r/coldcard: argument that Coinkite will not survive the incident
reddit-coinkite-done-for
https://www.reddit.com/r/coldcard/comments/1vcfugv/coinkite_is_done_for_here_is_why/
Latest reviewed change
source content difference between and
The Reddit thread gained a new participant comment arguing that open-source security review failed to catch the vulnerability.
body:
The CFO of coinkite was behide all of this, he’s going down.
+comment: p2ca3e3
+parent: t3_1vcfugv
+author: piejlucas
+created_utc: 1786136095
+edited: false
First lines only. The complete diff is in the timeline below.
- Organisation
- Evidence role
- Community discussion
- Published
- not established
- Source changes
- 5
- Detected differences
- 5
- Unreviewed
- 0
- Copies held
- 6
Every check is recorded, including checks that found no text change. A detected edit is therefore bounded between two checks. The publisher's exact save time is not observable from this record. Last checked .
This post is held twice: here, with this project's own note on why it matters, and again as part of the conversation captured at , which is polled for changes. Both copies are the same post; neither is a separate event.
Snapshot and diff bodies for this chain monitor are held in the local evidence archive but withheld from the public site because they can contain the addresses of people who published nothing themselves. Capture times and reviewed change summaries remain available below.
Held captures
-
The Reddit thread gained a new participant comment arguing that open-source security review failed to catch the vulnerability.
Recovered from the Internet Archive rather than captured by this project. The row records that third-party provenance separately from captures made by this project.
What changed from the previous capture 8 lines
body: The CFO of coinkite was behide all of this, he’s going down. +comment: p2ca3e3 +parent: t3_1vcfugv +author: piejlucas +created_utc: 1786136095 +edited: false +body: +To some extent it also reveals how flawed it is to rely on open source security. This code was sitting in a public container for years and only now has this “not complex” vulnerability surfaced. + more-stub: parent t1_p139si9 count <live-count>Extracted text as captured
post: 1vcfugv author: ardevd created_utc: 1785566580 title: Coinkite is done for - Here is why body: I see a lot of people here wondering what to do at this point and whether trusting Coinkite moving forward is possible. Here is my take: **Unforgivable sin #1** This bug was a integration mistake, not a complex crypto flaw. It should have been easily caught by basic build time assertions. It's a huge oversight and unforgivable for a company whose very existence is based on security. **Unforgivable sin #2** The most damning issue here is that Coinkite, a company that primary and ONLY premise is the development of a secure HARDWARE device does not test the output of that hardware at runtime. The fact that they didn't check that the output produced by the seed generator passed through standard randomness battery tests is wild! They would have instantly noticed that the outputs were coming from a deterministic PRNG if they bothered to test. **Unforgivable sin #3** At the end of the day, a hardware wallet only has one job. Generate true randomness. All coldcard wallets failed at this. Yes, you could say the bug is hard to spot, especially when doing static code analysis. The code is open source and has been subject to audits, but integration tests should have discovered this flaw before the affected firmware was ever published. The theory that this bug was discovered by AI is also a side track and completely irrelevant. This was not a complex vulnerability. comment: p10za0h parent: t3_1vcfugv author: didnt_hodl created_utc: 1785567591 edited: false body: 100% man. not properly testing the output of that PRNG is wild. I mean they did what? generated 2-3 numbers, which looked "random" to them and that's it?? they should have been running those tests non-stop, for years, just to confirm that there is no correlation, no significant repeats, etc. all standard tests would show the problem very quickly comment: p110ml4 parent: t3_1vcfugv author: ivme created_utc: 1785568248 edited: false body: What made me think is that despite being open-source, this bug wasn’t discovered until now. Therefore, one shouldn’t blindly trust open-source software. comment: p111ru6 parent: t3_1vcfugv author: Friendly_Variety6386Excerpt only. The complete copy is held offline and backs quotations on this site. The original publication remains the canonical public source.
-
Reddit added comments alleging that Coinkite personnel were responsible and should face prison, including an unsupported allegation about its CFO.
Recovered from the Internet Archive rather than captured by this project. The row records that third-party provenance separately from captures made by this project.
What changed from the previous capture 16 lines
Ledger doesn't just support BTC; it also supports many other cryptocurrencies. I'm not sure whether that would make it incompatible with a seed phrase that the Coldcard revealed after being fed dice roll values, but since the BTC-only Coldcard isn't relying on its own RNG in that case, I have a feeling that it should be possible. +comment: p1z1xpb +parent: t3_1vcfugv +author: bears196 +created_utc: 1785979460 +edited: false +body: +Yep, the people behind coldcard are responsible. They should go to prison for a very long time. + +comment: p1z2g8q +parent: t3_1vcfugv +author: bears196 +created_utc: 1785979631 +edited: false +body: +The CFO of coinkite was behide all of this, he’s going down. + more-stub: parent t1_p139si9 count <live-count>Extracted text as captured
post: 1vcfugv author: ardevd created_utc: 1785566580 title: Coinkite is done for - Here is why body: I see a lot of people here wondering what to do at this point and whether trusting Coinkite moving forward is possible. Here is my take: **Unforgivable sin #1** This bug was a integration mistake, not a complex crypto flaw. It should have been easily caught by basic build time assertions. It's a huge oversight and unforgivable for a company whose very existence is based on security. **Unforgivable sin #2** The most damning issue here is that Coinkite, a company that primary and ONLY premise is the development of a secure HARDWARE device does not test the output of that hardware at runtime. The fact that they didn't check that the output produced by the seed generator passed through standard randomness battery tests is wild! They would have instantly noticed that the outputs were coming from a deterministic PRNG if they bothered to test. **Unforgivable sin #3** At the end of the day, a hardware wallet only has one job. Generate true randomness. All coldcard wallets failed at this. Yes, you could say the bug is hard to spot, especially when doing static code analysis. The code is open source and has been subject to audits, but integration tests should have discovered this flaw before the affected firmware was ever published. The theory that this bug was discovered by AI is also a side track and completely irrelevant. This was not a complex vulnerability. comment: p10za0h parent: t3_1vcfugv author: didnt_hodl created_utc: 1785567591 edited: false body: 100% man. not properly testing the output of that PRNG is wild. I mean they did what? generated 2-3 numbers, which looked "random" to them and that's it?? they should have been running those tests non-stop, for years, just to confirm that there is no correlation, no significant repeats, etc. all standard tests would show the problem very quickly comment: p110ml4 parent: t3_1vcfugv author: ivme created_utc: 1785568248 edited: false body: What made me think is that despite being open-source, this bug wasn’t discovered until now. Therefore, one shouldn’t blindly trust open-source software. comment: p111ru6 parent: t3_1vcfugv author: Friendly_Variety6386Excerpt only. The complete copy is held offline and backs quotations on this site. The original publication remains the canonical public source.
-
Reddit added comments about a Bitcoin price prediction and using dice rolls to test deterministic seed generation.
Recovered from the Internet Archive rather than captured by this project. The row records that third-party provenance separately from captures made by this project.
What changed from the previous capture 34 lines
body: Gotcha. thanks +comment: p1v674m +parent: t1_p13uwq6 +author: Rogue_Frame83 +created_utc: 1785941151 +edited: false +body: +I concur but my timeline is slightly different. I truly believe the next best opportunity to purchase will be between Nov 30 - Dec 15 of 2026. That's our bottom, that lines up with the cycles in my very humble opinion., ands certainly not financial advice. + +I also agree - we will see $58k, perhaps as low as $56k around that time. + +comment: p1vvx2q +parent: t1_p18bt8i +author: masteratrisk +created_utc: 1785947608 +edited: false +body: +You can do it yourself. go to bitcoiner.guide/seed + +Do dice rolls and test that the seedphrase the coldcard creates is the same seed as what is done on that website. Several people have done this and confirmed it works, there are videos of people doing it in real time. + +Obviously dont use the seed you get in this test. Its just to verify that your next rolls will generate the right seed phrase. + +Eveyone doing self custody should do this, dont trust the RNG. Not your entropy not your coins. + +comment: p1wqcs0 +parent: t1_p1vvx2q +author: bje332013 +created_utc: 1785955100 +edited: false +body: +If you create a seed phrase by only entering dice roll values into the Coldcard, could that completely random seed phrase be exported onto hardware wallets that don't support dice rolls, such as those made by Ledger? + +Ledger doesn't just support BTC; it also supports many other cryptocurrencies. I'm not sure whether that would make it incompatible with a seed phrase that the Coldcard revealed after being fed dice roll values, but since the BTC-only Coldcard isn't relying on its own RNG in that case, I have a feeling that it should be possible. + more-stub: parent t1_p139si9 count <live-count>Extracted text as captured
post: 1vcfugv author: ardevd created_utc: 1785566580 title: Coinkite is done for - Here is why body: I see a lot of people here wondering what to do at this point and whether trusting Coinkite moving forward is possible. Here is my take: **Unforgivable sin #1** This bug was a integration mistake, not a complex crypto flaw. It should have been easily caught by basic build time assertions. It's a huge oversight and unforgivable for a company whose very existence is based on security. **Unforgivable sin #2** The most damning issue here is that Coinkite, a company that primary and ONLY premise is the development of a secure HARDWARE device does not test the output of that hardware at runtime. The fact that they didn't check that the output produced by the seed generator passed through standard randomness battery tests is wild! They would have instantly noticed that the outputs were coming from a deterministic PRNG if they bothered to test. **Unforgivable sin #3** At the end of the day, a hardware wallet only has one job. Generate true randomness. All coldcard wallets failed at this. Yes, you could say the bug is hard to spot, especially when doing static code analysis. The code is open source and has been subject to audits, but integration tests should have discovered this flaw before the affected firmware was ever published. The theory that this bug was discovered by AI is also a side track and completely irrelevant. This was not a complex vulnerability. comment: p10za0h parent: t3_1vcfugv author: didnt_hodl created_utc: 1785567591 edited: false body: 100% man. not properly testing the output of that PRNG is wild. I mean they did what? generated 2-3 numbers, which looked "random" to them and that's it?? they should have been running those tests non-stop, for years, just to confirm that there is no correlation, no significant repeats, etc. all standard tests would show the problem very quickly comment: p110ml4 parent: t3_1vcfugv author: ivme created_utc: 1785568248 edited: false body: What made me think is that despite being open-source, this bug wasn’t discovered until now. Therefore, one shouldn’t blindly trust open-source software. comment: p111ru6 parent: t3_1vcfugv author: Friendly_Variety6386Excerpt only. The complete copy is held offline and backs quotations on this site. The original publication remains the canonical public source.
-
An existing Reddit comment was replaced by the platform's deleted-user and deleted-comment placeholders.
Recovered from the Internet Archive rather than captured by this project. The row records that third-party provenance separately from captures made by this project.
What changed from the previous capture 4 lines
comment: p1ktv0c parent: t1_p1fuzen -author: 1n5aN1aC +author: [deleted] created_utc: 1785812839 edited: false body: -Yes, I just gave it a test actually, and it works really good. They have a python script you can use to verify it. (obviously not on your final seed) +[deleted] comment: p1mxjqp parent: t1_p1ktv0cExtracted text as captured
post: 1vcfugv author: ardevd created_utc: 1785566580 title: Coinkite is done for - Here is why body: I see a lot of people here wondering what to do at this point and whether trusting Coinkite moving forward is possible. Here is my take: **Unforgivable sin #1** This bug was a integration mistake, not a complex crypto flaw. It should have been easily caught by basic build time assertions. It's a huge oversight and unforgivable for a company whose very existence is based on security. **Unforgivable sin #2** The most damning issue here is that Coinkite, a company that primary and ONLY premise is the development of a secure HARDWARE device does not test the output of that hardware at runtime. The fact that they didn't check that the output produced by the seed generator passed through standard randomness battery tests is wild! They would have instantly noticed that the outputs were coming from a deterministic PRNG if they bothered to test. **Unforgivable sin #3** At the end of the day, a hardware wallet only has one job. Generate true randomness. All coldcard wallets failed at this. Yes, you could say the bug is hard to spot, especially when doing static code analysis. The code is open source and has been subject to audits, but integration tests should have discovered this flaw before the affected firmware was ever published. The theory that this bug was discovered by AI is also a side track and completely irrelevant. This was not a complex vulnerability. comment: p10za0h parent: t3_1vcfugv author: didnt_hodl created_utc: 1785567591 edited: false body: 100% man. not properly testing the output of that PRNG is wild. I mean they did what? generated 2-3 numbers, which looked "random" to them and that's it?? they should have been running those tests non-stop, for years, just to confirm that there is no correlation, no significant repeats, etc. all standard tests would show the problem very quickly comment: p110ml4 parent: t3_1vcfugv author: ivme created_utc: 1785568248 edited: false body: What made me think is that despite being open-source, this bug wasn’t discovered until now. Therefore, one shouldn’t blindly trust open-source software. comment: p111ru6 parent: t3_1vcfugv author: Friendly_Variety6386Excerpt only. The complete copy is held offline and backs quotations on this site. The original publication remains the canonical public source.
-
1 new Reddit comment was posted, including davidcwilliams.
Recovered from the Internet Archive rather than captured by this project. The row records that third-party provenance separately from captures made by this project.
What changed from the previous capture 8 lines
body: Yes, I just gave it a test actually, and it works really good. They have a python script you can use to verify it. (obviously not on your final seed) +comment: p1mxjqp +parent: t1_p1ktv0c +author: davidcwilliams +created_utc: 1785846029 +edited: false +body: +Gotcha. thanks + more-stub: parent t1_p139si9 count 0Extracted text as captured
post: 1vcfugv author: ardevd created_utc: 1785566580 title: Coinkite is done for - Here is why body: I see a lot of people here wondering what to do at this point and whether trusting Coinkite moving forward is possible. Here is my take: **Unforgivable sin #1** This bug was a integration mistake, not a complex crypto flaw. It should have been easily caught by basic build time assertions. It's a huge oversight and unforgivable for a company whose very existence is based on security. **Unforgivable sin #2** The most damning issue here is that Coinkite, a company that primary and ONLY premise is the development of a secure HARDWARE device does not test the output of that hardware at runtime. The fact that they didn't check that the output produced by the seed generator passed through standard randomness battery tests is wild! They would have instantly noticed that the outputs were coming from a deterministic PRNG if they bothered to test. **Unforgivable sin #3** At the end of the day, a hardware wallet only has one job. Generate true randomness. All coldcard wallets failed at this. Yes, you could say the bug is hard to spot, especially when doing static code analysis. The code is open source and has been subject to audits, but integration tests should have discovered this flaw before the affected firmware was ever published. The theory that this bug was discovered by AI is also a side track and completely irrelevant. This was not a complex vulnerability. comment: p10za0h parent: t3_1vcfugv author: didnt_hodl created_utc: 1785567591 edited: false body: 100% man. not properly testing the output of that PRNG is wild. I mean they did what? generated 2-3 numbers, which looked "random" to them and that's it?? they should have been running those tests non-stop, for years, just to confirm that there is no correlation, no significant repeats, etc. all standard tests would show the problem very quickly comment: p110ml4 parent: t3_1vcfugv author: ivme created_utc: 1785568248 edited: false body: What made me think is that despite being open-source, this bug wasn’t discovered until now. Therefore, one shouldn’t blindly trust open-source software. comment: p111ru6 parent: t3_1vcfugv author: Friendly_Variety6386Excerpt only. The complete copy is held offline and backs quotations on this site. The original publication remains the canonical public source.
-
Recovered from the Internet Archive rather than captured by this project. The row records that third-party provenance separately from captures made by this project.
What changed from the previous capture 0 lines
Extracted text as captured
post: 1vcfugv author: ardevd created_utc: 1785566580 title: Coinkite is done for - Here is why body: I see a lot of people here wondering what to do at this point and whether trusting Coinkite moving forward is possible. Here is my take: **Unforgivable sin #1** This bug was a integration mistake, not a complex crypto flaw. It should have been easily caught by basic build time assertions. It's a huge oversight and unforgivable for a company whose very existence is based on security. **Unforgivable sin #2** The most damning issue here is that Coinkite, a company that primary and ONLY premise is the development of a secure HARDWARE device does not test the output of that hardware at runtime. The fact that they didn't check that the output produced by the seed generator passed through standard randomness battery tests is wild! They would have instantly noticed that the outputs were coming from a deterministic PRNG if they bothered to test. **Unforgivable sin #3** At the end of the day, a hardware wallet only has one job. Generate true randomness. All coldcard wallets failed at this. Yes, you could say the bug is hard to spot, especially when doing static code analysis. The code is open source and has been subject to audits, but integration tests should have discovered this flaw before the affected firmware was ever published. The theory that this bug was discovered by AI is also a side track and completely irrelevant. This was not a complex vulnerability. comment: p10za0h parent: t3_1vcfugv author: didnt_hodl created_utc: 1785567591 edited: false body: 100% man. not properly testing the output of that PRNG is wild. I mean they did what? generated 2-3 numbers, which looked "random" to them and that's it?? they should have been running those tests non-stop, for years, just to confirm that there is no correlation, no significant repeats, etc. all standard tests would show the problem very quickly comment: p110ml4 parent: t3_1vcfugv author: ivme created_utc: 1785568248 edited: false body: What made me think is that despite being open-source, this bug wasn’t discovered until now. Therefore, one shouldn’t blindly trust open-source software. comment: p111ru6 parent: t3_1vcfugv author: Friendly_Variety6386Excerpt only. The complete copy is held offline and backs quotations on this site. The original publication remains the canonical public source.
0 presentation-noise differences. Sidebar, ticker and other page chrome churn that our review classified as not being changes to what the source says.
The excerpts and plain unified diffs above show the text this project held and how it changed. To verify a quotation, compare it against the page itself or against the Internet Archive's copies, which are independent of this project.
Complete captures are held offline rather than mirrored here, so this page shows diffs and excerpts. If a quotation is ever disputed, the full copy can be produced. Ask.
Compare the screenshot or a quotation against the original while it is available.