COLDCARD vulnerability what happened, and what to do
Informational only, and this site never asks for your recovery words. details

Informational only. This is independent analysis and an evidence-backed explainer, not financial, security or legal advice, and not a substitute for professional advice about your own situation. It is not affiliated with, endorsed by, or speaking for Coinkite, Block, or any other party named here. Published estimates are attributed, and differing scenarios are kept separate with their assumptions. Act on your own judgement. Editorial standards and corrections.

Do not disclose recovery material to a website, form, message or support account. This site never asks for it. Deliberate recovery on independently verified offline equipment is a separate operation. Seed-word safety.

BitBox is not affected

bitbox-not-affected

https://blog.bitbox.swiss/en/bitbox-is-not-affected-by-the-coldcard-rng-vulnerability/

Organisation
BitBox
Evidence role
Vendor statement
Published
2026-07-31
Source changes
0
Detected differences
0
Unreviewed
0
Copies held
1

Every check is recorded, including checks that found no text change. A detected edit is therefore bounded between two checks. The publisher's exact save time is not observable from this record. Last checked 2 Aug 2026, 00:59 UTC.

  1. Earliest copy held Current
    seen 1 Aug 2026, 00:46 UTC · Captured here text sha256 64d51a3aefdc2c07b58d9a75 6,982 chars
    Extracted text as captured
    Hardware wallet
    Reviews
    Security
    App
    Blog
    Support
    Shop
    Languages
    Languages
    English
    Deutsch
    Español
    Italiano
    Miscellaneous
    English
    Deutsch
    Español
    Italiano
    Security
    BitBox is not affected by the Coldcard RNG vulnerability
    Addressing questions BitBox users might have in light of the recent Coldcard security advisory.
    BitBox
    31 Jul 2026
    • 4 min read
    We can confirm that the BitBox02 and BitBox02 Nova are not affected by the recent Coldcard seed generation vulnerability. If your wallet was generated on a BitBox hardware wallet, there is no reason to worry.
    Note there is one important exception: If you originally generated your recovery words on an affected Coldcard device and later restored them on a BitBox, the seed itself may still be vulnerable. We explain this distinction below.
    What happened?
    On July 30, 2026, Coinkite warned users about wallet seeds generated on certain Coldcard devices and firmware versions. According to their security advisory, the issue affects:
    Coldcard Mk3 running firmware version 4.0.1 or later
    Coldcard Mk4 and Mk5 before firmware version 5.6.0
    Coldcard Q before firmware version 1.5.0Q
    For more details, see Coinkite’s technical explanation of the vulnerability.
    If you generated a wallet on any of the mentioned devices in the past, and you are still actively using it today, your funds may be at risk. We are mentioning this explicitly, as this can also apply to BitBox users who imported a wallet generated by the affected Coldcard devices on their BitBox.
    In such a case, do not panic and try to remain calm. Your next step should be to create a new wallet on the BitBox and send your funds from the affected wallet to it. Our support team can guide you through the concrete steps if you need help in doing so.
    Why quality of randomness is so important
    Every Bitcoin wallet starts with a large random number.
    The size of this number alone is not enough. It must also be unpredictable, also referred to as “truly random”. If a random number generator produces only a limited or predictable set of results, an attacker can search that much smaller set instead of the full range of possible wallets.
    This is why wallet security depends not only on keeping recovery words private, but also on generating them with sufficient entropy in the first place. We explain this concept in more detail in our article about how hard it is to guess a seed phrase.
    How BitBox generates a wallet seed
    BitBox does not rely on a single random number generator. When a BitBox creates a new wallet, it combines five independent sources of entropy:

    Excerpt only. The complete copy is held offline and backs quotations on this site. The original publication remains the canonical public source.

How to check this yourself

Each copy above is identified by the SHA-256 of its extracted text, shown beside it, and the diffs are plain unified diffs. To verify a quotation, compare it against the page itself or against the Internet Archive's copies, which are independent of this project.

Complete captures are held offline rather than mirrored here, so this page shows diffs and excerpts. If a quotation is ever disputed, the full copy can be produced. Ask.