
A July seed-generation flaw on Coldcard devices drained over 1,000 BTC. The incident reshapes the hardware-wallet trade-off against Ledger and Trezor.
A July firmware vulnerability that weakened seed-generation randomness on Coldcard devices has changed the terms of the hardware-wallet decision for Bitcoin users. Attackers drained more than 1,000 BTC from 1,196 wallets in the initial exploit, with follow-on thefts pushing estimated losses near $100 million, according to on-chain analysis by Block's Bitcoin Engineering team.
The Coldcard Mk5 and Q remain the most specialized Bitcoin-only wallets on the market, built around dual secure elements from different manufacturers, air-gapped signing via MicroSD or QR codes, and advanced multisig features. But the seed-generation flaw – in which certain firmware versions could fall back to a deterministic software random-number generator – cuts at the foundation of wallet security. A recovery phrase created on affected hardware remains weak even after firmware is updated, because the underlying private keys are unchanged. Block's team found that even when secure-element entropy was mixed into the fallback process, the effective entropy could still be severely constrained.
That incident is the most serious hardware-wallet security event in the current generation, because it affected core wallet creation rather than an ecommerce database or a support portal. It also clarifies the trade-offs among the three major manufacturers.
Ledger's current lineup – the Nano Gen5, Flex and Stax – uses CC EAL6+ certified secure elements from STMicroelectronics. The Secure Element stores private keys and performs signing operations, and on the Flex and Stax the display is driven directly by the chip, so a compromised computer cannot alter what the user sees. Ledger supports thousands of assets across Bitcoin, Ethereum, Solana and other chains, plus staking and DeFi access through Ledger Wallet and third-party applications. The ecosystem is the most polished for multi-chain and mobile users.
Ledger's security incidents have been different in kind. A 2020 breach of its ecommerce and marketing systems exposed more than one million email addresses and roughly 272,000 customer records containing names, addresses and phone numbers. That fueled phishing attacks against Ledger customers but did not compromise any hardware wallet's private keys. A December 2023 attack on a former employee's NPM account pushed malicious versions of Ledger Connect Kit, software used by decentralized applications to communicate with wallets. The active draining window lasted less than two hours, Ledger said. Again, the hardware itself was not directly breached.
Trezor has historically prioritized open-source transparency. Its firmware can be inspected and independently built, and the company's Safe range – Safe 3, Safe 5 and Safe 7 – added dedicated secure elements to address physical-extraction attacks that had been demonstrated against older Model One and Model T devices. The Safe 7 goes further with two secure elements (TROPIC01 and OPTIGA Trust M) and a hardened STM32U5 security microcontroller, plus Bluetooth, a large touchscreen and wireless charging. Trezor describes the Safe 7's architecture as "quantum-ready" because post-quantum cryptography is used for firmware verification and device authentication – a claim about the wallet's own code, not about Bitcoin itself.
Trezor's security history includes the physical-extraction attacks on older models, demonstrated by Ledger's Donjon team in 2019 and by Kraken Security Labs in 2020. Kraken estimated that a voltage-glitching attack could extract the encrypted seed with about 15 minutes of physical access; using a strong passphrase could protect funds because the passphrase was not stored on the device. The current Safe generation is built on different silicon and is not affected by that attack. A January 2024 support-portal breach exposed names and email addresses but did not compromise any wallet or cryptocurrency. More recently, researchers demonstrated a laser fault-injection attack against the TROPIC01 secure element; Trezor said the disclosed attack could not reveal the Safe 7 backup, PIN or funds because the device uses several independent security layers.
Coldcard's July 2026 vulnerability is of a different order because it affected the randomness source for wallet generation. The Mk5 and Q remain compelling for Bitcoin users who want air-gapped Partially Signed Bitcoin Transaction signing, trick PINs, SeedXOR, BIP-85 derived wallets, spending policies, and multisig configurations that Ledger and Trezor do not emphasize. But the seed-generation incident means that any user who created a wallet on affected firmware must generate a new backup on clean firmware and transfer funds to new addresses. The existing recovery phrase cannot be repaired.
The practical choice in 2026 depends on what a user holds and how they use it. A multi-chain portfolio with regular DeFi interaction points toward Ledger's secure-element ecosystem and mobile integration. A user who wants open-source verifiability plus modern secure-element hardware – and who holds Bitcoin alongside Ethereum, Dogecoin or stablecoins – fits Trezor's Safe range. A Bitcoin-only user who needs advanced cold-storage controls and is willing to manage the complexity of PSBT workflows may still prefer Coldcard, but must accept that the July incident shows specialized hardware and dual secure elements do not eliminate software risk.
No hardware wallet eliminates all risk. Ledger's breaches were external to the wallet itself. Trezor's older physical attacks required sophisticated access and are not relevant to current devices. Coldcard's seed-generation flaw was embedded in the wallet's own firmware. All three require the user to protect their recovery phrase, verify transactions on the device screen, and keep firmware current.
Drafted by a large language model from the source reporting linked above, then screened by automated publishing checks. It is not read by a journalist before publication. Some articles cite our Alpha Score. Verify prices and figures against the original source. Educational coverage, not personalized advice.