Guide · Updated August 2026

Coldcard vs. Trezor vs. BitBox

This guide used to compare three devices on equal footing. In late July 2026 that changed: a long-standing Coldcard firmware flaw made seeds generated on affected devices guessable, and funds were stolen. Here's what happened, what to do if it affects you, and how the remaining options compare.

If you own a Coldcard, read this first. Coldcard firmware 4.0.1 (released March 2021) contained a build error that sharply reduced the randomness used to generate wallet seeds. Seeds created on affected devices between March 2021 and the patched firmware released July 31, 2026 can be brute-forced. Affected models reportedly include the Mk3, Mk4, Q and Mk5. More than 1,300 BTC was drained from thousands of addresses beginning 30 July 2026.

Coinkite has shipped fixed firmware and published a security advisory. If your seed was generated on an affected device, the guidance is to move your funds to a newly generated seed on an unaffected device — unless you supplemented the device's entropy from an independent source, or your wallet is protected by a strong BIP‑39 passphrase.

Check coldcard.com for the official advisory and current firmware before acting. Treat this page as a starting point, not the authoritative source. PYMTW will never ask for your seed phrase.
How we compare and affiliate note. This is educational, not investment advice or a recommendation to use any specific product. We don't crown a single "best" — we give you criteria and honest trade-offs. Some links may become affiliate links; PYMTW may earn a commission at no additional cost to you, and compensation does not determine what we list (disclosure). Details change often — confirm current pricing and features on the provider's site.

Who this is for

Holders choosing a hardware wallet in the wake of the Coldcard disclosure — and existing Coldcard owners deciding what to do next.

What the breach actually teaches

The failure wasn't a broken chip or a clever physical attack. It was a software build error that quietly weakened seed generation and went unnoticed for more than five years. That points at three specific things worth weighing in any device you consider.

Multiple independent entropy sources

If a device mixes randomness from several unrelated sources, one degraded source can't by itself produce a guessable seed. Single-source designs have no such margin.

Reproducible builds

Open source only helps if the shipped binary provably matches the published source. Reproducible builds — independently verified — are what catch a build error like this one.

Independent security audits

External review by a firm with no stake in the outcome, published openly, with the vendor's remediation response attached.

A passphrase is real protection

Coldcard wallets guarded by a strong BIP‑39 passphrase were reportedly not drained. A passphrase is a genuine second line of defence, not a nicety.

The devices compared

Qualitative positioning — not exact specs or prices. Always confirm current details with the provider.

DeviceFocusAir-gapEntropy sourcesStatus
Foundation PassportBitcoin-onlyYes (QR, no USB data)Three, incl. open-source avalanche noise circuitUnaffected
BitBox02Bitcoin-only edition availableNo (USB); microSD backupFive, mixedUnaffected
Blockstream JadeBitcoin, plus Liquid/LightningYes (QR)Hardware CRNG drawing on multiple sensorsUnaffected
TrezorMulti-asset and BitcoinNo (USB)Device RNG + host entropyUnaffected
ColdcardBitcoin-only, advancedYes (microSD)Reduced by 2021–2026 firmware bugSeeds from Mar 2021 – Jul 2026 affected

Where each one fits

Swiss

BitBox02

Draws on five independent randomness sources and splits secrets across a dual-chip design, so an attacker needs several pieces rather than one. Open source with reproducible builds independently verified by WalletScrutiny, audited by Census Labs, with an active bug bounty. The Bitcoin-only edition keeps the attack surface small.

Trade-off: connects over USB rather than air-gapped, and one of its entropy sources is the host computer (mixed with the others, not relied on alone).

Best value

Blockstream Jade

Takes a different route to the same goal. Rather than a proprietary secure element — which ships under NDA and would block full open-sourcing — Jade splits your key material with a "blind oracle" that knows neither your wallet data nor your PIN. Compromising the device alone doesn't yield your keys. The oracle is open source and you can self-host it on a Raspberry Pi rather than relying on Blockstream's. Supports air-gapped QR signing, and it's the cheapest way into a reputable open-source device.

Trade-off: no dedicated secure element, so protection rests on the oracle or a strong passphrase; oracle mode implies a network dependency unless you self-host. Also supports Liquid and Lightning, so it isn't Bitcoin-only in the strict sense. We found no published independent audit.

Beginner-friendly

Trezor

The original hardware wallet, with a long track record, open-source firmware and the gentlest setup of the three. A reasonable entry point if the alternative is leaving coins on an exchange.

Trade-off: models differ meaningfully in their hardware protections — check what the specific model you're buying does and doesn't include before you rely on it for a large balance.

Affected

Coldcard

Long regarded as a leading Bitcoin-only air-gapped device, and Coinkite responded to the disclosure within days with patched firmware. But any seed generated on an affected device between March 2021 and July 2026 should be treated as compromised and migrated.

If you own one: follow the official advisory at coldcard.com before anything else.

Security first. Buy hardware only from the manufacturer, generate your own seed on the device, write it down offline, and never type it into a computer or share it — including with PYMTW. Learn the workflow in our Self-Custody workshop.

Advantages and limitations of self-custody

Advantages

  • You hold your own keys — no counterparty
  • Offline storage resists remote attacks
  • Standard seeds keep you portable across devices

Limitations

  • You are responsible for backups and recovery
  • Mistakes can be permanent
  • Vendors can ship bugs — verification and passphrases matter
Free checklist

Hardware-wallet prep checklist

Everything to have ready before setup.

Get the Starter Kit
I have a Coldcard. Am I definitely affected?
Not necessarily — it depends on when and how your seed was generated. Seeds created on affected firmware between March 2021 and the July 2026 patch are at risk. Wallets protected by a strong BIP‑39 passphrase, or where entropy was supplemented from an independent source, were reportedly not drained. Check the official advisory at coldcard.com to confirm your situation rather than guessing.
Does updating the firmware fix my existing wallet?
No. Patched firmware fixes seed generation going forward. It cannot change a seed that was already generated weakly. If your seed came from an affected device, you need to generate a new seed and move your funds to it.
Which one should I buy now?
The best device is the reputable one you'll set up correctly and maintain. If you want Bitcoin-only and air-gapped, Foundation Passport is the closest fit. If you'd rather have simpler USB setup with strong verification, BitBox02. If cost is the barrier or you want everything open source down to the security model, Blockstream Jade. Trezor remains a sensible entry point over leaving coins on an exchange. Whichever you pick, add a passphrase.
Where should I buy?
Only from the manufacturer directly — never a third-party marketplace — to avoid tampered devices.
Is this financial advice?
No. It's educational. See our Educational Disclaimer.

Last updated: 4 August 2026. Reporting on the Coldcard incident was still developing at the time of writing and loss figures were revised upward more than once. Confirm current details with each provider, and with Coinkite's official advisory, before relying on this guide.