COLDCARD RNG incident the public record, collected and explained
Informational only, and this site never asks for your seed words. details

Informational only. This is an open source collection of what others have published about the incident, together with an explanation of it. It is not financial, security or legal advice, and not a substitute for professional advice about your own situation. It is not affiliated with, endorsed by, or speaking for Coinkite. Material is attributed and quoted as published; where sources disagree their scenarios are kept separate with their assumptions rather than reconciled into one answer. Everything is meant to be checked against the linked evidence rather than taken on trust. Act on your own judgement about a particular situation. Editorial standards and corrections.

Do not disclose recovery material to a website, form, message or support account. This site never asks for it, and contributions containing recovery words or private keys are not accepted.

Coinkite shipping database has been leaked

reddit-coldcard-letter-db-leak

https://www.reddit.com/r/coldcard/comments/1uiix4b/coinkite_shipping_database_has_been_leaked/

Latest reviewed change

source content difference between and

The Reddit thread gained 1 new comment.

seen +8 -0 full history below
 body:
 Yep. Just in case anyone thought it could not get worse.
 
+comment: p1qrzaj
+parent: t3_1uiix4b
+author: Otherwise-Adagio4201
+created_utc: 1785882868
+edited: false

First lines only. The complete diff is in the timeline below.

Organisation
r/coldcard
Evidence role
Community discussion
Published
2026-06-29
Source changes
3
Detected differences
4
Unreviewed
0
Copies held
5

Second first-hand report of the June 2026 letter campaign, with a photograph of a slightly reworded variant carrying the same 30 June deadline and QR pretext. The thread title states the data-leak inference outright, which Coinkite denies in its 24 June response; this archive records the inference without adopting it. Located 3 Aug 2026.

Every check is recorded, including checks that found no text change. A detected edit is therefore bounded between two checks. The publisher's exact save time is not observable from this record. Last checked .

  1. source content difference between and Current source content +8 -0

    The Reddit thread gained 1 new comment.

    seen · Captured here 13,213 chars
    What changed from the previous capture 8 lines
     body:
     Yep. Just in case anyone thought it could not get worse.
     
    +comment: p1qrzaj
    +parent: t3_1uiix4b
    +author: Otherwise-Adagio4201
    +created_utc: 1785882868
    +edited: false
    +body:
    +Like I said to start this thread…Cold  Card has a problem.   
    +
     more-stub: parent t1_oui9ob6 count 9
    
    Extracted text as captured
    post: 1uiix4b
    author: worldresident2021
    created_utc: 1782709229
    title: Coinkite shipping database has been leaked
    body:
    I received this in my mail today, it has my name on it. I’m terrified that someone out there with obvious malicious intent knows I hold my keys on coldstorage and my address. I won’t be able to sleep now. 
    
    Stay safe out there and don’t ship Bitcoin hardware to your door, regardless on how safe the company might seem. 
    
    comment: oug2t25
    parent: t3_1uiix4b
    author: Quirky-Reveal-1669
    created_utc: 1782709662
    edited: false
    body:
    Coinkite denies any leakage. 
    
    comment: oug3f0r
    parent: t1_oug2t25
    author: worldresident2021
    created_utc: 1782709942
    edited: false
    body:
    Well, they got leaked and they don’t know it. 
    
    comment: oug83ib
    parent: t3_1uiix4b
    author: worldresident2021
    created_utc: 1782712106
    edited: 1782712481
    body:
    For everyone’s information. This scam is way scarier.
    
    Went into the QR code they want you to scan.
    
    Looks like the QR code was specific to this mail letter, the url was written like it was specific for me so it is possible every mail have their own website designed to capture your data and add it to what they already have (address, name and who knows what else).
    
    They ask you to select your device and put your pin while asking to keep your seed privately secured.
    
    The only way this is useful, is if they have physical access to your device. So if you are clever enough to not provide your seed, you may have still provided what device you have and your pin along with your address. If you have followed me until now, you understand how scary this is. Someone might be actually planning to pay visits to colcard buyers.

    Excerpt only. The complete copy is held offline and backs quotations on this site. The original publication remains the canonical public source.

  2. source content difference between and source content +8 -0

    The Reddit thread gained 1 new comment.

    seen · Captured here 13,041 chars
    What changed from the previous capture 8 lines
     body:
     Aged like ass milk huh? 🤔 
     
    +comment: p1qn4jl
    +parent: t1_p1q6fdu
    +author: worldresident2021
    +created_utc: 1785881445
    +edited: false
    +body:
    +Yep. Just in case anyone thought it could not get worse.
    +
     more-stub: parent t1_oui9ob6 count 9
    
    Extracted text as captured
    post: 1uiix4b
    author: worldresident2021
    created_utc: 1782709229
    title: Coinkite shipping database has been leaked
    body:
    I received this in my mail today, it has my name on it. I’m terrified that someone out there with obvious malicious intent knows I hold my keys on coldstorage and my address. I won’t be able to sleep now. 
    
    Stay safe out there and don’t ship Bitcoin hardware to your door, regardless on how safe the company might seem. 
    
    comment: oug2t25
    parent: t3_1uiix4b
    author: Quirky-Reveal-1669
    created_utc: 1782709662
    edited: false
    body:
    Coinkite denies any leakage. 
    
    comment: oug3f0r
    parent: t1_oug2t25
    author: worldresident2021
    created_utc: 1782709942
    edited: false
    body:
    Well, they got leaked and they don’t know it. 
    
    comment: oug83ib
    parent: t3_1uiix4b
    author: worldresident2021
    created_utc: 1782712106
    edited: 1782712481
    body:
    For everyone’s information. This scam is way scarier.
    
    Went into the QR code they want you to scan.
    
    Looks like the QR code was specific to this mail letter, the url was written like it was specific for me so it is possible every mail have their own website designed to capture your data and add it to what they already have (address, name and who knows what else).
    
    They ask you to select your device and put your pin while asking to keep your seed privately secured.
    
    The only way this is useful, is if they have physical access to your device. So if you are clever enough to not provide your seed, you may have still provided what device you have and your pin along with your address. If you have followed me until now, you understand how scary this is. Someone might be actually planning to pay visits to colcard buyers.

    Excerpt only. The complete copy is held offline and backs quotations on this site. The original publication remains the canonical public source.

  3. source content difference between and source content +8 -0

    The Reddit thread gained 1 new comment.

    seen · Captured here 12,877 chars
    What changed from the previous capture 8 lines
       
     Saying we did not leak anything is without a proper investigation of each claim is asking for trouble. Hopefully you can read this 1 month later. 
     
    +comment: p1q6fdu
    +parent: t3_1uiix4b
    +author: olivesandparmesan
    +created_utc: 1785876834
    +edited: false
    +body:
    +Aged like ass milk huh? 🤔 
    +
     more-stub: parent t1_oui9ob6 count 9
    
    Extracted text as captured
    post: 1uiix4b
    author: worldresident2021
    created_utc: 1782709229
    title: Coinkite shipping database has been leaked
    body:
    I received this in my mail today, it has my name on it. I’m terrified that someone out there with obvious malicious intent knows I hold my keys on coldstorage and my address. I won’t be able to sleep now. 
    
    Stay safe out there and don’t ship Bitcoin hardware to your door, regardless on how safe the company might seem. 
    
    comment: oug2t25
    parent: t3_1uiix4b
    author: Quirky-Reveal-1669
    created_utc: 1782709662
    edited: false
    body:
    Coinkite denies any leakage. 
    
    comment: oug3f0r
    parent: t1_oug2t25
    author: worldresident2021
    created_utc: 1782709942
    edited: false
    body:
    Well, they got leaked and they don’t know it. 
    
    comment: oug83ib
    parent: t3_1uiix4b
    author: worldresident2021
    created_utc: 1782712106
    edited: 1782712481
    body:
    For everyone’s information. This scam is way scarier.
    
    Went into the QR code they want you to scan.
    
    Looks like the QR code was specific to this mail letter, the url was written like it was specific for me so it is possible every mail have their own website designed to capture your data and add it to what they already have (address, name and who knows what else).
    
    They ask you to select your device and put your pin while asking to keep your seed privately secured.
    
    The only way this is useful, is if they have physical access to your device. So if you are clever enough to not provide your seed, you may have still provided what device you have and your pin along with your address. If you have followed me until now, you understand how scary this is. Someone might be actually planning to pay visits to colcard buyers.

    Excerpt only. The complete copy is held offline and backs quotations on this site. The original publication remains the canonical public source.

  4. Earliest copy held
    seen · Captured here 12,742 chars
    Extracted text as captured
    post: 1uiix4b
    author: worldresident2021
    created_utc: 1782709229
    title: Coinkite shipping database has been leaked
    body:
    I received this in my mail today, it has my name on it. I’m terrified that someone out there with obvious malicious intent knows I hold my keys on coldstorage and my address. I won’t be able to sleep now. 
    
    Stay safe out there and don’t ship Bitcoin hardware to your door, regardless on how safe the company might seem. 
    
    comment: oug2t25
    parent: t3_1uiix4b
    author: Quirky-Reveal-1669
    created_utc: 1782709662
    edited: false
    body:
    Coinkite denies any leakage. 
    
    comment: oug3f0r
    parent: t1_oug2t25
    author: worldresident2021
    created_utc: 1782709942
    edited: false
    body:
    Well, they got leaked and they don’t know it. 
    
    comment: oug83ib
    parent: t3_1uiix4b
    author: worldresident2021
    created_utc: 1782712106
    edited: 1782712481
    body:
    For everyone’s information. This scam is way scarier.
    
    Went into the QR code they want you to scan.
    
    Looks like the QR code was specific to this mail letter, the url was written like it was specific for me so it is possible every mail have their own website designed to capture your data and add it to what they already have (address, name and who knows what else).
    
    They ask you to select your device and put your pin while asking to keep your seed privately secured.
    
    The only way this is useful, is if they have physical access to your device. So if you are clever enough to not provide your seed, you may have still provided what device you have and your pin along with your address. If you have followed me until now, you understand how scary this is. Someone might be actually planning to pay visits to colcard buyers.

    Excerpt only. The complete copy is held offline and backs quotations on this site. The original publication remains the canonical public source.

1 presentation-noise difference. Sidebar, ticker and other page chrome churn that our review classified as not being a change to what the source says.
  • +1 -1 Only the Reddit more-comments stub count changed.
How to check this yourself

The excerpts and plain unified diffs above show the text this project held and how it changed. To verify a quotation, compare it against the page itself or against the Internet Archive's copies, which are independent of this project.

Complete captures are held offline rather than mirrored here, so this page shows diffs and excerpts. If a quotation is ever disputed, the full copy can be produced. Ask.