COLDCARD RNG incident the public record, collected and explained
Informational only, and this site never asks for your seed words. details

Informational only. This is an open source collection of what others have published about the incident, together with an explanation of it. It is not financial, security or legal advice, and not a substitute for professional advice about your own situation. It is not affiliated with, endorsed by, or speaking for Coinkite. Material is attributed and quoted as published; where sources disagree their scenarios are kept separate with their assumptions rather than reconciled into one answer. Everything is meant to be checked against the linked evidence rather than taken on trust. Act on your own judgement about a particular situation. Editorial standards and corrections.

Do not disclose recovery material to a website, form, message or support account. This site never asks for it, and contributions containing recovery words or private keys are not accepted.

r/Bitcoin: opinion urging owners to leave Coinkite products

reddit-coldtruth-opinion

https://www.reddit.com/r/Bitcoin/comments/1veo7gt/the_coldtruth/

Latest reviewed change

source content difference between and

Reddit served 1 additional comment record(s); the diff preserves their text and any edits to existing records.

seen +8 -0 full history below
 he'd be better off having literally no brain. that's the level of severe zoological retardation we are talking about here
 
 
+
+comment: p1twxxn
+parent: t1_p1kmw14
+author: CiaranCarroll
+created_utc: 1785927060

First lines only. The complete diff is in the timeline below.

Organisation
reddit
Evidence role
Community discussion
Published
not established
Source changes
1
Detected differences
1
Unreviewed
0
Copies held
2

Every check is recorded, including checks that found no text change. A detected edit is therefore bounded between two checks. The publisher's exact save time is not observable from this record. Last checked .

  1. source content difference between and Current source content +8 -0

    Reddit served 1 additional comment record(s); the diff preserves their text and any edits to existing records.

    seen · Captured here 2,878 chars
    What changed from the previous capture 8 lines
     he'd be better off having literally no brain. that's the level of severe zoological retardation we are talking about here
     
     
    +
    +comment: p1twxxn
    +parent: t1_p1kmw14
    +author: CiaranCarroll
    +created_utc: 1785927060
    +edited: false
    +body:
    +User error
    
    Extracted text as captured
    post: 1veo7gt
    author: Spy008
    created_utc: 1785787221
    title: The ColdTruth
    body:
    If you have any CoinKite products do yourself a favor and buy a new hardware wallet and move your coins off of it. 
    
    It doesn’t matter if you generated the keys yourself tossing the dice off of Mt.Everest in the moonlight. Here’s why you are now vulnerable:
    
    Scenario 1 - Coinkite goes out of business. Your ColdTrap product is perfectly secure at the moment, but 1 day, 1 week, 1 year later another vulnerability is found by say an ethical hacker or a new technology makes a vulnerability possible. Normally minor exploits especially ones found internally, through bug bounties or through research partners can be patched via firmware updates, but now that update channel and process is gone.
    
    Scenario 2 - Coinkite somehow survives this and continues operations. Revenue will still likely fall significantly, meaning less headcount, less security partnerships, less Q&A, etc. all this leaves you more vulnerable.
    
    Choose your next wallet wisely, DYOR isnt listening to influencers or even the people on this sub. 
    
    There were a ton of people pushing ColdCard even when it first came out - I argued with them back then that it doesn’t matter if its open source or airgapped what matters is how long its been on the market/how many qualified people are looking at the code/ how high of a target it is for hackers… hardware wallets arent like new phone models, the oldest ones with a long history of safety are typically better than just about anything new.
    
    Open source is great if you have A LOT of qualified people looking at it. With open source you ONLY have security when you’re the highest value target with the highest bug bounty—- there is a reason why researchers and competitors break down Trezor’s daily and not Jades, Bitboxs, or whatever people are pushing now in days.
    
    Also IMO some of the mods here should issue an apology for actively pushing ColdCard (they know who they are)
    
    comment: p1kmw14
    parent: t3_1veo7gt
    author: slvbtc
    created_utc: 1785810396
    edited: false
    body:
    Its wild some people think its still ok to use a coldcard because the bug was fixed.
    
    Once you find out the CTO of your HW wallet is homer simpson you stop using it completely. Fixing a bug doesnt change the fact the CTO is still homer simpson.
    
    comment: p1kpfm8
    parent: t1_p1kmw14
    author: Bred_Slippy
    created_utc: 1785811261
    edited: false
    body:
    A self-proclaimed "Wizard-level developer" no less. Smh
    
    comment: p1l55z1

    Excerpt only. The complete copy is held offline and backs quotations on this site. The original publication remains the canonical public source.

  2. Earliest copy held
    seen · Captured here 2,764 chars
    Extracted text as captured
    post: 1veo7gt
    author: Spy008
    created_utc: 1785787221
    title: The ColdTruth
    body:
    If you have any CoinKite products do yourself a favor and buy a new hardware wallet and move your coins off of it. 
    
    It doesn’t matter if you generated the keys yourself tossing the dice off of Mt.Everest in the moonlight. Here’s why you are now vulnerable:
    
    Scenario 1 - Coinkite goes out of business. Your ColdTrap product is perfectly secure at the moment, but 1 day, 1 week, 1 year later another vulnerability is found by say an ethical hacker or a new technology makes a vulnerability possible. Normally minor exploits especially ones found internally, through bug bounties or through research partners can be patched via firmware updates, but now that update channel and process is gone.
    
    Scenario 2 - Coinkite somehow survives this and continues operations. Revenue will still likely fall significantly, meaning less headcount, less security partnerships, less Q&A, etc. all this leaves you more vulnerable.
    
    Choose your next wallet wisely, DYOR isnt listening to influencers or even the people on this sub. 
    
    There were a ton of people pushing ColdCard even when it first came out - I argued with them back then that it doesn’t matter if its open source or airgapped what matters is how long its been on the market/how many qualified people are looking at the code/ how high of a target it is for hackers… hardware wallets arent like new phone models, the oldest ones with a long history of safety are typically better than just about anything new.
    
    Open source is great if you have A LOT of qualified people looking at it. With open source you ONLY have security when you’re the highest value target with the highest bug bounty—- there is a reason why researchers and competitors break down Trezor’s daily and not Jades, Bitboxs, or whatever people are pushing now in days.
    
    Also IMO some of the mods here should issue an apology for actively pushing ColdCard (they know who they are)
    
    comment: p1kmw14
    parent: t3_1veo7gt
    author: slvbtc
    created_utc: 1785810396
    edited: false
    body:
    Its wild some people think its still ok to use a coldcard because the bug was fixed.
    
    Once you find out the CTO of your HW wallet is homer simpson you stop using it completely. Fixing a bug doesnt change the fact the CTO is still homer simpson.
    
    comment: p1kpfm8
    parent: t1_p1kmw14
    author: Bred_Slippy
    created_utc: 1785811261
    edited: false
    body:
    A self-proclaimed "Wizard-level developer" no less. Smh
    
    comment: p1l55z1

    Excerpt only. The complete copy is held offline and backs quotations on this site. The original publication remains the canonical public source.

How to check this yourself

The excerpts and plain unified diffs above show the text this project held and how it changed. To verify a quotation, compare it against the page itself or against the Internet Archive's copies, which are independent of this project.

Complete captures are held offline rather than mirrored here, so this page shows diffs and excerpts. If a quotation is ever disputed, the full copy can be produced. Ask.