Subscribe Now
Trending News

Blog Post

EVERY HARDWARE WALLET RANKED BY ENTROPY — THE ONES THAT SURVIVE AND THE ONES THAT BET YOUR KEYS
Uncategorized

EVERY HARDWARE WALLET RANKED BY ENTROPY — THE ONES THAT SURVIVE AND THE ONES THAT BET YOUR KEYS 

People who stored their BTC on Coldcard got drained because of entropy.

The seed generation was reproducible. Anyone could recompute their keys.

So this researcher went through EVERY other hardware wallet to see how they make your seed — and whether the same thing can happen again. Here’s the full audit:

The One-Source Wallets (The Coldcard Bet)

Ledger: one certified chip (AIS-31, EAL5+). Good randomness. But it’s a single source, closed source, and you cannot verify any of it. You’re trusting them completely.

Tangem: key is born inside the chip and never comes out. Audited by three firms. Same trade: strong, and impossible for you to check by design.

ELLIPAL: single certified chip, no software fallback, fails closed instead of guessing. Closed source, so take it on faith.

The Multi-Source Wallets (The Safe Ones)

@Trezor: mixes the device’s randomness with randomness from your computer, and the device has to prove it used both. Even if its chip is fully broken, you’re still fine. The best design here by far.

@BitBoxSwiss: 5 separate sources of randomness combined. One bad source can’t sink you. Open source, reproducible builds, dice supported.

@FoundationHQ: built their own randomness circuit out of plain resistors and capacitors, open source, on top of two other sources. No black-box chip to trust. Supports dice.

@KeystoneWallet: 2 secure chips from 2 different manufacturers, combined. Also lets you roll 99 dice and publishes how to check the result yourself.

@Blockstream: Jade pulls from 7 things: radio noise, cpu counters, battery, temperature, camera, your input, the app. Very hard to break all of them.

@SeedSigner: your dice are the only source. No chip to trust at all. And they ship a guide teaching you to verify their own math. Weakest hardware, strongest proof.

@OneKey: secure element plus mcu combined on device, open source firmware. Solid, but you can’t add your own randomness.

@SafePal: 2 chips mixed. They’ve never published the details.

The Edge Cases

@ngrave_official: mixes chip randomness with your fingerprint and room light. Clever. But the “EAL7” badge covers one software component, not the whole device.

@COLDCARDwallet: patched now, and dice on Coldcard were always verifiable. But every seed made between 2021 and 2026 is permanently burned.

The Lesson

One source = Ledger, Tangem, ELLIPAL. That one source fails, everything fails. Their answer is to make it excellent and certified. That’s exactly the bet Coldcard lost.

Many sources = Trezor, BitBox, Passport, Jade, Keystone. One broken source never reaches your key.

And every one of these claims 128 or 256 bits.

Coldcard did too. Certification doesn’t help either — Coldcard’s chip was fine, the code just stopped calling it.

The only thing that saves you is being able to check.

Roll your own dice. Verify the words yourself.

Source: hardware wallet entropy audit on X

Previous

EVERY HARDWARE WALLET RANKED BY ENTROPY — THE ONES THAT SURVIVE AND THE ONES THAT BET YOUR KEYS

Related posts

Leave a Reply

Please authenticate to comment:

Required fields are marked *

⚡ Zap This!

Support this content with sats on Nostr

Zap QR

Lightning Address (tap to copy):

✅ Copied!

Or zap via Nostr client:

🟣 Open in Primal