COLDCARD RNG incident the public record, collected and explained
Informational only, and this site never asks for your seed words. details

Informational only. This is an open source collection of what others have published about the incident, together with an explanation of it. It is not financial, security or legal advice, and not a substitute for professional advice about your own situation. It is not affiliated with, endorsed by, or speaking for Coinkite. Material is attributed and quoted as published; where sources disagree their scenarios are kept separate with their assumptions rather than reconciled into one answer. Everything is meant to be checked against the linked evidence rather than taken on trust. Act on your own judgement about a particular situation. Editorial standards and corrections.

Do not disclose recovery material to a website, form, message or support account. This site never asks for it, and contributions containing recovery words or private keys are not accepted.

r/coldcard: owner leaving COLDCARD after the incident

reddit-im-out

https://www.reddit.com/r/coldcard/comments/1vfbi4w/im_out/

Latest reviewed change

source content difference between and

The thread gained a new comment comparing leaving COLDCARD to losing a relationship.

seen +8 -0 full history below
 
 I also moved my funds to Coinbase for now, I think it's much safer. Thank God I used a passphrase and rolled dice to generate my seeds on the Coldcard, but after this event, I completely lost trust in Coinkite. Who can guarantee there aren't other bugs out there?
 
+
+comment: p2i7983
+parent: t3_1vfbi4w
+author: carothersjoshua
+created_utc: 1786213673

First lines only. The complete diff is in the timeline below.

Organisation
reddit
Evidence role
Community discussion
Published
not established
Source changes
20
Detected differences
20
Unreviewed
0
Copies held
21

Every check is recorded, including checks that found no text change. A detected edit is therefore bounded between two checks. The publisher's exact save time is not observable from this record. Last checked .

  1. source content difference between and Current source content +8 -0

    The thread gained a new comment comparing leaving COLDCARD to losing a relationship.

    seen · Captured here 26,202 chars
    What changed from the previous capture 8 lines
     
     I also moved my funds to Coinbase for now, I think it's much safer. Thank God I used a passphrase and rolled dice to generate my seeds on the Coldcard, but after this event, I completely lost trust in Coinkite. Who can guarantee there aren't other bugs out there?
     
    +
    +comment: p2i7983
    +parent: t3_1vfbi4w
    +author: carothersjoshua
    +created_utc: 1786213673
    +edited: false
    +body:
    +It sucks because I really like Coldcard and finally got used to using it and now it’s all over. Like that girlfriend you just can’t get out of your mind. 
    
    Extracted text as captured
    post: 1vfbi4w
    author: General_Asparagus976
    created_utc: 1785852725
    title: I'm out
    body:
    Moved off of coldcard even with mk4 with dice and a passphrase.  This humbled a lot of people who thought they were doing the safest, most transparent form of self custody. This is not what any of us signed up for, and who knows what they have to do to recover trust and continue as a company but I'm not gonna leave my funds there while they sort it out. Sorry to everyone for going through this really sickening for those that lost btc and disturbing to anyone practicing self custody. 
    
    comment: p1nlzuy
    parent: t3_1vfbi4w
    author: Ok-Information-2428
    created_utc: 1785853196
    edited: false
    body:
    COLDCARD is done. They’re a bunch of incompetent reckless assholes. Sadly it’s too late
    
    comment: p1nnuzo
    parent: t3_1vfbi4w
    author: alixanc
    created_utc: 1785853690
    edited: false
    body:
    "doing the safest, most transparent form of self custody" Trusting a single black box RNG for seed creation is far from the safest and most transparent form of self custody. They trusted and they got rekt. So simple to just combine 2 or 3 software RNGs or mix in some physical entropy via card/dice/coins etc. Even the ColdCard maker himself suggested not trusting any single software RNG.
    
    comment: p1np0sk
    parent: t3_1vfbi4w
    author: Netopr22
    created_utc: 1785853999
    edited: false
    body:
    i dont trust them anymore, i will give my coldcard q for my kids to play.... Or in the event a thief breaks into my house i will give it to him with the seed phrase... Only 0.63 cents remain on it..
    
    comment: p1nqdxy
    parent: t3_1vfbi4w
    author: opossum_cz
    created_utc: 1785854362
    edited: false
    body:
    \> people who thought they were doing the safest, most transparent form of self custody
    
    Honestly, this sounds more like being delusional. I can't even blame Coldcard for this.

    Excerpt only. The complete copy is held offline and backs quotations on this site. The original publication remains the canonical public source.

  2. source content difference between and source content +2 -11

    Two comments by anotherfroggyevening were replaced with [deleted] and [removed], including one linking to a thread arguing the incident was deliberate rather than incompetent.

    seen · Captured here 25,942 chars
    What changed from the previous capture 13 lines
     
     comment: p1pfyij
     parent: t1_p1nlzuy
    -author: anotherfroggyevening
    +author: [deleted]
     created_utc: 1785869873
     edited: false
     body:
    -Even scarier to think it wasnt incompetente at all. Deliberate, planned way in advance:
    -https://www.reddit.com/r/CryptoCurrency/s/s5fNgg9k4X
    +[removed]
     
     comment: p1prhh8
     parent: t1_p1oy5k1
     body:
     Imagine continuing to trust a CC with your hard earned bitcoin after this, you would deserve to be rugged
     
    -comment: p1svl5z
    -parent: t1_p1rku7g
    -author: anotherfroggyevening
    -created_utc: 1785909477
    -edited: false
    -body:
    -A "bug" imo works much better according to that logic. "It can't be deliberate, because it's a bug." Sure. Seeing the general tone of comments, seems like it was a perfect game plan.
    -
     comment: p1t1im3
     parent: t1_p1rd237
     author: Sammy262
    
    Extracted text as captured
    post: 1vfbi4w
    author: General_Asparagus976
    created_utc: 1785852725
    title: I'm out
    body:
    Moved off of coldcard even with mk4 with dice and a passphrase.  This humbled a lot of people who thought they were doing the safest, most transparent form of self custody. This is not what any of us signed up for, and who knows what they have to do to recover trust and continue as a company but I'm not gonna leave my funds there while they sort it out. Sorry to everyone for going through this really sickening for those that lost btc and disturbing to anyone practicing self custody. 
    
    comment: p1nlzuy
    parent: t3_1vfbi4w
    author: Ok-Information-2428
    created_utc: 1785853196
    edited: false
    body:
    COLDCARD is done. They’re a bunch of incompetent reckless assholes. Sadly it’s too late
    
    comment: p1nnuzo
    parent: t3_1vfbi4w
    author: alixanc
    created_utc: 1785853690
    edited: false
    body:
    "doing the safest, most transparent form of self custody" Trusting a single black box RNG for seed creation is far from the safest and most transparent form of self custody. They trusted and they got rekt. So simple to just combine 2 or 3 software RNGs or mix in some physical entropy via card/dice/coins etc. Even the ColdCard maker himself suggested not trusting any single software RNG.
    
    comment: p1np0sk
    parent: t3_1vfbi4w
    author: Netopr22
    created_utc: 1785853999
    edited: false
    body:
    i dont trust them anymore, i will give my coldcard q for my kids to play.... Or in the event a thief breaks into my house i will give it to him with the seed phrase... Only 0.63 cents remain on it..
    
    comment: p1nqdxy
    parent: t3_1vfbi4w
    author: opossum_cz
    created_utc: 1785854362
    edited: false
    body:
    \> people who thought they were doing the safest, most transparent form of self custody
    
    Honestly, this sounds more like being delusional. I can't even blame Coldcard for this.

    Excerpt only. The complete copy is held offline and backs quotations on this site. The original publication remains the canonical public source.

  3. source content difference between and source content +10 -0

    The thread gained a comment saying the poster moved funds to Coinbase and lost trust in Coinkite despite having used a passphrase and dice-generated seeds.

    seen · Captured here 26,377 chars
    What changed from the previous capture 10 lines
     Why would you trust a team of clowns though? They're either complete morons or they're in on it.
     
     Maybe they'll accidentally push an update that uploads your private key next, who knows? How anyone can trust these people after this is beyond me.
    +
    +comment: p2arswq
    +parent: t3_1vfbi4w
    +author: eternal_recurrence12
    +created_utc: 1786121841
    +edited: false
    +body:
    +
    +I also moved my funds to Coinbase for now, I think it's much safer. Thank God I used a passphrase and rolled dice to generate my seeds on the Coldcard, but after this event, I completely lost trust in Coinkite. Who can guarantee there aren't other bugs out there?
    +
    
    Extracted text as captured
    post: 1vfbi4w
    author: General_Asparagus976
    created_utc: 1785852725
    title: I'm out
    body:
    Moved off of coldcard even with mk4 with dice and a passphrase.  This humbled a lot of people who thought they were doing the safest, most transparent form of self custody. This is not what any of us signed up for, and who knows what they have to do to recover trust and continue as a company but I'm not gonna leave my funds there while they sort it out. Sorry to everyone for going through this really sickening for those that lost btc and disturbing to anyone practicing self custody. 
    
    comment: p1nlzuy
    parent: t3_1vfbi4w
    author: Ok-Information-2428
    created_utc: 1785853196
    edited: false
    body:
    COLDCARD is done. They’re a bunch of incompetent reckless assholes. Sadly it’s too late
    
    comment: p1nnuzo
    parent: t3_1vfbi4w
    author: alixanc
    created_utc: 1785853690
    edited: false
    body:
    "doing the safest, most transparent form of self custody" Trusting a single black box RNG for seed creation is far from the safest and most transparent form of self custody. They trusted and they got rekt. So simple to just combine 2 or 3 software RNGs or mix in some physical entropy via card/dice/coins etc. Even the ColdCard maker himself suggested not trusting any single software RNG.
    
    comment: p1np0sk
    parent: t3_1vfbi4w
    author: Netopr22
    created_utc: 1785853999
    edited: false
    body:
    i dont trust them anymore, i will give my coldcard q for my kids to play.... Or in the event a thief breaks into my house i will give it to him with the seed phrase... Only 0.63 cents remain on it..
    
    comment: p1nqdxy
    parent: t3_1vfbi4w
    author: opossum_cz
    created_utc: 1785854362
    edited: false
    body:
    \> people who thought they were doing the safest, most transparent form of self custody
    
    Honestly, this sounds more like being delusional. I can't even blame Coldcard for this.

    Excerpt only. The complete copy is held offline and backs quotations on this site. The original publication remains the canonical public source.

  4. source content difference between and source content +40 -0

    The thread gained comments proposing limited reuse of a COLDCARD and criticizing Coinkite’s competence, including an inside-job allegation presented as the commenter’s speculation.

    seen · Captured here 26,001 chars
    What changed from the previous capture 40 lines
     edited: false
     body:
     Those are valid points. I'm not expecting to rely on any future fixes or support. I am not even installing their emergency patches, so if/when they go under it won't impact my use of the cold card. But...yes, it is likely worth looking into other solutions that will be reliable and eventually take cold card out of the picture entirely. 
    +
    +comment: p1yao12
    +parent: t3_1vfbi4w
    +author: FerdaStonks
    +created_utc: 1785970553
    +edited: false
    +body:
    +Don’t throw away your coldcard, it still works well as an airgapped way to calculate your 24th word if you make a wallet by flipping a coin 256 times.
    +
    +Use it to get that word and then use another wallet to actually transact with. I trust it to calculate 1 word and then turn off but wouldn’t trust it to actually enter dice rolls and get a legit seed or to transact with.
    +
    +comment: p1yeg9r
    +parent: t1_p1v78j6
    +author: Ok-Information-2428
    +created_utc: 1785971750
    +edited: false
    +body:
    +If the attacker was a highly sophisticated operation it would be more understandable- in this case though it was their own total incompetence and complete lack of concern with the most critical code path in their wallet
    +
    +comment: p1yu0bw
    +parent: t1_p1v78j6
    +author: rockorangebear
    +created_utc: 1785976860
    +edited: false
    +body:
    +Honestly, any competent senior developer from a top tech company could've done it. A wallet's functionality isn't that large in scope, in fact it's surprisingly simple.
    +
    +In terms of security, making sure that a newly generated seed is done so randomly is one of the only critical tasks needed.
    +
    +It's not difficult to have automated tests in place.
    +
    +comment: p1yv366
    +parent: t1_p1pzxcz
    +author: rockorangebear
    +created_utc: 1785977215
    +edited: false
    +body:
    +Why would you trust a team of clowns though? They're either complete morons or they're in on it.
    +
    +Maybe they'll accidentally push an update that uploads your private key next, who knows? How anyone can trust these people after this is beyond me.
    
    Extracted text as captured
    post: 1vfbi4w
    author: General_Asparagus976
    created_utc: 1785852725
    title: I'm out
    body:
    Moved off of coldcard even with mk4 with dice and a passphrase.  This humbled a lot of people who thought they were doing the safest, most transparent form of self custody. This is not what any of us signed up for, and who knows what they have to do to recover trust and continue as a company but I'm not gonna leave my funds there while they sort it out. Sorry to everyone for going through this really sickening for those that lost btc and disturbing to anyone practicing self custody. 
    
    comment: p1nlzuy
    parent: t3_1vfbi4w
    author: Ok-Information-2428
    created_utc: 1785853196
    edited: false
    body:
    COLDCARD is done. They’re a bunch of incompetent reckless assholes. Sadly it’s too late
    
    comment: p1nnuzo
    parent: t3_1vfbi4w
    author: alixanc
    created_utc: 1785853690
    edited: false
    body:
    "doing the safest, most transparent form of self custody" Trusting a single black box RNG for seed creation is far from the safest and most transparent form of self custody. They trusted and they got rekt. So simple to just combine 2 or 3 software RNGs or mix in some physical entropy via card/dice/coins etc. Even the ColdCard maker himself suggested not trusting any single software RNG.
    
    comment: p1np0sk
    parent: t3_1vfbi4w
    author: Netopr22
    created_utc: 1785853999
    edited: false
    body:
    i dont trust them anymore, i will give my coldcard q for my kids to play.... Or in the event a thief breaks into my house i will give it to him with the seed phrase... Only 0.63 cents remain on it..
    
    comment: p1nqdxy
    parent: t3_1vfbi4w
    author: opossum_cz
    created_utc: 1785854362
    edited: false
    body:
    \> people who thought they were doing the safest, most transparent form of self custody
    
    Honestly, this sounds more like being delusional. I can't even blame Coldcard for this.

    Excerpt only. The complete copy is held offline and backs quotations on this site. The original publication remains the canonical public source.

  5. source content difference between and source content +36 -0

    The thread gained comments questioning Coinkite's staffing and future support, and discussing alternative hardware wallets and continued use after dice-derived seed generation.

    seen · Captured here 24,396 chars
    What changed from the previous capture 36 lines
     edited: false
     body:
     Of course, any rational human being should toss any coldcard to the trash bin, I’ve disposed my two mk4s and have incoming parts to build a few seed signers and a jade ordered to make a multisig setup. This has been too close of a call, if I had been drained I don’t know what would have happened to me, I’m scared just to think of it.
    +
    +comment: p1v78j6
    +parent: t1_p1nlzuy
    +author: deny_by_default
    +created_utc: 1785941421
    +edited: false
    +body:
    +Isn't the "company" only like 5 people?  How can keep up with security exploits and audit your code properly with a staff that size?  Frankly, I'm amazed it took this long for this disaster to happen.  It's a shame too.  I really like the Coldcard Q, but I've lost faith in Coinkite.
    +
    +comment: p1vb9cu
    +parent: t1_p1owrme
    +author: cworxnine
    +created_utc: 1785942455
    +edited: false
    +body:
    +I was considering the same, it's just a signing device and I used dice rolls so maybe I can continue using it right? But now their future is unclear, their team and company is very small and unlikely to absorb the loss of future income for years to come. 
    +
    +It's unlikely they'll double down and reinvest in a dozen more developers, or revamp their broken QA. I doubt there's more than 30 full time employees there. This company doesn't have many business skills except grass roots marketing - which is gone now. How will this affect future firmware and support? 
    +
    +It's just too risky to keep using their products when other viable solutions are out there who are WAY more funded and can invest more money in support and continued development.
    +
    +comment: p1veieb
    +parent: t1_p1qah2m
    +author: cworxnine
    +created_utc: 1785943285
    +edited: false
    +body:
    +Trezor Safe 7 is actually pretty big. Ledger Flex is also a great device. I agree the CCQ is a sexy device, but I only use mine a few times a year anyways. Just needs to be easy to use and stable.
    +
    +comment: p1w3iok
    +parent: t1_p1vb9cu
    +author: Stack_Sats_Often
    +created_utc: 1785949479
    +edited: false
    +body:
    +Those are valid points. I'm not expecting to rely on any future fixes or support. I am not even installing their emergency patches, so if/when they go under it won't impact my use of the cold card. But...yes, it is likely worth looking into other solutions that will be reliable and eventually take cold card out of the picture entirely. 
    
    Extracted text as captured
    post: 1vfbi4w
    author: General_Asparagus976
    created_utc: 1785852725
    title: I'm out
    body:
    Moved off of coldcard even with mk4 with dice and a passphrase.  This humbled a lot of people who thought they were doing the safest, most transparent form of self custody. This is not what any of us signed up for, and who knows what they have to do to recover trust and continue as a company but I'm not gonna leave my funds there while they sort it out. Sorry to everyone for going through this really sickening for those that lost btc and disturbing to anyone practicing self custody. 
    
    comment: p1nlzuy
    parent: t3_1vfbi4w
    author: Ok-Information-2428
    created_utc: 1785853196
    edited: false
    body:
    COLDCARD is done. They’re a bunch of incompetent reckless assholes. Sadly it’s too late
    
    comment: p1nnuzo
    parent: t3_1vfbi4w
    author: alixanc
    created_utc: 1785853690
    edited: false
    body:
    "doing the safest, most transparent form of self custody" Trusting a single black box RNG for seed creation is far from the safest and most transparent form of self custody. They trusted and they got rekt. So simple to just combine 2 or 3 software RNGs or mix in some physical entropy via card/dice/coins etc. Even the ColdCard maker himself suggested not trusting any single software RNG.
    
    comment: p1np0sk
    parent: t3_1vfbi4w
    author: Netopr22
    created_utc: 1785853999
    edited: false
    body:
    i dont trust them anymore, i will give my coldcard q for my kids to play.... Or in the event a thief breaks into my house i will give it to him with the seed phrase... Only 0.63 cents remain on it..
    
    comment: p1nqdxy
    parent: t3_1vfbi4w
    author: opossum_cz
    created_utc: 1785854362
    edited: false
    body:
    \> people who thought they were doing the safest, most transparent form of self custody
    
    Honestly, this sounds more like being delusional. I can't even blame Coldcard for this.

    Excerpt only. The complete copy is held offline and backs quotations on this site. The original publication remains the canonical public source.

  6. source content difference between and source content +49 -0

    The thread gained owner accounts of leaving COLDCARD despite dice-derived seeds and passphrases, alongside replies asserting the patch is safe and questioning that assessment.

    seen · Captured here 22,424 chars
    What changed from the previous capture 49 lines
     edited: false
     body:
     I think Trezor had that happen to them as well or did I misunderstand that? 
    +
    +comment: p1tiiyg
    +parent: t3_1vfbi4w
    +author: Logical_Breadfruit36
    +created_utc: 1785920487
    +edited: false
    +body:
    +Jup, I have the Q and just bought the MK5 last week.. I did dice rolls and a strong passphrase. Im also moving out. Will never use these wallets again. For me the company is done. They wont convince me again. Just bought a new cold wallet. Will make my own seed phrase fully offline now.
    +
    +comment: p1tjva5
    +parent: t3_1vfbi4w
    +author: AmericanCryptoAbroad
    +created_utc: 1785921146
    +edited: false
    +body:
    +MK4 with > 50 dice rolls is safe to use. If you moved your funds to an exchange or a lower security wallet like a hot wallet, you should move them back.
    +
    +comment: p1tkxl8
    +parent: t1_p1ns7dv
    +author: Charming-Designer944
    +created_utc: 1785921667
    +edited: false
    +body:
    +The root cause of the coldcard firmware flaw have been analyzed in detail. There is no doubt that the patch fixes the issue and that seed phrases generated by  devices with a corrected firmware are safe.
    +
    +Some vendors have a design where the device RNG capability is not blindly trusted and minimize the risk that issues like this causes catastrophic failure.
    +
    +The same kind of hacks are possible with closed source firmware as well.  But takes a little more effort to find the flaw.
    +
    +
    +
    +comment: p1to9ju
    +parent: t1_p1tkxl8
    +author: magic-battry-unknown
    +created_utc: 1785923260
    +edited: false
    +body:
    +There's an interesting post here. Potentially pretty damning. And does call in question the correctness of the patch (amongst other things)
    +https://www.reddit.com/r/Bitcoin/s/VMGQZ0Z7bZ
    +
    +What I had meant to say earlier (it could happen to any company) is that, there could be similar flaws in other products too. So be careful with any alternative you choose. For example, it may be that I used the dice rolls (around 100) is the reason i still have my BTC. But i moved it anyway, just in case. Frankly, with everything that is being discovered, I'm not sure I'll ever use my new coldcard wallet i newly generated (with dice rolls too) with the updated firmware.
    +
    +comment: p1v1k69
    +parent: t3_1vfbi4w
    +author: Uhrenwerker
    +created_utc: 1785939926
    +edited: false
    +body:
    +Of course, any rational human being should toss any coldcard to the trash bin, I’ve disposed my two mk4s and have incoming parts to build a few seed signers and a jade ordered to make a multisig setup. This has been too close of a call, if I had been drained I don’t know what would have happened to me, I’m scared just to think of it.
    
    Extracted text as captured
    post: 1vfbi4w
    author: General_Asparagus976
    created_utc: 1785852725
    title: I'm out
    body:
    Moved off of coldcard even with mk4 with dice and a passphrase.  This humbled a lot of people who thought they were doing the safest, most transparent form of self custody. This is not what any of us signed up for, and who knows what they have to do to recover trust and continue as a company but I'm not gonna leave my funds there while they sort it out. Sorry to everyone for going through this really sickening for those that lost btc and disturbing to anyone practicing self custody. 
    
    comment: p1nlzuy
    parent: t3_1vfbi4w
    author: Ok-Information-2428
    created_utc: 1785853196
    edited: false
    body:
    COLDCARD is done. They’re a bunch of incompetent reckless assholes. Sadly it’s too late
    
    comment: p1nnuzo
    parent: t3_1vfbi4w
    author: alixanc
    created_utc: 1785853690
    edited: false
    body:
    "doing the safest, most transparent form of self custody" Trusting a single black box RNG for seed creation is far from the safest and most transparent form of self custody. They trusted and they got rekt. So simple to just combine 2 or 3 software RNGs or mix in some physical entropy via card/dice/coins etc. Even the ColdCard maker himself suggested not trusting any single software RNG.
    
    comment: p1np0sk
    parent: t3_1vfbi4w
    author: Netopr22
    created_utc: 1785853999
    edited: false
    body:
    i dont trust them anymore, i will give my coldcard q for my kids to play.... Or in the event a thief breaks into my house i will give it to him with the seed phrase... Only 0.63 cents remain on it..
    
    comment: p1nqdxy
    parent: t3_1vfbi4w
    author: opossum_cz
    created_utc: 1785854362
    edited: false
    body:
    \> people who thought they were doing the safest, most transparent form of self custody
    
    Honestly, this sounds more like being delusional. I can't even blame Coldcard for this.

    Excerpt only. The complete copy is held offline and backs quotations on this site. The original publication remains the canonical public source.

  7. source content difference between and source content +97 -0

    The thread gained criticism of COLDCARD and discussion of alternative wallets, dice-generated entropy, passphrases and speculation about the incident.

    seen · Captured here 19,957 chars
    What changed from the previous capture 97 lines
     edited: false
     body:
     I moved my stack off my Coldcard last night and then slept like a baby for the first time since this started. 
    +
    +comment: p1ruvvl
    +parent: t1_p1rbsb1
    +author: moviemaker2
    +created_utc: 1785895263
    +edited: false
    +body:
    +>I’m just saying that such attacks were used before many times with other wallet providers.
    +
    +No, you said:
    +
    +>Many YouTube videos from years ago go over this exact situation. 
    +
    +The claim that you and other know-nothings are making is that this exact exploit was known.  That is ridiculous.
    +
    +>I don’t think anyone should consider the 100 dice rolls “above and beyond”, regardless of the wallet maker.
    +
    +You don't think that **now,** with hindsight, just like every other Monday morning quarterback.  You're mistaking your ability to see the now obvious as some sort of insight.
    +
    +But the TRNG of the coldcard **WAS** considered sufficient for 256 bit entropy, as was the TRNGs of other leading wallet makers.  That was the entire point of these devices.
    +
    +comment: p1rx86a
    +parent: t1_p1pfyij
    +author: moviemaker2
    +created_utc: 1785896043
    +edited: false
    +body:
    +That is idiotic.
    +
    +comment: p1ry5b1
    +parent: t1_p1pzxcz
    +author: moviemaker2
    +created_utc: 1785896349
    +edited: false
    +body:
    +>Is not the device, but the software.
    +
    +What a braindead take.
    +
    +comment: p1sa64o
    +parent: t3_1vfbi4w
    +author: straight-up-digital
    +created_utc: 1785900538
    +edited: false
    +body:
    +I’ve got a seedsigner. The project nvk always mocked. How the tables have turned. For me, I’d say either seedsigner of blockstream Jade or Trezor.
    +
    +comment: p1seo7d
    +parent: t3_1vfbi4w
    +author: Lost-Bowl3269
    +created_utc: 1785902243
    +edited: false
    +body:
    +Você está certo.
    +Mesmo que o codigo seja arrumado, as pessoas devem boicotar e processar a empresa.
    +Eles prometeram o cofre mais seguro do mundo e entregaram uma piada.
    +Merecem e devem falir e seus donos processados por fraude e propaganda enganosa. 
    +
    +comment: p1sh27q
    +parent: t3_1vfbi4w
    +author: bigocreddit
    +created_utc: 1785903181
    +edited: false
    +body:
    +You’re safe if you truly did 100 dice rolls plus a 256bit passphrase but I understand it. 
    +
    +comment: p1sqvb7
    +parent: t1_p1ns7dv
    +author: coinfreekz
    +created_utc: 1785907326
    +edited: false
    +body:
    +Remember this is not a free product, cold card costs money and it's expensive. They had one job and failed.
    +
    +comment: p1ss6ns
    +parent: t1_p1pzxcz
    +author: Only_Assistant9176
    +created_utc: 1785907918
    +edited: false
    +body:
    +Imagine continuing to trust a CC with your hard earned bitcoin after this, you would deserve to be rugged
    +
    +comment: p1svl5z
    +parent: t1_p1rku7g
    +author: anotherfroggyevening
    +created_utc: 1785909477
    +edited: false
    +body:
    +A "bug" imo works much better according to that logic. "It can't be deliberate, because it's a bug." Sure. Seeing the general tone of comments, seems like it was a perfect game plan.
    +
    +comment: p1t1im3
    +parent: t1_p1rd237
    +author: Sammy262
    +created_utc: 1785912244
    +edited: false
    +body:
    +I think Trezor had that happen to them as well or did I misunderstand that? 
    
    Extracted text as captured
    post: 1vfbi4w
    author: General_Asparagus976
    created_utc: 1785852725
    title: I'm out
    body:
    Moved off of coldcard even with mk4 with dice and a passphrase.  This humbled a lot of people who thought they were doing the safest, most transparent form of self custody. This is not what any of us signed up for, and who knows what they have to do to recover trust and continue as a company but I'm not gonna leave my funds there while they sort it out. Sorry to everyone for going through this really sickening for those that lost btc and disturbing to anyone practicing self custody. 
    
    comment: p1nlzuy
    parent: t3_1vfbi4w
    author: Ok-Information-2428
    created_utc: 1785853196
    edited: false
    body:
    COLDCARD is done. They’re a bunch of incompetent reckless assholes. Sadly it’s too late
    
    comment: p1nnuzo
    parent: t3_1vfbi4w
    author: alixanc
    created_utc: 1785853690
    edited: false
    body:
    "doing the safest, most transparent form of self custody" Trusting a single black box RNG for seed creation is far from the safest and most transparent form of self custody. They trusted and they got rekt. So simple to just combine 2 or 3 software RNGs or mix in some physical entropy via card/dice/coins etc. Even the ColdCard maker himself suggested not trusting any single software RNG.
    
    comment: p1np0sk
    parent: t3_1vfbi4w
    author: Netopr22
    created_utc: 1785853999
    edited: false
    body:
    i dont trust them anymore, i will give my coldcard q for my kids to play.... Or in the event a thief breaks into my house i will give it to him with the seed phrase... Only 0.63 cents remain on it..
    
    comment: p1nqdxy
    parent: t3_1vfbi4w
    author: opossum_cz
    created_utc: 1785854362
    edited: false
    body:
    \> people who thought they were doing the safest, most transparent form of self custody
    
    Honestly, this sounds more like being delusional. I can't even blame Coldcard for this.

    Excerpt only. The complete copy is held offline and backs quotations on this site. The original publication remains the canonical public source.

  8. source content difference between and source content +8 -0

    The Reddit thread gained an owner report that they moved their bitcoin off a COLDCARD and felt safer afterward.

    seen · Captured here 17,133 chars
    What changed from the previous capture 8 lines
     I don’t believe that for a second. If it were intentional, it would be much smarter to simply drain a few high value wallets. There is no way they would drain this much and draw such attention to this bug.
     
     I understand how upsetting and infuriating this is, especially for those directly affected. But the majority of reactions I see are pure emotion and not much intellect.
    +
    +comment: p1rn9so
    +parent: t3_1vfbi4w
    +author: BTCMachineElf
    +created_utc: 1785892767
    +edited: false
    +body:
    +I moved my stack off my Coldcard last night and then slept like a baby for the first time since this started. 
    
    Extracted text as captured
    post: 1vfbi4w
    author: General_Asparagus976
    created_utc: 1785852725
    title: I'm out
    body:
    Moved off of coldcard even with mk4 with dice and a passphrase.  This humbled a lot of people who thought they were doing the safest, most transparent form of self custody. This is not what any of us signed up for, and who knows what they have to do to recover trust and continue as a company but I'm not gonna leave my funds there while they sort it out. Sorry to everyone for going through this really sickening for those that lost btc and disturbing to anyone practicing self custody. 
    
    comment: p1nlzuy
    parent: t3_1vfbi4w
    author: Ok-Information-2428
    created_utc: 1785853196
    edited: false
    body:
    COLDCARD is done. They’re a bunch of incompetent reckless assholes. Sadly it’s too late
    
    comment: p1nnuzo
    parent: t3_1vfbi4w
    author: alixanc
    created_utc: 1785853690
    edited: false
    body:
    "doing the safest, most transparent form of self custody" Trusting a single black box RNG for seed creation is far from the safest and most transparent form of self custody. They trusted and they got rekt. So simple to just combine 2 or 3 software RNGs or mix in some physical entropy via card/dice/coins etc. Even the ColdCard maker himself suggested not trusting any single software RNG.
    
    comment: p1np0sk
    parent: t3_1vfbi4w
    author: Netopr22
    created_utc: 1785853999
    edited: false
    body:
    i dont trust them anymore, i will give my coldcard q for my kids to play.... Or in the event a thief breaks into my house i will give it to him with the seed phrase... Only 0.63 cents remain on it..
    
    comment: p1nqdxy
    parent: t3_1vfbi4w
    author: opossum_cz
    created_utc: 1785854362
    edited: false
    body:
    \> people who thought they were doing the safest, most transparent form of self custody
    
    Honestly, this sounds more like being delusional. I can't even blame Coldcard for this.

    Excerpt only. The complete copy is held offline and backs quotations on this site. The original publication remains the canonical public source.

  9. source content difference between and source content +18 -0

    The Reddit thread gained two comments, including one rejecting an intentional-drain theory.

    seen · Captured here 16,919 chars
    What changed from the previous capture 18 lines
     edited: false
     body:
     The only information that was leaked was names, addresses, and emails from a third party hack.  If people are foolish enough to fall for scams, that’s their own fault. 
    +
    +comment: p1rkq8q
    +parent: t3_1vfbi4w
    +author: kotb0614
    +created_utc: 1785891936
    +edited: false
    +body:
    +Samesies. I just keep coming back here to try to save/warn other orangepilled bros and broettes
    +
    +comment: p1rku7g
    +parent: t1_p1pfyij
    +author: SomeGuyInOz
    +created_utc: 1785891972
    +edited: false
    +body:
    +I don’t believe that for a second. If it were intentional, it would be much smarter to simply drain a few high value wallets. There is no way they would drain this much and draw such attention to this bug.
    +
    +I understand how upsetting and infuriating this is, especially for those directly affected. But the majority of reactions I see are pure emotion and not much intellect.
    
    Extracted text as captured
    post: 1vfbi4w
    author: General_Asparagus976
    created_utc: 1785852725
    title: I'm out
    body:
    Moved off of coldcard even with mk4 with dice and a passphrase.  This humbled a lot of people who thought they were doing the safest, most transparent form of self custody. This is not what any of us signed up for, and who knows what they have to do to recover trust and continue as a company but I'm not gonna leave my funds there while they sort it out. Sorry to everyone for going through this really sickening for those that lost btc and disturbing to anyone practicing self custody. 
    
    comment: p1nlzuy
    parent: t3_1vfbi4w
    author: Ok-Information-2428
    created_utc: 1785853196
    edited: false
    body:
    COLDCARD is done. They’re a bunch of incompetent reckless assholes. Sadly it’s too late
    
    comment: p1nnuzo
    parent: t3_1vfbi4w
    author: alixanc
    created_utc: 1785853690
    edited: false
    body:
    "doing the safest, most transparent form of self custody" Trusting a single black box RNG for seed creation is far from the safest and most transparent form of self custody. They trusted and they got rekt. So simple to just combine 2 or 3 software RNGs or mix in some physical entropy via card/dice/coins etc. Even the ColdCard maker himself suggested not trusting any single software RNG.
    
    comment: p1np0sk
    parent: t3_1vfbi4w
    author: Netopr22
    created_utc: 1785853999
    edited: false
    body:
    i dont trust them anymore, i will give my coldcard q for my kids to play.... Or in the event a thief breaks into my house i will give it to him with the seed phrase... Only 0.63 cents remain on it..
    
    comment: p1nqdxy
    parent: t3_1vfbi4w
    author: opossum_cz
    created_utc: 1785854362
    edited: false
    body:
    \> people who thought they were doing the safest, most transparent form of self custody
    
    Honestly, this sounds more like being delusional. I can't even blame Coldcard for this.

    Excerpt only. The complete copy is held offline and backs quotations on this site. The original publication remains the canonical public source.

  10. source content difference between and source content +16 -0

    The Reddit thread gained two replies discussing a past customer-data leak and victims of phishing scams.

    seen · Captured here 16,248 chars
    What changed from the previous capture 16 lines
     I’m not saying coldcard is not at fault. Their randomness was not random. It’s definitely a big flaw.
     
     I’m just saying that such attacks were used before many times with other wallet providers. I don’t think anyone should consider the 100 dice rolls “above and beyond”, regardless of the wallet maker. 
    +
    +comment: p1rd237
    +parent: t1_p1pxriw
    +author: adequate_redditor
    +created_utc: 1785889465
    +edited: false
    +body:
    +There was a big data leak a few years ago. Not directly related to the device itself, but people lost millions to phishing attempts.
    +
    +comment: p1ren0n
    +parent: t1_p1rd237
    +author: Aqua-Barracuda
    +created_utc: 1785889972
    +edited: false
    +body:
    +The only information that was leaked was names, addresses, and emails from a third party hack.  If people are foolish enough to fall for scams, that’s their own fault. 
    
    Extracted text as captured
    post: 1vfbi4w
    author: General_Asparagus976
    created_utc: 1785852725
    title: I'm out
    body:
    Moved off of coldcard even with mk4 with dice and a passphrase.  This humbled a lot of people who thought they were doing the safest, most transparent form of self custody. This is not what any of us signed up for, and who knows what they have to do to recover trust and continue as a company but I'm not gonna leave my funds there while they sort it out. Sorry to everyone for going through this really sickening for those that lost btc and disturbing to anyone practicing self custody. 
    
    comment: p1nlzuy
    parent: t3_1vfbi4w
    author: Ok-Information-2428
    created_utc: 1785853196
    edited: false
    body:
    COLDCARD is done. They’re a bunch of incompetent reckless assholes. Sadly it’s too late
    
    comment: p1nnuzo
    parent: t3_1vfbi4w
    author: alixanc
    created_utc: 1785853690
    edited: false
    body:
    "doing the safest, most transparent form of self custody" Trusting a single black box RNG for seed creation is far from the safest and most transparent form of self custody. They trusted and they got rekt. So simple to just combine 2 or 3 software RNGs or mix in some physical entropy via card/dice/coins etc. Even the ColdCard maker himself suggested not trusting any single software RNG.
    
    comment: p1np0sk
    parent: t3_1vfbi4w
    author: Netopr22
    created_utc: 1785853999
    edited: false
    body:
    i dont trust them anymore, i will give my coldcard q for my kids to play.... Or in the event a thief breaks into my house i will give it to him with the seed phrase... Only 0.63 cents remain on it..
    
    comment: p1nqdxy
    parent: t3_1vfbi4w
    author: opossum_cz
    created_utc: 1785854362
    edited: false
    body:
    \> people who thought they were doing the safest, most transparent form of self custody
    
    Honestly, this sounds more like being delusional. I can't even blame Coldcard for this.

    Excerpt only. The complete copy is held offline and backs quotations on this site. The original publication remains the canonical public source.

  11. source content difference between and source content +20 -0

    The Reddit thread gained comments questioning the timing of the fix and discussing dice-generated entropy.

    seen · Captured here 15,735 chars
    What changed from the previous capture 20 lines
     edited: false
     body:
     The people that dont think like you seem to like getting bent over all day long
    +
    +comment: p1r7t0w
    +parent: t1_p1q0eis
    +author: moviemaker2
    +created_utc: 1785887779
    +edited: false
    +body:
    +Did all the world's cybercriminals just leave 80 million dollars on the table for 5 years out of their goodness of their hearts?
    +
    +Why did Coinkite not patch this easily fixable and company-destroying bug until after the wallets were drained, then patch it in a few hours?
    +
    +comment: p1rbsb1
    +parent: t1_p1r7t0w
    +author: adequate_redditor
    +created_utc: 1785889059
    +edited: false
    +body:
    +I’m not saying coldcard is not at fault. Their randomness was not random. It’s definitely a big flaw.
    +
    +I’m just saying that such attacks were used before many times with other wallet providers. I don’t think anyone should consider the 100 dice rolls “above and beyond”, regardless of the wallet maker. 
    
    Extracted text as captured
    post: 1vfbi4w
    author: General_Asparagus976
    created_utc: 1785852725
    title: I'm out
    body:
    Moved off of coldcard even with mk4 with dice and a passphrase.  This humbled a lot of people who thought they were doing the safest, most transparent form of self custody. This is not what any of us signed up for, and who knows what they have to do to recover trust and continue as a company but I'm not gonna leave my funds there while they sort it out. Sorry to everyone for going through this really sickening for those that lost btc and disturbing to anyone practicing self custody. 
    
    comment: p1nlzuy
    parent: t3_1vfbi4w
    author: Ok-Information-2428
    created_utc: 1785853196
    edited: false
    body:
    COLDCARD is done. They’re a bunch of incompetent reckless assholes. Sadly it’s too late
    
    comment: p1nnuzo
    parent: t3_1vfbi4w
    author: alixanc
    created_utc: 1785853690
    edited: false
    body:
    "doing the safest, most transparent form of self custody" Trusting a single black box RNG for seed creation is far from the safest and most transparent form of self custody. They trusted and they got rekt. So simple to just combine 2 or 3 software RNGs or mix in some physical entropy via card/dice/coins etc. Even the ColdCard maker himself suggested not trusting any single software RNG.
    
    comment: p1np0sk
    parent: t3_1vfbi4w
    author: Netopr22
    created_utc: 1785853999
    edited: false
    body:
    i dont trust them anymore, i will give my coldcard q for my kids to play.... Or in the event a thief breaks into my house i will give it to him with the seed phrase... Only 0.63 cents remain on it..
    
    comment: p1nqdxy
    parent: t3_1vfbi4w
    author: opossum_cz
    created_utc: 1785854362
    edited: false
    body:
    \> people who thought they were doing the safest, most transparent form of self custody
    
    Honestly, this sounds more like being delusional. I can't even blame Coldcard for this.

    Excerpt only. The complete copy is held offline and backs quotations on this site. The original publication remains the canonical public source.

  12. source content difference between and source content +8 -0

    The Reddit thread gained a new participant comment.

    seen · Captured here 14,952 chars
    What changed from the previous capture 8 lines
     Being humbled isn't what I would call it. People put trust in a company that should have done things properly but didn't. Now a bunch of people got ripped off because ColdCard messed up. If this taught something to everyone it's DO NOT TRUST anybody or any company and generate your seed with 99 dice roll and make sure you do that right and include a 8 word or more paraphrase on top of it. This was a horrible situation for many people who didn't deserve it.
     
     This was some epic BS and Cold Card is 100% to blame for this.
    +
    +comment: p1r0li2
    +parent: t3_1vfbi4w
    +author: RandyJohnsonsBird
    +created_utc: 1785885509
    +edited: false
    +body:
    +The people that dont think like you seem to like getting bent over all day long
    
    Extracted text as captured
    post: 1vfbi4w
    author: General_Asparagus976
    created_utc: 1785852725
    title: I'm out
    body:
    Moved off of coldcard even with mk4 with dice and a passphrase.  This humbled a lot of people who thought they were doing the safest, most transparent form of self custody. This is not what any of us signed up for, and who knows what they have to do to recover trust and continue as a company but I'm not gonna leave my funds there while they sort it out. Sorry to everyone for going through this really sickening for those that lost btc and disturbing to anyone practicing self custody. 
    
    comment: p1nlzuy
    parent: t3_1vfbi4w
    author: Ok-Information-2428
    created_utc: 1785853196
    edited: false
    body:
    COLDCARD is done. They’re a bunch of incompetent reckless assholes. Sadly it’s too late
    
    comment: p1nnuzo
    parent: t3_1vfbi4w
    author: alixanc
    created_utc: 1785853690
    edited: false
    body:
    "doing the safest, most transparent form of self custody" Trusting a single black box RNG for seed creation is far from the safest and most transparent form of self custody. They trusted and they got rekt. So simple to just combine 2 or 3 software RNGs or mix in some physical entropy via card/dice/coins etc. Even the ColdCard maker himself suggested not trusting any single software RNG.
    
    comment: p1np0sk
    parent: t3_1vfbi4w
    author: Netopr22
    created_utc: 1785853999
    edited: false
    body:
    i dont trust them anymore, i will give my coldcard q for my kids to play.... Or in the event a thief breaks into my house i will give it to him with the seed phrase... Only 0.63 cents remain on it..
    
    comment: p1nqdxy
    parent: t3_1vfbi4w
    author: opossum_cz
    created_utc: 1785854362
    edited: false
    body:
    \> people who thought they were doing the safest, most transparent form of self custody
    
    Honestly, this sounds more like being delusional. I can't even blame Coldcard for this.

    Excerpt only. The complete copy is held offline and backs quotations on this site. The original publication remains the canonical public source.

  13. source content difference between and source content +10 -0

    The Reddit thread gained a comment assigning responsibility for the incident to COLDCARD.

    seen · Captured here 14,765 chars
    What changed from the previous capture 10 lines
     edited: false
     body:
     To where did you move?
    +
    +comment: p1qoswd
    +parent: t3_1vfbi4w
    +author: Tebundo
    +created_utc: 1785881931
    +edited: false
    +body:
    +Being humbled isn't what I would call it. People put trust in a company that should have done things properly but didn't. Now a bunch of people got ripped off because ColdCard messed up. If this taught something to everyone it's DO NOT TRUST anybody or any company and generate your seed with 99 dice roll and make sure you do that right and include a 8 word or more paraphrase on top of it. This was a horrible situation for many people who didn't deserve it.
    +
    +This was some epic BS and Cold Card is 100% to blame for this.
    
    Extracted text as captured
    post: 1vfbi4w
    author: General_Asparagus976
    created_utc: 1785852725
    title: I'm out
    body:
    Moved off of coldcard even with mk4 with dice and a passphrase.  This humbled a lot of people who thought they were doing the safest, most transparent form of self custody. This is not what any of us signed up for, and who knows what they have to do to recover trust and continue as a company but I'm not gonna leave my funds there while they sort it out. Sorry to everyone for going through this really sickening for those that lost btc and disturbing to anyone practicing self custody. 
    
    comment: p1nlzuy
    parent: t3_1vfbi4w
    author: Ok-Information-2428
    created_utc: 1785853196
    edited: false
    body:
    COLDCARD is done. They’re a bunch of incompetent reckless assholes. Sadly it’s too late
    
    comment: p1nnuzo
    parent: t3_1vfbi4w
    author: alixanc
    created_utc: 1785853690
    edited: false
    body:
    "doing the safest, most transparent form of self custody" Trusting a single black box RNG for seed creation is far from the safest and most transparent form of self custody. They trusted and they got rekt. So simple to just combine 2 or 3 software RNGs or mix in some physical entropy via card/dice/coins etc. Even the ColdCard maker himself suggested not trusting any single software RNG.
    
    comment: p1np0sk
    parent: t3_1vfbi4w
    author: Netopr22
    created_utc: 1785853999
    edited: false
    body:
    i dont trust them anymore, i will give my coldcard q for my kids to play.... Or in the event a thief breaks into my house i will give it to him with the seed phrase... Only 0.63 cents remain on it..
    
    comment: p1nqdxy
    parent: t3_1vfbi4w
    author: opossum_cz
    created_utc: 1785854362
    edited: false
    body:
    \> people who thought they were doing the safest, most transparent form of self custody
    
    Honestly, this sounds more like being delusional. I can't even blame Coldcard for this.

    Excerpt only. The complete copy is held offline and backs quotations on this site. The original publication remains the canonical public source.

  14. source content difference between and source content +8 -8

    The Reddit thread gained 1 new comment and no longer served an earlier comment.

    seen · Captured here 14,143 chars
    What changed from the previous capture 16 lines
     body:
     …. And I am here expecting the company to pay back the $$ I spent to get 2 CCs that I got in 2023
     
    -comment: p1pvrei
    -parent: t3_1vfbi4w
    -author: Emotional-Run9144
    -created_utc: 1785874006
    -edited: false
    -body:
    -No form of custody is every 100% safe, not with crypto or real world assets.
    -
     comment: p1pwg0u
     parent: t3_1vfbi4w
     author: hakunamatata0002
     edited: false
     body:
     As someone almost buying a coldcard Q, im kinda disappointed. Because from a hardware perspective, it seems amazing. Jade uses a shit camera, q uses a qr reader. Trezor uses a tiny touchscreen. The Q uses a full physical keyboard…like fuck man. Honestly want other companies to just use this hardware for there firmwares. Or diy builtds
    +
    +comment: p1qdhay
    +parent: t3_1vfbi4w
    +author: JumpProfessional3372
    +created_utc: 1785878737
    +edited: false
    +body:
    +To where did you move?
    
    Extracted text as captured
    post: 1vfbi4w
    author: General_Asparagus976
    created_utc: 1785852725
    title: I'm out
    body:
    Moved off of coldcard even with mk4 with dice and a passphrase.  This humbled a lot of people who thought they were doing the safest, most transparent form of self custody. This is not what any of us signed up for, and who knows what they have to do to recover trust and continue as a company but I'm not gonna leave my funds there while they sort it out. Sorry to everyone for going through this really sickening for those that lost btc and disturbing to anyone practicing self custody. 
    
    comment: p1nlzuy
    parent: t3_1vfbi4w
    author: Ok-Information-2428
    created_utc: 1785853196
    edited: false
    body:
    COLDCARD is done. They’re a bunch of incompetent reckless assholes. Sadly it’s too late
    
    comment: p1nnuzo
    parent: t3_1vfbi4w
    author: alixanc
    created_utc: 1785853690
    edited: false
    body:
    "doing the safest, most transparent form of self custody" Trusting a single black box RNG for seed creation is far from the safest and most transparent form of self custody. They trusted and they got rekt. So simple to just combine 2 or 3 software RNGs or mix in some physical entropy via card/dice/coins etc. Even the ColdCard maker himself suggested not trusting any single software RNG.
    
    comment: p1np0sk
    parent: t3_1vfbi4w
    author: Netopr22
    created_utc: 1785853999
    edited: false
    body:
    i dont trust them anymore, i will give my coldcard q for my kids to play.... Or in the event a thief breaks into my house i will give it to him with the seed phrase... Only 0.63 cents remain on it..
    
    comment: p1nqdxy
    parent: t3_1vfbi4w
    author: opossum_cz
    created_utc: 1785854362
    edited: false
    body:
    \> people who thought they were doing the safest, most transparent form of self custody
    
    Honestly, this sounds more like being delusional. I can't even blame Coldcard for this.

    Excerpt only. The complete copy is held offline and backs quotations on this site. The original publication remains the canonical public source.

  15. source content difference between and source content +24 -0

    The Reddit thread gained 3 new comments.

    seen · Captured here 14,194 chars
    What changed from the previous capture 24 lines
     https://youtu.be/D9j5y3tyMo8
     
     Wallets that don’t offer the dice roll function could be at risk too if similar vulnerabilities are uncovered.
    +
    +comment: p1q6krx
    +parent: t1_p1p4tx9
    +author: RyzenNinja
    +created_utc: 1785876874
    +edited: false
    +body:
    +I didnt say it wouldn't happen but what was my alternative in a pinch leave it there and let it get stolen.
    +
    +comment: p1q6vbe
    +parent: t1_p1ogj0b
    +author: RyzenNinja
    +created_utc: 1785876953
    +edited: false
    +body:
    +Yes on the ColdCard I didnt erase it. I need to apply the firmware update and generate a new seed then test it out a bit but I'll never trust it to hold a lot.
    +
    +comment: p1qah2m
    +parent: t1_p1ocvfz
    +author: OddioClay
    +created_utc: 1785877927
    +edited: false
    +body:
    +As someone almost buying a coldcard Q, im kinda disappointed. Because from a hardware perspective, it seems amazing. Jade uses a shit camera, q uses a qr reader. Trezor uses a tiny touchscreen. The Q uses a full physical keyboard…like fuck man. Honestly want other companies to just use this hardware for there firmwares. Or diy builtds
    
    Extracted text as captured
    post: 1vfbi4w
    author: General_Asparagus976
    created_utc: 1785852725
    title: I'm out
    body:
    Moved off of coldcard even with mk4 with dice and a passphrase.  This humbled a lot of people who thought they were doing the safest, most transparent form of self custody. This is not what any of us signed up for, and who knows what they have to do to recover trust and continue as a company but I'm not gonna leave my funds there while they sort it out. Sorry to everyone for going through this really sickening for those that lost btc and disturbing to anyone practicing self custody. 
    
    comment: p1nlzuy
    parent: t3_1vfbi4w
    author: Ok-Information-2428
    created_utc: 1785853196
    edited: false
    body:
    COLDCARD is done. They’re a bunch of incompetent reckless assholes. Sadly it’s too late
    
    comment: p1nnuzo
    parent: t3_1vfbi4w
    author: alixanc
    created_utc: 1785853690
    edited: false
    body:
    "doing the safest, most transparent form of self custody" Trusting a single black box RNG for seed creation is far from the safest and most transparent form of self custody. They trusted and they got rekt. So simple to just combine 2 or 3 software RNGs or mix in some physical entropy via card/dice/coins etc. Even the ColdCard maker himself suggested not trusting any single software RNG.
    
    comment: p1np0sk
    parent: t3_1vfbi4w
    author: Netopr22
    created_utc: 1785853999
    edited: false
    body:
    i dont trust them anymore, i will give my coldcard q for my kids to play.... Or in the event a thief breaks into my house i will give it to him with the seed phrase... Only 0.63 cents remain on it..
    
    comment: p1nqdxy
    parent: t3_1vfbi4w
    author: opossum_cz
    created_utc: 1785854362
    edited: false
    body:
    \> people who thought they were doing the safest, most transparent form of self custody
    
    Honestly, this sounds more like being delusional. I can't even blame Coldcard for this.

    Excerpt only. The complete copy is held offline and backs quotations on this site. The original publication remains the canonical public source.

  16. source content difference between and source content +20 -0

    The Reddit thread gained 2 new comments.

    seen · Captured here 13,290 chars
    What changed from the previous capture 20 lines
     edited: false
     body:
     Ledger is Number One ☝️
    +
    +comment: p1pzxcz
    +parent: t3_1vfbi4w
    +author: StageComprehensive81
    +created_utc: 1785875104
    +edited: false
    +body:
    +Is not the device, but the software. They updated the software. You can make a new seed from it and a strong passphrase no need to throw away the Coldcard. 
    +
    +comment: p1q0eis
    +parent: t1_p1oxxr8
    +author: adequate_redditor
    +created_utc: 1785875229
    +edited: false
    +body:
    +Yes, but there were similar hacks before. Many YouTube videos from years ago go over this exact situation. The hardware is sufficient for entropy, but if it’s flawed in anyway then you get something like the coldcard hack…
    +
    +https://youtu.be/D9j5y3tyMo8
    +
    +Wallets that don’t offer the dice roll function could be at risk too if similar vulnerabilities are uncovered.
    
    Extracted text as captured
    post: 1vfbi4w
    author: General_Asparagus976
    created_utc: 1785852725
    title: I'm out
    body:
    Moved off of coldcard even with mk4 with dice and a passphrase.  This humbled a lot of people who thought they were doing the safest, most transparent form of self custody. This is not what any of us signed up for, and who knows what they have to do to recover trust and continue as a company but I'm not gonna leave my funds there while they sort it out. Sorry to everyone for going through this really sickening for those that lost btc and disturbing to anyone practicing self custody. 
    
    comment: p1nlzuy
    parent: t3_1vfbi4w
    author: Ok-Information-2428
    created_utc: 1785853196
    edited: false
    body:
    COLDCARD is done. They’re a bunch of incompetent reckless assholes. Sadly it’s too late
    
    comment: p1nnuzo
    parent: t3_1vfbi4w
    author: alixanc
    created_utc: 1785853690
    edited: false
    body:
    "doing the safest, most transparent form of self custody" Trusting a single black box RNG for seed creation is far from the safest and most transparent form of self custody. They trusted and they got rekt. So simple to just combine 2 or 3 software RNGs or mix in some physical entropy via card/dice/coins etc. Even the ColdCard maker himself suggested not trusting any single software RNG.
    
    comment: p1np0sk
    parent: t3_1vfbi4w
    author: Netopr22
    created_utc: 1785853999
    edited: false
    body:
    i dont trust them anymore, i will give my coldcard q for my kids to play.... Or in the event a thief breaks into my house i will give it to him with the seed phrase... Only 0.63 cents remain on it..
    
    comment: p1nqdxy
    parent: t3_1vfbi4w
    author: opossum_cz
    created_utc: 1785854362
    edited: false
    body:
    \> people who thought they were doing the safest, most transparent form of self custody
    
    Honestly, this sounds more like being delusional. I can't even blame Coldcard for this.

    Excerpt only. The complete copy is held offline and backs quotations on this site. The original publication remains the canonical public source.

  17. source content difference between and source content +24 -0

    The Reddit thread gained 3 new comments.

    seen · Captured here 12,551 chars
    What changed from the previous capture 24 lines
     edited: false
     body:
     …. And I am here expecting the company to pay back the $$ I spent to get 2 CCs that I got in 2023
    +
    +comment: p1pvrei
    +parent: t3_1vfbi4w
    +author: Emotional-Run9144
    +created_utc: 1785874006
    +edited: false
    +body:
    +No form of custody is every 100% safe, not with crypto or real world assets.
    +
    +comment: p1pwg0u
    +parent: t3_1vfbi4w
    +author: hakunamatata0002
    +created_utc: 1785874187
    +edited: false
    +body:
    +Bet they'll come out as different name for wallet soon!
    +
    +comment: p1pxriw
    +parent: t3_1vfbi4w
    +author: Aqua-Barracuda
    +created_utc: 1785874536
    +edited: false
    +body:
    +Ledger is Number One ☝️
    
    Extracted text as captured
    post: 1vfbi4w
    author: General_Asparagus976
    created_utc: 1785852725
    title: I'm out
    body:
    Moved off of coldcard even with mk4 with dice and a passphrase.  This humbled a lot of people who thought they were doing the safest, most transparent form of self custody. This is not what any of us signed up for, and who knows what they have to do to recover trust and continue as a company but I'm not gonna leave my funds there while they sort it out. Sorry to everyone for going through this really sickening for those that lost btc and disturbing to anyone practicing self custody. 
    
    comment: p1nlzuy
    parent: t3_1vfbi4w
    author: Ok-Information-2428
    created_utc: 1785853196
    edited: false
    body:
    COLDCARD is done. They’re a bunch of incompetent reckless assholes. Sadly it’s too late
    
    comment: p1nnuzo
    parent: t3_1vfbi4w
    author: alixanc
    created_utc: 1785853690
    edited: false
    body:
    "doing the safest, most transparent form of self custody" Trusting a single black box RNG for seed creation is far from the safest and most transparent form of self custody. They trusted and they got rekt. So simple to just combine 2 or 3 software RNGs or mix in some physical entropy via card/dice/coins etc. Even the ColdCard maker himself suggested not trusting any single software RNG.
    
    comment: p1np0sk
    parent: t3_1vfbi4w
    author: Netopr22
    created_utc: 1785853999
    edited: false
    body:
    i dont trust them anymore, i will give my coldcard q for my kids to play.... Or in the event a thief breaks into my house i will give it to him with the seed phrase... Only 0.63 cents remain on it..
    
    comment: p1nqdxy
    parent: t3_1vfbi4w
    author: opossum_cz
    created_utc: 1785854362
    edited: false
    body:
    \> people who thought they were doing the safest, most transparent form of self custody
    
    Honestly, this sounds more like being delusional. I can't even blame Coldcard for this.

    Excerpt only. The complete copy is held offline and backs quotations on this site. The original publication remains the canonical public source.

  18. source content difference between and source content +8 -0

    The Reddit thread gained 1 new comment.

    seen · Captured here 12,077 chars
    What changed from the previous capture 8 lines
     body:
     Even scarier to think it wasnt incompetente at all. Deliberate, planned way in advance:
     https://www.reddit.com/r/CryptoCurrency/s/s5fNgg9k4X
    +
    +comment: p1prhh8
    +parent: t1_p1oy5k1
    +author: ady1583
    +created_utc: 1785872875
    +edited: false
    +body:
    +…. And I am here expecting the company to pay back the $$ I spent to get 2 CCs that I got in 2023
    
    Extracted text as captured
    post: 1vfbi4w
    author: General_Asparagus976
    created_utc: 1785852725
    title: I'm out
    body:
    Moved off of coldcard even with mk4 with dice and a passphrase.  This humbled a lot of people who thought they were doing the safest, most transparent form of self custody. This is not what any of us signed up for, and who knows what they have to do to recover trust and continue as a company but I'm not gonna leave my funds there while they sort it out. Sorry to everyone for going through this really sickening for those that lost btc and disturbing to anyone practicing self custody. 
    
    comment: p1nlzuy
    parent: t3_1vfbi4w
    author: Ok-Information-2428
    created_utc: 1785853196
    edited: false
    body:
    COLDCARD is done. They’re a bunch of incompetent reckless assholes. Sadly it’s too late
    
    comment: p1nnuzo
    parent: t3_1vfbi4w
    author: alixanc
    created_utc: 1785853690
    edited: false
    body:
    "doing the safest, most transparent form of self custody" Trusting a single black box RNG for seed creation is far from the safest and most transparent form of self custody. They trusted and they got rekt. So simple to just combine 2 or 3 software RNGs or mix in some physical entropy via card/dice/coins etc. Even the ColdCard maker himself suggested not trusting any single software RNG.
    
    comment: p1np0sk
    parent: t3_1vfbi4w
    author: Netopr22
    created_utc: 1785853999
    edited: false
    body:
    i dont trust them anymore, i will give my coldcard q for my kids to play.... Or in the event a thief breaks into my house i will give it to him with the seed phrase... Only 0.63 cents remain on it..
    
    comment: p1nqdxy
    parent: t3_1vfbi4w
    author: opossum_cz
    created_utc: 1785854362
    edited: false
    body:
    \> people who thought they were doing the safest, most transparent form of self custody
    
    Honestly, this sounds more like being delusional. I can't even blame Coldcard for this.

    Excerpt only. The complete copy is held offline and backs quotations on this site. The original publication remains the canonical public source.

  19. source content difference between and source content +9 -0

    The Reddit thread gained 1 new comment.

    seen · Captured here 11,882 chars
    What changed from the previous capture 9 lines
     edited: false
     body:
     What makes you think that another hw wallet won't get hacked in a similar way?
    +
    +comment: p1pfyij
    +parent: t1_p1nlzuy
    +author: anotherfroggyevening
    +created_utc: 1785869873
    +edited: false
    +body:
    +Even scarier to think it wasnt incompetente at all. Deliberate, planned way in advance:
    +https://www.reddit.com/r/CryptoCurrency/s/s5fNgg9k4X
    
    Extracted text as captured
    post: 1vfbi4w
    author: General_Asparagus976
    created_utc: 1785852725
    title: I'm out
    body:
    Moved off of coldcard even with mk4 with dice and a passphrase.  This humbled a lot of people who thought they were doing the safest, most transparent form of self custody. This is not what any of us signed up for, and who knows what they have to do to recover trust and continue as a company but I'm not gonna leave my funds there while they sort it out. Sorry to everyone for going through this really sickening for those that lost btc and disturbing to anyone practicing self custody. 
    
    comment: p1nlzuy
    parent: t3_1vfbi4w
    author: Ok-Information-2428
    created_utc: 1785853196
    edited: false
    body:
    COLDCARD is done. They’re a bunch of incompetent reckless assholes. Sadly it’s too late
    
    comment: p1nnuzo
    parent: t3_1vfbi4w
    author: alixanc
    created_utc: 1785853690
    edited: false
    body:
    "doing the safest, most transparent form of self custody" Trusting a single black box RNG for seed creation is far from the safest and most transparent form of self custody. They trusted and they got rekt. So simple to just combine 2 or 3 software RNGs or mix in some physical entropy via card/dice/coins etc. Even the ColdCard maker himself suggested not trusting any single software RNG.
    
    comment: p1np0sk
    parent: t3_1vfbi4w
    author: Netopr22
    created_utc: 1785853999
    edited: false
    body:
    i dont trust them anymore, i will give my coldcard q for my kids to play.... Or in the event a thief breaks into my house i will give it to him with the seed phrase... Only 0.63 cents remain on it..
    
    comment: p1nqdxy
    parent: t3_1vfbi4w
    author: opossum_cz
    created_utc: 1785854362
    edited: false
    body:
    \> people who thought they were doing the safest, most transparent form of self custody
    
    Honestly, this sounds more like being delusional. I can't even blame Coldcard for this.

    Excerpt only. The complete copy is held offline and backs quotations on this site. The original publication remains the canonical public source.

  20. source content difference between and source content +8 -0

    The Reddit thread gained 1 new comment.

    seen · Captured here 11,631 chars
    What changed from the previous capture 8 lines
     edited: false
     body:
     Ive seen people say theyre okay with continuing to use the coldcard with their dice generated seedphrase and passphrase, but fuck that... This company doesnt deserve anyone staying with them. If they missed this bug that was there since 2021 what else have they missed... plus they arent gonna reimburse victims of this disaster. 
    +
    +comment: p1p4tx9
    +parent: t1_p1ocvfz
    +author: mj
    +created_utc: 1785867095
    +edited: false
    +body:
    +What makes you think that another hw wallet won't get hacked in a similar way?
    
    Extracted text as captured
    post: 1vfbi4w
    author: General_Asparagus976
    created_utc: 1785852725
    title: I'm out
    body:
    Moved off of coldcard even with mk4 with dice and a passphrase.  This humbled a lot of people who thought they were doing the safest, most transparent form of self custody. This is not what any of us signed up for, and who knows what they have to do to recover trust and continue as a company but I'm not gonna leave my funds there while they sort it out. Sorry to everyone for going through this really sickening for those that lost btc and disturbing to anyone practicing self custody. 
    
    comment: p1nlzuy
    parent: t3_1vfbi4w
    author: Ok-Information-2428
    created_utc: 1785853196
    edited: false
    body:
    COLDCARD is done. They’re a bunch of incompetent reckless assholes. Sadly it’s too late
    
    comment: p1nnuzo
    parent: t3_1vfbi4w
    author: alixanc
    created_utc: 1785853690
    edited: false
    body:
    "doing the safest, most transparent form of self custody" Trusting a single black box RNG for seed creation is far from the safest and most transparent form of self custody. They trusted and they got rekt. So simple to just combine 2 or 3 software RNGs or mix in some physical entropy via card/dice/coins etc. Even the ColdCard maker himself suggested not trusting any single software RNG.
    
    comment: p1np0sk
    parent: t3_1vfbi4w
    author: Netopr22
    created_utc: 1785853999
    edited: false
    body:
    i dont trust them anymore, i will give my coldcard q for my kids to play.... Or in the event a thief breaks into my house i will give it to him with the seed phrase... Only 0.63 cents remain on it..
    
    comment: p1nqdxy
    parent: t3_1vfbi4w
    author: opossum_cz
    created_utc: 1785854362
    edited: false
    body:
    \> people who thought they were doing the safest, most transparent form of self custody
    
    Honestly, this sounds more like being delusional. I can't even blame Coldcard for this.

    Excerpt only. The complete copy is held offline and backs quotations on this site. The original publication remains the canonical public source.

  21. Earliest copy held
    seen · Captured here 11,460 chars
    Extracted text as captured
    post: 1vfbi4w
    author: General_Asparagus976
    created_utc: 1785852725
    title: I'm out
    body:
    Moved off of coldcard even with mk4 with dice and a passphrase.  This humbled a lot of people who thought they were doing the safest, most transparent form of self custody. This is not what any of us signed up for, and who knows what they have to do to recover trust and continue as a company but I'm not gonna leave my funds there while they sort it out. Sorry to everyone for going through this really sickening for those that lost btc and disturbing to anyone practicing self custody. 
    
    comment: p1nlzuy
    parent: t3_1vfbi4w
    author: Ok-Information-2428
    created_utc: 1785853196
    edited: false
    body:
    COLDCARD is done. They’re a bunch of incompetent reckless assholes. Sadly it’s too late
    
    comment: p1nnuzo
    parent: t3_1vfbi4w
    author: alixanc
    created_utc: 1785853690
    edited: false
    body:
    "doing the safest, most transparent form of self custody" Trusting a single black box RNG for seed creation is far from the safest and most transparent form of self custody. They trusted and they got rekt. So simple to just combine 2 or 3 software RNGs or mix in some physical entropy via card/dice/coins etc. Even the ColdCard maker himself suggested not trusting any single software RNG.
    
    comment: p1np0sk
    parent: t3_1vfbi4w
    author: Netopr22
    created_utc: 1785853999
    edited: false
    body:
    i dont trust them anymore, i will give my coldcard q for my kids to play.... Or in the event a thief breaks into my house i will give it to him with the seed phrase... Only 0.63 cents remain on it..
    
    comment: p1nqdxy
    parent: t3_1vfbi4w
    author: opossum_cz
    created_utc: 1785854362
    edited: false
    body:
    \> people who thought they were doing the safest, most transparent form of self custody
    
    Honestly, this sounds more like being delusional. I can't even blame Coldcard for this.

    Excerpt only. The complete copy is held offline and backs quotations on this site. The original publication remains the canonical public source.

How to check this yourself

The excerpts and plain unified diffs above show the text this project held and how it changed. To verify a quotation, compare it against the page itself or against the Internet Archive's copies, which are independent of this project.

Complete captures are held offline rather than mirrored here, so this page shows diffs and excerpts. If a quotation is ever disputed, the full copy can be produced. Ask.