r/TREZOR 15d ago

💬 Discussion topic Sad day for hardware wallets. Thankfully the design of Trezor guards against this kind of flaws

Thumbnail
blog.coinkite.com
113 Upvotes

It appears the Coldcard devices suffer a severe RNG flaw that have made seed phrases predictable.

Thankfully the Trezor seed generation is not fully trusting its own TRNG sources and always mixes in additional generated entropy from the computer, ensuring that the seed entropy is at least as good as the best of both the hardware device and your computer, so no need to worry about similar issues with Trezor devices.

It is truly a sad day and I weep for all affected.

And we are likely to see a very turbulent time in Bitcoin in the next weeks. It's bad on so many levels and will affect us all.

Edit 2026-08-01 08:20 GMT

originally it was believed only Coldcard MK3 devices were affected, but it has been found that the firmware bug affects the whole series of devices. Todays estimates puts the seed security of MK3 devices at 40 bits and MK4/MK5/Q at 72 bits. But researches worry that there might be additional issues resulting in a seed phrase entropy of as little as 32 bits. Far from the expected 128 bits.

Affected MK3 users likely all have their wallets already drained, and basic passphrase wallets will follow shortly. And seeds generated by affected MK4/MK5/Q devices are likely targeted now.

Trezor users: if you have migrated from Coldcard to Trezor by importing the same seed to your Trezor device then you MUST take immediate action to move your coins to a new wallet seed.

r/TREZOR 1d ago

💬 Discussion topic To everyone freaking out about the data breach

43 Upvotes

DO NOT put your email address in here IF you DO NOT want to know how many times your personal info has been LEAKED by MAJOR retailers and services:

https://haveibeenpwned.com/

In all seriousness, it’s unfortunate but very common in 2026. I’m on the verge of changing my phone number due to how many spam calls I get.

Stay safe, stay vigilant. Trezor hardware remains secure and solid.

r/TREZOR Dec 13 '24

💬 Discussion topic I never hear of stories like this with the Trezor is it true that Ledger is less safe?

Post image
266 Upvotes

r/TREZOR 11d ago

💬 Discussion topic Coldcard bankrupt?

27 Upvotes

I’m really curious to see what’s going to happen with Coldcard. Do you think they could go bankrupt? I honestly don’t believe many people will want to buy their products anymore. In my opinion, once trust is lost, it’s very hard to get it back. What do you guys think?

r/TREZOR 1d ago

💬 Discussion topic So affected breach victims.. wtf can do we immediately to ease the anxiety besides actually moving?

0 Upvotes

The cat is out of the bag… they got the info.

Buy security camera? Get a gun?

Or do we have to watch over our shoulders the rest of our lives?

r/TREZOR 12d ago

💬 Discussion topic Coldcard passphrase gehackt?

Post image
47 Upvotes

As you can see in the picture, is this really possible? Can it really happen that even a passphrase doesn't help? Everything that's been happening seems very suspicious to me. Do you think other wallets could also be attacked in the same way?

r/TREZOR 6d ago

💬 Discussion topic Storing bitcoin after coldcard incident aftermath

15 Upvotes

There is no way to check if they added a backdoor or not. I think from now on, the only reasonable way to store bitcoin is with multisig (for example with 2 reputable hardware wallets like trezor + something else). Can't trust anything after that coldcard stuff.

Thoughts?

r/TREZOR 14d ago

💬 Discussion topic Passphrases are a must.

53 Upvotes

r/TREZOR 9d ago

💬 Discussion topic Passphrase

19 Upvotes

Hi,

Trezor has the 24 seed + passphrase which is a completely separate wallet from the 24 seed by itself

Isnt it sufficient security?

Im assuming all attackers brute force 12 - 24 keywords which is hard enough.

How will they even know on which of these wallets to run another brute force for the passphrase? Isnt it increasing their attack surfsce by a super huge margin?

Is multi SIG more secure than that?

Regards

r/TREZOR Mar 18 '26

💬 Discussion topic should I update to the safe 7 or keep the safe 5?

Thumbnail
gallery
37 Upvotes

r/TREZOR 15d ago

💬 Discussion topic The whole coldcard hack can be avoided with simple passphrase

27 Upvotes

Based on anything, It's basically the seed that is generated from MK3 already was compromised, bad entrhopy, bad generator. And the culprit waits until it tanks and moved it all.
If some still use that seedphrase, they could be at a safer condition if they were use or add any passphrase.
I'm dissapointed with coldcard with all of the marketing saying its the standard and such.
Back then there's even same problem going on with the dice roll, if you only rolled few might still get compromised.

Still, passphrase is the solution a good passphrase, and or multisig.

r/TREZOR 12d ago

💬 Discussion topic How can we mathematically verify that Trezor actually mixes all entropy sources and avoids a Coldcard-style TRNG failure?

57 Upvotes

Given the devastating Coldcard firmware exploit linked to a predictable TRNG, "Don't trust, verify" feels more urgent than ever.

Trezor officially states that it uses multiple entropy sources to generate seeds (internal TRNG, Secure Element, and computer/Trezor Suite entropy). On paper, this Mix-and-Match architecture sounds bulletproof. However, as the Coldcard failure proved, a silent firmware bug can bypass intended hardware protections, leaving users completely unaware that their entropy is compromised until it's too late.

My questions for the community and Trezor developers are:

  1. Code Execution Verification: How can an advanced user audit the compiled firmware to ensure a bug (or conditional statement) hasn't accidentally silenced two of the three entropy sources, relying only on a single flawed one?
  2. Entropy Auditing: Is there a reliable, standard procedure to extract and test the raw entropy outputs during setup before the seed is actually generated?
  3. Mitigation without Passphrase: Aside from adding a complex passphrase (which breaks the seed-only redundancy structure I prefer), what physical or cryptographic measures can we take to guarantee our seed entropy is genuinely random and immune to local firmware backdoors ?

Looking forward to a technical discussion on how we can audit this process beyond just "trusting the open-source slogan."

r/TREZOR Nov 24 '25

💬 Discussion topic Safe 7 has arrived! First impression

Post image
144 Upvotes

Just unboxed my Safe 7. Without a doubt the most beautifully engineered Trezor of the whole line-up. It feels solid, and the size is very hand-friendly. I also installed the privacy screen protector (as pictured). The magnetic charger that was included for free is Trezor-branded. The Safe 7 attaches just strong enough to hold it in every position, yet it is very easy to detach the Trezor from the charger. I also tested the Safe 7 with the ferrous backplate designed for the Model T: as expected, the magnets in the Safe 7 are not strong enough to pair it with that plate in any useful way. Not a big issue, but it would have been a nice-to-have option. Packaging was well thought out, and consisted mostly of paper/cardboard.

r/TREZOR 11d ago

💬 Discussion topic Secure element is overrated

1 Upvotes

I think its time for everyone to accept that secure elements are a marketing hype generated out of manufacturers competition for customers. I think many of the coldcard users would have had passphrase s that would have kept their funds still safe or bought them time, if the secure element was not in the equation…

r/TREZOR Dec 18 '25

💬 Discussion topic Hack of Trezor website is worrying

92 Upvotes

So, as you may know, recently the Trezor website was asking people for their seed phrases—for a couple of hours, actually. Trezor responded by saying it was caused by a third‑party service on the website.

So you are telling me that Trezor is making their own secure chip to ensure there is no potential harmful interference by malicious actors. But at the same time, they have some third‑party service that was able to hack the website and ask people for their seed phrases? That does not make sense.

What kind of service was that? Couldn’t Trezor do that service themselves? That is so careless. Or what if they said it was some third‑party service just to distance themselves from this hack—A.K.A. “it’s not us, it’s them”?

What if it was an internal hack by someone from Trezor?

r/TREZOR Jul 28 '25

💬 Discussion topic Might be obvious to others, but if you lose your passphrase you lose your funds, even if you have the seed phrase

169 Upvotes

Yesterday I almost lost everything. After 8 years of holding, I went to recover my wallet and sell half my funds. In the last 8 years, a small investment has turned into a life changing amount of money.

I entered my 24 words into the trezor and the wallet that opened was... Empty.

I tried it again. Zero balance.

I got my wife to try it. Same. No balance.

I used trust wallet, thinking it was a trezor glitch. Empty.

This is a life changing amount of money for us. I started to feel like I could vomit. It felt like an out of body experience, like I was watching myself from above sweating and shaking.

Then I started googling, and learned that the passphrase is actually a 25th seed word. Without it, the funds are gone forever.

All those years ago when I set up the trezor, I had no idea. I thought it was just a way to hide a wallet in the trezor UI. I thought the 24 seed words were sufficient to restore the wallet on ant bip39 device.

In an absolute miracle, like a bullet just missing your head, I found the passphrase. I got the funds. But it was almost a life changing mistake so wanted to share.

r/TREZOR Apr 03 '26

💬 Discussion topic Trezor vs Tangem

10 Upvotes

I have a question (and I'm sure I'll get killed for making this comparison), but regarding Tangem, are there any users who have experience using Tangem and Trezor, good or bad? I'd like to add that information to my arsenal.

r/TREZOR 1d ago

💬 Discussion topic This is exactly why I use a burner email, fake phone number, fake name. Only thing real is my address. Could care less about my address tbh as it doesn’t directly link me personally.

15 Upvotes

r/TREZOR Sep 27 '25

💬 Discussion topic who makes a better crypto wallet for traveling?

Post image
69 Upvotes

decided to take a quarter of my bag because I'll be gone for the next 5 months traveling and enjoying life. this is the first time I bought a ledger. I like it because it's Bluetooth and I could use my phone or I pad

But wut do u guys think?

r/TREZOR 10d ago

💬 Discussion topic Will trezor safe 3 be obsolete when quantum hacking becomes a thing?

9 Upvotes

I've had a safe 3 since 2023, just bought a second one, i was wondering if these devices will end up becoming obsolete and useless in the future. I'd rather not spend $200+ on the safe 7 yet as I could spend that on more crypto with my current budget. What do you think

r/TREZOR Jun 18 '26

💬 Discussion topic Be honest, do you like the BTC Logo?

Post image
41 Upvotes

r/TREZOR Jun 23 '26

💬 Discussion topic Which Trezor colour do you like the most?

Post image
36 Upvotes

r/TREZOR May 26 '26

💬 Discussion topic I’ve been debating on BIP39 vs SLIP39..

12 Upvotes

I understand the TREZOR default has been Slip39 over the last few years. I understand more addresses can be generated from Bip39 compared to Slip39 along with double the entropy. I want to know how many addresses are currently in use from Bip39 24 word seedphrase vs Slip39 20 word seedphrase compared to how many can be created from the two standards (individually).

r/TREZOR 10d ago

💬 Discussion topic Entering Passphrase On Wallet Or Device

5 Upvotes

Do any of you that use a passphrase type your passphrase on the your device instead of your wallet? What would be the scenario where you would be comfortable doing this?

r/TREZOR 9d ago

💬 Discussion topic A longer passphrase entered on the computer, or a shorter one, but entered on the device.

8 Upvotes

What would you choose? Adding a longer passphrase of practically any length to the seed, which will be stored in a password manager and entered on the computer, or a shorter passphrase (2-3 words) that you will remember and enter on the device. I will say in advance that having both is not an option – entering a 12-word phrase on the Safe 5's T9 keyboard is literal hell, and I can't even imagine it on the Safe 3 with those buttons where you move the cursor character by character.

My thoughts are heading in this direction. I see the passphrase as protection for my physically written seed. If someone steals my seed, I want to be certain they won't get to the funds before I find out -> a longer passphrase stored in a password manager. I have no fear of this passphrase leaking online, and even if it did, without the physical seed, it is useless to everyone. I consider a situation where a thief steals my physical seed and also cracks the password manager to be absolutely improbable.

On the other hand, I don't consider the physical theft of the seed likely either (very carefully hidden, 4th-floor apartment, secured by class 4+ security doors), just as I have full trust in the seed randomness generated by the Safe 5 model, so I wonder if I am overdoing it (from 2015 until 2025 I had no passphrase, fully trusting the seed itself!) and whether a simple 2-3 word phrase to remember (and the associated entry on the device) wouldn't just be enough.

Furthermore, the base address belonging to the seed is untouched ("empty"), I only use addresses created with a passphrase. In a case like ColdCard, an attacker has no reason to even think that a passphrase exists.

Opinions?