Kostas Chalkias, co-founder and chief cryptographer at Mysten Labs, has revealed he is building affordable quantum-safe two-factor authentication cards for the Sui blockchain. The project puts a fresh spotlight on hardware wallet security at a moment when the sector is dealing with one of its worst-ever exploits.
Sub-$10 Cards, NFC Signatures and a Dedicated Factory
Chalkias has set a target of under $10 per quantum card key and one to two seconds per NFC quantum signature. To reach that at scale, he quietly leased a factory to mass-produce quantum-resistant hardware wallet cards for Sui. The work has been carried out on personal time outside his day job, and Chalkias has said he may go as far as sponsoring cards for users who cannot afford them.
The push fits a broader pattern of quantum preparedness at Mysten Labs. Sui can adopt new authentication methods, including post-quantum cryptography, at the flip of a switch, and Chalkias has said the network was "designed to be quantum-ready from day one." Existing Sui accounts would be able to rotate into a quantum-safe key derived from their existing recovery phrase rather than requiring a full migration to a new wallet. Chalkias holds a PhD in identity-based cryptography and plays a key role in the development of the Sui blockchain and the Walrus decentralised storage layer.
Coldcard Exploit Sharpens the Focus on Wallet Security
Chalkias has cited recent hardware wallet failures as part of his motivation, and the timing is pointed. Beginning July 30, 2026, an attacker exploited a five-year-old firmware flaw in Coinkite's Coldcard hardware wallet to systematically drain bitcoin from affected devices, with the root cause traced to a March 2021 firmware release that caused seed generation to fall back on a weak software random number generator rather than the device's hardware-based source of entropy.
Galaxy Research confirmed 1,596 $BTC stolen across three attack waves, with a suspected fourth wave that could bring the total to approximately 2,055 BTC, worth close to $130 million. At least four waves of theft followed, draining funds from more than 5,200 addresses. The root cause was weak random-number generation dating to a March 2021 firmware build, not a flaw in the Bitcoin protocol itself.
Coinkite shipped emergency firmware for every affected model on July 31, but installing it does not repair an existing seed. Anyone who generated a seed on a Coldcard between March 2021 and the patch should treat it as compromised and migrate to a new seed. The incident has reinforced the case for rethinking how cryptographic keys are generated and secured at the hardware level, the precise problem Chalkias says he is working to address.
Sources:
Bitcoin.com News: Sui Co-Founder Is Building Quantum-Safe Hardware Wallets For $10
TRM Labs: The Largest Hardware Wallet Exploit of 2026, Inside the $116 Million Coldcard Hack
The Hacker News: Coldcard Hardware Wallet Flaw Linked to $70 Million Bitcoin Theft in 41 Minutes
