FAQs related to the COLDCARD incident, July 2026
ledger-incident-faq
https://support.ledger.com/article/FAQs-Related-to-the-Coldcard-Incident-July-2026
- Organisation
- Ledger
- Evidence role
- Vendor response
- Published
- 2026-08-07
- Source changes
- 0
- Detected differences
- 0
- Unreviewed
- 0
- Copies held
- 1
Ledger's official incident FAQ, linked from its stickied community-moderator statement. Held as a primary competing-vendor response and as the direct support document behind the moderator post. Security and product claims in it are Ledger's own and are not endorsed by registration.
Every check is recorded, including checks that found no text change. A detected edit is therefore bounded between two checks. The publisher's exact save time is not observable from this record. Last checked .
This post is held twice: here, with this project's own note on why it matters, and again as part of the conversation captured at , which is polled for changes. Both copies are the same post; neither is a separate event.
Snapshot and diff bodies for this chain monitor are held in the local evidence archive but withheld from the public site because they can contain the addresses of people who published nothing themselves. Capture times and reviewed change summaries remain available below.
Held captures
-
Recovered from the Internet Archive rather than captured by this project. The row records that third-party provenance separately from captures made by this project.
What changed from the previous capture 0 lines
Extracted text as captured
This article provides frequently asked questions and answers related to the July 2026 Coldcard incident and explains how Ledger signers generate secure seeds. FAQs Is Ledger affected by the recently published Coldcard Mk3 advisory? Ledger is not affected by the recently published Coldcard Mk3 advisory. Ledger devices use a True Random Number Generator (TRNG) built directly into our Secure Element chip, generating full 256 bits of entropy for every 24-word Secret Recovery Phrase. Please refer to this article for more information. Coinkite has published a security advisory regarding certain Coldcard Mk3 firmware versions - you can read their notice here. How do Ledger signers generate random seeds? The same TRNG principles apply to all Ledger signers, using a true hardware random number generator inside a certified Secure Element, with no software fallback. The generator is compliant with AIS-31/PTG.2, which evaluates the physical entropy source itself rather than just testing whether its output looks random, the distinction that matters, because weak randomness passes output tests. The Secure Element is certified at Common Criteria EAL5+ for Ledger Nano S™ and Ledger Nano X™ and EAL6+ for Ledger Nano S Plus™, Ledger Stax™, Ledger Flex™ and Ledger Nano™ Gen5 and various devices by ANSSI's first-level scheme measuring resistance to cyber attack with random number generation quality explicitly in scope. Producing a predictable random number is listed as Threat #1 in our published security targets, and has been for years. Ledger signer firmware and operating system are reviewed regularly by our internal security team, the Donjon, and undergo recurring evaluation by independent laboratories including EDSI and Synacktiv. This is not a one-time audit. It is an ongoing process, built into how the platform is maintained. Do all Ledger signers follow the same TRNG process? All Ledger signers follow the same TRNG principles, using a true hardware random number generator inside a certified Secure Element, with no software fallback. The generator is compliant with AIS-31/PTG.2, which evaluates the physical entropy source itself rather than just testing whether its output looks random, the distinction that matters, because weak randomness passes output tests. The Secure Element is certified at Common Criteria EAL5+ for Ledger Nano S™ and Ledger Nano X™ and EAL6+ for Ledger Nano S Plus™, Ledger Stax™, Ledger Flex™ and Ledger Nano™ Gen5 and various devices by ANSSI's first-level scheme measuring resistance to cyber attack with random number generation quality explicitly in scope. Producing a predictable random number is listed as Threat #1 in our published security targets, and has been for years. Ledger firmware and operating system are reviewed regularly by our internal security team, the Donjon, and undergo recurring evaluation by independent laboratories including EDSI and Synacktiv. This is not a one-time audit. It is an ongoing process, built into how the platform is maintained. How are Ledger firmware and operating system audited? Ledger firmware and operating system are reviewed regularly by our internal security team, the Donjon, and undergo recurring evaluation by independent laboratories including EDSI and Synacktiv. This is not a one-time audit. It is an ongoing process, built into how the platform is maintained. What ongoing measures does Ledger take to maintain the security of their signers and seed generation? All Ledger signers follow the same TRNG principles, using a true hardware random number generator inside a certified Secure Element, with no software fallback. The generator is compliant with AIS-31/PTG.2, which evaluates the physical entropy source itself rather than just testing whether its output looks random, the distinction that matters, because weak randomness passes output tests. The Secure Element is certified at Common Criteria EAL5+ for Ledger Nano S™ and Ledger Nano X™ and EAL6+ for Ledger Nano S Plus™, Ledger Stax™, Ledger Flex™ and Ledger Nano™ Gen5 and various devices by ANSSI's first-level scheme measuring resistance to cyber attack with random number generation quality explicitly in scope. Producing a predictable random number is listed as Threat #1 in our published security targets, and has been for years. Ledger firmware and operating system are reviewed regularly by our internal security team, the Donjon, and undergo recurring evaluation by independent laboratories including EDSI and Synacktiv. This is not a one-time audit. It is an ongoing process, built into how the platform is maintained. The Ledger Donjon makes heavy use of LLMs to hunt for vulnerabilities in our own products, and it is genuinely effective (see this blog post). The adversary is already doing this at machine speed. So do we, before they do. None of this makes us immune. It makes us measurable, monitored, and independently tested, the same standard that might have caught the failure mode Coldcard experienced. We'd rather be verifiable than merely trusted. Does the Ledger Nano S™ use the same TRNG architecture as newer Ledger signers? All Ledger signers follow the same TRNG principles, using a true hardware random number generator inside a certified Secure Element, with no software fallback. The generator is compliant with AIS-31/PTG.2, which evaluates the physical entropy source itself rather than just testing whether its output looks random, the distinction that matters, because weak randomness passes output tests. The Secure Element in the Ledger Nano S™ was certified at Common Criteria EAL5+ and the Ledger Nano S™ itself was awarded a certificate from ANSSI's first-level scheme in 2019, the first hardware wallet to receive it, measuring resistance to cyber attack with random number generation quality explicitly in scope. Producing a predictable random number is listed as Threat #1 in our published security targets, and has been for years. Ledger firmware and operating system are reviewed regularly by our internal security team, the Donjon, and undergo recurring evaluation by independent laboratories including EDSI and Synacktiv. This is not a one-time audit. It is an ongoing process, built into how the platform is maintained.Excerpt only. The complete copy is held offline and backs quotations on this site. The original publication remains the canonical public source.
0 presentation-noise differences. Sidebar, ticker and other page chrome churn that our review classified as not being changes to what the source says.
The excerpts and plain unified diffs above show the text this project held and how it changed. To verify a quotation, compare it against the page itself or against the Internet Archive's copies, which are independent of this project.
Complete captures are held offline rather than mirrored here, so this page shows diffs and excerpts. If a quotation is ever disputed, the full copy can be produced. Ask.
Compare the screenshot or a quotation against the original while it is available.