COLDCARD RNG incident the public record, collected and explained
Informational only, and this site never asks for your seed words. details

Informational only. This is an open source collection of what others have published about the incident, together with an explanation of it. It is not financial, security or legal advice, and not a substitute for professional advice about your own situation. It is not affiliated with, endorsed by, or speaking for Coinkite. Material is attributed and quoted as published; where sources disagree their scenarios are kept separate with their assumptions rather than reconciled into one answer. Everything is meant to be checked against the linked evidence rather than taken on trust. Act on your own judgement about a particular situation. Editorial standards and corrections.

Do not disclose recovery material to a website, form, message or support account. This site never asks for it, and contributions containing recovery words or private keys are not accepted.

nvk.wtf reactions index

nvkwtf-reactions

https://nvk.wtf/reactions

Latest reviewed change

source content difference between and

The page added a new entry quoting Leo Wandersleb's August 2021 X thread asking where the Coldcard Mk3 gets its entropy (concluding the default is the secure-element TRNG alone), with an editorial note and links to the Coldcard FAQ and the WalletScrutiny Mk3 review.

seen +24 -0 full history below
 
 These are other people's words, reproduced so they stay findable. Quoting a post here is not a claim that it is accurate — every entry links to the original so you can read it in context and judge for yourself.
 
+Leo Wandersleb
+@LeoWandersleb
+X
+12 Aug 2021
+I'm analyzing @COLDCARDwallet Mk3 for @WalletScrutiny and can't find any claims about the sources of entropy. Does the device by default rely solely on randomness from its "secure element" for masterseed creation?

First lines only. The complete diff is in the timeline below.

Organisation
nvk.wtf
Evidence role
Aggregator
Published
not established
Source changes
1
Detected differences
3
Unreviewed
0
Copies held
4

Full quotes of other people's public posts about the vulnerability, each linked to the original. Same operator and stance caveats as nvkwtf-articles. Treated as a discovery feed only: quoted material is registered and captured at its source. Circularity watch: should it ever quote cc-vuln.org material, that is this archive reflected back, not independent corroboration.

Every check is recorded, including checks that found no text change. A detected edit is therefore bounded between two checks. The publisher's exact save time is not observable from this record. Last checked .

  1. source content difference between and source content +24 -0

    The page added a new entry quoting Leo Wandersleb's August 2021 X thread asking where the Coldcard Mk3 gets its entropy (concluding the default is the secure-element TRNG alone), with an editorial note and links to the Coldcard FAQ and the WalletScrutiny Mk3 review.

    seen · Captured here 2,423 chars
    What changed from the previous capture 24 lines
     
     These are other people's words, reproduced so they stay findable. Quoting a post here is not a claim that it is accurate — every entry links to the original so you can read it in context and judge for yourself.
     
    +Leo Wandersleb
    +@LeoWandersleb
    +X
    +12 Aug 2021
    +I'm analyzing @COLDCARDwallet Mk3 for @WalletScrutiny and can't find any claims about the sources of entropy. Does the device by default rely solely on randomness from its "secure element" for masterseed creation?
    +
    +Pointers to firmware code or claims would be awesome!
    +
    +This looks like the default is to use only the TRNG. RNGs are close to impossible to verify if they produce true randomness.
    +
    +Whitening helps a bit against very specific attacks but not against the provider knowing the random numbers.
    +Enlarge this screenshot
    +
    +Wandersleb runs WalletScrutiny, which reviews hardware wallets. He asked in August 2021 where the Coldcard Mk3 gets its entropy; the two replies the thread shows are another user pointing him at the FAQ and his own conclusion from reading it, six weeks later. Neither is from Coldcard. The FAQ section in his screenshot is the same one NVK had posted approvingly on 8 September 2021, filed under Receipts.
    +
    +REFERENCED IN THE POST
    +
    +Coldcard's FAQ, the page he was pointed to
    +WalletScrutiny's Coldcard Mk3 review
    +
    +Via Leo Wandersleb on Nostr
    +(opens in a new tab)
    +
    +Open the post
     Economy-Cash6726
     u/Economy-Cash6726
     Reddit
    
    Extracted text as captured
    Reactions
    
    What other people have said publicly about the Coldcard vulnerability — quoted in full and captured here, whether or not it is still up, in case it does not stay that way.
    
    These are other people's words, reproduced so they stay findable. Quoting a post here is not a claim that it is accurate — every entry links to the original so you can read it in context and judge for yourself.
    
    Leo Wandersleb
    @LeoWandersleb
    X
    12 Aug 2021
    I'm analyzing @COLDCARDwallet Mk3 for @WalletScrutiny and can't find any claims about the sources of entropy. Does the device by default rely solely on randomness from its "secure element" for masterseed creation?
    
    Pointers to firmware code or claims would be awesome!
    
    This looks like the default is to use only the TRNG. RNGs are close to impossible to verify if they produce true randomness.
    
    Whitening helps a bit against very specific attacks but not against the provider knowing the random numbers.
    Enlarge this screenshot
    
    Wandersleb runs WalletScrutiny, which reviews hardware wallets. He asked in August 2021 where the Coldcard Mk3 gets its entropy; the two replies the thread shows are another user pointing him at the FAQ and his own conclusion from reading it, six weeks later. Neither is from Coldcard. The FAQ section in his screenshot is the same one NVK had posted approvingly on 8 September 2021, filed under Receipts.
    
    REFERENCED IN THE POST
    
    Coldcard's FAQ, the page he was pointed to
    WalletScrutiny's Coldcard Mk3 review
    
    Via Leo Wandersleb on Nostr
    (opens in a new tab)
    
    Open the post
    Economy-Cash6726
    u/Economy-Cash6726
    Reddit
    Ordered Coldcard Mk4 and wallet got drained even though I used a 12 word seed with no dice rolls. Ledger is better device and less cost
    
    Yes when it happened with me and I reported it I was blocked on their channel. They did not acknowledge the issue and several others encountered same. I even asked for refund from hodldee on Reddit and he still denied to pay me what I paid for the hardware wallet
    Enlarge this screenshot
    
    Both quotes are the same person. The first comment sat in an r/ledgerwallet thread for two years; the second is their answer when another user asked about it in the days after the vulnerability became public. Asked when the wallet was drained, they say 2022.
    

    Excerpt only. The complete copy is held offline and backs quotations on this site. The original publication remains the canonical public source.

  2. Earliest copy held
    seen · Captured here 1,273 chars
    Extracted text as captured
    Reactions
    
    What other people have said publicly about the Coldcard vulnerability — quoted in full and captured here, whether or not it is still up, in case it does not stay that way.
    
    These are other people's words, reproduced so they stay findable. Quoting a post here is not a claim that it is accurate — every entry links to the original so you can read it in context and judge for yourself.
    
    Economy-Cash6726
    u/Economy-Cash6726
    Reddit
    Ordered Coldcard Mk4 and wallet got drained even though I used a 12 word seed with no dice rolls. Ledger is better device and less cost
    
    Yes when it happened with me and I reported it I was blocked on their channel. They did not acknowledge the issue and several others encountered same. I even asked for refund from hodldee on Reddit and he still denied to pay me what I paid for the hardware wallet
    Enlarge this screenshot
    
    Both quotes are the same person. The first comment sat in an r/ledgerwallet thread for two years; the second is their answer when another user asked about it in the days after the vulnerability became public. Asked when the wallet was drained, they say 2022.
    
    REFERENCED IN THE POST
    
    The r/Bitcoin thread that resurfaced it
    Ali Sherief (@Zenul_Abidin) on X, where this screenshot circulated
    Read the original
2 presentation-noise differences. Sidebar, ticker and other page chrome churn that our review classified as not being changes to what the source says.
  • +3 -0 The reactions index displayed its count; the listed reactions were unchanged.
  • +2 -0 The reactions-index sort controls rendered in this capture; the listed reactions were unchanged.
How to check this yourself

The excerpts and plain unified diffs above show the text this project held and how it changed. To verify a quotation, compare it against the page itself or against the Internet Archive's copies, which are independent of this project.

Complete captures are held offline rather than mirrored here, so this page shows diffs and excerpts. If a quotation is ever disputed, the full copy can be produced. Ask.