{"@context":"https://schema.org","@type":"Dataset","name":"Proof of Custody — Hardware wallet rubric scores","description":"Hardware wallets scored on entropy and key generation, firmware, supply chain, disclosure conduct, interoperability and privacy, with the rationale for each score and the as-of date.","url":"https://proofofcustody.io/data/hardware-wallet-scores.json","creator":{"@type":"Organization","name":"Proof of Custody","url":"https://proofofcustody.io"},"license":"https://creativecommons.org/licenses/by/4.0/","isAccessibleForFree":true,"inLanguage":"en","dateModified":"2026-09-23T03:54:21.642Z","citation":"Proof of Custody, hardware wallet rubric, https://proofofcustody.io/learn/coldcard-alternatives","publisherDisclosure":"Proof of Custody is published by Onramp Bitcoin, which does not sell hardware wallets.","readMe":{"scope":"Devices assessed against a published rubric, not against each other. A device we have not assessed is absent, not disqualified.","staleness":"Each assessment carries an asOf date. A device that has shipped firmware since that date may have moved."},"dimensions":[{"key":"entropy","label":"Entropy & key generation","weight":25,"measures":"Whether the device demonstrably uses its hardware random number generator, offers a user-verifiable entropy path such as dice, and has had that path independently audited. This is weighted highest because a key generated from predictable randomness cannot be protected by anything downstream."},{"key":"firmware","label":"Firmware integrity","weight":20,"measures":"Open source, reproducible builds, signed updates, and a secure element. Whether an independent party can verify the code running on the device matches the code published."},{"key":"supplyChain","label":"Supply chain","weight":15,"measures":"Tamper-evident packaging, direct-from-manufacturer purchase, and whether a device can be verified as genuine on first use."},{"key":"disclosure","label":"Disclosure conduct","weight":15,"measures":"How the vendor has handled past defects: speed of acknowledgement, accuracy of initial guidance, willingness to correct, and whether affected users were told the truth early. Past conduct is the best available predictor of conduct during the next defect."},{"key":"interop","label":"Multisig & recovery portability","weight":15,"measures":"Standard descriptor support, breadth of compatible wallets, and whether a holder can reconstruct and spend without the vendor's own software. A device you cannot recover from independently is a vendor dependency."},{"key":"privacy","label":"Privacy & data handling","weight":10,"measures":"Customer data collection and breach history. Leaked purchase records produce years of targeted phishing and physical-coercion risk that outlive any firmware fix."}],"devices":[{"slug":"coldcard","name":"Coldcard","asOf":"2026-08-03","incidentSlug":"coldcard-entropy-2026","scores":{"entropy":25,"firmware":60,"supplyChain":85,"disclosure":55,"interop":75,"privacy":80},"rationale":{"entropy":"A firmware defect caused affected devices to bypass the hardware random number generator and fall back to a predictable software generator. Every model line proved affected: Coinkite's advisory, updated August 1, estimates roughly 40 bits of effective entropy on Mk2 and Mk3 and roughly 72 bits on Mk4, Q and Mk5, against an intended 128. The defect shipped in March 2021 and remained undetected in public source for roughly five years. A dedicated dice-entropy path of at least 50 independent rolls is the documented exception, and patched firmware protects new seeds only.","firmware":"Source-available with reproducible builds and a secure element, which is meaningful. The counterweight is that the entropy defect sat in publicly readable code for five years without being caught, which is evidence about the practical limits of that transparency rather than the intent behind it.","supplyChain":"Tamper-evident packaging, direct sales, and device attestation are strong and unaffected by this incident.","disclosure":"This score reflects conduct in both directions. Initial public reports were dismissed as FUD before being acknowledged and reversed the same day, and the first advisory told Mk4, Q and Mk5 owners they were unaffected, which was wrong. Against that, remediation has been unusually decisive: a technical backgrounder within a day, corrected scope by August 1, patched firmware across every model line, remaining vulnerable inventory destroyed, shipment halted, and users pointed to competitor devices including one made by the firm that published the competing analysis. The residual criticism is that the incorrect model guidance was replaced rather than visibly annotated as a correction.","interop":"Standard multisig with published descriptors is well supported and recoverable with independent tooling. Miniscript support ships only in Edge developer-preview firmware, which the vendor itself warns should not be used for a main stash.","privacy":"No known breach of customer purchase records."},"overall":59},{"slug":"ledger","name":"Ledger","asOf":"2026-08-03","scores":{"entropy":70,"firmware":45,"supplyChain":70,"disclosure":55,"interop":80,"privacy":20},"rationale":{"entropy":"Certified secure element with a hardware random number generator. No publicly documented defect in the entropy path. The generation process is not independently verifiable by the holder because the firmware is closed.","firmware":"The secure-element firmware is closed source and cannot be independently audited or reproducibly built. The 2023 Ledger Recover announcement demonstrated that firmware capable of extracting seed material could be delivered by update, which changed how many holders understood the device's trust model.","supplyChain":"Genuine-device attestation is strong. Broad retail distribution widens the surface relative to direct-only sales.","disclosure":"Acknowledged the 2020 breach and has published incident detail. Communication around Ledger Recover was widely criticised as unclear about the underlying capability.","interop":"Broad wallet compatibility, standard descriptors, and miniscript support in stable firmware. Recovery does not depend on Ledger's own software.","privacy":"The 2020 e-commerce breach exposed roughly a million email addresses and a subset of detailed delivery records including names, physical addresses, and phone numbers. Those records continue to drive targeted phishing and physical-coercion risk six years later. This is a permanent, unfixable exposure for affected customers and is the clearest example of why data handling belongs in a custody score."},"overall":59},{"slug":"trezor","name":"Trezor","asOf":"2026-08-03","scores":{"entropy":75,"firmware":85,"supplyChain":65,"disclosure":70,"interop":70,"privacy":45},"rationale":{"entropy":"Open-source entropy path with optional user-supplied entropy, independently auditable. No publicly documented defect.","firmware":"Fully open source with reproducible builds, the strongest transparency position in the category. Older models without a secure element remain vulnerable to documented physical-extraction attacks given device access.","supplyChain":"Tamper-evident packaging and holographic seals, with documented historical counterfeiting of devices through unofficial resellers.","disclosure":"Has generally acknowledged physical-attack research openly and published mitigations rather than disputing findings.","interop":"Standard descriptors and broad wallet compatibility. No shipped miniscript support, which limits use with policy-based vault designs.","privacy":"A 2024 breach of the third-party support ticketing system exposed contact details for a subset of users. Materially smaller in scope than the 2020 Ledger incident."},"overall":71},{"slug":"foundation-passport","name":"Foundation (Passport)","asOf":"2026-08-03","scores":{"entropy":85,"firmware":85,"supplyChain":80,"disclosure":75,"interop":75,"privacy":80},"rationale":{"entropy":"Two independent entropy sources combined at generation, with an open and auditable implementation. This design directly addresses the single-source failure mode the 2026 incident exposed.","firmware":"Open source with reproducible builds and a secure element.","supplyChain":"Air-gapped operation removes the USB attack surface entirely. Manufactured and assembled with a documented, verifiable process.","disclosure":"No significant defect disclosure event on record to assess against.","interop":"Standard descriptors, QR-based air-gapped signing, and broad multisig compatibility.","privacy":"No known breach of customer records."},"overall":81}]}