Intro

Randomness Is Not a Software Decision

Ledger Enterprise was not affected by the recent Coldcard incident. Here's why hardware-rooted, independently certified randomness makes the difference.

Why Ledger Enterprise Was Never Exposed to the Coldcard Vulnerability Class

Ledger Enterprise is not affected by the recent Coldcard incident. For institutions holding assets using the platform, this is a good moment to explain why, not as a response to any single concern, but because the incident illustrates exactly the kind of failure Ledger’s architecture was built to guard against. 

What Happened

According to Coinkite's own advisory, firmware released in March 2021 affected multiple Coldcard models through their recently fixed versions. Seeds generated on the affected firmware carried significantly reduced entropy. Private keys derived from those seeds were reconstructible offline, with no need for physical access or user interaction. Fixed firmware is now available for every affected model, and Coinkite has published migration guidance for impacted users. Coinkite's investigation is ongoing, and we will update this as their advisory evolves.

The underlying lesson is not new, but it is easy to underweight until an incident like this makes it concrete. Every private key traces back to one number, the seed. If that number can be predicted or reconstructed, everything derived from it can be too. A weak seed looks identical to a strong one until someone with the right knowledge goes looking.

How Ledger Enterprise Is Built Differently

At Ledger Enterprise, Shared Owner seeds are generated by Personal Security Devices using the hardware True Random Number Generator within the Secure Element. The relevant production seed generation path has been reviewed and does not provide any fallback to a software based or otherwise non-secure RNG. There is no code path where a configuration check can silently degrade to a weaker source. If the hardware generator encounters an anomaly, the device halts rather than continuing on predictable entropy.

This is architecture, not assurance. Financial Institutions working with Ledger Enterprise are not trusting a claim about randomness. They are relying on hardware that is built to catch degraded entropy before it is ever used to generate a key.

Independently Verified, Not Self-Certified

Claims about security are only as good as the parties willing to test them. The TRNG inside Ledger Enterprise's Secure Element is evaluated under AIS-31, the German BSI methodology used within the Common Criteria scheme, which examines the physical noise source itself rather than only the output it produces. It is certified at PTG.2, a classification reserved for genuine physical entropy sources with tested and independently evaluated behavior. The Secure Element carries Common Criteria certification at EAL5+ or EAL6+, depending on the PSD.

LedgerOS, Ledger Enterprise platform and PSDs are reviewed regularly by our internal security team, the Donjon, and undergo recurring evaluation by independent laboratories including EDSI and Synacktiv. This is not a one-time audit. It is an ongoing process, built into how the platform is maintained.

Certification Is Not a Finish Line

The work doesn't stop at certification. It's what keeps the platform measurable, monitored, and tested against exactly this class of failure.

The Donjon does not only test Ledger's own products. Our team actively works to find flaws before anyone else does, including through AI-assisted vulnerability research, an approach that mirrors how sophisticated attackers now operate. Modern language models have made it materially easier to rediscover vulnerabilities, reverse-engineer patches, and build exploitation tooling. The gap between a fix being published and a vulnerability being weaponized is shrinking. If adversaries are moving at machine speed, our own review process has to as well, and it does.

PSD firmware versions used across Ledger Enterprise key ceremonies fall within the scope of the review described above. The entropy source and seed-generation path for Shared Owner seeds are confirmed unaffected.

Based on our analysis completed as of August 3, 2026, no master-seed regeneration, wallet migration, key rotation, or other remedial action is required for institutions running Ledger Enterprise.

What This Means for Institutions

Enterprise clients can continue operating as they do today. Governance keys and signing keys generated through Ledger Enterprise's Personal Security Devices and Secure Element architecture aren’t exposed to the class of vulnerability described in Coinkite's advisory. That is the outcome of an architecture designed around hardware-rooted randomness from the outset, independently verified, with no fallback path.

We will continue to monitor Coinkite's advisory as their investigation progresses, and we will share updates if anything materially changes.

More