COLDCARD RNG incident the public record, collected and explained
Informational only, and this site never asks for your seed words. details

Informational only. This is an open source collection of what others have published about the incident, together with an explanation of it. It is not financial, security or legal advice, and not a substitute for professional advice about your own situation. It is not affiliated with, endorsed by, or speaking for Coinkite. Material is attributed and quoted as published; where sources disagree their scenarios are kept separate with their assumptions rather than reconciled into one answer. Everything is meant to be checked against the linked evidence rather than taken on trust. Act on your own judgement about a particular situation. Editorial standards and corrections.

Do not disclose recovery material to a website, form, message or support account. This site never asks for it, and contributions containing recovery words or private keys are not accepted.

r/Bitcoin: unaffected owner moving off COLDCARD anyway

reddit-coldcard-never-again

https://www.reddit.com/r/Bitcoin/comments/1vdsqhy/coldcard_youll_never_hurt_me_again/

Latest reviewed change

source content difference between and

A comment comparing the incident to Bitcointalk OGs recommending 256 coin flips was removed.

seen +0 -8 full history below
 body:
 why don’t you just use trezor instead? Ledger also owns your seed btw
 
-comment: p1bu274
-parent: t1_p1bopi0
-author: 0fWhomIAmChief
-created_utc: 1785705472
-edited: false

First lines only. The complete diff is in the timeline below.

Organisation
reddit
Evidence role
Community discussion
Published
not established
Source changes
3
Detected differences
3
Unreviewed
0
Copies held
4

Every check is recorded, including checks that found no text change. A detected edit is therefore bounded between two checks. The publisher's exact save time is not observable from this record. Last checked .

  1. source content difference between and Current source content +0 -8

    A comment comparing the incident to Bitcointalk OGs recommending 256 coin flips was removed.

    seen · Captured here 12,517 chars
    What changed from the previous capture 8 lines
     body:
     why don’t you just use trezor instead? Ledger also owns your seed btw
     
    -comment: p1bu274
    -parent: t1_p1bopi0
    -author: 0fWhomIAmChief
    -created_utc: 1785705472
    -edited: false
    -body:
    -This is what we have come to, OGs on Bitcointalk always swore by the 256 coin flips so i guess this is the 2026 version of that lol
    -
     comment: p1buuph
     parent: t1_p1boq3w
     author: NorthSky6
    
    Extracted text as captured
    post: 1vdsqhy
    author: Mentalextensi0n
    created_utc: 1785702715
    title: ColdCard: You’ll never hurt me again!
    body:
    My seed used with this device was strong and I was unaffected by the security flaw in the RNG setup. Still, I’m re-doing everything. I am moving back to my ledger until I get a multisig setup with a SeedSigner or similar. It’s gonna be a pain to generate a new private key or two and stamp em, so I am getting my sledgehammer swinging arm back in good shape. 
    
    What about you?
    
    Be safe out there…
    
    comment: p1bkzza
    parent: t3_1vdsqhy
    author: 0x14f
    created_utc: 1785702861
    edited: false
    body:
    Looks like you added a lot of randomness :)
    
    comment: p1blmbr
    parent: t3_1vdsqhy
    author: jwhendy
    created_utc: 1785703036
    edited: false
    body:
    I bet we'll get some gun range compilations of "shoot here" soon enough.
    
    comment: p1blqtl
    parent: t3_1vdsqhy
    author: Blade_Runner_69
    created_utc: 1785703070
    edited: false
    body:
    And the crowd goes wild... 👏
    
    comment: p1bm31r
    parent: t3_1vdsqhy
    author: Chemical_Resolve6038
    created_utc: 1785703166
    edited: false

    Excerpt only. The complete copy is held offline and backs quotations on this site. The original publication remains the canonical public source.

  2. source content difference between and source content +8 -0

    The Reddit thread gained a new participant comment urging the poster to preserve evidence for small claims court.

    seen · Captured here 12,753 chars
    What changed from the previous capture 8 lines
     edited: false
     body:
     Just like when ledger introduced Ledger Recover.. Where are the Cold Card tough guys now?
    +
    +comment: p2et2wr
    +parent: t3_1vdsqhy
    +author: Legitimate_Form5449
    +created_utc: 1786168023
    +edited: false
    +body:
    +Y are u doing this? Y are u destroying the evidence? take them to small claims court
    
    Extracted text as captured
    post: 1vdsqhy
    author: Mentalextensi0n
    created_utc: 1785702715
    title: ColdCard: You’ll never hurt me again!
    body:
    My seed used with this device was strong and I was unaffected by the security flaw in the RNG setup. Still, I’m re-doing everything. I am moving back to my ledger until I get a multisig setup with a SeedSigner or similar. It’s gonna be a pain to generate a new private key or two and stamp em, so I am getting my sledgehammer swinging arm back in good shape. 
    
    What about you?
    
    Be safe out there…
    
    comment: p1bkzza
    parent: t3_1vdsqhy
    author: 0x14f
    created_utc: 1785702861
    edited: false
    body:
    Looks like you added a lot of randomness :)
    
    comment: p1blmbr
    parent: t3_1vdsqhy
    author: jwhendy
    created_utc: 1785703036
    edited: false
    body:
    I bet we'll get some gun range compilations of "shoot here" soon enough.
    
    comment: p1blqtl
    parent: t3_1vdsqhy
    author: Blade_Runner_69
    created_utc: 1785703070
    edited: false
    body:
    And the crowd goes wild... 👏
    
    comment: p1bm31r
    parent: t3_1vdsqhy
    author: Chemical_Resolve6038
    created_utc: 1785703166
    edited: false

    Excerpt only. The complete copy is held offline and backs quotations on this site. The original publication remains the canonical public source.

  3. source content difference between and source content +0 -8

    A comment by DonTheHolder ("Office Space") no longer appears in the thread; it was deleted on the source.

    seen · Captured here 12,559 chars
    What changed from the previous capture 8 lines
     body:
     So those with 24 word seed on coldcard are safe? It was those with 12 words generated on coldcard that were hacked?
     
    -comment: p1e80go
    -parent: t3_1vdsqhy
    -author: DonTheHolder
    -created_utc: 1785736346
    -edited: false
    -body:
    -Office Space 🏬 🏢 
    -
     comment: p1e9s7k
     parent: t3_1vdsqhy
     author: setec404
    
    Extracted text as captured
    post: 1vdsqhy
    author: Mentalextensi0n
    created_utc: 1785702715
    title: ColdCard: You’ll never hurt me again!
    body:
    My seed used with this device was strong and I was unaffected by the security flaw in the RNG setup. Still, I’m re-doing everything. I am moving back to my ledger until I get a multisig setup with a SeedSigner or similar. It’s gonna be a pain to generate a new private key or two and stamp em, so I am getting my sledgehammer swinging arm back in good shape. 
    
    What about you?
    
    Be safe out there…
    
    comment: p1bkzza
    parent: t3_1vdsqhy
    author: 0x14f
    created_utc: 1785702861
    edited: false
    body:
    Looks like you added a lot of randomness :)
    
    comment: p1blmbr
    parent: t3_1vdsqhy
    author: jwhendy
    created_utc: 1785703036
    edited: false
    body:
    I bet we'll get some gun range compilations of "shoot here" soon enough.
    
    comment: p1blqtl
    parent: t3_1vdsqhy
    author: Blade_Runner_69
    created_utc: 1785703070
    edited: false
    body:
    And the crowd goes wild... 👏
    
    comment: p1bm31r
    parent: t3_1vdsqhy
    author: Chemical_Resolve6038
    created_utc: 1785703166
    edited: false

    Excerpt only. The complete copy is held offline and backs quotations on this site. The original publication remains the canonical public source.

  4. Earliest copy held
    seen · Captured here 12,681 chars
    Extracted text as captured
    post: 1vdsqhy
    author: Mentalextensi0n
    created_utc: 1785702715
    title: ColdCard: You’ll never hurt me again!
    body:
    My seed used with this device was strong and I was unaffected by the security flaw in the RNG setup. Still, I’m re-doing everything. I am moving back to my ledger until I get a multisig setup with a SeedSigner or similar. It’s gonna be a pain to generate a new private key or two and stamp em, so I am getting my sledgehammer swinging arm back in good shape. 
    
    What about you?
    
    Be safe out there…
    
    comment: p1bkzza
    parent: t3_1vdsqhy
    author: 0x14f
    created_utc: 1785702861
    edited: false
    body:
    Looks like you added a lot of randomness :)
    
    comment: p1blmbr
    parent: t3_1vdsqhy
    author: jwhendy
    created_utc: 1785703036
    edited: false
    body:
    I bet we'll get some gun range compilations of "shoot here" soon enough.
    
    comment: p1blqtl
    parent: t3_1vdsqhy
    author: Blade_Runner_69
    created_utc: 1785703070
    edited: false
    body:
    And the crowd goes wild... 👏
    
    comment: p1bm31r
    parent: t3_1vdsqhy
    author: Chemical_Resolve6038
    created_utc: 1785703166
    edited: false

    Excerpt only. The complete copy is held offline and backs quotations on this site. The original publication remains the canonical public source.

How to check this yourself

The excerpts and plain unified diffs above show the text this project held and how it changed. To verify a quotation, compare it against the page itself or against the Internet Archive's copies, which are independent of this project.

Complete captures are held offline rather than mirrored here, so this page shows diffs and excerpts. If a quotation is ever disputed, the full copy can be produced. Ask.