COLDCARD RNG incident the public record, collected and explained
Informational only, and this site never asks for your seed words. details

Informational only. This is an open source collection of what others have published about the incident, together with an explanation of it. It is not financial, security or legal advice, and not a substitute for professional advice about your own situation. It is not affiliated with, endorsed by, or speaking for Coinkite. Material is attributed and quoted as published; where sources disagree their scenarios are kept separate with their assumptions rather than reconciled into one answer. Everything is meant to be checked against the linked evidence rather than taken on trust. Act on your own judgement about a particular situation. Editorial standards and corrections.

Do not disclose recovery material to a website, form, message or support account. This site never asks for it, and contributions containing recovery words or private keys are not accepted.

Nunchuk advisory update and multisig guidance

nunchuk-advisory-update

https://x.com/nunchuk_io/status/2083034519183966214

Captured screenshot of the post by @nunchuk_io, posted 31 Jul 2026, 03:38 UTC
@nunchuk_io posted captured full-size capture → original post →
Author
@nunchuk_io
Organisation
Nunchuk
Evidence role
custody-provider-guidance
Posted
Capture status
capture held

Nunchuk's public guidance thread following Block's analysis: treats any on-device Coldcard seed since 2021 as suspect pending Coinkite's full report, and refines its multisig guidance to distinguish one compromised key from a quorum composed entirely of affected Coldcard seeds. Nunchuk is also reported to have emailed subscribers before posting publicly; the email itself is not in this archive.

This post is registered as evidence and has a locally held capture. The original remains the canonical publication.

How to check this yourself

Compare the screenshot or a quotation against the original while it is available.