Watch Simply Bitcoin Live!
Every Monday-Friday 12:30pm Eastern
Watch Simply Bitcoin Live!
Every Monday-Friday 12:30pm Eastern
Watch Simply Bitcoin Live!
Every Monday-Friday 12:30pm Eastern
Watch Simply Bitcoin Live!
Every Monday-Friday 12:30pm Eastern
Watch Simply Bitcoin Live!
Every Monday-Friday 12:30pm Eastern
Watch Simply Bitcoin Live!
Every Monday-Friday 12:30pm Eastern
get updates
BACK TO NEWS
August 13, 2026
/
0
Min Read

Trezor's Firmware Lead Says Old Self-Custody Rules Still Hold After Coldcard Hack

Two weeks after the Coldcard entropy bug drained Bitcoin from hardware wallets that owners believed were untouchable, Trezor's firmware lead sat down to explain why his company's devices were not exposed to the same failure, and what he thinks the entire hardware wallet industry needs to change.

A FIRMWARE ERROR, NOT A HACK

The Coldcard incident stemmed from a code path introduced years before anyone noticed it. The flaw traced to a March 2021 firmware release and a build configuration error that caused seed generation to fall back on a weak software random number generator rather than the device's hardware-based source of entropy, collapsing effective key strength from a designed 128 bits down to as little as 40 bits on older devices. Attackers needed no phishing, no malware, and no physical access to the device itself to exploit it.

John, the firmware engineer at Trezor who joined the show, described the moment the news broke as deeply unsettling for anyone working on wallet security. He compared it to always unplugging the kettle before leaving the house, then one day driving past a burning building and suddenly doubting whether you actually did.

WHY TREZOR WASN'T HIT

According to John, Trezor's devices mix entropy from two independent sources when generating a new seed: randomness produced inside the device's own secure elements, and randomness contributed by the connected computer. Because neither side holds the full picture on its own, a malfunction or compromise in one source would not, by itself, weaken the resulting seed. He said Trezor also runs an automated entropy check that verifies a newly generated wallet actually mixed in randomness from the computer as intended, catching the kind of silent failure that let the Coldcard bug persist undetected for years.

He was careful to note that this protection depends on calling two genuinely separate randomness functions rather than one function twice, which he said is exactly where the Coldcard flaw went wrong. Trezor's newest device, the Safe 7, layers a third chip on top of that design. It pairs an Infineon Optiga secure element with TROPIC01, which works alongside OPTIGA Trust M and the device's main microcontroller, and which Trezor describes as the world's only independently auditable secure element. If either chip were ever compromised, John said, the other still holds the line.

SINGLE SIG ISN'T DEAD

Asked whether the exploit should push everyday holders toward multisig, John pushed back on the idea that single signature setups are now obsolete. He argued that added complexity carries its own risk, and that for someone simply stacking sats with a reputable, open source hardware wallet and a securely stored seed, a single device covers the dominant threat model of remote attacks and phishing without inviting new ways to make a costly mistake. His line was that multisig makes sense once the amount at stake is genuinely significant, not as a default upgrade for every holder.

THE BASICS THAT STILL APPLY

John's practical advice for holders was intentionally unglamorous: choose a reputable, open source vendor with a real bug bounty history, never give out a seed phrase to anyone under any circumstance, keep backups away from fire and water, and run periodic recovery tests to confirm a backup actually works. He warned against amateur entropy tricks like rolling your own dice-based seed unless a holder truly understands the subtle traps involved, calling it an advanced technique that should not go into the beginner playbook.

He also flagged the second wave of danger that follows an incident like this: phishing emails impersonating the affected vendor, timed to exploit exactly the anxiety the exploit created. His advice was to treat urgency itself as a warning sign, verify anything alarming through official channels, and never enter a seed phrase anywhere in response to a message, no matter how official it looks.

THE INDUSTRY'S NEXT TEST

Looking ahead, John said the biggest shift underway is that AI has lowered the bar for finding vulnerabilities like Coldcard's from a task only a handful of specialists could attempt to something anyone can now automate. His takeaway for the industry is to use AI defensively and proactively to find its own flaws first, while keeping human review in the loop, since he does not believe current AI tools can be trusted to patch a security critical system without a person verifying the fix does not introduce a new problem.

This story comes from the Simply Bitcoin Live show. Watch the full episode.

About Simply Bitcoin
Simply Bitcoin is an independent Bitcoin media network delivering daily news, analysis, and original shows. We believe in spreading the Bitcoin signal: truth, transparency, and freedom through education and self-sovereignty.

related materials

Related Stories
on Bitcoin & Freedom

all articles
Subscribe
Mark Cuban Declares Bitcoin Trade OVER | $39 Trillion Says He's WRONG
May 22, 2026
Sovereignty Has A Security Budget
Jul 31, 2026
They Trapped Elon Musk's Trillion. Yours Is Next. Got Bitcoin?
Jun 22, 2026

Stay in the Loop

Get the Best Bitcoin 
Stories, Daily
Subscribe to our free newsletter for the latest Bitcoin updates, top videos, and curated market insights, delivered straight to your inbox.