COLDCARD RNG incident the public record, collected and explained
Informational only, and this site never asks for your seed words. details

Informational only. This is an open source collection of what others have published about the incident, together with an explanation of it. It is not financial, security or legal advice, and not a substitute for professional advice about your own situation. It is not affiliated with, endorsed by, or speaking for Coinkite. Material is attributed and quoted as published; where sources disagree their scenarios are kept separate with their assumptions rather than reconciled into one answer. Everything is meant to be checked against the linked evidence rather than taken on trust. Act on your own judgement about a particular situation. Editorial standards and corrections.

Do not disclose recovery material to a website, form, message or support account. This site never asks for it, and contributions containing recovery words or private keys are not accepted.

Anzen and the self-custody trilemma

lukechilds-anzen-trilemma

https://lu.ke/self-custody-trilemma

Organisation
Luke Childs
Evidence role
Secondary analysis
Published
2026-08-09
Source changes
0
Detected differences
0
Unreviewed
0
Copies held
1

Luke Childs publishes a writeup on Anzen, a wallet design presented as a response to Bitcoin's self-custody trilemma in the wake of the COLDCARD incident. Held as a dated product launch and design argument from the author. The claims about the design and its properties are the author's own and are not verified here.

Every check is recorded, including checks that found no text change. A detected edit is therefore bounded between two checks. The publisher's exact save time is not observable from this record. Last checked .

  1. Earliest copy held Current
    seen · Captured here 13,414 chars
    Extracted text as captured
    ‹ lu.ke
    Thoughts
    Solving Bitcoin’s Self-Custody Trilemma
    7th August 2026 ·
    Comments on X
    Last week, attackers started draining Coldcard wallets.
    A firmware bug made its random number generator predictable, so
    attackers could recreate seeds without ever touching a device.
    Losses are past $130 million and still climbing.
    My seed was originally generated on a vulnerable Coldcard. The only
    reason I didn’t lose my life savings is that, years ago when I set
    it up, I
    refused to trust its random number generator. I generated 256 bits
    of entropy on my MacBook, flipped a coin 256 times, and mixed all
    of it into the Coldcard’s own entropy on the device. Beforehand I
    did a test run,
    rewriting the Coldcard’s seed-derivation logic from scratch
    to verify my additional entropy sources would be combined
    correctly.
    Message to a friend when creating my Coldcard seed 5 years ago
    It is absolutely ridiculous that this is the level of paranoid
    schizophrenia required to not lose your life savings. Nobody should
    have to do this.
    The immediate cause was a bug. The real cause is that our industry’s
    standard advice puts people’s entire savings behind a single device,
    and just hopes that its hardware, firmware, supply chain, and random
    number generator are all flawless, forever.
    Everyone is now asking how we stop this from happening again. To
    answer that, you have to understand why every current option is
    broken.
    Bitcoin’s self-custody trilemma
    Today, you only get to pick two. There’s not a single self-custody
    solution on the market that delivers all three. Let’s walk through
    the options.
    Singlesig (hot wallet or single hardware wallet) is
    trustless and easy to use. One device, tap to spend. But it’s also
    a massive single point of failure. One bug, one theft, or one bad
    backup away from total loss. Almost every Coldcard victim last week
    was on this edge of the triangle. And lost their life savings
    because of it.

    Excerpt only. The complete copy is held offline and backs quotations on this site. The original publication remains the canonical public source.

How to check this yourself

The excerpts and plain unified diffs above show the text this project held and how it changed. To verify a quotation, compare it against the page itself or against the Internet Archive's copies, which are independent of this project.

Complete captures are held offline rather than mirrored here, so this page shows diffs and excerpts. If a quotation is ever disputed, the full copy can be produced. Ask.