{
  "schema": "https://cc-vuln.org/schemas/source-register-v1",
  "incident": "coldcard-entropy-2026",
  "archive_last_capture": "2026-08-02T01:00:28Z",
  "interpretation": {
    "publication_time": "When the source says it published, when established.",
    "capture_time": "When this project observed and stored a source state.",
    "revision_window": "The bounded interval between the last old state and first new state held.",
    "source_content": "Relevant text served by the publisher changed. This does not verify the new claim.",
    "capture_noise": "The detected difference came from dynamic chrome or collection mechanics.",
    "unreviewed": "The difference has not yet been reviewed for capture noise."
  },
  "web_sources": [
    {
      "id": "coinkite-backgrounder",
      "title": "Entropy technical backgrounder",
      "url": "https://blog.coinkite.com/entropy-technical-backgrounder/",
      "organisation": "Coinkite",
      "kind": "vendor-advisory",
      "role": "Vendor advisory",
      "publication_time": "2026-07-30",
      "note": "Publisher-dated 30 July. Revised to add Mk4/Q/Mk5 scope and later the Mk3 4.2.0 fix; exact revision times are unresolved.",
      "capture": {
        "status": "held",
        "copies": 3,
        "first_observed": "2026-08-01T00:17:31Z",
        "last_observed": "2026-08-01T18:44:29Z",
        "last_checked": "2026-08-02T00:57:38Z"
      },
      "differences": [
        {
          "observed_at": "2026-08-01T18:44:29Z",
          "window_start": "2026-08-01T14:02:31Z",
          "window_end": "2026-08-01T18:44:29Z",
          "status": "source-content",
          "summary": "Coinkite moved the backgrounder's update stamp to August 1, 2026 at 2:35 p.m. EDT and replaced Mk3 with Mk2 or Mk3 throughout: the affected firmware range became 'The affected Mk2 and Mk3 firmware range is 4.0.1 through 4.1.9', the seeded-PRNG analysis became 'On Mk2 and Mk3, the active PRNG was seeded primarily from device and timing state', the hotfix list became 'Version 4.2.0 for Mk2 and Mk3', and the migration steps and the pointer to the dedicated advisory were rewritten the same way.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 11,
          "removed_lines": 10
        },
        {
          "observed_at": "2026-08-01T14:02:31Z",
          "window_start": "2026-08-01T00:17:31Z",
          "window_end": "2026-08-01T14:02:31Z",
          "status": "source-content",
          "summary": "Coinkite replaced the backgrounder's fixed-firmware banner with an August 1 update stating that funds are at risk unless the seed was created with at least 50 independent private dice rolls and the wallet is protected by a strong, unique BIP-39 passphrase, added a paragraph qualifying what counts as such a passphrase, and added a sentence calling the reduced search space a direct security risk rather than a theoretical possibility for wallets meeting neither condition.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 15,
          "removed_lines": 3
        }
      ]
    },
    {
      "id": "coinkite-mk3-advisory",
      "title": "Mk3 security advisory",
      "url": "https://blog.coinkite.com/coldcard-mk3-seed-generation-warning/",
      "organisation": "Coinkite",
      "kind": "vendor-advisory",
      "role": "Vendor advisory",
      "publication_time": "2026-07-30",
      "note": "The original narrow advisory. Stated Mk4/Q/Mk5 'not affected based on our early analysis'.",
      "capture": {
        "status": "held",
        "copies": 5,
        "first_observed": "2026-07-31T01:56:33Z",
        "last_observed": "2026-08-01T18:44:33Z",
        "last_checked": "2026-08-02T00:57:40Z"
      },
      "differences": [
        {
          "observed_at": "2026-08-01T18:44:33Z",
          "window_start": "2026-08-01T14:02:34Z",
          "window_end": "2026-08-01T18:44:33Z",
          "status": "source-content",
          "summary": "Fourth recorded revision of the advisory, and the one that resolves the Mk2 question this archive had tracked as open. The update stamp moved to August 1, 2026 at 2:35 p.m. EDT and every Mk3-only statement about the defect and its fix now names both models: the fixed-firmware list reads 'Mk2/Mk3: version 4.2.0 or later', the affected range reads 'The issue is present on Mk2 and Mk3 firmware versions 4.0.1 through 4.1.9 inclusive', the at-risk sentence covers 'a seed generated on Mk2 or Mk3 version 4.0.1 (March 2021) through 4.1.9', and the release is described as 'Fixed Mk2/Mk3 firmware version 4.2.0' from the 'official Mk2/Mk3 download page'. The one-device migration section, the optional dice-only section and the closing migration steps were rewritten from Mk3-only to Mk2-or-Mk3 wording. Until this revision the vendor downloads-page listing was the only vendor evidence placing the Mk2 in the affected range or the hotfix. The published lower bound is unchanged at 4.0.1 for both models, so the v4.0.0 divergence recorded on the firmware page is untouched.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 30,
          "removed_lines": 29
        },
        {
          "observed_at": "2026-08-01T14:02:34Z",
          "window_start": "2026-08-01T00:17:31Z",
          "window_end": "2026-08-01T14:02:34Z",
          "status": "source-content",
          "summary": "Third recorded revision of the advisory. It now carries 'Updated August 1, 2026 at 9:35 a.m. EDT' and replaces the blanket warning that Mk3 4.0.1 to 4.1.9 users' funds 'may be at risk' with a conditional statement that funds are at risk unless the seed was created with at least 50 fair, independent, private dice rolls and the wallet is protected by a strong, unique BIP-39 passphrase. The passphrase section changed in both directions: it now states that reduced seed entropy alone is not enough to reach a passphrase wallet, and separately that a strong passphrase does not repair the seed, that passphrase users should also migrate, and that an uncertain passphrase means treating funds as at risk and migrating immediately.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 19,
          "removed_lines": 10
        },
        {
          "observed_at": "2026-08-01T00:17:31Z",
          "window_start": "2026-07-31T07:30:23Z",
          "window_end": "2026-08-01T00:17:31Z",
          "status": "source-content",
          "summary": "Coinkite announced fixed firmware for every affected model and release track, including Mk3 4.2.0, and rewrote the one-device migration guidance.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": true,
          "added_lines": 66,
          "removed_lines": 53
        },
        {
          "observed_at": "2026-07-31T07:30:23Z",
          "window_start": "2026-07-31T01:56:33Z",
          "window_end": "2026-07-31T07:30:23Z",
          "status": "source-content",
          "summary": "Coinkite expanded the affected scope to Mk4, Mk5 and Q, added dice guidance, and revised the passphrase and migration sections.",
          "inherited_from_wayback": true,
          "baseline_inherited_from_wayback": true,
          "added_lines": 56,
          "removed_lines": 19
        }
      ]
    },
    {
      "id": "coinkite-blog-index",
      "title": "Coinkite blog index",
      "url": "https://blog.coinkite.com/",
      "organisation": "Coinkite",
      "kind": "vendor-index",
      "role": "Vendor publication index",
      "publication_time": null,
      "note": "Coinkite's publication index, retained to detect additional incident material.",
      "capture": {
        "status": "held",
        "copies": 2,
        "first_observed": "2026-08-01T00:17:31Z",
        "last_observed": "2026-08-01T14:02:36Z",
        "last_checked": "2026-08-02T00:57:41Z"
      },
      "differences": [
        {
          "observed_at": "2026-08-01T14:02:36Z",
          "window_start": "2026-08-01T00:17:31Z",
          "window_end": "2026-08-01T14:02:36Z",
          "status": "source-content",
          "summary": "The blog index excerpt for the advisory changed with the advisory itself, from 'Coinkite is warning users who generated a seed using a COLDCARD on firmware versions 4.0.1 throug...' to 'Funds from affected COLDCARD seeds are at risk if the seed lacks 50 independent, private dice rol...'.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 1,
          "removed_lines": 1
        }
      ]
    },
    {
      "id": "coldcard-downloads",
      "title": "COLDCARD firmware downloads",
      "url": "https://coldcard.com/downloads",
      "organisation": "Coinkite",
      "kind": "vendor-releases",
      "role": "Firmware release index",
      "publication_time": null,
      "note": "Which firmware is actually being offered, and when it appeared.",
      "capture": {
        "status": "held",
        "copies": 2,
        "first_observed": "2026-08-01T00:17:31Z",
        "last_observed": "2026-08-01T14:02:38Z",
        "last_checked": "2026-08-02T00:57:43Z"
      },
      "differences": [
        {
          "observed_at": "2026-08-01T14:02:38Z",
          "window_start": "2026-08-01T00:17:31Z",
          "window_end": "2026-08-01T14:02:38Z",
          "status": "source-content",
          "summary": "The site-wide advisory banner hardened from 'Seeds generated on firmware 4.0.1 or later may be at risk' to 'Seeds generated on firmware 4.0.1 (2021 or later) are at risk'.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 1,
          "removed_lines": 1
        }
      ]
    },
    {
      "id": "mara-slipstream-portal",
      "title": "MARA Slipstream transaction-submission portal",
      "url": "https://slipstream.mara.com/",
      "organisation": "MARA",
      "kind": "vendor-docs",
      "role": "Vendor documentation",
      "publication_time": null,
      "note": "Live submission portal used to check the public client-code, fee and submission interface described on the threshold-wallet migration page.",
      "capture": {
        "status": "held",
        "copies": 1,
        "first_observed": "2026-08-01T09:15:12Z",
        "last_observed": "2026-08-01T09:15:12Z",
        "last_checked": "2026-08-02T00:57:46Z"
      },
      "differences": []
    },
    {
      "id": "mara-slipstream-api",
      "title": "MARA Slipstream API documentation",
      "url": "https://slipstream.mara.com/docs/",
      "organisation": "MARA",
      "kind": "vendor-docs",
      "role": "Vendor documentation",
      "publication_time": null,
      "note": "Official OpenAPI description captured through its stable JSON endpoint. It documents admission rules, best-effort handling and the request schema.",
      "capture": {
        "status": "held",
        "copies": 1,
        "first_observed": "2026-08-01T09:15:18Z",
        "last_observed": "2026-08-01T09:15:18Z",
        "last_checked": "2026-08-02T00:57:53Z"
      },
      "differences": []
    },
    {
      "id": "cc-changelog",
      "title": "COLDCARD firmware changelog",
      "url": "https://raw.githubusercontent.com/Coldcard/firmware/master/releases/ChangeLog.md",
      "organisation": "Coinkite",
      "kind": "repo-file",
      "role": "Repository file",
      "publication_time": null,
      "note": null,
      "capture": {
        "status": "held",
        "copies": 1,
        "first_observed": "2026-08-01T00:17:31Z",
        "last_observed": "2026-08-01T00:17:31Z",
        "last_checked": "2026-08-02T00:57:55Z"
      },
      "differences": []
    },
    {
      "id": "cc-history-mk3",
      "title": "Mk3 firmware history",
      "url": "https://raw.githubusercontent.com/Coldcard/firmware/master/releases/History-Mk3.md",
      "organisation": "Coinkite",
      "kind": "repo-file",
      "role": "Repository file",
      "publication_time": null,
      "note": "Carries the 4.2.0 entry and the do-not-generate banner.",
      "capture": {
        "status": "held",
        "copies": 1,
        "first_observed": "2026-08-01T00:17:31Z",
        "last_observed": "2026-08-01T00:17:31Z",
        "last_checked": "2026-08-02T00:57:57Z"
      },
      "differences": []
    },
    {
      "id": "cc-history-mk",
      "title": "Mk4 and Mk5 firmware history",
      "url": "https://raw.githubusercontent.com/Coldcard/firmware/master/releases/History-Mk.md",
      "organisation": "Coinkite",
      "kind": "repo-file",
      "role": "Repository file",
      "publication_time": null,
      "note": null,
      "capture": {
        "status": "held",
        "copies": 1,
        "first_observed": "2026-08-01T00:17:31Z",
        "last_observed": "2026-08-01T00:17:31Z",
        "last_checked": "2026-08-02T00:57:58Z"
      },
      "differences": []
    },
    {
      "id": "cc-history-q",
      "title": "Q firmware history",
      "url": "https://raw.githubusercontent.com/Coldcard/firmware/master/releases/History-Q.md",
      "organisation": "Coinkite",
      "kind": "repo-file",
      "role": "Repository file",
      "publication_time": null,
      "note": null,
      "capture": {
        "status": "held",
        "copies": 1,
        "first_observed": "2026-08-01T00:17:31Z",
        "last_observed": "2026-08-01T00:17:31Z",
        "last_checked": "2026-08-02T00:58:00Z"
      },
      "differences": []
    },
    {
      "id": "libngu-random-c",
      "title": "libngu random.c",
      "url": "https://raw.githubusercontent.com/switck/libngu/master/ngu/random.c",
      "organisation": "switck",
      "kind": "repo-file",
      "role": "Repository file",
      "publication_time": null,
      "note": "The #ifndef guard and 32-bit reseed. Still unfixed upstream as of 1 Aug 2026; this tracks whether that changes.",
      "capture": {
        "status": "held",
        "copies": 1,
        "first_observed": "2026-08-01T00:23:36Z",
        "last_observed": "2026-08-01T00:23:36Z",
        "last_checked": "2026-08-02T00:58:02Z"
      },
      "differences": []
    },
    {
      "id": "libngu-pr-58",
      "title": "libngu PR #58",
      "url": "https://github.com/switck/libngu/pull/58",
      "organisation": "switck",
      "kind": "repo-pr",
      "role": "Repository pull request",
      "publication_time": null,
      "note": "Incident-response PR open with no maintainer response present in the 1 Aug 2026 capture. Retained to record later review or status changes.",
      "capture": {
        "status": "held",
        "copies": 3,
        "first_observed": "2026-08-01T03:25:23Z",
        "last_observed": "2026-08-01T08:11:50Z",
        "last_checked": "2026-08-02T00:58:04Z"
      },
      "differences": [
        {
          "observed_at": "2026-08-01T08:11:50Z",
          "window_start": "2026-08-01T03:50:17Z",
          "window_end": "2026-08-01T08:11:50Z",
          "status": "capture-noise",
          "summary": "Only the thumbs-up reaction total and reacting-account list changed; the pull-request discussion and patch text were unchanged.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 3,
          "removed_lines": 3
        },
        {
          "observed_at": "2026-08-01T03:50:17Z",
          "window_start": "2026-08-01T03:25:23Z",
          "window_end": "2026-08-01T03:50:17Z",
          "status": "capture-noise",
          "summary": "Only GitHub repository navigation counters changed.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 2,
          "removed_lines": 2
        }
      ]
    },
    {
      "id": "libngu-pr-58-patch",
      "title": "libngu PR #58 patch",
      "url": "https://github.com/switck/libngu/pull/58.patch",
      "organisation": "switck",
      "kind": "repo-patch",
      "role": "Repository patch",
      "publication_time": null,
      "note": "Patch content for the open incident-response proposal. Kept separately from the conversation and review-state capture.",
      "capture": {
        "status": "held",
        "copies": 1,
        "first_observed": "2026-08-01T06:39:23Z",
        "last_observed": "2026-08-01T06:39:23Z",
        "last_checked": "2026-08-02T00:58:06Z"
      },
      "differences": []
    },
    {
      "id": "libngu-pr-59",
      "title": "libngu PR #59",
      "url": "https://github.com/switck/libngu/pull/59",
      "organisation": "switck",
      "kind": "repo-pr",
      "role": "Repository pull request",
      "publication_time": null,
      "note": "Broad incident-response PR. On 1 Aug the maintainer called the diff too large and the author offered a three-PR split.",
      "capture": {
        "status": "held",
        "copies": 3,
        "first_observed": "2026-08-01T03:25:24Z",
        "last_observed": "2026-08-01T16:08:11Z",
        "last_checked": "2026-08-02T00:58:09Z"
      },
      "differences": [
        {
          "observed_at": "2026-08-01T16:08:11Z",
          "window_start": "2026-08-01T03:50:19Z",
          "window_end": "2026-08-01T16:08:11Z",
          "status": "source-content",
          "summary": "The pull request was closed by its author in favour of a three-pull-request stack (#62, #63 and #64) described as summing to a byte-identical tree, with a suggested review order and an offer to reopen.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 20,
          "removed_lines": 2
        },
        {
          "observed_at": "2026-08-01T03:50:19Z",
          "window_start": "2026-08-01T03:25:24Z",
          "window_end": "2026-08-01T03:50:19Z",
          "status": "source-content",
          "summary": "The pull-request author added a comment offering to split the proposal into three smaller changes; GitHub navigation counters also changed.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 14,
          "removed_lines": 2
        }
      ]
    },
    {
      "id": "libngu-pr-59-patch",
      "title": "libngu PR #59 patch",
      "url": "https://github.com/switck/libngu/pull/59.patch",
      "organisation": "switck",
      "kind": "repo-patch",
      "role": "Repository patch",
      "publication_time": null,
      "note": "Patch content for the open incident-response proposal. Kept separately from the conversation and review-state capture.",
      "capture": {
        "status": "held",
        "copies": 1,
        "first_observed": "2026-08-01T06:39:31Z",
        "last_observed": "2026-08-01T06:39:31Z",
        "last_checked": "2026-08-02T00:58:11Z"
      },
      "differences": []
    },
    {
      "id": "libngu-pr-60",
      "title": "libngu PR #60: full-width reseeding",
      "url": "https://github.com/switck/libngu/pull/60",
      "organisation": "switck",
      "kind": "repo-pr",
      "role": "Repository pull request",
      "publication_time": null,
      "note": "Open incident-response proposal to absorb a bytes-like seed into all Yasmarang state words. Companion to Coldcard/firmware PR #691.",
      "capture": {
        "status": "held",
        "copies": 3,
        "first_observed": "2026-08-01T06:21:09Z",
        "last_observed": "2026-08-01T17:41:16Z",
        "last_checked": "2026-08-02T00:58:14Z"
      },
      "differences": [
        {
          "observed_at": "2026-08-01T17:41:16Z",
          "window_start": "2026-08-01T16:08:18Z",
          "window_end": "2026-08-01T17:41:16Z",
          "status": "source-content",
          "summary": "The inline cross-reference to Coldcard/firmware#691 changed from Open to Draft, reflecting a real state change on that pull request rather than rendering variance. Nothing else moved: no discussion, review or patch text on this pull request changed. The underlying state change is captured directly on coldcard-firmware-pr-691 at 20260801T174121Z, so this entry is the same event seen from the linked repository.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 1,
          "removed_lines": 1
        },
        {
          "observed_at": "2026-08-01T16:08:18Z",
          "window_start": "2026-08-01T06:21:09Z",
          "window_end": "2026-08-01T16:08:18Z",
          "status": "source-content",
          "summary": "Two contributors reviewed the reseed change, the author pushed a second commit rejecting a zero-length seed and documenting a roughly 72-bit state ceiling, a reviewer argued for removing Yasmarang entirely and announced a competing pull request, and the author closed this one in favour of #61.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 78,
          "removed_lines": 7
        }
      ]
    },
    {
      "id": "libngu-pr-60-patch",
      "title": "libngu PR #60 patch",
      "url": "https://github.com/switck/libngu/pull/60.patch",
      "organisation": "switck",
      "kind": "repo-patch",
      "role": "Repository patch",
      "publication_time": null,
      "note": "Patch content for the open full-width reseed proposal. Kept separately from the conversation and review-state capture.",
      "capture": {
        "status": "held",
        "copies": 2,
        "first_observed": "2026-08-01T06:39:32Z",
        "last_observed": "2026-08-01T16:08:21Z",
        "last_checked": "2026-08-02T00:58:16Z"
      },
      "differences": [
        {
          "observed_at": "2026-08-01T16:08:21Z",
          "window_start": "2026-08-01T06:39:32Z",
          "window_end": "2026-08-01T16:08:21Z",
          "status": "source-content",
          "summary": "The published patch series gained a second commit adding a ValueError on an empty seed, a regression test and a comment documenting the generator's roughly 72-bit independent state.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 61,
          "removed_lines": 1
        }
      ]
    },
    {
      "id": "coldcard-firmware-pr-691",
      "title": "COLDCARD firmware PR #691: pass the full secure-element digest",
      "url": "https://github.com/Coldcard/firmware/pull/691",
      "organisation": "Coinkite",
      "kind": "repo-pr",
      "role": "Repository pull request",
      "publication_time": null,
      "note": "Open incident-response proposal to remove the firmware-side four-byte truncation. Depends on the libngu PR #60 change.",
      "capture": {
        "status": "held",
        "copies": 4,
        "first_observed": "2026-08-01T06:21:15Z",
        "last_observed": "2026-08-01T17:41:21Z",
        "last_checked": "2026-08-02T00:58:19Z"
      },
      "differences": [
        {
          "observed_at": "2026-08-01T17:41:21Z",
          "window_start": "2026-08-01T16:08:24Z",
          "window_end": "2026-08-01T17:41:21Z",
          "status": "source-content",
          "summary": "The author marked the pull request as a draft at 16:13 and rewrote its description. The submodule bump note became a re-pin to the companion RNG fix, and the stated dependency moved from switck/libngu#60 to #61, described as replacing the generator with a SHA-256 Hash-DRBG and making reseed() require a seed of at least 32 bytes, so this firmware change becomes a prerequisite for #61 booting on-device. GitHub edited-comment and loading-error chrome appeared in the same capture.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 17,
          "removed_lines": 9
        },
        {
          "observed_at": "2026-08-01T16:08:24Z",
          "window_start": "2026-08-01T07:34:40Z",
          "window_end": "2026-08-01T16:08:24Z",
          "status": "source-content",
          "summary": "The pull request gained a further comment repeating the request to raise the libngu changes as a separate pull request against the libngu repository, linking switck/libngu#60; reaction totals were normalized in the same capture.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 12,
          "removed_lines": 0
        },
        {
          "observed_at": "2026-08-01T07:34:40Z",
          "window_start": "2026-08-01T06:21:15Z",
          "window_end": "2026-08-01T07:34:40Z",
          "status": "source-content",
          "summary": "A COLDCARD firmware collaborator asked the author to move the libngu changes into a separate pull request; GitHub review metadata and navigation chrome also changed.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 31,
          "removed_lines": 2
        }
      ]
    },
    {
      "id": "coldcard-firmware-pr-691-patch",
      "title": "COLDCARD firmware PR #691 patch",
      "url": "https://github.com/Coldcard/firmware/pull/691.patch",
      "organisation": "Coinkite",
      "kind": "repo-patch",
      "role": "Repository patch",
      "publication_time": null,
      "note": "Patch content for the open firmware-side full-digest proposal. Kept separately from the conversation and review-state capture.",
      "capture": {
        "status": "held",
        "copies": 1,
        "first_observed": "2026-08-01T06:39:34Z",
        "last_observed": "2026-08-01T06:39:34Z",
        "last_checked": "2026-08-02T00:58:22Z"
      },
      "differences": []
    },
    {
      "id": "coldcard-firmware-pr-689",
      "title": "COLDCARD firmware PR #689: Mk3 RNG hotfix",
      "url": "https://github.com/Coldcard/firmware/pull/689",
      "organisation": "Coinkite",
      "kind": "repo-pr",
      "role": "Repository pull request",
      "publication_time": null,
      "note": "Merged source-level Mk3 hotfix. Captures the pull-request provenance and merged source commit associated with 4.2.0; the signed release record is separate.",
      "capture": {
        "status": "held",
        "copies": 1,
        "first_observed": "2026-08-01T06:23:08Z",
        "last_observed": "2026-08-01T06:23:08Z",
        "last_checked": "2026-08-02T00:58:24Z"
      },
      "differences": []
    },
    {
      "id": "coldcard-firmware-pr-689-patch",
      "title": "COLDCARD firmware PR #689 patch",
      "url": "https://github.com/Coldcard/firmware/pull/689.patch",
      "organisation": "Coinkite",
      "kind": "repo-patch",
      "role": "Repository patch",
      "publication_time": null,
      "note": "Patch content for the merged Mk3 v4-legacy hotfix. Kept separately from the pull-request conversation capture.",
      "capture": {
        "status": "held",
        "copies": 1,
        "first_observed": "2026-08-01T06:39:35Z",
        "last_observed": "2026-08-01T06:39:35Z",
        "last_checked": "2026-08-02T00:58:27Z"
      },
      "differences": []
    },
    {
      "id": "coldcard-firmware-pr-690",
      "title": "COLDCARD firmware PR #690: Edge RNG hotfix",
      "url": "https://github.com/Coldcard/firmware/pull/690",
      "organisation": "Coinkite",
      "kind": "repo-pr",
      "role": "Repository pull request",
      "publication_time": null,
      "note": "Merged Edge source and release-history integration. Captures the pull-request provenance behind the published 6.6.0X and 6.6.0QX releases.",
      "capture": {
        "status": "held",
        "copies": 1,
        "first_observed": "2026-08-01T06:23:13Z",
        "last_observed": "2026-08-01T06:23:13Z",
        "last_checked": "2026-08-02T00:58:29Z"
      },
      "differences": []
    },
    {
      "id": "coldcard-firmware-pr-690-patch",
      "title": "COLDCARD firmware PR #690 patch",
      "url": "https://github.com/Coldcard/firmware/pull/690.patch",
      "organisation": "Coinkite",
      "kind": "repo-patch",
      "role": "Repository patch",
      "publication_time": null,
      "note": "Patch content for the merged Edge hotfix. Kept separately from the pull-request conversation capture.",
      "capture": {
        "status": "held",
        "copies": 1,
        "first_observed": "2026-08-01T06:39:36Z",
        "last_observed": "2026-08-01T06:39:36Z",
        "last_checked": "2026-08-02T00:58:32Z"
      },
      "differences": []
    },
    {
      "id": "coldcard-firmware-mainline-hotfix",
      "title": "COLDCARD mainline RNG hotfix commit ca724637",
      "url": "https://github.com/Coldcard/firmware/commit/ca72463709f4e3f8964952039d5caf955f566a87.patch",
      "organisation": "Coinkite",
      "kind": "repo-commit",
      "role": "Repository commit",
      "publication_time": null,
      "note": "Immutable patch for the direct mainline source commit contained in the normal Mk4/Mk5 v5.6.0 and Q v1.5.0Q release histories.",
      "capture": {
        "status": "held",
        "copies": 1,
        "first_observed": "2026-08-01T06:39:38Z",
        "last_observed": "2026-08-01T06:39:38Z",
        "last_checked": "2026-08-02T00:58:34Z"
      },
      "differences": []
    },
    {
      "id": "bitcoinorg-pr-4905",
      "title": "Bitcoin.org PR #4905: remove COLDCARD listings",
      "url": "https://github.com/bitcoin-dot-org/Bitcoin.org/pull/4905",
      "organisation": "Bitcoin.org",
      "kind": "repo-pr",
      "role": "Repository pull request",
      "publication_time": null,
      "note": "Merged community-response record. Bitcoin.org removed its COLDCARD and COLDCARD Q listings under the site's published wallet-listing criterion after the incident.",
      "capture": {
        "status": "held",
        "copies": 1,
        "first_observed": "2026-08-01T06:25:42Z",
        "last_observed": "2026-08-01T06:25:42Z",
        "last_checked": "2026-08-02T00:58:36Z"
      },
      "differences": []
    },
    {
      "id": "satsigner-pr-468",
      "title": "SatSigner PR #468: entropy audit and hardening",
      "url": "https://github.com/satsigner/satsigner/pull/468",
      "organisation": "SatSigner",
      "kind": "repo-pr",
      "role": "Repository pull request",
      "publication_time": null,
      "note": "Open downstream response prompted by the COLDCARD disclosure. The author reports that SatSigner's default path was sound and proposes fixes for separate optional dice and coin paths.",
      "capture": {
        "status": "held",
        "copies": 1,
        "first_observed": "2026-08-01T06:25:47Z",
        "last_observed": "2026-08-01T06:25:47Z",
        "last_checked": "2026-08-02T00:58:39Z"
      },
      "differences": []
    },
    {
      "id": "seedsigner-pr-962",
      "title": "SeedSigner PR #962: withdrawn camera-entropy hardening proposal",
      "url": "https://github.com/SeedSigner/seedsigner/pull/962",
      "organisation": "SeedSigner",
      "kind": "repo-pr",
      "role": "Repository pull request",
      "publication_time": null,
      "note": "Closed without merge after the author said the proposed histogram thresholds did not measure sensor entropy. Retained as a correction record, not evidence of a SeedSigner vulnerability.",
      "capture": {
        "status": "held",
        "copies": 1,
        "first_observed": "2026-08-01T06:25:52Z",
        "last_observed": "2026-08-01T06:25:52Z",
        "last_checked": "2026-08-02T00:58:42Z"
      },
      "differences": []
    },
    {
      "id": "coinkite-terms",
      "title": "Coinkite terms of sale",
      "url": "https://coinkite.com/terms",
      "organisation": "Coinkite",
      "kind": "vendor-legal",
      "role": "Legal terms",
      "publication_time": "2024-11-27",
      "note": "Terms of Sale. Caps aggregate liability at the purchase price, disclaims\nwarranties, reserves arbitration at Coinkite's sole option, waives class actions\nand selects Ontario law. Quoted on /response/legal/ alongside sections 2, 7 and\n8 of Ontario's Consumer Protection Act, 2002, which e-Laws listed as in force\nwhen checked on 1 Aug 2026. Whether those provisions apply to a particular\nbuyer or claim requires case-specific legal analysis. The terms are retained\nfor dated revision comparison.\n",
      "capture": {
        "status": "held",
        "copies": 2,
        "first_observed": "2026-08-01T03:25:25Z",
        "last_observed": "2026-08-01T16:08:33Z",
        "last_checked": "2026-08-02T00:58:44Z"
      },
      "differences": [
        {
          "observed_at": "2026-08-01T16:08:33Z",
          "window_start": "2026-08-01T03:25:25Z",
          "window_end": "2026-08-01T16:08:33Z",
          "status": "source-content",
          "summary": "The site-wide advisory banner on the terms page hardened from 'Seeds generated on firmware 4.0.1 or later may be at risk' to 'Seeds generated on firmware 4.0.1 (2021 or later) are at risk', matching the downloads page.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 1,
          "removed_lines": 1
        }
      ]
    },
    {
      "id": "ontario-consumer-protection-act-2002",
      "title": "Consumer Protection Act, 2002",
      "url": "https://www.ontario.ca/laws/statute/02c30",
      "organisation": "Ontario e-Laws",
      "kind": "government-legal",
      "role": "Government legislation",
      "publication_time": null,
      "note": "Official current consolidation used for the application, non-waiver, arbitration and class-proceeding provisions summarised on the legal-context page.",
      "capture": {
        "status": "held",
        "copies": 1,
        "first_observed": "2026-08-01T09:15:18Z",
        "last_observed": "2026-08-01T09:15:18Z",
        "last_checked": "2026-08-02T00:58:47Z"
      },
      "differences": []
    },
    {
      "id": "ontario-consumer-protection-act-2023",
      "title": "Consumer Protection Act, 2023",
      "url": "https://www.ontario.ca/laws/statute/23c23",
      "organisation": "Ontario e-Laws",
      "kind": "government-legal",
      "role": "Government legislation",
      "publication_time": null,
      "note": "Official statute page used to check commencement status. The page stated on 1 August 2026 that the Act was not yet in force and would commence by proclamation.",
      "capture": {
        "status": "held",
        "copies": 1,
        "first_observed": "2026-08-01T09:15:20Z",
        "last_observed": "2026-08-01T09:15:20Z",
        "last_checked": "2026-08-02T00:58:51Z"
      },
      "differences": []
    },
    {
      "id": "block-disclosure",
      "title": "Predictable RNG fallback and 32-bit reseed",
      "url": "https://engineering.block.xyz/blog/predictable-rng-fallback-and-32-bit-reseed-in-coldcard-firmware",
      "organisation": "Block",
      "kind": "research",
      "role": "Primary technical research",
      "publication_time": "2026-07-30",
      "note": null,
      "capture": {
        "status": "held",
        "copies": 2,
        "first_observed": "2026-07-31T03:29:24Z",
        "last_observed": "2026-08-01T00:17:31Z",
        "last_checked": "2026-08-02T00:58:54Z"
      },
      "differences": []
    },
    {
      "id": "threez-mk3-rng-disclosure",
      "title": "Mk3 binary reversal and bounded proof of concept",
      "url": "https://raw.githubusercontent.com/3z/coldcard-mk3-rng-disclosure/main/README.md",
      "organisation": "3z",
      "kind": "independent-analysis",
      "role": "Independent primary analysis",
      "publication_time": "2026-07-31",
      "note": "Independent binary-level comparison of vulnerable and fixed Mk3 firmware, with\na synthetic proof of concept. The repository deliberately excludes enumeration,\nwallet-recovery and fund-targeting capability. Its candidate-state analysis is\nthe author's model and is not treated here as a population measurement.\n",
      "capture": {
        "status": "held",
        "copies": 1,
        "first_observed": "2026-08-01T05:59:38Z",
        "last_observed": "2026-08-01T05:59:38Z",
        "last_checked": "2026-08-02T00:58:56Z"
      },
      "differences": []
    },
    {
      "id": "threez-mk3-rng-disclosure-pinned",
      "title": "Mk3 bounded proof README at e17d833b",
      "url": "https://raw.githubusercontent.com/3z/coldcard-mk3-rng-disclosure/e17d833bc02371ef779e66e25a78c755e57039ef/README.md",
      "organisation": "3z",
      "kind": "repo-commit",
      "role": "Repository commit",
      "publication_time": "2026-07-31",
      "note": "Immutable README revision used by the fixed synthetic Mk3 regression vector. The separate main-branch source remains registered for change detection.",
      "capture": {
        "status": "held",
        "copies": 1,
        "first_observed": "2026-08-01T06:39:38Z",
        "last_observed": "2026-08-01T06:39:38Z",
        "last_checked": "2026-08-02T00:58:58Z"
      },
      "differences": []
    },
    {
      "id": "kelbie-rng-postmortem",
      "title": "Chain-derived COLDCARD RNG postmortem",
      "url": "https://raw.githubusercontent.com/Kelbie/coldcard-rng-postmortem/main/README.md",
      "organisation": "Kelbie",
      "kind": "independent-analysis",
      "role": "Independent primary analysis",
      "publication_time": "2026-07-31",
      "note": "Rapidly updated independent postmortem built from frozen chain data and public\nreports. It documents its derivation and attribution rules, but its wave\ngrouping, entity attribution and counterfactual conclusions remain the author's\nanalysis rather than facts established by the chain alone.\n",
      "capture": {
        "status": "held",
        "copies": 3,
        "first_observed": "2026-08-01T05:59:38Z",
        "last_observed": "2026-08-01T17:12:00Z",
        "last_checked": "2026-08-02T00:59:00Z"
      },
      "differences": [
        {
          "observed_at": "2026-08-01T17:12:00Z",
          "window_start": "2026-08-01T16:07:15Z",
          "window_end": "2026-08-01T17:12:00Z",
          "status": "source-content",
          "summary": "The README added derivation sections on grouping waves into families by build traits rather than configuration dials, on fee pricing and its lack of correlation with value, on wave colour, and on re-applying Block's published seven-property fingerprint across the whole record, plus a new fingerprint script in the file map.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 43,
          "removed_lines": 3
        },
        {
          "observed_at": "2026-08-01T16:07:15Z",
          "window_start": "2026-08-01T05:59:38Z",
          "window_end": "2026-08-01T16:07:15Z",
          "status": "source-content",
          "summary": "The README renamed waves from ordinal numbers to block heights throughout, so 'wave 3' became 'wave 960188' and Block's 'waves 1 and 2' became 'waves 960183 and 960185'.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 4,
          "removed_lines": 4
        }
      ]
    },
    {
      "id": "alvap-weak-rng-research",
      "title": "Reproducible firmware and chain investigation",
      "url": "https://raw.githubusercontent.com/alva-p/coldcard-weak-rng-research/main/README.md",
      "organisation": "Álvaro P.",
      "kind": "independent-analysis",
      "role": "Independent primary analysis",
      "publication_time": "2026-07-31",
      "note": "Independent re-derivation of fix commits, on-chain movements and vulnerable\nversus patched firmware symbols. Its README excludes real-seed recovery and\nlabels unfinished work explicitly; deeper repository files include public\ntransaction identifiers and are not mirrored by this archive.\n",
      "capture": {
        "status": "held",
        "copies": 1,
        "first_observed": "2026-08-01T05:59:38Z",
        "last_observed": "2026-08-01T05:59:38Z",
        "last_checked": "2026-08-02T00:59:02Z"
      },
      "differences": []
    },
    {
      "id": "debian-openssl-dsa-1571",
      "title": "Debian Security Advisory DSA-1571-1",
      "url": "https://lists.debian.org/debian-security-announce/2008/msg00152.html",
      "organisation": "Debian",
      "kind": "vendor-advisory",
      "role": "Vendor advisory",
      "publication_time": "2008-05-13",
      "note": "Primary Debian advisory for CVE-2008-0166, including the affected release period and instruction to regenerate cryptographic key material.",
      "capture": {
        "status": "held",
        "copies": 1,
        "first_observed": "2026-08-01T09:15:22Z",
        "last_observed": "2026-08-01T09:15:22Z",
        "last_checked": "2026-08-02T00:59:03Z"
      },
      "differences": []
    },
    {
      "id": "android-securerandom-2013",
      "title": "Some SecureRandom thoughts",
      "url": "https://android-developers.googleblog.com/2013/08/some-securerandom-thoughts.html",
      "organisation": "Android Developers",
      "kind": "vendor-statement",
      "role": "Vendor statement",
      "publication_time": "2013-08-14",
      "note": "Primary Android statement on improper PRNG initialization affecting some cryptographic applications, including Bitcoin wallets.",
      "capture": {
        "status": "held",
        "copies": 1,
        "first_observed": "2026-08-01T09:15:34Z",
        "last_observed": "2026-08-01T09:15:34Z",
        "last_checked": "2026-08-02T00:59:17Z"
      },
      "differences": []
    },
    {
      "id": "unciphered-randstorm-disclosure",
      "title": "Disclosure of vulnerable Bitcoin wallet library",
      "url": "https://www.unciphered.com/disclosure-of-vulnerable-bitcoin-wallet-library-2/",
      "organisation": "Unciphered",
      "kind": "research",
      "role": "Primary technical research",
      "publication_time": "2023-11-14",
      "note": "Primary Randstorm disclosure describing vulnerable BitcoinJS-derived browser wallets and the browser- and date-dependent attack surface.",
      "capture": {
        "status": "held",
        "copies": 1,
        "first_observed": "2026-08-01T09:15:35Z",
        "last_observed": "2026-08-01T09:15:35Z",
        "last_checked": "2026-08-02T00:59:19Z"
      },
      "differences": []
    },
    {
      "id": "milksad-disclosure",
      "title": "Milk Sad vulnerability disclosure",
      "url": "https://milksad.info/disclosure.html",
      "organisation": "Milk Sad research team",
      "kind": "research",
      "role": "Primary technical research",
      "publication_time": "2023-08-08",
      "note": "Primary disclosure for CVE-2023-39910, including the 32-bit MT19937 seed funnel, partial impact accounting and comparison with the Trust Wallet incident.",
      "capture": {
        "status": "held",
        "copies": 1,
        "first_observed": "2026-08-01T09:15:35Z",
        "last_observed": "2026-08-01T09:15:35Z",
        "last_checked": "2026-08-02T00:59:21Z"
      },
      "differences": []
    },
    {
      "id": "nvd-cve-2023-31290",
      "title": "CVE-2023-31290 vulnerability record",
      "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-31290",
      "organisation": "NIST National Vulnerability Database",
      "kind": "government-record",
      "role": "Government vulnerability record",
      "publication_time": "2023-04-27",
      "note": "Official vulnerability record for the Trust Wallet browser-extension generator, affected versions, 32-bit entropy bound and reported exploitation period.",
      "capture": {
        "status": "held",
        "copies": 1,
        "first_observed": "2026-08-01T09:15:37Z",
        "last_observed": "2026-08-01T09:15:37Z",
        "last_checked": "2026-08-02T00:59:24Z"
      },
      "differences": []
    },
    {
      "id": "bitbox-not-affected",
      "title": "BitBox is not affected",
      "url": "https://blog.bitbox.swiss/en/bitbox-is-not-affected-by-the-coldcard-rng-vulnerability/",
      "organisation": "BitBox",
      "kind": "vendor-statement",
      "role": "Vendor statement",
      "publication_time": "2026-07-31",
      "note": null,
      "capture": {
        "status": "held",
        "copies": 1,
        "first_observed": "2026-08-01T00:46:13Z",
        "last_observed": "2026-08-01T00:46:13Z",
        "last_checked": "2026-08-02T00:59:27Z"
      },
      "differences": []
    },
    {
      "id": "jade-not-affected",
      "title": "Jade is unaffected",
      "url": "https://blog.blockstream.com/jade-unaffected-coldcard-vulnerability/",
      "organisation": "Blockstream",
      "kind": "vendor-statement",
      "role": "Vendor statement",
      "publication_time": "2026-07-31",
      "note": null,
      "capture": {
        "status": "held",
        "copies": 1,
        "first_observed": "2026-08-01T00:46:16Z",
        "last_observed": "2026-08-01T00:46:16Z",
        "last_checked": "2026-08-02T00:59:30Z"
      },
      "differences": []
    },
    {
      "id": "passport-not-affected",
      "title": "Passport is not affected",
      "url": "https://community.foundation.xyz/t/important-passport-is-not-affected-by-the-coldcard-seed-vulnerability/1147",
      "organisation": "Foundation",
      "kind": "vendor-statement",
      "role": "Vendor statement",
      "publication_time": "2026-07-31",
      "note": "The statement adds that a COLDCARD-generated seed imported into a Passport remains at risk.",
      "capture": {
        "status": "held",
        "copies": 2,
        "first_observed": "2026-08-01T00:46:19Z",
        "last_observed": "2026-08-01T16:09:53Z",
        "last_checked": "2026-08-02T00:59:33Z"
      },
      "differences": [
        {
          "observed_at": "2026-08-01T16:09:53Z",
          "window_start": "2026-08-01T00:46:19Z",
          "window_end": "2026-08-01T16:09:53Z",
          "status": "source-content",
          "summary": "Foundation added a reply to the thread saying manual firmware updates outside Envoy are scheduled for the next but one release, with no definitive timeframe committed.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 4,
          "removed_lines": 0
        }
      ]
    },
    {
      "id": "bitcoinmag-fix-and-ai",
      "title": "Coinkite releases fixed firmware",
      "url": "https://bitcoinmagazine.com/business/coinkite-releases-fixed-firmware-after-coldcard-bug-ai-likely-involved-in-the-hack",
      "organisation": "Bitcoin Magazine",
      "kind": "reporting",
      "role": "Reporting",
      "publication_time": "2026-07-31",
      "note": "Secondary reporting that quotes Peter Todd endorsing Slipstream as a submission option after Rob Hamilton's earlier recommendation.",
      "capture": {
        "status": "held",
        "copies": 1,
        "first_observed": "2026-08-01T00:46:22Z",
        "last_observed": "2026-08-01T00:46:22Z",
        "last_checked": "2026-08-02T00:59:35Z"
      },
      "differences": []
    },
    {
      "id": "tftc-who-must-move",
      "title": "Who must move their coins",
      "url": "https://www.tftc.io/coldcard-rng-failed-move-your-coins",
      "organisation": "TFTC",
      "kind": "analysis",
      "role": "Secondary analysis",
      "publication_time": "2026-07-31",
      "note": "Migration protocol plus a warning about scam recovery services.",
      "capture": {
        "status": "held",
        "copies": 2,
        "first_observed": "2026-08-01T00:46:24Z",
        "last_observed": "2026-08-01T03:08:27Z",
        "last_checked": "2026-08-02T00:59:37Z"
      },
      "differences": [
        {
          "observed_at": "2026-08-01T03:08:27Z",
          "window_start": "2026-08-01T00:46:24Z",
          "window_end": "2026-08-01T03:08:27Z",
          "status": "capture-noise",
          "summary": "Only rotating related-content cards below the article changed.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 10,
          "removed_lines": 10
        }
      ]
    },
    {
      "id": "theblock-galaxy-total",
      "title": "Galaxy loss estimate reporting",
      "url": "https://www.theblock.co/post/410332/bitcoin-losses-linked-coldcard-vulnerability-70-million-galaxy-research",
      "organisation": "The Block",
      "kind": "reporting",
      "role": "Reporting",
      "publication_time": "2026-07-31",
      "note": "Galaxy Research figures: 1,196 addresses, 1,082.65 BTC, 41-minute window.",
      "capture": {
        "status": "held",
        "copies": 6,
        "first_observed": "2026-08-01T00:46:26Z",
        "last_observed": "2026-08-01T22:26:20Z",
        "last_checked": "2026-08-02T00:59:39Z"
      },
      "differences": [
        {
          "observed_at": "2026-08-01T22:26:20Z",
          "window_start": "2026-08-01T16:10:02Z",
          "window_end": "2026-08-01T22:26:20Z",
          "status": "capture-noise",
          "summary": "Only the site chrome's rotating latest-news list changed; the incident article text, including its Galaxy total, was unchanged.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 4,
          "removed_lines": 4
        },
        {
          "observed_at": "2026-08-01T16:10:02Z",
          "window_start": "2026-08-01T08:12:59Z",
          "window_end": "2026-08-01T16:10:02Z",
          "status": "capture-noise",
          "summary": "Only the site chrome's rotating latest-news list changed; the incident article text was unchanged.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 2,
          "removed_lines": 2
        },
        {
          "observed_at": "2026-08-01T08:12:59Z",
          "window_start": "2026-08-01T03:22:37Z",
          "window_end": "2026-08-01T08:12:59Z",
          "status": "capture-noise",
          "summary": "The live market-ticker region was temporarily unavailable; the incident article text was unchanged.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 1,
          "removed_lines": 6
        },
        {
          "observed_at": "2026-08-01T03:22:37Z",
          "window_start": "2026-08-01T03:08:28Z",
          "window_end": "2026-08-01T03:22:37Z",
          "status": "capture-noise",
          "summary": "Only live cryptocurrency ticker values in the site navigation changed.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 4,
          "removed_lines": 4
        },
        {
          "observed_at": "2026-08-01T03:08:28Z",
          "window_start": "2026-08-01T00:46:26Z",
          "window_end": "2026-08-01T03:08:28Z",
          "status": "capture-noise",
          "summary": "Only live cryptocurrency ticker values in the site navigation changed.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 5,
          "removed_lines": 5
        }
      ]
    },
    {
      "id": "reddit-drained-timeline",
      "title": "Wallet drained timeline",
      "url": "https://www.reddit.com/r/Bitcoin/comments/1vb6teq/wallet_drained_timeline/",
      "organisation": "r/Bitcoin",
      "kind": "victim-account",
      "role": "First-hand account",
      "publication_time": "2026-07-31",
      "note": "A first-hand account posted while the sweep was still being worked out, before\nthe cause was publicly identified. A rendered capture from 1 Aug 2026 holds the\noriginal post and 25 comments locally. Public snapshot and diff text\nare withheld because the account contains identifying and wallet-specific\ndetails.",
      "capture": {
        "status": "held",
        "copies": 6,
        "first_observed": "2026-08-01T02:45:27Z",
        "last_observed": "2026-08-01T18:13:42Z",
        "last_checked": "2026-08-02T00:59:41Z"
      },
      "differences": [
        {
          "observed_at": "2026-08-01T18:13:42Z",
          "window_start": "2026-08-01T09:58:01Z",
          "window_end": "2026-08-01T18:13:42Z",
          "status": "capture-noise",
          "summary": "Two already-held comments swapped position in the rendered thread. No post or comment text was added, removed or altered, and the enabled normalizer already suppresses relative-time labels and engagement counts, so comment ordering is the only remaining difference. Reddit orders comments dynamically, so this is rendering variance rather than an edit by the author or moderators.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 10,
          "removed_lines": 10
        },
        {
          "observed_at": "2026-08-01T09:58:01Z",
          "window_start": "2026-08-01T09:52:30Z",
          "window_end": "2026-08-01T09:58:01Z",
          "status": "capture-noise",
          "summary": "Fewer lazy-loaded comments were present in this capture than the previous one, and the 'Read more' control was absent. The thread body is unchanged; the missing replies include two that link to the Coinkite advisory. Reddit renders comments progressively, so this is capture variance rather than deletion by the author or moderators.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 0,
          "removed_lines": 83
        },
        {
          "observed_at": "2026-08-01T09:52:30Z",
          "window_start": "2026-08-01T09:21:30Z",
          "window_end": "2026-08-01T09:52:30Z",
          "status": "capture-noise",
          "summary": "More lazy-loaded comments were rendered in this capture than in the previous one, and the 'Read more' control was present again. This is the inverse of the 09:58:01Z capture and the same progressive-rendering variance; no post or comment text already held was altered.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 83,
          "removed_lines": 0
        },
        {
          "observed_at": "2026-08-01T09:21:30Z",
          "window_start": "2026-08-01T02:59:16Z",
          "window_end": "2026-08-01T09:21:30Z",
          "status": "source-content",
          "summary": "The rendered thread added a comment linking to Gregory Sanders' reported reproduction; one comment present in the preceding capture was no longer rendered.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 10,
          "removed_lines": 8
        },
        {
          "observed_at": "2026-08-01T02:59:16Z",
          "window_start": "2026-08-01T02:45:27Z",
          "window_end": "2026-08-01T02:59:16Z",
          "status": "capture-correction",
          "summary": "A newly enabled comparison normalizer replaced relative-time labels and engagement counts; the post and comment text did not change.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 27,
          "removed_lines": 27
        }
      ]
    },
    {
      "id": "coldcard-watch",
      "title": "COLDCARD funds flow monitor",
      "url": "https://coldcard-watch.vercel.app/",
      "organisation": "community tracker",
      "kind": "chain-monitor",
      "role": "Chain monitor",
      "publication_time": null,
      "note": "The tracker expanded on 1 Aug from the first 1,195-address episode to two\nepisodes totalling 2,321 addresses and 1,128.4717 BTC. It includes a\nbrowser-local address checker and follows spends from the consolidation\naddresses hop by hop. It labels the first episode 29 July without stating a\ntimezone; the corresponding on-chain window begins 30 July at 01:10 UTC.\nOperator anonymous; figures cross-check against Galaxy's published map for the\nfirst episode.\n",
      "capture": {
        "status": "held",
        "copies": 6,
        "first_observed": "2026-08-01T02:34:03Z",
        "last_observed": "2026-08-02T00:59:57Z",
        "last_checked": "2026-08-02T00:59:57Z"
      },
      "differences": [
        {
          "observed_at": "2026-08-02T00:59:57Z",
          "window_start": "2026-08-01T17:43:04Z",
          "window_end": "2026-08-02T00:59:57Z",
          "status": "unreviewed",
          "summary": "This detected difference has not yet been reviewed for capture noise.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 3,
          "removed_lines": 3
        },
        {
          "observed_at": "2026-08-01T17:43:04Z",
          "window_start": "2026-08-01T14:03:09Z",
          "window_end": "2026-08-01T17:43:04Z",
          "status": "source-content",
          "summary": "The tracker's headline moved from 1,128.6633 BTC across 2,334 verified addresses to 1,158.8480 BTC across 2,686, and its address-check copy changed with it. The cluster description of three windows on 30 and 31 July was unchanged.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 3,
          "removed_lines": 3
        },
        {
          "observed_at": "2026-08-01T14:03:09Z",
          "window_start": "2026-08-01T13:01:10Z",
          "window_end": "2026-08-01T14:03:09Z",
          "status": "source-content",
          "summary": "The tracker moved from two episodes to three clusters by adding 13 addresses in block 960455, changed the destination set from four addresses to six, revised the same-block count for the last drained address from 250 to 237, and added an explanatory note about the two-scale timeline.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 4,
          "removed_lines": 3
        },
        {
          "observed_at": "2026-08-01T13:01:10Z",
          "window_start": "2026-08-01T05:28:59Z",
          "window_end": "2026-08-01T13:01:10Z",
          "status": "source-content",
          "summary": "The tracker added dashboard, address-list and methodology navigation, described its figures as verified minimums and a floor rather than totals, and changed its checkable address set from 2,321 to 2,334.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 11,
          "removed_lines": 6
        },
        {
          "observed_at": "2026-08-01T05:28:59Z",
          "window_start": "2026-08-01T02:34:03Z",
          "window_end": "2026-08-01T05:28:59Z",
          "status": "source-content",
          "summary": "The tracker expanded from the first 1,195-address episode to two episodes totalling 2,321 addresses and changed its headline from 1,082.5696 BTC to 1,128.4717 BTC.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 9,
          "removed_lines": 9
        }
      ]
    },
    {
      "id": "coldcard-hack-tracker",
      "title": "COLDCARD hack tracker",
      "url": "https://coldcard-hack-tracker.vercel.app/",
      "organisation": "community tracker",
      "kind": "chain-monitor",
      "role": "Chain monitor",
      "publication_time": null,
      "note": "Second, independent tracker of the same four holding addresses. States the\naccounting precision the reporting rounded: 1,082.65 BTC drained, 1,082.57 BTC\narrived, the difference paid to miners as fees. Cites Galaxy, Coinkite and Block.\nThe page is client-rendered. The empty shell from the first capture is preserved\nas a capture correction, followed by complete rendered captures.\n\nThe operator rebuilt the page on 2 August 2026 around a five-wave model, which\nrenamed the section heading this capture previously keyed on. The guard string\nmoved from that heading to \"Watched holdings\"; \"Holding 1\" and \"Movement feed\"\nare retained because they appear only after the client-side data resolves, so an\nunrendered shell still fails the check rather than entering the record.\n",
      "capture": {
        "status": "held",
        "copies": 30,
        "first_observed": "2026-08-01T02:34:16Z",
        "last_observed": "2026-08-02T00:59:59Z",
        "last_checked": "2026-08-02T00:59:59Z"
      },
      "differences": [
        {
          "observed_at": "2026-08-02T00:59:59Z",
          "window_start": "2026-08-02T00:31:24Z",
          "window_end": "2026-08-02T00:59:59Z",
          "status": "unreviewed",
          "summary": "This detected difference has not yet been reviewed for capture noise.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 1166,
          "removed_lines": 26
        },
        {
          "observed_at": "2026-08-02T00:31:24Z",
          "window_start": "2026-08-02T00:17:55Z",
          "window_end": "2026-08-02T00:31:24Z",
          "status": "unreviewed",
          "summary": "This detected difference has not yet been reviewed for capture noise.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 12,
          "removed_lines": 36
        },
        {
          "observed_at": "2026-08-02T00:17:55Z",
          "window_start": "2026-08-02T00:11:02Z",
          "window_end": "2026-08-02T00:17:55Z",
          "status": "unreviewed",
          "summary": "This detected difference has not yet been reviewed for capture noise.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 2,
          "removed_lines": 2
        },
        {
          "observed_at": "2026-08-02T00:11:02Z",
          "window_start": "2026-08-01T21:52:43Z",
          "window_end": "2026-08-02T00:11:02Z",
          "status": "source-content",
          "summary": "The operator rebuilt the tracker around a five-wave model: the July 31 entry split into Galaxy Wave 2 and a new Galaxy Wave 3 spanning Jul 31 to Aug 1, the headline total moved from 1,130.09411114 to 1,368.58411114 BTC, consolidated holdings from 1,130.00551671 to 1,160.19028 BTC, and the July 30 heading was renamed from Galaxy fingerprint to Galaxy Wave 1.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 56,
          "removed_lines": 30
        },
        {
          "observed_at": "2026-08-01T21:52:43Z",
          "window_start": "2026-08-01T21:21:08Z",
          "window_end": "2026-08-01T21:52:43Z",
          "status": "capture-noise",
          "summary": "Only the live fiat conversion changed; the BTC totals, cluster descriptions and movement state were unchanged.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 1,
          "removed_lines": 1
        },
        {
          "observed_at": "2026-08-01T21:21:08Z",
          "window_start": "2026-08-01T20:50:08Z",
          "window_end": "2026-08-01T21:21:08Z",
          "status": "source-content",
          "summary": "The evening-wave description gained a clause noting that the Kelbie vault also occurred on 31 July; the live fiat conversion changed in the same capture.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 2,
          "removed_lines": 2
        },
        {
          "observed_at": "2026-08-01T20:50:08Z",
          "window_start": "2026-08-01T20:18:43Z",
          "window_end": "2026-08-01T20:50:08Z",
          "status": "capture-noise",
          "summary": "Only the live fiat conversion changed; the BTC totals, cluster descriptions and movement state were unchanged.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 1,
          "removed_lines": 1
        },
        {
          "observed_at": "2026-08-01T20:18:43Z",
          "window_start": "2026-08-01T19:47:28Z",
          "window_end": "2026-08-01T20:18:43Z",
          "status": "capture-noise",
          "summary": "Only the live fiat conversion changed; the BTC totals, cluster descriptions and movement state were unchanged.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 1,
          "removed_lines": 1
        },
        {
          "observed_at": "2026-08-01T19:47:28Z",
          "window_start": "2026-08-01T19:16:23Z",
          "window_end": "2026-08-01T19:47:28Z",
          "status": "source-content",
          "summary": "The tracked total rose to 1,130.09411114 BTC after a delayed 0.19 BTC victim consolidation joined the Aug 1 hop vault. The tracker also recorded an Ocean block-960511 miner payout that touched the hop address and was peeled off, listing it as a possible lead that it does not count as stolen.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 14,
          "removed_lines": 10
        },
        {
          "observed_at": "2026-08-01T19:16:23Z",
          "window_start": "2026-08-01T18:45:24Z",
          "window_end": "2026-08-01T19:16:23Z",
          "status": "source-content",
          "summary": "The tracker added a 'TOTAL STOLEN' headline of 1,129.90257437 BTC with a four-wave breakdown chart, and raised the balance on watch to 1,130.00551671 BTC after a second UTXO reached the Aug 1 hop vault.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 37,
          "removed_lines": 5
        },
        {
          "observed_at": "2026-08-01T18:45:24Z",
          "window_start": "2026-08-01T17:43:06Z",
          "window_end": "2026-08-01T18:45:24Z",
          "status": "source-content",
          "summary": "The tracked total rose from 1,129.31416148 to 1,129.81397994 BTC, a separate 'Aug 1 hop vault' holding was added to the evening-wave cluster, the risk checklist gained Mk3 5.0.1 to 5.0.3, a seed-origin item and revised passphrase wording, and WizardSardine and Kevin Loaec were added as sources.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 27,
          "removed_lines": 11
        },
        {
          "observed_at": "2026-08-01T17:43:06Z",
          "window_start": "2026-08-01T17:12:32Z",
          "window_end": "2026-08-01T17:43:06Z",
          "status": "source-content",
          "summary": "The tracker restated its movement feed in terms of the reported consolidation only: the earlier outbound spend and unconfirmed hop were removed from the feed, last movement returned to 'Unmoved', and a note was added that later surplus passing through a vault is ignored while the reported balance remains.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 6,
          "removed_lines": 17
        },
        {
          "observed_at": "2026-08-01T17:12:32Z",
          "window_start": "2026-08-01T16:41:20Z",
          "window_end": "2026-08-01T17:12:32Z",
          "status": "source-content",
          "summary": "The tracker added an unconfirmed hop-1 movement of 0.4998206 BTC onward from the followed destination of the evening vault's first outbound spend.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 8,
          "removed_lines": 0
        },
        {
          "observed_at": "2026-08-01T16:41:20Z",
          "window_start": "2026-08-01T16:07:44Z",
          "window_end": "2026-08-01T16:41:20Z",
          "status": "source-content",
          "summary": "The tracker withdrew the Mk4 attribution for the 1 August morning wave, recording the seed as Mk3-origin, removed the 'Mk4 is in scope now' panel, and recorded the first outbound spend of 0.4099166 BTC from the evening vault at 16:33 UTC.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 12,
          "removed_lines": 11
        },
        {
          "observed_at": "2026-08-01T16:07:44Z",
          "window_start": "2026-08-01T15:36:39Z",
          "window_end": "2026-08-01T16:07:44Z",
          "status": "source-content",
          "summary": "The tracker's watched balance rose from 1,129.31416148 BTC to 1,129.6240794 BTC and the evening vault's displayed balance and UTXO count changed, while the reported consolidated figure for that vault stayed at 0.50980268 BTC.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 3,
          "removed_lines": 3
        },
        {
          "observed_at": "2026-08-01T15:36:39Z",
          "window_start": "2026-08-01T15:05:28Z",
          "window_end": "2026-08-01T15:36:39Z",
          "status": "source-content",
          "summary": "The tracker added an 'Aug 1 morning wave' cluster with a new vault address holding 0.33203236 BTC from 16 sweeps, described it as including a reported Mk4 RNG and duress-wallet honeypot attributed to Tomer Strolight while noting the device model is not visible on chain, added an 'Mk4 is in scope now' panel, and changed its headline to a running total.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 25,
          "removed_lines": 8
        },
        {
          "observed_at": "2026-08-01T15:05:28Z",
          "window_start": "2026-08-01T14:34:18Z",
          "window_end": "2026-08-01T15:05:28Z",
          "status": "source-content",
          "summary": "The tracker replaced its likely-exposed paragraph with a per-model vulnerable and fixed version table covering Mk3, Mk4, Mk5, Q and both Edge tracks, and moved the evening vault's block reference from the row label into the cluster description.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 11,
          "removed_lines": 3
        },
        {
          "observed_at": "2026-08-01T14:34:18Z",
          "window_start": "2026-08-01T14:03:11Z",
          "window_end": "2026-08-01T14:34:18Z",
          "status": "source-content",
          "summary": "The tracker rewrote its reader-guidance section against the August 1 advisory and Block's writeup, added a 'beyond the main seed' item covering paper-wallet keys, Seed XOR masks and Key Teleport, clone and Secure Notes material, moved the Galaxy scope figures into the cluster card, and replaced its short source labels with descriptive per-source summaries including CoinDesk and Clay Garrett. Holding 2's UTXO count also changed from one to two.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 33,
          "removed_lines": 15
        },
        {
          "observed_at": "2026-08-01T14:03:11Z",
          "window_start": "2026-08-01T13:01:13Z",
          "window_end": "2026-08-01T14:03:11Z",
          "status": "source-content",
          "summary": "The tracker added a third cluster, an 'Evening wave' of 31 July with its own 0.50980268 BTC vault attributed to Evan Schoenberg, restated every holding at full satoshi precision, and changed its headline from 1,128.56 BTC across two clusters to 1,129.06986038 BTC across three.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 29,
          "removed_lines": 15
        },
        {
          "observed_at": "2026-08-01T13:01:13Z",
          "window_start": "2026-08-01T10:26:29Z",
          "window_end": "2026-08-01T13:01:13Z",
          "status": "source-content",
          "summary": "The monitor changed Holding 1's displayed UTXO count from ten to eleven while its BTC balance and held status remained unchanged.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 1,
          "removed_lines": 1
        },
        {
          "observed_at": "2026-08-01T10:26:29Z",
          "window_start": "2026-08-01T09:53:15Z",
          "window_end": "2026-08-01T10:26:29Z",
          "status": "source-content",
          "summary": "The monitor changed Holding 1's displayed UTXO count from nine to ten while its BTC balance and held status remained unchanged.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 1,
          "removed_lines": 1
        },
        {
          "observed_at": "2026-08-01T09:53:15Z",
          "window_start": "2026-08-01T08:35:21Z",
          "window_end": "2026-08-01T09:53:15Z",
          "status": "source-content",
          "summary": "The monitor changed Holding 1's displayed UTXO count from eight to nine while its BTC balance and held status remained unchanged.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 1,
          "removed_lines": 1
        },
        {
          "observed_at": "2026-08-01T08:35:21Z",
          "window_start": "2026-08-01T08:18:05Z",
          "window_end": "2026-08-01T08:35:21Z",
          "status": "capture-correction",
          "summary": "The rendered capture again held the monitor's hydrated chain data after the preceding temporary loading-state capture.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 61,
          "removed_lines": 14
        },
        {
          "observed_at": "2026-08-01T08:18:05Z",
          "window_start": "2026-08-01T08:13:31Z",
          "window_end": "2026-08-01T08:18:05Z",
          "status": "capture-noise",
          "summary": "The rendered capture held the monitor's temporary loading state instead of its hydrated chain data.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 14,
          "removed_lines": 61
        },
        {
          "observed_at": "2026-08-01T08:13:31Z",
          "window_start": "2026-08-01T03:51:09Z",
          "window_end": "2026-08-01T08:13:31Z",
          "status": "source-content",
          "summary": "The monitor changed Holding 1's displayed UTXO count from seven to eight while its BTC balance and held status remained unchanged.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 1,
          "removed_lines": 1
        },
        {
          "observed_at": "2026-08-01T03:51:09Z",
          "window_start": "2026-08-01T03:22:57Z",
          "window_end": "2026-08-01T03:51:09Z",
          "status": "source-content",
          "summary": "The tracker added a separately attributed 45.91 BTC post-scan cluster and changed its headline total; live fiat figures also changed in the same capture.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 64,
          "removed_lines": 43
        },
        {
          "observed_at": "2026-08-01T03:22:57Z",
          "window_start": "2026-08-01T03:05:58Z",
          "window_end": "2026-08-01T03:22:57Z",
          "status": "capture-noise",
          "summary": "Only live fiat conversions changed; the BTC balances and movement state were unchanged.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 6,
          "removed_lines": 6
        },
        {
          "observed_at": "2026-08-01T03:05:58Z",
          "window_start": "2026-08-01T02:59:29Z",
          "window_end": "2026-08-01T03:05:58Z",
          "status": "capture-noise",
          "summary": "Only live fiat conversions changed; the BTC balances and movement state were unchanged.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 6,
          "removed_lines": 6
        },
        {
          "observed_at": "2026-08-01T02:59:29Z",
          "window_start": "2026-08-01T02:34:16Z",
          "window_end": "2026-08-01T02:59:29Z",
          "status": "capture-correction",
          "summary": "The browser capture obtained the rendered tracker after the initial scripted capture held an empty client-side shell.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 105,
          "removed_lines": 0
        }
      ]
    },
    {
      "id": "optech-416",
      "title": "Bitcoin Optech Newsletter #416",
      "url": "https://bitcoinops.org/en/newsletters/2026/07/31/",
      "organisation": "Bitcoin Optech",
      "kind": "analysis",
      "role": "Secondary analysis",
      "publication_time": "2026-07-31",
      "note": "Newsletter #416 led with the incident. It carries the unitemised estimate 'exceed 1,000 BTC' and dates the theft transactions to 29 July, possibly consistent with a US-local date; the newsletter does not state a timezone.",
      "capture": {
        "status": "held",
        "copies": 1,
        "first_observed": "2026-08-01T02:53:20Z",
        "last_observed": "2026-08-01T02:53:20Z",
        "last_checked": "2026-08-02T01:00:09Z"
      },
      "differences": []
    },
    {
      "id": "keychainx-reference",
      "title": "COLDCARD Mk3 entropy reference",
      "url": "https://keychainx.io/reference/coldcard-mk3-entropy/",
      "organisation": "KeychainX",
      "kind": "analysis",
      "role": "Secondary analysis",
      "publication_time": null,
      "note": "Reference write-up carrying 594.48 BTC (~US$38M) confirmed and 1,082.59 BTC if\nthe earlier set is linked. KeychainX is a wallet-recovery firm and says so on\nthe page; that commercial context applies to their framing, not to the figures,\nwhich restate Hamilton and Block.\n",
      "capture": {
        "status": "held",
        "copies": 1,
        "first_observed": "2026-08-01T02:53:21Z",
        "last_observed": "2026-08-01T02:53:21Z",
        "last_checked": "2026-08-02T01:00:11Z"
      },
      "differences": []
    },
    {
      "id": "coin360-drain",
      "title": "COLDCARD wallet drain report",
      "url": "https://coin360.com/news/coldcard-flaws-bitcoin-wallet-drain",
      "organisation": "Coin360",
      "kind": "reporting",
      "role": "Reporting",
      "publication_time": "2026-07-31",
      "note": "Carries a tabulated press estimate: 594.48 BTC / ~US$38.3M confirmed,\n488.11 BTC earlier under investigation, 1,082.59 BTC combined 'not fully\nconfirmed by Coinkite'. The article's own footer says it was 'refined and\nenhanced by ChatGPT'; provenance recorded, figures restate named sources.\n",
      "capture": {
        "status": "held",
        "copies": 4,
        "first_observed": "2026-08-01T02:53:23Z",
        "last_observed": "2026-08-02T00:09:05Z",
        "last_checked": "2026-08-02T01:00:15Z"
      },
      "differences": [
        {
          "observed_at": "2026-08-02T00:09:05Z",
          "window_start": "2026-08-01T16:10:12Z",
          "window_end": "2026-08-02T00:09:05Z",
          "status": "capture-noise",
          "summary": "A relative-age label the enabled normalizer did not match in its literal form; the article body is unchanged.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 1,
          "removed_lines": 1
        },
        {
          "observed_at": "2026-08-01T16:10:12Z",
          "window_start": "2026-08-01T03:51:25Z",
          "window_end": "2026-08-01T16:10:12Z",
          "status": "capture-noise",
          "summary": "Only the article's relative-time label changed, this time to the word 'yesterday', which the existing relative-time normalizer does not match. The article body was unchanged.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 1,
          "removed_lines": 1
        },
        {
          "observed_at": "2026-08-01T03:51:25Z",
          "window_start": "2026-08-01T02:53:23Z",
          "window_end": "2026-08-01T03:51:25Z",
          "status": "capture-noise",
          "summary": "Only the article's relative-time label changed from 15 hours to 16 hours.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 1,
          "removed_lines": 1
        }
      ]
    },
    {
      "id": "coldcard-docs-faq",
      "title": "COLDCARD entropy FAQ",
      "url": "https://coldcard.com/docs/faq/",
      "organisation": "Coinkite",
      "kind": "vendor-docs",
      "role": "Vendor documentation",
      "publication_time": null,
      "note": "The pre-incident entropy description: hardware TRNG from transistor noise, a\nPRNG XOR'd into it, SE1/SE2 boot seeding, SHA-256 whitening, and the line that\ndice add \"to the 256 bits of entropy already picked\". Quoted on\n/how-it-broke/promised/ to compare stated design against what shipped. It is\nmonitored closely because it describes the affected subsystem. The first\ncapture is post-disclosure and does not establish the page's earlier wording.\n",
      "capture": {
        "status": "held",
        "copies": 2,
        "first_observed": "2026-08-01T03:51:29Z",
        "last_observed": "2026-08-01T07:01:04Z",
        "last_checked": "2026-08-02T01:00:19Z"
      },
      "differences": [
        {
          "observed_at": "2026-08-01T07:01:04Z",
          "window_start": "2026-08-01T03:51:29Z",
          "window_end": "2026-08-01T07:01:04Z",
          "status": "capture-noise",
          "summary": "Only the FAQ footer's Last update date changed from July 31 to August 1; no extracted FAQ answer changed.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 1,
          "removed_lines": 1
        }
      ]
    },
    {
      "id": "wizardsardine-postmortem",
      "title": "Wizardsardine post-mortem and user guidance",
      "url": "https://wizardsardine.com/blog/coldcard-rng-vulnerability/",
      "organisation": "Wizardsardine",
      "kind": "independent-analysis",
      "role": "Independent primary analysis",
      "publication_time": "2026-08-01",
      "note": "Long-form post-mortem by the Liana wallet vendor: section 1 addresses Liana\nusers and descriptor game theory, the rest reconstructs the flaw and argues\nthat imported and dice-generated seeds remain exposed through derived-material\nfeatures. Wizardsardine sells competing wallet software, and the post was\nself-described as written quickly under stress with corrections invited; its\nfeature-exposure claims are the author's analysis until checked against source.\n",
      "capture": {
        "status": "held",
        "copies": 2,
        "first_observed": "2026-08-01T17:17:15Z",
        "last_observed": "2026-08-01T19:47:20Z",
        "last_checked": "2026-08-02T01:00:21Z"
      },
      "differences": [
        {
          "observed_at": "2026-08-01T19:47:20Z",
          "window_start": "2026-08-01T17:17:15Z",
          "window_end": "2026-08-01T19:47:20Z",
          "status": "source-content",
          "summary": "Wizardsardine added explicit Section 3 and Section 4 labels to two previously unlabelled headings and renumbered the two that followed from 3 and 4 to 5 and 6. In the same edit the TAPSIGNER, OPENDIME and SATSCARD paragraph changed from a flat statement that they are not affected to Coinkite's claim plus the qualification that their proprietary code prevents the authors stating with certainty that the devices are safe, while noting the architecture is not a MicroPython stack.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 5,
          "removed_lines": 5
        }
      ]
    },
    {
      "id": "btcpp-dettmer-commit-history",
      "title": "Dettmer commit-history analysis of the entropy bug",
      "url": "https://insider.btcpp.dev/p/when-randombytes-runs-but-doesnt",
      "organisation": "bitcoin++ Insider Edition",
      "kind": "independent-analysis",
      "role": "Independent primary analysis",
      "publication_time": "2026-08-01",
      "note": "Dustin Dettmer's walkthrough of the COLDCARD firmware commit history tracing\nhow the predictable generator path was introduced. Published on the bitcoin++\nInsider Edition substack; its commit-level claims are checkable against the\npinned repository clones held by this archive.\n",
      "capture": {
        "status": "held",
        "copies": 2,
        "first_observed": "2026-08-01T17:17:17Z",
        "last_observed": "2026-08-01T22:25:14Z",
        "last_checked": "2026-08-02T01:00:24Z"
      },
      "differences": [
        {
          "observed_at": "2026-08-01T22:25:14Z",
          "window_start": "2026-08-01T17:17:17Z",
          "window_end": "2026-08-01T22:25:14Z",
          "status": "source-content",
          "summary": "A reader comment from Frank Corva was added to the post's discussion, posted after the preceding capture rather than progressively rendered from it. Substack like and restack counters changed in the same capture. The guest post's own text was unchanged.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 9,
          "removed_lines": 0
        }
      ]
    },
    {
      "id": "dk27ss-poc-readme",
      "title": "End-to-end reproduction of the affected generator",
      "url": "https://raw.githubusercontent.com/DK27ss/ColdCard-38M-PoC/main/README.md",
      "organisation": "DK27ss",
      "kind": "independent-analysis",
      "role": "Independent primary analysis",
      "publication_time": "2026-08-01",
      "note": "Reimplements the MicroPython fallback and the libngu mixer, generates a\nsynthetic victim wallet through the affected path, then recovers its mnemonic by\nsearching the timer and skip space. The victim is fabricated by the repository's\nown script, so the demonstration never requires anyone's recovery material and\nruns offline. Author is anonymous and the repository states no licence; the\nclaims are checkable because the scripts and their target file are published.\n",
      "capture": {
        "status": "held",
        "copies": 1,
        "first_observed": "2026-08-02T00:26:40Z",
        "last_observed": "2026-08-02T00:26:40Z",
        "last_checked": "2026-08-02T01:00:26Z"
      },
      "differences": []
    },
    {
      "id": "samsamskies-tracker-readme",
      "title": "Source of the community holdings tracker",
      "url": "https://raw.githubusercontent.com/SamSamskies/coldcard-hack-tracker/main/README.md",
      "organisation": "SamSamskies",
      "kind": "chain-monitor",
      "role": "Chain monitor",
      "publication_time": "2026-07-31",
      "note": "The published source behind the tracker dashboard this archive already captures,\nwhich makes the deployed page auditable rather than opaque. Watches public\naddresses through public block-explorer APIs and takes no wallet material from\nthe reader. MIT licensed with a test suite; its watch set is hardcoded from\npublic reports rather than derived independently.\n",
      "capture": {
        "status": "held",
        "copies": 2,
        "first_observed": "2026-08-02T00:26:40Z",
        "last_observed": "2026-08-02T01:00:28Z",
        "last_checked": "2026-08-02T01:00:28Z"
      },
      "differences": [
        {
          "observed_at": "2026-08-02T01:00:28Z",
          "window_start": "2026-08-02T00:26:40Z",
          "window_end": "2026-08-02T01:00:28Z",
          "status": "unreviewed",
          "summary": "This detected difference has not yet been reviewed for capture noise.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 10,
          "removed_lines": 4
        }
      ]
    },
    {
      "id": "nobuxpt-entropy-test-readme",
      "title": "Collision demonstration and firmware guard scanner",
      "url": "https://raw.githubusercontent.com/nobuxpt/coldcard-entropy-test/master/README.md",
      "organisation": "nobuxpt",
      "kind": "independent-analysis",
      "role": "Independent primary analysis",
      "publication_time": "2026-08-01",
      "note": "Two offline tools: a collision simulation over the reduced search space, and a\nstatic scanner that flags the defined-ness guard in a firmware source tree. The\nscanner reads source directories rather than wallets, and neither tool accepts a\nseed or extended key. ISC licensed, with reference commits cited for the\nreimplemented generator.\n",
      "capture": {
        "status": "held",
        "copies": 1,
        "first_observed": "2026-08-02T00:26:41Z",
        "last_observed": "2026-08-02T00:26:41Z",
        "last_checked": "2026-08-02T01:00:29Z"
      },
      "differences": []
    },
    {
      "id": "coinkite-paper-spam",
      "title": "Coinkite's pre-incident paper-spam warning",
      "url": "https://blog.coinkite.com/paper-spam/",
      "organisation": "Coinkite",
      "kind": "vendor-statement",
      "role": "Vendor statement",
      "publication_time": "2026-06-24",
      "note": "Published five weeks before this incident, about a physical-mail campaign using\na post-quantum firmware-upgrade pretext. States that Coinkite would never send a\npaper letter, that the mail is a scam, and that customer physical addresses are\ndeleted after 120 days, which Coinkite attributes the targeting data to leaks\nelsewhere rather than a breach of its own. Held for two reasons: it establishes\nan impersonation playbook that predates the entropy disclosure and could be\nrecycled against it, and it shows the vendor publishing exactly the kind of scam\nguidance that has not accompanied the entropy advisory.\n",
      "capture": {
        "status": "held",
        "copies": 1,
        "first_observed": "2026-08-02T00:40:53Z",
        "last_observed": "2026-08-02T00:40:53Z",
        "last_checked": "2026-08-02T01:00:31Z"
      },
      "differences": []
    }
  ],
  "social_posts": [
    {
      "id": "nvk-apology",
      "title": "Full accountability statement",
      "url": "https://x.com/nvk/status/2083216713693151552",
      "author": "nvk",
      "organisation": "Coinkite",
      "posted": "2026-07-31T15:42:23Z",
      "role": "social-statement",
      "why_registered": "Vendor apology, hotfix summary, postmortem commitment and support offered to affected users.",
      "capture": {
        "status": "held",
        "artefacts": [
          {
            "name": "nvk-apology-2083216713693151552.png",
            "format": "PNG",
            "bytes": 749714,
            "sha256": "0148fb4a03a1f73f0ed78dd19981d293aaa32beaf991f6f95affe84e0a1926c2"
          },
          {
            "name": "nvk-apology-2083216713693151552.txt",
            "format": "TXT",
            "bytes": 3147,
            "sha256": "8df6f6a16a9f8837948adb53b2ff2f27e7c21546624af1c0250ea7702b7f086b"
          },
          {
            "name": "2083216713693151552_1.jpg",
            "format": "JPG",
            "bytes": 5109,
            "sha256": "fe6efdb081f32a4112414253d23c19c5e89cca5d1b2f595cab98189758a67488"
          },
          {
            "name": "2083216713693151552_1.jpg.json",
            "format": "JSON",
            "bytes": 2292,
            "sha256": "6152503e8f9a80810ea9ac501921a1bf8244d422e0a67ff1183c2798c90524f9"
          }
        ]
      }
    },
    {
      "id": "trustwallet-wasm-update",
      "title": "Browser-extension WASM vulnerability thread",
      "url": "https://x.com/TrustWallet/status/1649699428733947906",
      "author": "TrustWallet",
      "organisation": "Trust Wallet",
      "posted": "2023-04-22T08:59:28Z",
      "role": "historical-precedent",
      "why_registered": "Trust Wallet's primary incident thread states the affected browser-extension creation window, that the issue was fixed, and that affected users should follow its remediation guidance. The held capture covers the first post of the ten-post thread.",
      "capture": {
        "status": "held",
        "artefacts": [
          {
            "name": "trustwallet-wasm-update-1649699428733947906.png",
            "format": "PNG",
            "bytes": 105223,
            "sha256": "5dcd08a7c78262e49c2e14243217de5953c079c3cd4eedbee6b9c3e9e57d7eec"
          },
          {
            "name": "trustwallet-wasm-update-1649699428733947906.txt",
            "format": "TXT",
            "bytes": 675,
            "sha256": "af65e4612dc640d74ea27818645e43bd7a1f0af16e1d014139b003de8908999d"
          }
        ]
      }
    },
    {
      "id": "llfourn-model",
      "title": "Initial attack-cost model",
      "url": "https://x.com/LLFOURN/status/2082990000896147942",
      "author": "LLFOURN",
      "organisation": null,
      "posted": "2026-07-31T00:41:30Z",
      "role": "social-statement",
      "why_registered": "LLFOURN's stated attack-cost model: approximately 2^40.3 for Mk3 and 2^72.3 for Mk4-class devices under its listed UID, timing and interaction assumptions.",
      "capture": {
        "status": "held",
        "artefacts": [
          {
            "name": "llfourn-model-2082990000896147942.png",
            "format": "PNG",
            "bytes": 249125,
            "sha256": "ee03062acae5f181253de53a29a5f7b60e330bf399dd07f5fd4317b0205d773a"
          },
          {
            "name": "llfourn-model-2082990000896147942.txt",
            "format": "TXT",
            "bytes": 1162,
            "sha256": "70c9c282845b089a771d0d503485341eff40f7872e1a625f0f2372608e68816a"
          },
          {
            "name": "2082990000896147942_1.png",
            "format": "PNG",
            "bytes": 33506,
            "sha256": "13db23547ec4e481d6367847d0ec2a44a5115e77c78e35edc6bade49ffd96545"
          },
          {
            "name": "2082990000896147942_1.png.json",
            "format": "JSON",
            "bytes": 2731,
            "sha256": "4819859f00c1372d7b50b9277366212c3d8c498e76e5fd84103c027d4467bfbf"
          }
        ]
      }
    },
    {
      "id": "llfourn-followup",
      "title": "Attack-cost follow-up",
      "url": "https://x.com/LLFOURN/status/2083296357662765399",
      "author": "LLFOURN",
      "organisation": null,
      "posted": "2026-07-31T20:58:52Z",
      "role": "social-statement",
      "why_registered": "LLFOURN's follow-up lowering the Mk4-class estimate by 10 to 14 bits, giving approximately 2^58.3 to 2^62.3 under the revised assumptions.",
      "capture": {
        "status": "held",
        "artefacts": [
          {
            "name": "llfourn-followup-2083296357662765399.png",
            "format": "PNG",
            "bytes": 256955,
            "sha256": "52336074ff3ae1043ce9a6ec0ce922c81ab5813bf3ebb117cf923e56c71cafb3"
          },
          {
            "name": "llfourn-followup-2083296357662765399.txt",
            "format": "TXT",
            "bytes": 624,
            "sha256": "5640a0da62fe1fea85596006b81d04487a08bd872b5bc00f08d37b0eb43062ae"
          }
        ]
      }
    },
    {
      "id": "kloaec-multisig",
      "title": "Multisig threshold warning",
      "url": "https://x.com/KLoaec/status/2083301216050700780",
      "author": "KLoaec",
      "organisation": null,
      "posted": "2026-07-31T21:18:10Z",
      "role": "social-statement",
      "why_registered": "Dated guidance on configurations where affected COLDCARD keys meet a multisig or miniscript threshold, with qualified Taproot and private-submission advice.",
      "capture": {
        "status": "held",
        "artefacts": [
          {
            "name": "kloaec-multisig-2083301216050700780.png",
            "format": "PNG",
            "bytes": 252687,
            "sha256": "4c1ff75b4b5168954d3a6630c3103595afa3d299c58a9c7a039bcf92d75aa68a"
          },
          {
            "name": "kloaec-multisig-2083301216050700780.txt",
            "format": "TXT",
            "bytes": 1179,
            "sha256": "7a41b8adef7fccf1e93d6f4e037521052c0214aa873a9da6e5711c4e60dabe22"
          }
        ]
      }
    },
    {
      "id": "clay-attribution",
      "title": "Operator attribution report",
      "url": "https://x.com/clay_garrett/status/2083247006139503065",
      "author": "clay_garrett",
      "organisation": "Block",
      "posted": "2026-07-31T17:42:45Z",
      "role": "social-statement",
      "why_registered": "Block's report that the operator used a paid blockchain-services account; the complete thread says the provider's logs matched the workflow and that Block saw no evidence of knowing participation.",
      "capture": {
        "status": "held",
        "artefacts": [
          {
            "name": "clay-attribution-thread-2083247006139503065.png",
            "format": "PNG",
            "bytes": 261887,
            "sha256": "8f093e8d98be25e292f944f10a503309dba3f894ca398f723a51447b3ce384cc"
          },
          {
            "name": "clay-attribution-thread-2083247006139503065.txt",
            "format": "TXT",
            "bytes": 1681,
            "sha256": "1b16919b6659c4f64d5f7df97f212153ac51eecc5bb2b958137ff34763ea0d60"
          },
          {
            "name": "clay-attribution-thread-2083247007808774228.jpg",
            "format": "JPG",
            "bytes": 218214,
            "sha256": "1a6989495351635678569df49c229dac5a4ee549d0f1e59c849c14207ddd7d85"
          }
        ]
      }
    },
    {
      "id": "clay-earlier-waves-thread",
      "title": "Earlier-wave accounting thread",
      "url": "https://x.com/clay_garrett/status/2082980439367487724",
      "author": "clay_garrett",
      "organisation": "Block",
      "posted": "2026-07-31T00:03:31Z",
      "role": "on-chain-analysis",
      "why_registered": "Block's seven-post preliminary accounting thread for the reported 695 earlier transactions, including the two block-level counts, amounts, scan method and explicit warning that the common-incident attribution was not confirmed.",
      "capture": {
        "status": "held",
        "artefacts": [
          {
            "name": "clay-earlier-waves-thread-2082980439367487724-20260801T065902Z-part-1.jpg",
            "format": "JPG",
            "bytes": 27316,
            "sha256": "8d7eeefe4fe1a4aef3a5eb6c1c35a23b69a964aca40c7e09de7122536d6bddf6"
          },
          {
            "name": "clay-earlier-waves-thread-2082980439367487724-20260801T065902Z-part-2.jpg",
            "format": "JPG",
            "bytes": 21838,
            "sha256": "86f328b77b2363034a48f350acad0592ed18151d688359dfcd185dfe88f993a8"
          },
          {
            "name": "clay-earlier-waves-thread-2082980439367487724-20260801T065902Z-part-3.jpg",
            "format": "JPG",
            "bytes": 101551,
            "sha256": "dfdb326d6cfde33360b99b5d60d84038db3ef942ae3ddb7b518c59ec78c5203c"
          },
          {
            "name": "clay-earlier-waves-thread-2082980439367487724-20260801T065902Z-part-4.jpg",
            "format": "JPG",
            "bytes": 54054,
            "sha256": "217e8c0495c802d5e283149fd9eba336c1b544257a176ae4914abb2088bbdab7"
          },
          {
            "name": "clay-earlier-waves-thread-2082980439367487724-20260801T065902Z-part-5.jpg",
            "format": "JPG",
            "bytes": 104184,
            "sha256": "dfaec4d1fe61cf0ad119741d301a2fd944e664f2a987caad1a0c819577977977"
          },
          {
            "name": "clay-earlier-waves-thread-2082980439367487724-20260801T065902Z-part-6.jpg",
            "format": "JPG",
            "bytes": 61205,
            "sha256": "54ecfac296904459c6c156d5c8c4aedb4c8100e1d897263af0ecac7a4b628cd3"
          },
          {
            "name": "clay-earlier-waves-thread-2082980439367487724-20260801T065902Z-part-7.jpg",
            "format": "JPG",
            "bytes": 16395,
            "sha256": "33d5f28367b956d5bab818878e39f84eb3f2c863d71c4299201b0c5c2cd1aafe"
          },
          {
            "name": "clay-earlier-waves-thread-2082980439367487724-20260801T065902Z.txt",
            "format": "TXT",
            "bytes": 3159,
            "sha256": "591a5ed83a365b8f48531a9415b331cc393818ffb33f8f96efe6fcb96156781b"
          }
        ]
      }
    },
    {
      "id": "unchained-guidance",
      "title": "Unchained client guidance",
      "url": "https://x.com/unchained/status/2083036112449163618",
      "author": "unchained",
      "organisation": "Unchained",
      "posted": "2026-07-31T03:44:44Z",
      "role": "social-statement",
      "why_registered": "Unchained's client guidance to rotate COLDCARD-generated keys, with specific treatment of one versus two affected keys in a 2-of-3 vault.",
      "capture": {
        "status": "held",
        "artefacts": [
          {
            "name": "unchained-guidance-2083036112449163618.png",
            "format": "PNG",
            "bytes": 287276,
            "sha256": "abcf384d8b57f49df83236eb21d4ce767c02ad2fa898d3155317aea0d975c6b6"
          },
          {
            "name": "unchained-guidance-2083036112449163618.txt",
            "format": "TXT",
            "bytes": 1247,
            "sha256": "7aad3ef55c56e1524b646e95c44f622924a7e38d4b77f61fc8b4197ca16f2b5f"
          }
        ]
      }
    },
    {
      "id": "otaliptus-technical",
      "title": "Tentative Mk4 entropy model",
      "url": "https://x.com/otaliptus/status/2083365327740543404",
      "author": "otaliptus",
      "organisation": null,
      "posted": "2026-08-01T01:32:55Z",
      "role": "independent-analysis",
      "why_registered": "A deliberately tentative independent Mk4 model. Assuming a remote attacker does\nnot know the UID, otaliptus estimates about 20 to 21 bits from the wafer-coordinate\nword, narrows practical SysTick positions, and isolates the unresolved RTC term.\nThe post reports roughly 52 to 63 bits if Mk4 RTC behaviour is problematic and\nroughly 75 to 88 bits if it is not. The author labels this brainstorming and lists\nassumptions that may be wrong, so it is preserved as reported analysis rather than\na measured bound.\n",
      "capture": {
        "status": "held",
        "artefacts": [
          {
            "name": "otaliptus-technical-2083365327740543404-part1.png",
            "format": "PNG",
            "bytes": 402095,
            "sha256": "18e56c5fa508da0eafabc67e8f67682d59876d2ccc1a19f1e40b4ff88e5ea885"
          },
          {
            "name": "otaliptus-technical-2083365327740543404.png",
            "format": "PNG",
            "bytes": 702836,
            "sha256": "cf80ab2f4ba272191f7923b7184cc7ae757d95f9f74d45ab3f1ff308f1432d93"
          },
          {
            "name": "otaliptus-technical-2083365327740543404.txt",
            "format": "TXT",
            "bytes": 3126,
            "sha256": "d3a3a04cfa51c6a6f3af6ac52d5953ac42b4e968f9a3ef4d8086c968e9e9a989"
          }
        ]
      }
    },
    {
      "id": "benowhere-multisig-race",
      "title": "Multisig migration race",
      "url": "https://x.com/BEN0WHERE/status/2083351351980109950",
      "author": "BEN0WHERE",
      "organisation": null,
      "posted": "2026-08-01T00:37Z",
      "role": "migration-guidance",
      "why_registered": "Part of the Slipstream advice chain. Reply to \"why do multisig holders need\nSlipstream?\", explaining the mechanism: a thief holding some keys of a multisig\nmay still lack the wallet setup data, but the owner's own broadcast reveals\nenough of it to let the thief build a competing transaction; private miner\nsubmission avoids that race. Author's profile: Product Lead at Bitkey (Block's\nwallet), which bears on the conflict disclosure already on the Slipstream page.\n",
      "capture": {
        "status": "held",
        "artefacts": [
          {
            "name": "benowhere-multisig-slipstream-2083351351980109950.png",
            "format": "PNG",
            "bytes": 263172,
            "sha256": "27de6c61e846573b601eb6eeec00898353db08dd4067b31299c263a159b8dc9e"
          },
          {
            "name": "benowhere-multisig-slipstream-2083351351980109950.txt",
            "format": "TXT",
            "bytes": 795,
            "sha256": "c4edb0047b097769e74c8e13b7319fd7e1ecb2444c7574eaea73d3f6993ef511"
          }
        ]
      }
    },
    {
      "id": "glxyresearch-flow-map",
      "title": "Galaxy flow-of-funds map",
      "url": "https://x.com/glxyresearch/status/2083181683067506899",
      "author": "glxyresearch",
      "organisation": "Galaxy Research",
      "posted": "2026-07-31T13:23:11Z",
      "role": "social-statement",
      "why_registered": "Galaxy's own flow-of-funds post, the primary source behind the 1,082.65 BTC /\n1,196-address figure quoted by The Block. Adds what the reporting dropped: the\n30.0 sat/vB hardcoded fee signature with no change outputs, the BIP-84/49/44\nderivation mix, blocks 960,183-960,191, and the four consolidation addresses\nwith per-address balances (562.02 + 398.48 + 89.62 + 32.45 BTC).\nThe first rendered screenshot was taken before the attached chart hydrated. The\ntimestamped 07:49:51 UTC recapture includes the complete post and flow map.\n",
      "capture": {
        "status": "held",
        "artefacts": [
          {
            "name": "glxyresearch-flow-of-funds-2083181683067506899-20260801T074951Z.png",
            "format": "PNG",
            "bytes": 539462,
            "sha256": "a051ea303fb06451fed2d62bfe310da52b4f55efc42c7faa9ece1f69d4ab9278"
          },
          {
            "name": "glxyresearch-flow-of-funds-2083181683067506899-20260801T074951Z.txt",
            "format": "TXT",
            "bytes": 1318,
            "sha256": "9476b43669fd18805f9cb6548bcb46f21676634c4d8c56dc80c5793f817e614a"
          },
          {
            "name": "glxyresearch-flow-of-funds-2083181683067506899-20260801T075359Z-correction.txt",
            "format": "TXT",
            "bytes": 344,
            "sha256": "2f90ea965069497151c5655f4f7a23c56b0ac50a87b4ddd92f4eabcf007981a4"
          },
          {
            "name": "glxyresearch-flow-of-funds-2083181683067506899.png",
            "format": "PNG",
            "bytes": 568679,
            "sha256": "5182f6af8e20042f375b377a45216ad26865bf9fe754cce4ea84d9ad613c9f85"
          },
          {
            "name": "glxyresearch-flow-of-funds-2083181683067506899.txt",
            "format": "TXT",
            "bytes": 1281,
            "sha256": "fcd1654492be494f9275b1c42b61386b8d3ceede7e7d8388710e820cf99d5b7a"
          }
        ]
      }
    },
    {
      "id": "kevinkelbie-later-wave",
      "title": "Later 45.9 BTC wave",
      "url": "https://x.com/KevinKelbie/status/2083368025864990857",
      "author": "KevinKelbie",
      "organisation": null,
      "posted": "2026-08-01T01:43:39Z",
      "role": "on-chain-analysis",
      "why_registered": "Reports a later 31 July cluster of 1,216 transactions and 45.9 BTC, outside\nBlock's published scan window. The post says seven of Block's eight markers\nmatch while replace-by-fee behaviour differs. Captured as a reported lead, not\ntreated as verified until the underlying transaction set is independently\nchecked.\n",
      "capture": {
        "status": "held",
        "artefacts": [
          {
            "name": "kevinkelbie-later-wave-2083368025864990857.png",
            "format": "PNG",
            "bytes": 233959,
            "sha256": "241feab1e9b2d74be59a993ce3427c9610840eea5af43e66e33a796df7cd3b27"
          },
          {
            "name": "kevinkelbie-later-wave-2083368025864990857.txt",
            "format": "TXT",
            "bytes": 803,
            "sha256": "2fbc5d25fcabb164bc9d5a71ab6e3ed9b8fe8439b1d2759c30031069c410abe1"
          }
        ]
      }
    },
    {
      "id": "robhamilton-preliminary-sweep",
      "title": "Preliminary sweep accounting",
      "url": "https://x.com/Rob1Ham/status/2082896614218203616",
      "author": "Rob1Ham",
      "organisation": "AnchorWatch",
      "posted": "2026-07-30T18:30:25Z",
      "role": "on-chain-analysis",
      "why_registered": "Primary source for Hamilton's preliminary accounting: 1,324 UTXOs, 500\ntransactions, a three-block window, 594.48 BTC, and a later 562 BTC\nconsolidation. The post itself says the activity occurred over 15 minutes and\nlabels the analysis preliminary.\n",
      "capture": {
        "status": "held",
        "artefacts": [
          {
            "name": "robhamilton-preliminary-sweep-2082896614218203616.png",
            "format": "PNG",
            "bytes": 204875,
            "sha256": "7b991fd6df5ae07e4e4873993d4d5a604ffea485dadd88f0bf24bd6bbfab1be8"
          },
          {
            "name": "robhamilton-preliminary-sweep-2082896614218203616.txt",
            "format": "TXT",
            "bytes": 922,
            "sha256": "4f4d139f16540874f0942a2bd9fcdedcdc13961a25d33d39105d3ca833b047c5"
          }
        ]
      }
    },
    {
      "id": "llfourn-2083312169316499663",
      "title": "Pessimistic Mk4 scenario",
      "url": "https://x.com/LLFOURN/status/2083312169316499663",
      "author": "LLFOURN",
      "organisation": null,
      "posted": "2026-07-31T22:01:41Z",
      "role": "independent-analysis",
      "why_registered": "Reports a pessimistic Mk4 scenario of 32 bits of work per target if the UID is\nknown and the button-press count and clock behaviour are more predictable. This\nis an attributed attack model, not a measurement of shipped devices.\n",
      "capture": {
        "status": "held",
        "artefacts": [
          {
            "name": "llfourn-2083312169316499663-2083312169316499663-20260801T045718Z.png",
            "format": "PNG",
            "bytes": 95551,
            "sha256": "c26b5a1101aa4b2003fed7d7a52a920c0b4a0a3281643dd10f9b5110d296ae02"
          },
          {
            "name": "llfourn-2083312169316499663-2083312169316499663-20260801T045718Z.txt",
            "format": "TXT",
            "bytes": 670,
            "sha256": "4fc973ee1b93f304e17b62f7f81dbc8bdcf5d2fe4e46b37ffb80387a32bbc7e2"
          },
          {
            "name": "llfourn-2083312169316499663-2083312169316499663.png",
            "format": "PNG",
            "bytes": 254339,
            "sha256": "83959877ea5d492229c01a600fb78e7d11ca5b56837b60db2a02c33389a9e3b8"
          },
          {
            "name": "llfourn-2083312169316499663-2083312169316499663.txt",
            "format": "TXT",
            "bytes": 670,
            "sha256": "b4c54639e40ea03baa2071f19f715a0bc0795afaeb8d7e0670547e192ac1cb48"
          }
        ]
      }
    },
    {
      "id": "llfourn-2083375420721025313",
      "title": "Time-stamped migration risk",
      "url": "https://x.com/LLFOURN/status/2083375420721025313",
      "author": "LLFOURN",
      "organisation": null,
      "posted": "2026-08-01T02:13:02Z",
      "role": "migration-guidance",
      "why_registered": "A time-stamped risk assessment rather than a durable guarantee: LLFOURN reports\nlittle immediate risk in moving Mk4 multisig on 1 Aug, warns that could change\nwithin days, and describes Unchained's one-size process as sensible for a KYC\nprovider that knows its customer base.\n",
      "capture": {
        "status": "held",
        "artefacts": [
          {
            "name": "llfourn-2083375420721025313-2083375420721025313-20260801T045812Z.png",
            "format": "PNG",
            "bytes": 146171,
            "sha256": "15f0c78ac730d23a3e7cf282ef7a9ea600d46c011fea82295f07fcddb999e138"
          },
          {
            "name": "llfourn-2083375420721025313-2083375420721025313-20260801T045812Z.txt",
            "format": "TXT",
            "bytes": 935,
            "sha256": "6449a69a2ca1d5ecef6e793702b2059e899d84bced1cc8a8c7dcec3b9e21d066"
          },
          {
            "name": "llfourn-2083375420721025313-2083375420721025313.png",
            "format": "PNG",
            "bytes": 254007,
            "sha256": "ebe051d59089c118927786a93f0db00b02985df1c283d1192cf5d96022bf46f4"
          },
          {
            "name": "llfourn-2083375420721025313-2083375420721025313.txt",
            "format": "TXT",
            "bytes": 935,
            "sha256": "6a6e4037933cf6cb56b4e43ffa7567a4ffe6ea4f180e6c11bc51987cdedb0f5e"
          }
        ]
      }
    },
    {
      "id": "llfourn-2083298061250666721",
      "title": "Correction to multisig guidance",
      "url": "https://x.com/LLFOURN/status/2083298061250666721",
      "author": "LLFOURN",
      "organisation": null,
      "posted": "2026-07-31T21:05:38Z",
      "role": "migration-guidance",
      "why_registered": "An explicit correction of LLFOURN's earlier multisig guidance: Mk4, Mk5 and Q\nsetups in which affected devices meet the signing threshold, without a mitigating\nfactor such as dice rolls, need to move.\n",
      "capture": {
        "status": "held",
        "artefacts": [
          {
            "name": "llfourn-2083298061250666721-2083298061250666721.png",
            "format": "PNG",
            "bytes": 154022,
            "sha256": "426ccc08246fa68e5f9273f9f6ecbc0799b77409be423436efbcee7336e5a6e7"
          },
          {
            "name": "llfourn-2083298061250666721-2083298061250666721.txt",
            "format": "TXT",
            "bytes": 536,
            "sha256": "094ab5f90589fe2c39c6738675942d4296918021ad57991f82fe1d1a62e8d0e9"
          }
        ]
      }
    },
    {
      "id": "darosior-emergency-guidance",
      "title": "Emergency migration guidance",
      "url": "https://x.com/darosior/status/2083228876558290979",
      "author": "darosior",
      "organisation": null,
      "posted": "2026-07-31T16:30:43Z",
      "role": "migration-guidance",
      "why_registered": "Antoine Poinsot's high-urgency public warning covering Mk3, Mk4, Mk5 and Q,\nwith a 50-roll pure-dice exception. The scope and urgency are attributed\nguidance; the post does not itself provide evidence that every named model was\nalready being drained.\n",
      "capture": {
        "status": "held",
        "artefacts": [
          {
            "name": "darosior-2083228876558290979-2083228876558290979.png",
            "format": "PNG",
            "bytes": 113986,
            "sha256": "c6ba6649cec3048844a122c0b3d14f7281d7129f2a420c89592da6dcb2f7686f"
          },
          {
            "name": "darosior-2083228876558290979-2083228876558290979.txt",
            "format": "TXT",
            "bytes": 647,
            "sha256": "95b079d5997e9c6f8ca63150817ff769637782cbb76048c5f9b864448c717bba"
          }
        ]
      }
    },
    {
      "id": "instagibbs-reproduction",
      "title": "Independent hardware reproduction",
      "url": "https://x.com/theinstagibbs/status/2082958675975553224",
      "author": "theinstagibbs",
      "organisation": null,
      "posted": "2026-07-30T22:37:02Z",
      "role": "independent-reproduction",
      "why_registered": "Gregory Sanders's concise public result from an independent hardware\nreproduction: Mk2/Mk3 confirmed, with Mk4 explicitly left uncertain. The owned\ndevice inputs and unpublished scripts limit what this establishes about a blind\nremote search.\n",
      "capture": {
        "status": "held",
        "artefacts": [
          {
            "name": "instagibbs-2082958675975553224-2082958675975553224.png",
            "format": "PNG",
            "bytes": 55263,
            "sha256": "a9152676085d55b59aadae0ccdb0734d8da198f619d492f5e1f0b88cafc4c71f"
          },
          {
            "name": "instagibbs-2082958675975553224-2082958675975553224.txt",
            "format": "TXT",
            "bytes": 409,
            "sha256": "fac8fb66880645d74d131841637b2607dd10242959bf148617d82b3cdfae5695"
          },
          {
            "name": "instagibbs-reproduction-followup-2083188153318256742.png",
            "format": "PNG",
            "bytes": 109752,
            "sha256": "f9a700b303d68d27edb7a004b0af5e13641cd97c0fbc1885785a7f893cfcc232"
          },
          {
            "name": "instagibbs-reproduction-followup-2083188153318256742.txt",
            "format": "TXT",
            "bytes": 534,
            "sha256": "842dc8314a246d3d54204a0081719390629f8c6bb0c3ed5502fa24b6e10e2564"
          }
        ]
      }
    },
    {
      "id": "kloaec-early-hypothesis",
      "title": "Early low-entropy hypothesis",
      "url": "https://x.com/KLoaec/status/2082926304995762209",
      "author": "KLoaec",
      "organisation": null,
      "posted": "2026-07-30T20:28:24Z",
      "role": "early-analysis",
      "why_registered": "Kevin Loaec's early low-entropy hypothesis, based on BIP84-only scanning,\nlimited derivation depth and partial sweeps. The post labels the account a\ncurrent hypothesis; its claim that the operator used AI remains unverified.\n",
      "capture": {
        "status": "held",
        "artefacts": [
          {
            "name": "kloaec-2082926304995762209-2082926304995762209.png",
            "format": "PNG",
            "bytes": 272566,
            "sha256": "f47b45979310fdd2f1f3a56a2c41a564808e4469c52a878b2af7bb664af4b8bc"
          },
          {
            "name": "kloaec-2082926304995762209-2082926304995762209.txt",
            "format": "TXT",
            "bytes": 1350,
            "sha256": "841fa95d07658c3d95633925f8d3e583e66055c87450c5afbf453fd22a3709f9"
          }
        ]
      }
    },
    {
      "id": "dhruvbansal-ai-response",
      "title": "Layered security response",
      "url": "https://x.com/dhruvbansal/status/2083262201717244369",
      "author": "dhruvbansal",
      "organisation": null,
      "posted": "2026-07-31T18:43:08Z",
      "role": "ai-response",
      "why_registered": "Dhruv Bansal's broader security response, arguing for layered protections,\nredundancy and human involvement as Bitcoin, AI and computer security overlap.\nIts reference to an attacker using an LLM is commentary, not new attribution\nevidence.\n",
      "capture": {
        "status": "held",
        "artefacts": [
          {
            "name": "dhruvbansal-2083262201717244369-2083262201717244369.png",
            "format": "PNG",
            "bytes": 204391,
            "sha256": "140c0577437f601b9777b694314b6dcff659225337a493960f4317e232547a5c"
          },
          {
            "name": "dhruvbansal-2083262201717244369-2083262201717244369.txt",
            "format": "TXT",
            "bytes": 1153,
            "sha256": "236030033d9c5f7f46f7b68715a24cd76f8dd9d45ae296b1c8d9df1925a16472"
          },
          {
            "name": "dhruvbansal-ai-response-part1-2083262198382801261.png",
            "format": "PNG",
            "bytes": 205473,
            "sha256": "7bd6f835c1cd0f93ad9d507f20d6947ece9fd0f94a4c82a1cd8129a06d1043a6"
          },
          {
            "name": "dhruvbansal-ai-response-part1-2083262198382801261.txt",
            "format": "TXT",
            "bytes": 1092,
            "sha256": "de47b1e7693fdf72d9b0a930c05985a933cac3bc4e22879f99de63a052bb0ef6"
          },
          {
            "name": "dhruvbansal-ai-response-part2-2083262200152821835.png",
            "format": "PNG",
            "bytes": 288309,
            "sha256": "1fa4c7bfc1085b19dbc6495a1f28b5b3c71b85a0b8d71d3bcd590c4c1fcf5d21"
          },
          {
            "name": "dhruvbansal-ai-response-part2-2083262200152821835.txt",
            "format": "TXT",
            "bytes": 1527,
            "sha256": "862e22baf69ec5e91135852146ab5c4306736d0e14b9c5e688fd5acf86d5ae9f"
          }
        ]
      }
    },
    {
      "id": "praveenperera-independent-confirmation",
      "title": "Independent key-recovery confirmation",
      "url": "https://x.com/PraveenPerera/status/2082976249371115811",
      "author": "PraveenPerera",
      "organisation": null,
      "posted": "2026-07-30T23:46:52Z",
      "role": "independent-reproduction",
      "why_registered": "Praveen Perera's first public report that an independent scan recovered two\nprivate keys belonging to the known stolen-address set. The result is preserved\nas reported because the reproduction code and candidate data are not published.\n",
      "capture": {
        "status": "held",
        "artefacts": [
          {
            "name": "praveenperera-2082976249371115811-2082976249371115811.png",
            "format": "PNG",
            "bytes": 85702,
            "sha256": "7e8de664277cffb7634f2f37a3816288ee0f39af9134859ff9fbf82b848fc242"
          },
          {
            "name": "praveenperera-2082976249371115811-2082976249371115811.txt",
            "format": "TXT",
            "bytes": 442,
            "sha256": "502e886a8f3c4488f3e7b39fd7f84528954ff07ac433c1e0e9d66fd0c7a6d9e5"
          }
        ]
      }
    },
    {
      "id": "praveenperera-reproduction-cost",
      "title": "Reported reproduction cost",
      "url": "https://x.com/PraveenPerera/status/2082995029467942947",
      "author": "PraveenPerera",
      "organisation": null,
      "posted": "2026-07-31T01:01:29Z",
      "role": "independent-reproduction",
      "why_registered": "Adds scope and cost to Perera's earlier report: index-zero addresses against a\nknown stolen set, two recovered keys associated with about 34 BTC, roughly five\nminutes and less than US$5 of GPU time. The post also gives urgent dice and\npassphrase advice, which remains an attributed recommendation.\n",
      "capture": {
        "status": "held",
        "artefacts": [
          {
            "name": "praveenperera-2082995029467942947-2082995029467942947.png",
            "format": "PNG",
            "bytes": 236053,
            "sha256": "cbc0655de5eb406354fdf3b8ddf88eaedf356a459af4452c3f8a622aae714f27"
          },
          {
            "name": "praveenperera-2082995029467942947-2082995029467942947.txt",
            "format": "TXT",
            "bytes": 1051,
            "sha256": "f5c2828f8bcac958288fc2f5a186c8c16714c016b40af6037ee1d4b674f73822"
          }
        ]
      }
    },
    {
      "id": "robhamilton-multisig-psa",
      "title": "Multisig migration PSA",
      "url": "https://x.com/Rob1Ham/status/2083215573928853532",
      "author": "Rob1Ham",
      "organisation": null,
      "posted": "2026-07-31T15:37:51Z",
      "role": "migration-guidance",
      "why_registered": "Origin of the public multisig migration warning and Slipstream recommendation.\nHamilton describes the first-broadcast race for wallets whose affected COLDCARD\nkeys alone meet the threshold. The service recommendation is attributed, not\nindependently guaranteed.\n",
      "capture": {
        "status": "held",
        "artefacts": [
          {
            "name": "robhamilton-multisig-psa-2083215573928853532.png",
            "format": "PNG",
            "bytes": 186669,
            "sha256": "e29e7fdc12126a58f54ff3decca92ebe9a0164bd3dd938aca87c65faee2983ac"
          },
          {
            "name": "robhamilton-multisig-psa-2083215573928853532.txt",
            "format": "TXT",
            "bytes": 988,
            "sha256": "edc55ecc099ad6a2f7fd85703e04b5564cc32125cbfb8555fccf15ed24584f3e"
          }
        ]
      }
    },
    {
      "id": "petertodd-slipstream-guidance",
      "title": "Slipstream endorsement and caveat",
      "url": "https://x.com/peterktodd/status/2083219725094453649",
      "author": "peterktodd",
      "organisation": null,
      "posted": "2026-07-31T15:54:21Z",
      "role": "migration-guidance",
      "why_registered": "Peter Todd expands Hamilton's multisig scenario, endorses private miner\nsubmission, and adds the caveat that an already revealed script does not gain\nthe same protection. The recommendation and service assumptions remain\nattributed.\n",
      "capture": {
        "status": "held",
        "artefacts": [
          {
            "name": "petertodd-slipstream-guidance-2083219725094453649.png",
            "format": "PNG",
            "bytes": 257026,
            "sha256": "9b32a1a5a2367b540e2eed36f46a08b9d099fe0a828bb465aa60829cb785d5a5"
          },
          {
            "name": "petertodd-slipstream-guidance-2083219725094453649.txt",
            "format": "TXT",
            "bytes": 1090,
            "sha256": "8a92cad08fa01062d656705c9a5a42d04ecfae94c4ebeda8e38057b1f8b0f40e"
          }
        ]
      }
    },
    {
      "id": "portlandhodl-slipstream-access",
      "title": "Slipstream access-code offer",
      "url": "https://x.com/PortlandHODL/status/2083236118175322577",
      "author": "PortlandHODL",
      "organisation": null,
      "posted": "2026-07-31T16:59:29Z",
      "role": "service-access",
      "why_registered": "PortlandHODL publicly offered Slipstream access codes by direct message during\nthe incident. This records the access channel and its authentication risk; it\ndoes not establish service confidentiality or confirmation guarantees.\n",
      "capture": {
        "status": "held",
        "artefacts": [
          {
            "name": "portlandhodl-slipstream-access-2083236118175322577.png",
            "format": "PNG",
            "bytes": 42946,
            "sha256": "7be4a3c305fd913855c46676e9196922c247ae022c3e6cc6e102d2efa7c80b96"
          },
          {
            "name": "portlandhodl-slipstream-access-2083236118175322577.txt",
            "format": "TXT",
            "bytes": 400,
            "sha256": "f4a0f47a40104eb690a9a939c5c392fa031e7142b31a8aed456441180d8a7ede"
          }
        ]
      }
    },
    {
      "id": "coldcard-expanded-scope",
      "title": "Urgent expanded-scope update",
      "url": "https://x.com/COLDCARDwallet/status/2083155034762621425",
      "author": "COLDCARDwallet",
      "organisation": "Coinkite",
      "posted": "2026-07-31T11:37:18Z",
      "role": "vendor-update",
      "why_registered": "Official COLDCARD update expanding the affected scope beyond the initial Mk3 advisory and directing users to model-specific remediation.\n",
      "capture": {
        "status": "held",
        "artefacts": [
          {
            "name": "coldcard-expanded-scope-2083155034762621425.png",
            "format": "PNG",
            "bytes": 173895,
            "sha256": "7f06d4d198a6b934302a51531d2e019c2ffc0377d7d3d0ee37b7215e89829ff5"
          },
          {
            "name": "coldcard-expanded-scope-2083155034762621425.txt",
            "format": "TXT",
            "bytes": 660,
            "sha256": "2806c6243eb1d5941e322183e5dd9a71a668224cb7098c91c71ee94f21ae09c9"
          }
        ]
      }
    },
    {
      "id": "coldcard-mk3-hotfix-update",
      "title": "Mk3 v4.2.0 availability update",
      "url": "https://x.com/COLDCARDwallet/status/2083186689246208474",
      "author": "COLDCARDwallet",
      "organisation": "Coinkite",
      "posted": "2026-07-31T13:43:05Z",
      "role": "vendor-update",
      "why_registered": "Official COLDCARD announcement of the Mk3 v4.2.0 hotfix, useful for bounding the public remediation timeline.\n",
      "capture": {
        "status": "held",
        "artefacts": [
          {
            "name": "coldcard-mk3-hotfix-update-2083186689246208474.png",
            "format": "PNG",
            "bytes": 159313,
            "sha256": "0096883ccf4aaf12d22ab979fee43762b5b37741b13efd500ed8845fb9caa17d"
          },
          {
            "name": "coldcard-mk3-hotfix-update-2083186689246208474.txt",
            "format": "TXT",
            "bytes": 654,
            "sha256": "d057049290e2130773e33c1aa238b9c09a18c468280d80df45186f095fcbadae"
          }
        ]
      }
    },
    {
      "id": "coldcard-edge-hotfix-update",
      "title": "Edge hotfix availability update",
      "url": "https://x.com/COLDCARDwallet/status/2083234896676356587",
      "author": "COLDCARDwallet",
      "organisation": "Coinkite",
      "posted": "2026-07-31T16:54:38Z",
      "role": "vendor-update",
      "why_registered": "Official COLDCARD announcement naming the Edge hotfix releases 6.6.0X and 6.6.0QX.\n",
      "capture": {
        "status": "held",
        "artefacts": [
          {
            "name": "coldcard-edge-hotfix-update-2083234896676356587.png",
            "format": "PNG",
            "bytes": 121096,
            "sha256": "d8dddeb5a3138221fd9fba7411967d51c98167e860abbd1cbddee4d4fdbff5a3"
          },
          {
            "name": "coldcard-edge-hotfix-update-2083234896676356587.txt",
            "format": "TXT",
            "bytes": 599,
            "sha256": "ff9c59936fb7681ec485d9dd0c165e25cc3c860e3b98229323e5e877c1e1aef4"
          }
        ]
      }
    },
    {
      "id": "instagibbs-reproduction-followup",
      "title": "Mk3 on-device proof timing",
      "url": "https://x.com/theinstagibbs/status/2083188153318256742",
      "author": "theinstagibbs",
      "organisation": null,
      "posted": "2026-07-31T13:48:54Z",
      "role": "independent-reproduction",
      "why_registered": "Gregory Sanders states the elapsed time from deciding to investigate to an on-device Mk3 proof, while leaving method and brute-force runtime unstated.\n",
      "capture": {
        "status": "held",
        "artefacts": [
          {
            "name": "instagibbs-reproduction-followup-2083188153318256742.png",
            "format": "PNG",
            "bytes": 109752,
            "sha256": "f9a700b303d68d27edb7a004b0af5e13641cd97c0fbc1885785a7f893cfcc232"
          },
          {
            "name": "instagibbs-reproduction-followup-2083188153318256742.txt",
            "format": "TXT",
            "bytes": 534,
            "sha256": "842dc8314a246d3d54204a0081719390629f8c6bb0c3ed5502fa24b6e10e2564"
          }
        ]
      }
    },
    {
      "id": "benma-bip85-warning",
      "title": "Benma: BIP85 downstream-wallet warning",
      "url": "https://x.com/_benma_/status/2083375721687511366",
      "author": "_benma_",
      "organisation": null,
      "posted": "2026-08-01T02:14:13Z",
      "role": "downstream-wallet-scope",
      "why_registered": "Independent warning that BIP85 child wallets inherit exposure from an affected COLDCARD master seed and require separate migration consideration.\n",
      "capture": {
        "status": "held",
        "artefacts": [
          {
            "name": "benma-bip85-warning-2083375721687511366.png",
            "format": "PNG",
            "bytes": 45515,
            "sha256": "5e163bd08f6c4822da3f240a81cf267fae316648a63c1e50e1811f5255e066b7"
          },
          {
            "name": "benma-bip85-warning-2083375721687511366.txt",
            "format": "TXT",
            "bytes": 430,
            "sha256": "1db957758db7f4beb48e60a7cada2581850ed718eec44b995dbbd888587ad17c"
          }
        ]
      }
    },
    {
      "id": "kloaec-bip85-warning",
      "title": "Kevin Loaec: BIP85 downstream-wallet warning",
      "url": "https://x.com/KLoaec/status/2083138461452693772",
      "author": "KLoaec",
      "organisation": null,
      "posted": "2026-07-31T10:31:26Z",
      "role": "downstream-wallet-scope",
      "why_registered": "Kevin Loaec warns that BIP85-derived wallets from an affected COLDCARD master seed fall within the migration scope.\n",
      "capture": {
        "status": "held",
        "artefacts": [
          {
            "name": "kloaec-bip85-warning-2083138461452693772.png",
            "format": "PNG",
            "bytes": 52092,
            "sha256": "141e7932e49333357605a19cb5971b7ec271e61fe1a215c1c2c7d0aeb1c02cdf"
          },
          {
            "name": "kloaec-bip85-warning-2083138461452693772.txt",
            "format": "TXT",
            "bytes": 390,
            "sha256": "4c22ec1f564188792d557678eb9694a0dfee0d3dcc5f345cb38cd8592bf0ceb7"
          }
        ]
      }
    },
    {
      "id": "portlandhodl-slipstream-outcome",
      "title": "Reported Slipstream migration outcome",
      "url": "https://x.com/PortlandHODL/status/2083391943799865486",
      "author": "PortlandHODL",
      "organisation": null,
      "posted": "2026-08-01T03:18:41Z",
      "role": "reported-migration-outcome",
      "why_registered": "PortlandHODL reports a specific amount moved through Slipstream for a 2-of-3 multisig case; the result is retained as attributed and unverified.\n",
      "capture": {
        "status": "held",
        "artefacts": [
          {
            "name": "portlandhodl-slipstream-outcome-2083391943799865486.png",
            "format": "PNG",
            "bytes": 81485,
            "sha256": "57700360068d2e45ab3c4149a2cee8f5472e1258854ea7743d7f209e4ff477a1"
          },
          {
            "name": "portlandhodl-slipstream-outcome-2083391943799865486.txt",
            "format": "TXT",
            "bytes": 486,
            "sha256": "ea02c569853391b45424b95e091e2cd091105ee65139843a937b807dec793f31"
          }
        ]
      }
    },
    {
      "id": "guillemet-multisig-relay-analysis",
      "title": "Multisig relay and script-disclosure analysis",
      "url": "https://x.com/P3b7_/status/2083301695606648977",
      "author": "P3b7_",
      "organisation": "Ledger",
      "posted": "2026-07-31T21:20:04Z",
      "role": "independent-technical-analysis",
      "why_registered": "Charles Guillemet explains how script visibility changes a threshold-wallet migration race and recommends private transaction submission; Ledger affiliation requires disclosure.\n",
      "capture": {
        "status": "held",
        "artefacts": [
          {
            "name": "guillemet-multisig-relay-analysis-2083301695606648977.png",
            "format": "PNG",
            "bytes": 313518,
            "sha256": "39aa92596c5124c82148a7685c96f23362fd39ba4def305e7ac82637a2909b5d"
          },
          {
            "name": "guillemet-multisig-relay-analysis-2083301695606648977.txt",
            "format": "TXT",
            "bytes": 1615,
            "sha256": "c9cadf07c3f1d6eb11e99dfd7c2080886be97cc97be3657ac8239c962002199d"
          }
        ]
      }
    },
    {
      "id": "ledger-not-affected-response",
      "title": "Ledger not-affected response",
      "url": "https://x.com/Ledger/status/2083225280441721264",
      "author": "Ledger",
      "organisation": "Ledger",
      "posted": "2026-07-31T16:16:25Z",
      "role": "vendor-response",
      "why_registered": "Ledger states that its devices are not affected and describes the architecture and entropy source it says distinguish them.\n",
      "capture": {
        "status": "held",
        "artefacts": [
          {
            "name": "ledger-not-affected-response-2083225280441721264.png",
            "format": "PNG",
            "bytes": 152247,
            "sha256": "8d2016680431b3f3ef191866c42b93a4314fcaf86fc599ff01b445d889dfab0f"
          },
          {
            "name": "ledger-not-affected-response-2083225280441721264.txt",
            "format": "TXT",
            "bytes": 899,
            "sha256": "f0f1e29164252f19c1309057f9359e5109f5d3332a1c490e6d00f6f4a0c1b6e1"
          }
        ]
      }
    },
    {
      "id": "casa-incident-guidance",
      "title": "Casa multisig response",
      "url": "https://x.com/CasaHODL/status/2083222263617200589",
      "author": "CasaHODL",
      "organisation": "Casa",
      "posted": "2026-07-31T16:04:26Z",
      "role": "custody-provider-guidance",
      "why_registered": "Casa publishes incident-specific guidance for customers using COLDCARD keys in Casa vault policies.\n",
      "capture": {
        "status": "held",
        "artefacts": [
          {
            "name": "casa-incident-guidance-2083222263617200589.png",
            "format": "PNG",
            "bytes": 112007,
            "sha256": "bd62eb88d5fffa477f083e70ce3fdd8a71e96a64f67e1101b6c840d2042b4c60"
          },
          {
            "name": "casa-incident-guidance-2083222263617200589.txt",
            "format": "TXT",
            "bytes": 690,
            "sha256": "16a3a29f0112b09b80e16866cd409914ace6254469fa684bf0a3b937ca096a1a"
          }
        ]
      }
    },
    {
      "id": "nneuman-casa-migration-video",
      "title": "Casa migration video and risk claim",
      "url": "https://x.com/Nneuman/status/2083256427649388797",
      "author": "Nneuman",
      "organisation": "Casa",
      "posted": "2026-07-31T18:20:12Z",
      "role": "custody-provider-guidance",
      "why_registered": "Casa CEO Nick Neuman publishes migration guidance and a threshold-risk claim\nwhose applicability depends on the stated wallet policy and key-provenance\nassumptions.\n",
      "capture": {
        "status": "held",
        "artefacts": [
          {
            "name": "nneuman-casa-migration-video-2083256427649388797.png",
            "format": "PNG",
            "bytes": 236115,
            "sha256": "471c7a244e671d21c783243a78e65b3ce3a70bc81ece42c8c31bfd3272957f28"
          },
          {
            "name": "nneuman-casa-migration-video-2083256427649388797.txt",
            "format": "TXT",
            "bytes": 1178,
            "sha256": "4f2fb6b0a9c270597bf8fb0a034584eac819b7580e8ee8972cfb84510735c7c0"
          }
        ]
      }
    },
    {
      "id": "dhruvbansal-ai-response-part1",
      "title": "Layered-security response, part 1",
      "url": "https://x.com/dhruvbansal/status/2083262198382801261",
      "author": "dhruvbansal",
      "organisation": null,
      "posted": "2026-07-31T18:43:07Z",
      "role": "ai-security-response",
      "why_registered": "First post in Dhruv Bansal thread, preserving the setup and argument that precede the already registered concluding post.\n",
      "capture": {
        "status": "held",
        "artefacts": [
          {
            "name": "dhruvbansal-ai-response-part1-2083262198382801261.png",
            "format": "PNG",
            "bytes": 205473,
            "sha256": "7bd6f835c1cd0f93ad9d507f20d6947ece9fd0f94a4c82a1cd8129a06d1043a6"
          },
          {
            "name": "dhruvbansal-ai-response-part1-2083262198382801261.txt",
            "format": "TXT",
            "bytes": 1092,
            "sha256": "de47b1e7693fdf72d9b0a930c05985a933cac3bc4e22879f99de63a052bb0ef6"
          }
        ]
      }
    },
    {
      "id": "dhruvbansal-ai-response-part2",
      "title": "Layered-security response, part 2",
      "url": "https://x.com/dhruvbansal/status/2083262200152821835",
      "author": "dhruvbansal",
      "organisation": null,
      "posted": "2026-07-31T18:43:08Z",
      "role": "ai-security-response",
      "why_registered": "Second post in Dhruv Bansal thread, preserving the middle argument that precedes the already registered concluding post.\n",
      "capture": {
        "status": "held",
        "artefacts": [
          {
            "name": "dhruvbansal-ai-response-part2-2083262200152821835.png",
            "format": "PNG",
            "bytes": 288309,
            "sha256": "1fa4c7bfc1085b19dbc6495a1f28b5b3c71b85a0b8d71d3bcd590c4c1fcf5d21"
          },
          {
            "name": "dhruvbansal-ai-response-part2-2083262200152821835.txt",
            "format": "TXT",
            "bytes": 1527,
            "sha256": "862e22baf69ec5e91135852146ab5c4306736d0e14b9c5e688fd5acf86d5ae9f"
          }
        ]
      }
    },
    {
      "id": "zherbert-opendime-entropy-test",
      "title": "OPENDIME entropy-incorporation test",
      "url": "https://x.com/zherbert/status/2083399238445056082",
      "author": "zherbert",
      "organisation": "Foundation Devices",
      "posted": "2026-08-01T03:47:40Z",
      "role": "product-scope-test",
      "why_registered": "Foundation Devices co-founder and CEO Zach Herbert reports a physical OPENDIME\nentropy test and provides device-specific evidence bearing on the not-affected\nclaim. Foundation sells competing hardware-wallet products, so that affiliation\nis relevant to the report's provenance.\n",
      "capture": {
        "status": "held",
        "artefacts": [
          {
            "name": "zherbert-opendime-entropy-test-2083399238445056082.png",
            "format": "PNG",
            "bytes": 1503628,
            "sha256": "eb05996c8fe9369e3de70e8d2f81047d08dc622c97dacff6ea667c0f983c8913"
          },
          {
            "name": "zherbert-opendime-entropy-test-2083399238445056082.txt",
            "format": "TXT",
            "bytes": 6182,
            "sha256": "7228fa8e451ca1c432b6af01e29d60585a769e5eb0aa1414122b12940e75e4c1"
          }
        ]
      }
    },
    {
      "id": "robhamilton-opendime-tapsigner-scope",
      "title": "OPENDIME and TAPSIGNER scope response",
      "url": "https://x.com/Rob1Ham/status/2083403595995611223",
      "author": "Rob1Ham",
      "organisation": null,
      "posted": "2026-08-01T04:04:59Z",
      "role": "independent-product-scope",
      "why_registered": "Rob Hamilton responds to the OPENDIME test, distinguishes its observed entropy incorporation from the harder-to-verify closed-source TAPSIGNER claim.\n",
      "capture": {
        "status": "held",
        "artefacts": [
          {
            "name": "robhamilton-opendime-tapsigner-scope-2083403595995611223.png",
            "format": "PNG",
            "bytes": 295277,
            "sha256": "0e681ac4b5113a1188ec817a9054f1bcbe8dcf573cb36c072a4c5e57c7704b1e"
          },
          {
            "name": "robhamilton-opendime-tapsigner-scope-2083403595995611223.txt",
            "format": "TXT",
            "bytes": 1288,
            "sha256": "65dae3e9b535e3b94db230c76536b8dffb0325e11fa6dc23e93f5910e54875bc"
          }
        ]
      }
    },
    {
      "id": "jamesob-dice-roll-guidance",
      "title": "99-roll migration guidance",
      "url": "https://x.com/jamesob/status/2083195361313656949",
      "author": "jamesob",
      "organisation": null,
      "posted": "2026-07-31T14:17:32Z",
      "role": "incident-response-guidance",
      "why_registered": "James O'Beirne recommends migration for affected COLDCARD seeds generated with\nfewer than 99 dice rolls, documenting stricter public guidance than the vendor's\n50-roll threshold.\n",
      "capture": {
        "status": "held",
        "artefacts": [
          {
            "name": "jamesob-dice-roll-guidance-2083195361313656949.png",
            "format": "PNG",
            "bytes": 95906,
            "sha256": "151dbd2dc5a76495198a969abca247912b874e2a8e69019418621e9230c27196"
          },
          {
            "name": "jamesob-dice-roll-guidance-2083195361313656949.txt",
            "format": "TXT",
            "bytes": 609,
            "sha256": "54c911fad311428b12f876d3bb7234ca7fe857327375d019902ddd47aef89870"
          }
        ]
      }
    },
    {
      "id": "alwaysaimbig-multisig-webinar-question",
      "title": "Reader post with attached multisig webinar slide",
      "url": "https://x.com/alwaysaimbig/status/2083373191389425765",
      "author": "alwaysaimbig",
      "organisation": null,
      "posted": "2026-08-01T02:04:10Z",
      "role": "community-question",
      "why_registered": "Zach's post includes a slide headed \"An Unchained vault with 2\nColdcard-generated keys: Group A\" and describes it as webinar guidance. The\npost, complete attached image and attachment transcript are held. The archive\nhas not independently authenticated the slide's authorship, webinar context or\nthe complete presentation. The unversioned PNG and text capture are preserved\nas an incomplete first attempt; the timestamped PNG, JPG attachment and text\ncapture supersede them for reading the post and slide.\n",
      "capture": {
        "status": "held",
        "artefacts": [
          {
            "name": "alwaysaimbig-multisig-webinar-question-2083373191389425765-20260801T063232Z.png",
            "format": "PNG",
            "bytes": 265766,
            "sha256": "f56ee6fd267f2a69973fcd25d989983d9df5ed53f0a5794930f48e95acbd86e8"
          },
          {
            "name": "alwaysaimbig-multisig-webinar-question-2083373191389425765-20260801T063232Z.txt",
            "format": "TXT",
            "bytes": 1517,
            "sha256": "c51480e00b6775169deb31c303f170b8dc0d247662eb6f83190d8817e04d2cd6"
          },
          {
            "name": "alwaysaimbig-multisig-webinar-question-2083373191389425765-media-1-20260801T063232Z.jpg",
            "format": "JPG",
            "bytes": 57170,
            "sha256": "58ba30c0c1c2f86e3580f90572bd366ddac5cc68a359f63abe5c03af051acad3"
          },
          {
            "name": "alwaysaimbig-multisig-webinar-question-2083373191389425765.png",
            "format": "PNG",
            "bytes": 66901,
            "sha256": "6a0a89dd8ad710b84904541b7cca9d6d7a33b1e34d36eccf5609f493d9d6ed3f"
          },
          {
            "name": "alwaysaimbig-multisig-webinar-question-2083373191389425765.txt",
            "format": "TXT",
            "bytes": 511,
            "sha256": "03cc21a60f3680e53c72795a1a5a57206b006d8b021f7aec8b9b43bd1c8af5cb"
          }
        ]
      }
    },
    {
      "id": "coldcard-urgent-migration-appeal",
      "title": "COLDCARD Urgent Migration Appeal",
      "url": "https://x.com/COLDCARDwallet/status/2083513501662765530",
      "author": "COLDCARDwallet",
      "organisation": null,
      "posted": "2026-08-01T11:21:43Z",
      "role": "vendor-update",
      "why_registered": "Coinkite's 1 August escalation post asks users to treat migration as urgent and to spread the word to less-online owners. It quotes the vendor's 31 July urgent update, whose wording states the Mk3 affected boundary as 4.0.1+ and carves out seeds generated with at least 50 private, independent dice rolls. Both details bear directly on the affected-range boundary and the mixed-dice classification recorded elsewhere in this archive.\n",
      "capture": {
        "status": "held",
        "artefacts": [
          {
            "name": "coldcard-urgent-migration-appeal-2083513501662765530.png",
            "format": "PNG",
            "bytes": 134966,
            "sha256": "45f26c6fbc4e9c1f7253dd787d94230705ffd234e707d4b4c1ab143f4d7420a9"
          },
          {
            "name": "coldcard-urgent-migration-appeal-2083513501662765530.txt",
            "format": "TXT",
            "bytes": 614,
            "sha256": "d2b48a3d63cb2fa8502bf3fd198092e3784979e349634fdbc4a9ca482b7bfa13"
          }
        ]
      }
    },
    {
      "id": "kloaec-mk4-class-drain-report",
      "title": "KLoaec Mk4 Class Drain Report",
      "url": "https://x.com/KLoaec/status/2083530439101239380",
      "author": "KLoaec",
      "organisation": null,
      "posted": "2026-08-01T12:29:01Z",
      "role": "on-chain-analysis",
      "why_registered": "Kevin Loaec of Wizardsardine states on 1 August that Mk4, Mk5 and Q wallets are now being actively drained, quoting Tomer Strolight's account of an intentionally seeded Mk4 honeypot swept overnight to a named bc1q address. If corroborated on chain this is the first reported Mk4-class sweep, extending observed exploitation beyond the roughly 40-bit Mk3 space; the claim itself remains a reported third-party account.\n",
      "capture": {
        "status": "held",
        "artefacts": [
          {
            "name": "kloaec-mk4-class-drain-report-2083530439101239380.png",
            "format": "PNG",
            "bytes": 154468,
            "sha256": "1cd34b47836f334095643a5a6eded4c0bc4ade5700fb70b7f8e3d50bdcf96732"
          },
          {
            "name": "kloaec-mk4-class-drain-report-2083530439101239380.txt",
            "format": "TXT",
            "bytes": 577,
            "sha256": "9bf46807ad9fa2be58db01ab59f0dd2ee96b40f4928499ac937042da868f53d4"
          }
        ]
      }
    },
    {
      "id": "kloaec-wizardsardine-postmortem",
      "title": "KLoaec Wizardsardine Postmortem",
      "url": "https://x.com/KLoaec/status/2083579776887922865",
      "author": "KLoaec",
      "organisation": null,
      "posted": "2026-08-01T15:45:04Z",
      "role": "independent-analysis",
      "why_registered": "Kevin Loaec announces Wizardsardine's long-form post-mortem of the COLDCARD flaw, summarising it as worse than commonly understood because users with safe mnemonics, including dice-generated ones, still face broken features on affected devices. The linked blog post is captured separately as a web source; this post records the framing and the author's request for corrections.\n",
      "capture": {
        "status": "held",
        "artefacts": [
          {
            "name": "kloaec-wizardsardine-postmortem-2083579776887922865.png",
            "format": "PNG",
            "bytes": 157328,
            "sha256": "cab77d8fa7f412e09c27f6b9305688ffdb8354ebae0f98cf724f057bcd8c6487"
          },
          {
            "name": "kloaec-wizardsardine-postmortem-2083579776887922865.txt",
            "format": "TXT",
            "bytes": 683,
            "sha256": "95030d15912a08a9a8a0c4e9e4f9f79e03d83ef8d3e2ddf982dedd058e5c62e6"
          }
        ]
      }
    },
    {
      "id": "kloaec-derived-feature-exposure",
      "title": "KLoaec Derived Feature Exposure",
      "url": "https://x.com/KLoaec/status/2083580367970193449",
      "author": "KLoaec",
      "organisation": null,
      "posted": "2026-08-01T15:47:25Z",
      "role": "downstream-wallet-scope",
      "why_registered": "Kevin Loaec stresses that even users who imported a seed or generated one with dice are exposed if they used certain COLDCARD features, with an attached graphic enumerating them. This extends the incident's blast radius beyond seed generation into derived-material features and aligns with the Wizardsardine post-mortem's broken-features section; the specific feature list is the vendor-independent claim to check against source.\n",
      "capture": {
        "status": "held",
        "artefacts": [
          {
            "name": "kloaec-derived-feature-exposure-2083580367970193449.png",
            "format": "PNG",
            "bytes": 78036,
            "sha256": "eeb56b7e2be0465d39bbbf82a7f5e3c88e631c52eb56a4f03fc85210b68b03d3"
          },
          {
            "name": "kloaec-derived-feature-exposure-2083580367970193449.txt",
            "format": "TXT",
            "bytes": 526,
            "sha256": "8816bc415adfef4da3b02310a469f30ad08030d9d1189a9049f71dbb4bb37f17"
          }
        ]
      }
    },
    {
      "id": "claygarrett-bitkey-initial-findings",
      "title": "Claygarrett Bitkey Initial Findings",
      "url": "https://x.com/clay_garrett/status/2083585966481068398",
      "author": "clay_garrett",
      "organisation": null,
      "posted": "2026-08-01T16:09:40Z",
      "role": "vendor-response",
      "why_registered": "Block hardware lead Clay Garrett shares initial findings on a separately reported Bitkey vulnerability disclosed by 1440000bytes, stating it requires exceptional circumstances during inheritance setup, yields insufficient key material even if exploited, and that a mobile-app patch ships same day. Recorded because Block is a primary party in the COLDCARD incident record and this statement shows its concurrent security posture; the Bitkey issue itself is distinct from the COLDCARD RNG flaw.\n",
      "capture": {
        "status": "held",
        "artefacts": [
          {
            "name": "claygarrett-bitkey-initial-findings-2083585966481068398.png",
            "format": "PNG",
            "bytes": 231399,
            "sha256": "373aa0a0ec163e39926260e7974295499a75a98f92256c28a0e1ee901533ec63"
          },
          {
            "name": "claygarrett-bitkey-initial-findings-2083585966481068398.txt",
            "format": "TXT",
            "bytes": 1281,
            "sha256": "0c6fb8ebdcaaea2a15449c368ecf7d845a908924200b48f67852bbe72db47cba"
          }
        ]
      }
    },
    {
      "id": "btcpp-dettmer-analysis-announcement",
      "title": "Btcpp Dettmer Analysis Announcement",
      "url": "https://x.com/btcinsider__/status/2083592498954572145",
      "author": "btcinsider__",
      "organisation": null,
      "posted": "2026-08-01T16:35:37Z",
      "role": "independent-analysis",
      "why_registered": "bitcoin++ Insider Edition announces Dustin Dettmer's commit-history walkthrough of how the COLDCARD entropy bug was introduced, titled 'When random.bytes() runs but doesn't work'. The linked article is captured separately as a web source; this post records the publication and its framing.\n",
      "capture": {
        "status": "held",
        "artefacts": [
          {
            "name": "btcpp-dettmer-analysis-announcement-2083592498954572145.png",
            "format": "PNG",
            "bytes": 97311,
            "sha256": "87fdef2ebb1694e3542b26fa115d2813c12da278bf2e7a8b560afc0085c94d7c"
          },
          {
            "name": "btcpp-dettmer-analysis-announcement-2083592498954572145.txt",
            "format": "TXT",
            "bytes": 609,
            "sha256": "2024cbe726b330f5ccbd575371c97ced5167fd10a72c695756386d034e928a96"
          }
        ]
      }
    },
    {
      "id": "glxyresearch-third-wave-revision",
      "title": "Galaxy Research Third Wave Revision",
      "url": "https://x.com/glxyresearch/status/2083623500183421043",
      "author": "glxyresearch",
      "organisation": null,
      "posted": "2026-08-01T18:38:48Z",
      "role": "on-chain-analysis",
      "why_registered": "Galaxy Research's 1 August revision identifying a third sweep wave of 207.7294 BTC and raising its estimated observed total to 1,367.05 BTC across 4,585 addresses, superseding the roughly 1,083 BTC figure quoted earlier in this archive. The thread also states that no coin drained in waves 1 to 3 was created before block 674,951 on 17 March 2021, which bears independently on the affected-range lower bound, and carries Galaxy's own disclaimer that the work derives solely from block data and the unspent-output set without testing whether the identified addresses were in fact generated with low entropy.\n",
      "capture": {
        "status": "held",
        "artefacts": [
          {
            "name": "glxyresearch-third-wave-revision-2083623500183421043.png",
            "format": "PNG",
            "bytes": 877472,
            "sha256": "be6369251848193f09cef235707ad21f2bdc267a254a96f12a4ff99ee57d3f93"
          },
          {
            "name": "glxyresearch-third-wave-revision-2083623500183421043.txt",
            "format": "TXT",
            "bytes": 659,
            "sha256": "58bbb7d9f2d0145c936f828388454da5ce0898f83e0c20430cdd5fec4c00d9a2"
          }
        ]
      }
    },
    {
      "id": "glxyresearch-methodology-disclaimer",
      "title": "Galaxy Research Methodology Disclaimer",
      "url": "https://x.com/glxyresearch/status/2083623504285421622",
      "author": "glxyresearch",
      "organisation": null,
      "posted": "2026-08-01T18:38:49Z",
      "role": "on-chain-analysis",
      "why_registered": "Galaxy Research's own scope disclaimer for its wave analysis: the work derives solely from Bitcoin block data and the unspent-output set, and Galaxy has not used compute to test whether the addresses it identifies as possible victims were in fact generated with low entropy. This bounds every Galaxy figure quoted in this archive and is the reason those totals are recorded as attributed observations rather than established causation.\n",
      "capture": {
        "status": "held",
        "artefacts": [
          {
            "name": "glxyresearch-methodology-disclaimer-2083623504285421622.png",
            "format": "PNG",
            "bytes": 171478,
            "sha256": "fe6a779b42de323a0c4d79eeadc08eb626154e592a98e00212cbfc99df90d49d"
          },
          {
            "name": "glxyresearch-methodology-disclaimer-2083623504285421622.txt",
            "format": "TXT",
            "bytes": 1056,
            "sha256": "67dc7ca359fc1b1c263f1bc4b15c15192c57def11dbc486935b798dffc5d1428"
          }
        ]
      }
    },
    {
      "id": "glxyresearch-firmware-block-boundary",
      "title": "Galaxy Research Firmware Block Boundary",
      "url": "https://x.com/glxyresearch/status/2083623541921001756",
      "author": "glxyresearch",
      "organisation": null,
      "posted": "2026-08-01T18:38:58Z",
      "role": "on-chain-analysis",
      "why_registered": "Galaxy Research states that the vulnerable COLDCARD firmware shipped on 17 March 2021 around block 674,951, and that no coin identified in waves 1 to 3 was created before that block. This bears independently on the affected-range lower bound: 17 March 2021 is the v4.0.0 release date recorded here, not the 29 March 2021 v4.0.1 date that the vendor advisory uses as its stated boundary.\n",
      "capture": {
        "status": "held",
        "artefacts": [
          {
            "name": "glxyresearch-firmware-block-boundary-2083623541921001756.png",
            "format": "PNG",
            "bytes": 373036,
            "sha256": "2edecea89ead7600c31d662c775846d637dff09a4b3e55f7834fbffdfd4b4973"
          },
          {
            "name": "glxyresearch-firmware-block-boundary-2083623541921001756.txt",
            "format": "TXT",
            "bytes": 557,
            "sha256": "a2b82dd3aab2d1831d03ad58e77f1482dafc52d7eba1f661b777e7dbbb99e8b2"
          }
        ]
      }
    },
    {
      "id": "glxyresearch-attacker-holdings",
      "title": "Galaxy Research Attacker Holdings",
      "url": "https://x.com/glxyresearch/status/2083623527366734239",
      "author": "glxyresearch",
      "organisation": null,
      "posted": "2026-08-01T18:38:55Z",
      "role": "on-chain-analysis",
      "why_registered": "Galaxy Research reports 1,366.3865 BTC under attacker control with all endpoint attacker addresses fully unspent on chain as of 1 August 2026. Recorded alongside the funds accounting because it is the outcome question a reader asks after the sweep totals, and because an unspent endpoint set is the condition under which any later movement becomes newsworthy.\n",
      "capture": {
        "status": "held",
        "artefacts": [
          {
            "name": "glxyresearch-attacker-holdings-2083623527366734239.png",
            "format": "PNG",
            "bytes": 250612,
            "sha256": "0e8e4717feb74823d6e7b5d9eea975135dd6dc26410f9edb9d0556cd581dc836"
          },
          {
            "name": "glxyresearch-attacker-holdings-2083623527366734239.txt",
            "format": "TXT",
            "bytes": 504,
            "sha256": "93c31ad22a213b550e527c1c0fdac75717b354bcaa6744db6aac9654a10652b6"
          }
        ]
      }
    },
    {
      "id": "glxyresearch-same-operator-basis",
      "title": "Galaxy Research Same Operator Basis",
      "url": "https://x.com/glxyresearch/status/2083623511126638642",
      "author": "glxyresearch",
      "organisation": null,
      "posted": "2026-08-01T18:38:51Z",
      "role": "on-chain-analysis",
      "why_registered": "Galaxy Research states the basis for treating the sweep waves as one operator: waves 1 and 2 share funnel topology into a handful of collectors, the same P2WPKH destinations and the same mix of derivation paths, 27 hours apart, and that treating them as one operator is reasonable but rests on resemblance rather than proof. This is the attribution qualifier behind every same-operator total quoted in this archive.\n",
      "capture": {
        "status": "held",
        "artefacts": [
          {
            "name": "glxyresearch-same-operator-basis-2083623511126638642.png",
            "format": "PNG",
            "bytes": 347493,
            "sha256": "633c1283c8cfc51d6ea6e3689ab93282651a10a976870d3008b84f04b91c75dd"
          },
          {
            "name": "glxyresearch-same-operator-basis-2083623511126638642.txt",
            "format": "TXT",
            "bytes": 1785,
            "sha256": "a100ce02453bff169ea87ea13a8f9f66576c3b8ee6f5b3284752dd508e464042"
          }
        ]
      }
    },
    {
      "id": "lopp-scam-playbook-update",
      "title": "Lopp Scam Playbook Update",
      "url": "https://x.com/lopp/status/2083614303127547977",
      "author": "lopp",
      "organisation": null,
      "posted": "2026-08-01T18:02:16Z",
      "role": "scam-report",
      "why_registered": "Jameson Lopp posts a screenshot of a Telegram account impersonating COLDCARD WALLET that messaged a user on 1 August, opening with rapport rather than an immediate credential request: the sender claims database records showing the recipient was an early user and asks whether they moved their funds safely. The capture also shows Telegram's own contact panel marking the account Not an official account, registered March 2026, and the blue mark identified in-app as a Premium subscriber badge rather than verification. Quoted above his 31 July warning that phishing mail posing as Coinkite security notices would follow. First-hand documentary evidence of an impersonation channel exploiting this incident's migration guidance.\n",
      "capture": {
        "status": "held",
        "artefacts": [
          {
            "name": "lopp-scam-playbook-update-2083614303127547977-media-1-20260802T004200Z.jpg",
            "format": "JPG",
            "bytes": 88226,
            "sha256": "5d6d307c4e11d1941bf4abc82bc6e6ab9deaf21532e0013f5a8c8a1411dffec8"
          },
          {
            "name": "lopp-scam-playbook-update-2083614303127547977.png",
            "format": "PNG",
            "bytes": 112841,
            "sha256": "4d4133b93bc0e40618aa60a8f3a6110f936b532a985d6546812b3bafae4b36ac"
          },
          {
            "name": "lopp-scam-playbook-update-2083614303127547977.txt",
            "format": "TXT",
            "bytes": 930,
            "sha256": "9a90542863d27189e3f9be744ae6f23c6d24dabb8335f4fcd680f7b2a71b25ce"
          }
        ]
      }
    },
    {
      "id": "lopp-phishing-prediction",
      "title": "Lopp Phishing Prediction",
      "url": "https://x.com/lopp/status/2083205974907621835",
      "author": "lopp",
      "organisation": null,
      "posted": "2026-07-31T14:59:43Z",
      "role": "scam-report",
      "why_registered": "Jameson Lopp predicts on 31 July that phishing mail posing as Coinkite security notices will follow the disclosure and will try to get readers to type recovery words into a malicious site. Held because his 1 August impersonation screenshot quote-tweets this post: together they are a dated prediction and a dated artefact, and the pairing is what distinguishes a documented scam from an anticipated one.\n",
      "capture": {
        "status": "held",
        "artefacts": [
          {
            "name": "lopp-phishing-prediction-2083205974907621835.png",
            "format": "PNG",
            "bytes": 145083,
            "sha256": "f4ffbbaa94b84a3070da4e2f1c4658aa29f336716ca6f828a8b3e9ff0d6d9ddb"
          },
          {
            "name": "lopp-phishing-prediction-2083205974907621835.txt",
            "format": "TXT",
            "bytes": 585,
            "sha256": "0bd4cd5ccb0d55dff26ab4f00217d7c7e8e8af2dbc7ef8d476bbdae18edf9943"
          }
        ]
      }
    }
  ]
}
