COLDCARD RNG incident the public record, collected and explained
Informational only, and this site never asks for your seed words. details

Informational only. This is an open source collection of what others have published about the incident, together with an explanation of it. It is not financial, security or legal advice, and not a substitute for professional advice about your own situation. It is not affiliated with, endorsed by, or speaking for Coinkite. Material is attributed and quoted as published; where sources disagree their scenarios are kept separate with their assumptions rather than reconciled into one answer. Everything is meant to be checked against the linked evidence rather than taken on trust. Act on your own judgement about a particular situation. Editorial standards and corrections.

Do not disclose recovery material to a website, form, message or support account. This site never asks for it, and contributions containing recovery words or private keys are not accepted.

r/Bitcoin: claim that destroying hardware stock points to a possible second exploit

reddit-coldcards-next-exploit

https://www.reddit.com/r/Bitcoin/comments/1vn78qh/coldcards_next_exploit/

Latest reviewed change

source content difference between and

A reply by Oxymorix was added arguing that destroying affected inventory is more practical than reflashing because returning devices to factory-first-boot state may not be feasible.

seen +12 -0 full history below
 edited: false
 body:
 Not really.
+
+comment: p3tjfec
+parent: t1_p3rdv4h
+author: Oxymorix
+created_utc: 1786791727

First lines only. The complete diff is in the timeline below.

Organisation
reddit
Evidence role
Community discussion
Published
not established
Source changes
2
Detected differences
2
Unreviewed
0
Copies held
3

Every check is recorded, including checks that found no text change. A detected edit is therefore bounded between two checks. The publisher's exact save time is not observable from this record. Last checked .

  1. source content difference between and Current source content +12 -0

    A reply by Oxymorix was added arguing that destroying affected inventory is more practical than reflashing because returning devices to factory-first-boot state may not be feasible.

    seen · Captured here 15,306 chars
    What changed from the previous capture 12 lines
     edited: false
     body:
     Not really.
    +
    +comment: p3tjfec
    +parent: t1_p3rdv4h
    +author: Oxymorix
    +created_utc: 1786791727
    +edited: false
    +body:
    +Yes. It’s easier, faster, and cheaper to destroy a large number of devices with vulnerable firmware—in the case of COLDCARDs—than to open the old packaging, reflash each device, test it, and then repackage it.
    +
    +The issue is not just the firmware update itself. Each device would also have to go through the necessary testing and hardware checks. Beyond that, there is another complication: returning the device to the same factory-fresh state it was in when first powered on, where it displays the bag number and other initial setup information.
    +
    +Once Coinkite powers those devices on again for reflashing and testing, they may not be able to return them to that exact first-boot state, or at least not easily. For that reason, destroying the affected inventory may simply make more practical and economic sense.
    
    Extracted text as captured
    post: 1vn78qh
    author: Ok-Photograph-3585
    created_utc: 1786617945
    title: Coldcard's Next Exploit
    body:
    People here have been discussing the software bug that triggered the whole Coldcard debacle. that led many people to lose their Bitcoins savings. But what many didn't notice is that Coinkite decided to destroy their stock, instead of upgrading them. Had the bug been software-only, there would be no point in destroying the hardware. After speaking with many colleagues of mine, we have come to the conclusion that a hardware bug might be present, and this could trigger a second exploit. This is a textbook example of a "**Degenerate** **bug**". I believe a full audit of the software (latest version) and the hardware itself is warranted. A complete hardware check is difficult to carry out though because of the way it was designed. Please provide your thoughts and advice on how to proceed, as this could save many people from being victims of a second wave of bitcoin loses. At this point an inside job can also not be ruled out regrettably.
    
    comment: p3f3elp
    parent: t3_1vn78qh
    author: Laukess
    created_utc: 1786618109
    edited: false
    body:
    They destroyed their stock because it’s not feasible to update the firmware before shipping. It must be because they’re hiding something something even more nefarious
    
    comment: p3f3l0x
    parent: t1_p3f3elp
    author: Ok-Photograph-3585
    created_utc: 1786618183
    edited: false
    body:
    Regrettably, a degenerate attack can not be ruled out. These people are not being transparent and many things don't add up.
    
    comment: p3f4d1q
    parent: t3_1vn78qh
    author: Main-Massive
    created_utc: 1786618501
    edited: false
    body:
    They are degenerates indeed. u/nvk has retreated into his cave, gone hiding,and is probably cashing out the btc in Tel-Aviv, if you know what I mean. 
    
    comment: p3f4fzo
    parent: t1_p3f3elp
    author: SolutionOk1306
    created_utc: 1786618534
    edited: false
    body:
    Destroying stock over a firmware update sounds extreme but honestly in hardware manufacturing it's sometimes cheaper to scrap and start fresh than to pay people to unbox, flash, repackage, and re-certify every single unit. The logistics are a nightmare. If there's a deeper hardware flaw though that's a whole different level of bad and the lack of a full teardown audit just feeds the paranoia.
    
    comment: p3f4lbo

    Excerpt only. The complete copy is held offline and backs quotations on this site. The original publication remains the canonical public source.

  2. source content difference between and source content +40 -0

    The thread gained an exchange of short replies between grraarr and ItsAlwaysThemBooBoo disputing the original hardware-bug speculation.

    seen · Captured here 14,395 chars
    What changed from the previous capture 40 lines
     edited: false
     body:
     Is it tho?  Wouldn't you just pay 1 guy overtime to flash the cold cards and then feed that stock into the packaging phase of production?
    +
    +comment: p3rnh8p
    +parent: t1_p3fh1c7
    +author: grraarr
    +created_utc: 1786760057
    +edited: false
    +body:
    +Please go the fuck away.
    +
    +comment: p3rnj5p
    +parent: t1_p3f9s8l
    +author: grraarr
    +created_utc: 1786760077
    +edited: false
    +body:
    +You lot are pathetic.
    +
    +comment: p3rs2r1
    +parent: t1_p3rnh8p
    +author: ItsAlwaysThemBooBoo
    +created_utc: 1786761799
    +edited: false
    +body:
    +nah. 
    +
    +comment: p3rs6k8
    +parent: t1_p3rnj5p
    +author: ItsAlwaysThemBooBoo
    +created_utc: 1786761840
    +edited: false
    +body:
    +nah, we’re just adept at pattern recognition.
    +
    +comment: p3rv8hr
    +parent: t1_p3rs6k8
    +author: grraarr
    +created_utc: 1786763031
    +edited: false
    +body:
    +Not really.
    
    Extracted text as captured
    post: 1vn78qh
    author: Ok-Photograph-3585
    created_utc: 1786617945
    title: Coldcard's Next Exploit
    body:
    People here have been discussing the software bug that triggered the whole Coldcard debacle. that led many people to lose their Bitcoins savings. But what many didn't notice is that Coinkite decided to destroy their stock, instead of upgrading them. Had the bug been software-only, there would be no point in destroying the hardware. After speaking with many colleagues of mine, we have come to the conclusion that a hardware bug might be present, and this could trigger a second exploit. This is a textbook example of a "**Degenerate** **bug**". I believe a full audit of the software (latest version) and the hardware itself is warranted. A complete hardware check is difficult to carry out though because of the way it was designed. Please provide your thoughts and advice on how to proceed, as this could save many people from being victims of a second wave of bitcoin loses. At this point an inside job can also not be ruled out regrettably.
    
    comment: p3f3elp
    parent: t3_1vn78qh
    author: Laukess
    created_utc: 1786618109
    edited: false
    body:
    They destroyed their stock because it’s not feasible to update the firmware before shipping. It must be because they’re hiding something something even more nefarious
    
    comment: p3f3l0x
    parent: t1_p3f3elp
    author: Ok-Photograph-3585
    created_utc: 1786618183
    edited: false
    body:
    Regrettably, a degenerate attack can not be ruled out. These people are not being transparent and many things don't add up.
    
    comment: p3f4d1q
    parent: t3_1vn78qh
    author: Main-Massive
    created_utc: 1786618501
    edited: false
    body:
    They are degenerates indeed. u/nvk has retreated into his cave, gone hiding,and is probably cashing out the btc in Tel-Aviv, if you know what I mean. 
    
    comment: p3f4fzo
    parent: t1_p3f3elp
    author: SolutionOk1306
    created_utc: 1786618534
    edited: false
    body:
    Destroying stock over a firmware update sounds extreme but honestly in hardware manufacturing it's sometimes cheaper to scrap and start fresh than to pay people to unbox, flash, repackage, and re-certify every single unit. The logistics are a nightmare. If there's a deeper hardware flaw though that's a whole different level of bad and the lack of a full teardown audit just feeds the paranoia.
    
    comment: p3f4lbo

    Excerpt only. The complete copy is held offline and backs quotations on this site. The original publication remains the canonical public source.

  3. Earliest copy held
    seen · Captured here 13,775 chars
    Extracted text as captured
    post: 1vn78qh
    author: Ok-Photograph-3585
    created_utc: 1786617945
    title: Coldcard's Next Exploit
    body:
    People here have been discussing the software bug that triggered the whole Coldcard debacle. that led many people to lose their Bitcoins savings. But what many didn't notice is that Coinkite decided to destroy their stock, instead of upgrading them. Had the bug been software-only, there would be no point in destroying the hardware. After speaking with many colleagues of mine, we have come to the conclusion that a hardware bug might be present, and this could trigger a second exploit. This is a textbook example of a "**Degenerate** **bug**". I believe a full audit of the software (latest version) and the hardware itself is warranted. A complete hardware check is difficult to carry out though because of the way it was designed. Please provide your thoughts and advice on how to proceed, as this could save many people from being victims of a second wave of bitcoin loses. At this point an inside job can also not be ruled out regrettably.
    
    comment: p3f3elp
    parent: t3_1vn78qh
    author: Laukess
    created_utc: 1786618109
    edited: false
    body:
    They destroyed their stock because it’s not feasible to update the firmware before shipping. It must be because they’re hiding something something even more nefarious
    
    comment: p3f3l0x
    parent: t1_p3f3elp
    author: Ok-Photograph-3585
    created_utc: 1786618183
    edited: false
    body:
    Regrettably, a degenerate attack can not be ruled out. These people are not being transparent and many things don't add up.
    
    comment: p3f4d1q
    parent: t3_1vn78qh
    author: Main-Massive
    created_utc: 1786618501
    edited: false
    body:
    They are degenerates indeed. u/nvk has retreated into his cave, gone hiding,and is probably cashing out the btc in Tel-Aviv, if you know what I mean. 
    
    comment: p3f4fzo
    parent: t1_p3f3elp
    author: SolutionOk1306
    created_utc: 1786618534
    edited: false
    body:
    Destroying stock over a firmware update sounds extreme but honestly in hardware manufacturing it's sometimes cheaper to scrap and start fresh than to pay people to unbox, flash, repackage, and re-certify every single unit. The logistics are a nightmare. If there's a deeper hardware flaw though that's a whole different level of bad and the lack of a full teardown audit just feeds the paranoia.
    
    comment: p3f4lbo

    Excerpt only. The complete copy is held offline and backs quotations on this site. The original publication remains the canonical public source.

How to check this yourself

The excerpts and plain unified diffs above show the text this project held and how it changed. To verify a quotation, compare it against the page itself or against the Internet Archive's copies, which are independent of this project.

Complete captures are held offline rather than mirrored here, so this page shows diffs and excerpts. If a quotation is ever disputed, the full copy can be produced. Ask.