COLDCARD RNG incident the public record, collected and explained
Informational only, and this site never asks for your seed words. details

Informational only. This is an open source collection of what others have published about the incident, together with an explanation of it. It is not financial, security or legal advice, and not a substitute for professional advice about your own situation. It is not affiliated with, endorsed by, or speaking for Coinkite. Material is attributed and quoted as published; where sources disagree their scenarios are kept separate with their assumptions rather than reconciled into one answer. Everything is meant to be checked against the linked evidence rather than taken on trust. Act on your own judgement about a particular situation. Editorial standards and corrections.

Do not disclose recovery material to a website, form, message or support account. This site never asks for it, and contributions containing recovery words or private keys are not accepted.

Claimed undisclosed PIN exfiltration vulnerability

a_ferron-2085731252657696911

https://x.com/a_ferron/status/2085731252657696911

Captured screenshot of the post by @a_ferron, posted 7 Aug 2026, 14:14 UTC
@a_ferron posted captured full-size capture → original post →
Author
@a_ferron
Organisation
independent
Evidence role
social statement
Posted
Capture status
capture held

Antoine Ferron says he found a PIN-exfiltration vulnerability in a Coldcard product two years ago, waited for a fix, and will now publish because the update never arrived. Held as a dated, specific claim about an undisclosed prior vulnerability. The existence and details of the vulnerability are the poster's own and are not verified here.

This post is registered as evidence and has a locally held capture. The original remains the canonical publication. Last checked .

The conversation

Captured . 2 continuation posts, 7 replies held, 2 muted as low signal. Posts are in the archive's own order, oldest first, not the order X ranks them in.

  1. @a_ferron the registered post 7 Aug 2026, 14:14 UTC
    Captured screenshot of the post by @a_ferron

    capture taken

  2. @a_ferron same author, continuing 7 Aug 2026, 14:14 UTC
    Captured screenshot of the post by @a_ferron

    capture taken

  3. @a_ferron same author, continuing 7 Aug 2026, 14:27 UTC
    Captured screenshot of the post by @a_ferron

    capture taken

Replies are unmoderated third-party material, reproduced here as part of the record. Inclusion is not endorsement, and nothing in them has been checked by this project.
Replies held in this capture (7)

Low-signal replies are collapsed to one line, never removed. A reply is collapsed only on mechanical grounds: fewer than 40 characters, no text, mentions only, no letters or digits, a bare link, or text identical to another reply in the same capture. What a reply argues is never a reason. Each one says which rule collapsed it, and its screenshot is one click away.

  1. Captured screenshot of the reply by @TakeProfitLLC

    capture taken

  2. @Enkitek 7 Aug 2026, 21:06 UTC under 40 characters
    What is pIN exfiltration?
    show the capture Captured screenshot of the reply by @Enkitek

    capture taken

  3. @a_ferron 7 Aug 2026, 21:34 UTC the thread author answering in their own thread
    Captured screenshot of the reply by @a_ferron

    capture taken

  4. @BitcoinJiuJitsu 7 Aug 2026, 21:40 UTC under 40 characters
    The opposite of this.
    show the capture Captured screenshot of the reply by @BitcoinJiuJitsu

    capture taken

  5. @Excellion 8 Aug 2026, 10:08 UTC this account is registered elsewhere in the record
    Captured screenshot of the reply by @Excellion

    capture taken

  6. @domegabri 8 Aug 2026, 12:24 UTC
    Captured screenshot of the reply by @domegabri

    capture taken

  7. @a_ferron 8 Aug 2026, 14:41 UTC the thread author answering in their own thread
    Captured screenshot of the reply by @a_ferron

    capture taken

This capture reached the end of the conversation as X served it: it stopped because nothing further loaded, not because a limit was hit. X decides what a reader is shown, so that is not the same as a guarantee of every reply.

  1. Earliest copy held
    seen · Captured here 4,988 chars
    Extracted text as captured
    thread: 2085731252657696911
    url: https://x.com/a_ferron/status/2085731252657696911
    author: a_ferron
    
    post: 2085731252657696911
    role: focal
    author: a_ferron
    name: Antoine
    created: 2026-08-07T14:14:16Z
    media: 0
    body:
    Agree on the Coldcard silent criticisms. I choose to stay silent too : positivism/politeness, not harming their brand. I even found a vulnerability in one of their product 2 years ago, waited for them to do the fixing update. But it has never be done so far, so I haven't yet disclosed it. Yet another red flag when looking at the rearview mirror. I will publish that soon. It is about PIN exfiltration. In a way, stayed nicely silent hasn't helped/protected consumers, but only CC business. We all regret that.
    
    I disagree on the Secure Elements part. SEs are very important things to use, they offer a real protection on private data, like a vault. There is no such thing like virtual-SE. And without SE, you can not have secure boot nor genuine check, meaning you are not sure about the code running on the device. Why do you think that banks, governments and mobile network operators, all rely on SEs, if there could exist alternatives ? TINA, SEs are useful stuff in term of protecting your secret data.
    Ofc having a SE doesn't mean you are fully safe, 100% security doesn't exist. It just offer decent protection to various attacks, that a standard chip can not handle.
    
    post: 2085731255274942910
    role: self-thread
    author: a_ferron
    name: Antoine
    created: 2026-08-07T14:14:16Z
    media: 0
    body:
    The wallet I like the most today is the 
    @Keycard_
     Shell. An airgap device, with integrated smartcard SE reader that protects the seed. Plus you can easily change account/seed by just changing the smartcard inserted.
    
    post: 2085734605315854700
    role: self-thread
    author: a_ferron
    name: Antoine
    created: 2026-08-07T14:27:35Z
    media: 0
    body:
    A last word about the exfil protection. I see it as a complex mathematical toy that helps only to avoid very specific issues, which are rarely used by malicious actors. It adds more complexity than real security. As the author of this security mechanism wrote : "that still wouldn't stop a malicious wallet from stealing from you because it can basically just do whatever it wants." And without a SE, you have no guarantee what your hw wallet is doing.
    
    post: 2085835023240888816
    role: reply
    author: Enkitek
    name: EnkiTek

    Excerpt only. The complete copy is held offline and backs quotations on this site. The original publication remains the canonical public source.

How to check this yourself

The excerpts and plain unified diffs above show the text this project held and how it changed. To verify a quotation, compare it against the page itself or against the Internet Archive's copies, which are independent of this project.

Complete captures are held offline rather than mirrored here, so this page shows diffs and excerpts. If a quotation is ever disputed, the full copy can be produced. Ask.