COLDCARD RNG incident the public record, collected and explained
Informational only, and this site never asks for your seed words. details

Informational only. This is an open source collection of what others have published about the incident, together with an explanation of it. It is not financial, security or legal advice, and not a substitute for professional advice about your own situation. It is not affiliated with, endorsed by, or speaking for Coinkite. Material is attributed and quoted as published; where sources disagree their scenarios are kept separate with their assumptions rather than reconciled into one answer. Everything is meant to be checked against the linked evidence rather than taken on trust. Act on your own judgement about a particular situation. Editorial standards and corrections.

Do not disclose recovery material to a website, form, message or support account. This site never asks for it, and contributions containing recovery words or private keys are not accepted.

r/Bitcoin: bitcoin.org still listing COLDCARD after the disclosure

reddit-bitcoin-org-still-recommends

https://www.reddit.com/r/Bitcoin/comments/1veine5/bitcoinorg_still_recommends_coldcard/

Latest reviewed change

source content difference between and

The original post body was removed and replaced with a [removed] marker.

seen +1 -9 full history below
 created_utc: 1785775201
 title: Bitcoin.org still recommends coldcard
 body:
-[Bitcoin.org](http://Bitcoin.org) still recommends coldcard.
-
-"Very secure environment" = GOOD 
-
-"Control over your money" = GOOD 

First lines only. The complete diff is in the timeline below.

Organisation
reddit
Evidence role
Community discussion
Published
not established
Source changes
7
Detected differences
7
Unreviewed
0
Copies held
8

Every check is recorded, including checks that found no text change. A detected edit is therefore bounded between two checks. The publisher's exact save time is not observable from this record. Last checked .

  1. source content difference between and Current source content +1 -9

    The original post body was removed and replaced with a [removed] marker.

    seen · Captured here 23,853 chars
    What changed from the previous capture 10 lines
     created_utc: 1785775201
     title: Bitcoin.org still recommends coldcard
     body:
    -[Bitcoin.org](http://Bitcoin.org) still recommends coldcard.
    -
    -"Very secure environment" = GOOD 
    -
    -"Control over your money" = GOOD 
    -
    -Sauce: [https://bitcoin.org/en/wallets/hardware/coldcard/?platform=hardware&step=5](https://bitcoin.org/en/wallets/hardware/coldcard/?platform=hardware&step=5)
    -
    -
    +[removed]
     
     comment: p1h9sbz
     parent: t3_1veine5
    
    Extracted text as captured
    post: 1veine5
    author: HeyDontSkipLegDay
    created_utc: 1785775201
    title: Bitcoin.org still recommends coldcard
    body:
    [removed]
    
    comment: p1h9sbz
    parent: t3_1veine5
    author: EyesFor1
    created_utc: 1785775905
    edited: false
    body:
    With 100+ dice rolls and a passphrase its as safe as any other wallet. Human trust is another issue, people got burned bad by a bug that affected one aspect.
    
    comment: p1hbn75
    parent: t1_p1h9sbz
    author: riscten
    created_utc: 1785776360
    edited: false
    body:
    Honestly at this point even using the hardware RNG is probably super safe.
    
    I would absolutely use a Coldcard. The only real risk now is that they might go under, leaving existing users with no firmware updates or warranty support.
    
    comment: p1hcdlr
    parent: t1_p1hbn75
    author: EyesFor1
    created_utc: 1785776539
    edited: false
    body:
    I agree, they are, ironically, probably one of the safest wallets due to the amount of eyes on the code verifying the firmware rng entropy and dice roll function. If they go under, which they probably will then you gotta move. Its a human emotion issue now, people got burned and trust was destroyed even when the maths says its safe.
    
    comment: p1hf7ct
    parent: t1_p1hbn75
    author: [deleted]
    created_utc: 1785777230
    edited: 1786027775
    body:
    [deleted]

    Excerpt only. The complete copy is held offline and backs quotations on this site. The original publication remains the canonical public source.

  2. source content difference between and source content +8 -0

    The thread gained a comment saying that a hardware wallet is really only needed for the last word of a seed.

    seen · Captured here 24,137 chars
    What changed from the previous capture 8 lines
     
     Any HW wallet is a dangerous device if the user is not paranoid enough.
     
    +comment: p2bpoqc
    +parent: t1_p28nwep
    +author: riscten
    +created_utc: 1786130584
    +edited: false
    +body:
    +Absolutely. You really only need the hardware wallet for that last word.
    +
     more-stub: parent t1_p1m4y3j count <live-count>
     
     more-stub: parent t1_p1lqpae count <live-count>
    
    Extracted text as captured
    post: 1veine5
    author: HeyDontSkipLegDay
    created_utc: 1785775201
    title: Bitcoin.org still recommends coldcard
    body:
    [Bitcoin.org](http://Bitcoin.org) still recommends coldcard.
    
    "Very secure environment" = GOOD 
    
    "Control over your money" = GOOD 
    
    Sauce: [https://bitcoin.org/en/wallets/hardware/coldcard/?platform=hardware&step=5](https://bitcoin.org/en/wallets/hardware/coldcard/?platform=hardware&step=5)
    
    
    
    comment: p1h9sbz
    parent: t3_1veine5
    author: EyesFor1
    created_utc: 1785775905
    edited: false
    body:
    With 100+ dice rolls and a passphrase its as safe as any other wallet. Human trust is another issue, people got burned bad by a bug that affected one aspect.
    
    comment: p1hbn75
    parent: t1_p1h9sbz
    author: riscten
    created_utc: 1785776360
    edited: false
    body:
    Honestly at this point even using the hardware RNG is probably super safe.
    
    I would absolutely use a Coldcard. The only real risk now is that they might go under, leaving existing users with no firmware updates or warranty support.
    
    comment: p1hcdlr
    parent: t1_p1hbn75
    author: EyesFor1
    created_utc: 1785776539
    edited: false
    body:
    I agree, they are, ironically, probably one of the safest wallets due to the amount of eyes on the code verifying the firmware rng entropy and dice roll function. If they go under, which they probably will then you gotta move. Its a human emotion issue now, people got burned and trust was destroyed even when the maths says its safe.

    Excerpt only. The complete copy is held offline and backs quotations on this site. The original publication remains the canonical public source.

  3. source content difference between and source content +20 -0

    Two new comments by JumpProfessional3372: one praising the bitcoin.org paranoid guide, one explaining they trust small balances to a software wallet RNG but would dice-roll a seed for serious money.

    seen · Captured here 23,967 chars
    What changed from the previous capture 20 lines
     body:
     Corrupted compromised
     
    +comment: p28n4p6
    +parent: t1_p1hol9l
    +author: JumpProfessional3372
    +created_utc: 1786099146
    +edited: false
    +body:
    +And they also have a nice paranoid guide for this. I learned a lot from that guide. 
    +
    +comment: p28nwep
    +parent: t1_p1hbn75
    +author: JumpProfessional3372
    +created_utc: 1786099469
    +edited: false
    +body:
    +I recently created a new wallet Blixt ligthning wallet, i just checked that it is an open source self custody wallet and I 100% trusted the wallet to randomly generate a seed. Why? Because I only have a few sats in there. I accept the risk here.
    +
    +But if I had to put money I cannot afford to lose, I would not use any RNG, I prefer rolling 100+ dices to generate the seed myself and adding a good passphrase. I would do this no matter the wallet manufacturer.
    +
    +Any HW wallet is a dangerous device if the user is not paranoid enough.
    +
     more-stub: parent t1_p1m4y3j count <live-count>
     
     more-stub: parent t1_p1lqpae count <live-count>
    
    Extracted text as captured
    post: 1veine5
    author: HeyDontSkipLegDay
    created_utc: 1785775201
    title: Bitcoin.org still recommends coldcard
    body:
    [Bitcoin.org](http://Bitcoin.org) still recommends coldcard.
    
    "Very secure environment" = GOOD 
    
    "Control over your money" = GOOD 
    
    Sauce: [https://bitcoin.org/en/wallets/hardware/coldcard/?platform=hardware&step=5](https://bitcoin.org/en/wallets/hardware/coldcard/?platform=hardware&step=5)
    
    
    
    comment: p1h9sbz
    parent: t3_1veine5
    author: EyesFor1
    created_utc: 1785775905
    edited: false
    body:
    With 100+ dice rolls and a passphrase its as safe as any other wallet. Human trust is another issue, people got burned bad by a bug that affected one aspect.
    
    comment: p1hbn75
    parent: t1_p1h9sbz
    author: riscten
    created_utc: 1785776360
    edited: false
    body:
    Honestly at this point even using the hardware RNG is probably super safe.
    
    I would absolutely use a Coldcard. The only real risk now is that they might go under, leaving existing users with no firmware updates or warranty support.
    
    comment: p1hcdlr
    parent: t1_p1hbn75
    author: EyesFor1
    created_utc: 1785776539
    edited: false
    body:
    I agree, they are, ironically, probably one of the safest wallets due to the amount of eyes on the code verifying the firmware rng entropy and dice roll function. If they go under, which they probably will then you gotta move. Its a human emotion issue now, people got burned and trust was destroyed even when the maths says its safe.

    Excerpt only. The complete copy is held offline and backs quotations on this site. The original publication remains the canonical public source.

  4. source content difference between and source content +4 -4

    A comment by IllllIIlIllIllllIlll about buying another hardware wallet was self-deleted: author and body now read [deleted].

    seen · Captured here 23,129 chars
    What changed from the previous capture 8 lines
     
     comment: p1hf7ct
     parent: t1_p1hbn75
    -author: IllllIIlIllIllllIlll
    +author: [deleted]
     created_utc: 1785777230
    -edited: false
    -body:
    -Even if they stop support, people can simply buy another hardware wallet. Unless they were stupid enough to not backup their seed.
    +edited: 1786027775
    +body:
    +[deleted]
     
     comment: p1hgx5k
     parent: t1_p1hf7ct
    
    Extracted text as captured
    post: 1veine5
    author: HeyDontSkipLegDay
    created_utc: 1785775201
    title: Bitcoin.org still recommends coldcard
    body:
    [Bitcoin.org](http://Bitcoin.org) still recommends coldcard.
    
    "Very secure environment" = GOOD 
    
    "Control over your money" = GOOD 
    
    Sauce: [https://bitcoin.org/en/wallets/hardware/coldcard/?platform=hardware&step=5](https://bitcoin.org/en/wallets/hardware/coldcard/?platform=hardware&step=5)
    
    
    
    comment: p1h9sbz
    parent: t3_1veine5
    author: EyesFor1
    created_utc: 1785775905
    edited: false
    body:
    With 100+ dice rolls and a passphrase its as safe as any other wallet. Human trust is another issue, people got burned bad by a bug that affected one aspect.
    
    comment: p1hbn75
    parent: t1_p1h9sbz
    author: riscten
    created_utc: 1785776360
    edited: false
    body:
    Honestly at this point even using the hardware RNG is probably super safe.
    
    I would absolutely use a Coldcard. The only real risk now is that they might go under, leaving existing users with no firmware updates or warranty support.
    
    comment: p1hcdlr
    parent: t1_p1hbn75
    author: EyesFor1
    created_utc: 1785776539
    edited: false
    body:
    I agree, they are, ironically, probably one of the safest wallets due to the amount of eyes on the code verifying the firmware rng entropy and dice roll function. If they go under, which they probably will then you gotta move. Its a human emotion issue now, people got burned and trust was destroyed even when the maths says its safe.

    Excerpt only. The complete copy is held offline and backs quotations on this site. The original publication remains the canonical public source.

  5. source content difference between and source content +3 -3

    An existing Reddit comment was edited from “Corrupted” to “Corrupted compromised.”

    seen · Captured here 23,256 chars
    What changed from the previous capture 6 lines
     parent: t3_1veine5
     author: phamtruax
     created_utc: 1785855555
    -edited: false
    -body:
    -Corrupted
    +edited: 1785872260
    +body:
    +Corrupted compromised
     
     more-stub: parent t1_p1m4y3j count 0
     
    
    Extracted text as captured
    post: 1veine5
    author: HeyDontSkipLegDay
    created_utc: 1785775201
    title: Bitcoin.org still recommends coldcard
    body:
    [Bitcoin.org](http://Bitcoin.org) still recommends coldcard.
    
    "Very secure environment" = GOOD 
    
    "Control over your money" = GOOD 
    
    Sauce: [https://bitcoin.org/en/wallets/hardware/coldcard/?platform=hardware&step=5](https://bitcoin.org/en/wallets/hardware/coldcard/?platform=hardware&step=5)
    
    
    
    comment: p1h9sbz
    parent: t3_1veine5
    author: EyesFor1
    created_utc: 1785775905
    edited: false
    body:
    With 100+ dice rolls and a passphrase its as safe as any other wallet. Human trust is another issue, people got burned bad by a bug that affected one aspect.
    
    comment: p1hbn75
    parent: t1_p1h9sbz
    author: riscten
    created_utc: 1785776360
    edited: false
    body:
    Honestly at this point even using the hardware RNG is probably super safe.
    
    I would absolutely use a Coldcard. The only real risk now is that they might go under, leaving existing users with no firmware updates or warranty support.
    
    comment: p1hcdlr
    parent: t1_p1hbn75
    author: EyesFor1
    created_utc: 1785776539
    edited: false
    body:
    I agree, they are, ironically, probably one of the safest wallets due to the amount of eyes on the code verifying the firmware rng entropy and dice roll function. If they go under, which they probably will then you gotta move. Its a human emotion issue now, people got burned and trust was destroyed even when the maths says its safe.

    Excerpt only. The complete copy is held offline and backs quotations on this site. The original publication remains the canonical public source.

  6. source content difference between and source content +8 -0

    1 new Reddit comment was posted, by phamtruax.

    seen · Captured here 23,239 chars
    What changed from the previous capture 8 lines
     body:
     Use a deck of card and a good passphrase. More than 256 bit entropy, and it takes only as long as you need to properly shuffle the deck and write it down. The usual bip39 tools work air gapped.
     
    +comment: p1nuxqj
    +parent: t3_1veine5
    +author: phamtruax
    +created_utc: 1785855555
    +edited: false
    +body:
    +Corrupted
    +
     more-stub: parent t1_p1m4y3j count 0
     
     more-stub: parent t1_p1lqpae count 0
    
    Extracted text as captured
    post: 1veine5
    author: HeyDontSkipLegDay
    created_utc: 1785775201
    title: Bitcoin.org still recommends coldcard
    body:
    [Bitcoin.org](http://Bitcoin.org) still recommends coldcard.
    
    "Very secure environment" = GOOD 
    
    "Control over your money" = GOOD 
    
    Sauce: [https://bitcoin.org/en/wallets/hardware/coldcard/?platform=hardware&step=5](https://bitcoin.org/en/wallets/hardware/coldcard/?platform=hardware&step=5)
    
    
    
    comment: p1h9sbz
    parent: t3_1veine5
    author: EyesFor1
    created_utc: 1785775905
    edited: false
    body:
    With 100+ dice rolls and a passphrase its as safe as any other wallet. Human trust is another issue, people got burned bad by a bug that affected one aspect.
    
    comment: p1hbn75
    parent: t1_p1h9sbz
    author: riscten
    created_utc: 1785776360
    edited: false
    body:
    Honestly at this point even using the hardware RNG is probably super safe.
    
    I would absolutely use a Coldcard. The only real risk now is that they might go under, leaving existing users with no firmware updates or warranty support.
    
    comment: p1hcdlr
    parent: t1_p1hbn75
    author: EyesFor1
    created_utc: 1785776539
    edited: false
    body:
    I agree, they are, ironically, probably one of the safest wallets due to the amount of eyes on the code verifying the firmware rng entropy and dice roll function. If they go under, which they probably will then you gotta move. Its a human emotion issue now, people got burned and trust was destroyed even when the maths says its safe.

    Excerpt only. The complete copy is held offline and backs quotations on this site. The original publication remains the canonical public source.

  7. source content difference between and source content +18 -0

    2 new Reddit comments were posted, including SkidMarkShark,lolonaut.

    seen · Captured here 23,130 chars
    What changed from the previous capture 18 lines
     
     If a HW wallet has homer simpson as their CTO then it is not a safe wallet to use.
     
    +comment: p1mrese
    +parent: t3_1veine5
    +author: SkidMarkShark
    +created_utc: 1785843903
    +edited: false
    +body:
    +There's nothing wrong with the device only the RNG code. It's a seed signer the blockchain is the actual wallet. Don't let any device derive your seed phrase, everyone should know that. 
    +
    +comment: p1n2t1n
    +parent: t1_p1hjred
    +author: lolonaut
    +created_utc: 1785847715
    +edited: false
    +body:
    +Use a deck of card and a good passphrase. More than 256 bit entropy, and it takes only as long as you need to properly shuffle the deck and write it down. The usual bip39 tools work air gapped.
    +
     more-stub: parent t1_p1m4y3j count 0
    +
    +more-stub: parent t1_p1lqpae count 0
    
    Extracted text as captured
    post: 1veine5
    author: HeyDontSkipLegDay
    created_utc: 1785775201
    title: Bitcoin.org still recommends coldcard
    body:
    [Bitcoin.org](http://Bitcoin.org) still recommends coldcard.
    
    "Very secure environment" = GOOD 
    
    "Control over your money" = GOOD 
    
    Sauce: [https://bitcoin.org/en/wallets/hardware/coldcard/?platform=hardware&step=5](https://bitcoin.org/en/wallets/hardware/coldcard/?platform=hardware&step=5)
    
    
    
    comment: p1h9sbz
    parent: t3_1veine5
    author: EyesFor1
    created_utc: 1785775905
    edited: false
    body:
    With 100+ dice rolls and a passphrase its as safe as any other wallet. Human trust is another issue, people got burned bad by a bug that affected one aspect.
    
    comment: p1hbn75
    parent: t1_p1h9sbz
    author: riscten
    created_utc: 1785776360
    edited: false
    body:
    Honestly at this point even using the hardware RNG is probably super safe.
    
    I would absolutely use a Coldcard. The only real risk now is that they might go under, leaving existing users with no firmware updates or warranty support.
    
    comment: p1hcdlr
    parent: t1_p1hbn75
    author: EyesFor1
    created_utc: 1785776539
    edited: false
    body:
    I agree, they are, ironically, probably one of the safest wallets due to the amount of eyes on the code verifying the firmware rng entropy and dice roll function. If they go under, which they probably will then you gotta move. Its a human emotion issue now, people got burned and trust was destroyed even when the maths says its safe.

    Excerpt only. The complete copy is held offline and backs quotations on this site. The original publication remains the canonical public source.

  8. Earliest copy held
    seen · Captured here 22,510 chars
    Extracted text as captured
    post: 1veine5
    author: HeyDontSkipLegDay
    created_utc: 1785775201
    title: Bitcoin.org still recommends coldcard
    body:
    [Bitcoin.org](http://Bitcoin.org) still recommends coldcard.
    
    "Very secure environment" = GOOD 
    
    "Control over your money" = GOOD 
    
    Sauce: [https://bitcoin.org/en/wallets/hardware/coldcard/?platform=hardware&step=5](https://bitcoin.org/en/wallets/hardware/coldcard/?platform=hardware&step=5)
    
    
    
    comment: p1h9sbz
    parent: t3_1veine5
    author: EyesFor1
    created_utc: 1785775905
    edited: false
    body:
    With 100+ dice rolls and a passphrase its as safe as any other wallet. Human trust is another issue, people got burned bad by a bug that affected one aspect.
    
    comment: p1hbn75
    parent: t1_p1h9sbz
    author: riscten
    created_utc: 1785776360
    edited: false
    body:
    Honestly at this point even using the hardware RNG is probably super safe.
    
    I would absolutely use a Coldcard. The only real risk now is that they might go under, leaving existing users with no firmware updates or warranty support.
    
    comment: p1hcdlr
    parent: t1_p1hbn75
    author: EyesFor1
    created_utc: 1785776539
    edited: false
    body:
    I agree, they are, ironically, probably one of the safest wallets due to the amount of eyes on the code verifying the firmware rng entropy and dice roll function. If they go under, which they probably will then you gotta move. Its a human emotion issue now, people got burned and trust was destroyed even when the maths says its safe.

    Excerpt only. The complete copy is held offline and backs quotations on this site. The original publication remains the canonical public source.

How to check this yourself

The excerpts and plain unified diffs above show the text this project held and how it changed. To verify a quotation, compare it against the page itself or against the Internet Archive's copies, which are independent of this project.

Complete captures are held offline rather than mirrored here, so this page shows diffs and excerpts. If a quotation is ever disputed, the full copy can be produced. Ask.