COLDCARD RNG incident the public record, collected and explained
Informational only, and this site never asks for your seed words. details

Informational only. This is an open source collection of what others have published about the incident, together with an explanation of it. It is not financial, security or legal advice, and not a substitute for professional advice about your own situation. It is not affiliated with, endorsed by, or speaking for Coinkite. Material is attributed and quoted as published; where sources disagree their scenarios are kept separate with their assumptions rather than reconciled into one answer. Everything is meant to be checked against the linked evidence rather than taken on trust. Act on your own judgement about a particular situation. Editorial standards and corrections.

Do not disclose recovery material to a website, form, message or support account. This site never asks for it, and contributions containing recovery words or private keys are not accepted.

We can all learn one or two from this ColdCard incident

bitcointalk-learn-from-incident

https://bitcointalk.org/index.php?topic=5590065.0

Latest reviewed change

source content difference between and

The thread gained new posts by arwin100, Supreme Donvic and Dogedegen debating airgapped computers, diversification across wallets, and cracked operating systems.

seen +37 -0 full history below
 Post by: yhiaali3 on August 07, 2026, 04:04:12 AM
 Yes, this incident taught us many lessons, the most important of which is that there is no complete security in crypto unless you take the highest security and safety standards. The biggest mistake is to think you are safe just because you use a hardware wallet.
 The security level should be increased to the highest level by adding a passphrase to the seed, or by using multiple signatures and most importantly, not putting all your eggs in one basket. It is very important to distribute assets across more than one wallet in anticipation of the worst-case scenario.
+Title: Re: We can all learn one or two from this ColdCard incident
+Post by: arwin100 on August 07, 2026, 02:23:58 PM
+Quote from: bitmover on August 06, 2026, 10:12:18 AM
+Quote from: X-ray on August 06, 2026, 03:23:13 AM
+I've used airgapped computers for my wallet for quite sometime, I don't find it any more riskier than hardware wallet. You installed latest OS to an airgapped computer, you never connect it to the Internet and the wallet stays on the computer.

First lines only. The complete diff is in the timeline below.

Organisation
BitcoinTalk
Evidence role
Community discussion
Published
2026-08-03
Source changes
7
Detected differences
8
Unreviewed
0
Copies held
9

YellowSwap opening a lessons-learned thread on the Bitcoin Discussion board, drawing one of the longer forum discussions of the incident's takeaways for holders. A community response and sentiment record alongside bitcointalk-bright-side-opinion. The lessons and claims in the thread are the posters' own, not verified here.

Every check is recorded, including checks that found no text change. A detected edit is therefore bounded between two checks. The publisher's exact save time is not observable from this record. Last checked .

  1. source content difference between and source content +37 -0

    The thread gained new posts by arwin100, Supreme Donvic and Dogedegen debating airgapped computers, diversification across wallets, and cracked operating systems.

    seen · Captured here 72,495 chars
    What changed from the previous capture 37 lines
     Post by: yhiaali3 on August 07, 2026, 04:04:12 AM
     Yes, this incident taught us many lessons, the most important of which is that there is no complete security in crypto unless you take the highest security and safety standards. The biggest mistake is to think you are safe just because you use a hardware wallet.
     The security level should be increased to the highest level by adding a passphrase to the seed, or by using multiple signatures and most importantly, not putting all your eggs in one basket. It is very important to distribute assets across more than one wallet in anticipation of the worst-case scenario.
    +Title: Re: We can all learn one or two from this ColdCard incident
    +Post by: arwin100 on August 07, 2026, 02:23:58 PM
    +Quote from: bitmover on August 06, 2026, 10:12:18 AM
    +Quote from: X-ray on August 06, 2026, 03:23:13 AM
    +I've used airgapped computers for my wallet for quite sometime, I don't find it any more riskier than hardware wallet. You installed latest OS to an airgapped computer, you never connect it to the Internet and the wallet stays on the computer.
    +No supply chain attack which hardware wallet could be infected from, no accidental seed phrase leak because the internet isn't there in the first place, your wallet stay safe until the day you decided to withdraw it. I think it's robust enough solution for me, but it's just my opinion.
    +To be honest though, setting up one is a pain to do, you need to verify the stack and keep updated on latest exploit which going to take a lot of your time, which is why I also own hardware wallet.
    +There is a risk of supply chain attack, accidental seed phrase leak, everything.
    +The risk is exactly in the step you called a "pain to do". Setting it up. If you dont know exactly what you are doing,  you can expose yourself to those risks
    +When you buy a good hardware wallet (not coldcard), you are theoretically free of all those risks.
    +Yeah that situation is really possible to happen. Usually the risk occur in crucial stage on which lots of people made a mistake when setting up their wallet.
    +Many of them exposed themselves on the risk especially if they don't know how to back up their verify, do back ups and know how to handle properly their seed phrase.
    +What people need to understand that those incidents didn't happen because the hardware wallet they are using is not safe. But rather they just made a mistake for not paying close attention following the guide.
    +Title: Re: We can all learn one or two from this ColdCard incident
    +Post by: Supreme Donvic on August 07, 2026, 03:27:01 PM
    +Quote from: KiaKia on August 01, 2026, 12:17:17 PM
    +The only lesson I learnt here is that nowhere is safe, putting all your eggs in one basket is totally wrong, as for that passphrase thing, hardware wallets are the only ones offering it?
    +If any mobile wallet has passphrase+ recovery seeds then there is really no reason to run after hardware wallets anymore, I am really disappointed in this ColdCard company and their team together.
    +Many people might never return to Bitcoin investment after this, there are people who have been holding and stacking Bitcoin since 2019 on that list of victims, someone whom I never thought would use ColdCard because I've never heard the name from him before.
    +I agree with you, nowhere is actually safe and it is wrong for someone to put his eggs in one basket. Many people have lost everything because they decided to put all their finance in one place. I can't be relaxed if all my money is just in one place, it is a very risky thing to do. Those that spread their Bitcoin are more safe. If you want to be safe spread your Bitcoin don't keep it in one place.
    +Sure, a lot of those that are affected will not return back to bitcoin investment, I believe 80% of those that we were affected will not talk about bitcoin investment ever again. Just like you have said, a lot of them that was affected has been accumulating Bitcoin since the creation of Bitcoin. The pain of losing everything will never allow them to come back to Bitcoin.
    +Title: Re: We can all learn one or two from this ColdCard incident
    +Post by: Dogedegen on August 07, 2026, 07:24:33 PM
    +Quote from: hd49728 on Today at 03:34:16 AM
    +Quote from: X-ray on Today at 01:24:02 AM
    +Setting it up, installing OS etc is easy, the hard part is exactly what you mentioned, keeping up with the exploit updates and verify that you got the right files.
    +People must avoid using cracked OS because it is very dangerous in security. If it's not feasible for them to buy it to use, they can consider to use open source OS like Linux.
    +https://linuxmint.com/
    +This is true, but this is very rare so we must be careful what we write and how we write about it. There have been only a few times when this kind of case ended up in the news and this was mainly because the source of those cracked versions was not reputable, and if you think that there have been billions of installs of cracked OS and software the risk is very low. Actually the much higher risk comes from other attack vectors like malicious software, using very weak wallets like browser wallets as your main wallets and stuff like that. Anyway, using Windows as a primary OS for keeping cryptocurrency safe is very bad for both security and privacy and using a real license does not help with this. So you are very right to suggest Linux Mint, I have been using that and Ubuntu for a very long time and I have never had any issues of any kind when it comes to security. Simply by switching to such an OS the risk of a hack decreases considerably!
    +Quote from: Supreme Donvic on Today at 03:27:01 PM
    +Quote from: KiaKia on August 01, 2026, 12:17:17 PM
    +The only lesson I learnt here is that nowhere is safe, putting all your eggs in one basket is totally wrong, as for that passphrase thing, hardware wallets are the only ones offering it?
    +If any mobile wallet has passphrase+ recovery seeds then there is really no reason to run after hardware wallets anymore, I am really disappointed in this ColdCard company and their team together.
    +Many people might never return to Bitcoin investment after this, there are people who have been holding and stacking Bitcoin since 2019 on that list of victims, someone whom I never thought would use ColdCard because I've never heard the name from him before.
    +I agree with you, nowhere is actually safe and it is wrong for someone to put his eggs in one basket. Many people have lost everything because they decided to put all their finance in one place. I can't be relaxed if all my money is just in one place, it is a very risky thing to do. Those that spread their Bitcoin are more safe. If you want to be safe spread your Bitcoin don't keep it in one place.
    +Sure, a lot of those that are affected will not return back to bitcoin investment, I believe 80% of those that we were affected will not talk about bitcoin investment ever again. Just like you have said, a lot of them that was affected has been accumulating Bitcoin since the creation of Bitcoin. The pain of losing everything will never allow them to come back to Bitcoin.
    +This is also not the right advice, because the right advice is always about the balance. Somebody has a single basket that is more secure than somebody's 10 baskets combined. It depends on the situation, the setup and the actual need. There is a breaking point after which adding more baskets does not increase security, it reduces your security because of the complexity involved. Always be reasonable and try to find some kind of middle point when it comes to questions of security.
     Powered by SMF 1.1.19 |
     SMF © 2006-2009, Simple Machines
    
    Extracted text as captured
    Bitcoin Forum
    Bitcoin => Bitcoin Discussion => Topic started by: YellowSwap on August 01, 2026, 08:19:47 AM
    Title: We can all learn one or two from this ColdCard incident
    Post by: YellowSwap on August 01, 2026, 08:19:47 AM
    I am already seeing people saying things about hardware wallets because of what happened to ColdCard, the company messed up real bad for letting people generate recovery seed using weak RNG (Random Number Generator).
    This should not in anyway makes you look less on hardware wallets still.
    The case of ColdCard was caused by a firmware bug in the hardware wallet that disabled the hardware based RNG in certain ColdCard devices.
    If I have to choose between a software wallet and a hardware wallet it will be a non-custodial hardware wallet any day.
    This kind of incidents rarely happens with hardware wallet but it's the case with software wallets.
    It's not even the software wallets itself but the devices we run the software wallets on, while the ColdCard case is still going on, some people are losing digital assets via their iPhone and androids.
    https://talkimg.com/images/2026/08/01/UomI9C.jpg
    The lesson we have learnt from ColdCard incident is to always consider stricter security even with our hardware wallets.
    - let's start considering passphrase with recovery seeds.
    - let's start considering multisig if possible.
    - let's start considering the Dice 🎲 rolling method for entropy
    While Trezor and others aren't affected, I personally don't feel it's enough to just generate a recovery seed and sit on it as your total security method, the existence of 2FA strengthen the existence of passwords for every websites, so I hope you beginners learn something from this.
    Title: Re: We can all learn one or two from this ColdCard incident
    Post by: un_rank on August 01, 2026, 09:21:12 AM
    If you use a non custodian software wallet downloaded from th3 original website and the keys verified, with an open source software run on an airgapped device you get security similar to what you get on a hardware wallet.
    What has been emphasised for me from this incidence is we should never assume safety regardless of how secure we think we are. Always loom to double check and triple check, employing more of the security measures you mentioned like passphrase and multi sig. We should also verify open source codes and not assume other would have. Coldcard is open source and the bug went unnoticed for many years.
    - Jay -
    Title: Re: We can all learn one or two from this ColdCard incident
    Post by: Crypto Library on August 01, 2026, 10:19:36 AM
    Quote from: un_rank on August 01, 2026, 09:21:12 AM
    If you use a non custodian software wallet downloaded from th3 original website and the keys verified, with an open source software run on an airgapped device you get security similar to what you get on a hardware wallet.
    What has been emphasised for me from this incidence is we should never assume safety regardless of how secure we think we are. Always loom to double check and triple check, employing more of the security measures you mentioned like passphrase and multi sig. We should also verify open source codes and not assume other would have. Coldcard is open source and the bug went unnoticed for many years.
    - Jay -
    I may be wrong in my thinking, but after seeing some incidents with hardware wallets, I couldn't think of buying a hardware wallet.
    I have probably seen a Member on this forum before who got red tags for frauding with hardware wallets. He probably stored the passphrase of the hardware wallet with himself and later when users made deposits to the wallet, he would somehow steal it from there.
    And this new incident is already what we can see so far, about 1128.47  which is the equivalent https://bitcoindata.science/api/localprice.php?coin=bitcoin&amount=1128.47&currency=USD&hex=000000 (https://bitcoindata.science/bitcointalk-api.html#local-price) dollar. I actually feel bad for those people who were holding their bitcoins safely in hardware wallets as the ultimate protection.
    Title: Re: We can all learn one or two from this ColdCard incident
    Post by: MusaMohamed on August 01, 2026, 10:29:57 AM
    Quote from: YellowSwap on August 01, 2026, 08:19:47 AM
    The lesson we have learnt from ColdCard incident is to always consider stricter security even with our hardware wallets.
    - let's start considering passphrase with recovery seeds.
    It's applicable for software wallets, hot wallets too, and not limited to only hardware wallets.
    You can use (add) a passphrase to your wallet seed phrase and have another layer of security, but you must do it when you create a wallet. You can not do it after creating a wallet, then when you are recovering that wallet, you want to add a passphrase, this will recover a new wallet that is different with your initial wallet.
    Quote
    - let's start considering multisig if possible.
    It's right but multisig wallet will cost you more in transaction fees.

    Excerpt only. The complete copy is held offline and backs quotations on this site. The original publication remains the canonical public source.

  2. source content difference between and source content +37 -4

    Three new posts (X-ray on verification and watch-only workflows, hd49728 linking Electrum and Bitcoin Core verification guides, yhiaali3 on passphrases and distributing assets). The diff also contains SMF "Today at" relative-date rollover, which is presentation noise.

    seen · Captured here 65,551 chars
    What changed from the previous capture 41 lines
     To be honest though, setting up one is a pain to do, you need to verify the stack and keep updated on latest exploit which going to take a lot of your time, which is why I also own hardware wallet.
     Title: Re: We can all learn one or two from this ColdCard incident
     Post by: Outhue on August 06, 2026, 07:35:59 AM
    -Quote from: X-ray on Today at 03:23:13 AM
    +Quote from: X-ray on August 06, 2026, 03:23:13 AM
     Quote from: PostQuantumBTC on August 02, 2026, 12:36:35 AM
     Quote from: bitmover on August 01, 2026, 04:59:06 PM
     Airgapped computers are risky to setup and use.
     Also airgapped devices comes with extra security, if anyone tries to tamper with em they can self wiped themselves, talking for Keystone wallet though, I don't know about the rest, but if someone wants to tampered with that PC or Laptop behind your back they would successfully do it, but like I've just said, if you can handle it right then no problem, only that it's not for everyone.
     Title: Re: We can all learn one or two from this ColdCard incident
     Post by: PostQuantumBTC on August 06, 2026, 09:13:25 AM
    -Quote from: X-ray on Today at 03:23:13 AM
    +Quote from: X-ray on August 06, 2026, 03:23:13 AM
     To be honest though, setting up one is a pain to do, you need to verify the stack and keep updated on latest exploit which going to take a lot of your time, which is why I also own hardware wallet.
     I do not see any difficulty in setting up a wallet on an airgapped device, it was simple for me to do. Another thing is that if you are also not updated with exploit updates and knowing how to avoid hackers, hardware wallet can not save your coins from the hackers. Hackers also target hardware wallet users specifically.
     Title: Re: We can all learn one or two from this ColdCard incident
     Post by: bitmover on August 06, 2026, 10:12:18 AM
    -Quote from: X-ray on Today at 03:23:13 AM
    +Quote from: X-ray on August 06, 2026, 03:23:13 AM
     Quote from: PostQuantumBTC on August 02, 2026, 12:36:35 AM
     Quote from: bitmover on August 01, 2026, 04:59:06 PM
     Airgapped computers are risky to setup and use.
     When you buy a good hardware wallet (not coldcard), you are theoretically free of all those risks.
     Title: Re: We can all learn one or two from this ColdCard incident
     Post by: Z-tight on August 06, 2026, 05:14:28 PM
    -Quote from: X-ray on Today at 03:23:13 AM
    +Quote from: X-ray on August 06, 2026, 03:23:13 AM
     To be honest though, setting up one is a pain to do, you need to verify the stack and keep updated on latest exploit which going to take a lot of your time, which is why I also own hardware wallet.
     Setting up a wallet in an airgapped device is not so newbie-friendly, that's why the community recommends hardware wallets to newbies, as it is easier for them to use safely. An airgapped wallet has to be set up in a safe environment and you ought to know what you are doing, so you don't lock yourself out of your funds.
     However, if you are using a recommended wallet software, you do not need to constantly verify anything. E.G., if you set up Electrum in an airgapped device, which is a well-reviewed wallet, then you're good if you do everything correctly locally.
     Title: Re: We can all learn one or two from this ColdCard incident
     Post by: I_Anime on August 06, 2026, 07:34:03 PM
     Hardware wallet is the best to store your assets but don�t make it 100% safe there�s nothing like 100% when come to the crypto space. Hardware wallet has its own disadvantages too , like sometimes physical effects can damage it , like fire, water or you lose it (but can be recover if you have your seed phrase well save). And for those that are too lazy to write down their seed phrase and keep to a place safe and accessible, start writing it down now and stop saving it in your device just writing it down will save you a fortune .
    +Title: Re: We can all learn one or two from this ColdCard incident
    +Post by: X-ray on August 07, 2026, 01:24:02 AM
    +Quote from: PostQuantumBTC on August 06, 2026, 09:13:25 AM
    +I do not see any difficulty in setting up a wallet on an airgapped device, it was simple for me to do. Another thing is that if you are also not updated with exploit updates and knowing how to avoid hackers, hardware wallet can not save your coins from the hackers. Hackers also target hardware wallet users specifically.
    +Setting it up, installing OS etc is easy, the hard part is exactly what you mentioned, keeping up with the exploit updates and verify that you got the right files.
    +You need to verify authenticity with checksums for all the software you're going to install and search for latest exploit to make sure you're not installing vulnerable version.
    +If you want to be able to spend from the wallet inside airgapped computer, you also need to set up watch only wallet to create unsigned tx, sign it on your airgapped computer, then send it back again. If you've got time to do that, it is doable but honestly you almost certainly will crave for a simpler method but also secure which is hardware wallet.
    +Quote from: Z-tight on August 06, 2026, 05:14:28 PM
    +Setting up a wallet in an airgapped device is not so newbie-friendly, that's why the community recommends hardware wallets to newbies, as it is easier for them to use safely. An airgapped wallet has to be set up in a safe environment and you ought to know what you are doing, so you don't lock yourself out of your funds.
    +However, if you are using a recommended wallet software, you do not need to constantly verify anything. E.G., if you set up Electrum in an airgapped device, which is a well-reviewed wallet, then you're good if you do everything correctly locally.
    +Exactly and the price if compared to buying a brand new hardware wallet, almost roughly the same if you don't have old laptops lying around, even then old laptop might have security flaw on its old hardware.
    +Title: Re: We can all learn one or two from this ColdCard incident
    +Post by: hd49728 on August 07, 2026, 03:34:16 AM
    +Quote from: X-ray on Today at 01:24:02 AM
    +Setting it up, installing OS etc is easy, the hard part is exactly what you mentioned, keeping up with the exploit updates and verify that you got the right files.
    +People must avoid using cracked OS because it is very dangerous in security. If it's not feasible for them to buy it to use, they can consider to use open source OS like Linux.
    +https://linuxmint.com/
    +Quote
    +You need to verify authenticity with checksums for all the software you're going to install and search for latest exploit to make sure you're not installing vulnerable version.
    +For examples, there are guides to verify Bitcoin Core software and Electrum wallet software.
    +[GUIDE] How to Safely Download and Verify Electrum. (https://bitcointalk.org/index.php?topic=5240594.0)
    +The paranoid user's security guide for using Electrum safely. (https://bitcointalk.org/index.php?topic=5456886.0)
    +Bitcoin Core download and verification guide. (https://bitcoincore.org/en/download/)
    +Quote
    +If you want to be able to spend from the wallet inside airgapped computer, you also need to set up watch only wallet to create unsigned tx, sign it on your airgapped computer, then send it back again. If you've got time to do that, it is doable but honestly you almost certainly will crave for a simpler method but also secure which is hardware wallet.
    +This guide
    +How to create a cold storage wallet in Electrum. (https://bitcoinelectrum.com/creating-a-cold-storage-wallet-in-electrum/)
    +Not all people understand correctly about air-gapped devices and necessary steps to have an air-gapped device. Physical items that can connect the device to Internet need to be removed all.
    +[Guide] Secure air-gapped crypto wallet storage method. (https://bitcointalk.org/index.php?topic=2828437.0)
    +Title: Re: We can all learn one or two from this ColdCard incident
    +Post by: yhiaali3 on August 07, 2026, 04:04:12 AM
    +Yes, this incident taught us many lessons, the most important of which is that there is no complete security in crypto unless you take the highest security and safety standards. The biggest mistake is to think you are safe just because you use a hardware wallet.
    +The security level should be increased to the highest level by adding a passphrase to the seed, or by using multiple signatures and most importantly, not putting all your eggs in one basket. It is very important to distribute assets across more than one wallet in anticipation of the worst-case scenario.
     Powered by SMF 1.1.19 |
     SMF © 2006-2009, Simple Machines
    
    Extracted text as captured
    Bitcoin Forum
    Bitcoin => Bitcoin Discussion => Topic started by: YellowSwap on August 01, 2026, 08:19:47 AM
    Title: We can all learn one or two from this ColdCard incident
    Post by: YellowSwap on August 01, 2026, 08:19:47 AM
    I am already seeing people saying things about hardware wallets because of what happened to ColdCard, the company messed up real bad for letting people generate recovery seed using weak RNG (Random Number Generator).
    This should not in anyway makes you look less on hardware wallets still.
    The case of ColdCard was caused by a firmware bug in the hardware wallet that disabled the hardware based RNG in certain ColdCard devices.
    If I have to choose between a software wallet and a hardware wallet it will be a non-custodial hardware wallet any day.
    This kind of incidents rarely happens with hardware wallet but it's the case with software wallets.
    It's not even the software wallets itself but the devices we run the software wallets on, while the ColdCard case is still going on, some people are losing digital assets via their iPhone and androids.
    https://talkimg.com/images/2026/08/01/UomI9C.jpg
    The lesson we have learnt from ColdCard incident is to always consider stricter security even with our hardware wallets.
    - let's start considering passphrase with recovery seeds.
    - let's start considering multisig if possible.
    - let's start considering the Dice 🎲 rolling method for entropy
    While Trezor and others aren't affected, I personally don't feel it's enough to just generate a recovery seed and sit on it as your total security method, the existence of 2FA strengthen the existence of passwords for every websites, so I hope you beginners learn something from this.
    Title: Re: We can all learn one or two from this ColdCard incident
    Post by: un_rank on August 01, 2026, 09:21:12 AM
    If you use a non custodian software wallet downloaded from th3 original website and the keys verified, with an open source software run on an airgapped device you get security similar to what you get on a hardware wallet.
    What has been emphasised for me from this incidence is we should never assume safety regardless of how secure we think we are. Always loom to double check and triple check, employing more of the security measures you mentioned like passphrase and multi sig. We should also verify open source codes and not assume other would have. Coldcard is open source and the bug went unnoticed for many years.
    - Jay -
    Title: Re: We can all learn one or two from this ColdCard incident
    Post by: Crypto Library on August 01, 2026, 10:19:36 AM
    Quote from: un_rank on August 01, 2026, 09:21:12 AM
    If you use a non custodian software wallet downloaded from th3 original website and the keys verified, with an open source software run on an airgapped device you get security similar to what you get on a hardware wallet.
    What has been emphasised for me from this incidence is we should never assume safety regardless of how secure we think we are. Always loom to double check and triple check, employing more of the security measures you mentioned like passphrase and multi sig. We should also verify open source codes and not assume other would have. Coldcard is open source and the bug went unnoticed for many years.
    - Jay -
    I may be wrong in my thinking, but after seeing some incidents with hardware wallets, I couldn't think of buying a hardware wallet.
    I have probably seen a Member on this forum before who got red tags for frauding with hardware wallets. He probably stored the passphrase of the hardware wallet with himself and later when users made deposits to the wallet, he would somehow steal it from there.
    And this new incident is already what we can see so far, about 1128.47  which is the equivalent https://bitcoindata.science/api/localprice.php?coin=bitcoin&amount=1128.47&currency=USD&hex=000000 (https://bitcoindata.science/bitcointalk-api.html#local-price) dollar. I actually feel bad for those people who were holding their bitcoins safely in hardware wallets as the ultimate protection.
    Title: Re: We can all learn one or two from this ColdCard incident
    Post by: MusaMohamed on August 01, 2026, 10:29:57 AM
    Quote from: YellowSwap on August 01, 2026, 08:19:47 AM
    The lesson we have learnt from ColdCard incident is to always consider stricter security even with our hardware wallets.
    - let's start considering passphrase with recovery seeds.
    It's applicable for software wallets, hot wallets too, and not limited to only hardware wallets.
    You can use (add) a passphrase to your wallet seed phrase and have another layer of security, but you must do it when you create a wallet. You can not do it after creating a wallet, then when you are recovering that wallet, you want to add a passphrase, this will recover a new wallet that is different with your initial wallet.
    Quote
    - let's start considering multisig if possible.
    It's right but multisig wallet will cost you more in transaction fees.

    Excerpt only. The complete copy is held offline and backs quotations on this site. The original publication remains the canonical public source.

  3. source content difference between and source content +9 -0

    Two new posts: Z-tight on airgapped wallets not being newbie-friendly, and I_Anime advising users to write down seed phrases and not rely on hardware wallets being 100 percent safe.

    seen · Captured here 60,924 chars
    What changed from the previous capture 9 lines
     There is a risk of supply chain attack, accidental seed phrase leak, everything.
     The risk is exactly in the step you called a "pain to do". Setting it up. If you dont know exactly what you are doing,  you can expose yourself to those risks
     When you buy a good hardware wallet (not coldcard), you are theoretically free of all those risks.
    +Title: Re: We can all learn one or two from this ColdCard incident
    +Post by: Z-tight on August 06, 2026, 05:14:28 PM
    +Quote from: X-ray on Today at 03:23:13 AM
    +To be honest though, setting up one is a pain to do, you need to verify the stack and keep updated on latest exploit which going to take a lot of your time, which is why I also own hardware wallet.
    +Setting up a wallet in an airgapped device is not so newbie-friendly, that's why the community recommends hardware wallets to newbies, as it is easier for them to use safely. An airgapped wallet has to be set up in a safe environment and you ought to know what you are doing, so you don't lock yourself out of your funds.
    +However, if you are using a recommended wallet software, you do not need to constantly verify anything. E.G., if you set up Electrum in an airgapped device, which is a well-reviewed wallet, then you're good if you do everything correctly locally.
    +Title: Re: We can all learn one or two from this ColdCard incident
    +Post by: I_Anime on August 06, 2026, 07:34:03 PM
    +Hardware wallet is the best to store your assets but don�t make it 100% safe there�s nothing like 100% when come to the crypto space. Hardware wallet has its own disadvantages too , like sometimes physical effects can damage it , like fire, water or you lose it (but can be recover if you have your seed phrase well save). And for those that are too lazy to write down their seed phrase and keep to a place safe and accessible, start writing it down now and stop saving it in your device just writing it down will save you a fortune .
     Powered by SMF 1.1.19 |
     SMF © 2006-2009, Simple Machines
    
    Extracted text as captured
    Bitcoin Forum
    Bitcoin => Bitcoin Discussion => Topic started by: YellowSwap on August 01, 2026, 08:19:47 AM
    Title: We can all learn one or two from this ColdCard incident
    Post by: YellowSwap on August 01, 2026, 08:19:47 AM
    I am already seeing people saying things about hardware wallets because of what happened to ColdCard, the company messed up real bad for letting people generate recovery seed using weak RNG (Random Number Generator).
    This should not in anyway makes you look less on hardware wallets still.
    The case of ColdCard was caused by a firmware bug in the hardware wallet that disabled the hardware based RNG in certain ColdCard devices.
    If I have to choose between a software wallet and a hardware wallet it will be a non-custodial hardware wallet any day.
    This kind of incidents rarely happens with hardware wallet but it's the case with software wallets.
    It's not even the software wallets itself but the devices we run the software wallets on, while the ColdCard case is still going on, some people are losing digital assets via their iPhone and androids.
    https://talkimg.com/images/2026/08/01/UomI9C.jpg
    The lesson we have learnt from ColdCard incident is to always consider stricter security even with our hardware wallets.
    - let's start considering passphrase with recovery seeds.
    - let's start considering multisig if possible.
    - let's start considering the Dice 🎲 rolling method for entropy
    While Trezor and others aren't affected, I personally don't feel it's enough to just generate a recovery seed and sit on it as your total security method, the existence of 2FA strengthen the existence of passwords for every websites, so I hope you beginners learn something from this.
    Title: Re: We can all learn one or two from this ColdCard incident
    Post by: un_rank on August 01, 2026, 09:21:12 AM
    If you use a non custodian software wallet downloaded from th3 original website and the keys verified, with an open source software run on an airgapped device you get security similar to what you get on a hardware wallet.
    What has been emphasised for me from this incidence is we should never assume safety regardless of how secure we think we are. Always loom to double check and triple check, employing more of the security measures you mentioned like passphrase and multi sig. We should also verify open source codes and not assume other would have. Coldcard is open source and the bug went unnoticed for many years.
    - Jay -
    Title: Re: We can all learn one or two from this ColdCard incident
    Post by: Crypto Library on August 01, 2026, 10:19:36 AM
    Quote from: un_rank on August 01, 2026, 09:21:12 AM
    If you use a non custodian software wallet downloaded from th3 original website and the keys verified, with an open source software run on an airgapped device you get security similar to what you get on a hardware wallet.
    What has been emphasised for me from this incidence is we should never assume safety regardless of how secure we think we are. Always loom to double check and triple check, employing more of the security measures you mentioned like passphrase and multi sig. We should also verify open source codes and not assume other would have. Coldcard is open source and the bug went unnoticed for many years.
    - Jay -
    I may be wrong in my thinking, but after seeing some incidents with hardware wallets, I couldn't think of buying a hardware wallet.
    I have probably seen a Member on this forum before who got red tags for frauding with hardware wallets. He probably stored the passphrase of the hardware wallet with himself and later when users made deposits to the wallet, he would somehow steal it from there.
    And this new incident is already what we can see so far, about 1128.47  which is the equivalent https://bitcoindata.science/api/localprice.php?coin=bitcoin&amount=1128.47&currency=USD&hex=000000 (https://bitcoindata.science/bitcointalk-api.html#local-price) dollar. I actually feel bad for those people who were holding their bitcoins safely in hardware wallets as the ultimate protection.
    Title: Re: We can all learn one or two from this ColdCard incident
    Post by: MusaMohamed on August 01, 2026, 10:29:57 AM
    Quote from: YellowSwap on August 01, 2026, 08:19:47 AM
    The lesson we have learnt from ColdCard incident is to always consider stricter security even with our hardware wallets.
    - let's start considering passphrase with recovery seeds.
    It's applicable for software wallets, hot wallets too, and not limited to only hardware wallets.
    You can use (add) a passphrase to your wallet seed phrase and have another layer of security, but you must do it when you create a wallet. You can not do it after creating a wallet, then when you are recovering that wallet, you want to add a passphrase, this will recover a new wallet that is different with your initial wallet.
    Quote
    - let's start considering multisig if possible.
    It's right but multisig wallet will cost you more in transaction fees.

    Excerpt only. The complete copy is held offline and backs quotations on this site. The original publication remains the canonical public source.

  4. source content difference between and source content +15 -0

    One new post by bitmover arguing the risk of airgapped setups lies in the setup step itself, and that a good hardware wallet ("not coldcard") is theoretically free of those risks.

    seen · Captured here 59,348 chars
    What changed from the previous capture 15 lines
     Quote from: X-ray on Today at 03:23:13 AM
     To be honest though, setting up one is a pain to do, you need to verify the stack and keep updated on latest exploit which going to take a lot of your time, which is why I also own hardware wallet.
     I do not see any difficulty in setting up a wallet on an airgapped device, it was simple for me to do. Another thing is that if you are also not updated with exploit updates and knowing how to avoid hackers, hardware wallet can not save your coins from the hackers. Hackers also target hardware wallet users specifically.
    +Title: Re: We can all learn one or two from this ColdCard incident
    +Post by: bitmover on August 06, 2026, 10:12:18 AM
    +Quote from: X-ray on Today at 03:23:13 AM
    +Quote from: PostQuantumBTC on August 02, 2026, 12:36:35 AM
    +Quote from: bitmover on August 01, 2026, 04:59:06 PM
    +Airgapped computers are risky to setup and use.
    +How is it risky?
    +Airgapped computers means you are not sending anything out of the wallet in a way that you can be affected. If you have airgapped wallet, you are safe so far it stayed airgapped but stay away from crypto clipper.
    +But I will likely if you correct me because my understanding about the cold airgapped device may be limited.
    +I've used airgapped computers for my wallet for quite sometime, I don't find it any more riskier than hardware wallet. You installed latest OS to an airgapped computer, you never connect it to the Internet and the wallet stays on the computer.
    +No supply chain attack which hardware wallet could be infected from, no accidental seed phrase leak because the internet isn't there in the first place, your wallet stay safe until the day you decided to withdraw it. I think it's robust enough solution for me, but it's just my opinion.
    +To be honest though, setting up one is a pain to do, you need to verify the stack and keep updated on latest exploit which going to take a lot of your time, which is why I also own hardware wallet.
    +There is a risk of supply chain attack, accidental seed phrase leak, everything.
    +The risk is exactly in the step you called a "pain to do". Setting it up. If you dont know exactly what you are doing,  you can expose yourself to those risks
    +When you buy a good hardware wallet (not coldcard), you are theoretically free of all those risks.
     Powered by SMF 1.1.19 |
     SMF © 2006-2009, Simple Machines
    
    Extracted text as captured
    Bitcoin Forum
    Bitcoin => Bitcoin Discussion => Topic started by: YellowSwap on August 01, 2026, 08:19:47 AM
    Title: We can all learn one or two from this ColdCard incident
    Post by: YellowSwap on August 01, 2026, 08:19:47 AM
    I am already seeing people saying things about hardware wallets because of what happened to ColdCard, the company messed up real bad for letting people generate recovery seed using weak RNG (Random Number Generator).
    This should not in anyway makes you look less on hardware wallets still.
    The case of ColdCard was caused by a firmware bug in the hardware wallet that disabled the hardware based RNG in certain ColdCard devices.
    If I have to choose between a software wallet and a hardware wallet it will be a non-custodial hardware wallet any day.
    This kind of incidents rarely happens with hardware wallet but it's the case with software wallets.
    It's not even the software wallets itself but the devices we run the software wallets on, while the ColdCard case is still going on, some people are losing digital assets via their iPhone and androids.
    https://talkimg.com/images/2026/08/01/UomI9C.jpg
    The lesson we have learnt from ColdCard incident is to always consider stricter security even with our hardware wallets.
    - let's start considering passphrase with recovery seeds.
    - let's start considering multisig if possible.
    - let's start considering the Dice 🎲 rolling method for entropy
    While Trezor and others aren't affected, I personally don't feel it's enough to just generate a recovery seed and sit on it as your total security method, the existence of 2FA strengthen the existence of passwords for every websites, so I hope you beginners learn something from this.
    Title: Re: We can all learn one or two from this ColdCard incident
    Post by: un_rank on August 01, 2026, 09:21:12 AM
    If you use a non custodian software wallet downloaded from th3 original website and the keys verified, with an open source software run on an airgapped device you get security similar to what you get on a hardware wallet.
    What has been emphasised for me from this incidence is we should never assume safety regardless of how secure we think we are. Always loom to double check and triple check, employing more of the security measures you mentioned like passphrase and multi sig. We should also verify open source codes and not assume other would have. Coldcard is open source and the bug went unnoticed for many years.
    - Jay -
    Title: Re: We can all learn one or two from this ColdCard incident
    Post by: Crypto Library on August 01, 2026, 10:19:36 AM
    Quote from: un_rank on August 01, 2026, 09:21:12 AM
    If you use a non custodian software wallet downloaded from th3 original website and the keys verified, with an open source software run on an airgapped device you get security similar to what you get on a hardware wallet.
    What has been emphasised for me from this incidence is we should never assume safety regardless of how secure we think we are. Always loom to double check and triple check, employing more of the security measures you mentioned like passphrase and multi sig. We should also verify open source codes and not assume other would have. Coldcard is open source and the bug went unnoticed for many years.
    - Jay -
    I may be wrong in my thinking, but after seeing some incidents with hardware wallets, I couldn't think of buying a hardware wallet.
    I have probably seen a Member on this forum before who got red tags for frauding with hardware wallets. He probably stored the passphrase of the hardware wallet with himself and later when users made deposits to the wallet, he would somehow steal it from there.
    And this new incident is already what we can see so far, about 1128.47  which is the equivalent https://bitcoindata.science/api/localprice.php?coin=bitcoin&amount=1128.47&currency=USD&hex=000000 (https://bitcoindata.science/bitcointalk-api.html#local-price) dollar. I actually feel bad for those people who were holding their bitcoins safely in hardware wallets as the ultimate protection.
    Title: Re: We can all learn one or two from this ColdCard incident
    Post by: MusaMohamed on August 01, 2026, 10:29:57 AM
    Quote from: YellowSwap on August 01, 2026, 08:19:47 AM
    The lesson we have learnt from ColdCard incident is to always consider stricter security even with our hardware wallets.
    - let's start considering passphrase with recovery seeds.
    It's applicable for software wallets, hot wallets too, and not limited to only hardware wallets.
    You can use (add) a passphrase to your wallet seed phrase and have another layer of security, but you must do it when you create a wallet. You can not do it after creating a wallet, then when you are recovering that wallet, you want to add a passphrase, this will recover a new wallet that is different with your initial wallet.
    Quote
    - let's start considering multisig if possible.
    It's right but multisig wallet will cost you more in transaction fees.

    Excerpt only. The complete copy is held offline and backs quotations on this site. The original publication remains the canonical public source.

  5. source content difference between and source content +19 -0

    Two new posts: Outhue on airgapped-computer setups not suiting people who do not live alone, and PostQuantumBTC saying airgapped setup is simple and hardware wallet users are specifically targeted.

    seen · Captured here 57,622 chars
    What changed from the previous capture 19 lines
     I've used airgapped computers for my wallet for quite sometime, I don't find it any more riskier than hardware wallet. You installed latest OS to an airgapped computer, you never connect it to the Internet and the wallet stays on the computer.
     No supply chain attack which hardware wallet could be infected from, no accidental seed phrase leak because the internet isn't there in the first place, your wallet stay safe until the day you decided to withdraw it. I think it's robust enough solution for me, but it's just my opinion.
     To be honest though, setting up one is a pain to do, you need to verify the stack and keep updated on latest exploit which going to take a lot of your time, which is why I also own hardware wallet.
    +Title: Re: We can all learn one or two from this ColdCard incident
    +Post by: Outhue on August 06, 2026, 07:35:59 AM
    +Quote from: X-ray on Today at 03:23:13 AM
    +Quote from: PostQuantumBTC on August 02, 2026, 12:36:35 AM
    +Quote from: bitmover on August 01, 2026, 04:59:06 PM
    +Airgapped computers are risky to setup and use.
    +How is it risky?
    +Airgapped computers means you are not sending anything out of the wallet in a way that you can be affected. If you have airgapped wallet, you are safe so far it stayed airgapped but stay away from crypto clipper.
    +But I will likely if you correct me because my understanding about the cold airgapped device may be limited.
    +I've used airgapped computers for my wallet for quite sometime, I don't find it any more riskier than hardware wallet. You installed latest OS to an airgapped computer, you never connect it to the Internet and the wallet stays on the computer.
    +No supply chain attack which hardware wallet could be infected from, no accidental seed phrase leak because the internet isn't there in the first place, your wallet stay safe until the day you decided to withdraw it. I think it's robust enough solution for me, but it's just my opinion.
    +To be honest though, setting up one is a pain to do, you need to verify the stack and keep updated on latest exploit which going to take a lot of your time, which is why I also own hardware wallet.
    +Let's say that you can handle this perfectly, I am not new to Bitcoin but I can't do this same thing that you are doing, because of few reasons like I am not living alone, my computer isn't private and others, you can go out and someone startup your computer and connect it to the internet, unless you live alone all by yourself.
    +Also airgapped devices comes with extra security, if anyone tries to tamper with em they can self wiped themselves, talking for Keystone wallet though, I don't know about the rest, but if someone wants to tampered with that PC or Laptop behind your back they would successfully do it, but like I've just said, if you can handle it right then no problem, only that it's not for everyone.
    +Title: Re: We can all learn one or two from this ColdCard incident
    +Post by: PostQuantumBTC on August 06, 2026, 09:13:25 AM
    +Quote from: X-ray on Today at 03:23:13 AM
    +To be honest though, setting up one is a pain to do, you need to verify the stack and keep updated on latest exploit which going to take a lot of your time, which is why I also own hardware wallet.
    +I do not see any difficulty in setting up a wallet on an airgapped device, it was simple for me to do. Another thing is that if you are also not updated with exploit updates and knowing how to avoid hackers, hardware wallet can not save your coins from the hackers. Hackers also target hardware wallet users specifically.
     Powered by SMF 1.1.19 |
     SMF © 2006-2009, Simple Machines
    
    Extracted text as captured
    Bitcoin Forum
    Bitcoin => Bitcoin Discussion => Topic started by: YellowSwap on August 01, 2026, 08:19:47 AM
    Title: We can all learn one or two from this ColdCard incident
    Post by: YellowSwap on August 01, 2026, 08:19:47 AM
    I am already seeing people saying things about hardware wallets because of what happened to ColdCard, the company messed up real bad for letting people generate recovery seed using weak RNG (Random Number Generator).
    This should not in anyway makes you look less on hardware wallets still.
    The case of ColdCard was caused by a firmware bug in the hardware wallet that disabled the hardware based RNG in certain ColdCard devices.
    If I have to choose between a software wallet and a hardware wallet it will be a non-custodial hardware wallet any day.
    This kind of incidents rarely happens with hardware wallet but it's the case with software wallets.
    It's not even the software wallets itself but the devices we run the software wallets on, while the ColdCard case is still going on, some people are losing digital assets via their iPhone and androids.
    https://talkimg.com/images/2026/08/01/UomI9C.jpg
    The lesson we have learnt from ColdCard incident is to always consider stricter security even with our hardware wallets.
    - let's start considering passphrase with recovery seeds.
    - let's start considering multisig if possible.
    - let's start considering the Dice 🎲 rolling method for entropy
    While Trezor and others aren't affected, I personally don't feel it's enough to just generate a recovery seed and sit on it as your total security method, the existence of 2FA strengthen the existence of passwords for every websites, so I hope you beginners learn something from this.
    Title: Re: We can all learn one or two from this ColdCard incident
    Post by: un_rank on August 01, 2026, 09:21:12 AM
    If you use a non custodian software wallet downloaded from th3 original website and the keys verified, with an open source software run on an airgapped device you get security similar to what you get on a hardware wallet.
    What has been emphasised for me from this incidence is we should never assume safety regardless of how secure we think we are. Always loom to double check and triple check, employing more of the security measures you mentioned like passphrase and multi sig. We should also verify open source codes and not assume other would have. Coldcard is open source and the bug went unnoticed for many years.
    - Jay -
    Title: Re: We can all learn one or two from this ColdCard incident
    Post by: Crypto Library on August 01, 2026, 10:19:36 AM
    Quote from: un_rank on August 01, 2026, 09:21:12 AM
    If you use a non custodian software wallet downloaded from th3 original website and the keys verified, with an open source software run on an airgapped device you get security similar to what you get on a hardware wallet.
    What has been emphasised for me from this incidence is we should never assume safety regardless of how secure we think we are. Always loom to double check and triple check, employing more of the security measures you mentioned like passphrase and multi sig. We should also verify open source codes and not assume other would have. Coldcard is open source and the bug went unnoticed for many years.
    - Jay -
    I may be wrong in my thinking, but after seeing some incidents with hardware wallets, I couldn't think of buying a hardware wallet.
    I have probably seen a Member on this forum before who got red tags for frauding with hardware wallets. He probably stored the passphrase of the hardware wallet with himself and later when users made deposits to the wallet, he would somehow steal it from there.
    And this new incident is already what we can see so far, about 1128.47  which is the equivalent https://bitcoindata.science/api/localprice.php?coin=bitcoin&amount=1128.47&currency=USD&hex=000000 (https://bitcoindata.science/bitcointalk-api.html#local-price) dollar. I actually feel bad for those people who were holding their bitcoins safely in hardware wallets as the ultimate protection.
    Title: Re: We can all learn one or two from this ColdCard incident
    Post by: MusaMohamed on August 01, 2026, 10:29:57 AM
    Quote from: YellowSwap on August 01, 2026, 08:19:47 AM
    The lesson we have learnt from ColdCard incident is to always consider stricter security even with our hardware wallets.
    - let's start considering passphrase with recovery seeds.
    It's applicable for software wallets, hot wallets too, and not limited to only hardware wallets.
    You can use (add) a passphrase to your wallet seed phrase and have another layer of security, but you must do it when you create a wallet. You can not do it after creating a wallet, then when you are recovering that wallet, you want to add a passphrase, this will recover a new wallet that is different with your initial wallet.
    Quote
    - let's start considering multisig if possible.
    It's right but multisig wallet will cost you more in transaction fees.

    Excerpt only. The complete copy is held offline and backs quotations on this site. The original publication remains the canonical public source.

  6. source content difference between and source content +11 -0

    A participant added a discussion of using an air-gapped computer, describing its perceived benefits and setup burden.

    seen · Captured here 54,835 chars
    What changed from the previous capture 11 lines
     It is just to be better equipped with better security knowledge than to try to play it safe and still have loopholes that can be manipulated anytime.
     We have learnt a great deal from this coldcard incident and I must say I may try on my own to explore safer options that includes security features and diversity strategies Incase a similar or new kind of coldcard issue arises again.
     You are correct to point this out but I don't think it is reasonable to expect normal users to know these kinds of things. Maybe when we were promoting hardware wallets as the best solutions to the general public we have together made a mistake by not sharing the issues that could happen with it. I have had these wallets for years, and I consider myself a bit more security conscious than the average person but nothing special. I have never considered that my wallet could be hacked this way even if it was a very obvious possibility, I have considered all kinds of offline hacks, attacks by the vendor or through the internet but not a complete failure in the random generation where you are defenseless if you have set up the wallet the right way. I also don't think the regular advice was ever that you should in all cases add a passphrase to a hardware wallet, it was suggested only in some specific cases to deal with some sort of attacks or to add more protection. I think one lesson from this would be that adding passphrases to wallets should be a regular thing, and it does not even have to be extremely long but it would provide you enough time to survive the first wave attacks and get your keys out before some kind of brute force attack is successful against it.
    +Title: Re: We can all learn one or two from this ColdCard incident
    +Post by: X-ray on August 06, 2026, 03:23:13 AM
    +Quote from: PostQuantumBTC on August 02, 2026, 12:36:35 AM
    +Quote from: bitmover on August 01, 2026, 04:59:06 PM
    +Airgapped computers are risky to setup and use.
    +How is it risky?
    +Airgapped computers means you are not sending anything out of the wallet in a way that you can be affected. If you have airgapped wallet, you are safe so far it stayed airgapped but stay away from crypto clipper.
    +But I will likely if you correct me because my understanding about the cold airgapped device may be limited.
    +I've used airgapped computers for my wallet for quite sometime, I don't find it any more riskier than hardware wallet. You installed latest OS to an airgapped computer, you never connect it to the Internet and the wallet stays on the computer.
    +No supply chain attack which hardware wallet could be infected from, no accidental seed phrase leak because the internet isn't there in the first place, your wallet stay safe until the day you decided to withdraw it. I think it's robust enough solution for me, but it's just my opinion.
    +To be honest though, setting up one is a pain to do, you need to verify the stack and keep updated on latest exploit which going to take a lot of your time, which is why I also own hardware wallet.
     Powered by SMF 1.1.19 |
     SMF © 2006-2009, Simple Machines
    
    Extracted text as captured
    Bitcoin Forum
    Bitcoin => Bitcoin Discussion => Topic started by: YellowSwap on August 01, 2026, 08:19:47 AM
    Title: We can all learn one or two from this ColdCard incident
    Post by: YellowSwap on August 01, 2026, 08:19:47 AM
    I am already seeing people saying things about hardware wallets because of what happened to ColdCard, the company messed up real bad for letting people generate recovery seed using weak RNG (Random Number Generator).
    This should not in anyway makes you look less on hardware wallets still.
    The case of ColdCard was caused by a firmware bug in the hardware wallet that disabled the hardware based RNG in certain ColdCard devices.
    If I have to choose between a software wallet and a hardware wallet it will be a non-custodial hardware wallet any day.
    This kind of incidents rarely happens with hardware wallet but it's the case with software wallets.
    It's not even the software wallets itself but the devices we run the software wallets on, while the ColdCard case is still going on, some people are losing digital assets via their iPhone and androids.
    https://talkimg.com/images/2026/08/01/UomI9C.jpg
    The lesson we have learnt from ColdCard incident is to always consider stricter security even with our hardware wallets.
    - let's start considering passphrase with recovery seeds.
    - let's start considering multisig if possible.
    - let's start considering the Dice 🎲 rolling method for entropy
    While Trezor and others aren't affected, I personally don't feel it's enough to just generate a recovery seed and sit on it as your total security method, the existence of 2FA strengthen the existence of passwords for every websites, so I hope you beginners learn something from this.
    Title: Re: We can all learn one or two from this ColdCard incident
    Post by: un_rank on August 01, 2026, 09:21:12 AM
    If you use a non custodian software wallet downloaded from th3 original website and the keys verified, with an open source software run on an airgapped device you get security similar to what you get on a hardware wallet.
    What has been emphasised for me from this incidence is we should never assume safety regardless of how secure we think we are. Always loom to double check and triple check, employing more of the security measures you mentioned like passphrase and multi sig. We should also verify open source codes and not assume other would have. Coldcard is open source and the bug went unnoticed for many years.
    - Jay -
    Title: Re: We can all learn one or two from this ColdCard incident
    Post by: Crypto Library on August 01, 2026, 10:19:36 AM
    Quote from: un_rank on August 01, 2026, 09:21:12 AM
    If you use a non custodian software wallet downloaded from th3 original website and the keys verified, with an open source software run on an airgapped device you get security similar to what you get on a hardware wallet.
    What has been emphasised for me from this incidence is we should never assume safety regardless of how secure we think we are. Always loom to double check and triple check, employing more of the security measures you mentioned like passphrase and multi sig. We should also verify open source codes and not assume other would have. Coldcard is open source and the bug went unnoticed for many years.
    - Jay -
    I may be wrong in my thinking, but after seeing some incidents with hardware wallets, I couldn't think of buying a hardware wallet.
    I have probably seen a Member on this forum before who got red tags for frauding with hardware wallets. He probably stored the passphrase of the hardware wallet with himself and later when users made deposits to the wallet, he would somehow steal it from there.
    And this new incident is already what we can see so far, about 1128.47  which is the equivalent https://bitcoindata.science/api/localprice.php?coin=bitcoin&amount=1128.47&currency=USD&hex=000000 (https://bitcoindata.science/bitcointalk-api.html#local-price) dollar. I actually feel bad for those people who were holding their bitcoins safely in hardware wallets as the ultimate protection.
    Title: Re: We can all learn one or two from this ColdCard incident
    Post by: MusaMohamed on August 01, 2026, 10:29:57 AM
    Quote from: YellowSwap on August 01, 2026, 08:19:47 AM
    The lesson we have learnt from ColdCard incident is to always consider stricter security even with our hardware wallets.
    - let's start considering passphrase with recovery seeds.
    It's applicable for software wallets, hot wallets too, and not limited to only hardware wallets.
    You can use (add) a passphrase to your wallet seed phrase and have another layer of security, but you must do it when you create a wallet. You can not do it after creating a wallet, then when you are recovering that wallet, you want to add a passphrase, this will recover a new wallet that is different with your initial wallet.
    Quote
    - let's start considering multisig if possible.
    It's right but multisig wallet will cost you more in transaction fees.

    Excerpt only. The complete copy is held offline and backs quotations on this site. The original publication remains the canonical public source.

  7. source content difference between and source content +6 -0

    The BitcoinTalk thread gained a post arguing ordinary users cannot reasonably be expected to anticipate this attack class.

    seen · Captured here 53,493 chars
    What changed from the previous capture 6 lines
     Post by: dansus021 on August 04, 2026, 09:19:52 AM
     Hardware wallets are still vastly superior to keeping funds on internet-connected phones or computers, but the ColdCard RNG issue proves that relying on a single device, vendor, or internal generator leaves a single point of failure.
     In my opinion the best takeaway for anyone serious about security is to take entropy into your own hands by rolling physical dice, adding a strong BIP-39 passphrase, and moving toward a multi-vendor multisig setup so a single software or firmware bug never puts your entire stack at risk. Combine keys from two or three different hardware manufacturers Even if one hardware manufacturer ships flawed firmware or a compromised RNG, an attacker holding a single compromised key cannot spend your funds without a second signature from an unaffected device made by a completely different team.
    +Title: Re: We can all learn one or two from this ColdCard incident
    +Post by: Dogedegen on August 04, 2026, 07:22:08 PM
    +Quote from: Cryptomultiplier on August 03, 2026, 09:25:09 PM
    +It is just to be better equipped with better security knowledge than to try to play it safe and still have loopholes that can be manipulated anytime.
    +We have learnt a great deal from this coldcard incident and I must say I may try on my own to explore safer options that includes security features and diversity strategies Incase a similar or new kind of coldcard issue arises again.
    +You are correct to point this out but I don't think it is reasonable to expect normal users to know these kinds of things. Maybe when we were promoting hardware wallets as the best solutions to the general public we have together made a mistake by not sharing the issues that could happen with it. I have had these wallets for years, and I consider myself a bit more security conscious than the average person but nothing special. I have never considered that my wallet could be hacked this way even if it was a very obvious possibility, I have considered all kinds of offline hacks, attacks by the vendor or through the internet but not a complete failure in the random generation where you are defenseless if you have set up the wallet the right way. I also don't think the regular advice was ever that you should in all cases add a passphrase to a hardware wallet, it was suggested only in some specific cases to deal with some sort of attacks or to add more protection. I think one lesson from this would be that adding passphrases to wallets should be a regular thing, and it does not even have to be extremely long but it would provide you enough time to survive the first wave attacks and get your keys out before some kind of brute force attack is successful against it.
     Powered by SMF 1.1.19 |
     SMF © 2006-2009, Simple Machines
    
    Extracted text as captured
    Bitcoin Forum
    Bitcoin => Bitcoin Discussion => Topic started by: YellowSwap on August 01, 2026, 08:19:47 AM
    Title: We can all learn one or two from this ColdCard incident
    Post by: YellowSwap on August 01, 2026, 08:19:47 AM
    I am already seeing people saying things about hardware wallets because of what happened to ColdCard, the company messed up real bad for letting people generate recovery seed using weak RNG (Random Number Generator).
    This should not in anyway makes you look less on hardware wallets still.
    The case of ColdCard was caused by a firmware bug in the hardware wallet that disabled the hardware based RNG in certain ColdCard devices.
    If I have to choose between a software wallet and a hardware wallet it will be a non-custodial hardware wallet any day.
    This kind of incidents rarely happens with hardware wallet but it's the case with software wallets.
    It's not even the software wallets itself but the devices we run the software wallets on, while the ColdCard case is still going on, some people are losing digital assets via their iPhone and androids.
    https://talkimg.com/images/2026/08/01/UomI9C.jpg
    The lesson we have learnt from ColdCard incident is to always consider stricter security even with our hardware wallets.
    - let's start considering passphrase with recovery seeds.
    - let's start considering multisig if possible.
    - let's start considering the Dice 🎲 rolling method for entropy
    While Trezor and others aren't affected, I personally don't feel it's enough to just generate a recovery seed and sit on it as your total security method, the existence of 2FA strengthen the existence of passwords for every websites, so I hope you beginners learn something from this.
    Title: Re: We can all learn one or two from this ColdCard incident
    Post by: un_rank on August 01, 2026, 09:21:12 AM
    If you use a non custodian software wallet downloaded from th3 original website and the keys verified, with an open source software run on an airgapped device you get security similar to what you get on a hardware wallet.
    What has been emphasised for me from this incidence is we should never assume safety regardless of how secure we think we are. Always loom to double check and triple check, employing more of the security measures you mentioned like passphrase and multi sig. We should also verify open source codes and not assume other would have. Coldcard is open source and the bug went unnoticed for many years.
    - Jay -
    Title: Re: We can all learn one or two from this ColdCard incident
    Post by: Crypto Library on August 01, 2026, 10:19:36 AM
    Quote from: un_rank on August 01, 2026, 09:21:12 AM
    If you use a non custodian software wallet downloaded from th3 original website and the keys verified, with an open source software run on an airgapped device you get security similar to what you get on a hardware wallet.
    What has been emphasised for me from this incidence is we should never assume safety regardless of how secure we think we are. Always loom to double check and triple check, employing more of the security measures you mentioned like passphrase and multi sig. We should also verify open source codes and not assume other would have. Coldcard is open source and the bug went unnoticed for many years.
    - Jay -
    I may be wrong in my thinking, but after seeing some incidents with hardware wallets, I couldn't think of buying a hardware wallet.
    I have probably seen a Member on this forum before who got red tags for frauding with hardware wallets. He probably stored the passphrase of the hardware wallet with himself and later when users made deposits to the wallet, he would somehow steal it from there.
    And this new incident is already what we can see so far, about 1128.47  which is the equivalent https://bitcoindata.science/api/localprice.php?coin=bitcoin&amount=1128.47&currency=USD&hex=000000 (https://bitcoindata.science/bitcointalk-api.html#local-price) dollar. I actually feel bad for those people who were holding their bitcoins safely in hardware wallets as the ultimate protection.
    Title: Re: We can all learn one or two from this ColdCard incident
    Post by: MusaMohamed on August 01, 2026, 10:29:57 AM
    Quote from: YellowSwap on August 01, 2026, 08:19:47 AM
    The lesson we have learnt from ColdCard incident is to always consider stricter security even with our hardware wallets.
    - let's start considering passphrase with recovery seeds.
    It's applicable for software wallets, hot wallets too, and not limited to only hardware wallets.
    You can use (add) a passphrase to your wallet seed phrase and have another layer of security, but you must do it when you create a wallet. You can not do it after creating a wallet, then when you are recovering that wallet, you want to add a passphrase, this will recover a new wallet that is different with your initial wallet.
    Quote
    - let's start considering multisig if possible.
    It's right but multisig wallet will cost you more in transaction fees.

    Excerpt only. The complete copy is held offline and backs quotations on this site. The original publication remains the canonical public source.

  8. Earliest copy held
    seen · Captured here 51,651 chars
    Extracted text as captured
    Bitcoin Forum
    Bitcoin => Bitcoin Discussion => Topic started by: YellowSwap on August 01, 2026, 08:19:47 AM
    Title: We can all learn one or two from this ColdCard incident
    Post by: YellowSwap on August 01, 2026, 08:19:47 AM
    I am already seeing people saying things about hardware wallets because of what happened to ColdCard, the company messed up real bad for letting people generate recovery seed using weak RNG (Random Number Generator).
    This should not in anyway makes you look less on hardware wallets still.
    The case of ColdCard was caused by a firmware bug in the hardware wallet that disabled the hardware based RNG in certain ColdCard devices.
    If I have to choose between a software wallet and a hardware wallet it will be a non-custodial hardware wallet any day.
    This kind of incidents rarely happens with hardware wallet but it's the case with software wallets.
    It's not even the software wallets itself but the devices we run the software wallets on, while the ColdCard case is still going on, some people are losing digital assets via their iPhone and androids.
    https://talkimg.com/images/2026/08/01/UomI9C.jpg
    The lesson we have learnt from ColdCard incident is to always consider stricter security even with our hardware wallets.
    - let's start considering passphrase with recovery seeds.
    - let's start considering multisig if possible.
    - let's start considering the Dice 🎲 rolling method for entropy
    While Trezor and others aren't affected, I personally don't feel it's enough to just generate a recovery seed and sit on it as your total security method, the existence of 2FA strengthen the existence of passwords for every websites, so I hope you beginners learn something from this.
    Title: Re: We can all learn one or two from this ColdCard incident
    Post by: un_rank on August 01, 2026, 09:21:12 AM
    If you use a non custodian software wallet downloaded from th3 original website and the keys verified, with an open source software run on an airgapped device you get security similar to what you get on a hardware wallet.
    What has been emphasised for me from this incidence is we should never assume safety regardless of how secure we think we are. Always loom to double check and triple check, employing more of the security measures you mentioned like passphrase and multi sig. We should also verify open source codes and not assume other would have. Coldcard is open source and the bug went unnoticed for many years.
    - Jay -
    Title: Re: We can all learn one or two from this ColdCard incident
    Post by: Crypto Library on August 01, 2026, 10:19:36 AM
    Quote from: un_rank on August 01, 2026, 09:21:12 AM
    If you use a non custodian software wallet downloaded from th3 original website and the keys verified, with an open source software run on an airgapped device you get security similar to what you get on a hardware wallet.
    What has been emphasised for me from this incidence is we should never assume safety regardless of how secure we think we are. Always loom to double check and triple check, employing more of the security measures you mentioned like passphrase and multi sig. We should also verify open source codes and not assume other would have. Coldcard is open source and the bug went unnoticed for many years.
    - Jay -
    I may be wrong in my thinking, but after seeing some incidents with hardware wallets, I couldn't think of buying a hardware wallet.
    I have probably seen a Member on this forum before who got red tags for frauding with hardware wallets. He probably stored the passphrase of the hardware wallet with himself and later when users made deposits to the wallet, he would somehow steal it from there.
    And this new incident is already what we can see so far, about 1128.47  which is the equivalent https://bitcoindata.science/api/localprice.php?coin=bitcoin&amount=1128.47&currency=USD&hex=000000 (https://bitcoindata.science/bitcointalk-api.html#local-price) dollar. I actually feel bad for those people who were holding their bitcoins safely in hardware wallets as the ultimate protection.
    Title: Re: We can all learn one or two from this ColdCard incident
    Post by: MusaMohamed on August 01, 2026, 10:29:57 AM
    Quote from: YellowSwap on August 01, 2026, 08:19:47 AM
    The lesson we have learnt from ColdCard incident is to always consider stricter security even with our hardware wallets.
    - let's start considering passphrase with recovery seeds.
    It's applicable for software wallets, hot wallets too, and not limited to only hardware wallets.
    You can use (add) a passphrase to your wallet seed phrase and have another layer of security, but you must do it when you create a wallet. You can not do it after creating a wallet, then when you are recovering that wallet, you want to add a passphrase, this will recover a new wallet that is different with your initial wallet.
    Quote
    - let's start considering multisig if possible.
    It's right but multisig wallet will cost you more in transaction fees.

    Excerpt only. The complete copy is held offline and backs quotations on this site. The original publication remains the canonical public source.

1 presentation-noise difference. Sidebar, ticker and other page chrome churn that our review classified as not being a change to what the source says.
  • +4 -4 Only Bitcointalk's relative quote dates rolled from Today to absolute dates.
How to check this yourself

The excerpts and plain unified diffs above show the text this project held and how it changed. To verify a quotation, compare it against the page itself or against the Internet Archive's copies, which are independent of this project.

Complete captures are held offline rather than mirrored here, so this page shows diffs and excerpts. If a quotation is ever disputed, the full copy can be produced. Ask.