You can hold a hardware wallet, weigh it, read its spec sheet, and inspect the box it came in. What you can't do is look at the hardware wallet firmware running inside it, and that firmware is the piece deciding how your private keys get created, what the screen shows you before you approve a transaction, and whether the button you press means what you think it means. Buyers compare screens and prices because those are the parts you can see. The code is where the outcomes are decided.

A flaw that surfaced this summer made the point more sharply than any argument could.

A five-year-old bug, discovered by the people draining wallets

Starting on 30 July 2026, an attacker began emptying Coldcard devices in four waves. TRM Labs put the preliminary total at roughly 1,816 BTC, around 116 million USD, taken from more than 5,200 addresses, with the caveat that funds were still moving and victims often surface long after the event.

The cause wasn't a broken chip or a stolen device. It was a build configuration error in firmware version 4.0.1, shipped in March 2021, which caused affected units to fall back on a weak software random number generator instead of drawing from the hardware entropy source during seed creation. Key strength dropped from 128 bits to as little as 40 bits. Forty bits is a number a motivated attacker can search.

Two details deserve attention. The first is that the flaw sat quietly for around five years while the devices did everything a user would expect: they showed the right screens, signed the right transactions, and gave no sign anything was wrong. The second is that updating the firmware doesn't repair the damage, because the weak keys were already generated. Anyone who created a seed on an affected device during that window has to move their coins to a new one.

We've written separately about what the Coldcard incident means for Bitcoin holders. What follows is the more general lesson, because this could have happened to any vendor.

What firmware controls that you never see

Firmware is the software living on the device itself, and on a wallet it holds four jobs that decide whether your crypto stays yours.

The first is key generation, where the code picks the source of randomness your private key gets built from. Rendering the transaction on screen is the second, and it settles whether what you read matches what you're about to approve. Third comes confirmation: whether a button press on the device is required, and whether anything can route around it. Your backup passes through the same code on its way out, which determines what leaves the device and in what form.

Get any one of those wrong and the rest of the security story stops mattering. A certified chip protecting a key that was weak the moment it was born protects nothing.

Four things worth checking before you trust a device

You can't read the firmware yourself, and pretending otherwise helps nobody. What you can do is check whether someone qualified has, and whether the design limits how much damage a bug can do.

Has an independent firm audited it, and can you read the report? A vendor saying "audited" in marketing copy is not the same as a published report with findings you can look up. Ryder's firmware was audited by Halborn and the full report is public, which lets you check the scope rather than take our word for the conclusion.

Are keys generated inside a certified secure element, or in general-purpose code? This is the difference that would have contained the Coldcard failure. On the Ryder One, keys are generated inside an EAL6+ certified Infineon SLC38 secure element and never leave the chip. Firmware asks the chip for a key; it doesn't roll one itself in software where a build setting can quietly swap the entropy source. That narrows the blast radius of a firmware mistake considerably, though it doesn't shrink it to zero, and any vendor telling you their device cannot fail is selling something.

Can you see what you're signing? Blind approval turns every firmware bug into a signing bug. Every transaction on the Ryder One renders in readable detail on the 1.6-inch AMOLED screen before approval, and the physical button is wired directly to the secure element, so no software path can sign without your press.

What's the attack surface when the device is idle? Fewer radios means fewer ways in. The Ryder One communicates over NFC only, with no Bluetooth, no Wi-Fi, and no wired data port, so it stays silent unless you physically tap it.

Firmware risk and backup risk are the same conversation

Here's the part that connects the Coldcard story to how you store your backup. When your recovery depends on one seed phrase, written once at setup, the quality of that phrase is fixed forever at the moment the firmware generated it. You can stamp it into steel, split it across two safes, and hide it well. None of that helps if the number underneath was weak from the start, and none of it helps if the single object holding it burns or walks off.

TapSafe Recovery approaches the backup half differently by splitting it: the Recovery Tag holds 50%, your paired phone holds the other 50% encrypted in your iCloud or Google Drive rather than on the handset, and optional Recovery Contacts hold 25% each without seeing anything about your wallet. It runs on a custom implementation of Shamir's Secret Sharing. Your seed phrase stays available on-device as a last resort and follows the BIP-39 standard, so you can always leave for another wallet.

That handles losing a backup. It doesn't handle bad key generation, which is why the chip generating the key matters as much as the scheme protecting it. Both halves have to hold.

What to do if you're holding an affected device

If you generated a seed on a Coldcard between March 2021 and the patch, treat those keys as compromised and move the funds to a wallet with a freshly generated seed. Updating firmware alone leaves you exposed, because the weakness lives in the key, not the code path that made it.

More broadly, buy on the questions above rather than on screen size. Who audited the firmware, and can you read the findings yourself? Key generation is worth asking about directly, because there's a real difference between a key born inside a certified chip and one assembled in general-purpose code. It's also fair to ask what the device does while it sits in a drawer, since a radio that's always listening is a surface you never chose. A wallet earns trust by making its failure modes small and legible, and that's a property you can check before you hand it your savings.

Want a wallet whose audit you can read and whose keys never leave the chip? Get your Ryder One.


Meta description: A firmware bug drained 116 million USD from hardware wallets after five years unnoticed. What wallet firmware controls, and four things to check before trusting one.

Meet Ryder One
Meet Ryder One

The only crypto wallet you can install on a crowded subway.
Set it up in less than 60 seconds and just tap your phone to send, swap, and recover.

Learn More