Latest reviewed change
source content difference between and
The page added a new entry quoting Leo Wandersleb's August 2021 X thread asking where the Coldcard Mk3 gets its entropy (concluding the default is the secure-element TRNG alone), with an editorial note and links to the Coldcard FAQ and the WalletScrutiny Mk3 review.
These are other people's words, reproduced so they stay findable. Quoting a post here is not a claim that it is accurate — every entry links to the original so you can read it in context and judge for yourself.
+Leo Wandersleb
+@LeoWandersleb
+X
+12 Aug 2021
+I'm analyzing @COLDCARDwallet Mk3 for @WalletScrutiny and can't find any claims about the sources of entropy. Does the device by default rely solely on randomness from its "secure element" for masterseed creation?
First lines only. The complete diff is in the timeline below.
- Organisation
- nvk.wtf
- Evidence role
- Aggregator
- Published
- not established
- Source changes
- 1
- Detected differences
- 3
- Unreviewed
- 0
- Copies held
- 4
Full quotes of other people's public posts about the vulnerability, each linked to the original. Same operator and stance caveats as nvkwtf-articles. Treated as a discovery feed only: quoted material is registered and captured at its source. Circularity watch: should it ever quote cc-vuln.org material, that is this archive reflected back, not independent corroboration.
Every check is recorded, including checks that found no text change. A detected edit is therefore bounded between two checks. The publisher's exact save time is not observable from this record. Last checked .
This post is held twice: here, with this project's own note on why it matters, and again as part of the conversation captured at , which is polled for changes. Both copies are the same post; neither is a separate event.
Snapshot and diff bodies for this chain monitor are held in the local evidence archive but withheld from the public site because they can contain the addresses of people who published nothing themselves. Capture times and reviewed change summaries remain available below.
Held captures
-
The page added a new entry quoting Leo Wandersleb's August 2021 X thread asking where the Coldcard Mk3 gets its entropy (concluding the default is the secure-element TRNG alone), with an editorial note and links to the Coldcard FAQ and the WalletScrutiny Mk3 review.
Recovered from the Internet Archive rather than captured by this project. The row records that third-party provenance separately from captures made by this project.
What changed from the previous capture 24 lines
These are other people's words, reproduced so they stay findable. Quoting a post here is not a claim that it is accurate — every entry links to the original so you can read it in context and judge for yourself. +Leo Wandersleb +@LeoWandersleb +X +12 Aug 2021 +I'm analyzing @COLDCARDwallet Mk3 for @WalletScrutiny and can't find any claims about the sources of entropy. Does the device by default rely solely on randomness from its "secure element" for masterseed creation? + +Pointers to firmware code or claims would be awesome! + +This looks like the default is to use only the TRNG. RNGs are close to impossible to verify if they produce true randomness. + +Whitening helps a bit against very specific attacks but not against the provider knowing the random numbers. +Enlarge this screenshot + +Wandersleb runs WalletScrutiny, which reviews hardware wallets. He asked in August 2021 where the Coldcard Mk3 gets its entropy; the two replies the thread shows are another user pointing him at the FAQ and his own conclusion from reading it, six weeks later. Neither is from Coldcard. The FAQ section in his screenshot is the same one NVK had posted approvingly on 8 September 2021, filed under Receipts. + +REFERENCED IN THE POST + +Coldcard's FAQ, the page he was pointed to +WalletScrutiny's Coldcard Mk3 review + +Via Leo Wandersleb on Nostr +(opens in a new tab) + +Open the post Economy-Cash6726 u/Economy-Cash6726 RedditExtracted text as captured
Reactions What other people have said publicly about the Coldcard vulnerability — quoted in full and captured here, whether or not it is still up, in case it does not stay that way. These are other people's words, reproduced so they stay findable. Quoting a post here is not a claim that it is accurate — every entry links to the original so you can read it in context and judge for yourself. Leo Wandersleb @LeoWandersleb X 12 Aug 2021 I'm analyzing @COLDCARDwallet Mk3 for @WalletScrutiny and can't find any claims about the sources of entropy. Does the device by default rely solely on randomness from its "secure element" for masterseed creation? Pointers to firmware code or claims would be awesome! This looks like the default is to use only the TRNG. RNGs are close to impossible to verify if they produce true randomness. Whitening helps a bit against very specific attacks but not against the provider knowing the random numbers. Enlarge this screenshot Wandersleb runs WalletScrutiny, which reviews hardware wallets. He asked in August 2021 where the Coldcard Mk3 gets its entropy; the two replies the thread shows are another user pointing him at the FAQ and his own conclusion from reading it, six weeks later. Neither is from Coldcard. The FAQ section in his screenshot is the same one NVK had posted approvingly on 8 September 2021, filed under Receipts. REFERENCED IN THE POST Coldcard's FAQ, the page he was pointed to WalletScrutiny's Coldcard Mk3 review Via Leo Wandersleb on Nostr (opens in a new tab) Open the post Economy-Cash6726 u/Economy-Cash6726 Reddit Ordered Coldcard Mk4 and wallet got drained even though I used a 12 word seed with no dice rolls. Ledger is better device and less cost Yes when it happened with me and I reported it I was blocked on their channel. They did not acknowledge the issue and several others encountered same. I even asked for refund from hodldee on Reddit and he still denied to pay me what I paid for the hardware wallet Enlarge this screenshot Both quotes are the same person. The first comment sat in an r/ledgerwallet thread for two years; the second is their answer when another user asked about it in the days after the vulnerability became public. Asked when the wallet was drained, they say 2022.Excerpt only. The complete copy is held offline and backs quotations on this site. The original publication remains the canonical public source.
-
Recovered from the Internet Archive rather than captured by this project. The row records that third-party provenance separately from captures made by this project.
What changed from the previous capture 0 lines
Extracted text as captured
Reactions What other people have said publicly about the Coldcard vulnerability — quoted in full and captured here, whether or not it is still up, in case it does not stay that way. These are other people's words, reproduced so they stay findable. Quoting a post here is not a claim that it is accurate — every entry links to the original so you can read it in context and judge for yourself. Economy-Cash6726 u/Economy-Cash6726 Reddit Ordered Coldcard Mk4 and wallet got drained even though I used a 12 word seed with no dice rolls. Ledger is better device and less cost Yes when it happened with me and I reported it I was blocked on their channel. They did not acknowledge the issue and several others encountered same. I even asked for refund from hodldee on Reddit and he still denied to pay me what I paid for the hardware wallet Enlarge this screenshot Both quotes are the same person. The first comment sat in an r/ledgerwallet thread for two years; the second is their answer when another user asked about it in the days after the vulnerability became public. Asked when the wallet was drained, they say 2022. REFERENCED IN THE POST The r/Bitcoin thread that resurfaced it Ali Sherief (@Zenul_Abidin) on X, where this screenshot circulated Read the originalExcerpt only. The complete copy is held offline and backs quotations on this site. The original publication remains the canonical public source.
2 presentation-noise differences. Sidebar, ticker and other page chrome churn that our review classified as not being changes to what the source says.
- +3 -0 The reactions index displayed its count; the listed reactions were unchanged.
- +2 -0 The reactions-index sort controls rendered in this capture; the listed reactions were unchanged.
The excerpts and plain unified diffs above show the text this project held and how it changed. To verify a quotation, compare it against the page itself or against the Internet Archive's copies, which are independent of this project.
Complete captures are held offline rather than mirrored here, so this page shows diffs and excerpts. If a quotation is ever disputed, the full copy can be produced. Ask.
Compare the screenshot or a quotation against the original while it is available.