The Coldcard Incident: What Ballet Users Should Know

What happened in the recent Coinkite / Coldcard security incident?

On July 30, 2026, the company Coinkite disclosed that its Coldcard devices running certain firmware versions did not generate seed words with enough randomness, which means an attacker could reproduce those seed words and then steal those funds. Only their Coldcard devices running those firmware versions are affected.

Coinkite has released a firmware update fixing the issue, but upgrading it does not repair seed words that have already been generated, possibly years ago. If you also use a Coldcard device, refer to Coinkite's official advisory

https://blog.coinkite.com/coldcard-mk3-seed-generation-warning/

Does the Coldcard incident mean all hardware cold storage wallets are unsafe?

No. This incident traces back to a firmware bug, where a single code change by one manufacturer (Coinkite) affected the safety and security of its Coldcard wallets. It was a software engineering bug, and not a problem with hardware cold storage wallets in general.

Could this same kind of issue happen to my Ballet cold storage wallet?

No. This incident originated in Coldcard's firmware, which Ballet cold storage wallets do not have. Rather, Ballet wallets are all non-electronic, and therefore they never have computer chips nor any firmware. This feature of Ballet wallets is by design, for the best security.

The two components behind a Ballet wallet's private key — the private key entropy and the passphrase entropy — are generated independently at Ballet's facilities across two geographic locations (in the United States and in China). True randomness is drawn twice, once for each component, and it comes from physical dice rolls and not from software alone.

Ballet's key generation process is published at

https://ballet.com/2FKG

As a Ballet wallet user, do I need to do anything further to keep my funds secure?

No, you do not need to do anything else in terms of what’s happening in this Coinkite/Coldcard incident. This incident came from a defect in Coldcard's firmware, and Ballet cold storage wallets have no firmware and no chips, so there is nothing to update or change. However, as for all Ballet cold storage wallets, please make sure you keep them physically safe and secure, and do not allow any unauthorized personnel to gain access to them.

As a Ballet cold storage wallet user, how should I keep my digital assets safe?

Firstly, do not let anyone see the two private key components on your Ballet cold storage wallet: the private key entropy beneath the QR code sticker, and the passphrase entropy beneath the scratch-off. Only uncover them when you are ready to send assets out, and always keep the physical wallet itself secure. Remember to never photograph these private key components or send them to anyone, including to anyone claiming to be from Ballet support.

Secondly, do not lose or damage your Ballet wallet. The two private key components needed to generate your private key exist solely on the wallet, and there is no other backup. As we have always emphasized, Ballet does not keep any copies of them. If your Ballet wallet is ever lost or destroyed, then those assets may never be recovered.

Was this article helpful?
0 out of 0 found this helpful

Articles in this section