COLDCARD RNG incident the public record, collected and explained
Informational only, and this site never asks for your seed words. details

Informational only. This is an open source collection of what others have published about the incident, together with an explanation of it. It is not financial, security or legal advice, and not a substitute for professional advice about your own situation. It is not affiliated with, endorsed by, or speaking for Coinkite. Material is attributed and quoted as published; where sources disagree their scenarios are kept separate with their assumptions rather than reconciled into one answer. Everything is meant to be checked against the linked evidence rather than taken on trust. Act on your own judgement about a particular situation. Editorial standards and corrections.

Do not disclose recovery material to a website, form, message or support account. This site never asks for it, and contributions containing recovery words or private keys are not accepted.

Plain language Updated 15 Aug 2026

How to cite this record

Cite the publisher first and this archive second, and name the state you read.

The short version

Cite the publisher first and this archive second. What Coinkite, Block, LLFOURN or anyone else said is theirs; what this project contributes is the preserved state, the time it was observed, and the record that the state existed. A citation that names only cc-vuln.org attributes someone else's statement to us, which is the one thing this record is built not to do.

Citing a source held in the record

This is the normal case, and the reason to involve this archive at all is usually that the page has since changed or gone. Give the original publication, then the state and where it is preserved:

Coinkite. "Mk3 security advisory." 30 July 2026.
  https://blog.coinkite.com/coldcard-mk3-seed-generation-warning/
  State of 1 August 2026, 00:17:31 UTC preserved at
  https://cc-vuln.org/record/sources/coinkite-mk3-advisory/

Every registered source has a page of that shape at /record/sources/, listing each state held, when it was observed, and what changed between one state and the next. Quote the capture time when the wording matters, which for a live incident it usually does: that advisory said three materially different things in thirty hours, and a citation without a time does not say which one you read.

Some held states were not collected by this project. The two earliest states of that advisory were recovered from the Internet Archive after the fact, and are marked provenance: wayback wherever they appear. Cite those to the Wayback Machine, which collected them, rather than to this project, which inherited them. The source page says which is which for every state it holds.

Citing the project itself

Appropriate when you are citing the collection, the change record, or a figure it derived rather than one it reports.

cc-vuln.org. COLDCARD predictable-RNG incident archive. 2026.
  https://cc-vuln.org/ (commit 0e17c99e366f, accessed 15 Aug 2026)

The author is the project, not a person: the site is published pseudonymously, and attribution to "cc-vuln.org" is both what the licence asks for and all there is.

@misc{cc-vuln-coldcard-2026,
  author       = {{cc-vuln.org}},
  title        = {{COLDCARD} predictable-{RNG} incident archive},
  year         = {2026},
  howpublished = {\url{https://cc-vuln.org/}},
  note         = {Commit 0e17c99e366f, accessed 15 Aug 2026}
}
{
  "id": "cc-vuln-coldcard-2026",
  "type": "dataset",
  "title": "COLDCARD predictable-RNG incident archive",
  "author": [{ "literal": "cc-vuln.org" }],
  "publisher": "cc-vuln.org",
  "issued": { "date-parts": [[2026]] },
  "URL": "https://cc-vuln.org/",
  "accessed": { "date-parts": [[2026, 8, 15]] },
  "note": "commit 0e17c99e366f"
}

A repository citation, including for the capture tooling, is in CITATION.cff, which GitHub renders as a "Cite this repository" button.

Naming the state you read

This record changes: sources are polled on a schedule, new material is registered, and pages are corrected. An "accessed" date alone therefore points at nothing recoverable. Every build stamps the commit it was made from, in the page footer and at /version.json, along with how much of the record existed at that commit. Quote that commit and the state you read can be reconstructed exactly from the public repository.

There is no DOI. Citing the URL together with the commit identifies the state precisely, which a DOI on a moving record would not; if that changes it will be published here and in CITATION.cff.

What citing this record does and does not assert

Read the marker, not the site
  • A held capture evidences publication, not truth. It establishes that this text was served from that URL when the archive read it. Whether the claim inside it is correct is a separate question, and the site marks that separately.
  • Carry the evidence basis across. Every material claim here is marked verified, reported, derived or unverified, and separately contested where sources disagree. Citing a reported claim as though this site had verified it misrepresents both of us. Where the site presents several parties' incompatible figures, it is because it does not adjudicate between them, and a citation that picks one should say who published it.
  • This is not an evidentiary chain. There is no timestamping authority and no signature over any capture. Snapshot hashes are this project's own change-detection and audit data, and they are not published as proof of provenance or tamper resistance. Where independence matters, cite a Wayback Machine copy alongside, and where none exists, say so.
  • Published pages carry excerpts, not mirrors. Source pages show a diff, a short excerpt and a link. The complete captures stay local, so an excerpt is evidence of the passage quoted rather than of everything the source said.

What is stable

Citations are made to last, so these are commitments rather than current behaviour:

  • Source identifiers are permanent and never reused. coinkite-mk3-advisory means one source for good, so /record/sources/coinkite-mk3-advisory/ is safe to cite.
  • Retired routes redirect permanently rather than disappearing. Pages have been merged and rebuilt already; every published URL still resolves, and that is a build gate rather than an intention.
  • Snapshots are append-only, from 6 August 2026. A snapshot is not rewritten or deleted, including one this project later decides was wrong: a bad capture is corrected by a later capture or a classification beside it, never by editing the record. Redacting personal data this project itself leaked is the one standing exception. The rule is dated because the archive has not always met it: a capture-method migration on 4 August 2026 deleted the earlier captures of five Reddit sources, and two sets of duplicate media from the first days of collection were removed on 6 August. Both are recorded, the first in corrections and both in the repository changelog with file sizes and hashes. Everything held now, and everything captured since, is covered by the rule as stated.
  • The register is published as data. /record/sources.json against a versioned JSON Schema, with the change record at /record/changes.json. Machine consumers should read those rather than scraping the pages.

Announcements on nostr

The project announces record updates on nostr as npub1pfuvza2kkeqjqnp6l2tlqr2ewgx5ue0kc7rwztxvjr8p5wcec3zsrvp9w2. The identifier [email protected] verifies that key against this domain, so a client can confirm the account is this project's and not an impersonator's. Announcements point at the record; they are not part of it, and nothing cited here depends on one.

Licence and attribution

The project's own writing, diagrams and data are CC BY 4.0: copy, mirror and adapt them, including commercially, with attribution to cc-vuln.org and a link. The capture tooling and the site code are MIT. Attribution is not only courtesy here: the claims are graded and linked to artefacts, and material stripped of its attribution and markers can no longer be rechecked, which turns a record into an assertion.

Material captured from other people is neither of those licences. It remains its authors' copyright, held for research and archival purposes and quoted with attribution. Reusing it is between you and them. Full terms are in LICENSE-CONTENT.md.

For journalists and researchers

The project is independent, pseudonymous, unfunded and not affiliated with any party in the record. It carries no advertising and sells nothing. Questions about method, requests for the reasoning behind a figure, and pointers to material the record is missing all go to [email protected].

What this project will and will not do

Will: point to the primary material behind anything published here; explain how a capture was taken, how a difference was classified or how a derived figure was calculated; say plainly where the evidence runs out, which is collected under known limits; and correct anything shown to be wrong, in public, at /corrections/.

Will not: adjudicate between the parties, or supply a quote that does; assess an individual's wallet or holdings; recommend a course of action; or withdraw correctly reported material from the record because a party would prefer it gone.

The whole collection, the capture tooling, the review classifications and this site are public at the source repository. Anything asserted here can be re-derived from it, which is the point.