COLDCARD RNG incident the public record, collected and explained
Informational only, and this site never asks for your seed words. details

Informational only. This is an open source collection of what others have published about the incident, together with an explanation of it. It is not financial, security or legal advice, and not a substitute for professional advice about your own situation. It is not affiliated with, endorsed by, or speaking for Coinkite. Material is attributed and quoted as published; where sources disagree their scenarios are kept separate with their assumptions rather than reconciled into one answer. Everything is meant to be checked against the linked evidence rather than taken on trust. Act on your own judgement about a particular situation. Editorial standards and corrections.

Do not disclose recovery material to a website, form, message or support account. This site never asks for it, and contributions containing recovery words or private keys are not accepted.

nostr: inference that NVK's 2021 knowledge was the entropy bug

nvk-2021-knowledge-inference-528c5ea0

https://njump.me/note122x9agz9dnh8t93m0v9e0y47v5sx6g2vyhz92x3pwxt6zc6f09uqgpe0jv

Author
npub1ak68qfc…rxy8fx
Organisation
nostr
Evidence role
community
Posted
Capture status
capture held

A reply-thread argument that Coinkite's disclosure chronology, which says firmware 4.0.0 was never released, forces the conclusion that private knowledge alluded to by a third party in 2021 was the entropy bug rather than a USB flaw. A developed strand of the post-incident culpability debate, held as dated, attributed public interpretation; the inference is the author's own and is not verified here. Complements the registered reddit-nvk-awareness-critique discussion.

This post is registered as evidence and has a locally held capture: the signed nostr event as served by the relay, plus its flattened text. The original remains the canonical publication.

Held captures

captured event.json, event.txt, meta.json

Flattened event text as captured
url:      https://njump.me/note122x9agz9dnh8t93m0v9e0y47v5sx6g2vyhz92x3pwxt6zc6f09uqgpe0jv
event id: 528c5ea0456cee75963b7b0b9792be65206d214c25c4551a217197a163497978
author:   npub1ak68qfcjj7k95c0jwleu69x72nr8adwv6g80pkwl9xlps6zmkqzqrxy8fx
posted:   2026-08-06T02:16:45Z (created_at 1785982605)
captured: 20260806T052553Z via nak version v0.20.2; nak req -i from wss://relay.damus.io.
          nostr events are self-authenticating signed artefacts;
          nak verified the signature on receipt.

--- note text (verbatim) ---

The important part of this is that it shows NVK was aware of the entropy bug in 2021, the less but still tragic part is that it does imply Matt was told secret knowledge of it. 

You can't be protected from something that was never released. Coinkite's own disclosure says 4.0.0 wasn't pubic for what that is worth. That isn't the secret knowedge.

I know this is terrible to contemplate. Take a moment and really think about what was actually said.

No one was at risk from 4.0.0 because it was never released. Matt says he has a piece of knowledge that he isn't allowed to say - that makes his guide true.

what is that piece of knowledge? It can't be a usb bug because no one had that firmware. 

His guide can only protect users from something that is released. The only code released at the time was 4.0.1. with the entropy bug, not a usb bug.

The secret knowledge has to be the entropy bug because it is the only threat at that can harm users and that his guide would protect from. 

Matt couldn't steal all your bitcoin without physical access if it was usb. He could with the entropy exploit.

If 4.0.0 was released then I would concede it is 50/50

--- replies (0) ---
How to check this yourself

Compare the captured text or a quotation against the original while it is available.