Source change record
Every difference the archive holds between two states of a tracked page, classified and dated.
No code. Written to be actionable.
Newest first. A reviewed source-content difference means the relevant text served by the publisher changed between two captures. It does not verify the new claim. Dynamic page chrome, collection-method corrections, baselines and fetch errors remain preserved below without being presented as editorial revisions. Chain-monitor diff bodies remain local because they can contain victim addresses.
Some states here were not collected by this project. Where a difference involves a page state recovered from the Internet Archive, the entry carries an Internet Archive mark: on the later state when that state was inherited, and as a baseline note when the text being revised was the inherited one. As of 1 August 2026, 2 of the 74 recorded differences carry one of those marks. This keeps a recovered state from reading as a change this project caught live.
This record is part of the evidence section, which lists every tracked source and what is held for it. To follow it without revisiting the page, the same entries are published as a JSON feed at /record/changes.json, carrying the bounded revision window and provenance flags per item.
No source-content changes recorded yet.
-
samsamskies-tracker-readme · SamSamskies / chain-monitor
compared against an Internet Archive baseline
This detected difference has not yet been reviewed for capture noise.
-
coldcard-hack-tracker · community tracker / chain-monitor
compared against an Internet Archive baseline
This detected difference has not yet been reviewed for capture noise.
-
coldcard-watch · community tracker / chain-monitor
compared against an Internet Archive baseline
This detected difference has not yet been reviewed for capture noise.
-
coldcard-hack-tracker · community tracker / chain-monitor
compared against an Internet Archive baseline
This detected difference has not yet been reviewed for capture noise.
-
coldcard-hack-tracker · community tracker / chain-monitor
compared against an Internet Archive baseline
This detected difference has not yet been reviewed for capture noise.
-
coldcard-hack-tracker · community tracker / chain-monitor
compared against an Internet Archive baseline
The operator rebuilt the tracker around a five-wave model: the July 31 entry split into Galaxy Wave 2 and a new Galaxy Wave 3 spanning Jul 31 to Aug 1, the headline total moved from 1,130.09411114 to 1,368.58411114 BTC, consolidated holdings from 1,130.00551671 to 1,160.19028 BTC, and the July 30 heading was renamed from Galaxy fingerprint to Galaxy Wave 1.
-
btcpp-dettmer-commit-history · bitcoin++ Insider Edition / independent-analysis
compared against an Internet Archive baseline
A reader comment from Frank Corva was added to the post's discussion, posted after the preceding capture rather than progressively rendered from it. Substack like and restack counters changed in the same capture. The guest post's own text was unchanged.
+8 +1 +8 +1 +Frank Corva +34m +Great piece. Thank you, Rusty and Nifty. +Reply +Share -
coldcard-hack-tracker · community tracker / chain-monitor
compared against an Internet Archive baseline
The evening-wave description gained a clause noting that the Kelbie vault also occurred on 31 July; the live fiat conversion changed in the same capture.
-
coldcard-hack-tracker · community tracker / chain-monitor
compared against an Internet Archive baseline
The tracked total rose to 1,130.09411114 BTC after a delayed 0.19 BTC victim consolidation joined the Aug 1 hop vault. The tracker also recorded an Ocean block-960511 miner payout that touched the hop address and was peeled off, listing it as a possible lead that it does not count as stolen.
-
wizardsardine-postmortem · Wizardsardine / independent-analysis
compared against an Internet Archive baseline
Wizardsardine added explicit Section 3 and Section 4 labels to two previously unlabelled headings and renumbered the two that followed from 3 and 4 to 5 and 6. In the same edit the TAPSIGNER, OPENDIME and SATSCARD paragraph changed from a flat statement that they are not affected to Coinkite's claim plus the qualification that their proprietary code prevents the authors stating with certainty that the devices are safe, while noting the architecture is not a MicroPython stack.
-Who exactly is affected +Section 3: Who exactly is affected -TAPSIGNER, OPENDIME and SATSCARD are not affected, because they run on entirely different codebases. +For the TAPSIGNER, OPENDIME, and SATSCARD, Coinkite claims they are not affected, and it’s true that their architecture is completely different: they are not built on a MicroPython stack, whereas the bug specifically stems from a MicroPython compilation flag. However, since the code is proprietary, we cannot state with certainty that these devices are safe. -What to do now +Section 4: What to do now -Section 3: The knock-on consequences +Section 5: The knock-on consequences -Section 4: How to stop being exposed to this kind of flaw +Section 6: How to stop being exposed to this kind of flaw -
coldcard-hack-tracker · community tracker / chain-monitor
compared against an Internet Archive baseline
The tracker added a 'TOTAL STOLEN' headline of 1,129.90257437 BTC with a four-wave breakdown chart, and raised the balance on watch to 1,130.00551671 BTC after a second UTXO reached the Aug 1 hop vault.
-
coldcard-hack-tracker · community tracker / chain-monitor
compared against an Internet Archive baseline
The tracked total rose from 1,129.31416148 to 1,129.81397994 BTC, a separate 'Aug 1 hop vault' holding was added to the evening-wave cluster, the risk checklist gained Mk3 5.0.1 to 5.0.3, a seed-origin item and revised passphrase wording, and WizardSardine and Kevin Loaec were added as sources.
-
coinkite-mk3-advisory · Coinkite / vendor-advisory
compared against an Internet Archive baseline
Fourth recorded revision of the advisory, and the one that resolves the Mk2 question this archive had tracked as open. The update stamp moved to August 1, 2026 at 2:35 p.m. EDT and every Mk3-only statement about the defect and its fix now names both models: the fixed-firmware list reads 'Mk2/Mk3: version 4.2.0 or later', the affected range reads 'The issue is present on Mk2 and Mk3 firmware versions 4.0.1 through 4.1.9 inclusive', the at-risk sentence covers 'a seed generated on Mk2 or Mk3 version 4.0.1 (March 2021) through 4.1.9', and the release is described as 'Fixed Mk2/Mk3 firmware version 4.2.0' from the 'official Mk2/Mk3 download page'. The one-device migration section, the optional dice-only section and the closing migration steps were rewritten from Mk3-only to Mk2-or-Mk3 wording. Until this revision the vendor downloads-page listing was the only vendor evidence placing the Mk2 in the affected range or the hotfix. The published lower bound is unchanged at 4.0.1 for both models, so the v4.0.0 divergence recorded on the firmware page is untouched.
-Updated August 1, 2026 at 9:35 a.m. EDT: Funds controlled by seeds generated +Updated August 1, 2026 at 2:35 p.m. EDT: Funds controlled by seeds generated -Mk3: version 4.2.0 or later +Mk2/Mk3: version 4.2.0 or later -Funds controlled by a seed generated on Mk3 version 4.0.1 (March 2021) -through 4.1.9 inclusive are at risk if the seed was created without at least 50 -fair, independent, private dice rolls and the funded wallet is not protected by -a strong, unique BIP-39 passphrase. +Funds controlled by a seed generated on Mk2 or Mk3 version 4.0.1 (March +2021) through 4.1.9 inclusive are at risk if the seed was created without at +least 50 fair, independent, private dice rolls and the funded wallet is not +protected by a strong, unique BIP-39 passphrase. -The issue is present on Mk3 firmware versions 4.0.1 through 4.1.9 +The issue is present on Mk2 and Mk3 firmware versions 4.0.1 through 4.1.9 -
coinkite-backgrounder · Coinkite / vendor-advisory
compared against an Internet Archive baseline
Coinkite moved the backgrounder's update stamp to August 1, 2026 at 2:35 p.m. EDT and replaced Mk3 with Mk2 or Mk3 throughout: the affected firmware range became 'The affected Mk2 and Mk3 firmware range is 4.0.1 through 4.1.9', the seeded-PRNG analysis became 'On Mk2 and Mk3, the active PRNG was seeded primarily from device and timing state', the hotfix list became 'Version 4.2.0 for Mk2 and Mk3', and the migration steps and the pointer to the dedicated advisory were rewritten the same way.
-Updated August 1, 2026 at 9:35 a.m. EDT: Funds controlled by seeds generated +Updated August 1, 2026 at 2:35 p.m. EDT: Funds controlled by seeds generated -If your seed was generated on a Mk3 running firmware 4.0.1 through 4.1.9 +If your seed was generated on a Mk2 or Mk3 running firmware 4.0.1 through 4.1.9 -Update the Mk3 to firmware version 4.2.0 or +Update the Mk2 or Mk3 to firmware version 4.2.0 or -Generate a completely new seed on the updated Mk3. +Generate a completely new seed on the updated COLDCARD. -Follow the dedicated Mk3 Security Advisory and migration +Follow the dedicated Mk2/Mk3 Security Advisory and migration -On Mk3, the active PRNG was seeded primarily from device and timing +On Mk2 and Mk3, the active PRNG was seeded primarily from device and timing -The affected Mk3 firmware range is 4.0.1 through 4.1.9. Version 4.2.0 corrects -new seed generation. The eight-year figure therefore describes the age of the -
coldcard-hack-tracker · community tracker / chain-monitor
compared against an Internet Archive baseline
The tracker restated its movement feed in terms of the reported consolidation only: the earlier outbound spend and unconfirmed hop were removed from the feed, last movement returned to 'Unmoved', and a note was added that later surplus passing through a vault is ignored while the reported balance remains.
-
coldcard-watch · community tracker / chain-monitor
compared against an Internet Archive baseline
The tracker's headline moved from 1,128.6633 BTC across 2,334 verified addresses to 1,158.8480 BTC across 2,686, and its address-check copy changed with it. The cluster description of three windows on 30 and 31 July was unchanged.
-
coldcard-firmware-pr-691 · Coinkite / repo-pr
compared against an Internet Archive baseline
The author marked the pull request as a draft at 16:13 and rewrote its description. The submodule bump note became a re-pin to the companion RNG fix, and the stated dependency moved from switck/libngu#60 to #61, described as replacing the generator with a SHA-256 Hash-DRBG and making reseed() require a seed of at least 32 bytes, so this firmware change becomes a prerequisite for #61 booting on-device. GitHub edited-comment and loading-error chrome appeared in the same capture.
-Open +Draft -Open +Draft +• +edited +Loading +Uh oh! +There was an error while loading. Please reload this page. -Bump external/libngu to the companion fix that makes reseed() absorb a -full-width seed into all generator state words. +Re-pin external/libngu to the companion RNG fix. -Requires switck/libngu#60 (the reseed() rework). Until that merges, the bumped -submodule commit exists only on the libngu fork, so firmware CI cannot fetch it -
libngu-pr-60 · switck / repo-pr
compared against an Internet Archive baseline
The inline cross-reference to Coldcard/firmware#691 changed from Open to Draft, reflecting a real state change on that pull request rather than rendering variance. Nothing else moved: no discussion, review or patch text on this pull request changed. The underlying state change is captured directly on coldcard-firmware-pr-691 at 20260801T174121Z, so this entry is the same event seen from the linked repository.
-Open +Draft -
coldcard-hack-tracker · community tracker / chain-monitor
compared against an Internet Archive baseline
The tracker added an unconfirmed hop-1 movement of 0.4998206 BTC onward from the followed destination of the evening vault's first outbound spend.
-
kelbie-rng-postmortem · Kelbie / independent-analysis
compared against an Internet Archive baseline
The README added derivation sections on grouping waves into families by build traits rather than configuration dials, on fee pricing and its lack of correlation with value, on wave colour, and on re-applying Block's published seven-property fingerprint across the whole record, plus a new fingerprint script in the file map.
- those gives the same answer. The headline figures and the block cascade read the first episode; - everything else carries all of it. + those gives the same answer. The headline figures read the first episode; everything else carries + all of it. +- **Which waves were built by the same program** — `fingerprints[]` splits what a transaction + reveals into two kinds of evidence and groups the waves on the first kind only. A **build** trait + is something the program does regardless of who runs it: the order it writes inputs in, where it + gets a size estimate from, what it puts in nLockTime, whether it grinds its signatures. A + **config** trait is a dial — fee rate, replace-by-fee, whether coins are pooled into a collector + or scattered one address per sweep. Waves form a **family** when no build trait *either could + show* disagrees, and split into **variants** inside it by their dials. Traits a wave cannot + exhibit — input ordering, when every sweep spends one input — come back null and are skipped, so + a small wave joins on the evidence it has rather than being split off for evidence it could never + have produced. Where that leaves it fitting more than one family, `alsoFits` says so and the page -
coldcard-hack-tracker · community tracker / chain-monitor
compared against an Internet Archive baseline
The tracker withdrew the Mk4 attribution for the 1 August morning wave, recording the seed as Mk3-origin, removed the 'Mk4 is in scope now' panel, and recorded the first outbound spend of 0.4099166 BTC from the evening vault at 16:33 UTC.
-
passport-not-affected · Foundation / vendor-statement
compared against an Internet Archive baseline
Foundation added a reply to the thread saying manual firmware updates outside Envoy are scheduled for the next but one release, with no definitive timeframe committed.
+qna +August 1, 2026, 10:24am +5 +This is currently scheduled for the next but one release, but our roadmap is always subject to change and as of right now, I do not have definitive time frame for this. -
coinkite-terms · Coinkite / vendor-legal
compared against an Internet Archive baseline
The site-wide advisory banner on the terms page hardened from 'Seeds generated on firmware 4.0.1 or later may be at risk' to 'Seeds generated on firmware 4.0.1 (2021 or later) are at risk', matching the downloads page.
-Seeds generated on firmware 4.0.1 or later may be at risk. +Seeds generated on firmware 4.0.1 (2021 or later) are at risk. -
coldcard-firmware-pr-691 · Coinkite / repo-pr
compared against an Internet Archive baseline
The pull request gained a further comment repeating the request to raise the libngu changes as a separate pull request against the libngu repository, linking switck/libngu#60; reaction totals were normalized in the same capture.
+<github-reactions> +ballance +commented +Aug 1, 2026 +Copy link +Copy Markdown +Author +Can you please open libngu changes as separate PR against libngu repo? thanks +switck/libngu#60 +Sorry, something went wrong. +Uh oh! +There was an error while loading. Please reload this page. -
libngu-pr-60-patch · switck / repo-patch
compared against an Internet Archive baseline
The published patch series gained a second commit adding a ValueError on an empty seed, a regression test and a comment documenting the generator's roughly 72-bit independent state.
-Subject: [PATCH] fix: absorb full-width entropy in random.reseed() +Subject: [PATCH 1/2] fix: absorb full-width entropy in random.reseed() +From 6766258eae9a11e40fc77402af2dd9462938b2e6 Mon Sep 17 00:00:00 2001 +From: Ballance <[email protected]> +Date: Sat, 1 Aug 2026 10:21:54 -0400 +Subject: [PATCH 2/2] review: reject empty seed and document 72-bit state + ceiling +Address review feedback on switck/libngu#60: +- reseed() now raises ValueError on a zero-length seed instead of + silently performing a no-op reseed; test_random.py covers it. +- Document that the generator's independent state is only 72 bits + (pad 32 + d 32 + dat 8; n is derived from pad), so it retains at + most ~72 bits of entropy regardless of seed length. + An empty hand gives -
libngu-pr-60 · switck / repo-pr
compared against an Internet Archive baseline
Two contributors reviewed the reseed change, the author pushed a second commit rejecting a zero-length seed and documenting a roughly 72-bit state ceiling, a reviewer argued for removing Yasmarang entirely and announced a competing pull request, and the author closed this one in favour of #61.
-Open -ballance wants to merge 1 commit into +Closed +ballance wants to merge 2 commits into -ConversationCommits1 (1)ChecksFiles changed -Open +ConversationCommits2 (2)ChecksFiles changed +Closed -ballance wants to merge 1 commit into +ballance wants to merge 2 commits into -All reactions +<github-reactions> +doc-hex +commented -
libngu-pr-59 · switck / repo-pr
compared against an Internet Archive baseline
The pull request was closed by its author in favour of a three-pull-request stack (#62, #63 and #64) described as summing to a byte-identical tree, with a suggested review order and an offer to reopen.
-Open +Closed -Open +Closed +jgmontoya +commented +Aug 1, 2026 +Copy link +Copy Markdown +Author +Per your feedback that the diff was too big, I've split this into a stack of three PRs that sum to exactly this branch (byte-identical tree): +add HMAC_DRBG (SP 800-90A 10.1.2, SHA-256), verified against NIST CAVP vectors #62 — the HMAC_DRBG core + NIST CAVP test harness (pure addition, self-verifying, no behavior change to any build) +add entropy health rule as a pure, deterministically tested module #63 — the entropy health rule + its deterministic tests (pure addition) +random: fail-closed entropy backends; all output via HMAC_DRBG #64 — the random.c rework that composes them, with compile-gate regression tests and README (the part that fixes the advisory) -
coldcard-hack-tracker · community tracker / chain-monitor
compared against an Internet Archive baseline
The tracker's watched balance rose from 1,129.31416148 BTC to 1,129.6240794 BTC and the evening vault's displayed balance and UTXO count changed, while the reported consolidated figure for that vault stayed at 0.50980268 BTC.
-
kelbie-rng-postmortem · Kelbie / independent-analysis
compared against an Internet Archive baseline
The README renamed waves from ordinal numbers to block heights throughout, so 'wave 3' became 'wave 960188' and Block's 'waves 1 and 2' became 'waves 960183 and 960185'.
-The first report in the file yields wave 3's collector, wave 3's vault, and 500 victims. +The first report in the file yields wave 960188's collector, its vault, and 500 victims. -Block published waves 1 and 2 as a fingerprint match and said in the same thread that they "have not +Block published waves 960183 and 960185 as a fingerprint match and said in the same thread that they "have not -- **Labels** — "Wave 1 collector A" is generated from the wave and role, with a letter only where +- **Labels** — "Wave 960183 collector A" is generated from the wave and role, with a letter only where -The last one is decided by **time, not amount**. Wave 1 swept outputs worth 1,200 satoshis — smaller +The last one is decided by **time, not amount**. Wave 960183 swept outputs worth 1,200 satoshis — smaller -
coldcard-hack-tracker · community tracker / chain-monitor
compared against an Internet Archive baseline
The tracker added an 'Aug 1 morning wave' cluster with a new vault address holding 0.33203236 BTC from 16 sweeps, described it as including a reported Mk4 RNG and duress-wallet honeypot attributed to Tomer Strolight while noting the device model is not visible on chain, added an 'Mk4 is in scope now' panel, and changed its headline to a running total.
-
coldcard-hack-tracker · community tracker / chain-monitor
compared against an Internet Archive baseline
The tracker replaced its likely-exposed paragraph with a per-model vulnerable and fixed version table covering Mk3, Mk4, Mk5, Q and both Edge tracks, and moved the evening vault's block reference from the row label into the cluster description.
-
coldcard-hack-tracker · community tracker / chain-monitor
compared against an Internet Archive baseline
The tracker rewrote its reader-guidance section against the August 1 advisory and Block's writeup, added a 'beyond the main seed' item covering paper-wallet keys, Seed XOR masks and Key Teleport, clone and Secure Notes material, moved the Galaxy scope figures into the cluster card, and replaced its short source labels with descriptive per-source summaries including CoinDesk and Clay Garrett. Holding 2's UTXO count also changed from one to two.
-
coldcard-hack-tracker · community tracker / chain-monitor
compared against an Internet Archive baseline
The tracker added a third cluster, an 'Evening wave' of 31 July with its own 0.50980268 BTC vault attributed to Evan Schoenberg, restated every holding at full satoshi precision, and changed its headline from 1,128.56 BTC across two clusters to 1,129.06986038 BTC across three.
-
coldcard-watch · community tracker / chain-monitor
compared against an Internet Archive baseline
The tracker moved from two episodes to three clusters by adding 13 addresses in block 960455, changed the destination set from four addresses to six, revised the same-block count for the last drained address from 250 to 237, and added an explanatory note about the two-scale timeline.
-
coldcard-downloads · Coinkite / vendor-releases
compared against an Internet Archive baseline
The site-wide advisory banner hardened from 'Seeds generated on firmware 4.0.1 or later may be at risk' to 'Seeds generated on firmware 4.0.1 (2021 or later) are at risk'.
-Seeds generated on firmware 4.0.1 or later may be at risk. +Seeds generated on firmware 4.0.1 (2021 or later) are at risk. -
coinkite-blog-index · Coinkite / vendor-index
compared against an Internet Archive baseline
The blog index excerpt for the advisory changed with the advisory itself, from 'Coinkite is warning users who generated a seed using a COLDCARD on firmware versions 4.0.1 throug...' to 'Funds from affected COLDCARD seeds are at risk if the seed lacks 50 independent, private dice rol...'.
-Coinkite is warning users who generated a seed using a COLDCARD on firmware versions 4.0.1 throug... +Funds from affected COLDCARD seeds are at risk if the seed lacks 50 independent, private dice rol... -
coinkite-mk3-advisory · Coinkite / vendor-advisory
compared against an Internet Archive baseline
Third recorded revision of the advisory. It now carries 'Updated August 1, 2026 at 9:35 a.m. EDT' and replaces the blanket warning that Mk3 4.0.1 to 4.1.9 users' funds 'may be at risk' with a conditional statement that funds are at risk unless the seed was created with at least 50 fair, independent, private dice rolls and the wallet is protected by a strong, unique BIP-39 passphrase. The passphrase section changed in both directions: it now states that reduced seed entropy alone is not enough to reach a passphrase wallet, and separately that a strong passphrase does not repair the seed, that passphrase users should also migrate, and that an uncertain passphrase means treating funds as at risk and migrating immediately.
-Updated July 31, 2026 at 12:39 p.m. EDT: Fixed firmware is now available -for every affected model and release track: +Updated August 1, 2026 at 9:35 a.m. EDT: Funds controlled by seeds generated +on affected firmware are at risk if the seed was created without at least 50 +independent, private dice rolls and the funded wallet is not protected by a +strong, unique BIP-39 passphrase. +Fixed firmware is now available for every affected model and release track: -Coinkite is warning all users who -generated a seed using a Mk3 on version 4.0.1 (March 2021) thru 4.1.9 (inclusive) -that their funds may be at risk. +Funds controlled by a seed generated on Mk3 version 4.0.1 (March 2021) +through 4.1.9 inclusive are at risk if the seed was created without at least 50 +fair, independent, private dice rolls and the funded wallet is not protected by +a strong, unique BIP-39 passphrase. -
coinkite-backgrounder · Coinkite / vendor-advisory
compared against an Internet Archive baseline
Coinkite replaced the backgrounder's fixed-firmware banner with an August 1 update stating that funds are at risk unless the seed was created with at least 50 independent private dice rolls and the wallet is protected by a strong, unique BIP-39 passphrase, added a paragraph qualifying what counts as such a passphrase, and added a sentence calling the reduced search space a direct security risk rather than a theoretical possibility for wallets meeting neither condition.
-Updated July 31, 2026 at 12:39 p.m. EDT: Fixed firmware is now available -for every affected model and release track, including Edge firmware versions -6.6.0X for Mk4/Mk5 and 6.6.0QX for Q. +Updated August 1, 2026 at 9:35 a.m. EDT: Funds controlled by seeds generated +on affected firmware are at risk if the seed was created without at least 50 +independent, private dice rolls and the funded wallet is not protected by a +strong, unique BIP-39 passphrase. +Fixed firmware is now available for every affected model and release track, +including Edge firmware versions 6.6.0X for Mk4/Mk5 and 6.6.0QX for Q. +The passphrase must be strong, unique, secret, and separate from the seed +backup. A short, common, patterned, quoted, reused, exposed, or uncertain +passphrase does not qualify; treat those funds as at risk. Even when a strong +passphrase reduces the immediate exposure, it does not repair an affected seed. +Unless the independent dice-entropy exception applies, replace the seed and -
coldcard-hack-tracker · community tracker / chain-monitor
compared against an Internet Archive baseline
The monitor changed Holding 1's displayed UTXO count from ten to eleven while its BTC balance and held status remained unchanged.
-
coldcard-watch · community tracker / chain-monitor
compared against an Internet Archive baseline
The tracker added dashboard, address-list and methodology navigation, described its figures as verified minimums and a floor rather than totals, and changed its checkable address set from 2,321 to 2,334.
-
coldcard-hack-tracker · community tracker / chain-monitor
compared against an Internet Archive baseline
The monitor changed Holding 1's displayed UTXO count from nine to ten while its BTC balance and held status remained unchanged.
-
coldcard-hack-tracker · community tracker / chain-monitor
compared against an Internet Archive baseline
The monitor changed Holding 1's displayed UTXO count from eight to nine while its BTC balance and held status remained unchanged.
-
reddit-drained-timeline · r/Bitcoin / victim-account
compared against an Internet Archive baseline
The rendered thread added a comment linking to Gregory Sanders' reported reproduction; one comment present in the preceding capture was no longer rendered.
+ViperG +• +<relative-time> + +Someone was able to replicate the rng exploit on mk2/mk3: + +https://x.com/i/status/2082958675975553224 + +<engagement-count> +<more-replies> -artilekt -• -<relative-time> - -
coldcard-hack-tracker · community tracker / chain-monitor
compared against an Internet Archive baseline
The monitor changed Holding 1's displayed UTXO count from seven to eight while its BTC balance and held status remained unchanged.
-
coldcard-firmware-pr-691 · Coinkite / repo-pr
compared against an Internet Archive baseline
A COLDCARD firmware collaborator asked the author to move the libngu changes into a separate pull request; GitHub review metadata and navigation chrome also changed.
+scgbckbone +reviewed +Aug 1, 2026 +View reviewed changes +scgbckbone +left a comment +Copy link +Copy Markdown +Collaborator +There was a problem hiding this comment. +Choose a reason for hiding this comment +The reason will be displayed to describe this comment to others. Learn more. +Choose a reason +Spam -
coldcard-watch · community tracker / chain-monitor
compared against an Internet Archive baseline
The tracker expanded from the first 1,195-address episode to two episodes totalling 2,321 addresses and changed its headline from 1,082.5696 BTC to 1,128.4717 BTC.
-
coldcard-hack-tracker · community tracker / chain-monitor
compared against an Internet Archive baseline
The tracker added a separately attributed 45.91 BTC post-scan cluster and changed its headline total; live fiat figures also changed in the same capture.
-
libngu-pr-59 · switck / repo-pr
compared against an Internet Archive baseline
The pull-request author added a comment offering to split the proposal into three smaller changes; GitHub navigation counters also changed.
-10 +11 -5 +6 +jgmontoya +commented +Aug 1, 2026 +Copy link +Copy Markdown +Author +diff too big +I'd be happy to split into a 3-PR stack: two independent, self-verifying additions (DRBG+CAVP, health rule) and then the random.c rework as a much smaller final diff. +All reactions +Sorry, something went wrong. -
coinkite-mk3-advisory · Coinkite / vendor-advisory
compared against an Internet Archive baseline
Coinkite announced fixed firmware for every affected model and release track, including Mk3 4.2.0, and rewrote the one-device migration guidance.
-Mk3 Security Advisory +Coldcard Security Advisory -Out of an abundance of caution, Coinkite is warning all users who -generated a seed using a Mk3 on version 4.0.1 (March 2021) or any -subsequent version that their funds may be at risk. +Updated July 31, 2026 at 12:39 p.m. EDT: Fixed firmware is now available +for every affected model and release track: +Mk3: version 4.2.0 or later +Mk4/Mk5 standard: version 5.6.0 or later +Q standard: version 1.5.0Q or later +Mk4/Mk5 Edge: version 6.6.0X or later +Q Edge: version 6.6.0QX or later +Standard and Edge are separate release tracks. If you use Edge, install the +fixed Edge release for your model. Do not assume an older Edge 6.x release is -
coinkite-mk3-advisory · Coinkite / vendor-advisory
compared against an Internet Archive baseline
Coinkite expanded the affected scope to Mk4, Mk5 and Q, added dice guidance, and revised the passphrase and migration sections.
-Mk4, Q and Mk5 are not affected based on our early analysis of the issue. -The issue is present through firmware version 5.0.3, -the final release that supported Mk3. -Investigation Ongoing +Seeds generated on Mk4, Q and Mk5 before the fixed firmware releases are also +affected, with about 72 bits of entropy rather than the expected 128 bits. +TAPSIGNER, OPENDIME and SATSCARD are not affected by this bug as they are different codebases +The issue is present on every Mk3 firmware version since +4.0.1. It also affects seeds generated on +Mk4 and Mk5 before version 5.6.0, and on Q before version 1.5.0Q. The impact on +Mk4, Mk5 and Q is not as severe but is still serious. +If You Added Dice When Creating the Seed +This issue affects the device-generated entropy. It does not remove independent +entropy that you supplied with dice.
Preserved collection differences 24
These diffs remain part of the record, but review found that they came from dynamic page chrome or a collection-method correction rather than a relevant edit by the publisher.
No collection differences are recorded. Every detected difference so far was reviewed as a change in the source content itself.
-
coin360-drain · Coin360 / reporting
compared against an Internet Archive baseline
A relative-age label the enabled normalizer did not match in its literal form; the article body is unchanged.
-
theblock-galaxy-total · The Block / reporting
compared against an Internet Archive baseline
Only the site chrome's rotating latest-news list changed; the incident article text, including its Galaxy total, was unchanged.
-
coldcard-hack-tracker · community tracker / chain-monitor
compared against an Internet Archive baseline
Only the live fiat conversion changed; the BTC totals, cluster descriptions and movement state were unchanged.
-
coldcard-hack-tracker · community tracker / chain-monitor
compared against an Internet Archive baseline
Only the live fiat conversion changed; the BTC totals, cluster descriptions and movement state were unchanged.
-
coldcard-hack-tracker · community tracker / chain-monitor
compared against an Internet Archive baseline
Only the live fiat conversion changed; the BTC totals, cluster descriptions and movement state were unchanged.
-
reddit-drained-timeline · r/Bitcoin / victim-account
compared against an Internet Archive baseline
Two already-held comments swapped position in the rendered thread. No post or comment text was added, removed or altered, and the enabled normalizer already suppresses relative-time labels and engagement counts, so comment ordering is the only remaining difference. Reddit orders comments dynamically, so this is rendering variance rather than an edit by the author or moderators.
-
coin360-drain · Coin360 / reporting
compared against an Internet Archive baseline
Only the article's relative-time label changed, this time to the word 'yesterday', which the existing relative-time normalizer does not match. The article body was unchanged.
-
theblock-galaxy-total · The Block / reporting
compared against an Internet Archive baseline
Only the site chrome's rotating latest-news list changed; the incident article text was unchanged.
-
reddit-drained-timeline · r/Bitcoin / victim-account
compared against an Internet Archive baseline
Fewer lazy-loaded comments were present in this capture than the previous one, and the 'Read more' control was absent. The thread body is unchanged; the missing replies include two that link to the Coinkite advisory. Reddit renders comments progressively, so this is capture variance rather than deletion by the author or moderators.
-
reddit-drained-timeline · r/Bitcoin / victim-account
compared against an Internet Archive baseline
More lazy-loaded comments were rendered in this capture than in the previous one, and the 'Read more' control was present again. This is the inverse of the 09:58:01Z capture and the same progressive-rendering variance; no post or comment text already held was altered.
-
coldcard-hack-tracker · community tracker / chain-monitor
compared against an Internet Archive baseline
The rendered capture again held the monitor's hydrated chain data after the preceding temporary loading-state capture.
-
coldcard-hack-tracker · community tracker / chain-monitor
compared against an Internet Archive baseline
The rendered capture held the monitor's temporary loading state instead of its hydrated chain data.
-
theblock-galaxy-total · The Block / reporting
compared against an Internet Archive baseline
The live market-ticker region was temporarily unavailable; the incident article text was unchanged.
-
libngu-pr-58 · switck / repo-pr
compared against an Internet Archive baseline
Only the thumbs-up reaction total and reacting-account list changed; the pull-request discussion and patch text were unchanged.
-
coldcard-docs-faq · Coinkite / vendor-docs
compared against an Internet Archive baseline
Only the FAQ footer's Last update date changed from July 31 to August 1; no extracted FAQ answer changed.
-
coin360-drain · Coin360 / reporting
compared against an Internet Archive baseline
Only the article's relative-time label changed from 15 hours to 16 hours.
-
libngu-pr-58 · switck / repo-pr
compared against an Internet Archive baseline
Only GitHub repository navigation counters changed.
-
coldcard-hack-tracker · community tracker / chain-monitor
compared against an Internet Archive baseline
Only live fiat conversions changed; the BTC balances and movement state were unchanged.
-
theblock-galaxy-total · The Block / reporting
compared against an Internet Archive baseline
Only live cryptocurrency ticker values in the site navigation changed.
-
theblock-galaxy-total · The Block / reporting
compared against an Internet Archive baseline
Only live cryptocurrency ticker values in the site navigation changed.
-
tftc-who-must-move · TFTC / analysis
compared against an Internet Archive baseline
Only rotating related-content cards below the article changed.
-
coldcard-hack-tracker · community tracker / chain-monitor
compared against an Internet Archive baseline
Only live fiat conversions changed; the BTC balances and movement state were unchanged.
-
coldcard-hack-tracker · community tracker / chain-monitor
compared against an Internet Archive baseline
The browser capture obtained the rendered tracker after the initial scripted capture held an empty client-side shell.
-
reddit-drained-timeline · r/Bitcoin / victim-account
compared against an Internet Archive baseline
A newly enabled comparison normalizer replaced relative-time labels and engagement counts; the post and comment text did not change.
Collection baselines and fetch errors 71
Baselines establish the first copy held. Fetch errors describe this project's collection attempt, not a change at the source.
No baselines or fetch errors are recorded in the capture log yet.
- 2 Aug 2026, 00:40 UTC Coinkite's pre-incident paper-spam warning baseline
- 2 Aug 2026, 00:26 UTC Collision demonstration and firmware guard scanner baseline
- 2 Aug 2026, 00:26 UTC End-to-end reproduction of the affected generator baseline
- 2 Aug 2026, 00:26 UTC Source of the community holdings tracker baseline
- 2 Aug 2026, 00:13 UTC COLDCARD hack tracker blocked
- 2 Aug 2026, 00:09 UTC COLDCARD hack tracker blocked
- 2 Aug 2026, 00:08 UTC COLDCARD hack tracker blocked
- 1 Aug 2026, 23:59 UTC COLDCARD hack tracker blocked
- 1 Aug 2026, 23:28 UTC COLDCARD hack tracker blocked
- 1 Aug 2026, 22:57 UTC COLDCARD hack tracker blocked
- 1 Aug 2026, 22:23 UTC COLDCARD hack tracker blocked
- 1 Aug 2026, 17:17 UTC Dettmer commit-history analysis of the entropy bug baseline
- 1 Aug 2026, 17:17 UTC Wizardsardine post-mortem and user guidance baseline
- 1 Aug 2026, 09:15 UTC CVE-2023-31290 vulnerability record baseline
- 1 Aug 2026, 09:15 UTC Disclosure of vulnerable Bitcoin wallet library baseline
- 1 Aug 2026, 09:15 UTC Milk Sad vulnerability disclosure baseline
- 1 Aug 2026, 09:15 UTC Some SecureRandom thoughts baseline
- 1 Aug 2026, 09:15 UTC Debian Security Advisory DSA-1571-1 baseline
- 1 Aug 2026, 09:15 UTC Consumer Protection Act, 2023 baseline
- 1 Aug 2026, 09:15 UTC MARA Slipstream API documentation baseline
- 1 Aug 2026, 09:15 UTC Consumer Protection Act, 2002 baseline
- 1 Aug 2026, 09:15 UTC MARA Slipstream transaction-submission portal baseline
- 1 Aug 2026, 06:39 UTC COLDCARD mainline RNG hotfix commit ca724637 baseline
- 1 Aug 2026, 06:39 UTC Mk3 bounded proof README at e17d833b baseline
- 1 Aug 2026, 06:39 UTC COLDCARD firmware PR #690 patch baseline
- 1 Aug 2026, 06:39 UTC COLDCARD firmware PR #689 patch baseline
- 1 Aug 2026, 06:39 UTC COLDCARD firmware PR #691 patch baseline
- 1 Aug 2026, 06:39 UTC libngu PR #60 patch baseline
- 1 Aug 2026, 06:39 UTC libngu PR #59 patch baseline
- 1 Aug 2026, 06:39 UTC libngu PR #58 patch baseline
- 1 Aug 2026, 06:25 UTC SeedSigner PR #962: withdrawn camera-entropy hardening proposal baseline
- 1 Aug 2026, 06:25 UTC SatSigner PR #468: entropy audit and hardening baseline
- 1 Aug 2026, 06:25 UTC Bitcoin.org PR #4905: remove COLDCARD listings baseline
- 1 Aug 2026, 06:23 UTC COLDCARD firmware PR #690: Edge RNG hotfix baseline
- 1 Aug 2026, 06:23 UTC COLDCARD firmware PR #689: Mk3 RNG hotfix baseline
- 1 Aug 2026, 06:21 UTC COLDCARD firmware PR #691: pass the full secure-element digest baseline
- 1 Aug 2026, 06:21 UTC libngu PR #60: full-width reseeding baseline
- 1 Aug 2026, 05:59 UTC Mk3 binary reversal and bounded proof of concept baseline
- 1 Aug 2026, 05:59 UTC Chain-derived COLDCARD RNG postmortem baseline
- 1 Aug 2026, 05:59 UTC Reproducible firmware and chain investigation baseline
- 1 Aug 2026, 03:51 UTC COLDCARD entropy FAQ baseline
- 1 Aug 2026, 03:50 UTC Galaxy loss estimate reporting fetch error Source check returned HTTP 403.
- 1 Aug 2026, 03:25 UTC Coinkite terms of sale baseline
- 1 Aug 2026, 03:25 UTC libngu PR #59 baseline
- 1 Aug 2026, 03:25 UTC libngu PR #58 baseline
- 1 Aug 2026, 02:53 UTC COLDCARD wallet drain report baseline
- 1 Aug 2026, 02:53 UTC COLDCARD Mk3 entropy reference baseline
- 1 Aug 2026, 02:53 UTC Bitcoin Optech Newsletter #416 baseline
- 1 Aug 2026, 02:45 UTC Wallet drained timeline baseline
- 1 Aug 2026, 02:34 UTC COLDCARD hack tracker baseline
- 1 Aug 2026, 02:34 UTC COLDCARD funds flow monitor baseline
- 1 Aug 2026, 01:22 UTC Wallet drained timeline blocked
- 1 Aug 2026, 00:46 UTC Galaxy loss estimate reporting baseline
- 1 Aug 2026, 00:46 UTC Who must move their coins baseline
- 1 Aug 2026, 00:46 UTC Coinkite releases fixed firmware baseline
- 1 Aug 2026, 00:46 UTC Passport is not affected baseline
- 1 Aug 2026, 00:46 UTC Jade is unaffected baseline
- 1 Aug 2026, 00:46 UTC BitBox is not affected baseline
- 1 Aug 2026, 00:23 UTC libngu random.c baseline
- 1 Aug 2026, 00:17 UTC Predictable RNG fallback and 32-bit reseed baseline
- 1 Aug 2026, 00:17 UTC COLDCARD firmware changelog baseline
- 1 Aug 2026, 00:17 UTC COLDCARD firmware downloads baseline
- 1 Aug 2026, 00:17 UTC Mk4 and Mk5 firmware history baseline
- 1 Aug 2026, 00:17 UTC Mk3 firmware history baseline
- 1 Aug 2026, 00:17 UTC Q firmware history baseline
- 1 Aug 2026, 00:17 UTC Entropy technical backgrounder baseline
- 1 Aug 2026, 00:17 UTC Coinkite blog index baseline
- 1 Aug 2026, 00:17 UTC Mk3 security advisory baseline
- 31 Jul 2026, 07:30 UTC Mk3 security advisory baseline
- 31 Jul 2026, 03:29 UTC Predictable RNG fallback and 32-bit reseed baseline
- 31 Jul 2026, 01:56 UTC Mk3 security advisory baseline
Back to the evidence index, or read the same differences as structured data in the JSON change feed.