Coldcard vs. Trezor vs. BitBox
This guide used to compare three devices on equal footing. In late July 2026 that changed: a long-standing Coldcard firmware flaw made seeds generated on affected devices guessable, and funds were stolen. Here's what happened, what to do if it affects you, and how the remaining options compare.
Coinkite has shipped fixed firmware and published a security advisory. If your seed was generated on an affected device, the guidance is to move your funds to a newly generated seed on an unaffected device — unless you supplemented the device's entropy from an independent source, or your wallet is protected by a strong BIP‑39 passphrase.
Check coldcard.com for the official advisory and current firmware before acting. Treat this page as a starting point, not the authoritative source. PYMTW will never ask for your seed phrase.
Who this is for
Holders choosing a hardware wallet in the wake of the Coldcard disclosure — and existing Coldcard owners deciding what to do next.
What the breach actually teaches
The failure wasn't a broken chip or a clever physical attack. It was a software build error that quietly weakened seed generation and went unnoticed for more than five years. That points at three specific things worth weighing in any device you consider.
Multiple independent entropy sources
If a device mixes randomness from several unrelated sources, one degraded source can't by itself produce a guessable seed. Single-source designs have no such margin.
Reproducible builds
Open source only helps if the shipped binary provably matches the published source. Reproducible builds — independently verified — are what catch a build error like this one.
Independent security audits
External review by a firm with no stake in the outcome, published openly, with the vendor's remediation response attached.
A passphrase is real protection
Coldcard wallets guarded by a strong BIP‑39 passphrase were reportedly not drained. A passphrase is a genuine second line of defence, not a nicety.
The devices compared
Qualitative positioning — not exact specs or prices. Always confirm current details with the provider.
| Device | Focus | Air-gap | Entropy sources | Status |
|---|---|---|---|---|
| Foundation Passport | Bitcoin-only | Yes (QR, no USB data) | Three, incl. open-source avalanche noise circuit | Unaffected |
| BitBox02 | Bitcoin-only edition available | No (USB); microSD backup | Five, mixed | Unaffected |
| Blockstream Jade | Bitcoin, plus Liquid/Lightning | Yes (QR) | Hardware CRNG drawing on multiple sensors | Unaffected |
| Trezor | Multi-asset and Bitcoin | No (USB) | Device RNG + host entropy | Unaffected |
| Coldcard | Bitcoin-only, advanced | Yes (microSD) | Reduced by 2021–2026 firmware bug | Seeds from Mar 2021 – Jul 2026 affected |
Where each one fits
Foundation Passport
Bitcoin-only and fully air-gapped — it signs over QR codes and has no USB data path at all. Seeds are generated from three independent sources, one of which is an open-source avalanche noise circuit built from ordinary components you can inspect on the board rather than a black-box chip. Open source under GPLv3 with reproducible builds and an independent Keylabs audit. Assembled in the USA with a published supply chain.
Trade-off: higher price, and the QR workflow takes a little getting used to.
BitBox02
Draws on five independent randomness sources and splits secrets across a dual-chip design, so an attacker needs several pieces rather than one. Open source with reproducible builds independently verified by WalletScrutiny, audited by Census Labs, with an active bug bounty. The Bitcoin-only edition keeps the attack surface small.
Trade-off: connects over USB rather than air-gapped, and one of its entropy sources is the host computer (mixed with the others, not relied on alone).
Blockstream Jade
Takes a different route to the same goal. Rather than a proprietary secure element — which ships under NDA and would block full open-sourcing — Jade splits your key material with a "blind oracle" that knows neither your wallet data nor your PIN. Compromising the device alone doesn't yield your keys. The oracle is open source and you can self-host it on a Raspberry Pi rather than relying on Blockstream's. Supports air-gapped QR signing, and it's the cheapest way into a reputable open-source device.
Trade-off: no dedicated secure element, so protection rests on the oracle or a strong passphrase; oracle mode implies a network dependency unless you self-host. Also supports Liquid and Lightning, so it isn't Bitcoin-only in the strict sense. We found no published independent audit.
Trezor
The original hardware wallet, with a long track record, open-source firmware and the gentlest setup of the three. A reasonable entry point if the alternative is leaving coins on an exchange.
Trade-off: models differ meaningfully in their hardware protections — check what the specific model you're buying does and doesn't include before you rely on it for a large balance.
Coldcard
Long regarded as a leading Bitcoin-only air-gapped device, and Coinkite responded to the disclosure within days with patched firmware. But any seed generated on an affected device between March 2021 and July 2026 should be treated as compromised and migrated.
If you own one: follow the official advisory at coldcard.com before anything else.
Advantages and limitations of self-custody
Advantages
- You hold your own keys — no counterparty
- Offline storage resists remote attacks
- Standard seeds keep you portable across devices
Limitations
- You are responsible for backups and recovery
- Mistakes can be permanent
- Vendors can ship bugs — verification and passphrases matter
Self-Custody Without the Fear
Set up any of these devices calmly and correctly — including passphrases and migrating an existing seed.
See the workshopHardware-wallet prep checklist
Everything to have ready before setup.
Get the Starter KitI have a Coldcard. Am I definitely affected?
Does updating the firmware fix my existing wallet?
Which one should I buy now?
Where should I buy?
Is this financial advice?
Last updated: 4 August 2026. Reporting on the Coldcard incident was still developing at the time of writing and loss figures were revised upward more than once. Confirm current details with each provider, and with Coinkite's official advisory, before relying on this guide.