there is no fundamental solution other than to stop using the affected devices. These incidents highlight how important proper implementation and rigorous code review are when it comes to complex cryptographic processing.
In July 2026, two separate incidents took place.
The first was the exploitation of a zero-day vulnerability in Coldcard, a hardware wallet for crypto assets. Users had set up hardware wallets, never revealed their private keys to anyone, and even took care not to let their addresses become known more than necessary. There should have been no way in for thieves. Even so, Bitcoin (BTC) was stolen. In total, around 1,600 BTC is reported to have been taken.
The second was the release of detailed information about a vulnerability in FeliCa. In Japan, FeliCa is used in transit IC cards, e-money, and more. It is far more widespread than crypto assets and is a much-loved part of everyday life. The existence of the vulnerability was first reported last year, and detailed information has now been made public.
Crypto wallets and FeliCa are technologies that would normally never cross paths. Yet their vulnerabilities turned out to have a lot in common: payment methods, cryptography, hardware, legacy software, and more. In this article, I'll explain both vulnerabilities and examine them from the perspective of cryptographic hardware security, the technology that protects our assets.