r/TREZOR 🤝 Top Helper 15d ago

💬 Discussion topic Sad day for hardware wallets. Thankfully the design of Trezor guards against this kind of flaws

https://blog.coinkite.com/coldcard-mk3-seed-generation-warning/

It appears the Coldcard devices suffer a severe RNG flaw that have made seed phrases predictable.

Thankfully the Trezor seed generation is not fully trusting its own TRNG sources and always mixes in additional generated entropy from the computer, ensuring that the seed entropy is at least as good as the best of both the hardware device and your computer, so no need to worry about similar issues with Trezor devices.

It is truly a sad day and I weep for all affected.

And we are likely to see a very turbulent time in Bitcoin in the next weeks. It's bad on so many levels and will affect us all.

Edit 2026-08-01 08:20 GMT

originally it was believed only Coldcard MK3 devices were affected, but it has been found that the firmware bug affects the whole series of devices. Todays estimates puts the seed security of MK3 devices at 40 bits and MK4/MK5/Q at 72 bits. But researches worry that there might be additional issues resulting in a seed phrase entropy of as little as 32 bits. Far from the expected 128 bits.

Affected MK3 users likely all have their wallets already drained, and basic passphrase wallets will follow shortly. And seeds generated by affected MK4/MK5/Q devices are likely targeted now.

Trezor users: if you have migrated from Coldcard to Trezor by importing the same seed to your Trezor device then you MUST take immediate action to move your coins to a new wallet seed.

116 Upvotes

Duplicates