COLDCARD RNG incident the public record, collected and explained
Informational only, and this site never asks for your seed words. details

Informational only. This is an open source collection of what others have published about the incident, together with an explanation of it. It is not financial, security or legal advice, and not a substitute for professional advice about your own situation. It is not affiliated with, endorsed by, or speaking for Coinkite. Material is attributed and quoted as published; where sources disagree their scenarios are kept separate with their assumptions rather than reconciled into one answer. Everything is meant to be checked against the linked evidence rather than taken on trust. Act on your own judgement about a particular situation. Editorial standards and corrections.

Do not disclose recovery material to a website, form, message or support account. This site never asks for it, and contributions containing recovery words or private keys are not accepted.

Bitcoin Well design-revolution essay

bitcoinwell-2085381011769348122

https://x.com/bitcoinwell/status/2085381011769348122

Captured screenshot of the post by @bitcoinwell, posted 6 Aug 2026, 15:02 UTC
@bitcoinwell posted captured full-size capture → original post →
Author
@bitcoinwell
Organisation
independent
Evidence role
social statement
Posted
Capture status
capture held

A long post from the company account of Bitcoin Well, a bitcoin exchange and self-custody business, arguing that the answer to the incident is better-designed self-custody rather than surrendering keys, and linking its own blog essay "Why Bitcoin Needs a Design Revolution". It restates the incident as roughly 594 bitcoin, about US$38 million, from some 500 wallets in 25 minutes on 30 July, traced by Block to a one-line build error shipped in March 2021 that skipped the hardware random number generator in favour of software randomness seeded from the chip's serial number and a timer, leaving a pool of about four billion, with suspected related losses nearer US$116 million. It tells Mk2 and Mk3 owners to move to a fresh seed made on a non-COLDCARD device, says Bitkey, Trezor and Ledger were unaffected, and argues COLDCARD's austerity did no security work at all. The company is promoting its own essay and product direction while praising a competing vendor's device, so the argument carries a commercial interest. The figures are this author's restatement of numbers published by others and the design argument is his own; neither is verified here.

This post is registered as evidence and has a locally held capture. The original remains the canonical publication.

How to check this yourself

Compare the screenshot or a quotation against the original while it is available.