Security alert · 30 Jul 2026: a seed-generation flaw in Coldcard devices was disclosed. What to do →

Why use three different hardware wallet brands?

TL;DR

Using three makers means one company’s mistake can’t cost you your coins. With three brands, a bug, a bad batch or a supply chain problem at one company gets an attacker one key, and they need two.

What can go wrong at one maker

  • Firmware bugs. In 2026 it came out that some Coldcard firmware since 2021 had generated seeds with weak randomness. Every seed made on affected devices was at risk.
  • Supply chain. A tampered batch or a compromised distribution channel. See supply chain attacks.
  • Customer data leaks. A leaked customer list makes owners targets for scams.
  • The company itself. It can go bust or stop supporting a model. See if a maker goes bust.

Why the same brand three times is weaker

Three devices of one brand share firmware, chips and supply chain. One flaw hits all three at once, and your 2-of-3 becomes a single point of failure again, just with more hardware.

Mixing approaches helps too

Trezor and BitBox02 firmware is fully open source. Ledger’s Bitcoin app is open source too, but it runs on a closed operating system inside the secure element. A flaw in one design is unlikely to affect the others. More in open vs closed source.

What it costs

Three apps to learn and slightly different setup steps per device. The setup guide covers each one.

Trezor Safe 5: Buy from Trezor · Buy on Amazon
BitBox02: Buy from BitBox · Buy on Amazon
Ledger Nano S Plus: Buy from Ledger · Buy on Amazon