Market desk Bitcoin Ethereum Altcoins DeFi Stablecoins Markets & Trading

How Bitcoin Hardware Wallets Supported Users During the Coldcard Crisis

An examination of how 13 top bitcoin hardware wallet manufacturers communicated on X and supported their customers during the Coldcard crisis.
2 weeks ago 35 views
How Bitcoin Hardware Wallets Supported Users During the Coldcard Crisis

Following the Coldcard crisis that erupted between late July and August, Bitcoin.com News reviewed how the top 13 manufacturers of bitcoin hardware wallets communicated with their customers on the social media platform X. Response speeds varied by more than a day across the manufacturers, and teams differed significantly in clarity, helpfulness, tone, and follow-up frequency.

Response Speeds and Communication Styles

Block, the U.S.-based manufacturer of Bitkey, was part of the initial Coldcard investigation and among the first to warn users and the broader community about the exploit. They were soon followed by Canada-based Blockstream, the manufacturer of Jade. For other manufacturers, posting on X took more than a day, with Europe-based Ledger informing followers approximately 14 hours after the crisis began. However, the fastest responders were not always the most thorough.

Open-source wallets such as Passport Prime, Trezor, Bitbox, Keystone, and Blockstream Jade leaned into verifiability to reassure users. In contrast, closed-source designs like Ledger, Tangem, and Ngrave relied more heavily on certifications and audits.

Entropy and Self-Custody Best Practices

Across communications, manufacturers placed a heavy emphasis on how entropy is generated to differentiate themselves from Coldcard. Several teams highlighted support for user-generated entropy, such as manual dice-roll entropy, to reduce trust in a device's built-in random number generator. Additionally, while some companies used the moment to push broader self-custody best practices and multisignature setups as a structural defense, not all teams discussed multisig or provided practical migration advice for affected users.

Manufacturers like Foundation (Passport Prime), Bitkey, Ellipal, Jade, Bitbox, and Trezor stood out for offering actionable guidance. Meanwhile, Ngrave and Ellipal utilized stronger promotional language in their messaging.

Manufacturer Responses at a Glance

  • Bitkey: Block independently investigated thefts, confirmed seedless Bitkey was unaffected, warned that vulnerable Coldcard seeds remain compromised even if moved, and detailed its 2-of-3 multisig design.
  • Blockstream Jade: Highlighted multi-source entropy generation, published a four-step migration guide for affected users, and emphasized its fully open-source nature.
  • Passport Prime: Stated its models have always generated correct entropy safely, explained multi-source hardware entropy, and introduced new health monitoring and an entropy-testing app.
  • Trezor: Assured user fund safety while warning that Coldcard-generated seeds moved to Trezor remained at risk. Trezor later disclosed a data breach involving a shipping provider affecting nearly 14,000 customers.
  • OneKey: Explained that its dual on-device entropy sources combine independent random sources and shared articles on multisig and seed phrase security.
  • BitBox: Noted its seeds combine five independent entropy sources and pointed to open-source firmware, internal audits, and bug bounties. BitBox also patched unrelated firmware bugs with no exploits reported.
  • Keystone: Confirmed internal checks showed devices were safe, emphasized verified generation processes, and offered BIP-39 passphrases or dice-roll features.
  • Ledger: Pointed to a certified true random number generator in its secure element. Ledger noted that customers were impacted by two third-party data leaks, though Ledger itself suffered no breaches.
  • Tangem: Emphasized that its seedless device runs on separate code and argued that security stems from architecture, testing, and independent verification.
  • Ellipal: Invited users to verify randomness independently, shared a migration checklist for users who made seeds on a Coldcard, and warned against phishing attempts.
  • SafePal: Differentiated itself by explaining how it pulls entropy at wallet creation. SafePal later disclosed a data breach affecting nearly 40,000 customers.
  • Ngrave: Highlighted its "Perfect Key" generation combining cryptographic techniques, air-gapped generation, and user fingerprints, alongside LLM-assisted cyberdefense evaluations.
  • KeepKey: Shared a developer technical breakdown and a blog post covering who was at risk and migration steps.
Market snapshot

Top cryptocurrency prices

Explore all prices
Market prices will appear after the next scheduled refresh.