Corrections
What this project got wrong, what it says now, and what changed its mind.
A record that grades its own claims has to be able to say where it got one wrong. Every correction to a material claim on this site is listed here, newest first, and marked on the page where the claim was. The two together are the policy: a log nobody passing the claim would see, or a quiet edit with no index, would each be half of it.
This is not where sources changing their own pages go. That is the record's subject rather than an error of ours, and it is kept in the source change record, with the underlying captures preserved either way. Rewording, restructuring and tooling changes are in the repository history.
Corrections are welcome and are the most useful thing anyone can send. Name the page and the claim, say what is wrong, and include something another reader can check: [email protected]. Whoever reports a correction is credited here if they want to be. A claim is never quietly deleted: what it said stays on this page.
This log opened on 6 Aug 2026 and holds no entries. That records the state of the log, not a claim that the site has never been wrong: changes made before it opened are in the repository history, where every edit to every page is dated and attributable to a commit.
6 corrections since 6 Aug 2026
- Correction
The page said no source itemised a reconciliation between the two published wave-4 figures. The tracker had itemised one, in a capture this archive already held when the claim was published.
- It said
- coldcard-hack-tracker carries the wave at 443.34 BTC across 703 addresses, applying both @intangiblecoins corrections to the circulated list. Neither Galaxy nor the tracker itemises a reconciliation between those two wave-4 figures.
- It says now
- The tracker states its own derivation: it starts from 448.73 BTC, which it attributes to Galaxy rather than to @intangiblecoins, and drops six further destinations that already had prior on-chain history, 5.39 BTC, to reach 443.34. It also reads Galaxy's approximately 2,055 BTC ceiling as its high-confidence 1,596 plus that 448.73 candidate. Galaxy's own thread publishes neither 448.73 nor any itemised wave-4 component, so the reconciliation is the tracker's reading of Galaxy rather than Galaxy's own, and its arithmetic is not adopted here: 1,596 plus 448.73 is 2,044.73, not the 2,055 Galaxy states.
- Why
- Found on 7 August 2026 while rechecking the funds page against 6 and 7 August captures. The itemised derivation is in the tracker's own wave-4 source note, first captured at 20260803T131304Z, refined at 20260804T130740Z and unchanged through 20260807T132028Z. It was therefore in this archive before the claim was published, which makes this an error of reading rather than a source that moved underneath the page. Galaxy's side is confirmed by the held capture of its wave-4 caveat post, which states only that including the wave would bring the total to 2,055 BTC.
- Reported by
- Where
- /record/funds/
- Correction
The page counted three post-disclosure scam reports in the archive. Four further reports were already held and registered on the day it was published.
- It said
- Three post-disclosure reports are held.
- It says now
- The section no longer states a count. It says what kind of material is held and which artefacts are reproduced here rather than described, and the page now carries the phishing-email reports, the baited repository and the impersonation accounts it had left out.
- Why
- Found on 7 August 2026 while bringing the page up to date. A count of this project's own holdings is a claim in this project's voice, and it was wrong when published on 5 August: reddit-phishing-advisory-email, americanhodl-desktop-app-phishing, bitcoinrothbard-trezor-phishing and joecarlasare-fake-post-warning were all captured on 4 August 2026 and named no report on the page. The fix is not a larger number. A count of holdings goes stale on the next capture and invites exactly this error, so the page now describes the material instead of counting it.
- Reported by
- Where
- /response/scams/
- Clarification
Two pages said no confirmed drain of an Mk4-class wallet had been captured, without saying they meant this incident's July 2026 waves. One held source describes an earlier confirmed Mk4 theft whose cause is unproven.
- It said
- As of 4 August 2026, no captured source in this archive demonstrated a confirmed drain of a wallet generated on one of those models.
- It says now
- The claim is now bounded to this incident's July 2026 waves, on both pages, and the entropy page records the earlier case beside it: ChuckSRQ's 4 August catalogue of pre-July drain reports lists a July 2023 theft of 3.73118785 BTC from an Mk4 owner who described a device-generated seed, with the theft and amount cited to a transaction and the author stating plainly that its exact cause is not proven.
- Why
- Found on 7 August 2026 while rechecking the candidate-space pages. Both statements were defensible against their own evidence markers, which said "in this incident", and the entropy page carried a 4 August bound while the ChuckSRQ capture is dated 5 August. Neither reads that way on the page: a sentence saying no Mk4-class drain has been captured, with no incident named, asserts more than the archive establishes, and the archive held a contradicting case before the pages were last edited on 6 August. Logged as a clarification rather than a correction because the graded claim was accurate and the prose around it was not, which is the distinction this log exists to keep. Nothing here establishes that the 2023 theft was caused by this defect; the source says it is the best public candidate and that the cause is unproven, and this project adds nothing to that.
- Reported by
- Where
- /how-it-broke/entropy//
- Clarification
The page dated two claims about an upstream pull request to 6 August while the newest capture behind them was from 4 August. The request was merged on 6 August, and the guard it changes was replaced the same day.
- It said
- libngu's #ifndef guard is unchanged in the public repository: it still tests the macro's presence rather than its value ... Pull request #58, which proposes the value check, remains open as of 6 August 2026.
- It says now
- Pull request #58 was merged upstream on 6 August 2026 as commit e9d5e80, and the guard in ngu/random.c now reads #if MICROPY_HW_ENABLE_RNG == 0, so a zero-valued macro no longer passes it. The page states both merges, #61 on 5 August and #58 on 6 August, and adds what they do not change: these are commits on the library's public branch, released firmware builds against a pinned revision, and the board macro is still defined as zero.
- Why
- Found on 7 August 2026 while rechecking the technical pages. The page was committed at 09:25 UTC on 6 August; the merge was captured at 16:26 UTC the same day, so the sentence was true against the evidence held when it was written and false by the end of the day it named. That is why this is logged. The error was not the reading but the bound: the newest capture behind the claim was from 4 August, and dating it to 6 August asserted a currency the archive had not checked. A claim of this kind should be dated to the capture that supports it, not to the day of writing. Established by the held captures of libngu-pr-58 and libngu-random-c, both at 20260806T162628Z and 20260806T162626Z.
- Reported by
- Where
- /how-it-broke/
- Correction
The archive has not been append-only without exception. A capture-method migration on 4 August 2026 deleted 134 held captures of five Reddit sources, along with their diffs and their entries in the poll log.
- It said
- Captures are append-only. A snapshot is never rewritten or deleted, including one this project later decides was wrong: a bad capture is corrected by a later capture or a classification beside it, never by editing the record. The single exception is redacting personal data this project itself leaked.
- It says now
- Snapshots are append-only from 6 August 2026, with one exception on the record before that date: the 4 August 2026 reddit-json migration deleted the pre-migration captures of five Reddit sources. The commitment stands for everything held now and everything captured since.
- Why
- Found on 6 August 2026 while auditing the repository for superseded material before an archival deposit. Five sources (reddit-ai-discovery-thread, reddit-coldcard-letter-db-leak, reddit-drained-timeline, reddit-june-letter-report, reddit-wallet-brand-link-warning) switched from rendered-page capture to the Reddit JSON API on 4 August 2026. The switch removed 134 captures taken between 1 and 4 August 2026, 402 files in total, their diffs, and every corresponding line in archive/index.jsonl, which is why those sources now show a first capture of 4 August. The design record for the migration documented retiring PDF provenance for future captures; it did not document deleting the history, and nothing recorded the deletion at the time. The removed material was a backup copy held outside the repository until 6 August 2026, when it was deleted deliberately rather than restored: it was duplicate rendered-page capture of threads the archive still holds in a better form, from the days before the project's capture process settled. That is an operator decision about low-value superseded material, recorded here because the site had claimed an absolute rule that the archive did not meet. The claim is now scoped to what is true, and the rule is enforced going forward. No editorial claim on any page depended on the deleted captures.
- Reported by
- Where
- /cite/
- Correction
coldcardwatch.com was wrongly described as gone or offline. It remained live; the capture host's filtering DNS resolver was blocking the name.
- It said
- The landing page and source register listed the COLDCARD funds flow monitor among sources that had "disappeared from the web". Its source page said, "This page is gone from the web" and described this archive's capture as the only remaining public copy. The funds page labelled the tracker "offline".
- It says now
- coldcardwatch.com is live. This archive has not been able to resolve it through the capture host's filtering resolver since 4 August, so the funds page keeps the last successful capture and labels its capture status "unreachable here". The source remains registered for polling.
- Why
- A reader reported successfully opening coldcardwatch.com on 6 August 2026. Rechecking against independent public DNS services found the same A record, 216.150.1.1, through both Google Public DNS and Cloudflare DNS. Connecting to that address over HTTPS with coldcardwatch.com as the hostname returned status 200 and the live tracker page. An ordinary request from the capture host still fails with "Could not resolve host", which isolates the failure to that host's resolver rather than the publisher. The 53 failed archive polls remain in the append-only poll record because they accurately record what this collector experienced; only the site's interpretation of them was wrong.
- Reported by
How a correction is handled
- The claim is rechecked against the artefact it cites, not against the argument for it. If the artefact does not support the claim, the claim is wrong however reasonable it sounded.
- The page is changed where the claim was, keeping its evidence marker honest: a claim that turns out to rest on someone's say-so becomes reported, not verified.
- An entry is added here with the published wording that was wrong, so the correction can be checked rather than taken on trust.
- Captures are never rewritten. The archive is append-only, so a correction changes what this site says about a source and never what the source was recorded as saying.
Requests to remove correctly reported material are not corrections and are not honoured: what a party published is the record. The limits of that are set out on the About page.