The replacement device is the easy decision and the one that matters least. Here is what changes your exposure and what only changes the logo.
If you own a Coldcard and have not checked whether your seed is affected, do that first. Every model is affected at some magnitude, and patched firmware does not repair a seed that was already generated.
Since the entropy failure became public, the most common question we receive is which hardware wallet to buy instead. It is the wrong first question, and answering it directly does more harm than leaving it alone, because the reflex it satisfies is the reflex that built the exposure in the first place.
A holder moving from one single-signature hardware wallet to another single-signature hardware wallet has changed which company can ruin their week. They still depend on one vendor, one firmware lineage, and one entropy implementation. That is one failure domain before and one failure domain after.
Our hardware rubric puts numbers on how little the obvious swap buys. Coldcard scores 59 and Ledger scores 59 — identical totals, arrived at from opposite directions. Coldcard is marked down hardest on entropy and key generation, the dimension this defect destroyed. Ledger is marked down hardest on privacy and data handling after its customer database leaked, and on firmware integrity because the secure-element code cannot be independently verified. A holder fleeing one for the other has traded a key-generation risk for a physical-targeting risk and kept the total constant.
Our rubric weights six dimensions, with entropy and key generation weighted highest at 25% because a key generated from predictable randomness cannot be protected by anything downstream.
| Device | Overall | Weakest dimension |
|---|---|---|
| Foundation (Passport) | 81 | Disclosure conduct (75) |
| Trezor | 71 | Privacy & data handling (45) |
| Coldcard | 59 | Entropy & key generation (25) |
| Ledger | 59 | Privacy & data handling (20) |
A coverage note we would rather state than hide. We have scored 4 devices. Coinkite’s own advisory points displaced users toward Bitkey, Ledger, Trezor, Jade and BitBox, and we currently score only two of those five. BitBox02, Blockstream Jade, Bitkey, Keystone and SeedSigner are not yet assessed, and we are not going to imply a ranking we have not done. Bitkey is made by Block, the company that published the competing engineering analysis of this defect, which is worth knowing when reading either party on the other.
The useful measure is not which device you own. It is how many independent things have to fail before your bitcoin moves without your consent. Count domains, not devices. Three Coldcards in a multisig quorum are one domain, because one firmware defect reaches every key in the quorum at the same moment. That is not a hypothetical: it is the specific configuration that turned this defect into a systemic event rather than a series of unlucky individual losses.
| Arrangement | Failure domains | What that means |
|---|---|---|
| Single-signature hardware wallet | 1 | One device, one firmware, one key. Whoever compromises the entropy path or the device holds the coins. |
| Multisig, all keys from one vendor | 1 | Looks distributed, is not. One firmware defect reaches every key at once. This is the configuration that made the Coldcard incident a systemic event rather than an individual loss. |
| Multisig, keys from different vendors, self-managed | 2 to 3 | Technically the strongest self-managed answer. Every pillar of independence is achievable, and the entire burden of sustaining it over decades sits with one person. |
| Collaborative custody | 2 | The provider cannot move funds alone, which is real sovereignty. Vendor and entropy independence still depend on which devices the holder chooses, and geographic separation remains the holder's job. |
| Qualified single custodian | 1 | Strong on segregation, legal title, and operational discipline. Unchanged on independence: one institution can move the assets. |
| Multi-institution custody | 2 | Independence is structural rather than holder-maintained. Separate institutions generate and hold keys under their own ceremonies, in separate jurisdictions, and the burden of sustaining that sits with them. |
Note what the table does not say. It does not say multi-institution custody is the right answer for everyone, and it does not say self-managed multi-vendor multisig is a compromise. The self-managed arrangement earns the strongest technical marks available to an individual. Its weakness is operational: every pillar of independence is achievable, and the entire burden of sustaining it across decades, moves, deaths and divorces sits with one person who is not being paid to remember.
An affected holder has to generate a new seed and move funds regardless. That is the cheapest moment they will ever have to fix the architecture rather than replace the device, because the migration cost is already being paid. The single highest-value change is not a better brand. It is ensuring that no two keys in your setup share a vendor, a firmware lineage, or an entropy source.
Device scores come from our published hardware rubric, assessed against publicly documented facts. Incident facts come from Coinkite’s advisory and updates, Block’s engineering analysis, and Galaxy Research’s loss reporting, each cited on the incident record. Proof of Custody has not independently reproduced any of that research. The incident is still developing and was last updated 2026-08-04.
Proof of Custody, "Coldcard alternatives: what to actually move to", Steve L, updated 2026-08-05. https://proofofcustody.io/learn/coldcard-alternativesThere is no single answer, because the device is not the decision. On our hardware rubric Foundation Passport scores highest of the devices we have assessed, ahead of Trezor, with Coldcard and Ledger tied below them. But moving from one single-signature device to another leaves you with exactly one failure domain, which is the condition that made this incident a systemic event rather than an individual loss.
Our rubric scores the two devices identically, for different reasons. Coldcard is marked down hardest on entropy and key generation after this defect; Ledger is marked down hardest on privacy and data handling after its customer database leaked, and on firmware because the secure-element code is closed source. Switching between them changes which risk you hold, not how much.
Coinkite states that funds are at risk if the seed was created without at least 50 independent, private dice rolls and the wallet is not protected by a strong, unique BIP-39 passphrase. Fifty fair rolls contribute at least 128 bits on their own, which is why that path is treated differently. If you did not roll dice, treat the seed as compromised regardless of model.
No. Coinkite states the patched firmware prevents the issue for newly generated seeds and does not repair or restore security to a seed already generated on vulnerable firmware. An affected holder must generate a new seed on fixed firmware and move funds to it. Updating alone leaves the existing keys reconstructible.
Counting devices is the wrong measure. Three devices from one vendor running one firmware is one failure domain, not three: a single defect reaches every key at once. Two devices from two vendors, with keys generated from separate entropy sources, is two. Independence is what you are buying, and it is counted by domain rather than by device.
Not against this class of failure. A multisig quorum built entirely from one vendor's devices shares a firmware and an entropy path, so one defect can reconstruct every key in the quorum simultaneously. This is the specific configuration that turned the Coldcard defect into a systemic event, and it is why our independence standard scores vendor diversity separately from key count.