COLDCARD RNG incident the public record, collected and explained
Informational only, and this site never asks for your seed words. details

Informational only. This is an open source collection of what others have published about the incident, together with an explanation of it. It is not financial, security or legal advice, and not a substitute for professional advice about your own situation. It is not affiliated with, endorsed by, or speaking for Coinkite. Material is attributed and quoted as published; where sources disagree their scenarios are kept separate with their assumptions rather than reconciled into one answer. Everything is meant to be checked against the linked evidence rather than taken on trust. Act on your own judgement about a particular situation. Editorial standards and corrections.

Do not disclose recovery material to a website, form, message or support account. This site never asks for it, and contributions containing recovery words or private keys are not accepted.

r/coldcard: speculation about the bug's 2021 origin

reddit-inside-job-speculation

https://www.reddit.com/r/coldcard/comments/1vfdmtf/inside_job_the_bug_conveniently_originated_in_2021/

Latest reviewed change

source content difference between and

One new comment by Charming-Designer944 laying out dice-roll entropy math: 50 rolls for 128 bits and 100 rolls for a 256-bit, 24-word seed.

seen +10 -0 full history below
 body:
 Why would he mention it to Matt Odell in 2021 and basically give away that the bug is a vulnerability in the RNG?  
 There's a video of matt talking about it out there.
+
+comment: p263krk
+parent: t1_p1soeju
+author: Charming-Designer944
+created_utc: 1786061774

First lines only. The complete diff is in the timeline below.

Organisation
reddit
Evidence role
Community discussion
Published
not established
Source changes
8
Detected differences
8
Unreviewed
0
Copies held
9

Every check is recorded, including checks that found no text change. A detected edit is therefore bounded between two checks. The publisher's exact save time is not observable from this record. Last checked .

  1. source content difference between and Current source content +10 -0

    One new comment by Charming-Designer944 laying out dice-roll entropy math: 50 rolls for 128 bits and 100 rolls for a 256-bit, 24-word seed.

    seen · Captured here 7,580 chars
    What changed from the previous capture 10 lines
     body:
     Why would he mention it to Matt Odell in 2021 and basically give away that the bug is a vulnerability in the RNG?  
     There's a video of matt talking about it out there.
    +
    +comment: p263krk
    +parent: t1_p1soeju
    +author: Charming-Designer944
    +created_utc: 1786061774
    +edited: false
    +body:
    +50 dice rolls are required for 128 bits of entropy, which is considered the minimum secure level, and also the amount of entropy that is saved in a 12 word Bip-39 seed phrase.
    +
    +For 256 bits (24 word bip-39 seed phrase) 100 dice rolls are needed. (256/log2(6) = 99.034).
    
    Extracted text as captured
    post: 1vfdmtf
    author: Such_Advantage6988
    created_utc: 1785857383
    title: Inside job? The “bug” conveniently originated in 2021
    body:
    Original: https://x.com/coldcardwallet/status/1447213375398846473?s=46
    
    comment: p1o60gy
    parent: t3_1vfdmtf
    author: EngelGate
    created_utc: 1785858429
    edited: false
    body:
    Priceless. 
    
    comment: p1o81cs
    parent: t3_1vfdmtf
    author: Friendly-Sign-3289
    created_utc: 1785858941
    edited: false
    body:
    Seems bait AF this tweet 🤔 
    
    comment: p1obza0
    parent: t3_1vfdmtf
    author: Such_Advantage6988
    created_utc: 1785859939
    edited: false
    body:
    to quote from another thread:
    
    That would be Peter Gray, aka doc-hex.
    
    The person most clearly associated with the vulnerable Coldcard RNG integration is Peter D. Gray, via the doc-hexaccount.
    
    The exact sequence was:
    
    1.	⁠switck\*\*, January 28, 2021:\*\* wrote the defective libNgU feature check.  
    2.	⁠doc-hex\*\*, March 1, 2021:\*\* imported that code, disabled MicroPython’s hardware RNG in the board configuration, and switched master-seed generation to the affected ngu.random path.  
    3.	⁠Coinkite, March 17, 2021: released it as firmware 4.0.0.  

    Excerpt only. The complete copy is held offline and backs quotations on this site. The original publication remains the canonical public source.

  2. source content difference between and source content +9 -0

    Reddit served 1 additional comment record(s); the diff preserves their text and any edits to existing records.

    seen · Captured here 7,200 chars
    What changed from the previous capture 9 lines
     edited: false
     body:
     Thanks. I think I also did 100 dice rolls and was able to move my balance to an updated, new wallet, yesterday. 🤷‍♂️
    +
    +comment: p22oqgf
    +parent: t3_1vfdmtf
    +author: monstane
    +created_utc: 1786028969
    +edited: false
    +body:
    +Why would he mention it to Matt Odell in 2021 and basically give away that the bug is a vulnerability in the RNG?  
    +There's a video of matt talking about it out there.
    
    Extracted text as captured
    post: 1vfdmtf
    author: Such_Advantage6988
    created_utc: 1785857383
    title: Inside job? The “bug” conveniently originated in 2021
    body:
    Original: https://x.com/coldcardwallet/status/1447213375398846473?s=46
    
    comment: p1o60gy
    parent: t3_1vfdmtf
    author: EngelGate
    created_utc: 1785858429
    edited: false
    body:
    Priceless. 
    
    comment: p1o81cs
    parent: t3_1vfdmtf
    author: Friendly-Sign-3289
    created_utc: 1785858941
    edited: false
    body:
    Seems bait AF this tweet 🤔 
    
    comment: p1obza0
    parent: t3_1vfdmtf
    author: Such_Advantage6988
    created_utc: 1785859939
    edited: false
    body:
    to quote from another thread:
    
    That would be Peter Gray, aka doc-hex.
    
    The person most clearly associated with the vulnerable Coldcard RNG integration is Peter D. Gray, via the doc-hexaccount.
    
    The exact sequence was:
    
    1.	⁠switck\*\*, January 28, 2021:\*\* wrote the defective libNgU feature check.  
    2.	⁠doc-hex\*\*, March 1, 2021:\*\* imported that code, disabled MicroPython’s hardware RNG in the board configuration, and switched master-seed generation to the affected ngu.random path.  
    3.	⁠Coinkite, March 17, 2021: released it as firmware 4.0.0.  

    Excerpt only. The complete copy is held offline and backs quotations on this site. The original publication remains the canonical public source.

  3. source content difference between and source content +16 -0

    Reddit served 2 additional comment record(s); the diff preserves their text and any edits to existing records.

    seen · Captured here 6,934 chars
    What changed from the previous capture 16 lines
     edited: false
     body:
     The one thing that makes me think it could have been an inside job is that their CTO wrote that shady crypto library under a pseudonym.
    +
    +comment: p1y0rnt
    +parent: t1_p1soeju
    +author: aureliorramos
    +created_utc: 1785967532
    +edited: false
    +body:
    +I think it was like 100 dice rolls when I set mine up several years ago
    +
    +comment: p1y5emo
    +parent: t1_p1y0rnt
    +author: 4r4nd0mninj4
    +created_utc: 1785968926
    +edited: false
    +body:
    +Thanks. I think I also did 100 dice rolls and was able to move my balance to an updated, new wallet, yesterday. 🤷‍♂️
    
    Extracted text as captured
    post: 1vfdmtf
    author: Such_Advantage6988
    created_utc: 1785857383
    title: Inside job? The “bug” conveniently originated in 2021
    body:
    Original: https://x.com/coldcardwallet/status/1447213375398846473?s=46
    
    comment: p1o60gy
    parent: t3_1vfdmtf
    author: EngelGate
    created_utc: 1785858429
    edited: false
    body:
    Priceless. 
    
    comment: p1o81cs
    parent: t3_1vfdmtf
    author: Friendly-Sign-3289
    created_utc: 1785858941
    edited: false
    body:
    Seems bait AF this tweet 🤔 
    
    comment: p1obza0
    parent: t3_1vfdmtf
    author: Such_Advantage6988
    created_utc: 1785859939
    edited: false
    body:
    to quote from another thread:
    
    That would be Peter Gray, aka doc-hex.
    
    The person most clearly associated with the vulnerable Coldcard RNG integration is Peter D. Gray, via the doc-hexaccount.
    
    The exact sequence was:
    
    1.	⁠switck\*\*, January 28, 2021:\*\* wrote the defective libNgU feature check.  
    2.	⁠doc-hex\*\*, March 1, 2021:\*\* imported that code, disabled MicroPython’s hardware RNG in the board configuration, and switched master-seed generation to the affected ngu.random path.  
    3.	⁠Coinkite, March 17, 2021: released it as firmware 4.0.0.  

    Excerpt only. The complete copy is held offline and backs quotations on this site. The original publication remains the canonical public source.

  4. source content difference between and source content +8 -0

    Reddit served 1 additional comment record(s); the diff preserves their text and any edits to existing records.

    seen · Captured here 6,539 chars
    What changed from the previous capture 8 lines
     edited: false
     body:
     Yeah he’s going to prison 
    +
    +comment: p1vyq6p
    +parent: t1_p1qbmgs
    +author: Deto
    +created_utc: 1785948304
    +edited: false
    +body:
    +The one thing that makes me think it could have been an inside job is that their CTO wrote that shady crypto library under a pseudonym.
    
    Extracted text as captured
    post: 1vfdmtf
    author: Such_Advantage6988
    created_utc: 1785857383
    title: Inside job? The “bug” conveniently originated in 2021
    body:
    Original: https://x.com/coldcardwallet/status/1447213375398846473?s=46
    
    comment: p1o60gy
    parent: t3_1vfdmtf
    author: EngelGate
    created_utc: 1785858429
    edited: false
    body:
    Priceless. 
    
    comment: p1o81cs
    parent: t3_1vfdmtf
    author: Friendly-Sign-3289
    created_utc: 1785858941
    edited: false
    body:
    Seems bait AF this tweet 🤔 
    
    comment: p1obza0
    parent: t3_1vfdmtf
    author: Such_Advantage6988
    created_utc: 1785859939
    edited: false
    body:
    to quote from another thread:
    
    That would be Peter Gray, aka doc-hex.
    
    The person most clearly associated with the vulnerable Coldcard RNG integration is Peter D. Gray, via the doc-hexaccount.
    
    The exact sequence was:
    
    1.	⁠switck\*\*, January 28, 2021:\*\* wrote the defective libNgU feature check.  
    2.	⁠doc-hex\*\*, March 1, 2021:\*\* imported that code, disabled MicroPython’s hardware RNG in the board configuration, and switched master-seed generation to the affected ngu.random path.  
    3.	⁠Coinkite, March 17, 2021: released it as firmware 4.0.0.  

    Excerpt only. The complete copy is held offline and backs quotations on this site. The original publication remains the canonical public source.

  5. source content difference between and source content +90 -0

    Reddit served 11 additional comment record(s); the diff preserves their text and any edits to existing records.

    seen · Captured here 6,309 chars
    What changed from the previous capture 90 lines
     edited: false
     body:
     Jews right 
    +
    +comment: p1rvgbd
    +parent: t1_p1rtkru
    +author: Dense_Egg_5858
    +created_utc: 1785895453
    +edited: false
    +body:
    +God fuck right off 
    +
    +comment: p1s0gho
    +parent: t3_1vfdmtf
    +author: [deleted]
    +created_utc: 1785897115
    +edited: false
    +body:
    +[removed]
    +
    +comment: p1sa5s6
    +parent: t1_p1rvgbd
    +author: DavidssonA
    +created_utc: 1785900535
    +edited: false
    +body:
    +New here?
    +
    +comment: p1sf3pp
    +parent: t3_1vfdmtf
    +author: Lost-Bowl3269
    +created_utc: 1785902410
    +edited: false
    +body:
    +Provavelmente. 
    +
    +comment: p1shfyk
    +parent: t1_p1s0gho
    +author: moviemaker2
    +created_utc: 1785903332
    +edited: false
    +body:
    +No they have not, If you'd even watched the first 20 seconds you'd have gotten to the part where the user just used a single dice roll, so they weren't even using the TRNG properly.
    +
    +Why are people so allergic to watching/reading the links they post as "evidence" for this nonsense?
    +
    +comment: p1shpln
    +parent: t1_p1shfyk
    +author: [deleted]
    +created_utc: 1785903438
    +edited: false
    +body:
    +[removed]
    +
    +comment: p1sler3
    +parent: t1_p1shpln
    +author: moviemaker2
    +created_utc: 1785904962
    +edited: false
    +body:
    +You presented that video as evidence that this exploit was called out 2 years ago.  An improper number of dice rolls is not related in any way, shape or form to this vulnerability.  You have no idea what you're talking about.
    +
    +comment: p1soeju
    +parent: t3_1vfdmtf
    +author: 4r4nd0mninj4
    +created_utc: 1785906238
    +edited: false
    +body:
    +Does anyone know how many dice rolls were needed to be safe from this?
    +
    +comment: p1t02th
    +parent: t1_p1qbmgs
    +author: The25thUser
    +created_utc: 1785911560
    +edited: false
    +body:
    +This is a good point, announcing publicly would have meant an attacker could have gotten to it first.
    +
    +comment: p1t8r82
    +parent: t3_1vfdmtf
    +author: TraditionalAd7423
    +created_utc: 1785915721
    +edited: false
    +body:
    +Can't spell crypto without "scam"
    +
    +comment: p1tbvhx
    +parent: t1_p1obza0
    +author: No-Aardvark-3840
    +created_utc: 1785917244
    +edited: false
    +body:
    +Yeah he’s going to prison 
    
    Extracted text as captured
    post: 1vfdmtf
    author: Such_Advantage6988
    created_utc: 1785857383
    title: Inside job? The “bug” conveniently originated in 2021
    body:
    Original: https://x.com/coldcardwallet/status/1447213375398846473?s=46
    
    comment: p1o60gy
    parent: t3_1vfdmtf
    author: EngelGate
    created_utc: 1785858429
    edited: false
    body:
    Priceless. 
    
    comment: p1o81cs
    parent: t3_1vfdmtf
    author: Friendly-Sign-3289
    created_utc: 1785858941
    edited: false
    body:
    Seems bait AF this tweet 🤔 
    
    comment: p1obza0
    parent: t3_1vfdmtf
    author: Such_Advantage6988
    created_utc: 1785859939
    edited: false
    body:
    to quote from another thread:
    
    That would be Peter Gray, aka doc-hex.
    
    The person most clearly associated with the vulnerable Coldcard RNG integration is Peter D. Gray, via the doc-hexaccount.
    
    The exact sequence was:
    
    1.	⁠switck\*\*, January 28, 2021:\*\* wrote the defective libNgU feature check.  
    2.	⁠doc-hex\*\*, March 1, 2021:\*\* imported that code, disabled MicroPython’s hardware RNG in the board configuration, and switched master-seed generation to the affected ngu.random path.  
    3.	⁠Coinkite, March 17, 2021: released it as firmware 4.0.0.  

    Excerpt only. The complete copy is held offline and backs quotations on this site. The original publication remains the canonical public source.

  6. source content difference between and source content +8 -0

    The Reddit thread gained an antisemitic reply asserting a Jewish conspiracy.

    seen · Captured here 4,377 chars
    What changed from the previous capture 8 lines
     edited: false
     body:
     They could also just have a social media person who has no idea what's going on with the code.
    +
    +comment: p1rtkru
    +parent: t3_1vfdmtf
    +author: extraepicc
    +created_utc: 1785894835
    +edited: false
    +body:
    +Jews right 
    
    Extracted text as captured
    post: 1vfdmtf
    author: Such_Advantage6988
    created_utc: 1785857383
    title: Inside job? The “bug” conveniently originated in 2021
    body:
    Original: https://x.com/coldcardwallet/status/1447213375398846473?s=46
    
    comment: p1o60gy
    parent: t3_1vfdmtf
    author: EngelGate
    created_utc: 1785858429
    edited: false
    body:
    Priceless. 
    
    comment: p1o81cs
    parent: t3_1vfdmtf
    author: Friendly-Sign-3289
    created_utc: 1785858941
    edited: false
    body:
    Seems bait AF this tweet 🤔 
    
    comment: p1obza0
    parent: t3_1vfdmtf
    author: Such_Advantage6988
    created_utc: 1785859939
    edited: false
    body:
    to quote from another thread:
    
    That would be Peter Gray, aka doc-hex.
    
    The person most clearly associated with the vulnerable Coldcard RNG integration is Peter D. Gray, via the doc-hexaccount.
    
    The exact sequence was:
    
    1.	⁠switck\*\*, January 28, 2021:\*\* wrote the defective libNgU feature check.  
    2.	⁠doc-hex\*\*, March 1, 2021:\*\* imported that code, disabled MicroPython’s hardware RNG in the board configuration, and switched master-seed generation to the affected ngu.random path.  
    3.	⁠Coinkite, March 17, 2021: released it as firmware 4.0.0.  

    Excerpt only. The complete copy is held offline and backs quotations on this site. The original publication remains the canonical public source.

  7. source content difference between and source content +8 -0

    The Reddit thread gained a comment suggesting the social-media responder might not know the codebase.

    seen · Captured here 4,265 chars
    What changed from the previous capture 8 lines
     This is a tricky one either way since you can’t fix already generated seeds.
     
     UPDATE: This actually has me thinking now lol… maybe they were aware of the issue and the introduction of dice rolls feature was their silent way out without announcing it and ruining their company??!?
    +
    +comment: p1qza2c
    +parent: t1_p1okmrn
    +author: grraarr
    +created_utc: 1785885096
    +edited: false
    +body:
    +They could also just have a social media person who has no idea what's going on with the code.
    
    Extracted text as captured
    post: 1vfdmtf
    author: Such_Advantage6988
    created_utc: 1785857383
    title: Inside job? The “bug” conveniently originated in 2021
    body:
    Original: https://x.com/coldcardwallet/status/1447213375398846473?s=46
    
    comment: p1o60gy
    parent: t3_1vfdmtf
    author: EngelGate
    created_utc: 1785858429
    edited: false
    body:
    Priceless. 
    
    comment: p1o81cs
    parent: t3_1vfdmtf
    author: Friendly-Sign-3289
    created_utc: 1785858941
    edited: false
    body:
    Seems bait AF this tweet 🤔 
    
    comment: p1obza0
    parent: t3_1vfdmtf
    author: Such_Advantage6988
    created_utc: 1785859939
    edited: false
    body:
    to quote from another thread:
    
    That would be Peter Gray, aka doc-hex.
    
    The person most clearly associated with the vulnerable Coldcard RNG integration is Peter D. Gray, via the doc-hexaccount.
    
    The exact sequence was:
    
    1.	⁠switck\*\*, January 28, 2021:\*\* wrote the defective libNgU feature check.  
    2.	⁠doc-hex\*\*, March 1, 2021:\*\* imported that code, disabled MicroPython’s hardware RNG in the board configuration, and switched master-seed generation to the affected ngu.random path.  
    3.	⁠Coinkite, March 17, 2021: released it as firmware 4.0.0.  

    Excerpt only. The complete copy is held offline and backs quotations on this site. The original publication remains the canonical public source.

  8. source content difference between and source content +20 -0

    The Reddit thread gained 1 new comment rejecting an inside-job theory while speculating about disclosure timing.

    seen · Captured here 4,073 chars
    What changed from the previous capture 20 lines
     3. Encourages people to roll dice instead of using the compromized RNG, reducing the potential bounty.
     
     It could be that they were malicious but if so their strategy was all over the place, between clever setup of plausible deniability and some weird choices. For example they could have easily put the backdoor in the proprietary secure element for less chance of it being discovered (and still the same amount of plausible deniability). And as you say it would likely be the same in their other products. So yeah I think incompetence is more likely.
    +
    +comment: p1qbmgs
    +parent: t3_1vfdmtf
    +author: blurred_rabbit
    +created_utc: 1785878238
    +edited: 1785878605
    +body:
    +I put a lot of thought into this from so many different angles and none of them land on inside job.
    +
    +No one in their right mind would intentionally put a seed generation bug in an open source code base during the early stages of their company. Then let 5 years go by and decide it’s time to now drain wallets.
    +
    +Pretty sure it was pure programming neglect/stupidity with no checks and balances in place for one of the most important part of hardware wallets: seed generation.
    +
    +One thing that did cross my mind is… what if Coinkite did see/notice this bug at some point within the past 5 years and had a huge decision to make:
    +
    +Announce it and patch it and our company is basically done OR see how long we can ride this out.
    +
    +This is a tricky one either way since you can’t fix already generated seeds.
    +
    +UPDATE: This actually has me thinking now lol… maybe they were aware of the issue and the introduction of dice rolls feature was their silent way out without announcing it and ruining their company??!?
    
    Extracted text as captured
    post: 1vfdmtf
    author: Such_Advantage6988
    created_utc: 1785857383
    title: Inside job? The “bug” conveniently originated in 2021
    body:
    Original: https://x.com/coldcardwallet/status/1447213375398846473?s=46
    
    comment: p1o60gy
    parent: t3_1vfdmtf
    author: EngelGate
    created_utc: 1785858429
    edited: false
    body:
    Priceless. 
    
    comment: p1o81cs
    parent: t3_1vfdmtf
    author: Friendly-Sign-3289
    created_utc: 1785858941
    edited: false
    body:
    Seems bait AF this tweet 🤔 
    
    comment: p1obza0
    parent: t3_1vfdmtf
    author: Such_Advantage6988
    created_utc: 1785859939
    edited: false
    body:
    to quote from another thread:
    
    That would be Peter Gray, aka doc-hex.
    
    The person most clearly associated with the vulnerable Coldcard RNG integration is Peter D. Gray, via the doc-hexaccount.
    
    The exact sequence was:
    
    1.	⁠switck\*\*, January 28, 2021:\*\* wrote the defective libNgU feature check.  
    2.	⁠doc-hex\*\*, March 1, 2021:\*\* imported that code, disabled MicroPython’s hardware RNG in the board configuration, and switched master-seed generation to the affected ngu.random path.  
    3.	⁠Coinkite, March 17, 2021: released it as firmware 4.0.0.  

    Excerpt only. The complete copy is held offline and backs quotations on this site. The original publication remains the canonical public source.

  9. Earliest copy held
    seen · Captured here 2,960 chars
    Extracted text as captured
    post: 1vfdmtf
    author: Such_Advantage6988
    created_utc: 1785857383
    title: Inside job? The “bug” conveniently originated in 2021
    body:
    Original: https://x.com/coldcardwallet/status/1447213375398846473?s=46
    
    comment: p1o60gy
    parent: t3_1vfdmtf
    author: EngelGate
    created_utc: 1785858429
    edited: false
    body:
    Priceless. 
    
    comment: p1o81cs
    parent: t3_1vfdmtf
    author: Friendly-Sign-3289
    created_utc: 1785858941
    edited: false
    body:
    Seems bait AF this tweet 🤔 
    
    comment: p1obza0
    parent: t3_1vfdmtf
    author: Such_Advantage6988
    created_utc: 1785859939
    edited: false
    body:
    to quote from another thread:
    
    That would be Peter Gray, aka doc-hex.
    
    The person most clearly associated with the vulnerable Coldcard RNG integration is Peter D. Gray, via the doc-hexaccount.
    
    The exact sequence was:
    
    1.	⁠switck\*\*, January 28, 2021:\*\* wrote the defective libNgU feature check.  
    2.	⁠doc-hex\*\*, March 1, 2021:\*\* imported that code, disabled MicroPython’s hardware RNG in the board configuration, and switched master-seed generation to the affected ngu.random path.  
    3.	⁠Coinkite, March 17, 2021: released it as firmware 4.0.0.  

    Excerpt only. The complete copy is held offline and backs quotations on this site. The original publication remains the canonical public source.

How to check this yourself

The excerpts and plain unified diffs above show the text this project held and how it changed. To verify a quotation, compare it against the page itself or against the Internet Archive's copies, which are independent of this project.

Complete captures are held offline rather than mirrored here, so this page shows diffs and excerpts. If a quotation is ever disputed, the full copy can be produced. Ask.