Bitcoin wallets compared: Ballet, Ledger, Trezor, Coinbase and Kraken

Bitcoin Research — Law, Regulation, Markets & Origins (2026)

Market

2026-10-09

Document text

Research, not advice. Part of the Bitcoin research archive (October 2026). Claims labelled unverified, contested or fringe are reported, not endorsed; statuses of bills and rules are as of the date checked. Government, court and patent records are public domain; the research notes are CC BY 4.0.

Bitcoin wallets compared: Ballet, Ledger, Trezor, Coinbase and Kraken

This note covers who holds the keys in each case, what has gone wrong at each company, what each one costs, what insurance there is (usually none), and how each is regulated in the US. Everything was checked on 2026-10-09 unless another date is given. Prices and terms change, so each figure is tied to the page it came from. Saved government and court documents are in ../sources/wallets/.

This is research, not advice. Nothing here recommends a wallet, an exchange, or buying or selling anything.

How to read the labels. - (unverified) means I could not confirm the point from a primary or reliable source today. - CONTESTED means credible parties disagree. - FRINGE means a minority or speculative claim. Each one names who makes it. - SPARK-REJECTED marks material that the local Spark research run filtered out. The editor asked for it to be kept, so it is included and labelled (see §12).


The short version

  • There are two models. A custodial account (Coinbase or Kraken) means the company holds the private keys and you hold an IOU-like claim on its books. A self-custody wallet (Ballet, Ledger, Trezor, Coinbase Wallet, Kraken Wallet) means the key is with you. FinCEN's terms are "hosted" and "unhosted" wallets. A hosted-wallet provider "has total independent control over the value". With an unhosted wallet the owner "has total independent control" (FinCEN FIN-2019-G001 §4.2.1, 2019-05-09).
  • Coinbase's terms say you own the coins and Coinbase keeps the keys. Its US User Agreement says title stays with the customer and the assets "are not property of Coinbase". It also says Coinbase "shall retain control over electronic private keys" and may hold customer coins in shared ("omnibus") addresses (Coinbase User Agreement §§2.7.1–2.7.4, last updated 2026-07-22, archived 2026-10-01).
  • Custodial bankruptcy risk has actually happened. In the Celsius bankruptcy the court held that coins customers had put in "Earn" accounts became Celsius's property. About 600,000 accounts holding about $4.2 billion became property of the bankruptcy estate (In re Celsius, Bankr. S.D.N.Y., 2023-01-04). The outcome turned on Celsius's own terms of use, which is why the wording of each custodian's terms matters.
  • Self-custody failures look different. Today, 2026-10-09, Ledger is investigating reports that buyers of devices from a Southeast Asian reseller, CryptoBilis, lost an estimated $72–87 million. The cause is not confirmed. Ledger told recent buyers not to set up those devices (The Block; Decrypt).
  • Leaked customer lists from both kinds of company feed phishing and physical "wrench" attacks. Examples are Ledger's 2020 e-commerce database (about 272,000 home addresses), Coinbase's 2025 insider theft (69,461 people) and Trezor's shipping-partner leak in 2026 (sections 3–5).
  • US regulation follows custody. Custodians are money transmitters with FinCEN registration and state licences, and they faced SEC suits from 2023 that were dropped in 2025. Device makers and makers of non-custodial software are generally outside money-transmitter rules (§9).

1. Comparison table

Ballet REAL Ledger Trezor Coinbase (account) Coinbase Wallet Kraken (account)
Who controls the key You, once you reveal both halves printed on the card You (device, PIN, 24-word phrase). Optional Ledger Recover splits the backup across 3 companies You (device, PIN, phrase or multi-share backup) Coinbase You (key on your device) Kraken (Payward)
Electronics None: a printed metal card Secure-element device, closed-source OS Secure-element device on current models, open-source firmware n/a Phone/browser app n/a
Backup if lost None: lose the card, lose the coins (Mantripping review, 2026-05-08) Recovery phrase. Paid Ledger Recover. Ledger Recovery Key card (Flex/Stax) Recovery phrase. Multi-share (SLIP-39) backup Account recovery through Coinbase (ID checks) Recovery phrase Account recovery through Kraken
Up-front cost $49–$299 per card $69–$399 per device (shop prices 2026-10-09) $59 / $129 / $249 none none none
Trading cost n/a n/a (third-party swaps in-app) n/a spread + Coinbase fee. 1% limit-order fee. Advanced: no spread DEX service fee (was 1% through Mar 2023) app 1% + spread. Pro maker 0.40% / taker 0.80% at the lowest tier
Insurance none none on the device. Recover: Coincover "may" pay up to $50,000 none found crypto not FDIC/SIPC. USD balances pass-through FDIC up to $250k none "not covered by insurance against losses"
US status no licence found (non-custodial product) no licence needed for device (FinCEN tool-supplier rule). Sued in US over 2020 breach same as Ledger FinCEN MSB. State licences. NY BitLicense. NY trust company. CFTC FCM/DCM. SEC case dismissed 2025 SEC's "broker" claim on Wallet dismissed 2024 FinCEN MSB (2 entities). State MTLs incl. Oregon #30242, not NY. Wyoming bank charter. SEC case dismissed 2025
Headline incidents none found (see §2 caveats) 2020 customer data leak. 2023 Recover backlash. 2023 Connect Kit drain (~$610k). 2026 Global-e leak. 2026 CryptoBilis reseller losses 2020 physical seed-extraction flaw (old models). 2024 support-portal breach. 2026 ShipMonk leak and phishing 2021 account takeovers (6,000+). 2025 insider data theft ($180–400M cost estimate) 2025 data theft did not touch self-custody keys 2022 OFAC Iran settlement. SEC commingling allegations (denied). 2025 bribery attempt repelled

Sources for each cell are in the sections below.


2. Ballet (physical "REAL" cold-storage cards)

What it is. Ballet makes stainless-steel and gold-plated cards that carry a bitcoin deposit address and an encrypted private key. There is no chip, battery or connection. Bobby Lee, former CEO and co-founder of the Chinese exchange BTCC, launched it in September 2019, with seed money from Ribbit Capital (Grit Daily, Sept 2019). Ballet's own anniversary release gives its founding year as 2019. It also says that as of 2025-09-12 users "secure over one billion dollars" with its products, a figure Ballet published itself and nobody else has checked (Ballet, 2025-09-12).

How it holds the key. The card has three parts. The deposit address is printed on the front. The "private-key entropy" is on a yellow QR sticker under a tamper-evident silver sticker. The "passphrase entropy" is laser-etched under a scratch-off strip. Combining the two hidden parts with BIP38 decryption produces the actual private key. Ballet says this happens "on your device, for the first and only time" and that "the private key is never created at the factory" (ballet.com/how-it-works).

Two-Factor Key Generation (2FKG). This is Ballet's manufacturing process (ballet.com/2FKG): 1. An air-gapped computer at the US facility makes the BIP38 passphrase, an "intermediate code" and a serial number. 2. Only the intermediate code and serial number go to the China facility. 3. The China facility generates and prints the encrypted key and address, then deletes the data. 4. The cards return to the US, where the passphrase is etched and covered and the data is deleted. 5. Ballet checks each card's BIP38 "confirmation code" and destroys random units for spot checks.

In 2019 the two sites were described as Las Vegas and Shanghai (Grit Daily). This is the "EC-multiply" mode of BIP38, which was designed so that a "printer" can make encrypted keys without knowing the owner's passphrase. A confirmation code lets the passphrase holder check that the printer's address really depends on it (BIP38 spec).

Points to weigh. Each is cited. - No backup. If the card is lost or destroyed before the coins are moved, the coins are gone. Once the sticker and strip are removed, the card is no longer cold storage (Mantripping review, 2026-05-08). - You trust the factory process. BIP38 assigns two roles: an "owner" who knows the passphrase and makes the intermediate codes, and a "printer" who makes the key without being able to decrypt it (BIP38 spec). In a standard Ballet card both roles are Ballet's: the US facility acts as owner and the China facility as printer. The buyer does not choose the passphrase (2FKG). This is my reading of the two documents. - The design keeps the halves apart, so no single facility or person holds both. But the buyer cannot independently confirm that the data was deleted. - The BIP38 spec itself says: "An issuer of physical bitcoins must be trustworthy and trusted... A physical bitcoin that cannot be compromised by its issuer is always more intrinsically valuable than one that can." - The reviewer above flags the same "manufacturer dependency". - I found no published third-party audit of Ballet's factories. - Patent status is unclear. One Ballet page calls 2FKG "patent-pending" (2FKG page). A 2024 Ballet post calls it a "patented approach" (Ballet blog, 2024-08-19). I found no patent number. - Ballet can recognise its own addresses. Ballet's verification page tells you whether a deposit address came from a Ballet card, unless "privacy lock" is enabled (ballet.com/verify). My inference, not a Ballet statement: Ballet keeps some list of the addresses it issued, which has privacy implications. - BIP38's status in the Bitcoin BIPs repository carries a comment summary of "Unanimously Discourage for implementation" (BIP38 spec header). The comments behind that summary were not reviewed. (unverified as to the reasons)

History of security incidents. I found no reported hack, theft or data breach at Ballet in the sources I could reach. That is an absence of reports, not proof. The Spark search found almost no independent reviews.

Fees. The card is the main cost: about $49 for stainless steel to $299 for 24K gold-plated (Mantripping). The REAL Bitcoin Gold Edition is listed at $299 (bobbylee.com). Bitcoin network fees apply when you spend. Any fees inside the Ballet app were not found (gap).

Insurance. None found.

US regulatory status. I found no FinCEN registration or state licence for Ballet. Since Ballet never holds customer funds, FinCEN's 2019 guidance would treat it as a supplier of "tools (communications, hardware, or software)", which it says is "engaged in trade and not money transmission" (FIN-2019-G001 §4.5.1(b)). Applying the guidance to Ballet is my reading; FinCEN has issued no ruling on Ballet.


3. Ledger (hardware wallets)

Company. Ledger was founded in 2014 and is headquartered in Paris, with an office in Vierzon among eight worldwide. It reports "7 000 000+" devices sold and uses "the Secure Element chip and Ledger's proprietary OS" (ledger.com/the-company). A Ledger executive put its customers at about 8 million in September 2026 (Yahoo Finance, 2026-09-24).

How it holds keys. The private keys and recovery phrase are generated and kept inside a certified secure element. Ledger rates the Nano S Plus, Flex, Stax and the new Nano Gen5 CC EAL6+ and the Nano X CC EAL5+ (Ledger comparison page). The operating system is proprietary, which is a long-running point of criticism (§11).

Prices as shown on shop.ledger.com product pages on 2026-10-09 (may include promotions): Nano S Plus $69, Nano X $99, Flex $249, Stax $399 (product pages for Nano S Plus, Nano X, Flex, Stax).

3.1 The 2020 customer data breach

Date Event Source
2020-06-25 Someone used an exposed API key to access Ledger's e-commerce and marketing database Ledger statement
2020-07-14 A bug-bounty researcher told Ledger. Ledger first said about 1 million emails and 9,500 detailed records (name, postal address, phone) same
2020-07-29 Public disclosure same
Dec 2020 Full database dumped on RaidForums. The CEO said the dump held about 272,000 detailed records, not the 9,532 Ledger had first found. Ledger offered no compensation Ledger CEO message, 2020-12-21
2020-12-20 Have I Been Pwned listed 1.1 million addresses with names, phone numbers and physical addresses HIBP
2022-12-01 US lawsuit (Baton v. Ledger SAS). The Ninth Circuit held California courts had jurisdiction over Ledger, which had sold about 70,000 wallets directly to Californians. But Ledger's terms send disputes to French courts, and those clauses were enforced except for California consumer-law class claims, whose dismissal was reversed. Claims against Shopify, which ran Ledger's online store, went back for jurisdictional discovery 9th Cir. memorandum

How the case ended after remand was not found (gap).

Consequences. Ledger says no funds or recovery phrases were exposed (Ledger CEO message). But a list of names and home addresses of known crypto owners is a target list. CertiK counted 52 verified "wrench attacks" (physical coercion) worth $124.1 million in the first half of 2026, against 39 incidents and $10.5 million a year earlier. France had 33 of them. CertiK partly blames "a run of data breaches" that "hand attackers ready-made target lists" (it named French government breaches, not Ledger's) (Decrypt via Yahoo, 2026-07-23). Ledger co-founder David Balland was himself kidnapped from his home in central France on 2025-01-21. A ransom of €10 million was demanded and police freed him the next day. A suspect was arrested in Spain, as reported on 2026-03-23 (Cointelegraph).

3.2 Ledger Recover (2023)

  • What it is. An optional paid service. Inside the secure element and under the user's PIN, the device splits the recovery-phrase entropy into three encrypted shares (Ledger blog, 2023-07-25). The shares are held by Coincover, Ledger and EscrowTech (Ledger Recover page). Restoring needs identity checks passed with two of the three providers independently. Coincover uses Onfido; Ledger uses Tessi/IDnow (Coincover blog, 2023-07-09). A government passport or national ID is required, and US and Canadian driver's licences are accepted. Supported devices are Stax, Flex, Nano X and Nano S Plus, not the original Nano S. Coincover "$50,000 compensation may be available... subject to investigation" (Ledger Recover page).
  • Price. It is not shown on the current page. At the 2023 launch it was $9.99 a month (unverified).
  • Backlash, May 2023 (CONTESTED). Critics said the feature showed the firmware can send seed material off the device, breaking what users understood as a promise that the seed never leaves. They also objected to the ID (KYC) requirement and to closed-source code that outsiders cannot audit. Those quoted included Pavol Rusnak (SatoshiLabs/Trezor co-founder), Laurence E. Day, Christopher Allen and "Seth For Privacy" (Yahoo Finance, 2023-05-19). Ledger's answer was that the service is opt-in and that the firmware must already be trusted anyway.
  • Delay. CEO Pascal Gauthier delayed the launch, called the rollout an "unintentional communication mistake", and promised a whitepaper and open-sourcing of the Recover protocol. CTO Charles Guillemet said it is "an optional subscription" (IBTimes, 2023-05-24). Launch date: October 2023 (unverified).
  • Later offline option. The Ledger Recovery Key is an NFC smart card that stores a PIN-protected backup offline, with no ID checks, for Flex and Stax. It was announced in June 2025 (Cointelegraph, 2025-06-24).

3.3 Other Ledger incidents

  • Ledger Connect Kit, 2023-12-14. A former employee was phished, and their access to Ledger's NPM (JavaScript package) account had not been revoked. The attacker published malicious versions 1.1.5–1.1.7 of a web library used by crypto apps. The code was live about 5 hours and drained funds for under 2 hours. Hardware and Ledger Live were not affected (Ledger incident report). About $610k was stolen, and revoke.cash says Ledger committed to reimbursing victims (revoke.cash). Ledger's own letter does not state a reimbursement amount (Ledger CEO letter).
  • Global-e breach, January 2026. Global-e, Ledger's third-party payment processor, was breached. Customers' names, email, phone, postal addresses and order details were exposed. Ledger says its own systems and recovery phrases were untouched (Gizmodo, 2026-01-07; HG Tech, 2026-01-12). Number affected: not disclosed.
  • Alleged 471,000-record sale, September 2026 (unverified). A forum seller with no reputation offered "Ledger" customer records. The data fields match the 2020 dump, so it may be recycled data. Ledger had not commented as of publication (TheCyberSecGuru, 2026-09-16).
  • CryptoBilis reseller losses, reported 2026-10-09 (developing, cause unconfirmed).
  • On-chain researchers estimate $72–87 million taken from buyers who used CryptoBilis, an official Ledger reseller in Indonesia, Malaysia and the Philippines, within the last 90 days. Arkham's breakdown: about $42M ETH, $17.6M BTC and $16.5M USDT (Decrypt).
  • Ledger asked CryptoBilis to pause all sales. It told recent buyers not to set devices up, and told those who had to "consider moving assets to a new Ledger signer (with new seed)" (The Block; Bitcoin Magazine).
  • Suggested causes include tampered or counterfeit devices, or devices shipped with a recovery phrase the attacker already knew. None is confirmed, and investigator Specter said not every theft may be linked (Decrypt).
  • 2018 Nano S research (unverified). A 2018 report by researcher Saleem Rashid described an attack on the Nano S's non-secure microcontroller (Ars Technica, 2018-03). The page could not be fetched today to confirm details.

Business. Ledger planned a US listing valued above $4 billion but paused before filing, as reported 2026-05-13 (Yahoo Finance). CONTESTED/inconsistent: a 2026-09-02 CoinDesk report lists Ledger among "recently listed" companies with weak aftermarket performance (CoinDesk). I found no confirmation that Ledger listed. On 2026-09-24 Ledger and Payward (Kraken's parent) announced a tie-up for holding tokenized stocks ("xStocks") with Ledger signing (Yahoo Finance).

Insurance. None on the devices. The Recover add-on carries the Coincover clause above.

US regulatory status. Ledger sells hardware and non-custodial software. Under FinCEN's guidance, suppliers of hardware or software tools are "engaged in trade and not money transmission", and a person using an unhosted wallet for their own purchases "is not a money transmitter" (FIN-2019-G001 §§4.2.1, 4.5.1(b)). Recover's regulatory treatment, with three companies holding encrypted shares, was not researched (gap).


4. Trezor (hardware wallets)

Company. SatoshiLabs, Prague. It has been innovating since 2013, made the Trezor Model One in 2014 ("the world's first hardware wallet"), is 100% self-owned with 110+ staff, and authored the BIP39, BIP44 and SLIP39 standards (trezor.io/company).

How it holds keys. Current models are the Safe 3 ($59), Safe 5 ($129) and Safe 7 ($249). All have an EAL6+ certified secure element and open-source firmware, and support 12/20/24-word backups plus "Advanced Multi-share Backup" (Shamir/SLIP-39) (Safe 3, Safe 5, Safe 7, compare). The Safe 7 adds the TROPIC01, which Trezor calls the "world's first auditable Secure Element". It works alongside an EAL6+ Optiga chip, and the Safe 7 uses post-quantum signatures (SLH-DSA-128) for firmware and boot checks (Safe 7).

Security incidents. - 2020-01-31: physical seed extraction on older models. Kraken Security Labs showed that with about 15 minutes of physical access, voltage glitching could pull the encrypted seed out of the Trezor One and Model T microcontroller. A 4-digit PIN then fell to brute force "in under 2 minutes". The flaw is in the chip and "cannot be patched via firmware". The mitigation is a BIP39 passphrase, which is not stored on the device (Kraken blog). Note that a competitor published this. - 2024-01-17: support-portal breach. A third-party ticketing system was accessed, exposing about 66,000 people who had contacted support since December 2021. Phishers then asked victims for their seed phrases. Trezor counted 41 attempts and said no funds were lost (BleepingComputer, 2024-01-22). - August–September 2026: ShipMonk logistics breach. ShipMonk told Trezor on 2026-08-10. The count was first 13,689 customers, later 67,000 in the US. Names, emails, phones, shipping addresses and order numbers were exposed. The attack was attributed to a Metabase SQL-injection flaw and the ShinyHunters gang. Trezor says it had been "repeatedly" assured the data was deleted (The Hacker News, 2026-09-05). The reports disagree. That report gives the exposed orders as dating from November 2019 to August 2021. Another gives orders placed between 2026-05-10 and 2026-08-08 and 81,000 affected (iSec News, 2026-09-10). - September 2026: phishing from a compromised email provider. Attackers sent fake "Critical Security Alert: STM32 Entropy Vulnerability" emails (iSec News). The alleged flaw is the attackers' invention, not a confirmed vulnerability. SPARK-SEARCH ONLY: a headline says a "Brevo breach exposes 347,000 Trezor users to phishing" (betanews.com/article/brevo-breach-trezor-phishing). The page refused access, so this is unverified.

Fees and insurance. The device price is the main cost; no subscription was found. No insurance product was found.

US regulatory status. Same as Ledger: a hardware and software tool supplier, not a money transmitter under FIN-2019-G001 §4.5.1(b). The ShipMonk and other data leaks fall under ordinary breach-notification law. Whether Trezor filed US state notices was not checked (gap).


5. Coinbase (custodial accounts, and the self-custody Coinbase Wallet)

Company. Founded in June 2012 by Brian Armstrong, with co-founder Fred Ehrsam. It says it has over 100 million users and is the largest US-based exchange and largest bitcoin custodian, holding "nearly 12 percent of all bitcoin in existence" (Wikipedia, revision 2026-09-13). It joined the S&P 500 on 2025-05-19 (same source).

5.1 How the custodial account holds keys

  • Coinbase holds the keys. Customer assets "are custodial assets held by Coinbase for your benefit". Title "shall at all times remain with you". The assets "are not property of Coinbase, and are not subject to claims of Coinbase's creditors", and Coinbase "shall retain control over electronic private keys" (User Agreement §2.7, last updated 2026-07-22).
  • Legal framing. Coins are treated as "financial assets" under Article 8 of the Uniform Commercial Code, with Coinbase as "securities intermediary" (§2.7.2). It may use "shared blockchain addresses" and has "no obligation to create a segregated blockchain address" (§2.7.4). It will not lend or pledge customer assets except as listed in the agreement (§2.7.1).
  • Hot wallets. Coinbase says it "generally seek[s] to hold no more than 2% of assets under custody in hot wallets" (Coinbase 10-K for 2025, filed 2026-02-12).
  • Bankruptcy history. In May 2022 Coinbase's 10-Q warned that custodial crypto "may be considered to be the property of a bankruptcy estate" and customers "could be treated as our general unsecured creditors" (Wikipedia, citing the 10-Q). The present Article 8 wording is designed to answer that. Whether it holds up has not been tested in a Coinbase insolvency.

5.2 Coinbase Wallet (self-custody)

  • Who holds the key. Coinbase Wallet is a separate app. The private key "is stored locally on the user's device", and the assets are "self-custodied" (SEC v. Coinbase opinion, pp. 78–80). In practice that means only someone with the device can move funds.
  • Swap fee. Through at least March 2023, Coinbase charged a flat 1% on swaps made through Wallet (same opinion, p. 80).
  • SEC claim dismissed. The court threw out the SEC's claim that offering Wallet made Coinbase an unregistered broker (same opinion, p. 84).
  • Names. Renamed "Base App" in July 2025, then renamed back to Coinbase Wallet in September 2026 (CoinCentral, 2026-09-11).

5.3 Security incidents

Date Incident Source
June 2019 A spear-phishing attack using two Firefox zero-day exploits was detected and blocked. Coinbase says nothing was stolen Wikipedia
2021-03 to 2021-05-20 Account takeovers. At least 6,000 customers had funds removed. Attackers already had email, password and phone, then used "a flaw in Coinbase's SMS Account Recovery process". Coinbase said it would reimburse the full value Coinbase notice filed with California AG
from 2024-12-26, disclosed 2025-05-15 Insider data theft. Bribed overseas support staff took customer data: name, date of birth, last 4 of SSN, masked bank numbers, address, phone, email, images of government ID, balances and history. No passwords, seed phrases or keys. A $20M extortion demand was refused and a $20M reward offered. Coinbase promised to reimburse customers who were socially engineered into sending funds Coinbase notice filed with California AG
(same) 69,461 people per a Maine AG filing; "less than 1% of Coinbase monthly transacting users" The Hacker News, 2025-05-15
(same) Coinbase estimated costs of $180–400 million BleepingComputer, 2025-05-15
2025-06-02 Reuters reported that Coinbase knew of insider leaks at its contractor TaskUs (India) from January 2025, months before disclosure. Coinbase said such access had been "independently detected" in prior months Decrypt summarising Reuters
2025-05-23 A shareholder proposed a securities-fraud class action in E.D. Pa. over the breach and a UK fine (SPARK-REJECTED, see §12) Law360
2025-10 The breach attacker swapped about $5M DAI to USDC, according to ZachXBT. The funds were stolen customer assets (SPARK-REJECTED) Yahoo Finance, 2025-10-02
Jan 2025 Solana withdrawals delayed 14–24+ hours. Users demanded proof of reserves, and some speculated (unverified) that customer SOL was staked without consent Coinpaprika, 2025-01-22

5.4 Fees

From Coinbase's fee disclosure page, archived 2026-09-19 (help.coinbase.com): - Simple buys and sells include a spread plus a Coinbase fee that varies by payment method, size and other factors. Limit orders carry a separate 1% execution fee, and Coinbase "may also charge a 1.875% Coinbase fee (varies by payment method)". - Coinbase Advanced has no spread because you trade on the order book. Its maker/taker rates were not captured (gap). - Coinbase One (subscription) gives "zero trading fees... with certain limitations". - Sending bitcoin off-platform costs an estimated network fee. Lightning sends cost 0.2%. - Storing crypto in the account is free. - Staking commission is 35% standard.

5.5 Insurance

  • Crypto. Not covered by FDIC or SIPC. The User Agreement says "SIPC does not apply to digital assets" and that Coinbase is "not an FDIC-insured bank" (User Agreement). The FDIC itself lists "Crypto assets" as not covered (FDIC, last updated 2024-04-01).
  • Cash (USD) balances. Held in pooled custodial bank accounts set up for pass-through FDIC/NCUSIF cover up to $250,000. That cover is "contingent upon" Coinbase keeping correct records, and Coinbase "owns the interest" on the cash (same agreement).
  • Voluntary reimbursements. Coinbase covered victims in both 2021 and 2025 by choice, not because insurance required it (2021 notice; 2025 notice).
  • Corporate crime insurance. Coinbase took out insurance on online bitcoin in 2014 (Wikipedia). Its current scope was not found (gap).

5.6 US regulatory status

  • Registrations and licences. Registered with FinCEN as a money services business. Money-transmitter licences "in the states where such licenses... are required". A NYDFS BitLicense and a Louisiana virtual-currency licence. Coinbase Custody Trust Company is a New York limited-purpose trust company. Coinbase Financial Markets is a CFTC-registered futures commission merchant, and Coinbase Derivatives Exchange is a designated contract market. Coinbase Capital Markets is an SEC-registered broker-dealer and FINRA member (10-K for 2025). Coinbase got its BitLicense in January 2017 (Wikipedia). The FinCEN registry entry itself was not checked: msb.fincen.gov robots.txt forbids automated queries.
  • SEC v. Coinbase.
  • Filed 2023-06-06. The SEC alleged an unregistered exchange, broker and clearing agency, plus unregistered staking (complaint).
  • 2024-03-27: Judge Failla let the exchange, broker, clearing-agency and staking claims proceed and dismissed the Wallet claim (opinion).
  • Dismissed with prejudice by joint stipulation filed 2025-02-28. The SEC said this was "as a policy matter" after its new crypto task force (stipulation).
  • NYDFS, 2023-01-04. A $50M penalty plus $50M in compliance spending. NYDFS found know-your-customer checks treated as "check-the-box" and a backlog of more than 100,000 unreviewed transaction-monitoring alerts (NYDFS press release).
  • CFTC, 2021-03-19. $6.5M for false or misleading reporting through two in-house trading programs (2015–2018), and for a former employee's Litecoin/Bitcoin wash trades in 2016 (CFTC release 8369-21).
  • IRS "John Doe" summons, 2017-11-28. Coinbase was ordered to produce taxpayer ID, name, date of birth, address and records for accounts with at least $20,000 in any one transaction type in any year 2013–2015. Coinbase said this covered 14,355 account holders and 8.9 million transactions (order).
  • A customer's Fourth Amendment challenge failed: Harper v. Werfel, 1st Cir., 2024-09-24 (opinion).
  • Certiorari was denied on 2025-06-30, with Coinbase among the amici backing Harper (Supreme Court docket 24-922).
  • Abroad. Dutch central bank fine of €3.3M (January 2023) and UK FCA fine of £3.5M (July 2024) (Wikipedia).

6. Kraken (custodial)

Company. Payward, Inc. was founded in July 2011 by Jesse Powell, Thanh Luu and Michael Gronager, and opened to the public in September 2013. Kraken helped the Mt. Gox bankruptcy trustees. It left New York in August 2015, partly because of the BitLicense. Dave Ripley and Arjun Sethi have been co-CEOs since October 2024. It launched the self-custody "Kraken Wallet" in 2024 (Wikipedia, revision 2026-09-09). - IPO. Confidential filing in November 2025, shelved in March 2026, now Q2 2027 at the earliest. - Size. Valued at $20B in a May 2026 round, with 6.6M funded accounts (CoinDesk, 2026-09-02).

6.1 How Kraken holds keys

Customer coins sit in wallets Kraken controls, often pooled "omnibus" wallets, with trades booked off-chain on Kraken's ledger (SEC v. Payward order, p. 3).

CONTESTED: did Kraken mix customer and company money? Kraken denied these allegations (Wikipedia). The SEC's 2023 complaint alleged (complaint ¶¶2, 210–221): - Kraken "has commingled" customer crypto (at times more than $33B) with its own. - Its auditor flagged "a significant risk of loss". - About $33.6M of customer cash sat in Kraken's operating accounts at the end of 2021, and Kraken had paid operating expenses from accounts holding customer cash. - Its terms gave "no warranty" that customer assets were free of liens by Payward's creditors.

The case was dismissed in 2025 without any finding on these points.

Proof of reserves. Latest review 2026-06-30, showing a BTC reserve ratio of 102.9%. Kraken itself says the method "cannot prove exclusive possession of private keys" or rule out borrowed funds (kraken.com/proof-of-reserves).

6.2 Security incidents

  • No theft of customer funds through a Kraken platform hack turned up in the sources reviewed. That is an absence of reports, not proof.
  • May 2025. Kraken and Binance reportedly fought off Coinbase-style attempts to bribe support staff (SPARK-REJECTED) (PYMNTS citing Bloomberg, 2025-05-18).
  • June 2024 (unverified). CertiK researchers reportedly used a Kraken deposit bug to withdraw about $3M, then disputed with Kraken whether this was a bug bounty or extortion. The funds were reportedly returned. No source was fetched today.

6.3 Fees

From the Kraken fee schedule fetched 2026-10-09 (kraken.com/features/fee-schedule): - Kraken app. "1% trading fee on instant and recurring trades" and 1.5% on custom orders, plus spread. Kraken+ members trade free up to $10,000 a month. - Kraken Pro, Tier 1 ($0+ 30-day volume): maker 0.40% / taker 0.80%. At $10K+ it is 0.22% / 0.38%. - Stablecoin pairs: 0.20%. - Withdrawal and payment-method fees vary by method.

6.4 Insurance

Kraken's disclosures say: "Digital assets and Kraken accounts are not covered by insurance against losses. They are not subject to Federal Deposit Insurance Corporation or Securities Investor Protection Corporation protections" (Kraken legal disclosures, last updated 2026-08-11). Kraken Financial (below) says it runs "on a full-reserve basis" (Kraken blog, 2026-03-04).

6.5 US regulatory status

  • FinCEN and state licences. Payward Interactive, Inc. is a FinCEN MSB (registration 31000270997766, NMLS 1843762). Payward Financial, Inc. is too (31000288010248, NMLS 2429615) (Kraken legal disclosures).
  • Oregon: Money Transmitter License #30242, issued by the Oregon Division of Financial Regulation.
  • The licence table has rows for 46 jurisdictions. It has no row for New York, Hawaii, Indiana, Maine, Massachusetts or Montana (my count). Some of those states may not require a licence; New York is the one Kraken left.
  • Virginia's licence "does not cover the transmission of virtual currency".
  • A California Digital Financial Assets Law application is pending (same page).
  • Kraken Financial. Got a Wyoming special purpose depository institution charter in September 2020 (Wikipedia). Kraken says it got a Federal Reserve master account on 2026-03-04, "the first digital asset bank" to do so (Kraken blog). The Fed's own record was not checked (unverified beyond Kraken's statement).
  • SEC staking case, 2023-02-09. Kraken settled for $30M and stopped US staking-as-a-service (complaint; SEC 2023-25). It offered a new US staking product in some states in 2025 (Wikipedia).
  • SEC v. Payward (exchange case).
  • Filed 2023-11-20 (complaint).
  • 2024-08-23: Judge Orrick denied Kraken's motion to dismiss (order).
  • Dismissed with prejudice by stipulation on 2025-03-27. The SEC called this a matter of its "ongoing efforts to reform", not a merits judgment (SEC LR-26278).
  • OFAC, 2022-11-28. $362,158.70 plus $100,000 in compliance spending, for 826 transactions (about $1.68M) between October 2015 and June 2019 by users who appeared to be in Iran. OFAC called the violations non-egregious and voluntarily disclosed (OFAC release).
  • CFTC, 2021-09-28. $1.25M for illegal margined retail trading and acting as an unregistered futures commission merchant, June 2020 to July 2021 (CFTC 8433-21).
  • IRS "John Doe" summons, 2023-06-30. Kraken was ordered to give name, date of birth, taxpayer ID, address, phone, email and transaction records for users with at least $20,000 of transactions in any one year 2016–2020 (order).
  • Australia. Kraken's local operator Bit Trade was fined A$8M in August 2024 (Wikipedia).

7. Fees side by side

Option One-off cost Per-trade cost Ongoing Source
Ballet card $49–$299 network fee when spending none found §2
Ledger $69–$399 network fee. Third-party swap fees in app (not researched) Recover subscription optional, $9.99 a month at launch (unverified) §3
Trezor $59–$249 network fee none found §4
Coinbase none spread + variable Coinbase fee. 1% limit-order fee. Advanced has no spread (maker/taker not captured) Coinbase One optional §5.4
Coinbase Wallet none DEX service fee (1% flat through Mar 2023) none §5.2
Kraken none app 1% (custom 1.5%) + spread. Pro 0.40%/0.80% at the lowest tier Kraken+ optional §6.3

The cost that matters most for a long holder is often not the fee. With self-custody it is the risk of losing the backup; with a custodian it is the risk of the company failing or freezing the account (§10).


8. Insurance and what happens if the company fails

  • Self-custody (Ballet, Ledger, Trezor, Coinbase Wallet). If the company fails, your coins are unaffected as long as you hold the key or backup. If you lose the key, nobody can restore it, except through a paid backup you chose such as Ledger Recover. No device maker found here insures your coins.
  • Custodial (Coinbase, Kraken). No FDIC or SIPC cover for crypto (FDIC; Kraken disclosures). If the company goes bankrupt, what customers get back depends on the terms and on state law:
  • Celsius customers' Earn coins became estate property under Celsius's terms (Celsius opinion).
  • Coinbase's current terms say the opposite: title stays with you, under UCC Article 8 (User Agreement).
  • Kraken's terms, as quoted by the SEC in 2023, gave "no warranty" against creditor liens (SEC complaint ¶215). Its current terms were not reviewed (gap).

9. US regulatory frame

  • Who is a money transmitter.
  • Since 2013 FinCEN has said a "user" of virtual currency "is not an MSB", but an "exchanger" or "administrator" is a money transmitter (FIN-2013-G001).
  • In 2019 it set out the custody test: who owns the value, where it is stored, whether the owner deals with the network directly, and whether the intermediary "has total independent control". Hosted-wallet providers are "account-based money transmitters". Unhosted-wallet users buying for themselves are not, and hardware and software tool suppliers "are engaged in trade" (FIN-2019-G001 §§4.2, 4.5.1(b)).
  • Proposed reporting on unhosted wallets. In December 2020 FinCEN proposed that banks and MSBs keep records and verify identities for some transfers to and from unhosted wallets (85 FR 83840). It was never finalised. FinCEN withdrew it as of 2026-10-06 and said it "will not take any further action on this NPRM" (91 FR 63514, FR Doc 2026-20430). (Completeness check, 2026-10-09: this replaces an earlier "unverified" marker. Full history in legislation/us-federal-fincen-wallet-registration.md.)
  • Tax reporting differs by model. Brokers file Form 1099-DA for digital-asset sales: gross proceeds from 2025, cost basis from 2026 (IRS, page reviewed 2026-06-27). Custodial exchanges are brokers. A wallet you control yourself generates no broker report. You still owe the tax (my reading, not stated on that page).
  • Pending federal self-custody protection. H.R. 3633, the CLARITY Act, says a US individual "shall retain the right to... maintain a hardware wallet or software wallet" for "own lawful custody". It passed the House 2025-07-17 (engrossed text). The Senate Banking Committee reported a rewritten version on 2026-06-01 (Calendar No. 423). That version includes a "Keep Your Coins Act" section barring federal agencies from prohibiting or restricting self-custody "for any lawful purpose" (Senate-reported text, Sec. 605). On 2026-09-15 the Senate rejected cloture on the motion to proceed to H.R. 3633, 49–50 (Roll Call Vote 234) (Senate vote record). It is not law as of 2026-10-09. (Completeness check, 2026-10-09: this replaces an earlier gap note.)

10. The self-custody vs custodial trade-off

Risk Self-custody (Ballet / Ledger / Trezor / Coinbase Wallet) Custodial (Coinbase / Kraken)
Company insolvency Coins unaffected Customers may be creditors. Depends on the terms (Celsius)
Losing your secret Total loss unless backed up. Ballet has no backup at all Account recovery through company ID checks
Phishing and social engineering Seed-phrase phishing after leaks (Trezor 2024: 41 attempts) Account takeover (Coinbase 2021: 6,000+) and impersonation using leaked ID data (Coinbase 2025)
Supply chain Tampered or counterfeit devices or resellers (CryptoBilis 2026, developing). Malicious libraries (Connect Kit 2023) n/a for the customer, but the company's own staff and vendors are an attack surface (TaskUs 2025)
Leaks of who owns crypto Purchase records leak: Ledger 2020, Global-e 2026, Trezor/ShipMonk 2026 Full KYC files leak, including ID images (Coinbase 2025)
Physical coercion A "wrench attack" can force a transfer. CertiK: $124.1M in H1 2026 Harder to force a quick large transfer, but leaked KYC data marks targets
Government access No account to subpoena. Coins on-chain are still traceable IRS John Doe summonses upheld (Coinbase 2017; Kraken 2023; Harper)
Freezes and delays None imposed by a third party Withdrawal delays (Coinbase/Solana 2025). Accounts can be frozen under the terms
Fees Device cost Spreads and trading fees
Tax paperwork No broker 1099-DA 1099-DA from 2025

11. Contested, disputed and fringe claims (kept on purpose)

Claim Who makes it Status
Ledger Recover showed the firmware can export the seed: a "backdoor" Critics in May 2023, incl. Laurence E. Day and Pavol Rusnak (Yahoo, 2023-05-19) CONTESTED. Ledger says it is opt-in, PIN-gated and computed in the secure element (Ledger blog). Both sides agree the user must trust Ledger's closed firmware
Closed-source secure elements (Ledger) can't be independently verified. Open-source designs (Trezor) are safer Trezor/SatoshiLabs and open-source advocates. Trezor markets the Safe 7's "auditable" TROPIC01 as an answer (Trezor) CONTESTED. Trezor's own older open designs were physically extractable (Kraken, 2020)
Pre-generated cards like Ballet's are only as safe as the factory Reviewer (Mantripping, 2026); also implied by BIP38's design notes CONTESTED. Ballet says no single facility or person has both halves (2FKG). No public audit found
Kraken commingled customer assets SEC complaint, 2023 Denied by Kraken. Case dismissed 2025 with no finding
Coinbase customers would be unsecured creditors in a bankruptcy Coinbase's own 10-Q risk factor, May 2022 CONTESTED / superseded. Current terms rely on UCC Article 8. Untested in a Coinbase insolvency
Coinbase Tracer (formerly Coinbase Analytics) helps government surveillance. ICE bought a $1.37M licence in 2021 with "historical geo tracking data" Tech Inquiry FOIA, reported by Bitcoin Magazine (Justin Ehrenhofer, Cake Wallet) (Bitcoin Magazine; GoodIndex) Partly documented. Coinbase says Tracer uses public data and it "does not sell proprietary customer data"
Coinbase is a single point of failure for bitcoin ETFs (custodian for 8 of 11 spot ETFs at launch) Gannett Trust's 2026 CIO report, via CryptoSlate (2026-03-02) Opinion / risk analysis. Counter-view in the same piece: concentration brings consistent controls
Exchanges run fractional reserves Users demanding proof of reserves after FTX (Coinpaprika, 2025-01-22) FRINGE / unproven for Coinbase. Kraken publishes reserve reviews (102.9% BTC, 2026-06-30) but admits their limits
The July 2025 move of $8.6B in 14-year-dormant bitcoin might be "the largest heist in human history" Conor Grogan, Coinbase head of product, who said he was "speculating on straws" (Cointelegraph, 2025-07-05) FRINGE / speculative. No hack confirmed. SPARK-REJECTED
An "STM32 entropy vulnerability" threatens Trezor wallets Attackers' phishing emails, September 2026 (iSec News) FALSE. It was the lure in a phishing campaign
Ledger has already gone public CoinDesk aside, 2026-09-02 Inconsistent with the May 2026 report that Ledger paused its IPO. Unverified
A new 471,000-record Ledger customer database is for sale Anonymous forum seller, September 2026 Unverified. Possibly recycled 2020 data

12. What the Spark run rejected, and whether it should have

The editor asked to include what the Spark rejects. The local Spark run on this topic (20261009-143643--how-do-bitcoin-wallets-compare-hardware-wallets-ledger-trezo) logged these rejections. I followed up each one I could.

Rejected item Spark's reason What it turned out to be
ballet.com/2FKG low relevance score (0.27) Relevant. Ballet's manufacturing process. Used in §2
ballet.com/verify low score (0.09) Relevant. Shows Ballet can recognise its own addresses. Used in §2
Yahoo: "Coinbase exploit hacker swaps $5M" low score (0.27) Relevant. Post-breach laundering of stolen customer funds, Oct 2025. Used in §5.3
Benzinga: "Coinbase knew customer data was at risk in vendor hack months before disclosure" low score (0.18). Page 403 Relevant. Confirmed via Decrypt/Reuters. Used in §5.3
Law360: "Coinbase investor sues over hack fallout, UK fine" low score (0.18) Relevant. Shareholder suit, E.D. Pa., 2025-05-23. Used in §5.3
PYMNTS / Bloomberg: "Binance and Kraken fend off social-engineering hack" low score (0.27 / 0.0) Relevant. Used in §6.2
Cointelegraph: "Bitcoin whale transfer, hack possibility, Coinbase exec speculates" low score (0.18) Speculative. Kept in §11 as FRINGE
help.coinbase.com regulatory-compliance page; coinbase.com; pro.kraken.com low score (0.25) Company pages. The same facts came from the 10-K and Kraken disclosures
cryptowisser.com Trezor prices (Trezor One €69, Model T €149) facts dropped: "quote_absent" Old prices for discontinued models. Current prices are in §4. Treat as historical (unverified)
patents.google.com US10664797B2 low relevance Irrelevant. An Amazon supply-chain ledger patent, not Ballet's
books.google.com results for "Ballet cold storage security" robots.txt refused Not read
IEEE, ACM, SSRN, OUP academic papers on wallet security bot checks / no slot Not read (gap)

12.1 The Spark final report: claims it rejected, and claims that conflict with primary sources

The run finished at 2026-10-09T22:45Z with overall confidence "MIXED". Run research report 20261009-143643--how-do-bitcoin-wallets-compare-hardware-wallets-ledger-trezo to read it. These claims are kept here as the editor asked. None of them is relied on above unless a primary source in this note confirms it.

Spark claim Spark's own verdict Check against primary sources
"Coinbase is licensed as a money transmitter in 48 U.S. states, including New York's BitLicense and Montana licenses" (from a cryptomaniaks.com review) Rejected by its own verifier: "Not supported by the cited evidence" Coinbase's 10-K says licences are held "in the states where such licenses... are required" and confirms the NY BitLicense. The 48-state count and Montana licence are unverified
Hardware-wallet users "control fee settings directly" Rejected by its own verifier In general, wallet software lets users set network fees. Not relied on here
Coinbase's insider data breach was in "May 2023" Listed as "partially supported" Wrong year. The breach began 2024-12-26 and was disclosed 2025-05-15 (California AG notice)
Ledger's 2020 breach came "through its e-commerce partner Shopify" "partially supported" CONTESTED. Ledger blamed an exposed API key on its e-commerce/marketing database (Ledger). Shopify ran the store and was sued alongside Ledger in Baton (9th Cir.). Whether Shopify staff caused the leak was not established in what I read (unverified)
Connect Kit drain was "nearly $500,000" "partially supported"; Spark itself asked whether this was a separate incident Conflicts with revoke.cash's $610k across seven chains. Same incident, different tallies
A TaskUs employee (named in a court filing as Ashita Mishra) kept data on more than 10,000 Coinbase customers on her phone. The Justice Department is investigating. Coinbase faces at least 13 class actions stated as fact (Yahoo-syndicated articles) SPARK-SOURCED, not independently checked (Spark sources 24, 27, 30, 31 in its report)
Ledger "Clear Signing" displays transactions inside the secure element, while Trezor relies on "Blockaid" "partially supported" CONTESTED. The source is Ledger's own "Ledger vs Trezor 2026" article, i.e. a competitor
Supported-asset counts: Ledger 5,500+ or 15,000+; Trezor 1,289–1,456 or 9,000+ stated from review sites Inconsistent between sources. Not used
Kraken+ costs $4.99 a month (fee-free up to $10,000 a month). Coinbase One costs $49.99 a year stated (source: Kraken's own "Kraken vs Coinbase" page) The Kraken+ $10,000 waiver matches Kraken's fee page. Both prices are unverified, and the Coinbase One price comes from a competitor
Ledger Nano S at 1,099–1,442 CZK; Trezor Model T at $170 / €160 from a Czech price-comparison site and an old TechRadar review Old prices for discontinued or older models. Not used
"Kraken has never suffered a major hack" stated (thecryptotime.com review) Consistent with what I found, but it is a review site's claim, not an audit
Ballet security "undocumented in the evidence" Spark's conclusion Spark's searches rejected Ballet's own technical pages (see the table above). They are used in §2

13. Gaps

  • Ballet: no independent review of the 2FKG factories, no patent number, no app-fee schedule, and no regulatory filings found.
  • Ledger: the current Ledger Recover price (only the 2023 launch price, unverified). How Baton v. Ledger ended after remand. Confirmation of the October 2023 Recover launch date and the 2018 Rashid research. The cause of the CryptoBilis losses, which is still developing.
  • Trezor: which of the two ShipMonk accounts is right (exposure window, 67,000 vs 81,000). The "Brevo/347,000" report.
  • Coinbase: Coinbase Advanced maker/taker rates. Current crime-insurance cover. The FinCEN MSB registry entry itself (robots.txt forbids queries). The NYDFS consent-order PDF (Cloudflare block).
  • Kraken: a primary source for the 2024 CertiK incident. Whether the Federal Reserve's own records confirm the master account. Kraken's current terms on creditor liens.
  • Law: (resolved by the completeness check, 2026-10-09) FinCEN's 2020 unhosted-wallet proposal was withdrawn as of 2026-10-06, not finalised (91 FR 63514). On H.R. 3633, the Senate rejected cloture on the motion to proceed, 49–50, on 2026-09-15 (Roll Call Vote 234, 119th Congress, 2nd session) (Senate vote record). No later Senate floor action was found.