We can confirm that the BitBox02 and BitBox02 Nova are not affected by the recent Coldcard seed generation vulnerability. If your wallet was generated on a BitBox hardware wallet, there is no reason to worry.
Note there is one important exception: If you originally generated your recovery words on an affected Coldcard device and later restored them on a BitBox, the seed itself may still be vulnerable. We explain this distinction below.
What happened?
On July 30, 2026, Coinkite warned users about wallet seeds generated on certain Coldcard devices and firmware versions. According to their security advisory, the issue affects:
- Coldcard Mk3 running firmware version 4.0.1 or later
- Coldcard Mk4 and Mk5 before firmware version 5.6.0
- Coldcard Q before firmware version 1.5.0Q
For more details, see Coinkite’s technical explanation of the vulnerability.
If you generated a wallet on any of the mentioned devices in the past, and you are still actively using it today, your funds may be at risk. We are mentioning this explicitly, as this can also apply to BitBox users who imported a wallet generated by the affected Coldcard devices on their BitBox.
In such a case, do not panic and try to remain calm. Your next step should be to create a new wallet on the BitBox and send your funds from the affected wallet to it. Our support team can guide you through the concrete steps if you need help in doing so.
Why quality of randomness is so important
Every Bitcoin wallet starts with a large random number.
The size of this number alone is not enough. It must also be unpredictable, also referred to as “truly random”. If a random number generator produces only a limited or predictable set of results, an attacker can search that much smaller set instead of the full range of possible wallets.
This is why wallet security depends not only on keeping recovery words private, but also on generating them with sufficient entropy in the first place. We explain this concept in more detail in our article about how hard it is to guess a seed phrase.
How BitBox generates a wallet seed
BitBox does not rely on a single random number generator. When a BitBox creates a new wallet, it combines five independent sources of entropy:
- A true random number generator on the secure chip
- A true random number generator on the microcontroller
- A random value installed on each BitBox during factory setup, unique to each BitBox
- Randomness supplied by the host device running the BitBoxApp
- A cryptographic hash derived from the user chosen device password
The advantage of combining different entropy sources like this is redundancy. If you combine good randomness with bad randomness, the result is still good randomness. In other words, as long as at least one independent source remains unpredictable to an attacker, the result remains unpredictable as well. A weak or compromised source therefore cannot, by itself, compromise the wallet. This is part of our defense in depth approach.
We continuously audit our own firmware code, including research with frontier AI models, and can confirm that an initial review of the wallet generation logic in the BitBox firmware showed that the implementation functions as intended and described above.
This implementation in the open-source BitBox firmware can be reviewed by independent security researchers, while reproducible builds allow you to verify that the published firmware matches the public source code. You can also find a broader overview on the BitBox security page.
Why BitBox is not affected
The recent Coldcard security advisory does not describe a flaw in Bitcoin itself or in wallet standards. It concerns a bug in how the Coldcard firmware specifically generated and used the underlying random number during wallet creation, resulting in weak randomness.
BitBox uses different hardware, different firmware, and multiple sources of entropy as described above. Neither the BitBox02 nor BitBox02 Nova shares relevant code in this regard with the Coldcard firmware. Wallets generated on a BitBox are therefore not affected by this vulnerability.
What should I do to stay safe?
If your wallet seed was generated on a BitBox02 or BitBox02 Nova, no action is required. There is no need to change your wallet setup or move your funds.
As always, stay alert for phishing attempts that use security news to create urgency. BitBox will never ask for your recovery words. Never enter them anywhere, other than directly on a trusted hardware wallet.
Do not hesitate to contact our support team in case you still have any questions.
The BitBox team
Don’t own a BitBox yet?
Keeping your crypto secure doesn't have to be hard. The BitBox hardware wallets store the private keys for your cryptocurrencies offline. So you can manage your coins safely.
Both the BitBox02 Nova and the BitBox02 also come in a Bitcoin-only edition, featuring a radically focused firmware: less code means less attack surface, which further improves your security when only storing bitcoin.
Buy the BitBox02 Nova or grab a BitBox02 in our shop!

Shift Crypto is a privately-held company based in Zurich, Switzerland. Our team of Bitcoin contributors, crypto experts, and security engineers builds products that enable customers to enjoy a stress-free journey from novice to mastery level of cryptocurrency management. The BitBox02, our second generation hardware wallet, lets users store, protect, and transact Bitcoin and other cryptocurrencies with ease — along with its software companion, the BitBoxApp!