COLDCARD RNG incident the public record, collected and explained
Informational only, and this site never asks for your seed words. details

Informational only. This is an open source collection of what others have published about the incident, together with an explanation of it. It is not financial, security or legal advice, and not a substitute for professional advice about your own situation. It is not affiliated with, endorsed by, or speaking for Coinkite. Material is attributed and quoted as published; where sources disagree their scenarios are kept separate with their assumptions rather than reconciled into one answer. Everything is meant to be checked against the linked evidence rather than taken on trust. Act on your own judgement about a particular situation. Editorial standards and corrections.

Do not disclose recovery material to a website, form, message or support account. This site never asks for it, and contributions containing recovery words or private keys are not accepted.

Casa Coldcard troubleshooting support page

casa-support-coldcard-troubleshooting

https://support.casa.io/knowledge/coldcard-troubleshooting

Latest reviewed change

source content difference between and

Casa added a security advisory banner (updated August 1, 2026) warning of the Coldcard seed-generation flaw and recommending the device be replaced, and the page date moved from March 4, 2026 to August 6, 2026.

seen +2 -1 full history below
 Help Center
 Hardware devices
 Coldcard
-March 4, 2026
+August 6, 2026
 Coldcard troubleshooting
 Coldcard Mk 3+ hardware devices are compatible with Casa multisig vaults.
+⚠️ Security Advisory (Updated August 1, 2026): Coinkite has identified a seed-generation flaw affecting certain Coldcard firmware versions. If you generated your seed on affected firmware, your funds may be at risk. We do recommend replacing this device as soon as you are able.

First lines only. The complete diff is in the timeline below.

Organisation
Casa
Evidence role
Custody guidance
Published
not established
Source changes
1
Detected differences
1
Unreviewed
0
Copies held
2

Casa's standing Coldcard support document. As of 3 Aug 2026 Casa has published no blog post on the incident; its only public statements are two X posts (casa-incident-guidance, nneuman-casa-migration-video). Registered as the page where written guidance would land, so any edit is recorded.

Every check is recorded, including checks that found no text change. A detected edit is therefore bounded between two checks. The publisher's exact save time is not observable from this record. Last checked .

  1. source content difference between and Current source content +2 -1

    Casa added a security advisory banner (updated August 1, 2026) warning of the Coldcard seed-generation flaw and recommending the device be replaced, and the page date moved from March 4, 2026 to August 6, 2026.

    seen · Captured here 5,232 chars
    What changed from the previous capture 3 lines
     Help Center
     Hardware devices
     Coldcard
    -March 4, 2026
    +August 6, 2026
     Coldcard troubleshooting
     Coldcard Mk 3+ hardware devices are compatible with Casa multisig vaults.
    +⚠️ Security Advisory (Updated August 1, 2026): Coinkite has identified a seed-generation flaw affecting certain Coldcard firmware versions. If you generated your seed on affected firmware, your funds may be at risk. We do recommend replacing this device as soon as you are able.
     Whether you are adding the Coldcard, doing a health check, or sending funds from your Casa vault, it has the unique benefit of offering offline-signing via PSBTs to add a signature to your vault.
     One thing to keep in mind when using your Coldcard is to remember to check for the most recent firmware updates here.
     With Coldcard, the instructions for performing a health check and signing a transaction do differ slightly. See the below articles for the instructions for each function:
    
    Extracted text as captured
    Skip to content
    English
    Show submenu for translations
    More support
    Take control of your digital future.
    Open main navigation
    Close main navigation
    Take control of your digital future.
    English
    Show submenu for translations
    More support
    Search the Help Center
    There are no suggestions because the search field is empty.
    Help Center
    Hardware devices
    Coldcard
    August 6, 2026
    Coldcard troubleshooting
    Coldcard Mk 3+ hardware devices are compatible with Casa multisig vaults.
    ⚠️ Security Advisory (Updated August 1, 2026): Coinkite has identified a seed-generation flaw affecting certain Coldcard firmware versions. If you generated your seed on affected firmware, your funds may be at risk. We do recommend replacing this device as soon as you are able.
    Whether you are adding the Coldcard, doing a health check, or sending funds from your Casa vault, it has the unique benefit of offering offline-signing via PSBTs to add a signature to your vault.
    One thing to keep in mind when using your Coldcard is to remember to check for the most recent firmware updates here.
    With Coldcard, the instructions for performing a health check and signing a transaction do differ slightly. See the below articles for the instructions for each function:
    Performing a Health Check with Coldcard
    Signing a Transaction With Coldcard
    Some common Coldcard errors are:
    Failure. My XFP not involved
    Change fraud
    Couldn't find signature
    Failure Invaid PSBT multisig.py 715
    Failure Invalid PSBT multisig.py 716
    Failure XPUBs in PSBT do not match any known wallet
    Error: file must be .psbt
    "Sorry, there was a problem completing your Health Check. Problem Detail: Error. No authorization token was found"
    Failure. My XFP not involved
    Solution: Double-check that the Coldcard is the device used for that vault. If you are performing a key rotation make sure that you are not using the device you marked for replacement to try to sign.
    Change fraud
    There is an issue with the Coldcard firmware where it looks for the OP_CHECKMULTISIG opcode in the redeem script, but can't find it because it isn't taking into account that we use nested segwit (P2SH-P2WSH). It's assuming all addresses are P2SH or P2WSH.
    You can get around this by going to Settings > Multisig Wallets > Skip Checks, and turning that setting on.
    Couldn't find signature

    Excerpt only. The complete copy is held offline and backs quotations on this site. The original publication remains the canonical public source.

  2. Earliest copy held
    seen · Captured here 4,952 chars
    Extracted text as captured
    Skip to content
    English
    Show submenu for translations
    More support
    Take control of your digital future.
    Open main navigation
    Close main navigation
    Take control of your digital future.
    English
    Show submenu for translations
    More support
    Search the Help Center
    There are no suggestions because the search field is empty.
    Help Center
    Hardware devices
    Coldcard
    March 4, 2026
    Coldcard troubleshooting
    Coldcard Mk 3+ hardware devices are compatible with Casa multisig vaults.
    Whether you are adding the Coldcard, doing a health check, or sending funds from your Casa vault, it has the unique benefit of offering offline-signing via PSBTs to add a signature to your vault.
    One thing to keep in mind when using your Coldcard is to remember to check for the most recent firmware updates here.
    With Coldcard, the instructions for performing a health check and signing a transaction do differ slightly. See the below articles for the instructions for each function:
    Performing a Health Check with Coldcard
    Signing a Transaction With Coldcard
    Some common Coldcard errors are:
    Failure. My XFP not involved
    Change fraud
    Couldn't find signature
    Failure Invaid PSBT multisig.py 715
    Failure Invalid PSBT multisig.py 716
    Failure XPUBs in PSBT do not match any known wallet
    Error: file must be .psbt
    "Sorry, there was a problem completing your Health Check. Problem Detail: Error. No authorization token was found"
    Failure. My XFP not involved
    Solution: Double-check that the Coldcard is the device used for that vault. If you are performing a key rotation make sure that you are not using the device you marked for replacement to try to sign.
    Change fraud
    There is an issue with the Coldcard firmware where it looks for the OP_CHECKMULTISIG opcode in the redeem script, but can't find it because it isn't taking into account that we use nested segwit (P2SH-P2WSH). It's assuming all addresses are P2SH or P2WSH.
    You can get around this by going to Settings > Multisig Wallets > Skip Checks, and turning that setting on.
    Couldn't find signature
    Solution: Make sure to upload the correct file to confirm this request. It will prompt you with the file name to look for in the error message.

    Excerpt only. The complete copy is held offline and backs quotations on this site. The original publication remains the canonical public source.

How to check this yourself

The excerpts and plain unified diffs above show the text this project held and how it changed. To verify a quotation, compare it against the page itself or against the Internet Archive's copies, which are independent of this project.

Complete captures are held offline rather than mirrored here, so this page shows diffs and excerpts. If a quotation is ever disputed, the full copy can be produced. Ask.