COLDCARD RNG incident the public record, collected and explained
Informational only, and this site never asks for your seed words. details

Informational only. This is an open source collection of what others have published about the incident, together with an explanation of it. It is not financial, security or legal advice, and not a substitute for professional advice about your own situation. It is not affiliated with, endorsed by, or speaking for Coinkite. Material is attributed and quoted as published; where sources disagree their scenarios are kept separate with their assumptions rather than reconciled into one answer. Everything is meant to be checked against the linked evidence rather than taken on trust. Act on your own judgement about a particular situation. Editorial standards and corrections.

Do not disclose recovery material to a website, form, message or support account. This site never asks for it, and contributions containing recovery words or private keys are not accepted.

r/coldcard: recipient of the June scam letter asking whether Coinkite had a data breach

reddit-letter-data-breach-question

https://www.reddit.com/r/coldcard/comments/1udt4zh/received_a_letter_today_from_coinkite_data_breach/

Organisation
reddit
Evidence role
Community discussion
Published
not established
Source changes
0
Detected differences
0
Unreviewed
0
Copies held
1

Every check is recorded, including checks that found no text change. A detected edit is therefore bounded between two checks. The publisher's exact save time is not observable from this record. Last checked .

  1. Earliest copy held Current
    seen · Captured here 7,560 chars
    Extracted text as captured
    post: 1udt4zh
    author: TexasBryan14
    created_utc: 1782247862
    title: Received a letter today from "Coinkite". Data breach???
    body:
    I received a letter from Coinkite today with steps to guard against post-quantum cryptography. Looks very official, but a quick internet search shows this is likely a scam.
    
    My question is...how did the scammers get my name and address along with the Coinkite device that I purchased (that info is on the letter)? I purchased the device directly from Coinkite not a third party.
    
    Seems to me that Coinkite may have had a data breach and has not announced it. I'm very concerned about this.
    
    comment: otegf7b
    parent: t3_1udt4zh
    author: Quirky-Reveal-1669
    created_utc: 1782248210
    edited: false
    body:
    Can you tell us when you made the purchase? Then we would know the breach would have occurred after that. Did Coinkite make a statement after that date? 
    
    comment: otegp5u
    parent: t3_1udt4zh
    author: Quirky-Reveal-1669
    created_utc: 1782248281
    edited: false
    body:
    The only other option would be if you would have ‘registered’ your Coldcard at some other site. 
    
    comment: otehfo5
    parent: t1_otegf7b
    author: PapaUrsidae
    created_utc: 1782248471
    edited: false
    body:
    Not OP, but I purchased from them 11/19/2025 and received same letter. 
    
    Didn’t think it was real, but it 100% looked super legitimate. Only thing that gave it away to me was scanning a QR code. Nice in theory, but zero awareness of where it goes.
    
    comment: oteir7s
    parent: t1_otegf7b
    author: TexasBryan14

    Excerpt only. The complete copy is held offline and backs quotations on this site. The original publication remains the canonical public source.

How to check this yourself

The excerpts and plain unified diffs above show the text this project held and how it changed. To verify a quotation, compare it against the page itself or against the Internet Archive's copies, which are independent of this project.

Complete captures are held offline rather than mirrored here, so this page shows diffs and excerpts. If a quotation is ever disputed, the full copy can be produced. Ask.