The incident affecting Coldcard users this week was extremely unfortunate. Security issues like this affect the entire self-custody ecosystem and can undermine crypto’s promise of being your own bank.
To reassure our users: The specific failure behind the Coldcard incident has no equivalent in how Zodl generates recovery phrases.
On Android, Zodl relies on the operating system’s cryptographically secure random number generator, which is backed by hardware entropy sources. On iOS, it relies on Apple’s equivalent, seeded from the device’s Secure Enclave. These are the same sources that provide for your device's encryption, the encryption of its connections, and of secure messengers you use.
On both platforms, Zodl generates 24-word recovery phrases from 256 bits of entropy, twice the industry-baseline 128 bits as in the Coldcard disclosure.
We do not implement the type of software fallback involved in the Coldcard incident. If the required entropy isn’t available, wallet creation fails rather than proceeding with a weaker source.
This assurance applies to recovery phrases generated by Zodl. If you imported a recovery phrase created elsewhere, its security depends on how that phrase was originally generated.
Keystone (
@KeystoneWallet) recovery phrases are generated using entropy from multiple independent hardware sources, rather than relying on a single source of randomness. There is equally no equivalence to the Coldcard failure in how Keystone generates recovery phrases.
High-quality entropy is fundamental to wallet security. We take our users’ security and privacy seriously, and we’re grateful for the trust they place in Zodl.