COLDCARD RNG incident the public record, collected and explained
Informational only, and this site never asks for your seed words. details

Informational only. This is an open source collection of what others have published about the incident, together with an explanation of it. It is not financial, security or legal advice, and not a substitute for professional advice about your own situation. It is not affiliated with, endorsed by, or speaking for Coinkite. Material is attributed and quoted as published; where sources disagree their scenarios are kept separate with their assumptions rather than reconciled into one answer. Everything is meant to be checked against the linked evidence rather than taken on trust. Act on your own judgement about a particular situation. Editorial standards and corrections.

Do not disclose recovery material to a website, form, message or support account. This site never asks for it, and contributions containing recovery words or private keys are not accepted.

r/Bitcoin: the Coldcard hack does not mean hardware wallets are doomed

reddit-coldcard-not-doom-hardware-wallets

https://www.reddit.com/r/Bitcoin/comments/1vmi5bq/the_coldcards_hack_doesnt_mean_hardware_wallets/

Latest reviewed change

source content difference between and

A comment by certifr1ed was added stating they are still sticking to open source wallets.

seen +8 -0 full history below
 edited: false
 body:
 Even if these hardware wallets are compromised, a hack is preventable if you just used a secure (i.e. sufficiently random) passphrase.  These are kind of like a password being added on to the random private key (although they technically just add extra entropy).  ColdCard, Trezor, and Ledger all allow you to add this extra layer of security by adding a passphrase.  ColdCard and Trezor allow anyone to scrutinize their source code so you know this passphrase makes them secure.
+
+comment: p3g2lbl
+parent: t1_p3cfauy
+author: certifr1ed
+created_utc: 1786629615

First lines only. The complete diff is in the timeline below.

Organisation
reddit
Evidence role
Community discussion
Published
not established
Source changes
1
Detected differences
1
Unreviewed
0
Copies held
2

Every check is recorded, including checks that found no text change. A detected edit is therefore bounded between two checks. The publisher's exact save time is not observable from this record. Last checked .

  1. source content difference between and Current source content +8 -0

    A comment by certifr1ed was added stating they are still sticking to open source wallets.

    seen · Captured here 7,609 chars
    What changed from the previous capture 8 lines
     edited: false
     body:
     Even if these hardware wallets are compromised, a hack is preventable if you just used a secure (i.e. sufficiently random) passphrase.  These are kind of like a password being added on to the random private key (although they technically just add extra entropy).  ColdCard, Trezor, and Ledger all allow you to add this extra layer of security by adding a passphrase.  ColdCard and Trezor allow anyone to scrutinize their source code so you know this passphrase makes them secure.
    +
    +comment: p3g2lbl
    +parent: t1_p3cfauy
    +author: certifr1ed
    +created_utc: 1786629615
    +edited: false
    +body:
    +I'm still sticking to open source
    
    Extracted text as captured
    post: 1vmi5bq
    author: chainglance_cm
    created_utc: 1786550264
    title: The Coldcard's hack doesn't mean hardware wallets are doomed
    body:
    Seeing a lot of people treat the Coldcard hack like proof hardware wallets in general aren't safe anymore. That's not really what happened.
    
    Coldcard had a bug in how their firmware generated the random numbers used to create your seed phrase, and it sat there undetected for five years. A code change in March 2021 quietly swapped out the proper hardware randomness for a broken software substitute. That made some seeds way easier to guess than they should've been, and that's how funds got drained. 
    
    That's a Coldcard problem. A mistake in their code, not a flaw in the whole idea of hardware wallets as a category. 
    
    However, I'm not making the argument that it can't happen to other brands too. Any company can ship a bad update. But wallets that are fully open source, like Trezor or Blockstream Jade, tend to have way more independent people checking the code over time, which makes bugs like this less likely to slip through for years. Not a guarantee, just better odds. And this is how most tech usually evolves. Some things go wrong but that's how it becomes more robust and anti-fragile. 
    
    But I also understand that "that's just how tech evolves" doesn't help people who actually lost their money. Genuinely feel for everyone who lost years of savings over something totally out of their control though, that part really sucks and doesn't get fixed by any of this logic.
    
    comment: p39jxs2
    parent: t3_1vmi5bq
    author: never_safe_for_life
    created_utc: 1786550674
    edited: false
    body:
    Thanks ChatGPT 
    
    comment: p39klwp
    parent: t3_1vmi5bq
    author: mrjune2040
    created_utc: 1786550844
    edited: false
    body:
    Engagement slop.
    
    comment: p39mbx2
    parent: t3_1vmi5bq
    author: GettingFasterDude
    created_utc: 1786551278
    edited: false
    body:
    I think a Coldcard-like hack involving another cold wallet company is much less likely now, than it was prior to July 30th. All the other companies have the benefit of a wakeup call. The have the opportunity to use the same powerful AI programs to secure their software that the hackers used to exploit Coldcard's very amateurish software bug.
    
    comment: p39n2e0

    Excerpt only. The complete copy is held offline and backs quotations on this site. The original publication remains the canonical public source.

  2. Earliest copy held
    seen · Captured here 7,475 chars
    Extracted text as captured
    post: 1vmi5bq
    author: chainglance_cm
    created_utc: 1786550264
    title: The Coldcard's hack doesn't mean hardware wallets are doomed
    body:
    Seeing a lot of people treat the Coldcard hack like proof hardware wallets in general aren't safe anymore. That's not really what happened.
    
    Coldcard had a bug in how their firmware generated the random numbers used to create your seed phrase, and it sat there undetected for five years. A code change in March 2021 quietly swapped out the proper hardware randomness for a broken software substitute. That made some seeds way easier to guess than they should've been, and that's how funds got drained. 
    
    That's a Coldcard problem. A mistake in their code, not a flaw in the whole idea of hardware wallets as a category. 
    
    However, I'm not making the argument that it can't happen to other brands too. Any company can ship a bad update. But wallets that are fully open source, like Trezor or Blockstream Jade, tend to have way more independent people checking the code over time, which makes bugs like this less likely to slip through for years. Not a guarantee, just better odds. And this is how most tech usually evolves. Some things go wrong but that's how it becomes more robust and anti-fragile. 
    
    But I also understand that "that's just how tech evolves" doesn't help people who actually lost their money. Genuinely feel for everyone who lost years of savings over something totally out of their control though, that part really sucks and doesn't get fixed by any of this logic.
    
    comment: p39jxs2
    parent: t3_1vmi5bq
    author: never_safe_for_life
    created_utc: 1786550674
    edited: false
    body:
    Thanks ChatGPT 
    
    comment: p39klwp
    parent: t3_1vmi5bq
    author: mrjune2040
    created_utc: 1786550844
    edited: false
    body:
    Engagement slop.
    
    comment: p39mbx2
    parent: t3_1vmi5bq
    author: GettingFasterDude
    created_utc: 1786551278
    edited: false
    body:
    I think a Coldcard-like hack involving another cold wallet company is much less likely now, than it was prior to July 30th. All the other companies have the benefit of a wakeup call. The have the opportunity to use the same powerful AI programs to secure their software that the hackers used to exploit Coldcard's very amateurish software bug.
    
    comment: p39n2e0

    Excerpt only. The complete copy is held offline and backs quotations on this site. The original publication remains the canonical public source.

How to check this yourself

The excerpts and plain unified diffs above show the text this project held and how it changed. To verify a quotation, compare it against the page itself or against the Internet Archive's copies, which are independent of this project.

Complete captures are held offline rather than mirrored here, so this page shows diffs and excerpts. If a quotation is ever disputed, the full copy can be produced. Ask.