PROOFOFCUSTODY
Scores
Incidents
Learn
About
Get the Report
PROOFOFCUSTODY

The independent scoring system for Bitcoin custody. Every platform scored and ranked.

$1B+ in assets under custody expertise

No spam. Unsubscribe anytime.

PLATFORM SCORES
All ScoresCompareMethodologyIndependence StandardDataCustody Assessment
LEARN
Bitcoin 101Custody GuidesCustody InsuranceIs Your Setup Safe?Custody TimelineIncidentsFAQQuiz
COMPANY
AboutAuthorsEditorial IndependenceChangelogCorrections
RESOURCES
PodcastPressReport
CONNECT
Twitter / XLinkedInYouTubehello@proofofcustody.io
2026 Proof of Custody. Published by Onramp Bitcoin. Editorial Independence.PrivacyTermsproofofcustody.io
Custody

Coldcard alternatives: what to actually move to

The replacement device is the easy decision and the one that matters least. Here is what changes your exposure and what only changes the logo.

By Steve L, Editorial Lead·Reviewed by Proof of Custody Editorial
Published Aug 5, 2026
Before anything else

If you own a Coldcard and have not checked whether your seed is affected, do that first. Every model is affected at some magnitude, and patched firmware does not repair a seed that was already generated.

Check if you are affected →Full incident record

Since the entropy failure became public, the most common question we receive is which hardware wallet to buy instead. It is the wrong first question, and answering it directly does more harm than leaving it alone, because the reflex it satisfies is the reflex that built the exposure in the first place.

The swap that changes nothing

A holder moving from one single-signature hardware wallet to another single-signature hardware wallet has changed which company can ruin their week. They still depend on one vendor, one firmware lineage, and one entropy implementation. That is one failure domain before and one failure domain after.

Our hardware rubric puts numbers on how little the obvious swap buys. Coldcard scores 59 and Ledger scores 59 — identical totals, arrived at from opposite directions. Coldcard is marked down hardest on entropy and key generation, the dimension this defect destroyed. Ledger is marked down hardest on privacy and data handling after its customer database leaked, and on firmware integrity because the secure-element code cannot be independently verified. A holder fleeing one for the other has traded a key-generation risk for a physical-targeting risk and kept the total constant.

The devices we have scored

Our rubric weights six dimensions, with entropy and key generation weighted highest at 25% because a key generated from predictable randomness cannot be protected by anything downstream.

DeviceOverallWeakest dimension
Foundation (Passport)81Disclosure conduct (75)
Trezor71Privacy & data handling (45)
Coldcard59Entropy & key generation (25)
Ledger59Privacy & data handling (20)

A coverage note we would rather state than hide. We have scored 4 devices. Coinkite’s own advisory points displaced users toward Bitkey, Ledger, Trezor, Jade and BitBox, and we currently score only two of those five. BitBox02, Blockstream Jade, Bitkey, Keystone and SeedSigner are not yet assessed, and we are not going to imply a ranking we have not done. Bitkey is made by Block, the company that published the competing engineering analysis of this defect, which is worth knowing when reading either party on the other.

The question underneath the question

The useful measure is not which device you own. It is how many independent things have to fail before your bitcoin moves without your consent. Count domains, not devices. Three Coldcards in a multisig quorum are one domain, because one firmware defect reaches every key in the quorum at the same moment. That is not a hypothetical: it is the specific configuration that turned this defect into a systemic event rather than a series of unlucky individual losses.

ArrangementFailure domainsWhat that means
Single-signature hardware wallet1One device, one firmware, one key. Whoever compromises the entropy path or the device holds the coins.
Multisig, all keys from one vendor1Looks distributed, is not. One firmware defect reaches every key at once. This is the configuration that made the Coldcard incident a systemic event rather than an individual loss.
Multisig, keys from different vendors, self-managed2 to 3Technically the strongest self-managed answer. Every pillar of independence is achievable, and the entire burden of sustaining it over decades sits with one person.
Collaborative custody2The provider cannot move funds alone, which is real sovereignty. Vendor and entropy independence still depend on which devices the holder chooses, and geographic separation remains the holder's job.
Qualified single custodian1Strong on segregation, legal title, and operational discipline. Unchanged on independence: one institution can move the assets.
Multi-institution custody2Independence is structural rather than holder-maintained. Separate institutions generate and hold keys under their own ceremonies, in separate jurisdictions, and the burden of sustaining that sits with them.

Note what the table does not say. It does not say multi-institution custody is the right answer for everyone, and it does not say self-managed multi-vendor multisig is a compromise. The self-managed arrangement earns the strongest technical marks available to an individual. Its weakness is operational: every pillar of independence is achievable, and the entire burden of sustaining it across decades, moves, deaths and divorces sits with one person who is not being paid to remember.

If you are rebuilding anyway

An affected holder has to generate a new seed and move funds regardless. That is the cheapest moment they will ever have to fix the architecture rather than replace the device, because the migration cost is already being paid. The single highest-value change is not a better brand. It is ensuring that no two keys in your setup share a vendor, a firmware lineage, or an entropy source.

Where to go from here

Deciding what to move to

You have the failure-domain count and the device scores. What remains is matching an arrangement to how much operational burden you are willing to carry for the next thirty years. These are the routes we can actually stand behind.

  • Score your current setup against the independence standard

    Four pillars — vendor, entropy, control and operational independence — with a badge for arrangements that meet all four. Start here if you have not counted your own failure domains yet.

    →
  • Compare every platform we score

    90+ custody platforms scored on the same published methodology, filterable by whether the provider can move funds alone, whether keys are multi-institution, and what happens if the provider disappears.

    →
  • Collaborative custody: Unchained, Casa

    You hold keys, the provider holds one and cannot move funds alone. Removes the single-device failure domain while keeping you in the quorum. Vendor and entropy independence still depend on which devices you choose.

    →
  • Multi-institution custody: OnrampPublishes this site

    Three independent institutions generate and hold keys under their own ceremonies in separate jurisdictions. Independence is structural rather than holder-maintained, which is the tradeoff for giving up sole control of the quorum.

    →

Proof of Custody is published by Onramp Bitcoin. Onramp is scored by the same published methodology as every other platform and does not control rankings or coverage. How that is kept honest.

What this is based on

Device scores come from our published hardware rubric, assessed against publicly documented facts. Incident facts come from Coinkite’s advisory and updates, Block’s engineering analysis, and Galaxy Research’s loss reporting, each cited on the incident record. Proof of Custody has not independently reproduced any of that research. The incident is still developing and was last updated 2026-08-04.

How to cite
Proof of Custody, "Coldcard alternatives: what to actually move to", Steve L, updated 2026-08-05. https://proofofcustody.io/learn/coldcard-alternatives
Frequently asked questions
What is the best Coldcard alternative?+

There is no single answer, because the device is not the decision. On our hardware rubric Foundation Passport scores highest of the devices we have assessed, ahead of Trezor, with Coldcard and Ledger tied below them. But moving from one single-signature device to another leaves you with exactly one failure domain, which is the condition that made this incident a systemic event rather than an individual loss.

Should I switch from Coldcard to Ledger?+

Our rubric scores the two devices identically, for different reasons. Coldcard is marked down hardest on entropy and key generation after this defect; Ledger is marked down hardest on privacy and data handling after its customer database leaked, and on firmware because the secure-element code is closed source. Switching between them changes which risk you hold, not how much.

Is my Coldcard safe if I generated the seed with dice?+

Coinkite states that funds are at risk if the seed was created without at least 50 independent, private dice rolls and the wallet is not protected by a strong, unique BIP-39 passphrase. Fifty fair rolls contribute at least 128 bits on their own, which is why that path is treated differently. If you did not roll dice, treat the seed as compromised regardless of model.

Does updating the firmware fix an affected Coldcard?+

No. Coinkite states the patched firmware prevents the issue for newly generated seeds and does not repair or restore security to a seed already generated on vulnerable firmware. An affected holder must generate a new seed on fixed firmware and move funds to it. Updating alone leaves the existing keys reconstructible.

How many hardware wallets do I need?+

Counting devices is the wrong measure. Three devices from one vendor running one firmware is one failure domain, not three: a single defect reaches every key at once. Two devices from two vendors, with keys generated from separate entropy sources, is two. Independence is what you are buying, and it is counted by domain rather than by device.

Is multisig with several Coldcards safe?+

Not against this class of failure. A multisig quorum built entirely from one vendor's devices shares a firmware and an entropy path, so one defect can reconstruct every key in the quorum simultaneously. This is the specific configuration that turned the Coldcard defect into a systemic event, and it is why our independence standard scores vendor diversity separately from key count.