COLDCARD vulnerability what happened, and what to do
Informational only, and this site never asks for your recovery words. details

Informational only. This is independent analysis and an evidence-backed explainer, not financial, security or legal advice, and not a substitute for professional advice about your own situation. It is not affiliated with, endorsed by, or speaking for Coinkite, Block, or any other party named here. Published estimates are attributed, and differing scenarios are kept separate with their assumptions. Act on your own judgement. Editorial standards and corrections.

Do not disclose recovery material to a website, form, message or support account. This site never asks for it. Deliberate recovery on independently verified offline equipment is a separate operation. Seed-word safety.

Evidence

What each party said, when relevant source content changed, and what the archive classified as collection-only differences. 134 snapshots across 59 registered web sources preserve 45 reviewed source-content changes. Substantive claims elsewhere on the site link to these evidence records.

59sources tracked
134snapshots held
45source changes
55/55posts captured

The archive also preserves 24 collection differences caused by capture-method corrections or dynamic page chrome. 5 detected differences currently await review.

Organisational statements and documentation

First-party advisories, documentation, terms and service records from organisations responsible for the product or service discussed.

Legislation

Official government statute pages used for legal context. Inclusion identifies the text checked and does not determine how it applies to a particular claim.

Public vulnerability records

Government-maintained vulnerability records used to identify published technical details and affected-version ranges.

Primary technical research

Original analysis by people who read the code or the chain themselves, rather than reporting on somebody who did. Credited individually on the analysis page.

Secondary analysis

Technical interpretation and guidance built from primary disclosures or other researchers. Useful, but one step removed from the original finding.

Repository files and pull requests

Release notes, source files and the upstream fixes proposed after disclosure. Mostly append-only sources preserved for source-level context.

Reporting

Coverage that relays and interprets the primary sources above. Useful, and one step removed from the finding.

Chain monitors

Community-run trackers that let anyone check an address against the known affected set. Live services rather than documents, so they have no publication date.

First-hand accounts

People describing what happened to them. Not evidence of mechanism, and the only material here written by someone who lost money.

Registered posts

Social posts that shaped the research or response. Each has a local evidence record showing whether a text or image capture is actually held.