COLDCARD RNG incident the public record, collected and explained
Informational only, and this site never asks for your seed words. details

Informational only. This is an open source collection of what others have published about the incident, together with an explanation of it. It is not financial, security or legal advice, and not a substitute for professional advice about your own situation. It is not affiliated with, endorsed by, or speaking for Coinkite. Material is attributed and quoted as published; where sources disagree their scenarios are kept separate with their assumptions rather than reconciled into one answer. Everything is meant to be checked against the linked evidence rather than taken on trust. Act on your own judgement about a particular situation. Editorial standards and corrections.

Do not disclose recovery material to a website, form, message or support account. This site never asks for it, and contributions containing recovery words or private keys are not accepted.

Trezor devices are not affected

trezor-coldcard-not-affected

https://trezor.io/blog/news/coldcard-vulnerability-trezor-devices-are-not-affected

Latest reviewed change

source content difference between and

Trezor edited the article: the migration sentence for ex-Coldcard wallets now says "follow these instructions" instead of "follow Coinkite's official guidance", and "wallet backup" was shortened to "wallet".

seen +1 -1 full history below
 Your wallet was originally generated on an affected Coldcard device
 You later recovered or imported that same backup created on the Coldcard onto a Trezor
 Moving a wallet backup to a different device does not change the backup itself.
-If this applies to you, follow Coinkite’s official guidance and migrate your funds to a newly generated wallet backup as soon as possible. Take care to verify every step before moving funds.
+If this applies to you, follow these instructions and migrate your funds to a newly generated wallet as soon as possible. Take care to verify every step before moving funds.
 You are not affected if your wallet was originally generated on a Trezor.
 Stay alert for scams
 ­Security events often lead to phishing attempts designed to create fear and urgency.
Organisation
Trezor
Evidence role
Vendor statement
Published
2026-08-05
Source changes
1
Detected differences
4
Unreviewed
0
Copies held
5

The article the twelve-post FAQ thread points at. Covers who may need to move funds, how Trezor backups are generated, and the related scam wave.

Every check is recorded, including checks that found no text change. A detected edit is therefore bounded between two checks. The publisher's exact save time is not observable from this record. Last checked .

  1. source content difference between and source content +1 -1

    Trezor edited the article: the migration sentence for ex-Coldcard wallets now says "follow these instructions" instead of "follow Coinkite's official guidance", and "wallet backup" was shortened to "wallet".

    seen · Captured here 7,434 chars
    What changed from the previous capture 2 lines
     Your wallet was originally generated on an affected Coldcard device
     You later recovered or imported that same backup created on the Coldcard onto a Trezor
     Moving a wallet backup to a different device does not change the backup itself.
    -If this applies to you, follow Coinkite’s official guidance and migrate your funds to a newly generated wallet backup as soon as possible. Take care to verify every step before moving funds.
    +If this applies to you, follow these instructions and migrate your funds to a newly generated wallet as soon as possible. Take care to verify every step before moving funds.
     You are not affected if your wallet was originally generated on a Trezor.
     Stay alert for scams
     ­Security events often lead to phishing attempts designed to create fear and urgency.
    
    Extracted text as captured
    Skip to content
    Products AppCoinsLearn & Support
    Search...
    Search for anything...
    Cart
    0
    Hardware wallets
    Why you need one
    Trezor Safe 7
    Trezor Safe 5
    Trezor Safe 3
    Compare wallets
    All products & accessories
    Save with bundles
    Backup
    Safeguard your wealth
    with Keep Metal
    English
    Čeština
    日本語
    Deutsch
    Español
    Français
    Português (Brasil)
    Back to Trezor Blog
    News
    Coldcard vulnerability: Trezor devices are not affected
    Trezor Team
    6 mins read
    Aug 5, 2026
    Summary
    A recently discovered vulnerability is affecting wallets generated by certain Coldcard firmware versions, resulting in a loss of funds. Trezor devices and wallets originally generated on Trezor are not affected, and user funds are safe. However, if anyone generated a wallet on Coldcard in the past, and later restored it on Trezor, they should create a new wallet and migrate their funds.
    Important: Trezor devices are not affected by the Coldcard vulnerability. If your wallet was originally generated on a Trezor, your funds are safe and no action is required.
    Table of contents
    What happened
    On July 30, 2026, Coinkite disclosed an issue affecting wallets generated by certain versions of Coldcard firmware.
    We want to reassure you that Trezor devices are not affected by this bug.
    Coldcard’s issue relates to the way certain devices generate randomness when creating a wallet. Trezor does not use Coldcard’s firmware or code.
    Trezor generates wallets using multiple independent sources of randomness, including device hardware, the connected host and, on newer models, Secure Element chips. With Entropy Check, you can verify that your Trezor used the randomness supplied by the host when generating your wallet.
    Who may need to take action

    Excerpt only. The complete copy is held offline and backs quotations on this site. The original publication remains the canonical public source.

  2. Earliest copy held
    seen · Captured here 7,451 chars
    Extracted text as captured
    Skip to content
    Products AppCoinsLearn & Support
    Search...
    Search for anything...
    Cart
    0
    Hardware wallets
    Why you need one
    Trezor Safe 7
    Trezor Safe 5
    Trezor Safe 3
    Compare wallets
    All products & accessories
    Save with bundles
    Backup
    Safeguard your wealth
    with Keep Metal
    English
    Čeština
    日本語
    Deutsch
    Español
    Français
    Português (Brasil)
    Back to Trezor Blog
    News
    Coldcard vulnerability: Trezor devices are not affected
    Trezor Team
    6 mins read
    Aug 5, 2026
    Summary
    A recently discovered vulnerability is affecting wallets generated by certain Coldcard firmware versions, resulting in a loss of funds. Trezor devices and wallets originally generated on Trezor are not affected, and user funds are safe. However, if anyone generated a wallet on Coldcard in the past, and later restored it on Trezor, they should create a new wallet and migrate their funds.
    Important: Trezor devices are not affected by the Coldcard vulnerability. If your wallet was originally generated on a Trezor, your funds are safe and no action is required.
    Table of contents
    What happened
    On July 30, 2026, Coinkite disclosed an issue affecting wallets generated by certain versions of Coldcard firmware.
    We want to reassure you that Trezor devices are not affected by this bug.
    Coldcard’s issue relates to the way certain devices generate randomness when creating a wallet. Trezor does not use Coldcard’s firmware or code.
    Trezor generates wallets using multiple independent sources of randomness, including device hardware, the connected host and, on newer models, Secure Element chips. With Entropy Check, you can verify that your Trezor used the randomness supplied by the host when generating your wallet.
    Who may need to take action

    Excerpt only. The complete copy is held offline and backs quotations on this site. The original publication remains the canonical public source.

3 presentation-noise differences. Sidebar, ticker and other page chrome churn that our review classified as not being changes to what the source says.
  • +2 -0 Only the repeated author-tagline line 'Sharing insights on crypto, security & self-custody' appeared in the header and author bio areas; the article text was unchanged.
  • +3 -3 Only rotating related-content cards below the article changed, swapping a 'Permissionless storage with Suite Sync' entry for a 'Recent customer data exposed in shipping provider incident' entry, and the article text was unchanged.
  • +2 -0 Only the page's language-selector menu changed, adding Simplified Chinese and Indonesian entries.
How to check this yourself

The excerpts and plain unified diffs above show the text this project held and how it changed. To verify a quotation, compare it against the page itself or against the Internet Archive's copies, which are independent of this project.

Complete captures are held offline rather than mirrored here, so this page shows diffs and excerpts. If a quotation is ever disputed, the full copy can be produced. Ask.