COLDCARD RNG incident the public record, collected and explained
Informational only, and this site never asks for your seed words. details

Informational only. This is an open source collection of what others have published about the incident, together with an explanation of it. It is not financial, security or legal advice, and not a substitute for professional advice about your own situation. It is not affiliated with, endorsed by, or speaking for Coinkite. Material is attributed and quoted as published; where sources disagree their scenarios are kept separate with their assumptions rather than reconciled into one answer. Everything is meant to be checked against the linked evidence rather than taken on trust. Act on your own judgement about a particular situation. Editorial standards and corrections.

Do not disclose recovery material to a website, form, message or support account. This site never asks for it, and contributions containing recovery words or private keys are not accepted.

Coldcard scam letter in the mail

reddit-june-letter-report

https://www.reddit.com/r/Bitcoin/comments/1ub35ej/coldcard_scam_letter_in_the_mail/

Organisation
r/Bitcoin
Evidence role
Community discussion
Published
2026-06-20
Source changes
0
Detected differences
0
Unreviewed
0
Copies held
1

First-hand report with a photograph of the June 2026 physical letter impersonating Coinkite: post-quantum security-update pretext, 30 June 2026 deadline, personalised QR code, forged CEO signature. The poster asks whether Coinkite had a data breach, and a reply in Coinkite's name denies one, citing the 120-day address deletion. Located 3 Aug 2026; until then the letter was known here only through Coinkite's 24 June response (coinkite-paper-spam).

Every check is recorded, including checks that found no text change. A detected edit is therefore bounded between two checks. The publisher's exact save time is not observable from this record. Last checked .

  1. Earliest copy held Current
    seen · Captured here 4,859 chars
    Extracted text as captured
    post: 1ub35ej
    author: Constant-Number4020
    created_utc: 1781978598
    title: Coldcard scam letter in the mail
    body:
    Received this letter in the mail, supposedly from Coinkite (even though the envelope indicates a Michigan origination) begs the question... did Coinkite experience a data breach and now coldcard owners are being targeted? I know this has been going on with Ledger for years. Be careful out there friends!
    
    comment: ossyi29
    parent: t3_1ub35ej
    author: [deleted]
    created_utc: 1781978856
    edited: false
    body:
    [deleted]
    
    comment: ossypui
    parent: t1_ossyi29
    author: Constant-Number4020
    created_utc: 1781978921
    edited: false
    body:
    Good point! I own both (ledger for shitcoins) so yes, i was likely in the ledger leak. 
    
    Edit - but I've moved recently and this letter had my new address, so if there was a coinkite leak, it had to happen recently (bought my coldcard last fall) The ledger leak would not have my new address
    
    comment: osszd6v
    parent: t1_ossyi29
    author: [deleted]
    created_utc: 1781979110
    edited: false
    body:
    [removed]
    
    comment: osszgp0
    parent: t3_1ub35ej
    author: Hit4Help
    created_utc: 1781979139
    edited: false
    body:
    I had one like this for trezor land at an old address (and eventually passed to me), was sent from France and used nice quality paper. 

    Excerpt only. The complete copy is held offline and backs quotations on this site. The original publication remains the canonical public source.

How to check this yourself

The excerpts and plain unified diffs above show the text this project held and how it changed. To verify a quotation, compare it against the page itself or against the Internet Archive's copies, which are independent of this project.

Complete captures are held offline rather than mirrored here, so this page shows diffs and excerpts. If a quotation is ever disputed, the full copy can be produced. Ask.