Trezor Rules Out Coldcard Flaw, But Warns Some Users Remain Exposed

A $70M Bitcoin theft tied to Coldcard firmware pushed Ledger and Trezor to insist their own hardware wallets are unaffected. (Image: Shutterstock)
A $70M Bitcoin theft tied to Coldcard firmware pushed Ledger and Trezor to insist their own hardware wallets are unaffected. (Image: Shutterstock)

Ledger and Trezor told users their funds are safe after a firmware flaw in rival Coldcard wallets enabled a $70 million Bitcoin (BTC) theft in 41 minutes.

Key Points:

  • Ledger, Trezor, Bitkey, Jade and Tangem said the Coldcard firmware flaw does not touch their devices.
  • Attackers drained 1,082.65 BTC from 1,196 addresses on Jul. 30, nearly double the first estimate.
  • Bitcoin social sentiment fell to a record low, and spot ETFs lost $265.4 million on Jul. 31.

Ledger And Trezor Reject Coldcard Link

Ledger said it was not affected by the Coldcard Mk3 advisory, citing a certified random number generator built into its secure element chip.

Trezor told customers on Friday that the fault sits in Coinkite's own custom firmware, which Trezor does not share. Bitkey, Jade and Tangem also moved to reassure their users within hours.

Trezor attached one warning. Anyone who created a seed on an affected Coldcard and later restored it on another device stays exposed, because the weak randomness travels with the seed itself.

Also Read: AI Infrastructure, Payday Lender's Desperate $1B Pivot To Dominate Data Centers

Bitcoin Sentiment Falls To Record Low

Galaxy Research linked the sweep to a 41-minute window early on Jul. 30, covering 1,082.65 BTC across 1,196 addresses. That total roughly doubled the 594 BTC first reported. Santiment then logged a bullish-to-bearish commentary ratio of 0.58, its weakest Bitcoin reading on record.

Money followed the mood.

U.S. spot Bitcoin ETFs shed $265.4 million on Jul. 31, ending two days of inflows. BlackRock's IBIT accounted for $122.7 million of that, with Fidelity's FBTC next at $54.8 million. Bitcoin itself has held near $63,000 since Friday's decline of almost 3%.

Ido Ben-Natan, chief executive of security firm Blockaid, argued that most 2026 crypto losses came from compromised keys rather than broken smart contracts. Joe Burnett of Strive wrote that the episode could permanently reshape how investors think about self-custody.

Coldcard Firmware Flaw Timeline

The vulnerability sat unnoticed for five years. Block's engineers traced it to a code commit dated Mar. 1, 2021, which shipped in firmware 4.0.0 and quietly routed seed generation to a software substitute.

Effective entropy on Mk3 devices fell to roughly 40 bits, against the 128 bits a standard seed should carry.

Coinkite issued its first public advisory about 30 hours after the sweep began, covering Mk3 units before widening it to Mk4, Mk5 and Q models.

Patching alone does not help, since seeds already made on vulnerable firmware stay guessable.

Read Next: Foldable iPhone Rumors Get Specific: $2,500, No Face ID, No Telephoto

Alexey Bondarev profile photo

Alexey Bondarev

Alexey Bondarev is the Head of Content at Yellow.com, having reported on crypto for the last 10 years. He specializes in in-depth Research and Learn pieces, with a focus on analytical reporting, industry context, and the bigger forces shaping crypto, from the AI era and security technologies to fintech innovation. He believes that everything digital will imminently overcome everything analogue and is working hard to make that come true.

Disclaimer and Risk Warning: The information provided in this article is for educational and informational purposes only and is based on the author's opinion. It does not constitute financial, investment, legal, or tax advice. Cryptocurrency assets are highly volatile and subject to high risk, including the risk of losing all or a substantial amount of your investment. Trading or holding crypto assets may not be suitable for all investors. The views expressed in this article are solely those of the author(s) and do not represent the official policy or position of Yellow, its founders, or its executives. Always conduct your own thorough research (D.Y.O.R.) and consult a licensed financial professional before making any investment decision.
Trezor Rules Out Coldcard Flaw, But Warns Some Users Remain Exposed | Yellow