COLDCARD RNG incident the public record, collected and explained
Informational only, and this site never asks for your seed words. details

Informational only. This is an open source collection of what others have published about the incident, together with an explanation of it. It is not financial, security or legal advice, and not a substitute for professional advice about your own situation. It is not affiliated with, endorsed by, or speaking for Coinkite. Material is attributed and quoted as published; where sources disagree their scenarios are kept separate with their assumptions rather than reconciled into one answer. Everything is meant to be checked against the linked evidence rather than taken on trust. Act on your own judgement about a particular situation. Editorial standards and corrections.

Do not disclose recovery material to a website, form, message or support account. This site never asks for it, and contributions containing recovery words or private keys are not accepted.

r/coldcard: whether COLDCARD is really open source

reddit-coldcard-open-source-question

https://www.reddit.com/r/coldcard/comments/1vf4z1b/is_coldcard_really_open_source_or_not/

Latest reviewed change

source content difference between and

The post body was deleted and now reads [removed], while the title and comments remain. The prior capture preserves the original body asking whether Coldcard's code was available for inspection.

seen +1 -9 full history below
 created_utc: 1785834128
 title: Is Coldcard Really Open Source or Not?
 body:
-Is Coldcard really open-source? I'm confused. I'm getting mixed messages about this. My definition of 'Open Source' for a a hardware wallet is:  Can anyone download the code for free without permission and pay a software engineer or an AI to check for bugs?
-
-Why did no-one spot the error in Coldcard's programing?
-
-[https://insider.btcpp.dev/p/when-randombytes-runs-but-doesnt](https://insider.btcpp.dev/p/when-randombytes-runs-but-doesnt)

First lines only. The complete diff is in the timeline below.

Organisation
reddit
Evidence role
Community discussion
Published
not established
Source changes
6
Detected differences
6
Unreviewed
0
Copies held
7

Every check is recorded, including checks that found no text change. A detected edit is therefore bounded between two checks. The publisher's exact save time is not observable from this record. Last checked .

  1. source content difference between and Current source content +1 -9

    The post body was deleted and now reads [removed], while the title and comments remain. The prior capture preserves the original body asking whether Coldcard's code was available for inspection.

    seen · Captured here 4,668 chars
    What changed from the previous capture 10 lines
     created_utc: 1785834128
     title: Is Coldcard Really Open Source or Not?
     body:
    -Is Coldcard really open-source? I'm confused. I'm getting mixed messages about this. My definition of 'Open Source' for a a hardware wallet is:  Can anyone download the code for free without permission and pay a software engineer or an AI to check for bugs?
    -
    -Why did no-one spot the error in Coldcard's programing?
    -
    -[https://insider.btcpp.dev/p/when-randombytes-runs-but-doesnt](https://insider.btcpp.dev/p/when-randombytes-runs-but-doesnt)
    -
    -Was it that the code was locked up and unavailable for inspection
    -
    -or was it available to inspect but no-one bothered?
    +[removed]
     
     comment: p1m5tc6
     parent: t3_1vf4z1b
    
    Extracted text as captured
    post: 1vf4z1b
    author: Crypto-Moony
    created_utc: 1785834128
    title: Is Coldcard Really Open Source or Not?
    body:
    [removed]
    
    comment: p1m5tc6
    parent: t3_1vf4z1b
    author: Level-Set5770
    created_utc: 1785834583
    edited: false
    body:
    According to your definition.
    
    Yes, it is. Anyone can check the code.
    
    Why did no one spot the error?
    
    Because it is niche product and nobody bothered. Most of the clowns who regurgitate "trust but verify" never had the technical knowhow to actually do a proper review.
    
    comment: p1m97b1
    parent: t3_1vf4z1b
    author: RevolutionaryPick241
    created_utc: 1785836263
    edited: 1785847017
    body:
    Open source is already defined. And coldcard firmware isn't.
    
    The reason no one bothered is because it isn't open source. If you can't fork it to start your own product, you don't test it. Choosing a source available license is usually an act of misery.
    
    Edit: because it can be misunderstood: "Choosing a source available license" (instead an open source licence)...
    
    comment: p1me5rv
    parent: t3_1vf4z1b
    author: dDtaK
    created_utc: 1785838592
    edited: false
    body:
    It was open source in the sense that the code was available, and indeed this is what enabled the attacker to find the exploit. People who claim it wasn't true open source are referring to the licence it was shared under. This is something of a technicality, though it's possible that if it was shared under a more permissive licence then more people would have used the code and the bug would have been found by a good actor not a bad one. Obviously we will never know.

    Excerpt only. The complete copy is held offline and backs quotations on this site. The original publication remains the canonical public source.

  2. source content difference between and source content +8 -0

    Reddit served 1 additional comment record(s); the diff preserves their text and any edits to existing records.

    seen · Captured here 5,219 chars
    What changed from the previous capture 8 lines
     It always been don't trust. But if you are trusting and not verifying. Then don't complain that no one verified because checking buggy code is hard work and testing and the people willing to do that is because they want to build on top of it. If you can't fork it, then you have less testing.
     
     By the way, haven't you seen all the "firmware upgrade bricked my cc", "my cc doesn't boot after I..",  etc? That kind of bugs are easy to fix when another company tests the firmware on different hardware.
    +
    +comment: p1tbkzb
    +parent: t3_1vf4z1b
    +author: _gianlucag_
    +created_utc: 1785917100
    +edited: false
    +body:
    +Being open source is totally irrelevant if you are unable to compile and flash the binary into the device. You can inspect the code on github or whatever but that's non sense if you just trust that software is really the one running on your device.
    
    Extracted text as captured
    post: 1vf4z1b
    author: Crypto-Moony
    created_utc: 1785834128
    title: Is Coldcard Really Open Source or Not?
    body:
    Is Coldcard really open-source? I'm confused. I'm getting mixed messages about this. My definition of 'Open Source' for a a hardware wallet is:  Can anyone download the code for free without permission and pay a software engineer or an AI to check for bugs?
    
    Why did no-one spot the error in Coldcard's programing?
    
    [https://insider.btcpp.dev/p/when-randombytes-runs-but-doesnt](https://insider.btcpp.dev/p/when-randombytes-runs-but-doesnt)
    
    Was it that the code was locked up and unavailable for inspection
    
    or was it available to inspect but no-one bothered?
    
    comment: p1m5tc6
    parent: t3_1vf4z1b
    author: Level-Set5770
    created_utc: 1785834583
    edited: false
    body:
    According to your definition.
    
    Yes, it is. Anyone can check the code.
    
    Why did no one spot the error?
    
    Because it is niche product and nobody bothered. Most of the clowns who regurgitate "trust but verify" never had the technical knowhow to actually do a proper review.
    
    comment: p1m97b1
    parent: t3_1vf4z1b
    author: RevolutionaryPick241
    created_utc: 1785836263
    edited: 1785847017
    body:
    Open source is already defined. And coldcard firmware isn't.
    
    The reason no one bothered is because it isn't open source. If you can't fork it to start your own product, you don't test it. Choosing a source available license is usually an act of misery.
    
    Edit: because it can be misunderstood: "Choosing a source available license" (instead an open source licence)...

    Excerpt only. The complete copy is held offline and backs quotations on this site. The original publication remains the canonical public source.

  3. source content difference between and source content +10 -0

    The Reddit thread gained new participant comments.

    seen · Captured here 4,869 chars
    What changed from the previous capture 10 lines
     Just another midwit regurgitating shit takes.
     
     Since when did **"trust but verify"** become **"trust but only verify if I can fork it to start my own project"**
    +
    +comment: p1qy08f
    +parent: t1_p1qh56a
    +author: RevolutionaryPick241
    +created_utc: 1785884699
    +edited: false
    +body:
    +It always been don't trust. But if you are trusting and not verifying. Then don't complain that no one verified because checking buggy code is hard work and testing and the people willing to do that is because they want to build on top of it. If you can't fork it, then you have less testing.
    +
    +By the way, haven't you seen all the "firmware upgrade bricked my cc", "my cc doesn't boot after I..",  etc? That kind of bugs are easy to fix when another company tests the firmware on different hardware.
    
    Extracted text as captured
    post: 1vf4z1b
    author: Crypto-Moony
    created_utc: 1785834128
    title: Is Coldcard Really Open Source or Not?
    body:
    Is Coldcard really open-source? I'm confused. I'm getting mixed messages about this. My definition of 'Open Source' for a a hardware wallet is:  Can anyone download the code for free without permission and pay a software engineer or an AI to check for bugs?
    
    Why did no-one spot the error in Coldcard's programing?
    
    [https://insider.btcpp.dev/p/when-randombytes-runs-but-doesnt](https://insider.btcpp.dev/p/when-randombytes-runs-but-doesnt)
    
    Was it that the code was locked up and unavailable for inspection
    
    or was it available to inspect but no-one bothered?
    
    comment: p1m5tc6
    parent: t3_1vf4z1b
    author: Level-Set5770
    created_utc: 1785834583
    edited: false
    body:
    According to your definition.
    
    Yes, it is. Anyone can check the code.
    
    Why did no one spot the error?
    
    Because it is niche product and nobody bothered. Most of the clowns who regurgitate "trust but verify" never had the technical knowhow to actually do a proper review.
    
    comment: p1m97b1
    parent: t3_1vf4z1b
    author: RevolutionaryPick241
    created_utc: 1785836263
    edited: 1785847017
    body:
    Open source is already defined. And coldcard firmware isn't.
    
    The reason no one bothered is because it isn't open source. If you can't fork it to start your own product, you don't test it. Choosing a source available license is usually an act of misery.
    
    Edit: because it can be misunderstood: "Choosing a source available license" (instead an open source licence)...

    Excerpt only. The complete copy is held offline and backs quotations on this site. The original publication remains the canonical public source.

  4. source content difference between and source content +10 -0

    The Reddit thread gained 1 new comment about open-source verification.

    seen · Captured here 4,259 chars
    What changed from the previous capture 10 lines
     > or was it available to inspect but no-one bothered?
     
     I'd say some people bothered for the same reason the attacker last week did, they just failed for 5 years until last week, for the reason I just gave above.
    +
    +comment: p1qh56a
    +parent: t1_p1m97b1
    +author: Level-Set5770
    +created_utc: 1785879752
    +edited: false
    +body:
    +Just another midwit regurgitating shit takes.
    +
    +Since when did **"trust but verify"** become **"trust but only verify if I can fork it to start my own project"**
    
    Extracted text as captured
    post: 1vf4z1b
    author: Crypto-Moony
    created_utc: 1785834128
    title: Is Coldcard Really Open Source or Not?
    body:
    Is Coldcard really open-source? I'm confused. I'm getting mixed messages about this. My definition of 'Open Source' for a a hardware wallet is:  Can anyone download the code for free without permission and pay a software engineer or an AI to check for bugs?
    
    Why did no-one spot the error in Coldcard's programing?
    
    [https://insider.btcpp.dev/p/when-randombytes-runs-but-doesnt](https://insider.btcpp.dev/p/when-randombytes-runs-but-doesnt)
    
    Was it that the code was locked up and unavailable for inspection
    
    or was it available to inspect but no-one bothered?
    
    comment: p1m5tc6
    parent: t3_1vf4z1b
    author: Level-Set5770
    created_utc: 1785834583
    edited: false
    body:
    According to your definition.
    
    Yes, it is. Anyone can check the code.
    
    Why did no one spot the error?
    
    Because it is niche product and nobody bothered. Most of the clowns who regurgitate "trust but verify" never had the technical knowhow to actually do a proper review.
    
    comment: p1m97b1
    parent: t3_1vf4z1b
    author: RevolutionaryPick241
    created_utc: 1785836263
    edited: 1785847017
    body:
    Open source is already defined. And coldcard firmware isn't.
    
    The reason no one bothered is because it isn't open source. If you can't fork it to start your own product, you don't test it. Choosing a source available license is usually an act of misery.
    
    Edit: because it can be misunderstood: "Choosing a source available license" (instead an open source licence)...

    Excerpt only. The complete copy is held offline and backs quotations on this site. The original publication remains the canonical public source.

  5. source content difference between and source content +18 -0

    The Reddit thread gained 1 new comment.

    seen · Captured here 3,995 chars
    What changed from the previous capture 18 lines
     edited: false
     body:
     Ledger is not 100% open source, parts of the ledger os that interact with the Secure Element chip are closed. Trezor is closer to 100% but not 100%. You have to trust a company at some point.
    +
    +comment: p1pwdku
    +parent: t3_1vf4z1b
    +author: snek-jazz
    +created_utc: 1785874169
    +edited: 1785874632
    +body:
    +Some people have tried to redefine Open Source to mean FOSS (Free and Open Source Software). It's confusing and annoying.
    +
    +Yes the code is open source, but it's not FOSS.
    +
    +> Why did no-one spot the error in Coldcard's programing?
    +
    +Because it's hard for a human to find without the latest AI models. That's why it was found right after Kimi 3 became available. And it's why Calle and the others using AI to look into other projects this week with AI have said they're finding 1 critical bug per hour.
    +
    +> or was it available to inspect but no-one bothered?
    +
    +I'd say some people bothered for the same reason the attacker last week did, they just failed for 5 years until last week, for the reason I just gave above.
    
    Extracted text as captured
    post: 1vf4z1b
    author: Crypto-Moony
    created_utc: 1785834128
    title: Is Coldcard Really Open Source or Not?
    body:
    Is Coldcard really open-source? I'm confused. I'm getting mixed messages about this. My definition of 'Open Source' for a a hardware wallet is:  Can anyone download the code for free without permission and pay a software engineer or an AI to check for bugs?
    
    Why did no-one spot the error in Coldcard's programing?
    
    [https://insider.btcpp.dev/p/when-randombytes-runs-but-doesnt](https://insider.btcpp.dev/p/when-randombytes-runs-but-doesnt)
    
    Was it that the code was locked up and unavailable for inspection
    
    or was it available to inspect but no-one bothered?
    
    comment: p1m5tc6
    parent: t3_1vf4z1b
    author: Level-Set5770
    created_utc: 1785834583
    edited: false
    body:
    According to your definition.
    
    Yes, it is. Anyone can check the code.
    
    Why did no one spot the error?
    
    Because it is niche product and nobody bothered. Most of the clowns who regurgitate "trust but verify" never had the technical knowhow to actually do a proper review.
    
    comment: p1m97b1
    parent: t3_1vf4z1b
    author: RevolutionaryPick241
    created_utc: 1785836263
    edited: 1785847017
    body:
    Open source is already defined. And coldcard firmware isn't.
    
    The reason no one bothered is because it isn't open source. If you can't fork it to start your own product, you don't test it. Choosing a source available license is usually an act of misery.
    
    Edit: because it can be misunderstood: "Choosing a source available license" (instead an open source licence)...

    Excerpt only. The complete copy is held offline and backs quotations on this site. The original publication remains the canonical public source.

  6. source content difference between and source content +8 -0

    The Reddit thread gained 1 new comment.

    seen · Captured here 3,178 chars
    What changed from the previous capture 8 lines
     edited: false
     body:
     It was "source available software". Means everyone can view it, but cannot make a product using that code and start selling it, offering services, etc.
    +
    +comment: p1p3m2g
    +parent: t3_1vf4z1b
    +author: EyesFor1
    +created_utc: 1785866794
    +edited: false
    +body:
    +Ledger is not 100% open source, parts of the ledger os that interact with the Secure Element chip are closed. Trezor is closer to 100% but not 100%. You have to trust a company at some point.
    
    Extracted text as captured
    post: 1vf4z1b
    author: Crypto-Moony
    created_utc: 1785834128
    title: Is Coldcard Really Open Source or Not?
    body:
    Is Coldcard really open-source? I'm confused. I'm getting mixed messages about this. My definition of 'Open Source' for a a hardware wallet is:  Can anyone download the code for free without permission and pay a software engineer or an AI to check for bugs?
    
    Why did no-one spot the error in Coldcard's programing?
    
    [https://insider.btcpp.dev/p/when-randombytes-runs-but-doesnt](https://insider.btcpp.dev/p/when-randombytes-runs-but-doesnt)
    
    Was it that the code was locked up and unavailable for inspection
    
    or was it available to inspect but no-one bothered?
    
    comment: p1m5tc6
    parent: t3_1vf4z1b
    author: Level-Set5770
    created_utc: 1785834583
    edited: false
    body:
    According to your definition.
    
    Yes, it is. Anyone can check the code.
    
    Why did no one spot the error?
    
    Because it is niche product and nobody bothered. Most of the clowns who regurgitate "trust but verify" never had the technical knowhow to actually do a proper review.
    
    comment: p1m97b1
    parent: t3_1vf4z1b
    author: RevolutionaryPick241
    created_utc: 1785836263
    edited: 1785847017
    body:
    Open source is already defined. And coldcard firmware isn't.
    
    The reason no one bothered is because it isn't open source. If you can't fork it to start your own product, you don't test it. Choosing a source available license is usually an act of misery.
    
    Edit: because it can be misunderstood: "Choosing a source available license" (instead an open source licence)...

    Excerpt only. The complete copy is held offline and backs quotations on this site. The original publication remains the canonical public source.

  7. Earliest copy held
    seen · Captured here 2,888 chars
    Extracted text as captured
    post: 1vf4z1b
    author: Crypto-Moony
    created_utc: 1785834128
    title: Is Coldcard Really Open Source or Not?
    body:
    Is Coldcard really open-source? I'm confused. I'm getting mixed messages about this. My definition of 'Open Source' for a a hardware wallet is:  Can anyone download the code for free without permission and pay a software engineer or an AI to check for bugs?
    
    Why did no-one spot the error in Coldcard's programing?
    
    [https://insider.btcpp.dev/p/when-randombytes-runs-but-doesnt](https://insider.btcpp.dev/p/when-randombytes-runs-but-doesnt)
    
    Was it that the code was locked up and unavailable for inspection
    
    or was it available to inspect but no-one bothered?
    
    comment: p1m5tc6
    parent: t3_1vf4z1b
    author: Level-Set5770
    created_utc: 1785834583
    edited: false
    body:
    According to your definition.
    
    Yes, it is. Anyone can check the code.
    
    Why did no one spot the error?
    
    Because it is niche product and nobody bothered. Most of the clowns who regurgitate "trust but verify" never had the technical knowhow to actually do a proper review.
    
    comment: p1m97b1
    parent: t3_1vf4z1b
    author: RevolutionaryPick241
    created_utc: 1785836263
    edited: 1785847017
    body:
    Open source is already defined. And coldcard firmware isn't.
    
    The reason no one bothered is because it isn't open source. If you can't fork it to start your own product, you don't test it. Choosing a source available license is usually an act of misery.
    
    Edit: because it can be misunderstood: "Choosing a source available license" (instead an open source licence)...

    Excerpt only. The complete copy is held offline and backs quotations on this site. The original publication remains the canonical public source.

How to check this yourself

The excerpts and plain unified diffs above show the text this project held and how it changed. To verify a quotation, compare it against the page itself or against the Internet Archive's copies, which are independent of this project.

Complete captures are held offline rather than mirrored here, so this page shows diffs and excerpts. If a quotation is ever disputed, the full copy can be produced. Ask.