Most people assume that crypto lost from a hardware wallet is the owner's fault — a seed phrase typed into a phishing site, a photo of the backup sitting in a camera roll, a device left behind somewhere. In reality the risk sits in at least three layers, and the deeper you go, the less of it is under your control.

Layer one — User Risk. Phishing, careless seed storage, being coerced into disclosure. You control almost all of this, and it is the layer everyone talks about.

Layer two — Supply Chain Risk. A device opened and tampered with before it reaches you, or bought from an unauthorised reseller. This layer is partly controllable: buying direct from the manufacturer, checking the tamper-evident seal, and always generating the seed yourself reduces the risk substantially — but never to zero.

Layer three — Product Risk. A defect in the firmware or in the private key generation process. Here you can do nothing at all, and it is more dangerous than the first two layers for two reasons: there is no warning sign — you have no way of knowing until the money is already gone — and it does not affect you alone, but everyone running the same codebase at the same time.

The clearest example is the Coldcard incident of late July to early August 2026. Firmware version 4.0.1, released back in March 2021, fell back to a software random number generator instead of the device's hardware entropy source during seed generation. Keys that should have carried 128 bits of strength were reduced to roughly 40 bits on some models. Attackers were therefore able to reconstruct private keys from public blockchain data without touching anyone's device for even a second. Losses reported as at early August 2026 ranged between USD 70 million and USD 116 million across more than 5,200 addresses, and those figures remain preliminary. More troubling still, the flaw sat in publicly auditable code for five years.

Most victims had stored their Bitcoin exactly by the book. Nobody was tricked into disclosing anything. They lost their assets regardless.

Pulse Legal has written this article as a guide for future digital asset theft incidents, whichever layer of risk they arise from — because on the day Hardware Code and Computer Code can no longer protect your assets, there may at least still be Legal Code as another avenue for recovering what you have lost.

The First 24 Hours: Technical Work

1. Send nothing further to the affected addresses. Attackers typically leave bots watching compromised addresses; anything newly deposited disappears within seconds.

2. Check whether other wallets were generated on the same device or derived from the same seed. Many people assume they have lost a single wallet, when the entire set of addresses traces back to one seed.

3. Migrate in order: update firmware → generate a new seed → verify the backup and fingerprint → test with a small amount → move the remaining balance → keep the old backup until the migration is complete.

4. There is no such thing as a "coin recovery service." A confirmed transaction on the blockchain cannot be reversed. Anyone promising to pull your coins back is not telling you the truth.

The First 72 Hours: International Practice

Preserve the evidence first. Digital asset cases are lost on evidence far more often than on law. Collect the full set: device model, serial number and firmware version as at the date the seed was created / the purchase receipt and the name of the seller or importer / the xpub and the affected addresses / transaction IDs with timestamps and destination addresses / block explorer screenshots / the withdrawal history from exchanges into that wallet. Bundle it all together, hash the bundle, and record the date and time.

Flag the destination addresses as fast as possible. One of the highest-priority steps is reporting the attacker's addresses to blockchain analytics firms (Chainabuse, Chainalysis, TRM Labs, Elliptic) and directly to the compliance teams of the major exchanges. Once an address is tagged, screening systems worldwide will catch it the moment the coins try to come in. This is a mechanism that has worked in a number of real cases — often before any court order was issued — and it costs nothing.

Two civil routes used internationally. The first is to follow the coin: on-chain investigation, then applications for freezing orders and disclosure orders against exchanges. In practice this runs through the courts of England, Singapore, Hong Kong or the BVI — expensive, and only worthwhile where the loss is large or victims can be aggregated. The second is to sue the manufacturer in tort and product liability, which faces two obstacles: terms of use typically contain arbitration clauses and limitations of liability, and the claimant must show the manufacturer ought reasonably to have foreseen the harm.

Enforcement in Thailand

Victims should file a police report quickly, via www.thaipoliceonline.go.th or the 1441 hotline. Where the amount is significant, attend in person before an investigating officer at the Cyber Crime Investigation Bureau (บช.สอท.) or the Technology Crime Suppression Division (บก.ปอท.). The reason is not that the police will immediately apprehend a cross-border offender — it is that every asset-freezing mechanism in Thailand keys off a case reference number.

Know the limits of Thai criminal law in advance. The theft offences under Sections 334 and 335 of the Penal Code use the term ทรัพย์ ("thing"), which Section 137 of the Civil and Commercial Code defines as a corporeal object; Supreme Court Decision No. 5161/2547 established that copying computer data does not constitute theft. The same reasoning applies naturally to a private key. Fraud under Section 341 requires deception, which is absent in a hardware wallet product defect scenario. That leaves the Computer Crime Act B.E. 2550 (2007), Sections 5, 7 and 9, as the principal basis — and while these provisions are aimed at attackers who break into systems, there is still no clear precedent under Thai law on how they apply to facts of this kind.

Where Thai law may actually help is consumer protection. Remember the instruction to keep the receipt and the seller's name? This is why. The Product Liability Act B.E. 2551 (2008) imposes strict liability — the injured party need not prove negligence, which removes the "was the harm foreseeable to the manufacturer" obstacle that causes difficulty abroad. It also makes manufacturers, importers and sellers jointly liable. So if you bought through a reseller in Thailand, you may have a defendant within reach of a Thai court, rather than having to sue a foreign company overseas. And under Section 9, an advance agreement excluding liability is unenforceable.

Limitation is the point to watch most closely: three years from the date the injured party became aware of the damage and of the person liable, but in no case more than ten years from the date the product was sold. Devices bought back in 2021 are steadily approaching that ten-year mark.

Procedurally, a claim of this kind falls under the Consumer Case Procedure Act B.E. 2551 (2008), which exempts the claimant from court fees, permits filing in the court where the consumer is domiciled, and shifts part of the burden of proof onto the business operator.

Following the Coldcard incident, therefore, businesses selling hardware wallets in Thailand may need to exercise considerably more care in choosing which brands they stock, since a repeat of an incident like this could expose them to liability under consumer protection law.

What to Do Before Anything Goes Wrong

Diversify hardware wallet manufacturers — for example, a 2-of-3 multi-sig built from three different brands.

Set a passphrase. In the 2026 incident, a BIP-39 passphrase was the line between those who became victims and those who stayed safe. And setting one is free.

Keep your documents. None of us can predict whether an incident like this will one day happen to us, but preparing by retaining the relevant records and evidence is a form of risk management in itself — and it costs almost nothing. Treat it as one more layer of discipline in your self-custody practice: noting the date the seed was created and recording the firmware version may prove valuable to you in the future.

If you were affected, or if you are reviewing how you or your organization hold digital assets, Pulse Legal would be glad to help.