Security alert · 30 Jul 2026: a seed-generation flaw in Coldcard devices was disclosed. What to do →

Reproducible builds: checking your wallet runs the published code

TL;DR

A reproducible build means anyone can compile the published source code and get a file identical, bit for bit, to the firmware the maker ships. It closes the gap between “the code is public” and “my device runs that code”.

The problem it solves

A maker can publish perfectly clean source code and still ship firmware built from something else. Without a way to compare, you can’t tell whether your device runs the published code.

How it works

  1. The maker publishes the source code and exact build instructions, usually a container with fixed tool versions.
  2. Someone independent builds the firmware from that source.
  3. They compare the hash (a fingerprint of the file) with the firmware the maker released.
  4. If they match, the released firmware was built from the published code.

Who checks

You can do it yourself if you’re comfortable with the command line. Most people rely on others who do: security researchers and projects such as WalletScrutiny, which track which wallet releases have been reproduced.

Which wallets

BitBox makes reproducible builds a central part of its approach, Trezor’s firmware can also be reproduced, and Blockstream publishes build instructions for the Jade. Check WalletScrutiny for the current status of any device and firmware version, since it can change per release.

Why it matters in this setup

It’s one reason the BitBox02 is in the guide. Combined with a closed design from another maker, you’re not relying on any single kind of trust.