I’ve spent the better part of two weeks watching the ColdCard situation unfold in real time, and if you run in Bitcoin self-custody circles the way I do for this publication, you’ve probably felt the same low hum of anxiety I have.
Coinkite, the Canadian outfit behind ColdCard, disclosed on July 30 that a firmware bug dating back to March 2021 had quietly weakened how some of its devices generated wallet seeds. Per the company’s own security advisory, funds controlled by seeds generated on a ColdCard Mk2 or Mk3 running firmware version 4.0.1 through 4.1.9, or on early Mk4, Mk5, and Q releases, turned out to be at risk if the seed wasn’t backstopped by dozens of independent dice rolls or a genuinely strong BIP-39 passphrase. That’s not a minor caveat buried in a changelog. That’s the foundation of self-custody, the randomness behind your seed words, quietly cracked for five years without anyone noticing.
The company was direct about the scope of the damage in its own follow-up post. Coinkite described the days after disclosure as among the hardest in the company’s history, acknowledging that money people had spent years saving was gone and trust that took years to build had broken. On the technical side, blockchain-intelligence firm TRM Labs put real numbers on it in its own analysis: attackers began sweeping bitcoin from ColdCard-secured wallets on July 30, 2026, exploiting a five-year-old firmware flaw, with roughly 1,816 BTC, around $116 million, drained across four waves from more than 5,200 addresses, making it the third-largest crypto hack of the year.

Updating the firmware, crucially, fixes nothing that’s already exposed. Anyone who generated a seed on a ColdCard during the vulnerable window has to treat it as compromised and migrate to an entirely new seed, since patching only protects wallets created after the fix.
That last point is the whole story, as far as I’m concerned. This wasn’t a “install the update and move on” incident. It was a “your money may already be gone, and if it isn’t, you need to move it, today, correctly” incident. And that’s exactly the kind of moment that sends people hunting for a new device.
Why the Panic Is Rational, Not Just Reflexive
I want to push back gently on the framing I’ve seen elsewhere that this is purely FUD-driven migration. It isn’t. Coinkite itself told affected users to move, and it named names while doing it. In the same Sunday update where the company took ownership of the failure, it pointed displaced users toward specific alternatives: anyone who needed a device sooner than Coinkite could provide one, or who wanted an alternative while deciding next steps, was told Bitkey, Ledger, Trezor, Jade, and BitBox were reputable options, while collaborative-custody users were pointed toward AnchorWatch, Casa, Unchained, Nunchuk, and Liana.

That’s genuinely rare. I can’t think of another major hardware wallet vendor that, mid-crisis, published its competitors’ names as safe harbors for its own customers. It’s also why I’m building this piece around exactly those five, rather than the usual “best hardware wallets” listicle framing. This is ColdCard’s own referral list, and it lines up with where the on-chain and community chatter says people are actually going.
One more wrinkle worth flagging before the list, because it’s the part that actually worries me more than the original bug: the scam wave that followed. Security researchers documented phishing campaigns impersonating ColdCard itself, inviting recipients to complete a “coordinated hardware audit” through cloned sites designed to harvest recovery phrases or install remote-access tools. Every single wallet maker I researched for this piece, independently, on their own channels, felt the need to publish a version of “we will never ask for your seed words.” That tells you how ugly the secondary wave got.
1. Ledger — the “we told you so” moment for secure-element purists
Ledger didn’t waste time distancing itself. The company’s own blog post states plainly that it was not affected by the published ColdCard Mk3 advisory, explaining that its devices use a True Random Number Generator built directly into their Secure Element chip, generating a full 256 bits of entropy for every 24-word recovery phrase. Ledger went further in the same post, framing the episode as a referendum on the whole category, arguing that independently certified hardware random number generators are essential to securely creating recovery phrases, and noting that AI is now accelerating how quickly this kind of vulnerability gets found by both defenders and attackers. For Bitcoiners weighing a move, Ledger’s pitch is essentially: don’t trust a vendor’s word on entropy, trust a certification body’s.
2. Trezor — leaning on its “we don’t share that code” defense
Trezor’s response was fast and came straight from its own verified account rather than a press release. Trezor told its users their funds were safe, explaining that the ColdCard issue was limited to Coinkite’s own custom firmware and how some of its devices generated randomness, and that Trezor has always mixed multiple independent sources of randomness, device hardware, host, and secure elements on newer models, rather than relying on a single path. Trezor was also careful to close the loophole people kept asking about: restoring an old seed onto new hardware doesn’t cleanse it.
The company warned that if a seed was generated on an affected ColdCard and later moved to a Trezor, it remains affected, because the weak randomness was baked in at creation and simply carrying the words to a new device does nothing to fix that. As the phishing wave built, Trezor pushed a second, blunter warning:
Following the disclosure, the company said it was already seeing a rise in phishing attempts, and reminded users never to share a wallet backup, to only enter one directly on a Trezor device during recovery, and to ignore any wallet-migration instructions arriving by unsolicited email, message, or phone call.
3. Blockstream Jade — leading with an actual migration script
Of everyone on Coinkite’s list, Blockstream’s response reads the most like a rescue manual rather than a press statement, and I mean that as a compliment. The company’s own blog post confirms its Jade lineup is unaffected, and rather than stopping at reassurance, lays out four concrete steps: generate a brand-new wallet without restoring the old recovery phrase, move the full balance over immediately, never type a recovery phrase into any website or “checker” tool, and get a Jade to move to cold storage on freshly generated keys. The company was also unusually transparent about why it feels confident making that claim. Jade builds its entropy by hashing together timing from user interaction, CPU counters, uninitialized memory, the prior state of its entropy pool, a built-in hardware random number generator, and entropy contributed by the companion app, with the higher-tier Classic and Plus models adding battery readings and boot-time camera images. That layered-sourcing argument, no single point of entropy failure, is precisely the design philosophy that ColdCard’s own advisory shows was missing in the vulnerable path.
4. BitBox — the “no reason to worry” camp, with one exception spelled out clearly
Shift Crypto’s BitBox team issued a short, confident statement, but didn’t gloss over the one scenario that actually matters for anyone considering a move. BitBox confirmed the BitBox02 and BitBox02 Nova are not affected by the ColdCard seed-generation vulnerability, and told users whose wallets were generated on a BitBox device there’s no reason to worry, with one important exception: anyone who originally generated their recovery words on an affected ColdCard and later restored them onto a BitBox may still be carrying a vulnerable seed. It’s a small distinction, but it’s the one that trips people up most in every one of these advisories, and I appreciated that BitBox didn’t bury it.
5. Bitkey — the outlier structurally, and Coinkite’s most unconventional recommendation
Bitkey is the odd one out here, and worth pausing on, because its architecture sidesteps the entire category of bug that hit ColdCard. In its own blog post, Bitkey confirms it does not use the software involved in the reported ColdCard issue, explaining that it uses three keys created in three separate environments, hardware, phone, and server, so moving funds requires two of the three, and none of those key-generation paths were compromised. Bitkey’s team also addressed the “should I move to you” question head-on for existing ColdCard users: setting up a Bitkey wallet creates entirely new keys and does not import a ColdCard seed phrase, meaning current Bitkey users don’t need to take any action because of the reported issue. Whether a 2-of-3, app-and-server-involved model appeals to a hardened self-custody purist is a separate argument but as a landing pad for someone in a panic who just wants something that demonstrably isn’t the affected codebase, I understand why Coinkite listed it.
The Number I Went Looking For and Couldn’t Find
I went looking for the obvious follow-up number, how many people actually landed on each of these five and came up empty. Ledger, Trezor, BitBox, Blockstream, and Bitkey have all published security guidance; none has published a device-activation count, a sales figure, or even a percentage-growth claim tied to the ColdCard window. The only official, company-sourced number in this entire story belongs to Coinkite itself, and it’s a supply-side one: per the same Sunday update, the company halted all ColdCard shipments the moment the vulnerability was confirmed and destroyed its remaining in-house inventory built on the affected firmware, telling customers who’d already received orders that it was reaching out directly with advisory and migration steps rather than continuing to sell into the problem. That’s real, and it’s official, but it tells you what ColdCard stopped shipping, not what anyone else started selling.
Everything else circulating as “proof” of migration comes from analytics firms and exchanges describing bitcoin in motion, not hardware makers describing who caught it, useful signals, but not a Ledger or Trezor or Bitkey press release with a number in it.
Six Wallets, Side by Side
Before I build this out as a proper infographic, here’s the flat comparison, ColdCard as the wallet at the center of the story, plus the five names Coinkite itself pointed displaced users toward. Every detail below is pulled straight from each company’s own advisory, linked above.

One thing worth sitting with once you look at it laid out this way: ColdCard is the only device on this list that was, by design, supposed to sit in the same “single hardware TRNG” camp as Ledger and the bug was specifically that its firmware stopped doing what its own architecture promised. Everyone else on the list leans on multiple entropy sources stitched together (Trezor, Jade) or shifts the trust model entirely away from a single seed (Bitkey’s multisig split). That’s not a coincidence in how Coinkite’s own list reads, it’s basically a lineup of “the other ways to not have a single point of failure.”
Where I’ve Landed on It
I’m not going to tell you which of the six to buy, because that decision genuinely depends on your threat model, your comfort with air-gapped QR workflows versus USB, and whether you want a secure element, multiple entropy sources, or a multisig-style split custody model instead of a single seed at all. What I will say, as someone who’s read every one of these advisories in full rather than skimming the headlines, is that the honest answer to “which cold wallet is safe now” is the same one Trezor, BitBox, Blockstream, Ledger, and Bitkey all gave independently, in their own words, on their own channels: verify everything on the device screen, generate fresh, never restore a ColdCard-origin seed as-is, and treat any unsolicited “migration help” as the scam it almost certainly is. The rest, which brand, which form factor, is genuinely a personal call, and it deserves better data than any of us currently have to make it with.
Disclosure: This is not trading or investment advice. Always do your research before buying any cryptocurrency or investing in any services. Follow us on X @nulltxnews







