BitBox is not affected
bitbox-not-affected
https://blog.bitbox.swiss/en/bitbox-is-not-affected-by-the-coldcard-rng-vulnerability/
- Organisation
- BitBox
- Evidence role
- Vendor statement
- Published
- 2026-07-31
- Source changes
- 0
- Detected differences
- 0
- Unreviewed
- 0
- Copies held
- 1
Every check is recorded, including checks that found no text change. A detected edit is therefore bounded between two checks. The publisher's exact save time is not observable from this record. Last checked 2 Aug 2026, 00:59 UTC.
Snapshot and diff bodies for this chain monitor are held in the local evidence archive but withheld from the public site because they can contain victim addresses. Integrity hashes, capture times and reviewed change summaries remain available below.
-
Recovered from the Internet Archive rather than captured by this project. The row records that third-party provenance separately from captures made by this project.
What changed from the previous capture 0 lines
Extracted text as captured
Hardware wallet Reviews Security App Blog Support Shop Languages Languages English Deutsch Español Italiano Miscellaneous English Deutsch Español Italiano Security BitBox is not affected by the Coldcard RNG vulnerability Addressing questions BitBox users might have in light of the recent Coldcard security advisory. BitBox 31 Jul 2026 • 4 min read We can confirm that the BitBox02 and BitBox02 Nova are not affected by the recent Coldcard seed generation vulnerability. If your wallet was generated on a BitBox hardware wallet, there is no reason to worry. Note there is one important exception: If you originally generated your recovery words on an affected Coldcard device and later restored them on a BitBox, the seed itself may still be vulnerable. We explain this distinction below. What happened? On July 30, 2026, Coinkite warned users about wallet seeds generated on certain Coldcard devices and firmware versions. According to their security advisory, the issue affects: Coldcard Mk3 running firmware version 4.0.1 or later Coldcard Mk4 and Mk5 before firmware version 5.6.0 Coldcard Q before firmware version 1.5.0Q For more details, see Coinkite’s technical explanation of the vulnerability. If you generated a wallet on any of the mentioned devices in the past, and you are still actively using it today, your funds may be at risk. We are mentioning this explicitly, as this can also apply to BitBox users who imported a wallet generated by the affected Coldcard devices on their BitBox. In such a case, do not panic and try to remain calm. Your next step should be to create a new wallet on the BitBox and send your funds from the affected wallet to it. Our support team can guide you through the concrete steps if you need help in doing so. Why quality of randomness is so important Every Bitcoin wallet starts with a large random number. The size of this number alone is not enough. It must also be unpredictable, also referred to as “truly random”. If a random number generator produces only a limited or predictable set of results, an attacker can search that much smaller set instead of the full range of possible wallets. This is why wallet security depends not only on keeping recovery words private, but also on generating them with sufficient entropy in the first place. We explain this concept in more detail in our article about how hard it is to guess a seed phrase. How BitBox generates a wallet seed BitBox does not rely on a single random number generator. When a BitBox creates a new wallet, it combines five independent sources of entropy:Excerpt only. The complete copy is held offline and backs quotations on this site. The original publication remains the canonical public source.
Each copy above is identified by the SHA-256 of its extracted text, shown beside it, and the diffs are plain unified diffs. To verify a quotation, compare it against the page itself or against the Internet Archive's copies, which are independent of this project.
Complete captures are held offline rather than mirrored here, so this page shows diffs and excerpts. If a quotation is ever disputed, the full copy can be produced. Ask.
The SHA-256 prefixes above identify each held copy without turning this page into a mirror of somebody else's post. Compare a quotation against the original. If the post has since been edited or deleted, ask and the held copy can be produced.