COLDCARD RNG incident the public record, collected and explained
Informational only, and this site never asks for your seed words. details

Informational only. This is an open source collection of what others have published about the incident, together with an explanation of it. It is not financial, security or legal advice, and not a substitute for professional advice about your own situation. It is not affiliated with, endorsed by, or speaking for Coinkite. Material is attributed and quoted as published; where sources disagree their scenarios are kept separate with their assumptions rather than reconciled into one answer. Everything is meant to be checked against the linked evidence rather than taken on trust. Act on your own judgement about a particular situation. Editorial standards and corrections.

Do not disclose recovery material to a website, form, message or support account. This site never asks for it, and contributions containing recovery words or private keys are not accepted.

RRWallet mnemonics and the Ill Bloom flaw

coinspect-2085430121670811898

https://x.com/coinspect/status/2085430121670811898

Captured screenshot of the post by @coinspect, posted 6 Aug 2026, 18:17 UTC
@coinspect posted captured full-size capture → original post →
Author
@coinspect
Organisation
independent
Evidence role
social statement
Posted
Capture status
capture held

The security firm Coinspect warns that RRWallet, formerly RenrenBit, generated seed phrases vulnerable to Ill Bloom in both English and Chinese, says a user who kept using an affected mnemonic lost $2M recently, and tells anyone who ever used RRWallet to move funds and never reuse a mnemonic it produced. Ill Bloom is a separate weak-entropy flaw, described in the record as a twelve-year-old CryptoJS issue whose public proof of concept is relayed at threatwire_-2085593099749749082; it is not the COLDCARD defect. Held for the wider entropy-auditing wave the incident set off and the losses being attributed to it elsewhere. Interest: Coinspect sells wallet security audits. The affected- wallet claim and the $2M figure are the firm's own and are not verified here.

This post is registered as evidence and has a locally held capture. The original remains the canonical publication.

How to check this yourself

Compare the screenshot or a quotation against the original while it is available.