No. Coinkite, the maker of Coldcard, never saw a user’s private key in the 2026 incident. According to Decrypt’s 4 August 2026 report, Coinkite disclosed a firmware flaw, traced to a March 2021 build, in which the air-gapped Coldcard wallet used a software fallback instead of its hardware random number generator to create wallet seeds. That made some private keys guessable by any attacker who understood the weakness – it did not give Coinkite, or anyone else, visibility into a key that wasn’t already there. Ledger differs from Coldcard on that specific randomness question, but Ledger has run into a separate and more direct version of the vendor-visibility question with its optional Recover feature, which by its own published design sends encrypted pieces of a user’s seed to outside custodians.
“Can the vendor see my keys” is actually shorthand for two separate technical questions. The first is whether the randomness used to generate a seed phrase was strong enough that no outside party – vendor, attacker, or anyone else – could guess or reconstruct it. That is a question about attacker access, not vendor access, and it is where Coldcard’s 2026 incident sits. The second is whether key material, even encrypted, ever leaves the device to anyone other than the user, including the vendor or partners the vendor chooses. That is the actual vendor-visibility question, and it is where Ledger’s 2023 Recover controversy sits. Treating the two as the same failure is the mistake this page exists to correct.
Per Decrypt, Coinkite disclosed the flaw the week before its 4 August 2026 report and released patched firmware shortly after, urging affected users to move funds to newly generated wallets. The bug meant that instead of drawing entropy from the device’s hardware random number generator, some seeds were generated through a software fallback path, which made some private keys guessable, per Decrypt’s reporting. This was not a case of Coinkite or anyone else seeing a user’s key directly – it was a weakness that any attacker who identified it could exploit from outside. Decrypt reported that losses tied to the flaw have reached roughly $130 million to date, with other thefts still under investigation. That figure comes from one outlet, is described as approximate, and Coinkite did not respond to Decrypt’s request for comment – so there is no independent confirmation of either the total or how it was calculated.
Ledger’s CTO, Charles Guillemet, told Decrypt that Ledger’s own hardware wallets were not affected because they generate the 24-word Secret Recovery Phrase differently. He said the phrase comes from “a true hardware random number generator” built into what Ledger describes as a certified Secure Element, and that the process “produces the full 256 bits of entropy for every seed.” That is Ledger’s own characterization of its architecture, relayed through one journalist’s interview – not a citation to a published third-party certification report in this evidence.
Guillemet drew a distinction that matters beyond this one incident: “Open source and reviewed are not the same thing,” he told Decrypt. He said the Coldcard flaw “sat in public code for more than five years” before, reportedly, an adversary used AI to find it – a claim Decrypt reported as Guillemet’s characterization, with the AI-discovery detail itself hedged as unconfirmed. Decrypt’s report separately noted that in May, a researcher used the AI tool Claude Opus 4.8 to identify a four-year-old vulnerability that could have enabled unlimited minting of Zcash, after which the token fell more than 40% in a single day – an example the reporting placed alongside Guillemet’s comments rather than a case he was shown citing himself. Guillemet said Ledger has spent the past two years using AI alongside human engineers to look for vulnerabilities before attackers do, and that its Donjon research lab “exists to try to break our products before anyone else can” – again, Ledger’s own account of its internal process, not an outcome verified by an outside party in this evidence.
The randomness question is not where a reader should look for a vendor-visibility failure. Recover is. In May 2023, Ledger introduced Recover, an optional subscription letting users back up their seed, and on 21 June 2023 the company published a white paper on the service, according to Cointelegraph. The paper describes splitting a user’s seed into shares using Shamir’s Secret Sharing, with the service – provided by the digital-asset security firm Coincover – then expected to launch in the fourth quarter of 2023, according to Cointelegraph. Guillemet told Cointelegraph that the white paper’s main takeaway was that the new service is “100% secure,” and separately said the feature “does not change the security” of Ledger devices – both statements are the CTO’s own assurance about the design, per Cointelegraph, not text drawn from the white paper itself.
That framing did not settle the argument, because the underlying mechanics are exactly the vendor-visibility question. Polygon Labs’ Mudit Gupta wrote, as quoted by Cointelegraph, that “the encrypted keys parts are sent to 3 corporations” who could together reconstruct a user’s key. Binance’s Changpeng Zhao asked, per the same report, “So the seed can leave the device now?” – pointing to what he framed as a departure from the industry’s usual pitch that keys never leave the device. BeInCrypto’s coverage of the same episode noted the announcement was “severely criticized by a portion of the Web3 community” over that same contradiction. The white paper itself states that having fewer than the required number of shares “does not give any information on the seed,” which is Ledger’s technical rebuttal to the reconstruction concern – but it does not change the fact that, by design, encrypted fragments of key material leave the device under Recover, something the core signing path in a Ledger device without Recover does not do.
The mistake is expecting the Coldcard incident to answer the question of vendor visibility. It doesn’t. Coinkite’s flaw was about the quality of randomness, exploitable by any attacker who found it – not about Coinkite’s own access to keys. The question a reader is actually asking – can a vendor see or reconstruct my key – is answered, imperfectly, by the Recover episode: Ledger’s design keeps core signing keys inside the Secure Element, per Guillemet, but the optional Recover feature sends encrypted key shares to parties Ledger selected, which is precisely what drew the 2023 criticism from Gupta and Zhao, per Cointelegraph. Being air-gapped, as Coldcard’s design is, or open source, as Trezor emphasizes, does not by itself settle either question – CoinPaper’s 7 August 2026 comparison notes that Coldcard’s Mk5 and Q models each use two secure elements while Ledger’s newer devices carry CC EAL6+ certification on their Secure Element chip, certifications that speak to the hardware, not automatically to every line of firmware that runs on it or to what an optional add-on service does with a seed after it exists.
This page cannot independently verify the $130 million Coldcard loss figure. It comes from one outlet, is described there as approximate with other thefts still under investigation, and Coinkite did not respond to that outlet’s request for comment – there is no on-chain audit or Coinkite statement in this evidence confirming the total.
This page cannot verify Ledger’s claims about its own Secure Element randomness process. Those claims come from a Ledger executive quoted in one article, not from a published independent certification or lab report in the evidence available here.
This page also cannot say whether an AI tool actually found the Coldcard flaw, as Guillemet suggested to Decrypt using the word “reportedly” – that detail is unconfirmed in the sourcing available.
On Recover, this evidence dates to the feature’s 2023 announcement and white paper. It does not tell you the feature’s current adoption, opt-in rate, or operational status, and it does not confirm whether any of the 2023 criticisms from Gupta, Zhao or the wider community were later addressed by Ledger, because no source reviewed here covers that later period.
Finally, this page cannot tell you whether any specific hardware wallet vendor can see or reconstruct a user’s key today. It can only show, from the evidence available, that Coldcard’s incident does not establish that Coinkite could, and that Ledger’s own optional Recover feature is the one place in this evidence where the vendor-visibility question is actually in play.
Every fact above is attributed to one of these reports. Where they disagree, the article says so.
We measure how many people read this site. That is all it is used for — there is no ad network, no advertising cookie, and nothing sold to anyone. Decline and the site works exactly the same. What we collect