COLDCARD RNG incident the public record, collected and explained
Informational only, and this site never asks for your seed words. details

Informational only. This is an open source collection of what others have published about the incident, together with an explanation of it. It is not financial, security or legal advice, and not a substitute for professional advice about your own situation. It is not affiliated with, endorsed by, or speaking for Coinkite. Material is attributed and quoted as published; where sources disagree their scenarios are kept separate with their assumptions rather than reconciled into one answer. Everything is meant to be checked against the linked evidence rather than taken on trust. Act on your own judgement about a particular situation. Editorial standards and corrections.

Do not disclose recovery material to a website, form, message or support account. This site never asks for it, and contributions containing recovery words or private keys are not accepted.

Allegation that CoinKite CTO wrote vulnerable dependency pseudonymously

oomahq-2085717166884618584

https://x.com/oomahq/status/2085717166884618584

Captured screenshot of the post by @oomahq, posted 7 Aug 2026, 13:18 UTC
@oomahq posted captured full-size capture → original post →

Latest reviewed change

source content difference between and

Four replies (from kiawtzin, Brandoniann1, Brandonwords and xolandar) were removed even though the capture deepened from 23 to 24 scroll rounds, while two older replies (MichaelDunwort1 and theretailbull) re-entered due to the deeper scroll.

seen +19 -36 full history below
 
 And after I was done I thought a non-vaguepost version of this information was needed.
 
-post: 2085755157296427477
-role: reply
-author: kiawtzin
-name: Kiawtzin - BIP110
-created: 2026-08-07T15:49:15Z

First lines only. The complete diff is in the timeline below.

Author
@oomahq
Organisation
independent
Evidence role
social statement
Posted
Capture status
capture held

oomahq alleges that the external firmware dependency containing the critical vulnerability was written by CoinKite CTO Peter Gray under the @DocHex nym, and that the claim is verifiable. Held as a dated, specific attribution allegation made during the incident-response period, alongside the related oomahq-nvk-switck-knowledge-claim. The allegation and the cited evidence are the poster's own reading and are not independently verified here.

This post is registered as evidence and has a locally held capture. The original remains the canonical publication. Last checked .

The conversation

Captured . 6 continuation posts, 123 replies held, 49 muted as low signal. Posts are in the archive's own order, oldest first, not the order X ranks them in.

  1. @oomahq the registered post 7 Aug 2026, 13:18 UTC
    Captured screenshot of the post by @oomahq

    capture taken

  2. @oomahq same author, continuing 7 Aug 2026, 13:19 UTC
    Captured screenshot of the post by @oomahq

    capture taken

  3. @oomahq same author, continuing 7 Aug 2026, 13:19 UTC
    Captured screenshot of the post by @oomahq

    capture taken

  4. @oomahq same author, continuing 7 Aug 2026, 13:20 UTC
    Captured screenshot of the post by @oomahq

    capture taken

  5. @oomahq same author, continuing 7 Aug 2026, 13:21 UTC
    Captured screenshot of the post by @oomahq

    capture taken

  6. @oomahq same author, continuing 7 Aug 2026, 13:21 UTC
    Captured screenshot of the post by @oomahq

    capture taken

  7. @oomahq same author, continuing 7 Aug 2026, 13:22 UTC
    Captured screenshot of the post by @oomahq

    capture taken

Replies are unmoderated third-party material, reproduced here as part of the record. Inclusion is not endorsement, and nothing in them has been checked by this project.
Replies held in this capture (123)

Low-signal replies are collapsed to one line, never removed. A reply is collapsed only on mechanical grounds: fewer than 40 characters, no text, mentions only, no letters or digits, a bare link, or text identical to another reply in the same capture. What a reply argues is never a reason. Each one says which rule collapsed it, and its screenshot is one click away.

  1. Captured screenshot of the reply by @twannl

    capture taken

  2. Captured screenshot of the reply by @resembleai

    capture taken

  3. Captured screenshot of the reply by @RevenueCat

    capture taken

  4. Captured screenshot of the reply by @secondaidcom

    capture taken

  5. Captured screenshot of the reply by @SnuvNestLiving

    capture taken

  6. Captured screenshot of the reply by @ewa_app

    capture taken

  7. Captured screenshot of the reply by @TipperAnalytics

    capture taken

  8. @oomahq 7 Aug 2026, 13:22 UTC the thread author answering in their own thread
    Captured screenshot of the reply by @oomahq

    capture taken

  9. @oomahq 7 Aug 2026, 13:23 UTC the thread author answering in their own thread
    Captured screenshot of the reply by @oomahq

    capture taken

  10. @oomahq 7 Aug 2026, 13:24 UTC the thread author answering in their own thread
    Captured screenshot of the reply by @oomahq

    capture taken

  11. @oomahq 7 Aug 2026, 13:24 UTC the thread author answering in their own thread
    Captured screenshot of the reply by @oomahq

    capture taken

  12. @oomahq 7 Aug 2026, 13:25 UTC the thread author answering in their own thread
    Captured screenshot of the reply by @oomahq

    capture taken

The remaining 111 replies
  1. @oomahq glad your own research corroborates what has already been discovered first by someone else. Always verify.
    show the capture Captured screenshot of the reply by @SovereignBTCer

    capture taken

  2. https:// github.com/switck/libngu/ blame/0371d6372eb7c1165f9c0410f6d6537e09882402/ngu/random.c#L30 … 28 June 2021, commit message "x", commiter: switck (unverified).
    show the capture Captured screenshot of the reply by @GregTonoski

    capture taken

  3. @oomahq 7 Aug 2026, 14:01 UTC the thread author answering in their own thread
    GitHub displays the "Unverified" message when a commit is GPG signed but GitHub doesn't have proof that the public key belongs to the user that signed. If you click on the yellow "Unverified" badge you'll see that the fingerprint is the same as the "Verified" commits of DocHex.
    show the capture Captured screenshot of the reply by @oomahq

    capture taken

  4. @oomahq 7 Aug 2026, 15:48 UTC the thread author answering in their own thread
    Yup, this tweet is part of what made me start digging. And after I was done I thought a non-vaguepost version of this information was needed.
    show the capture Captured screenshot of the reply by @oomahq

    capture taken

  5. @kiawtzin 7 Aug 2026, 15:49 UTC under 40 characters
    Sick
    show the capture Captured screenshot of the reply by @kiawtzin

    capture taken

  6. Rip new startups focusing on hardware wallet and @Trezor and companies working and already established will take the whole cake
    show the capture Captured screenshot of the reply by @PrivacyisBetter

    capture taken

  7. @djsenior13 7 Aug 2026, 17:33 UTC no text captured
    show the capture Captured screenshot of the reply by @djsenior13

    capture taken

  8. @joseph_welbourn 7 Aug 2026, 17:34 UTC no text captured
    show the capture Captured screenshot of the reply by @joseph_welbourn

    capture taken

  9. @RN72686 7 Aug 2026, 17:37 UTC under 40 characters
    @grok is this true?
    show the capture Captured screenshot of the reply by @RN72686

    capture taken

  10. @innerhat 7 Aug 2026, 17:39 UTC under 40 characters
    gut undefeated
    show the capture Captured screenshot of the reply by @innerhat

    capture taken

  11. @innerhat 7 Aug 2026, 17:39 UTC under 40 characters
    excellent work
    show the capture Captured screenshot of the reply by @innerhat

    capture taken

  12. Nvk gloating about this in a sly roundabout way.."One gray beard"
    show the capture Captured screenshot of the reply by @Laserman_21

    capture taken

  13. @Queen1Crypto 7 Aug 2026, 17:46 UTC under 40 characters
    X account not found in 3…2…
    show the capture Captured screenshot of the reply by @Queen1Crypto

    capture taken

  14. @inverse_hanlon 7 Aug 2026, 17:47 UTC under 40 characters
    Yep all verified
    show the capture Captured screenshot of the reply by @inverse_hanlon

    capture taken

  15. @ironhand_crypto 7 Aug 2026, 17:49 UTC under 40 characters
    Next it'll be confirmed dude is Mossad.
    show the capture Captured screenshot of the reply by @ironhand_crypto

    capture taken

  16. I’m beginning to think that the deep state actually wants you to lose trust in self custody which is the one thing which makes one truly sovereign. And this is want to they want to kill. AI/quantum/coldcard hack… any threat or scandal to scare you out of self custody bitcoin.
    show the capture Captured screenshot of the reply by @super_cool9

    capture taken

  17. @0xn3ro 7 Aug 2026, 18:14 UTC
    Apart from the fact that this vulnerability was exploited, I find it alarming that so few people have familiarised themselves with the open source code and that everything relied on trust me bro.
    show the capture Captured screenshot of the reply by @0xn3ro

    capture taken

  18. @DesertRanger113 7 Aug 2026, 18:16 UTC no text captured
    show the capture Captured screenshot of the reply by @DesertRanger113

    capture taken

  19. Peter Gray’s experience in black hat operations is real, check out his patent: https:// patents.google.com/patent/US85953 24B2/en …
    show the capture Captured screenshot of the reply by @CatoTheElder17

    capture taken

  20. @EthanKasner_ 7 Aug 2026, 18:20 UTC identical to another reply in this capture
    🫪
    show the capture Captured screenshot of the reply by @EthanKasner_

    capture taken

  21. These two rats likely run to a particular desert country soon
    show the capture Captured screenshot of the reply by @NitayNostrasifu

    capture taken

  22. Looking like many useful idiots among podcasters
    show the capture Captured screenshot of the reply by @BoredSoJoinedX

    capture taken

  23. @MichaelDunwort1 7 Aug 2026, 18:42 UTC under 40 characters
    @ozsats256 99/1 now
    show the capture Captured screenshot of the reply by @MichaelDunwort1

    capture taken

  24. @jstamby 7 Aug 2026, 18:44 UTC
    People thought “Canadian company, must be safe”. Turns out it was likely a State sponsored attack, and preplanned before BIP110, scooping coins onto exchanges. Now a Chinese company like Keystone is and was always, the safer choice.
    show the capture Captured screenshot of the reply by @jstamby

    capture taken

  25. What’s the next move? Reach out to @DocHex ? Go straight to authorities?
    show the capture Captured screenshot of the reply by @enjoywithouthey

    capture taken

  26. @GotAll21 7 Aug 2026, 19:07 UTC under 40 characters
    Humiliation ritual.
    show the capture Captured screenshot of the reply by @GotAll21

    capture taken

  27. @TriggerCoder 7 Aug 2026, 19:19 UTC under 40 characters
    @threadreaderapp unroll
    show the capture Captured screenshot of the reply by @TriggerCoder

    capture taken

  28. That whole SLT are pieces of shit. Scum of the earth. Deserve to go to prison.
    show the capture Captured screenshot of the reply by @LANDIGlobal

    capture taken

  29. @ThielFellow 7 Aug 2026, 19:25 UTC under 40 characters
    Smoking gun
    show the capture Captured screenshot of the reply by @ThielFellow

    capture taken

  30. @mybitcoinaccou1 7 Aug 2026, 19:32 UTC mentions only
    @noD7R
    show the capture Captured screenshot of the reply by @mybitcoinaccou1

    capture taken

  31. @ayyylmaobruhhh 7 Aug 2026, 19:34 UTC no text captured
    show the capture Captured screenshot of the reply by @ayyylmaobruhhh

    capture taken

  32. @Jimmydahaus 7 Aug 2026, 19:35 UTC under 40 characters
    Thank you for your service.
    show the capture Captured screenshot of the reply by @Jimmydahaus

    capture taken

  33. @Kais3rP 7 Aug 2026, 19:40 UTC
    Do these guys live chill after this kind of stuff ? I mean, considering a lot of bitcoin holders are pretty bad guys, I would never wanna live my life having to watch my back 24/7.
    show the capture Captured screenshot of the reply by @Kais3rP

    capture taken

  34. Whenever I see something marketed heavily, I get paranoid. Coldcard was that for me and stayed away from it.
    show the capture Captured screenshot of the reply by @EdgarFi68671457

    capture taken

  35. @DavidChoiMusic 7 Aug 2026, 19:57 UTC identical to another reply in this capture
    🫪
    show the capture Captured screenshot of the reply by @DavidChoiMusic

    capture taken

  36. @Owll_D 7 Aug 2026, 19:57 UTC under 40 characters
    You're the best
    show the capture Captured screenshot of the reply by @Owll_D

    capture taken

  37. I seriously considered getting one. But I move slow
    show the capture Captured screenshot of the reply by @Brandoniann1

    capture taken

  38. @vera_rostova 7 Aug 2026, 20:10 UTC mentions only
    @R38TAO
    show the capture Captured screenshot of the reply by @vera_rostova

    capture taken

  39. @0xDebuff 7 Aug 2026, 20:21 UTC under 40 characters
    omg
    show the capture Captured screenshot of the reply by @0xDebuff

    capture taken

  40. @EGrey3717 7 Aug 2026, 20:26 UTC
    Thanks but intuitively this was obvious from the start
    show the capture Captured screenshot of the reply by @EGrey3717

    capture taken

  41. @DutyToRebel 7 Aug 2026, 20:37 UTC under 40 characters
    He thought he was being slick.
    show the capture Captured screenshot of the reply by @DutyToRebel

    capture taken

  42. @theretailbull 7 Aug 2026, 20:57 UTC this account is registered elsewhere in the record
    Look when switck stopped posting on X.
    show the capture Captured screenshot of the reply by @theretailbull

    capture taken

  43. @GRIDsquad 7 Aug 2026, 21:08 UTC under 40 characters
    This is so so so so so bad.
    show the capture Captured screenshot of the reply by @GRIDsquad

    capture taken

  44. @PratikKala 7 Aug 2026, 21:09 UTC under 40 characters
    Excellent forensics
    show the capture Captured screenshot of the reply by @PratikKala

    capture taken

  45. @lm_tldr 7 Aug 2026, 21:22 UTC under 40 characters
    Expedite the man to the French!
    show the capture Captured screenshot of the reply by @lm_tldr

    capture taken

  46. @oomahq 7 Aug 2026, 21:44 UTC the thread author answering in their own thread
    If that happens I have a backup Nostr identity: npub100mahqlhxg50thmt5dyynu40nl25hat9kkkknzk8pqjfkvgq0xsqtdfyy5
    show the capture Captured screenshot of the reply by @oomahq

    capture taken

  47. @NOT2OLD2HODL 7 Aug 2026, 22:16 UTC under 40 characters
    Jesus.
    show the capture Captured screenshot of the reply by @NOT2OLD2HODL

    capture taken

  48. @Fredvs79 7 Aug 2026, 22:17 UTC
    Ooph! This is going to be damning during the forthcoming lawsuits!
    show the capture Captured screenshot of the reply by @Fredvs79

    capture taken

  49. Interesting his name is Gray. Which is a mix of white and black.
    show the capture Captured screenshot of the reply by @Taurus4BTC

    capture taken

  50. We need the #osint community to dig and see if there is a #CIA connection.
    show the capture Captured screenshot of the reply by @pillin_d_masses

    capture taken

  51. @maximalismo_btc 7 Aug 2026, 22:32 UTC under 40 characters
    Yo @grok what here is true?
    show the capture Captured screenshot of the reply by @maximalismo_btc

    capture taken

  52. @AlgoFamily 7 Aug 2026, 22:35 UTC under 40 characters
    Can we trust anything these days?
    show the capture Captured screenshot of the reply by @AlgoFamily

    capture taken

  53. @AdamSch33035084 7 Aug 2026, 22:58 UTC under 40 characters
    @DocHex needs to answer to this.
    show the capture Captured screenshot of the reply by @AdamSch33035084

    capture taken

  54. @oomahq 7 Aug 2026, 23:05 UTC the thread author answering in their own thread
    Exhibit one. Everybody knows about this already, you know. Let's talk something else.
    show the capture Captured screenshot of the reply by @oomahq

    capture taken

  55. @BeachMaster893 7 Aug 2026, 23:41 UTC under 40 characters
    He will be running to Tel Aviv
    show the capture Captured screenshot of the reply by @BeachMaster893

    capture taken

  56. @TrustD21 8 Aug 2026, 00:09 UTC
    Has anyone seen this guy in the last week?
    show the capture Captured screenshot of the reply by @TrustD21

    capture taken

  57. @Brandonwords 8 Aug 2026, 00:20 UTC under 40 characters
    This has Israel written all over it.
    show the capture Captured screenshot of the reply by @Brandonwords

    capture taken

  58. @xolandar 8 Aug 2026, 00:23 UTC under 40 characters
    Tldr:
    show the capture Captured screenshot of the reply by @xolandar

    capture taken

  59. This @dochex @switck guy is literally the evil counterpart to @halfin and satoshi.
    show the capture Captured screenshot of the reply by @Humblepleb21m

    capture taken

  60. @mattbroadstreet 8 Aug 2026, 00:35 UTC no text captured
    show the capture Captured screenshot of the reply by @mattbroadstreet

    capture taken

  61. @XjbhhX 8 Aug 2026, 01:54 UTC
    I'd be happy if did it irresponsibly or responsibly.
    show the capture Captured screenshot of the reply by @XjbhhX

    capture taken

  62. @chefgoose 8 Aug 2026, 03:47 UTC
    @twitt_tr some nerd stuff you probably find interesting
    show the capture Captured screenshot of the reply by @chefgoose

    capture taken

  63. Is there any chance, the bug was there. Then he impersonated himself, now he introduces a clear place where the bug is traceable and as part of a white hat rescue, recovers all the wallets? In this way, the rescue is within the same company but operated in the shadow.
    show the capture Captured screenshot of the reply by @joaquinorma1

    capture taken

  64. @FullChode 8 Aug 2026, 04:28 UTC
    THIS HACK WAS PROMISED TO THEM 3000 YEARS AGO.
    show the capture Captured screenshot of the reply by @FullChode

    capture taken

  65. @fruitymuncher 8 Aug 2026, 05:22 UTC no text captured
    show the capture Captured screenshot of the reply by @fruitymuncher

    capture taken

  66. Is Jon Stewart the only honest one in their group? He has empathy. Nobody else does.
    show the capture Captured screenshot of the reply by @Annathehumanist

    capture taken

  67. That peter gray replying to himself is the biggest clue
    show the capture Captured screenshot of the reply by @guitarstar87

    capture taken

  68. Cryptographic signatures are undeniable. So… unless there’s another explanation, this is starting to smell like an insider job. Interesting.
    show the capture Captured screenshot of the reply by @LibertySwapFi

    capture taken

  69. @big_simp 8 Aug 2026, 07:11 UTC under 40 characters
    @Mmagnet7 Inside job just as I said
    show the capture Captured screenshot of the reply by @big_simp

    capture taken

  70. @maxnaut 8 Aug 2026, 07:21 UTC
    looks so incredibly shady, the chance of a dev accidentally setting 0 instead of 1 and also having a insanely insufficient fallback option is too much of a coincidence
    show the capture Captured screenshot of the reply by @maxnaut

    capture taken

  71. That is absolutely insane . Thanks for sharing this research.
    show the capture Captured screenshot of the reply by @DukeDukingtonRD

    capture taken

  72. wait till you find out @DocHex is an @nvk alt account
    show the capture Captured screenshot of the reply by @electric_btc

    capture taken

  73. @9FigureSats 8 Aug 2026, 08:23 UTC mentions only
    @jackmallers
    show the capture Captured screenshot of the reply by @9FigureSats

    capture taken

  74. The obvious question: Has anyone ever seen Peter Gray and NVK in the same room?
    show the capture Captured screenshot of the reply by @MichaelRoerade

    capture taken

  75. @MaxisClub 8 Aug 2026, 08:33 UTC
    Waiting for them to disprove it...still waiting...still waiting...
    show the capture Captured screenshot of the reply by @MaxisClub

    capture taken

  76. @oomahq 8 Aug 2026, 08:34 UTC the thread author answering in their own thread
    I doubt this because once the cat was out of the bag on July 30-31th anyone in the world with half a clue could start sweeping UTXOs. It's next to impossible that they've all been swept by the same entity. It's also impossible to clearly identify all the sweeping txs if the thieves are careful.
    show the capture Captured screenshot of the reply by @oomahq

    capture taken

  77. @MaxisClub 8 Aug 2026, 08:35 UTC mentions only
    @hodlonaut
    show the capture Captured screenshot of the reply by @MaxisClub

    capture taken

  78. @em 8 Aug 2026, 08:44 UTC
    wow what an investigation - I am still trying to understand it all but its already very interesting and I assumed this to be an inside job from the moment I tried to reproduce the bug and understand it better and must say, it seemed weird to me that someone randomly found and exploited it.
    show the capture Captured screenshot of the reply by @em

    capture taken

  79. @hanan_beer 8 Aug 2026, 08:51 UTC under 40 characters
    pretty damn damning
    show the capture Captured screenshot of the reply by @hanan_beer

    capture taken

  80. Wow this is incredible work. Free Samourai, make room for the real criminals
    show the capture Captured screenshot of the reply by @2ndCityBitcoin

    capture taken

  81. @andreujuanc 8 Aug 2026, 09:19 UTC under 40 characters
    Viste @PabloSabbatella
    show the capture Captured screenshot of the reply by @andreujuanc

    capture taken

  82. This is what I was thinking man. It was an odd class of “bug” on the only thing the software was supposed to do. I was 50-50 but now I’m 70-30
    show the capture Captured screenshot of the reply by @andreujuanc

    capture taken

  83. I lost $17,000 on their platform and did my own firmeware analysis of the code and its bypass structures. I realised they had nothing to offer in terms of security and after filing my AP order. My crypto was frozen on 2 websites, literally at a point of sale. My independent investigators at that time also linked the identities to 2 ip addresses, located near their own facility
    show the capture Captured screenshot of the reply by @DeepwatchXX1

    capture taken

  84. @No008008 8 Aug 2026, 09:44 UTC under 40 characters
    @galgitron called it
    show the capture Captured screenshot of the reply by @No008008

    capture taken

  85. @roger__9000 8 Aug 2026, 09:49 UTC under 40 characters
    Thank you for your work here man
    show the capture Captured screenshot of the reply by @roger__9000

    capture taken

  86. Also worth noting that CoinKite is from Canada and with X’s new country feature you can see that @switck is also from Canada
    show the capture Captured screenshot of the reply by @defnosaint

    capture taken

  87. I tested it using Yasmarang PRNG, used different seeds and timestamps, believe me, it's real if someone knows the PRNG used.. It has atypical state of 32-bit which is easily exhausted.
    show the capture Captured screenshot of the reply by @Coinlens001

    capture taken

  88. And now this brings us to another query, is there any other wallet that uses PRNG like LCG, Xorshift32, SFC32, PCG32 etc. All this can be exploited in hours.
    show the capture Captured screenshot of the reply by @Coinlens001

    capture taken

  89. @oomahq 8 Aug 2026, 10:24 UTC the thread author answering in their own thread
    So did you actually mine some drained wallets?
    show the capture Captured screenshot of the reply by @oomahq

    capture taken

  90. @oomahq 8 Aug 2026, 10:28 UTC the thread author answering in their own thread
    My pleasure.
    show the capture Captured screenshot of the reply by @oomahq

    capture taken

  91. @manwithpurpose_ 8 Aug 2026, 10:34 UTC under 40 characters
    legendary work sir
    show the capture Captured screenshot of the reply by @manwithpurpose_

    capture taken

  92. @oomahq 8 Aug 2026, 10:37 UTC the thread author answering in their own thread
    Thank you, Pav.
    show the capture Captured screenshot of the reply by @oomahq

    capture taken

  93. Thanks for the writeup. You should probably read this if you haven’t https:// cryptome.org/2012/07/gent-f orum-spies.htm …
    show the capture Captured screenshot of the reply by @YuviLightman

    capture taken

  94. @nanobtcs 8 Aug 2026, 11:00 UTC
    @bitdov é muita teoria da conspiração? Será?
    show the capture Captured screenshot of the reply by @nanobtcs

    capture taken

  95. @ab28ab28 8 Aug 2026, 11:26 UTC
    I wonder how many wallets dochex has swiped over the years with his exploit. Maybe that’s why that gaslit anyone who discovered their coldcard stack mysteriously swiped.
    show the capture Captured screenshot of the reply by @ab28ab28

    capture taken

  96. You guys are so fucking smart. How do you even begin to start a process like this
    show the capture Captured screenshot of the reply by @SteveAirMcNair

    capture taken

  97. @oomahq 8 Aug 2026, 13:02 UTC the thread author answering in their own thread
    Exhibit two.
    show the capture Captured screenshot of the reply by @oomahq

    capture taken

  98. @oomahq 8 Aug 2026, 13:23 UTC the thread author answering in their own thread
    ^ @mshodl maybe you clown can explain why Shitnobi was spreading this nonsense if everything in my thread was already known to him 5 days ago, by your own account.
    show the capture Captured screenshot of the reply by @oomahq

    capture taken

  99. Have you read this article? They were using a perfectly fine working TRNG firmware function of their own in multiple places in the code but Doc Hex replaced ONLY the call used for seed generation with his bugged MICROPY wrapper without explanation.
    show the capture Captured screenshot of the reply by @digitalnaut

    capture taken

  100. @btctbtctb 8 Aug 2026, 15:19 UTC
    Don’t do your own research. The vulnerability wasnt in the external dependency
    show the capture Captured screenshot of the reply by @btctbtctb

    capture taken

  101. @szabo0x 8 Aug 2026, 15:31 UTC under 40 characters
    Will they be arrested for this??
    show the capture Captured screenshot of the reply by @szabo0x

    capture taken

  102. @DelcinMaria 8 Aug 2026, 15:35 UTC under 40 characters
    @berm_blazer .
    show the capture Captured screenshot of the reply by @DelcinMaria

    capture taken

  103. Is @FBI or @DOJFraudDiv looking into this? (unless fedbois were involved somehow.. of course)
    show the capture Captured screenshot of the reply by @truthnuke916

    capture taken

  104. @DominikZazo 9 Aug 2026, 06:12 UTC under 40 characters
    @grok vies mi zhrnúť tento thread?
    show the capture Captured screenshot of the reply by @DominikZazo

    capture taken

  105. @juanzo007 9 Aug 2026, 08:42 UTC
    Forgive my ignorance, I do see how this is suspect, but if the wallets where the swept funds are being watched like a hawk, how do the perps spend it? Or do they not care about that, the intention was to try and disrupt/discredit Bitcoin in general?
    show the capture Captured screenshot of the reply by @juanzo007

    capture taken

  106. @Light36X 9 Aug 2026, 11:34 UTC under 40 characters
    Someone tell the @FBI
    show the capture Captured screenshot of the reply by @Light36X

    capture taken

  107. @LibertyTrek 9 Aug 2026, 13:13 UTC under 40 characters
    Wow... words fail me.
    show the capture Captured screenshot of the reply by @LibertyTrek

    capture taken

  108. @SavannahSmhi 10 Aug 2026, 20:17 UTC under 40 characters
    Hey
    show the capture Captured screenshot of the reply by @SavannahSmhi

    capture taken

  109. Stop juggling multiple systems. Your entire truck and civil business... One login...now with live GPS tracking
    show the capture Captured screenshot of the reply by @DirtChampApp

    capture taken

  110. Get Pro Workspace, early access, & featured work. Lottie Squad is now open worldwide. For designers, developers & motion lovers. Application link in the comments If you got into Squad, what would you build first?
    show the capture Captured screenshot of the reply by @LottieFiles

    capture taken

  111. I just launched AfterShot — a shared event camera for weddings, parties, birthdays, and trips. Invite guests by link or QR code and collect everyone’s photos and videos in one private album.
    show the capture Captured screenshot of the reply by @AbdrBytebit

    capture taken

This capture reached the end of the conversation as X served it: it stopped because nothing further loaded, not because a limit was hit. X decides what a reader is shown, so that is not the same as a guarantee of every reply.

  1. source content difference between and source content +19 -36

    Four replies (from kiawtzin, Brandoniann1, Brandonwords and xolandar) were removed even though the capture deepened from 23 to 24 scroll rounds, while two older replies (MichaelDunwort1 and theretailbull) re-entered due to the deeper scroll.

    seen · Captured here 25,980 chars
    What changed from the previous capture 55 lines
     
     And after I was done I thought a non-vaguepost version of this information was needed.
     
    -post: 2085755157296427477
    -role: reply
    -author: kiawtzin
    -name: Kiawtzin - BIP110
    -created: 2026-08-07T15:49:15Z
    -media: 0
    -body:
    -Sick
    -
     post: 2085778395825054109
     role: reply
     author: PrivacyisBetter
     body:
     Looking like many useful idiots among podcasters
     
    +post: 2085798708059459964
    +role: reply
    +author: MichaelDunwort1
    +name: Michael Dunworth
    +created: 2026-08-07T18:42:18Z
    +media: 0
    +body:
    +@ozsats256
    + 99/1 now
    +
     post: 2085799334025842914
     role: reply
     author: jstamby
     body:
     You're the best
     
    -post: 2085819407373054120
    -role: reply
    -author: Brandoniann1
    -name: Braindoniann
    -created: 2026-08-07T20:04:34Z
    -media: 0
    -body:
    -I seriously considered getting one. But I move slow
    -
     post: 2085820979641819200
     role: reply
     author: vera_rostova
     body:
     He thought he was being slick.
     
    +post: 2085832812280561894
    +role: reply
    +author: theretailbull
    +name: Tim Lamb
    +created: 2026-08-07T20:57:50Z
    +media: 0
    +body:
    +Look when switck stopped posting on X.
    +
     post: 2085835412090577304
     role: reply
     author: GRIDsquad
     media: 0
     body:
     Has anyone seen this guy in the last week?
    -
    -post: 2085883885091741732
    -role: reply
    -author: Brandonwords
    -name: Bangkok Carnivore
    -created: 2026-08-08T00:20:46Z
    -media: 0
    -body:
    -This has Israel written all over it.
    -
    -post: 2085884563675349020
    -role: reply
    -author: xolandar
    -name: Xolandar
    -created: 2026-08-08T00:23:28Z
    -media: 1
    -body:
    -Tldr:
     
     post: 2085886339959185560
     role: reply
    
    Extracted text as captured
    thread: 2085717166884618584
    url: https://x.com/oomahq/status/2085717166884618584
    author: oomahq
    
    post: 2085717166884618584
    role: focal
    author: oomahq
    name: Extractive Ghost of Unhosted Marcellus
    created: 2026-08-07T13:18:17Z
    media: 1
    body:
    I did my own investigation because I obviously don't trust them.
    
    What I found is that the external dependency of the firmware with the critical vulnerability hidden in it was written by CoinKite's CTO 
    @DocHex
     pretending to be someone else.
    
    All of the following can be verified:
    
    post: 2085717418123383008
    role: self-thread
    author: oomahq
    name: Extractive Ghost of Unhosted Marcellus
    created: 2026-08-07T13:19:17Z
    media: 1
    body:
    As a SeedSigner user I'm very familiar with 
    @nvk
    's FUD of it.
    
    One of his main talking points is that the SeedSigner and its dependencies cannot be verified down to the metal, whereas ColdCard's software stack is developed in-house at Coinkite, top-to-bottom and controlled.
    
    post: 2085717576449995123
    role: self-thread
    author: oomahq
    name: Extractive Ghost of Unhosted Marcellus
    created: 2026-08-07T13:19:55Z
    media: 1
    body:
    So imagine my surprise when it turns out that the CC's firmware depends on a random project maintained by a nym named 

    Excerpt only. The complete copy is held offline and backs quotations on this site. The original publication remains the canonical public source.

  2. source content difference between and source content +2 -30

    Two reply authors changed their display names: GregTonoski added 'Blake2b' to 'Greg Tonoski, BIP-110', and Delcin changed '#BIP110' to '#Observer'.

    seen · Captured here 26,262 chars
    What changed from the previous capture 32 lines
     post: 2085727326130598068
     role: reply
     author: GregTonoski
    -name: Greg Tonoski, BIP-110
    +name: Greg Tonoski, BIP-110, Blake2b
     created: 2026-08-07T13:58:40Z
     media: 0
     body:
     body:
     Looking like many useful idiots among podcasters
     
    -post: 2085798708059459964
    -role: reply
    -author: MichaelDunwort1
    -name: Michael Dunworth
    -created: 2026-08-07T18:42:18Z
    -media: 0
    -body:
    -@ozsats256
    - 99/1 now
    -
     post: 2085799334025842914
     role: reply
     author: jstamby
     body:
     He thought he was being slick.
     
    -post: 2085832812280561894
    -role: reply
    -author: theretailbull
    -name: Tim Lamb
    -created: 2026-08-07T20:57:50Z
    -media: 0
    -body:
    -Look when switck stopped posting on X.
    -
     post: 2085835412090577304
     role: reply
     author: GRIDsquad
     Exhibit one.
     
     Everybody knows about this already, you know. Let's talk something else.
    -
    -post: 2085873969941606436
    -role: reply
    -author: BeachMaster893
    -name: Congo_Dandy
    -created: 2026-08-07T23:41:22Z
    -media: 0
    -body:
    -He will be running to Tel Aviv
     
     post: 2085881105132233214
     role: reply
     post: 2086114171708682395
     role: reply
     author: DelcinMaria
    -name: Delcin #BIP110
    +name: Delcin #Observer
     created: 2026-08-08T15:35:51Z
     media: 0
     body:
    
    Extracted text as captured
    thread: 2085717166884618584
    url: https://x.com/oomahq/status/2085717166884618584
    author: oomahq
    
    post: 2085717166884618584
    role: focal
    author: oomahq
    name: Extractive Ghost of Unhosted Marcellus
    created: 2026-08-07T13:18:17Z
    media: 1
    body:
    I did my own investigation because I obviously don't trust them.
    
    What I found is that the external dependency of the firmware with the critical vulnerability hidden in it was written by CoinKite's CTO 
    @DocHex
     pretending to be someone else.
    
    All of the following can be verified:
    
    post: 2085717418123383008
    role: self-thread
    author: oomahq
    name: Extractive Ghost of Unhosted Marcellus
    created: 2026-08-07T13:19:17Z
    media: 1
    body:
    As a SeedSigner user I'm very familiar with 
    @nvk
    's FUD of it.
    
    One of his main talking points is that the SeedSigner and its dependencies cannot be verified down to the metal, whereas ColdCard's software stack is developed in-house at Coinkite, top-to-bottom and controlled.
    
    post: 2085717576449995123
    role: self-thread
    author: oomahq
    name: Extractive Ghost of Unhosted Marcellus
    created: 2026-08-07T13:19:55Z
    media: 1
    body:
    So imagine my surprise when it turns out that the CC's firmware depends on a random project maintained by a nym named 

    Excerpt only. The complete copy is held offline and backs quotations on this site. The original publication remains the canonical public source.

  3. source content difference between and source content +46 -10

    The thread lost one reply and gained five additional replies, plus one display-name change.

    seen · Captured here 26,719 chars
    What changed from the previous capture 56 lines
     post: 2085781515502235977
     role: reply
     author: djsenior13
    -name: David - Satoshi Services
    +name: David
     created: 2026-08-07T17:33:59Z
     media: 0
     body:
     
     
     
    -post: 2085803131741348283
    -role: reply
    -author: GigmaSigachad
    -name: Windows Explorer
    -created: 2026-08-07T18:59:53Z
    -media: 0
    -body:
    -Man there’s jews deserve prison
    -
     post: 2085805005802541288
     role: reply
     author: GotAll21
     body:
     omg
     
    +post: 2085824906327986203
    +role: reply
    +author: EGrey3717
    +name: Edever Grey
    +created: 2026-08-07T20:26:25Z
    +media: 0
    +body:
    +Thanks but intuitively this was obvious from the start
    +
     post: 2085827728415064074
     role: reply
     author: DutyToRebel
     media: 0
     body:
     Has anyone seen this guy in the last week?
    +
    +post: 2085883885091741732
    +role: reply
    +author: Brandonwords
    +name: Bangkok Carnivore
    +created: 2026-08-08T00:20:46Z
    +media: 0
    +body:
    +This has Israel written all over it.
     
     post: 2085884563675349020
     role: reply
     body:
     
     
    +post: 2085961700810064378
    +role: reply
    +author: Annathehumanist
    +name: pricesearch.net
    +created: 2026-08-08T05:29:59Z
    +media: 0
    +body:
    +Is Jon Stewart the only honest one in their group? He has empathy. Nobody else does.
    +
     post: 2085965012347359464
     role: reply
     author: guitarstar87
     @nvk
      alt account
     
    +post: 2086005374360989950
    +role: reply
    +author: 9FigureSats
    +name: DatSupraKid
    +created: 2026-08-08T08:23:32Z
    +media: 0
    +body:
    +@jackmallers
    +
     post: 2086007718104473737
     role: reply
     author: MichaelRoerade
     media: 0
     body:
     Wow... words fail me.
    +
    +post: 2086909727619895583
    +role: reply
    +author: SavannahSmhi
    +name: Savannah Smith
    +created: 2026-08-10T20:17:06Z
    +media: 0
    +body:
    +Hey
    
    Extracted text as captured
    thread: 2085717166884618584
    url: https://x.com/oomahq/status/2085717166884618584
    author: oomahq
    
    post: 2085717166884618584
    role: focal
    author: oomahq
    name: Extractive Ghost of Unhosted Marcellus
    created: 2026-08-07T13:18:17Z
    media: 1
    body:
    I did my own investigation because I obviously don't trust them.
    
    What I found is that the external dependency of the firmware with the critical vulnerability hidden in it was written by CoinKite's CTO 
    @DocHex
     pretending to be someone else.
    
    All of the following can be verified:
    
    post: 2085717418123383008
    role: self-thread
    author: oomahq
    name: Extractive Ghost of Unhosted Marcellus
    created: 2026-08-07T13:19:17Z
    media: 1
    body:
    As a SeedSigner user I'm very familiar with 
    @nvk
    's FUD of it.
    
    One of his main talking points is that the SeedSigner and its dependencies cannot be verified down to the metal, whereas ColdCard's software stack is developed in-house at Coinkite, top-to-bottom and controlled.
    
    post: 2085717576449995123
    role: self-thread
    author: oomahq
    name: Extractive Ghost of Unhosted Marcellus
    created: 2026-08-07T13:19:55Z
    media: 1
    body:
    So imagine my surprise when it turns out that the CC's firmware depends on a random project maintained by a nym named 

    Excerpt only. The complete copy is held offline and backs quotations on this site. The original publication remains the canonical public source.

  4. source content difference between and source content +11 -20

    A new reply by LibertyTrek was added and two users' display names lost their BIP110 suffixes, while two older replies are missing in a capture that stopped one scroll round earlier.

    seen · Captured here 26,078 chars
    What changed from the previous capture 31 lines
     post: 2085827728415064074
     role: reply
     author: DutyToRebel
    -name: Duty to Re₿el #BIP110
    +name: Duty to Re₿el
     created: 2026-08-07T20:37:37Z
     media: 0
     body:
     media: 0
     body:
     Has anyone seen this guy in the last week?
    -
    -post: 2085883885091741732
    -role: reply
    -author: Brandonwords
    -name: Bangkok Carnivore - BIP110
    -created: 2026-08-08T00:20:46Z
    -media: 0
    -body:
    -This has Israel written all over it.
     
     post: 2085884563675349020
     role: reply
     @nvk
      alt account
     
    -post: 2086005374360989950
    -role: reply
    -author: 9FigureSats
    -name: DatSupraKid
    -created: 2026-08-08T08:23:32Z
    -media: 0
    -body:
    -@jackmallers
    -
     post: 2086007718104473737
     role: reply
     author: MichaelRoerade
     post: 2086027079649231275
     role: reply
     author: roger__9000
    -name: ROGER 9000  + ₿IP-110
    +name: ROGER 9000
     created: 2026-08-08T09:49:46Z
     media: 0
     body:
     body:
     Someone tell the 
     @FBI
    +
    +post: 2086440709175787948
    +role: reply
    +author: LibertyTrek
    +name: LibertyTrek
    +created: 2026-08-09T13:13:23Z
    +media: 0
    +body:
    +Wow... words fail me.
    
    Extracted text as captured
    thread: 2085717166884618584
    url: https://x.com/oomahq/status/2085717166884618584
    author: oomahq
    
    post: 2085717166884618584
    role: focal
    author: oomahq
    name: Extractive Ghost of Unhosted Marcellus
    created: 2026-08-07T13:18:17Z
    media: 1
    body:
    I did my own investigation because I obviously don't trust them.
    
    What I found is that the external dependency of the firmware with the critical vulnerability hidden in it was written by CoinKite's CTO 
    @DocHex
     pretending to be someone else.
    
    All of the following can be verified:
    
    post: 2085717418123383008
    role: self-thread
    author: oomahq
    name: Extractive Ghost of Unhosted Marcellus
    created: 2026-08-07T13:19:17Z
    media: 1
    body:
    As a SeedSigner user I'm very familiar with 
    @nvk
    's FUD of it.
    
    One of his main talking points is that the SeedSigner and its dependencies cannot be verified down to the metal, whereas ColdCard's software stack is developed in-house at Coinkite, top-to-bottom and controlled.
    
    post: 2085717576449995123
    role: self-thread
    author: oomahq
    name: Extractive Ghost of Unhosted Marcellus
    created: 2026-08-07T13:19:55Z
    media: 1
    body:
    So imagine my surprise when it turns out that the CC's firmware depends on a random project maintained by a nym named 

    Excerpt only. The complete copy is held offline and backs quotations on this site. The original publication remains the canonical public source.

  5. Earliest copy held
    seen · Captured here 20,807 chars
    Extracted text as captured
    thread: 2085717166884618584
    url: https://x.com/oomahq/status/2085717166884618584
    author: oomahq
    
    post: 2085717166884618584
    role: focal
    author: oomahq
    name: Extractive Ghost of Unhosted Marcellus
    created: 2026-08-07T13:18:17Z
    media: 1
    body:
    I did my own investigation because I obviously don't trust them.
    
    What I found is that the external dependency of the firmware with the critical vulnerability hidden in it was written by CoinKite's CTO 
    @DocHex
     pretending to be someone else.
    
    All of the following can be verified:
    
    post: 2085717418123383008
    role: self-thread
    author: oomahq
    name: Extractive Ghost of Unhosted Marcellus
    created: 2026-08-07T13:19:17Z
    media: 1
    body:
    As a SeedSigner user I'm very familiar with 
    @nvk
    's FUD of it.
    
    One of his main talking points is that the SeedSigner and its dependencies cannot be verified down to the metal, whereas ColdCard's software stack is developed in-house at Coinkite, top-to-bottom and controlled.
    
    post: 2085717576449995123
    role: self-thread
    author: oomahq
    name: Extractive Ghost of Unhosted Marcellus
    created: 2026-08-07T13:19:55Z
    media: 1
    body:
    So imagine my surprise when it turns out that the CC's firmware depends on a random project maintained by a nym named 

    Excerpt only. The complete copy is held offline and backs quotations on this site. The original publication remains the canonical public source.

How to check this yourself

The excerpts and plain unified diffs above show the text this project held and how it changed. To verify a quotation, compare it against the page itself or against the Internet Archive's copies, which are independent of this project.

Complete captures are held offline rather than mirrored here, so this page shows diffs and excerpts. If a quotation is ever disputed, the full copy can be produced. Ask.