Veuillez noter : nos articles de blog ne sont actuellement disponibles qu’en anglais.

Coldcard vulnerability: Trezor devices are not affected
A recently discovered vulnerability is affecting wallets generated by certain Coldcard firmware versions, resulting in a loss of funds. Trezor devices and wallets originally generated on Trezor are not affected, and user funds are safe. However, if anyone generated a wallet on Coldcard in the past, and later restored it on Trezor, they should create a new wallet and migrate their funds.
Important: Trezor devices are not affected by the Coldcard vulnerability. If your wallet was originally generated on a Trezor, your funds are safe and no action is required.
What happened
On July 30, 2026, Coinkite disclosed an issue affecting wallets generated by certain versions of Coldcard firmware.
We want to reassure you that Trezor devices are not affected by this bug.
Coldcard’s issue relates to the way certain devices generate randomness when creating a wallet. Trezor does not use Coldcard’s firmware or code.
Trezor generates wallets using multiple independent sources of randomness, including device hardware, the connected host and, on newer models, Secure Element chips. With Entropy Check, you can verify that your Trezor used the randomness supplied by the host when generating your wallet.
Who may need to take action
You may be affected by this Coldcard incident if:
- Your wallet was originally generated on an affected Coldcard device
- You later recovered or imported that same backup created on the Coldcard onto a Trezor
Moving a wallet backup to a different device does not change the backup itself.
If this applies to you, follow these instructions and migrate your funds to a newly generated wallet as soon as possible. Take care to verify every step before moving funds.
You are not affected if your wallet was originally generated on a Trezor.
Stay alert for scams
Security events often lead to phishing attempts designed to create fear and urgency.
This is an example pretending to be the Trezor CEO:
And another scam urging users to download malicious apps:
Please remember:
- Never share your wallet backup, aka recovery seed (12/20/24 words)
- Only enter your wallet backup as instructed on your Trezor device. Never type it into a website, form, app or message
- Trezor will never contact you asking for your wallet backup
- Do not follow wallet-migration instructions from unsolicited emails, messages or phone calls
If you are not affected, you do not need to take any action, but please share this information with anyone you know who may use a Coldcard hardware wallet.
A message from our Chief Commercial Officer:
Common FAQs
Understandably, we’re receiving a lot of questions. Here are quick answers to the most frequently asked ones:
1. Are Trezor devices affected by this incident?
No. Trezor devices are not affected by the Coldcard vulnerability.
2. What if I generated my wallet on a Coldcard and later restored it on a Trezor?
You are still affected. Restoring the wallet on a Trezor does not fix weak randomness used when the wallet was originally created.
Generate a new wallet on your Trezor and carefully migrate your funds.
3. If I send coins from an affected Coldcard wallet to a new Trezor address (under a new wallet backup), are they safe?
Yes, once the transaction is confirmed and the receiving address belongs to a completely new wallet generated on the Trezor, those funds are no longer controlled by the affected Coldcard-generated keys. Simply restoring the affected Coldcard wallet on a Trezor is not enough. The funds must be moved to a newly generated wallet.
4. Are older models such as Trezor Model One and Model T still safe?
Yes. Trezor Model One and Model T remain perfectly safe to use. They combine randomness from the device and the host to generate the wallet.
Trezor Safe 3 and Safe 5 add randomness from the Optiga Secure Element chip as well, while Trezor Safe 7 also includes the TROPIC01 chip (mixes four sources).
All models generate at least 128-bit entropy under default settings.
5. Should I update my firmware and regenerate my Trezor wallet?
Keep your Trezor firmware up to date, but this Coldcard incident does not require Trezor users to regenerate wallets originally created on a Trezor.
If your wallet was generated on an affected Coldcard, create a new wallet and migrate your funds.
6. How does Trezor’s wallet (entropy) generation differ from Coldcard’s?
Trezor does not rely on one source of entropy. It combines entropy from the device and host, with additional independent hardware sources on Trezor Safe models. Entropy Check provides another safeguard by making parts of this process verifiable.
View more information below:
7. Does Trezor use AI to audit its firmware?
Yes. Trezor uses automated tooling, including AI-assisted analysis, as one layer of code review. This is used alongside human review, public open-source review, external audits and Trezor’s Bug Bounty Program.
8. Will Trezor add more support for dice rolls or change its default wallet format?
We are studying the lessons from this incident and considering additional safeguards, including support for user-supplied entropy. We cannot commit to a specific feature yet.
The central issue in this incident was not simply the availability of entropy, but whether the firmware correctly used it.
9. Would multisig have prevented this issue?
Multisig may reduce risk if the affected Coldcard key is only one part of the setup and the remaining keys are secure, but the exact impact depends on the multisig configuration. An affected key should still be replaced.
10. Have any historical Trezor firmware versions had similar entropy problems?
No. Trezor’s seed-generation code is continuously reviewed, publicly auditable and protected by multiple independent entropy sources, entropy checks, signed firmware and a bug bounty program.


