COLDCARD RNG incident the public record, collected and explained
Informational only, and this site never asks for your seed words. details

Informational only. This is an open source collection of what others have published about the incident, together with an explanation of it. It is not financial, security or legal advice, and not a substitute for professional advice about your own situation. It is not affiliated with, endorsed by, or speaking for Coinkite. Material is attributed and quoted as published; where sources disagree their scenarios are kept separate with their assumptions rather than reconciled into one answer. Everything is meant to be checked against the linked evidence rather than taken on trust. Act on your own judgement about a particular situation. Editorial standards and corrections.

Do not disclose recovery material to a website, form, message or support account. This site never asks for it, and contributions containing recovery words or private keys are not accepted.

BitBox is not affected

bitbox-not-affected

https://blog.bitbox.swiss/en/bitbox-is-not-affected-by-the-coldcard-rng-vulnerability/

Organisation
BitBox
Evidence role
Vendor statement
Published
2026-07-31
Source changes
0
Detected differences
2
Unreviewed
0
Copies held
3

Every check is recorded, including checks that found no text change. A detected edit is therefore bounded between two checks. The publisher's exact save time is not observable from this record. Last checked .

  1. Earliest copy held
    seen · Captured here 6,982 chars
    Extracted text as captured
    Hardware wallet
    Reviews
    Security
    App
    Blog
    Support
    Shop
    Languages
    Languages
    English
    Deutsch
    Español
    Italiano
    Miscellaneous
    English
    Deutsch
    Español
    Italiano
    Security
    BitBox is not affected by the Coldcard RNG vulnerability
    Addressing questions BitBox users might have in light of the recent Coldcard security advisory.
    BitBox
    31 Jul 2026
    • 4 min read
    We can confirm that the BitBox02 and BitBox02 Nova are not affected by the recent Coldcard seed generation vulnerability. If your wallet was generated on a BitBox hardware wallet, there is no reason to worry.
    Note there is one important exception: If you originally generated your recovery words on an affected Coldcard device and later restored them on a BitBox, the seed itself may still be vulnerable. We explain this distinction below.
    What happened?
    On July 30, 2026, Coinkite warned users about wallet seeds generated on certain Coldcard devices and firmware versions. According to their security advisory, the issue affects:
    Coldcard Mk3 running firmware version 4.0.1 or later
    Coldcard Mk4 and Mk5 before firmware version 5.6.0
    Coldcard Q before firmware version 1.5.0Q
    For more details, see Coinkite’s technical explanation of the vulnerability.
    If you generated a wallet on any of the mentioned devices in the past, and you are still actively using it today, your funds may be at risk. We are mentioning this explicitly, as this can also apply to BitBox users who imported a wallet generated by the affected Coldcard devices on their BitBox.
    In such a case, do not panic and try to remain calm. Your next step should be to create a new wallet on the BitBox and send your funds from the affected wallet to it. Our support team can guide you through the concrete steps if you need help in doing so.
    Why quality of randomness is so important
    Every Bitcoin wallet starts with a large random number.
    The size of this number alone is not enough. It must also be unpredictable, also referred to as “truly random”. If a random number generator produces only a limited or predictable set of results, an attacker can search that much smaller set instead of the full range of possible wallets.
    This is why wallet security depends not only on keeping recovery words private, but also on generating them with sufficient entropy in the first place. We explain this concept in more detail in our article about how hard it is to guess a seed phrase.
    How BitBox generates a wallet seed
    BitBox does not rely on a single random number generator. When a BitBox creates a new wallet, it combines five independent sources of entropy:

    Excerpt only. The complete copy is held offline and backs quotations on this site. The original publication remains the canonical public source.

2 presentation-noise differences. Sidebar, ticker and other page chrome churn that our review classified as not being changes to what the source says.
  • +9 -4 The site's rotating related-post cards and post count changed. The BitBox statement itself did not change.
  • +0 -1 Only site chrome changed: the site-wide footer products list dropped the BitBoxBase entry. The not-affected statement text was unchanged.
How to check this yourself

The excerpts and plain unified diffs above show the text this project held and how it changed. To verify a quotation, compare it against the page itself or against the Internet Archive's copies, which are independent of this project.

Complete captures are held offline rather than mirrored here, so this page shows diffs and excerpts. If a quotation is ever disputed, the full copy can be produced. Ask.