Coldcard does not ship two Secure Elements in the Ledger sense. Microchip ATECC608 and Maxim DS28C36B are authenticators: slots, HMAC, ECDSA, datasheet, no OS, no applets. Nobody loads Recover onto them. Open firmware on the MCU composes PSBTs, speaks microSD or QR (Q), applies policies. The two chips, from two vendors, hold shares of the secret and harden the PIN. One broken ROM must not suffice. That is all “dual SE” means here.
In July 2026, Coinkite disclosed an entropy bug dating to firmware 4.0.1 (March 2021). A draw supposed to come from the hardware RNG fell back on Yasmarang, a weak software PRNG. Seeds generated without enough dice became remotely brute-forceable. Thefts followed, on the order of a hundred million dollars. The two authenticators had nothing to say: the secret had been born too small, in the MCU.
Open MCU source did not prevent the bug from lasting five years. It made it readable afterwards. Corrected firmwares require user entropy. Migrating any seed born without dice on an affected version is not optional.
Fits if
Large Bitcoin amounts, air-gap, technical users, a key in a multisig.
Keep in mind
Entropy bug 2021–2026: migrate any seed without dice on affected firmware. Demanding UX. Bitcoin only. The two chips are not ST33s.
Related incidents
- 2026 — Coldcard entropy bug
Two SEs do not fix a seed born too short. Open source is not an audit. User entropy (dice) is not optional.
- 2018– — Clones and marketplaces
The first security ritual is commercial: who sold you the object, and what does attestation say on first plug-in?