Bitcoin Forum
August 05, 2026, 10:41:51 AM *
News: COLDCARD users only: critical vulnerability risks funds stored on COLDCARD devices; immediate action required
 
   Home   Help Search Login Register More  
Pages: [1]
  Print  
Author Topic: Interesting tweet comparing all hardware wallets' security (with ranking)  (Read 63 times)
sergiorus (OP)
Sr. Member
****
Offline

Activity: 980
Merit: 326



View Profile
August 03, 2026, 06:32:51 PM
 #1

Hi everybody. Stumbled upon this tweet [1] and found it interesting enough to share on here. Hopefully someone will take their time to critisise it (or approve).




Quote
people who stored their btc on coldcard got drained because of entropy.

the seed generation was reproducible, anyone could recompute their keys.

so i went through every other hardware wallet to see how they make your seed, and whether the same thing can happen again.

@Trezor
: mixes the device's randomness with randomness from your computer, and the device has to prove it used both. even if its chip is fully broken, you're still fine. the best design here by far.

@BitBoxSwiss
: 5 separate sources of randomness combined. one bad source can't sink you. open source, reproducible builds, dice supported.

@FoundationHQ
: built their own randomness circuit out of plain resistors and capacitors, open source, on top of two other sources. no black-box chip to trust. supports dice.

@KeystoneWallet
: 2 secure chips from 2 different manufacturers, combined. also lets you roll 99 dice and publishes how to check the result yourself.

@Blockstream
: jade pulls from 7 things: radio noise, cpu counters, battery, temperature, camera, your input, the app. very hard to break all of them.

@SeedSigner
: your dice are the only source. no chip to trust at all. and they ship a guide teaching you to verify their own math. weakest hardware, strongest proof.

@OneKey
: secure element plus mcu combined on device, open source firmware. solid, but you can't add your own randomness.

@Ledger
: one certified chip (AIS-31, EAL5+). good randomness. but it's a single source, closed source, and you cannot verify any of it. you're trusting them completely.

@Tangem
: key is born inside the chip and never comes out. audited by three firms. same trade: strong, and impossible for you to check by design.

@ngrave_official
: mixes chip randomness with your fingerprint and room light. clever. but the "EAL7" badge covers one software component, not the whole device.

@ELLIPAL
: single certified chip, no software fallback, fails closed instead of guessing. closed source, so take it on faith.

@SafePal
: 2 chips mixed. they've never published the details.

@COLDCARDwallet
: patched now, and dice on coldcard were always verifiable. but every seed made between 2021 and 2026 is permanently burned.

one source = ledger, tangem, ellipal. that one source fails, everything fails. their answer is to make it excellent and certified. that's exactly the bet coldcard lost.

many sources = trezor, bitbox, passport, jade, keystone. one broken source never reaches your key.

and every one of these claims 128 or 256 bits.

coldcard did too. certification doesn't help either, coldcard's chip was fine, the code just stopped calling it.

the only thing that saves you is being able to check.
roll your own dice. verify the words yourself.












References:

[1] https://x.com/the_smart_ape/status/2084265598368809390


███████▄▄███▄███▄
███▄▄████████▌██
▄█████████████▐██▌
██▄███████████▌█▌
███████▀██████▐▌█
██████████████▌▌▐
████████▄███████▐▐
█████████████████
███████████████▄██▄
██████████████▀▀▀
█████▀███▀▀▀

▄▄▄██████▄▄▄███████▄▄▄
███████████████████████████
███▌█████▀███▌█████▀▀███████████▄▄▄▄▄▄▄▄
███▌█████▄███▌█████▄███▐███████████████████▄
▐████████████▀███████▄██████████▀▀▀▀▀▀▀▀████▀
▐████████████▄██▄███████████▌█████████▄████▀
▐█████████▀█████████▌█████████████▄▄████▀
██████████▄███████████▐███▌██▄██████▀
██████████████▀███▐███▌██████████████████████
████▀██████▀▀█████████▌███▀▀▀▀███▀▀▀▀▀▀▀████▌

█████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████
 
P R E M I E R   B I T C O I N   C A S I N O   &   S P O R T S B O O K
 

█████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████

█▀▀









▀▀▀

▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀
98%
RTP


▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀

▀▀█









▀▀▀

█▀▀









▀▀▀

▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀
HIGH
ODDS


▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀

▀▀█









▀▀▀

██████
██
██
██
██
██
██
██
██
██▄▄▄▄
▀▀▀▀▀▀

███████████████████████████████
 
PLAY NOW
 

███████████████████████████████

██████
██
██
██
██
██
██
██
██
▄▄▄▄██
▀▀▀▀▀▀
Meuserna
Sr. Member
****
Offline

Activity: 337
Merit: 556


View Profile WWW
August 03, 2026, 07:26:13 PM
 #2

Quote
@SeedSigner
: your dice are the only source. no chip to trust at all. and they ship a guide teaching you to verify their own math. weakest hardware, strongest proof.

Really good stuff.

I'm a fan of the SeedSigner model for self custody. The hardware doesn't generate your seed phrase. And the hardware doesn't save your seed or wallet. When powered down or rebooted, the seed and the wallet get wiped.

That's great because it changes the way you view the wallet. Instead of thinking the device is the wallet, which is a mistake too many people make, you instead realize the seed is the wallet.

There's a fork of SeedSigner called ShieldSigner that adds encrypted Sed QR, Passphrase QR, and smartcard capability to SeedSigner. It's fantastic. BTC Hardware Solutions sells a smartcard compatible version of the hardware for ShieldSigner. I definitely recommend it.

Quote
@Trezor
: mixes the device's randomness with randomness from your computer, and the device has to prove it used both. even if its chip is fully broken, you're still fine. the best design here by far.

I'm glad to learn that. Trezor is what I usually recommend for most self custody newcomers.

Mia Chloe
Legendary
*
Offline

Activity: 1148
Merit: 2257


Contact me for your designs...


View Profile
August 03, 2026, 08:54:04 PM
 #3

Hi everybody. Stumbled upon this tweet [1] and found it interesting enough to share on here. Hopefully someone will take their time to critisise it (or approve).
How necessary is comparisons like these really if we are being sincere. First off I think this is just a result of the recent cold card disaster and it's expected that people will start questioning the safety of hardware wallets now. The theft that was pulled off could have happened to almost any hardware wallet under similar scenarios.

The kind randomness itself is not necessarily the problem in this case the big question how could you tell if the firmware was tampered or not ? If people knew about it before then the attack scale wouldn't have been that large.

███████████████████████████
███████▄████████████▄██████
████████▄████████▄████████
███▀█████▀▄███▄▀█████▀███
█████▀█▀▄██▀▀▀██▄▀█▀█████
███████▄███████████▄███████
███████████████████████████
███████▀███████████▀███████
████▄██▄▀██▄▄▄██▀▄██▄████
████▄████▄▀███▀▄████▄████
██▄███▀▀█▀██████▀█▀███▄███
██▀█▀████████████████▀█▀███
███████████████████████████
.
.Duelbits PREDICT..
█████████████████████████
█████████████████████████
███████████▀▀░░░░▀▀██████
██████████░░▄████▄░░████
█████████░░████████░░████
█████████░░████████░░████
█████████▄▀██████▀▄████
████████▀▀░░░▀▀▀▀░░▄█████
██████▀░░░░██▄▄▄▄████████
████▀░░░░▄███████████████
█████▄▄█████████████████
█████████████████████████
█████████████████████████
.
.WHERE EVERYTHING IS A MARKET..
█████
██
██







██
██
██████
Will Bitcoin hit $200,000
before January 1st 2027?

    No @1.15         Yes @6.00    
█████
██
██







██
██
██████

  CHECK MORE > 
sergiorus (OP)
Sr. Member
****
Offline

Activity: 980
Merit: 326



View Profile
August 03, 2026, 09:11:36 PM
Last edit: August 03, 2026, 09:50:27 PM by sergiorus
 #4

Quote
@Trezor
: mixes the device's randomness with randomness from your computer, and the device has to prove it used both. even if its chip is fully broken, you're still fine. the best design here by far.

I'm glad to learn that. Trezor is what I usually recommend for most self custody newcomers.

I've had a Trezor for 8 years and love it. Usually I would just recommend it to everyone but now I'm no longer comfortable with taking that responsibility so I will just be sending some educational material like this one instead.






How necessary is comparisons like these really if we are being sincere. First off I think this is just a result of the recent cold card disaster and it's expected that people will start questioning the safety of hardware wallets now.

Yes, of course it is a thing now. I believe many people used to think all hardware wallets are safe by default, as long as the seed phrase and the device are not compromised. Some question if theirs is safe enough, others are in panic looking for the most secure way to store their funds.





The theft that was pulled off could have happened to almost any hardware wallet under similar scenarios.
The kind randomness itself is not necessarily the problem in this case the big question how could you tell if the firmware was tampered or not ? If people knew about it before then the attack scale wouldn't have been that large.

That's not what I've read about it so far. Could you elaborate further?


███████▄▄███▄███▄
███▄▄████████▌██
▄█████████████▐██▌
██▄███████████▌█▌
███████▀██████▐▌█
██████████████▌▌▐
████████▄███████▐▐
█████████████████
███████████████▄██▄
██████████████▀▀▀
█████▀███▀▀▀

▄▄▄██████▄▄▄███████▄▄▄
███████████████████████████
███▌█████▀███▌█████▀▀███████████▄▄▄▄▄▄▄▄
███▌█████▄███▌█████▄███▐███████████████████▄
▐████████████▀███████▄██████████▀▀▀▀▀▀▀▀████▀
▐████████████▄██▄███████████▌█████████▄████▀
▐█████████▀█████████▌█████████████▄▄████▀
██████████▄███████████▐███▌██▄██████▀
██████████████▀███▐███▌██████████████████████
████▀██████▀▀█████████▌███▀▀▀▀███▀▀▀▀▀▀▀████▌

█████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████
 
P R E M I E R   B I T C O I N   C A S I N O   &   S P O R T S B O O K
 

█████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████

█▀▀









▀▀▀

▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀
98%
RTP


▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀

▀▀█









▀▀▀

█▀▀









▀▀▀

▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀
HIGH
ODDS


▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀

▀▀█









▀▀▀

██████
██
██
██
██
██
██
██
██
██▄▄▄▄
▀▀▀▀▀▀

███████████████████████████████
 
PLAY NOW
 

███████████████████████████████

██████
██
██
██
██
██
██
██
██
▄▄▄▄██
▀▀▀▀▀▀
Meuserna
Sr. Member
****
Offline

Activity: 337
Merit: 556


View Profile WWW
August 03, 2026, 09:47:00 PM
 #5

Hi everybody. Stumbled upon this tweet [1] and found it interesting enough to share on here. Hopefully someone will take their time to critisise it (or approve).
How necessary is comparisons like these really if we are being sincere. First off I think this is just a result of the recent cold card disaster and it's expected that people will start questioning the safety of hardware wallets now. The theft that was pulled off could have happened to almost any hardware wallet under similar scenarios.

I think that info is great. I found it useful to know where the randomness in different devices comes from. For self custody, that matters, and it's something people don't think about.

The kind randomness itself is not necessarily the problem in this case the big question how could you tell if the firmware was tampered or not ? If people knew about it before then the attack scale wouldn't have been that large.

ColdCard's code wasn't tampered with. ColdCard's devs wrote the error in the firmware. It was just a mistake, but that error was part of ColdCard's firmware since March 2021.

PX-Z
Legendary
*
Offline

Activity: 2254
Merit: 1360


Wallet Transaction Notifier - @txnNotifierBot


View Profile
August 04, 2026, 11:32:54 PM
 #6

...The theft that was pulled off could have happened to almost any hardware wallet under similar scenarios.
However, there's an important distinction, it doesn't mean all hardware wallets are equally vulnerable.

The kind randomness itself is not necessarily the problem in this case the big question how could you tell if the firmware was tampered or not ? If people knew about it before then the attack scale wouldn't have been that large.
That's exactly one of the hardest problems in hardware wallet security. It's on the manufacturers to address, QA, QC, etc.. Also, if there's an independent open source code review it can significantly reduce the risk, but it cannot guarantee that a bug like this would be caught.

 
 b1exch.to 
  ETH      DAI   
  BTC      LTC   
  USDT     XMR    
.███████████▄▀▄▀
█████████▄█▄▀
███████████
███████▄█▀
█▀█
▄▄▀░░██▄▄
▄▀██▄▀█████▄
██▄▀░▄██████
███████░█████
█░████░█████████
█░█░█░████░█████
█░█░█░██░█████
▀▀▀▄█▄████▀▀▀
Pages: [1]
  Print  
 
Jump to:  

Powered by MySQL Powered by PHP Powered by SMF 1.1.19 | SMF © 2006-2009, Simple Machines Valid XHTML 1.0! Valid CSS!