Learn

The Coldcard bug: why a silent randomness failure can’t reach your vaults

In July 2026, thieves emptied bitcoin wallets by guessing keys that were supposed to be unguessable — a firmware bug had quietly fed those wallets predictable “random” numbers for five years. Could that happen to a Sealby vault? No. Here is why, in plain terms.

Key takeaways

  • The July 2026 wallet thefts came from one silent mistake: devices skipped their hardware randomness and built keys from predictable values for five years.
  • Sealby never rolls its own randomness — keys come from the operating system’s hardware-seeded source, so there is no homemade generator for a hidden mistake to break.
  • Key creation checks two separate system paths and stops cold if either misbehaves. A randomness problem would be an error on your screen, not five quiet years.
  • Even a misbehaving random number could not silently repeat a key — uniqueness is built into how vaults are constructed, not left to chance.
  • No trust required: you can create a vault from dice you roll yourself and verify the result with an independent tool.

One minute on what happened

On July 30, 2026, attackers began emptying bitcoin wallets whose keys they could simply guess: a firmware mistake from March 2021 had made affected devices skip their randomness chip and build keys from predictable values. Nothing looked wrong for five years — then tens of millions of dollars left in days. The blow-by-blow has been covered everywhere. The question it leaves anyone with an encrypted vault is simpler: could that happen to my data?

Why randomness is the whole game

Everything encrypted starts with a random number. Truly random, and guessing it is hopeless. Quietly predictable, and everything built on top still works perfectly — while protecting nothing. Worse, encrypted data can be attacked in private, on the attacker’s own computers, with no lockouts and no alarms. The strength of that first random number is the whole game.

Why it can’t quietly happen in Sealby

Sealby never rolls its own dice. Every key comes from the random source built into the operating system — hardware-seeded and maintained by Apple for the platform’s own security. There is no homemade generator inside Sealby for a hidden mistake to break, and nothing predictable — no timestamps, no device identifiers — is ever used as key material.

Two more safety nets. Key creation checks two separate system paths and stops cold if either misbehaves — an error on your screen, not five quiet years. And even a random number that somehow repeated could not silently protect two things with the same key, because uniqueness is built into how vaults are constructed. Every build is also tested against fixed values, so the kind of change that broke those wallets would fail Sealby’s build on day one.

No trust needed: roll your own dice

For your most sensitive vaults, you do not have to trust any generator at all — Sealby’s or Apple’s. Roll real dice, type in the rolls, and your vault’s keys and recovery phrase are built from your randomness. You can even check the result with a separate, independent tool. That is the real lesson of the wallet theft — not “trust us,” but “check us” — and it is the standard your files deserve.

Quick answers

Is Sealby affected by the Coldcard bug?

No. Sealby shares no code, firmware, or hardware with any wallet, and its keys come from the random source built into iOS — the one Apple seeds from dedicated hardware for the platform’s own security.

Could a hidden randomness bug ever weaken my vault?

This failure is designed out rather than promised away. Sealby checks two separate system randomness paths and stops immediately if either misbehaves — creation fails loudly instead of continuing with something weaker. The failure that emptied those wallets was exactly that: a silent switch to predictable numbers. In Sealby it has nowhere to hide.

How does Sealby generate its keys?

From the operating system’s cryptographic random source, hardware-seeded by Apple — never from timestamps, device identifiers, or anything predictable. Every build is also checked against fixed test values, so a change in the cryptography fails the build instead of shipping.

Do more recovery words mean a safer phrase?

Not by themselves. The words are a human-readable form of the random number underneath — the affected wallets produced normal-looking phrases from a tiny pool. What counts is where the randomness came from, not how many words encode it.

I used one of the affected wallets — what should I do?

Go by the maker’s official security advisory, not headlines: check whether your device, firmware version, and setup method are affected, and follow its migration steps. Nothing here is advice about third-party products.

Your vault is waiting.

Download Sealby and protect what matters. Setup takes under a minute, and there’s no account to create.

Download on the App Store

iPhone & iPad · iOS 17+ · Free