r/Bitcoin: Trezor's incident-response email to its users
reddit-trezor-user-alert-email
https://www.reddit.com/r/Bitcoin/comments/1vepzf1/trezor_just_woke_up_and_alerted_its_users_by_this/
Latest reviewed change
source content difference between and
Two comments by the same author comparing Trezor entropy redundancy to COLDCARD were removed by Reddit, with the author shown as [deleted] and the bodies as [removed].
comment: p1j7ryj
parent: t1_p1izh9g
-author: 0fWhomIAmChief
+author: [deleted]
created_utc: 1785794106
edited: false
body:
First lines only. The complete diff is in the timeline below.
- Organisation
- Evidence role
- Community discussion
- Published
- not established
- Source changes
- 9
- Detected differences
- 9
- Unreviewed
- 0
- Copies held
- 10
Every check is recorded, including checks that found no text change. A detected edit is therefore bounded between two checks. The publisher's exact save time is not observable from this record. Last checked .
This post is held twice: here, with this project's own note on why it matters, and again as part of the conversation captured at , which is polled for changes. Both copies are the same post; neither is a separate event.
Snapshot and diff bodies for this chain monitor are held in the local evidence archive but withheld from the public site because they can contain the addresses of people who published nothing themselves. Capture times and reviewed change summaries remain available below.
Held captures
-
Two comments by the same author comparing Trezor entropy redundancy to COLDCARD were removed by Reddit, with the author shown as [deleted] and the bodies as [removed].
Recovered from the Internet Archive rather than captured by this project. The row records that third-party provenance separately from captures made by this project.
What changed from the previous capture 16 lines
comment: p1j7ryj parent: t1_p1izh9g -author: 0fWhomIAmChief +author: [deleted] created_utc: 1785794106 edited: false body: -Coldcard had 0 entropy redundancy, Trezors have 3 or 4 sources of entropy redundancy +[removed] comment: p1ja82c parent: t1_p1izlz0 In the BTC world, the random variable Z generates a seed phrase, and it must have high entropy to not be reverse engineered. -comment: p1jo9hp -parent: t1_p1jd3gs -author: 0fWhomIAmChief -created_utc: 1785799081 -edited: false -body: -https://trezor.io/guides/trezor-devices/trezor-fundamentals/what-is-entropy-and-how-does-trezor-generate-your-wallet - comment: p1joz0x parent: t1_p1j7ryj author: cilicia3k3 comment: p1jyq0q parent: t1_p1joz0x -author: 0fWhomIAmChief +author: [deleted] created_utc: 1785802418 edited: false body: -https://trezor.io/guides/trezor-devices/trezor-fundamentals/what-is-entropy-and-how-does-trezor-generate-your-wallet +[removed] comment: p1jyvzz parent: t1_p1jyq0qExtracted text as captured
post: 1vepzf1 author: paco_1987 created_utc: 1785791157 title: Trezor just woke up and alerted its users by this email body: I am surprised it took them so long to send emails to their users. "Important: Trezor is not affected by the Coldcard hardware wallet vulnerability. Trezor users: your funds are safe. Hi, On July 30, Coinkite disclosed an issue affecting wallets generated by certain versions of Coldcard firmware. Trezor devices are not affected. Coldcard’s issue relates to the way certain devices generate randomness when creating a wallet. Trezor does not use Coldcard’s firmware or code. Trezor generates wallets using multiple independent sources of randomness, including device hardware, the connected host and, on newer models, Secure Element chips. With our entropy check feature, you can also verify that your wallet backup is generated randomly. Who may need to take action You may be affected if: Your wallet was originally generated on an affected Coldcard device You later recovered or imported that same backup created on the Coldcard onto a Trezor Moving a wallet backup to a different device does not change the backup itself. If this applies to you, follow Coinkite’s official guidance and migrate your funds to a newly generated wallet backup as soon as possible. Take care to verify every step before moving funds. Please share this information with anyone you know who may use a Coldcard hardware wallet. Stay alert for scams Security events often lead to phishing attempts designed to create fear and urgency. Please remember: Never share your wallet backup, aka recovery seed (12/20/24 words)Excerpt only. The complete copy is held offline and backs quotations on this site. The original publication remains the canonical public source.
-
The thread gained a sub-thread in which a commenter claims Trezor added a back door in a firmware update over a year ago and moved to Passport, and another replies that it sounds concerning but asks no further questions.
Recovered from the Internet Archive rather than captured by this project. The row records that third-party provenance separately from captures made by this project.
What changed from the previous capture 26 lines
edited: false body: Please elaborate for us ? Very courious to hear about this + +comment: p2a5pwe +parent: t1_p2778s6 +author: Btcmot +created_utc: 1786116180 +edited: false +body: +Over a year ago, Trezor did an update to their firmware that included what is equal to a back door to their software and your Trezor. They had some bs explanation why but I did not accept the update and as fast as I could picked a different wallet and moved away from Trezor. Im not a techy but i can’t afford to trust a company that wants the ability to get into my wallet stash. + +And because you will ask, i moved to Passport. Its not the most convenient but it is a Bitcoin only wallet ( my first rule) and its had a great reputation so far. + +comment: p2a68yp +parent: t1_p2a5pwe +author: 7thlttd +created_utc: 1786116315 +edited: false +body: +Thanks for the reply man appreciate it . That def sounds concerning for sure + +comment: p2a7keu +parent: t1_p2a68yp +author: Btcmot +created_utc: 1786116648 +edited: false +body: +Sorry i cant explain the specific change, but its worth not using them.Extracted text as captured
post: 1vepzf1 author: paco_1987 created_utc: 1785791157 title: Trezor just woke up and alerted its users by this email body: I am surprised it took them so long to send emails to their users. "Important: Trezor is not affected by the Coldcard hardware wallet vulnerability. Trezor users: your funds are safe. Hi, On July 30, Coinkite disclosed an issue affecting wallets generated by certain versions of Coldcard firmware. Trezor devices are not affected. Coldcard’s issue relates to the way certain devices generate randomness when creating a wallet. Trezor does not use Coldcard’s firmware or code. Trezor generates wallets using multiple independent sources of randomness, including device hardware, the connected host and, on newer models, Secure Element chips. With our entropy check feature, you can also verify that your wallet backup is generated randomly. Who may need to take action You may be affected if: Your wallet was originally generated on an affected Coldcard device You later recovered or imported that same backup created on the Coldcard onto a Trezor Moving a wallet backup to a different device does not change the backup itself. If this applies to you, follow Coinkite’s official guidance and migrate your funds to a newly generated wallet backup as soon as possible. Take care to verify every step before moving funds. Please share this information with anyone you know who may use a Coldcard hardware wallet. Stay alert for scams Security events often lead to phishing attempts designed to create fear and urgency. Please remember: Never share your wallet backup, aka recovery seed (12/20/24 words)Excerpt only. The complete copy is held offline and backs quotations on this site. The original publication remains the canonical public source.
-
Two new comments: one says Trezor posted a multi-post statement about the incident on X the day it happened, another asks an earlier commenter to elaborate.
Recovered from the Internet Archive rather than captured by this project. The row records that third-party provenance separately from captures made by this project.
What changed from the previous capture 16 lines
edited: false body: Use a passphrase or just buy the ETF… This is 2026 not 2016. + +comment: p23tgph +parent: t1_p1krtag +author: FirmRain6748 +created_utc: 1786039064 +edited: false +body: +They put a massive multi post thing about it on their X basically the day it happened + +comment: p2778s6 +parent: t1_p1k3kr4 +author: 7thlttd +created_utc: 1786075389 +edited: false +body: +Please elaborate for us ? Very courious to hear about thisExtracted text as captured
post: 1vepzf1 author: paco_1987 created_utc: 1785791157 title: Trezor just woke up and alerted its users by this email body: I am surprised it took them so long to send emails to their users. "Important: Trezor is not affected by the Coldcard hardware wallet vulnerability. Trezor users: your funds are safe. Hi, On July 30, Coinkite disclosed an issue affecting wallets generated by certain versions of Coldcard firmware. Trezor devices are not affected. Coldcard’s issue relates to the way certain devices generate randomness when creating a wallet. Trezor does not use Coldcard’s firmware or code. Trezor generates wallets using multiple independent sources of randomness, including device hardware, the connected host and, on newer models, Secure Element chips. With our entropy check feature, you can also verify that your wallet backup is generated randomly. Who may need to take action You may be affected if: Your wallet was originally generated on an affected Coldcard device You later recovered or imported that same backup created on the Coldcard onto a Trezor Moving a wallet backup to a different device does not change the backup itself. If this applies to you, follow Coinkite’s official guidance and migrate your funds to a newly generated wallet backup as soon as possible. Take care to verify every step before moving funds. Please share this information with anyone you know who may use a Coldcard hardware wallet. Stay alert for scams Security events often lead to phishing attempts designed to create fear and urgency. Please remember: Never share your wallet backup, aka recovery seed (12/20/24 words)Excerpt only. The complete copy is held offline and backs quotations on this site. The original publication remains the canonical public source.
-
New comment from BigvalBROski advising using a passphrase or just buying the ETF.
Recovered from the Internet Archive rather than captured by this project. The row records that third-party provenance separately from captures made by this project.
What changed from the previous capture 8 lines
edited: false body: Fundsas’ar’safu + +comment: p21i3pi +parent: t3_1vepzf1 +author: BigvalBROski +created_utc: 1786016655 +edited: false +body: +Use a passphrase or just buy the ETF… This is 2026 not 2016.Extracted text as captured
post: 1vepzf1 author: paco_1987 created_utc: 1785791157 title: Trezor just woke up and alerted its users by this email body: I am surprised it took them so long to send emails to their users. "Important: Trezor is not affected by the Coldcard hardware wallet vulnerability. Trezor users: your funds are safe. Hi, On July 30, Coinkite disclosed an issue affecting wallets generated by certain versions of Coldcard firmware. Trezor devices are not affected. Coldcard’s issue relates to the way certain devices generate randomness when creating a wallet. Trezor does not use Coldcard’s firmware or code. Trezor generates wallets using multiple independent sources of randomness, including device hardware, the connected host and, on newer models, Secure Element chips. With our entropy check feature, you can also verify that your wallet backup is generated randomly. Who may need to take action You may be affected if: Your wallet was originally generated on an affected Coldcard device You later recovered or imported that same backup created on the Coldcard onto a Trezor Moving a wallet backup to a different device does not change the backup itself. If this applies to you, follow Coinkite’s official guidance and migrate your funds to a newly generated wallet backup as soon as possible. Take care to verify every step before moving funds. Please share this information with anyone you know who may use a Coldcard hardware wallet. Stay alert for scams Security events often lead to phishing attempts designed to create fear and urgency. Please remember: Never share your wallet backup, aka recovery seed (12/20/24 words)Excerpt only. The complete copy is held offline and backs quotations on this site. The original publication remains the canonical public source.
-
Reddit added a short comment asserting that funds are safe.
Recovered from the Internet Archive rather than captured by this project. The row records that third-party provenance separately from captures made by this project.
What changed from the previous capture 8 lines
edited: false body: Probably just ensuring everything before making a mass email + +comment: p1xmvro +parent: t3_1vepzf1 +author: RCBT88 +created_utc: 1785963582 +edited: false +body: +Fundsas’ar’safuExtracted text as captured
post: 1vepzf1 author: paco_1987 created_utc: 1785791157 title: Trezor just woke up and alerted its users by this email body: I am surprised it took them so long to send emails to their users. "Important: Trezor is not affected by the Coldcard hardware wallet vulnerability. Trezor users: your funds are safe. Hi, On July 30, Coinkite disclosed an issue affecting wallets generated by certain versions of Coldcard firmware. Trezor devices are not affected. Coldcard’s issue relates to the way certain devices generate randomness when creating a wallet. Trezor does not use Coldcard’s firmware or code. Trezor generates wallets using multiple independent sources of randomness, including device hardware, the connected host and, on newer models, Secure Element chips. With our entropy check feature, you can also verify that your wallet backup is generated randomly. Who may need to take action You may be affected if: Your wallet was originally generated on an affected Coldcard device You later recovered or imported that same backup created on the Coldcard onto a Trezor Moving a wallet backup to a different device does not change the backup itself. If this applies to you, follow Coinkite’s official guidance and migrate your funds to a newly generated wallet backup as soon as possible. Take care to verify every step before moving funds. Please share this information with anyone you know who may use a Coldcard hardware wallet. Stay alert for scams Security events often lead to phishing attempts designed to create fear and urgency. Please remember: Never share your wallet backup, aka recovery seed (12/20/24 words)Excerpt only. The complete copy is held offline and backs quotations on this site. The original publication remains the canonical public source.
-
Multiple comments by one participant were removed and replaced with deleted-account placeholders, withdrawing discussion of entropy sources, vendor trust and possible intent.
Recovered from the Internet Archive rather than captured by this project. The row records that third-party provenance separately from captures made by this project.
What changed from the previous capture 32 lines
comment: p1k2yf1 parent: t1_p1j7ryj -author: OldHamburger7923 +author: [deleted] created_utc: 1785803790 edited: false body: -Coldcard has hardware and other sources of entropy, they just disabled it. - -Trezor doesn't have this issue at the moment, but it's disingenuous to claim trezor couldn't likewise disable their rng sources and implement an insecure rng. - - +[deleted] comment: p1k3kr4 parent: t3_1vepzf1 comment: p1k738a parent: t1_p1k6fpt -author: OldHamburger7923 +author: [deleted] created_utc: 1785805140 edited: false body: -Yes, which is why I reversed my initial reaction that this bug doesn't mean the rest of coldcard has an issue. But this level of incompetence means I wouldn't trust anything they do. At the most fundamental level, without a random seed there is no security. And at the same time, people are now recommending ledger after they created a direct to cloud seed export feature. - -People should want less attack surface, not more. - -Still, my point with the previous reply is that it doesn't matter how many sources of entropy one has vs another. That doesn't mean it's being used. +[deleted] comment: p1k80gv parent: t1_p1k738a comment: p1k8d1x parent: t1_p1k80gv -author: OldHamburger7923 +author: [deleted] created_utc: 1785805562 edited: false body: -Wrong. Read what I replied to. Someone said trezor had 4 sources of entropy, as if that means they couldn't have this issue. Number of sources of randomness doesn't prove anything. - -I made no claim that trezor is stupid. But that doesn't mean trezor couldn't be stupid. +[deleted] comment: p1k9b76 parent: t1_p1jka4n Interesting point about people who moved a wallet over from coldcard onto trezor. This is the sort of gotcha that gets missed if you just spam an email without a careful review -comment: p1kg696 -parent: t1_p1kdi97 -author: OldHamburger7923 -created_utc: 1785808148 -edited: 1785808396 -body: -I'm a software developer of 26 years. It is super simple to undefine code. You're also assuming this was a mistake. We don't know what was going on there. I am not making the claims you are attributing to me. Even if it looks like a clear mistake, that could be for plausible deniability. - -I'll say it one last time, 4 sources of entropy doesn't mean your device is safe because having that functionality doesn't mean it's in the workflow. It was super easy to disable, there is nothing in the world that can guarantee security just because the hardware is present. That doesn't mean it was smart, that doesn't mean anything beyond what I said, and I don't know anyone's intention in this. - comment: p1kqwn6 parent: t1_p1jb13m author: ShadySuperCoderExtracted text as captured
post: 1vepzf1 author: paco_1987 created_utc: 1785791157 title: Trezor just woke up and alerted its users by this email body: I am surprised it took them so long to send emails to their users. "Important: Trezor is not affected by the Coldcard hardware wallet vulnerability. Trezor users: your funds are safe. Hi, On July 30, Coinkite disclosed an issue affecting wallets generated by certain versions of Coldcard firmware. Trezor devices are not affected. Coldcard’s issue relates to the way certain devices generate randomness when creating a wallet. Trezor does not use Coldcard’s firmware or code. Trezor generates wallets using multiple independent sources of randomness, including device hardware, the connected host and, on newer models, Secure Element chips. With our entropy check feature, you can also verify that your wallet backup is generated randomly. Who may need to take action You may be affected if: Your wallet was originally generated on an affected Coldcard device You later recovered or imported that same backup created on the Coldcard onto a Trezor Moving a wallet backup to a different device does not change the backup itself. If this applies to you, follow Coinkite’s official guidance and migrate your funds to a newly generated wallet backup as soon as possible. Take care to verify every step before moving funds. Please share this information with anyone you know who may use a Coldcard hardware wallet. Stay alert for scams Security events often lead to phishing attempts designed to create fear and urgency. Please remember: Never share your wallet backup, aka recovery seed (12/20/24 words)Excerpt only. The complete copy is held offline and backs quotations on this site. The original publication remains the canonical public source.
-
The thread gained a reply speculating that Trezor was checking details before sending a mass email.
Recovered from the Internet Archive rather than captured by this project. The row records that third-party provenance separately from captures made by this project.
What changed from the previous capture 8 lines
edited: false body: Ha! I got 3 or 4 scam "Trezor" emails before I got the real one. Those scammers are persistent and annoying. + +comment: p1rzgbm +parent: t3_1vepzf1 +author: painfuldrp +created_utc: 1785896779 +edited: false +body: +Probably just ensuring everything before making a mass emailExtracted text as captured
post: 1vepzf1 author: paco_1987 created_utc: 1785791157 title: Trezor just woke up and alerted its users by this email body: I am surprised it took them so long to send emails to their users. "Important: Trezor is not affected by the Coldcard hardware wallet vulnerability. Trezor users: your funds are safe. Hi, On July 30, Coinkite disclosed an issue affecting wallets generated by certain versions of Coldcard firmware. Trezor devices are not affected. Coldcard’s issue relates to the way certain devices generate randomness when creating a wallet. Trezor does not use Coldcard’s firmware or code. Trezor generates wallets using multiple independent sources of randomness, including device hardware, the connected host and, on newer models, Secure Element chips. With our entropy check feature, you can also verify that your wallet backup is generated randomly. Who may need to take action You may be affected if: Your wallet was originally generated on an affected Coldcard device You later recovered or imported that same backup created on the Coldcard onto a Trezor Moving a wallet backup to a different device does not change the backup itself. If this applies to you, follow Coinkite’s official guidance and migrate your funds to a newly generated wallet backup as soon as possible. Take care to verify every step before moving funds. Please share this information with anyone you know who may use a Coldcard hardware wallet. Stay alert for scams Security events often lead to phishing attempts designed to create fear and urgency. Please remember: Never share your wallet backup, aka recovery seed (12/20/24 words)Excerpt only. The complete copy is held offline and backs quotations on this site. The original publication remains the canonical public source.
-
The Reddit thread gained 1 new comment about scam Trezor emails.
Recovered from the Internet Archive rather than captured by this project. The row records that third-party provenance separately from captures made by this project.
What changed from the previous capture 8 lines
edited: false body: Yes, but you can sign up for their newsletter, which is separate from the email database used for purchase. + +comment: p1qi1qh +parent: t3_1vepzf1 +author: Crypta_Silva +created_utc: 1785880005 +edited: false +body: +Ha! I got 3 or 4 scam "Trezor" emails before I got the real one. Those scammers are persistent and annoying.Extracted text as captured
post: 1vepzf1 author: paco_1987 created_utc: 1785791157 title: Trezor just woke up and alerted its users by this email body: I am surprised it took them so long to send emails to their users. "Important: Trezor is not affected by the Coldcard hardware wallet vulnerability. Trezor users: your funds are safe. Hi, On July 30, Coinkite disclosed an issue affecting wallets generated by certain versions of Coldcard firmware. Trezor devices are not affected. Coldcard’s issue relates to the way certain devices generate randomness when creating a wallet. Trezor does not use Coldcard’s firmware or code. Trezor generates wallets using multiple independent sources of randomness, including device hardware, the connected host and, on newer models, Secure Element chips. With our entropy check feature, you can also verify that your wallet backup is generated randomly. Who may need to take action You may be affected if: Your wallet was originally generated on an affected Coldcard device You later recovered or imported that same backup created on the Coldcard onto a Trezor Moving a wallet backup to a different device does not change the backup itself. If this applies to you, follow Coinkite’s official guidance and migrate your funds to a newly generated wallet backup as soon as possible. Take care to verify every step before moving funds. Please share this information with anyone you know who may use a Coldcard hardware wallet. Stay alert for scams Security events often lead to phishing attempts designed to create fear and urgency. Please remember: Never share your wallet backup, aka recovery seed (12/20/24 words)Excerpt only. The complete copy is held offline and backs quotations on this site. The original publication remains the canonical public source.
-
The Reddit thread gained 3 new comments about email records and moving to a new seed.
Recovered from the Internet Archive rather than captured by this project. The row records that third-party provenance separately from captures made by this project.
What changed from the previous capture 24 lines
edited: false body: I imagine it took this long to verify for sure they weren't affected at all. + +comment: p1qc2mg +parent: t3_1vepzf1 +author: topinf +created_utc: 1785878358 +edited: false +body: +Trezor doens't have my email. + +comment: p1qhhyy +parent: t1_p1jd62e +author: PiDigitsOfPi +created_utc: 1785879851 +edited: false +body: +YES. If it has been years, (and that is the whole point of coldcard, create it and keep it stored for years) it would be easy to forget if your seed phrase was generated by the coldcard or not. So, generating a new seed and moving to it will 100% ensure that you are not accidently using a coldcard seed. + +comment: p1qhnpu +parent: t1_p1jsb5f +author: PiDigitsOfPi +created_utc: 1785879896 +edited: false +body: +Yes, but you can sign up for their newsletter, which is separate from the email database used for purchase.Extracted text as captured
post: 1vepzf1 author: paco_1987 created_utc: 1785791157 title: Trezor just woke up and alerted its users by this email body: I am surprised it took them so long to send emails to their users. "Important: Trezor is not affected by the Coldcard hardware wallet vulnerability. Trezor users: your funds are safe. Hi, On July 30, Coinkite disclosed an issue affecting wallets generated by certain versions of Coldcard firmware. Trezor devices are not affected. Coldcard’s issue relates to the way certain devices generate randomness when creating a wallet. Trezor does not use Coldcard’s firmware or code. Trezor generates wallets using multiple independent sources of randomness, including device hardware, the connected host and, on newer models, Secure Element chips. With our entropy check feature, you can also verify that your wallet backup is generated randomly. Who may need to take action You may be affected if: Your wallet was originally generated on an affected Coldcard device You later recovered or imported that same backup created on the Coldcard onto a Trezor Moving a wallet backup to a different device does not change the backup itself. If this applies to you, follow Coinkite’s official guidance and migrate your funds to a newly generated wallet backup as soon as possible. Take care to verify every step before moving funds. Please share this information with anyone you know who may use a Coldcard hardware wallet. Stay alert for scams Security events often lead to phishing attempts designed to create fear and urgency. Please remember: Never share your wallet backup, aka recovery seed (12/20/24 words)Excerpt only. The complete copy is held offline and backs quotations on this site. The original publication remains the canonical public source.
-
Recovered from the Internet Archive rather than captured by this project. The row records that third-party provenance separately from captures made by this project.
What changed from the previous capture 0 lines
Extracted text as captured
post: 1vepzf1 author: paco_1987 created_utc: 1785791157 title: Trezor just woke up and alerted its users by this email body: I am surprised it took them so long to send emails to their users. "Important: Trezor is not affected by the Coldcard hardware wallet vulnerability. Trezor users: your funds are safe. Hi, On July 30, Coinkite disclosed an issue affecting wallets generated by certain versions of Coldcard firmware. Trezor devices are not affected. Coldcard’s issue relates to the way certain devices generate randomness when creating a wallet. Trezor does not use Coldcard’s firmware or code. Trezor generates wallets using multiple independent sources of randomness, including device hardware, the connected host and, on newer models, Secure Element chips. With our entropy check feature, you can also verify that your wallet backup is generated randomly. Who may need to take action You may be affected if: Your wallet was originally generated on an affected Coldcard device You later recovered or imported that same backup created on the Coldcard onto a Trezor Moving a wallet backup to a different device does not change the backup itself. If this applies to you, follow Coinkite’s official guidance and migrate your funds to a newly generated wallet backup as soon as possible. Take care to verify every step before moving funds. Please share this information with anyone you know who may use a Coldcard hardware wallet. Stay alert for scams Security events often lead to phishing attempts designed to create fear and urgency. Please remember: Never share your wallet backup, aka recovery seed (12/20/24 words)Excerpt only. The complete copy is held offline and backs quotations on this site. The original publication remains the canonical public source.
0 presentation-noise differences. Sidebar, ticker and other page chrome churn that our review classified as not being changes to what the source says.
The excerpts and plain unified diffs above show the text this project held and how it changed. To verify a quotation, compare it against the page itself or against the Internet Archive's copies, which are independent of this project.
Complete captures are held offline rather than mirrored here, so this page shows diffs and excerpts. If a quotation is ever disputed, the full copy can be produced. Ask.
Compare the screenshot or a quotation against the original while it is available.