r/Bitcoin: what Coinkite could have done once the vulnerability was found
reddit-coinkite-options-after-disclosure
https://www.reddit.com/r/Bitcoin/comments/1ve1r5g/is_there_anything_coinkite_could_have_done_once/
Latest reviewed change
source content difference between and
The thread gained a comment alleging an unaddressed RNG failure and arguing that routine randomness and integration testing should have detected it.
body:
Another issue is that some customers themselves could be the bad actors, and alerting them just gives them an early heads-up on the vulnerability.
+comment: p1x7kxw
+parent: t1_p1do8xt
+author: Present-Resolution23
+created_utc: 1785959521
+edited: false
First lines only. The complete diff is in the timeline below.
- Organisation
- Evidence role
- Community discussion
- Published
- not established
- Source changes
- 4
- Detected differences
- 4
- Unreviewed
- 0
- Copies held
- 5
Every check is recorded, including checks that found no text change. A detected edit is therefore bounded between two checks. The publisher's exact save time is not observable from this record. Last checked .
This post is held twice: here, with this project's own note on why it matters, and again as part of the conversation captured at , which is polled for changes. Both copies are the same post; neither is a separate event.
Snapshot and diff bodies for this chain monitor are held in the local evidence archive but withheld from the public site because they can contain the addresses of people who published nothing themselves. Capture times and reviewed change summaries remain available below.
Held captures
-
The thread gained a comment alleging an unaddressed RNG failure and arguing that routine randomness and integration testing should have detected it.
Recovered from the Internet Archive rather than captured by this project. The row records that third-party provenance separately from captures made by this project.
What changed from the previous capture 10 lines
body: Another issue is that some customers themselves could be the bad actors, and alerting them just gives them an early heads-up on the vulnerability. +comment: p1x7kxw +parent: t1_p1do8xt +author: Present-Resolution23 +created_utc: 1785959521 +edited: false +body: +I know I'm coming from the future with more information but.. no shot they would have let an exploit like this go unaddressed for years.. This wasn't like a small bug.. This was entirely bypassing all of their fancy encryption for a basic pseudorandom rng with limited seeds.. + +That said.. they absolutely should have caught this with randomness testing, integration testing (simply replacing the call to the hardware RNG with a call to a counter would have told them instantly the hardware was never being hit,) or any number of other standard procedures in the industry.. Giving them the most benefit.. I imagine they probably ran these when they first launched but after swapping libraries, or ANYTIME in the last half-decade, they definitely should have run any of the above at least once.. It's negligent enough that I expect they're beyond toast once the litigation starts. + more-stub: parent t1_p1jyoqk count <live-count>Extracted text as captured
post: 1ve1r5g author: JollyJury created_utc: 1785726750 title: Is there anything Coinkite could have done once the vulnerability was found? body: Let's say you are the Coinkite CEO and it is one week before the first ColdCard attack. You have identified the vulnerability and know that hackers can recreate user keys. What is your course of action? Obviously you warn your customers, right? But the second that message goes public, every hacker on the planet will race to steal those keys. Perhaps a lucky few will get the warning in time and move their bitcoin out, but it would be too late for most. Or maybe the attack takes enough time to plan that most users might get out safely? Was there any way out of this with minimal losses or were they completely fucked the moment the ColdCards shipped with the weak RNG? comment: p1dn8mf parent: t3_1ve1r5g author: [deleted] created_utc: 1785727190 edited: false body: [deleted] held before deletion (captured 20260804T171722Z): One of the tricky things is they delete all customer data after a few months so they didn’t have a way to contact customers directly. Good from a security point of view but obviously backfired in this case. comment: p1do8xt parent: t3_1ve1r5g author: No-Aardvark-3840 created_utc: 1785727596 edited: false body: Aren’t there a ton of reports emerging that they have known about these vulnerabilities for years and intentionally suppressed reports? comment: p1docjr parent: t3_1ve1r5g author: alpacastacka created_utc: 1785727637 edited: 1785729576 body: best thing I could think is to make an announcement saying there is a security flaw in the hardware and urge people to switch to a different wallet or perhaps breadcrumb with updates and try to convince people to upgrade to a multisig hackers would likely start digging in though, so it's a tough one for sure comment: p1dpke6 parent: t1_p1do8xtExcerpt only. The complete copy is held offline and backs quotations on this site. The original publication remains the canonical public source.
-
A comment characterising the event as a wallet collision and a longer comment arguing against multisig were removed or replaced with deleted-account placeholders.
Recovered from the Internet Archive rather than captured by this project. The row records that third-party provenance separately from captures made by this project.
What changed from the previous capture 12 lines
comment: p1ed0nj parent: t1_p1dyd6l -author: OldHamburger7923 +author: [deleted] created_utc: 1785738807 edited: false body: -more likely a wallet collision than a hack. - -comment: p1edgwu -parent: t1_p1e36i7 -author: OldHamburger7923 -created_utc: 1785739032 -edited: false -body: -i really don't see why multisig. A passphrase can have more entropy than the 24 seed itself with sufficient length (40 characters). If you randomly generate the seed yourself, it's already secure. Multi sig does what? Relies on you not trusting either wallet? But then you're just hoping at least one of them was generated properly. You may as well generate your own properly and not hope and pray. +[deleted] comment: p1efdei parent: t1_p1dps95Extracted text as captured
post: 1ve1r5g author: JollyJury created_utc: 1785726750 title: Is there anything Coinkite could have done once the vulnerability was found? body: Let's say you are the Coinkite CEO and it is one week before the first ColdCard attack. You have identified the vulnerability and know that hackers can recreate user keys. What is your course of action? Obviously you warn your customers, right? But the second that message goes public, every hacker on the planet will race to steal those keys. Perhaps a lucky few will get the warning in time and move their bitcoin out, but it would be too late for most. Or maybe the attack takes enough time to plan that most users might get out safely? Was there any way out of this with minimal losses or were they completely fucked the moment the ColdCards shipped with the weak RNG? comment: p1dn8mf parent: t3_1ve1r5g author: [deleted] created_utc: 1785727190 edited: false body: [deleted] held before deletion (captured 20260804T171722Z): One of the tricky things is they delete all customer data after a few months so they didn’t have a way to contact customers directly. Good from a security point of view but obviously backfired in this case. comment: p1do8xt parent: t3_1ve1r5g author: No-Aardvark-3840 created_utc: 1785727596 edited: false body: Aren’t there a ton of reports emerging that they have known about these vulnerabilities for years and intentionally suppressed reports? comment: p1docjr parent: t3_1ve1r5g author: alpacastacka created_utc: 1785727637 edited: 1785729576 body: best thing I could think is to make an announcement saying there is a security flaw in the hardware and urge people to switch to a different wallet or perhaps breadcrumb with updates and try to convince people to upgrade to a multisig hackers would likely start digging in though, so it's a tough one for sure comment: p1dpke6 parent: t1_p1do8xtExcerpt only. The complete copy is held offline and backs quotations on this site. The original publication remains the canonical public source.
-
An existing Reddit comment was edited or removed.
Recovered from the Internet Archive rather than captured by this project. The row records that third-party provenance separately from captures made by this project.
What changed from the previous capture 4 lines
comment: p1dn8mf parent: t3_1ve1r5g -author: SmokeAndSkate +author: [deleted] created_utc: 1785727190 edited: false body: -One of the tricky things is they delete all customer data after a few months so they didn’t have a way to contact customers directly. Good from a security point of view but obviously backfired in this case. +[deleted] comment: p1do8xt parent: t3_1ve1r5gExtracted text as captured
post: 1ve1r5g author: JollyJury created_utc: 1785726750 title: Is there anything Coinkite could have done once the vulnerability was found? body: Let's say you are the Coinkite CEO and it is one week before the first ColdCard attack. You have identified the vulnerability and know that hackers can recreate user keys. What is your course of action? Obviously you warn your customers, right? But the second that message goes public, every hacker on the planet will race to steal those keys. Perhaps a lucky few will get the warning in time and move their bitcoin out, but it would be too late for most. Or maybe the attack takes enough time to plan that most users might get out safely? Was there any way out of this with minimal losses or were they completely fucked the moment the ColdCards shipped with the weak RNG? comment: p1dn8mf parent: t3_1ve1r5g author: [deleted] created_utc: 1785727190 edited: false body: [deleted] held before deletion (captured 20260804T171722Z): One of the tricky things is they delete all customer data after a few months so they didn’t have a way to contact customers directly. Good from a security point of view but obviously backfired in this case. comment: p1do8xt parent: t3_1ve1r5g author: No-Aardvark-3840 created_utc: 1785727596 edited: false body: Aren’t there a ton of reports emerging that they have known about these vulnerabilities for years and intentionally suppressed reports? comment: p1docjr parent: t3_1ve1r5g author: alpacastacka created_utc: 1785727637 edited: 1785729576 body: best thing I could think is to make an announcement saying there is a security flaw in the hardware and urge people to switch to a different wallet or perhaps breadcrumb with updates and try to convince people to upgrade to a multisig hackers would likely start digging in though, so it's a tough one for sure comment: p1dpke6 parent: t1_p1do8xtExcerpt only. The complete copy is held offline and backs quotations on this site. The original publication remains the canonical public source.
-
The Reddit thread gained 1 new comment.
Recovered from the Internet Archive rather than captured by this project. The row records that third-party provenance separately from captures made by this project.
What changed from the previous capture 8 lines
Stay in school and don't do Matt Kratter kids +comment: p1ol912 +parent: t1_p1ejb70 +author: JollyJury +created_utc: 1785862259 +edited: false +body: +Another issue is that some customers themselves could be the bad actors, and alerting them just gives them an early heads-up on the vulnerability. + more-stub: parent t1_p1jyoqk count 0Extracted text as captured
post: 1ve1r5g author: JollyJury created_utc: 1785726750 title: Is there anything Coinkite could have done once the vulnerability was found? body: Let's say you are the Coinkite CEO and it is one week before the first ColdCard attack. You have identified the vulnerability and know that hackers can recreate user keys. What is your course of action? Obviously you warn your customers, right? But the second that message goes public, every hacker on the planet will race to steal those keys. Perhaps a lucky few will get the warning in time and move their bitcoin out, but it would be too late for most. Or maybe the attack takes enough time to plan that most users might get out safely? Was there any way out of this with minimal losses or were they completely fucked the moment the ColdCards shipped with the weak RNG? comment: p1dn8mf parent: t3_1ve1r5g author: SmokeAndSkate created_utc: 1785727190 edited: false body: One of the tricky things is they delete all customer data after a few months so they didn’t have a way to contact customers directly. Good from a security point of view but obviously backfired in this case. comment: p1do8xt parent: t3_1ve1r5g author: No-Aardvark-3840 created_utc: 1785727596 edited: false body: Aren’t there a ton of reports emerging that they have known about these vulnerabilities for years and intentionally suppressed reports? comment: p1docjr parent: t3_1ve1r5g author: alpacastacka created_utc: 1785727637 edited: 1785729576 body: best thing I could think is to make an announcement saying there is a security flaw in the hardware and urge people to switch to a different wallet or perhaps breadcrumb with updates and try to convince people to upgrade to a multisig hackers would likely start digging in though, so it's a tough one for sure comment: p1dpke6 parent: t1_p1do8xt author: moviemaker2 created_utc: 1785728131 edited: falseExcerpt only. The complete copy is held offline and backs quotations on this site. The original publication remains the canonical public source.
-
Recovered from the Internet Archive rather than captured by this project. The row records that third-party provenance separately from captures made by this project.
What changed from the previous capture 0 lines
Extracted text as captured
post: 1ve1r5g author: JollyJury created_utc: 1785726750 title: Is there anything Coinkite could have done once the vulnerability was found? body: Let's say you are the Coinkite CEO and it is one week before the first ColdCard attack. You have identified the vulnerability and know that hackers can recreate user keys. What is your course of action? Obviously you warn your customers, right? But the second that message goes public, every hacker on the planet will race to steal those keys. Perhaps a lucky few will get the warning in time and move their bitcoin out, but it would be too late for most. Or maybe the attack takes enough time to plan that most users might get out safely? Was there any way out of this with minimal losses or were they completely fucked the moment the ColdCards shipped with the weak RNG? comment: p1dn8mf parent: t3_1ve1r5g author: SmokeAndSkate created_utc: 1785727190 edited: false body: One of the tricky things is they delete all customer data after a few months so they didn’t have a way to contact customers directly. Good from a security point of view but obviously backfired in this case. comment: p1do8xt parent: t3_1ve1r5g author: No-Aardvark-3840 created_utc: 1785727596 edited: false body: Aren’t there a ton of reports emerging that they have known about these vulnerabilities for years and intentionally suppressed reports? comment: p1docjr parent: t3_1ve1r5g author: alpacastacka created_utc: 1785727637 edited: 1785729576 body: best thing I could think is to make an announcement saying there is a security flaw in the hardware and urge people to switch to a different wallet or perhaps breadcrumb with updates and try to convince people to upgrade to a multisig hackers would likely start digging in though, so it's a tough one for sure comment: p1dpke6 parent: t1_p1do8xt author: moviemaker2 created_utc: 1785728131 edited: falseExcerpt only. The complete copy is held offline and backs quotations on this site. The original publication remains the canonical public source.
0 presentation-noise differences. Sidebar, ticker and other page chrome churn that our review classified as not being changes to what the source says.
The excerpts and plain unified diffs above show the text this project held and how it changed. To verify a quotation, compare it against the page itself or against the Internet Archive's copies, which are independent of this project.
Complete captures are held offline rather than mirrored here, so this page shows diffs and excerpts. If a quotation is ever disputed, the full copy can be produced. Ask.
Compare the screenshot or a quotation against the original while it is available.