Thirteen years of telling people how to hold their own keys — paper wallets and Tails, Ledger, Trezor, KeepKey, Digital BitBox, Coldcard — laid against the hacks and breaches that eventually hit each of them. What we backed the most, when, and what we actually said.
Across the LLM-Wiki transcript archive and The Bitcoin Group's 483 transcripts, Ledger was our most-covered hardware brand — 29 tutorial/interview episodes plus heavy newsroom mention — and our earliest, going back to Jamie Nelson's 2014 review. Paper wallets came first of all (2013), and Mad Bitcoins taught them hands-on with Tails Linux in 2014. Trezor ran the longest span (2014–2023), Coldcard was the most concentrated (a 2019 teaching burst), and KeepKey, Digital BitBox and OpenDime got passing coverage. One theme connects the whole arc: we were warning about weak randomness — the exact failure behind the 2026 Coldcard hack — as far back as 2013.
| Device / method | Episodes | Span | Mainly |
|---|---|---|---|
| Ledger | 29 + TBG news | 2014–2020 | WCN + MB |
| Paper wallets | 22 | 2013–2022 | MB + WCN |
| Coldcard | 19 | 2018–2020 | WCN (Max) |
| Trezor | 15 | 2014–2023 | WCN + MB |
| Tails (OS, often w/ paper wallets) | 11 | 2014–2019 | WCN + MB |
| Digital BitBox | 4 | 2013–2019 | WCN |
| KeepKey | 3 | 2017–2018 | WCN |
| OpenDime | 2 | 2018–2019 | WCN |
| "Hardware wallet" (generic) | 72 | 2013–2021 | WCN |
Counts are transcript/summary matches across WCN + Mad Bitcoins (LLM-Wiki, 1,934 episodes) and keyword matches across The Bitcoin Group's 483 transcripts. "Ledger" and "hardware wallet" figures include some newsroom mentions alongside dedicated segments.
Before any device, cold storage on the show meant a paper wallet. Mad Bitcoins ran full step-by-step tutorials in July 2014 — PC and Mac versions — built around booting Tails Linux so the key was generated on an amnesiac, offline operating system. It was the right instinct for the era (keep generation off a networked machine), and it is exactly the setup you remember airing. Worth being honest in hindsight: the industry moved away from paper wallets between 2016 and 2019 — they are a single point of failure, easy to generate insecurely, and they push address reuse. The modern equivalent is a hardware wallet with the seed written on metal.
Our hardware-wallet coverage effectively starts with Ledger: Jamie Nelson's installation and review of the Ledger USB wallet in December 2014, then a Mad Bitcoins interview with Ledger at Bitcoin Miami 2015, and years of newsroom mention on The Bitcoin Group. We treated it as the accessible on-ramp to self-custody. The Ledger story later turned on a data breach rather than a device break — see the incidents below.
Trezor shows up from 2014 and never really leaves, largely through interviews with its people — Slush and Pavol Rusnak on WCN's "Proof of Work," and an HCPP interview with Slush alongside Tone Vays and Thomas Hunt. It was framed as the open-source, founder-led option.
The most concentrated hardware coverage we ever did: Max Hillebrand's 2019 teaching series on the Coldcard Mk2 — PINs, duress wallets, encrypted SD backups, air-gapped signing. That work, and how it stands against the July 2026 firmware hack, is its own report: Coldcard on WCN and Our Coldcard Coverage vs. the 2026 Hack.
Lighter touches: KeepKey (3 mentions, 2017–18), Digital BitBox (4, from 2013), and OpenDime — the Coinkite "Bitcoin bearer stick" — alongside the Coldcard coverage. None got a dedicated tutorial run.
The single most important thread in hindsight is randomness. A Bitcoin key is only as safe as the entropy that made it, and our house was on that beat from the very start.
In August 2013, Mad Bitcoins covered the Android / Java SecureRandom
bug in real time — twice. The
first
segment explained that a weak generator "could create non-random, and thus vulnerable,
Bitcoin wallet keys"; the
follow-up
reported "Google confirms Android crypto flaw was used in a $5,700 Bitcoin heist" and that
developers "were warned about the need to update how they handle pseudo-random number
generators." Thirteen years later, the 2026 Coldcard exploit is the same class of bug —
firmware that skipped its true random-number generator and made seeds guessable. We were right
about the danger in 2013; the industry kept relearning it.
Android's SecureRandom produced predictable values, causing some wallets to reuse
signature nonces — which lets anyone recover the private key from the public blockchain. ~55.8
BTC reported stolen; Bitcoin Wallet, Mycelium, BitcoinSpinner and blockchain.info affected.
Fixed by patching the PRNG and reading entropy from /dev/urandom. We
covered it live.
Kraken Security Labs showed that with ~15 minutes of physical access and a voltage-glitch on the microcontroller, the encrypted seed could be dumped from a Trezor One / Model T (and the same class of attack hit KeepKey). It needs the device in hand; the defense is a strong PIN plus a BIP-39 passphrase. A microcontroller-level flaw, not a remote break.
A misconfigured API exposed Ledger's e-commerce customer database: ~1,075,000 emails and ~272,000 fuller records (names, postal addresses, phone numbers), dumped publicly in December 2020. No keys, seeds or crypto were compromised — it was customer PII from the online store, entirely separate from the devices. The real damage was the aftermath: a long wave of phishing, "enter your 24 words" scams, and extortion/physical-threat emails to people now known to own crypto hardware at a home address.
Firmware 4.0.x (from March 2021) skipped the Coldcard's true hardware RNG, making seeds guessable; ~594 BTC (~$38M) was swept from ~500 wallets in 25 minutes on 31 July 2026. Only seeds generated on the affected firmware are at risk. Full breakdown in the Coldcard hack report.
Over thirteen years we backed, in rough order of emphasis, Ledger, paper wallets/Tails, Coldcard and Trezor. Every one of those later had a security event — but the events were different in kind: Ledger's was a marketing-database leak that never touched keys; Trezor's and KeepKey's needed the device physically in hand; paper wallets simply aged out of best practice; and Coldcard's was a firmware regression that arrived years after our coverage. The consistent, creditable thread is that we treated randomness and verification as the core of self-custody from 2013 onward — the "ain't so random" instinct — even as the specific gear and its specific failures changed underneath it.
SecureRandom vulnerability · 2013-08-11