COLDCARD RNG incident the public record, collected and explained
Informational only, and this site never asks for your seed words. details

Informational only. This is an open source collection of what others have published about the incident, together with an explanation of it. It is not financial, security or legal advice, and not a substitute for professional advice about your own situation. It is not affiliated with, endorsed by, or speaking for Coinkite. Material is attributed and quoted as published; where sources disagree their scenarios are kept separate with their assumptions rather than reconciled into one answer. Everything is meant to be checked against the linked evidence rather than taken on trust. Act on your own judgement about a particular situation. Editorial standards and corrections.

Do not disclose recovery material to a website, form, message or support account. This site never asks for it, and contributions containing recovery words or private keys are not accepted.

r/Bitcoin: argument that blaming users shifts liability away from Coinkite

reddit-liability-blame-debate

https://www.reddit.com/r/Bitcoin/comments/1vefwkc/blaming_coldcard_users_for_the_entropy/

Latest reviewed change

source content difference between and

New top-level comment by Weary-Discipline591, a first-hand victim account claiming Coinkite/Coldcard cost them 3 bitcoins and expressing anger at the company.

seen +8 -0 full history below
 edited: false
 body:
 Let’s not forget this is Canada, not US, so customer protection actually means something. It will be very difficult to refund these victims, but I think these shady figures will be held accountable 
+
+comment: p26jgmu
+parent: t3_1vefwkc
+author: Weary-Discipline591
+created_utc: 1786066938

First lines only. The complete diff is in the timeline below.

Organisation
reddit
Evidence role
Community discussion
Published
not established
Source changes
7
Detected differences
7
Unreviewed
0
Copies held
8

Every check is recorded, including checks that found no text change. A detected edit is therefore bounded between two checks. The publisher's exact save time is not observable from this record. Last checked .

  1. source content difference between and Current source content +8 -0

    New top-level comment by Weary-Discipline591, a first-hand victim account claiming Coinkite/Coldcard cost them 3 bitcoins and expressing anger at the company.

    seen · Captured here 37,918 chars
    What changed from the previous capture 8 lines
     edited: false
     body:
     Let’s not forget this is Canada, not US, so customer protection actually means something. It will be very difficult to refund these victims, but I think these shady figures will be held accountable 
    +
    +comment: p26jgmu
    +parent: t3_1vefwkc
    +author: Weary-Discipline591
    +created_utc: 1786066938
    +edited: false
    +body:
    +I hate coinkite/coldcard.  They fucked me out of 3 bitcoins and years of saving and investing.  I fucking hate them.  I hate them as much as I hate the thief, maybe more.  I hate them. 
    
    Extracted text as captured
    post: 1vefwkc
    author: MysteriousKitchen469
    created_utc: 1785769278
    title: Blaming Coldcard users for the entropy vulnerability wrongly shifts liability away from Coinkite
    body:
    In the early 70s, Ford rushed the Pinto to market under intense competition they were facing from cheap foreign imports. The Pinto's design cycle was hurried and unfortunately shipped containing a design defect where the fuel tank was positioned too close behind the rear axle of the car. This design made the car vulnerable to rear end collisions and greatly increased the likelihood of the fuel tank being punctured by the rear axle during a crash, causing the vehicle to catch fire and even explode. 
    
    To make matters worse, Ford allegedly became aware of the defect, but decided (in a later discovered memo) that it would be cheaper to settle wrongful death and injury lawsuits, than to fix the cars. As it turns out, the defect did cause injury and death, and after years of investigations and lawsuits, Ford was eventually found civilly liable (Grimshaw v. Ford) for the engineering defect and was forced to pay punitive damages to its victims. They were also charged criminally for the burn deaths of three teenagers in 1978, but were acquitted on those charges in 1980. They ended up recalling 1.5 million vehicles affected by the defect, that its own engineers claimed would have only cost only $11 to retrofit. It remains one of the most commonly taught case studies in business schools today. 
    
    There is much more to the Ford Pinto case if you are interested, but the main reason I am sharing this story is to illustrate that when a product is used as intended, at a certain point liability must shift from the user to the manufacturer. People who purchased Ford Pintos in the 70s had a reasonable expectation that the fuel tank was designed with safety in mind and wouldn't spontaneous combust from a common fender bender. 
    
    Likewise, Coldcard users had a reasonable expectation that the seed generation tool developed for their device would produce adequate entropy on par with industry standards in Bitcoin/cryptography. They should not be expected to audit every line of code to check for errors, just like Ford Pinto owners should not have been expected to measure the distance between their fuel tank and rear axle before driving the car. 
    
    We have this tendency in Bitcoin to be overzealous when it comes to personal responsibility/accountability. I do not think that's a bad thing per se, but there HAS to be a point where a user can reasonably say they did everything in their power to prevent something like this from happening. At SOME point, the liability for a commercial product to prevent damages must fall on the company and its engineers who designed the product, *even if* open source. 
    
    I think Coldcard users being expected to understand how to read code, much less review it and locate such a defect, is as unreasonable as expecting people to measure the distance between their fuel tank and axle. My condolences go out to all who are affected. This should have NEVER happened to coins in cold storage.     
    
    comment: p1gkyjt
    parent: t3_1vefwkc
    author: [deleted]
    created_utc: 1785769598
    edited: 1785842395
    body:
    [removed]
    
    held before deletion (captured 20260804T134418Z):
    Paddle hammock blanket cinnamon orange amber pinecone almond
    
    This post was anonymized with Redact.dev
    
    comment: p1glli9
    parent: t3_1vefwkc
    author: GodsMoney_Ape
    created_utc: 1785769764
    edited: false
    body:
    This is not a car. This is not the state. This is bitcoin. You trusted coldcards TRNG. Ok, you can. Mostly that works. And this time, you got fucked. 
    
    People could have: Made entropy themselves. They didn't. They trusted, and did not verify. 
    

    Excerpt only. The complete copy is held offline and backs quotations on this site. The original publication remains the canonical public source.

  2. source content difference between and source content +4 -10

    Reddit now marks two comments questioning users' storage and audit practices as deleted.

    seen · Captured here 37,623 chars
    What changed from the previous capture 14 lines
     
     comment: p1gqy0u
     parent: t1_p1glli9
    -author: slowbar1
    +author: [deleted]
     created_utc: 1785771152
     edited: false
     body:
    -Do you have cold storage bitcoin?
    -
    -Did you roll dice for your seed?
    -
    -Did you audit your wallets firmware?
    -
    -How can you engage with the system without at least some level of trust?
    +[deleted]
     
     comment: p1grxt6
     parent: t1_p1glli9
     
     comment: p1gw0vu
     parent: t1_p1gs6vg
    -author: slowbar1
    +author: [deleted]
     created_utc: 1785772453
     edited: false
     body:
    -Do you feel confident this was the only weak point in your security? Do you trust every other aspect of your hardware wallet?
    +[deleted]
     
     comment: p1gwags
     parent: t1_p1guji5
    
    Extracted text as captured
    post: 1vefwkc
    author: MysteriousKitchen469
    created_utc: 1785769278
    title: Blaming Coldcard users for the entropy vulnerability wrongly shifts liability away from Coinkite
    body:
    In the early 70s, Ford rushed the Pinto to market under intense competition they were facing from cheap foreign imports. The Pinto's design cycle was hurried and unfortunately shipped containing a design defect where the fuel tank was positioned too close behind the rear axle of the car. This design made the car vulnerable to rear end collisions and greatly increased the likelihood of the fuel tank being punctured by the rear axle during a crash, causing the vehicle to catch fire and even explode. 
    
    To make matters worse, Ford allegedly became aware of the defect, but decided (in a later discovered memo) that it would be cheaper to settle wrongful death and injury lawsuits, than to fix the cars. As it turns out, the defect did cause injury and death, and after years of investigations and lawsuits, Ford was eventually found civilly liable (Grimshaw v. Ford) for the engineering defect and was forced to pay punitive damages to its victims. They were also charged criminally for the burn deaths of three teenagers in 1978, but were acquitted on those charges in 1980. They ended up recalling 1.5 million vehicles affected by the defect, that its own engineers claimed would have only cost only $11 to retrofit. It remains one of the most commonly taught case studies in business schools today. 
    
    There is much more to the Ford Pinto case if you are interested, but the main reason I am sharing this story is to illustrate that when a product is used as intended, at a certain point liability must shift from the user to the manufacturer. People who purchased Ford Pintos in the 70s had a reasonable expectation that the fuel tank was designed with safety in mind and wouldn't spontaneous combust from a common fender bender. 
    
    Likewise, Coldcard users had a reasonable expectation that the seed generation tool developed for their device would produce adequate entropy on par with industry standards in Bitcoin/cryptography. They should not be expected to audit every line of code to check for errors, just like Ford Pinto owners should not have been expected to measure the distance between their fuel tank and rear axle before driving the car. 
    
    We have this tendency in Bitcoin to be overzealous when it comes to personal responsibility/accountability. I do not think that's a bad thing per se, but there HAS to be a point where a user can reasonably say they did everything in their power to prevent something like this from happening. At SOME point, the liability for a commercial product to prevent damages must fall on the company and its engineers who designed the product, *even if* open source. 
    
    I think Coldcard users being expected to understand how to read code, much less review it and locate such a defect, is as unreasonable as expecting people to measure the distance between their fuel tank and axle. My condolences go out to all who are affected. This should have NEVER happened to coins in cold storage.     
    
    comment: p1gkyjt
    parent: t3_1vefwkc
    author: [deleted]
    created_utc: 1785769598
    edited: 1785842395
    body:
    [removed]
    
    held before deletion (captured 20260804T134418Z):
    Paddle hammock blanket cinnamon orange amber pinecone almond
    
    This post was anonymized with Redact.dev
    
    comment: p1glli9
    parent: t3_1vefwkc
    author: GodsMoney_Ape
    created_utc: 1785769764
    edited: false
    body:
    This is not a car. This is not the state. This is bitcoin. You trusted coldcards TRNG. Ok, you can. Mostly that works. And this time, you got fucked. 
    
    People could have: Made entropy themselves. They didn't. They trusted, and did not verify. 
    

    Excerpt only. The complete copy is held offline and backs quotations on this site. The original publication remains the canonical public source.

  3. source content difference between and source content +8 -0

    Reddit served an additional comment arguing that Canadian consumer protection could hold the people involved accountable despite difficulties refunding victims.

    seen · Captured here 37,907 chars
    What changed from the previous capture 8 lines
     Then you input the same dice rolls in the hardware wallet and compare the hashes.
     
     That's part of what they mean verify.
    +
    +comment: p1uby21
    +parent: t1_p1kiksp
    +author: iloverunning11
    +created_utc: 1785932556
    +edited: false
    +body:
    +Let’s not forget this is Canada, not US, so customer protection actually means something. It will be very difficult to refund these victims, but I think these shady figures will be held accountable 
    
    Extracted text as captured
    post: 1vefwkc
    author: MysteriousKitchen469
    created_utc: 1785769278
    title: Blaming Coldcard users for the entropy vulnerability wrongly shifts liability away from Coinkite
    body:
    In the early 70s, Ford rushed the Pinto to market under intense competition they were facing from cheap foreign imports. The Pinto's design cycle was hurried and unfortunately shipped containing a design defect where the fuel tank was positioned too close behind the rear axle of the car. This design made the car vulnerable to rear end collisions and greatly increased the likelihood of the fuel tank being punctured by the rear axle during a crash, causing the vehicle to catch fire and even explode. 
    
    To make matters worse, Ford allegedly became aware of the defect, but decided (in a later discovered memo) that it would be cheaper to settle wrongful death and injury lawsuits, than to fix the cars. As it turns out, the defect did cause injury and death, and after years of investigations and lawsuits, Ford was eventually found civilly liable (Grimshaw v. Ford) for the engineering defect and was forced to pay punitive damages to its victims. They were also charged criminally for the burn deaths of three teenagers in 1978, but were acquitted on those charges in 1980. They ended up recalling 1.5 million vehicles affected by the defect, that its own engineers claimed would have only cost only $11 to retrofit. It remains one of the most commonly taught case studies in business schools today. 
    
    There is much more to the Ford Pinto case if you are interested, but the main reason I am sharing this story is to illustrate that when a product is used as intended, at a certain point liability must shift from the user to the manufacturer. People who purchased Ford Pintos in the 70s had a reasonable expectation that the fuel tank was designed with safety in mind and wouldn't spontaneous combust from a common fender bender. 
    
    Likewise, Coldcard users had a reasonable expectation that the seed generation tool developed for their device would produce adequate entropy on par with industry standards in Bitcoin/cryptography. They should not be expected to audit every line of code to check for errors, just like Ford Pinto owners should not have been expected to measure the distance between their fuel tank and rear axle before driving the car. 
    
    We have this tendency in Bitcoin to be overzealous when it comes to personal responsibility/accountability. I do not think that's a bad thing per se, but there HAS to be a point where a user can reasonably say they did everything in their power to prevent something like this from happening. At SOME point, the liability for a commercial product to prevent damages must fall on the company and its engineers who designed the product, *even if* open source. 
    
    I think Coldcard users being expected to understand how to read code, much less review it and locate such a defect, is as unreasonable as expecting people to measure the distance between their fuel tank and axle. My condolences go out to all who are affected. This should have NEVER happened to coins in cold storage.     
    
    comment: p1gkyjt
    parent: t3_1vefwkc
    author: [deleted]
    created_utc: 1785769598
    edited: 1785842395
    body:
    [removed]
    
    held before deletion (captured 20260804T134418Z):
    Paddle hammock blanket cinnamon orange amber pinecone almond
    
    This post was anonymized with Redact.dev
    
    comment: p1glli9
    parent: t3_1vefwkc
    author: GodsMoney_Ape
    created_utc: 1785769764
    edited: false
    body:
    This is not a car. This is not the state. This is bitcoin. You trusted coldcards TRNG. Ok, you can. Mostly that works. And this time, you got fucked. 
    
    People could have: Made entropy themselves. They didn't. They trusted, and did not verify. 
    

    Excerpt only. The complete copy is held offline and backs quotations on this site. The original publication remains the canonical public source.

  4. source content difference between and source content +12 -0

    The thread gained a comment describing a proposed verification process that compares a software-emulated dice-roll wallet hash with the hardware wallet result.

    seen · Captured here 37,604 chars
    What changed from the previous capture 12 lines
     edited: false
     body:
     Goodluck finding gross negligence. Id argue its not negligent if it held up for at least 5 years with no problems. Its a mistake that cost them business, but they wont be liable to pay out. 
    +
    +comment: p1t1gd7
    +parent: t1_p1h8xoi
    +author: t_char
    +created_utc: 1785912214
    +edited: false
    +body:
    +You can download code to emulate the dice roll and show you the wallet hash.
    +
    +Then you input the same dice rolls in the hardware wallet and compare the hashes.
    +
    +That's part of what they mean verify.
    
    Extracted text as captured
    post: 1vefwkc
    author: MysteriousKitchen469
    created_utc: 1785769278
    title: Blaming Coldcard users for the entropy vulnerability wrongly shifts liability away from Coinkite
    body:
    In the early 70s, Ford rushed the Pinto to market under intense competition they were facing from cheap foreign imports. The Pinto's design cycle was hurried and unfortunately shipped containing a design defect where the fuel tank was positioned too close behind the rear axle of the car. This design made the car vulnerable to rear end collisions and greatly increased the likelihood of the fuel tank being punctured by the rear axle during a crash, causing the vehicle to catch fire and even explode. 
    
    To make matters worse, Ford allegedly became aware of the defect, but decided (in a later discovered memo) that it would be cheaper to settle wrongful death and injury lawsuits, than to fix the cars. As it turns out, the defect did cause injury and death, and after years of investigations and lawsuits, Ford was eventually found civilly liable (Grimshaw v. Ford) for the engineering defect and was forced to pay punitive damages to its victims. They were also charged criminally for the burn deaths of three teenagers in 1978, but were acquitted on those charges in 1980. They ended up recalling 1.5 million vehicles affected by the defect, that its own engineers claimed would have only cost only $11 to retrofit. It remains one of the most commonly taught case studies in business schools today. 
    
    There is much more to the Ford Pinto case if you are interested, but the main reason I am sharing this story is to illustrate that when a product is used as intended, at a certain point liability must shift from the user to the manufacturer. People who purchased Ford Pintos in the 70s had a reasonable expectation that the fuel tank was designed with safety in mind and wouldn't spontaneous combust from a common fender bender. 
    
    Likewise, Coldcard users had a reasonable expectation that the seed generation tool developed for their device would produce adequate entropy on par with industry standards in Bitcoin/cryptography. They should not be expected to audit every line of code to check for errors, just like Ford Pinto owners should not have been expected to measure the distance between their fuel tank and rear axle before driving the car. 
    
    We have this tendency in Bitcoin to be overzealous when it comes to personal responsibility/accountability. I do not think that's a bad thing per se, but there HAS to be a point where a user can reasonably say they did everything in their power to prevent something like this from happening. At SOME point, the liability for a commercial product to prevent damages must fall on the company and its engineers who designed the product, *even if* open source. 
    
    I think Coldcard users being expected to understand how to read code, much less review it and locate such a defect, is as unreasonable as expecting people to measure the distance between their fuel tank and axle. My condolences go out to all who are affected. This should have NEVER happened to coins in cold storage.     
    
    comment: p1gkyjt
    parent: t3_1vefwkc
    author: [deleted]
    created_utc: 1785769598
    edited: 1785842395
    body:
    [removed]
    
    held before deletion (captured 20260804T134418Z):
    Paddle hammock blanket cinnamon orange amber pinecone almond
    
    This post was anonymized with Redact.dev
    
    comment: p1glli9
    parent: t3_1vefwkc
    author: GodsMoney_Ape
    created_utc: 1785769764
    edited: false
    body:
    This is not a car. This is not the state. This is bitcoin. You trusted coldcards TRNG. Ok, you can. Mostly that works. And this time, you got fucked. 
    
    People could have: Made entropy themselves. They didn't. They trusted, and did not verify. 
    

    Excerpt only. The complete copy is held offline and backs quotations on this site. The original publication remains the canonical public source.

  5. source content difference between and source content +16 -0

    The Reddit thread gained 2 new comments about potential liability.

    seen · Captured here 37,309 chars
    What changed from the previous capture 16 lines
     The Coldcard and every other "wallet" is only a key signer. The wallet is the blockchain. Never let a wallet or any other device to establish strong entropy for your seed phrase. Always use a non BIP 39 passphrase with character distinction. Read the owners manual and educate yourself.
     
     Terrible analogy, the facts were true though.  
    +
    +comment: p1qmcuw
    +parent: t1_p1hfcjv
    +author: CeramicDrip
    +created_utc: 1785881222
    +edited: false
    +body:
    +Exactly. People quite literally got what they payed for which was a hardware device. They didn’t do anything deceptive. It just wasn’t a good product. 
    +
    +comment: p1qmzc0
    +parent: t1_p1klqj2
    +author: CeramicDrip
    +created_utc: 1785881402
    +edited: false
    +body:
    +Goodluck finding gross negligence. Id argue its not negligent if it held up for at least 5 years with no problems. Its a mistake that cost them business, but they wont be liable to pay out. 
    
    Extracted text as captured
    post: 1vefwkc
    author: MysteriousKitchen469
    created_utc: 1785769278
    title: Blaming Coldcard users for the entropy vulnerability wrongly shifts liability away from Coinkite
    body:
    In the early 70s, Ford rushed the Pinto to market under intense competition they were facing from cheap foreign imports. The Pinto's design cycle was hurried and unfortunately shipped containing a design defect where the fuel tank was positioned too close behind the rear axle of the car. This design made the car vulnerable to rear end collisions and greatly increased the likelihood of the fuel tank being punctured by the rear axle during a crash, causing the vehicle to catch fire and even explode. 
    
    To make matters worse, Ford allegedly became aware of the defect, but decided (in a later discovered memo) that it would be cheaper to settle wrongful death and injury lawsuits, than to fix the cars. As it turns out, the defect did cause injury and death, and after years of investigations and lawsuits, Ford was eventually found civilly liable (Grimshaw v. Ford) for the engineering defect and was forced to pay punitive damages to its victims. They were also charged criminally for the burn deaths of three teenagers in 1978, but were acquitted on those charges in 1980. They ended up recalling 1.5 million vehicles affected by the defect, that its own engineers claimed would have only cost only $11 to retrofit. It remains one of the most commonly taught case studies in business schools today. 
    
    There is much more to the Ford Pinto case if you are interested, but the main reason I am sharing this story is to illustrate that when a product is used as intended, at a certain point liability must shift from the user to the manufacturer. People who purchased Ford Pintos in the 70s had a reasonable expectation that the fuel tank was designed with safety in mind and wouldn't spontaneous combust from a common fender bender. 
    
    Likewise, Coldcard users had a reasonable expectation that the seed generation tool developed for their device would produce adequate entropy on par with industry standards in Bitcoin/cryptography. They should not be expected to audit every line of code to check for errors, just like Ford Pinto owners should not have been expected to measure the distance between their fuel tank and rear axle before driving the car. 
    
    We have this tendency in Bitcoin to be overzealous when it comes to personal responsibility/accountability. I do not think that's a bad thing per se, but there HAS to be a point where a user can reasonably say they did everything in their power to prevent something like this from happening. At SOME point, the liability for a commercial product to prevent damages must fall on the company and its engineers who designed the product, *even if* open source. 
    
    I think Coldcard users being expected to understand how to read code, much less review it and locate such a defect, is as unreasonable as expecting people to measure the distance between their fuel tank and axle. My condolences go out to all who are affected. This should have NEVER happened to coins in cold storage.     
    
    comment: p1gkyjt
    parent: t3_1vefwkc
    author: [deleted]
    created_utc: 1785769598
    edited: 1785842395
    body:
    [removed]
    
    held before deletion (captured 20260804T134418Z):
    Paddle hammock blanket cinnamon orange amber pinecone almond
    
    This post was anonymized with Redact.dev
    
    comment: p1glli9
    parent: t3_1vefwkc
    author: GodsMoney_Ape
    created_utc: 1785769764
    edited: false
    body:
    This is not a car. This is not the state. This is bitcoin. You trusted coldcards TRNG. Ok, you can. Mostly that works. And this time, you got fucked. 
    
    People could have: Made entropy themselves. They didn't. They trusted, and did not verify. 
    

    Excerpt only. The complete copy is held offline and backs quotations on this site. The original publication remains the canonical public source.

  6. source content difference between and source content +5 -45

    Several previously anonymized or deleted comments were removed or replaced with Reddit’s “[removed]” placeholder.

    seen · Captured here 36,764 chars
    What changed from the previous capture 50 lines
     created_utc: 1785769598
     edited: 1785842395
     body:
    -Paddle hammock blanket cinnamon orange amber pinecone almond
    -
    -This post was anonymized with Redact.dev
    +[removed]
     
     comment: p1glli9
     parent: t3_1vefwkc
     created_utc: 1785770187
     edited: 1785842387
     body:
    -Otter cinnamon teapot willow thimble raindrop tangerine pumpkin
    -
    -This post was anonymized with Redact.dev
    +[removed]
     
     comment: p1gnz7u
     parent: t1_p1gmyhr
     edited: false
     body:
     You got the facts wrong. The Pinto was vulnerable to other people rear ending you, regardless if you kept a safe distance.
    -
    -comment: p1gp0nh
    -parent: t1_p1gnz7u
    -author: [deleted]
    -created_utc: 1785770655
    -edited: 1785842382
    -body:
    -Biscuit saffron breezy teapot umbrella yarn
    -
    -This post was anonymized with Redact.dev
     
     comment: p1gp7r9
     parent: t1_p1go8a9
     created_utc: 1785770705
     edited: 1785842376
     body:
    -Glove compass vanilla compass velvet otter velvet pebble ginger
    -
    -This post was anonymized with Redact.dev
    +[removed]
     
     comment: p1gpxdx
     parent: t3_1vefwkc
     body:
     No, I don’t. There could be more issues obviously, but in cold storage the potential issues are quite low. Except in this low entropy case like with cold card
     
    -comment: p1h0bq7
    -parent: t1_p1gyt9b
    -author: [deleted]
    -created_utc: 1785773549
    -edited: 1785842370
    -body:
    -Teapot ribbon willow ginger willow cobalt feather
    -
    -This post was anonymized with Redact.dev
    -
     comment: p1h0c7a
     parent: t1_p1gvffv
     author: the_bitcoin_kid
     created_utc: 1785774865
     edited: 1785842364
     body:
    -Quilt maple acorn breezy sparrow saffron waffle willow
    -
    -This post was anonymized with Redact.dev
    +[removed]
     
     comment: p1h5p8i
     parent: t1_p1gy12i
     created_utc: 1785776845
     edited: 1785842359
     body:
    -Raindrop satchel yarn juniper juniper compass coated lavender raindrop
    -
    -This post was anonymized with Redact.dev
    +[removed]
     
     comment: p1heios
     parent: t1_p1h8xoi
     Noone died.
     
     If you bought a keypad lock and installed it on your front door, didn't change the default pinpad code or made it something that could be easily guessed, and someone guessed it and stole the contents of your home is the lock manufacturer at fault? 
    -
    -comment: p1hl2fs
    -parent: t1_p1hfgk8
    -author: [deleted]
    -created_utc: 1785778662
    -edited: 1785842353
    -body:
    -Vanilla peach trumpet trumpet pillow meadow biscuit pinecone pebble
    -
    -This post was anonymized with Redact.dev
     
     comment: p1hl39s
     parent: t1_p1gm9af
    
    Extracted text as captured
    post: 1vefwkc
    author: MysteriousKitchen469
    created_utc: 1785769278
    title: Blaming Coldcard users for the entropy vulnerability wrongly shifts liability away from Coinkite
    body:
    In the early 70s, Ford rushed the Pinto to market under intense competition they were facing from cheap foreign imports. The Pinto's design cycle was hurried and unfortunately shipped containing a design defect where the fuel tank was positioned too close behind the rear axle of the car. This design made the car vulnerable to rear end collisions and greatly increased the likelihood of the fuel tank being punctured by the rear axle during a crash, causing the vehicle to catch fire and even explode. 
    
    To make matters worse, Ford allegedly became aware of the defect, but decided (in a later discovered memo) that it would be cheaper to settle wrongful death and injury lawsuits, than to fix the cars. As it turns out, the defect did cause injury and death, and after years of investigations and lawsuits, Ford was eventually found civilly liable (Grimshaw v. Ford) for the engineering defect and was forced to pay punitive damages to its victims. They were also charged criminally for the burn deaths of three teenagers in 1978, but were acquitted on those charges in 1980. They ended up recalling 1.5 million vehicles affected by the defect, that its own engineers claimed would have only cost only $11 to retrofit. It remains one of the most commonly taught case studies in business schools today. 
    
    There is much more to the Ford Pinto case if you are interested, but the main reason I am sharing this story is to illustrate that when a product is used as intended, at a certain point liability must shift from the user to the manufacturer. People who purchased Ford Pintos in the 70s had a reasonable expectation that the fuel tank was designed with safety in mind and wouldn't spontaneous combust from a common fender bender. 
    
    Likewise, Coldcard users had a reasonable expectation that the seed generation tool developed for their device would produce adequate entropy on par with industry standards in Bitcoin/cryptography. They should not be expected to audit every line of code to check for errors, just like Ford Pinto owners should not have been expected to measure the distance between their fuel tank and rear axle before driving the car. 
    
    We have this tendency in Bitcoin to be overzealous when it comes to personal responsibility/accountability. I do not think that's a bad thing per se, but there HAS to be a point where a user can reasonably say they did everything in their power to prevent something like this from happening. At SOME point, the liability for a commercial product to prevent damages must fall on the company and its engineers who designed the product, *even if* open source. 
    
    I think Coldcard users being expected to understand how to read code, much less review it and locate such a defect, is as unreasonable as expecting people to measure the distance between their fuel tank and axle. My condolences go out to all who are affected. This should have NEVER happened to coins in cold storage.     
    
    comment: p1gkyjt
    parent: t3_1vefwkc
    author: [deleted]
    created_utc: 1785769598
    edited: 1785842395
    body:
    [removed]
    
    held before deletion (captured 20260804T134418Z):
    Paddle hammock blanket cinnamon orange amber pinecone almond
    
    This post was anonymized with Redact.dev
    
    comment: p1glli9
    parent: t3_1vefwkc
    author: GodsMoney_Ape
    created_utc: 1785769764
    edited: false
    body:
    This is not a car. This is not the state. This is bitcoin. You trusted coldcards TRNG. Ok, you can. Mostly that works. And this time, you got fucked. 
    
    People could have: Made entropy themselves. They didn't. They trusted, and did not verify. 
    

    Excerpt only. The complete copy is held offline and backs quotations on this site. The original publication remains the canonical public source.

  7. source content difference between and source content +68 -38

    2 new Reddit comments were posted, including SeaworthinessSad7300,SkidMarkShark.

    seen · Captured here 37,839 chars
    What changed from the previous capture 106 lines
     
     comment: p1gkyjt
     parent: t3_1vefwkc
    -author: Specialist_Trust4945
    +author: [deleted]
     created_utc: 1785769598
    -edited: false
    -body:
    -Except it's a completely wrong example. Let's say you have a Ford Pinto with the fuel tank way too close to the rear axle... do you blame Ford if you rear end another car? The car was defective, absolutely true, but that has nothing to do with you rear ending someone else because you didn't keep a safe distance. Similarly, you should've dice rolled your seed phrase - you didn't do it and now blame Coinkite.
    +edited: 1785842395
    +body:
    +Paddle hammock blanket cinnamon orange amber pinecone almond
    +
    +This post was anonymized with Redact.dev
     
     comment: p1glli9
     parent: t3_1vefwkc
     
     comment: p1gn7rw
     parent: t1_p1gm9af
    -author: Specialist_Trust4945
    +author: [deleted]
     created_utc: 1785770187
    -edited: false
    -body:
    -They trusted and didn't verify. When you do anything in the Bitcoin ecosystem, you're expected to don't trust anybody and to always verify everything. You can absolutely trust someone else, but don't expect sympathy from anyone. If you don't know what you're doing, you're better off keeping your funds in a CEX or buying an ETF - plain and simple.
    +edited: 1785842387
    +body:
    +Otter cinnamon teapot willow thimble raindrop tangerine pumpkin
    +
    +This post was anonymized with Redact.dev
     
     comment: p1gnz7u
     parent: t1_p1gmyhr
     
     comment: p1gp0nh
     parent: t1_p1gnz7u
    -author: Specialist_Trust4945
    +author: [deleted]
     created_utc: 1785770655
    -edited: false
    -body:
    ->but will let you know that computer are way better at generating random numbers than humans.
    -
    -No person with a functioning brain and the slightest knowledge in computer technology will ever tell you this.
    -
    -Also, maybe you shouldn't self custody if you don't know how the whole thing works. Again, it is your prerogative to self custody if you don't have a clue as much as it's your prerogative to ride a F1 car 340kmh even if you don't have a driving license - but what do you think the outcome is going to be?
    +edited: 1785842382
    +body:
    +Biscuit saffron breezy teapot umbrella yarn
    +
    +This post was anonymized with Redact.dev
     
     comment: p1gp7r9
     parent: t1_p1go8a9
    -author: Specialist_Trust4945
    +author: [deleted]
     created_utc: 1785770705
    -edited: 1785771083
    -body:
    -Read my message again, difficulties understanding English?
    +edited: 1785842376
    +body:
    +Glove compass vanilla compass velvet otter velvet pebble ginger
    +
    +This post was anonymized with Redact.dev
     
     comment: p1gpxdx
     parent: t3_1vefwkc
     
     comment: p1h0bq7
     parent: t1_p1gyt9b
    -author: Specialist_Trust4945
    +author: [deleted]
     created_utc: 1785773549
    -edited: false
    -body:
    -Exactly. You are in a trustless environment in case you didn't notice, so you need to trust nobody. That means creating your own entropy.
    +edited: 1785842370
    +body:
    +Teapot ribbon willow ginger willow cobalt feather
    +
    +This post was anonymized with Redact.dev
     
     comment: p1h0c7a
     parent: t1_p1gvffv
     
     comment: p1h5leh
     parent: t1_p1h483i
    -author: Specialist_Trust4945
    +author: [deleted]
     created_utc: 1785774865
    -edited: false
    -body:
    -I already explained it [here](https://www.reddit.com/r/Bitcoin/comments/1ve65yq/comment/p1epu69/?context=3).
    +edited: 1785842364
    +body:
    +Quilt maple acorn breezy sparrow saffron waffle willow
    +
    +This post was anonymized with Redact.dev
     
     comment: p1h5p8i
     parent: t1_p1gy12i
     
     comment: p1hdmne
     parent: t1_p1h7aie
    -author: Specialist_Trust4945
    +author: [deleted]
     created_utc: 1785776845
    -edited: false
    -body:
    -Electrum in a fully airgapped computer, while I have another istance of watch-only Electrum in a computer connected to the Internet which I use to generate the transaction and broadcast it once validated on the airgapped computer.
    +edited: 1785842359
    +body:
    +Raindrop satchel yarn juniper juniper compass coated lavender raindrop
    +
    +This post was anonymized with Redact.dev
     
     comment: p1heios
     parent: t1_p1h8xoi
     
     comment: p1hl2fs
     parent: t1_p1hfgk8
    -author: Specialist_Trust4945
    +author: [deleted]
     created_utc: 1785778662
    -edited: false
    -body:
    -Nah, fuck steel. One in my safe, one at my parent's house safe. The one at my parents' is encrypted with a key I can't forget.
    -
    -I was actually thinking about switching to a SLIP39 seed so I can have 3 parts of my seed in 3 different locations and access to my wallet with 2 out of 3 parts - but I need to look into it a bit better.
    +edited: 1785842353
    +body:
    +Vanilla peach trumpet trumpet pillow meadow biscuit pinecone pebble
    +
    +This post was anonymized with Redact.dev
     
     comment: p1hl39s
     parent: t1_p1gm9af
     edited: false
     body:
     The question is irrelevant. If people want to use BTC, they will. I am ok either way. 
    +
    +comment: p1mhtya
    +parent: t1_p1h87ry
    +author: SeaworthinessSad7300
    +created_utc: 1785840175
    +edited: false
    +body:
    +How do you roll a seed phrase,? The dice have letters?
    +
    +comment: p1mtudm
    +parent: t3_1vefwkc
    +author: SkidMarkShark
    +created_utc: 1785844768
    +edited: false
    +body:
    +The was a little button on the back of the Pinto that allowed the operator to use water instead of gas making the car extremely safe, but the salesman at the dealership failed to tell the purchaser. The purchaser also failed to learn the Pinto could be operated that way because in took a long time to read the owners manual.
    +
    +The Coldcard and every other "wallet" is only a key signer. The wallet is the blockchain. Never let a wallet or any other device to establish strong entropy for your seed phrase. Always use a non BIP 39 passphrase with character distinction. Read the owners manual and educate yourself.
    +
    +Terrible analogy, the facts were true though.  
    
    Extracted text as captured
    post: 1vefwkc
    author: MysteriousKitchen469
    created_utc: 1785769278
    title: Blaming Coldcard users for the entropy vulnerability wrongly shifts liability away from Coinkite
    body:
    In the early 70s, Ford rushed the Pinto to market under intense competition they were facing from cheap foreign imports. The Pinto's design cycle was hurried and unfortunately shipped containing a design defect where the fuel tank was positioned too close behind the rear axle of the car. This design made the car vulnerable to rear end collisions and greatly increased the likelihood of the fuel tank being punctured by the rear axle during a crash, causing the vehicle to catch fire and even explode. 
    
    To make matters worse, Ford allegedly became aware of the defect, but decided (in a later discovered memo) that it would be cheaper to settle wrongful death and injury lawsuits, than to fix the cars. As it turns out, the defect did cause injury and death, and after years of investigations and lawsuits, Ford was eventually found civilly liable (Grimshaw v. Ford) for the engineering defect and was forced to pay punitive damages to its victims. They were also charged criminally for the burn deaths of three teenagers in 1978, but were acquitted on those charges in 1980. They ended up recalling 1.5 million vehicles affected by the defect, that its own engineers claimed would have only cost only $11 to retrofit. It remains one of the most commonly taught case studies in business schools today. 
    
    There is much more to the Ford Pinto case if you are interested, but the main reason I am sharing this story is to illustrate that when a product is used as intended, at a certain point liability must shift from the user to the manufacturer. People who purchased Ford Pintos in the 70s had a reasonable expectation that the fuel tank was designed with safety in mind and wouldn't spontaneous combust from a common fender bender. 
    
    Likewise, Coldcard users had a reasonable expectation that the seed generation tool developed for their device would produce adequate entropy on par with industry standards in Bitcoin/cryptography. They should not be expected to audit every line of code to check for errors, just like Ford Pinto owners should not have been expected to measure the distance between their fuel tank and rear axle before driving the car. 
    
    We have this tendency in Bitcoin to be overzealous when it comes to personal responsibility/accountability. I do not think that's a bad thing per se, but there HAS to be a point where a user can reasonably say they did everything in their power to prevent something like this from happening. At SOME point, the liability for a commercial product to prevent damages must fall on the company and its engineers who designed the product, *even if* open source. 
    
    I think Coldcard users being expected to understand how to read code, much less review it and locate such a defect, is as unreasonable as expecting people to measure the distance between their fuel tank and axle. My condolences go out to all who are affected. This should have NEVER happened to coins in cold storage.     
    
    comment: p1gkyjt
    parent: t3_1vefwkc
    author: [deleted]
    created_utc: 1785769598
    edited: 1785842395
    body:
    Paddle hammock blanket cinnamon orange amber pinecone almond
    
    This post was anonymized with Redact.dev
    
    comment: p1glli9
    parent: t3_1vefwkc
    author: GodsMoney_Ape
    created_utc: 1785769764
    edited: false
    body:
    This is not a car. This is not the state. This is bitcoin. You trusted coldcards TRNG. Ok, you can. Mostly that works. And this time, you got fucked. 
    
    People could have: Made entropy themselves. They didn't. They trusted, and did not verify. 
    
    comment: p1gm9af
    parent: t1_p1gkyjt
    author: pako-bitbox

    Excerpt only. The complete copy is held offline and backs quotations on this site. The original publication remains the canonical public source.

  8. Earliest copy held
    seen · Captured here 38,289 chars
    Extracted text as captured
    post: 1vefwkc
    author: MysteriousKitchen469
    created_utc: 1785769278
    title: Blaming Coldcard users for the entropy vulnerability wrongly shifts liability away from Coinkite
    body:
    In the early 70s, Ford rushed the Pinto to market under intense competition they were facing from cheap foreign imports. The Pinto's design cycle was hurried and unfortunately shipped containing a design defect where the fuel tank was positioned too close behind the rear axle of the car. This design made the car vulnerable to rear end collisions and greatly increased the likelihood of the fuel tank being punctured by the rear axle during a crash, causing the vehicle to catch fire and even explode. 
    
    To make matters worse, Ford allegedly became aware of the defect, but decided (in a later discovered memo) that it would be cheaper to settle wrongful death and injury lawsuits, than to fix the cars. As it turns out, the defect did cause injury and death, and after years of investigations and lawsuits, Ford was eventually found civilly liable (Grimshaw v. Ford) for the engineering defect and was forced to pay punitive damages to its victims. They were also charged criminally for the burn deaths of three teenagers in 1978, but were acquitted on those charges in 1980. They ended up recalling 1.5 million vehicles affected by the defect, that its own engineers claimed would have only cost only $11 to retrofit. It remains one of the most commonly taught case studies in business schools today. 
    
    There is much more to the Ford Pinto case if you are interested, but the main reason I am sharing this story is to illustrate that when a product is used as intended, at a certain point liability must shift from the user to the manufacturer. People who purchased Ford Pintos in the 70s had a reasonable expectation that the fuel tank was designed with safety in mind and wouldn't spontaneous combust from a common fender bender. 
    
    Likewise, Coldcard users had a reasonable expectation that the seed generation tool developed for their device would produce adequate entropy on par with industry standards in Bitcoin/cryptography. They should not be expected to audit every line of code to check for errors, just like Ford Pinto owners should not have been expected to measure the distance between their fuel tank and rear axle before driving the car. 
    
    We have this tendency in Bitcoin to be overzealous when it comes to personal responsibility/accountability. I do not think that's a bad thing per se, but there HAS to be a point where a user can reasonably say they did everything in their power to prevent something like this from happening. At SOME point, the liability for a commercial product to prevent damages must fall on the company and its engineers who designed the product, *even if* open source. 
    
    I think Coldcard users being expected to understand how to read code, much less review it and locate such a defect, is as unreasonable as expecting people to measure the distance between their fuel tank and axle. My condolences go out to all who are affected. This should have NEVER happened to coins in cold storage.     
    
    comment: p1gkyjt
    parent: t3_1vefwkc
    author: Specialist_Trust4945
    created_utc: 1785769598
    edited: false
    body:
    Except it's a completely wrong example. Let's say you have a Ford Pinto with the fuel tank way too close to the rear axle... do you blame Ford if you rear end another car? The car was defective, absolutely true, but that has nothing to do with you rear ending someone else because you didn't keep a safe distance. Similarly, you should've dice rolled your seed phrase - you didn't do it and now blame Coinkite.
    
    comment: p1glli9
    parent: t3_1vefwkc
    author: GodsMoney_Ape
    created_utc: 1785769764
    edited: false
    body:
    This is not a car. This is not the state. This is bitcoin. You trusted coldcards TRNG. Ok, you can. Mostly that works. And this time, you got fucked. 
    
    People could have: Made entropy themselves. They didn't. They trusted, and did not verify. 
    
    comment: p1gm9af
    parent: t1_p1gkyjt
    author: pako-bitbox
    created_utc: 1785769936
    edited: false

    Excerpt only. The complete copy is held offline and backs quotations on this site. The original publication remains the canonical public source.

How to check this yourself

The excerpts and plain unified diffs above show the text this project held and how it changed. To verify a quotation, compare it against the page itself or against the Internet Archive's copies, which are independent of this project.

Complete captures are held offline rather than mirrored here, so this page shows diffs and excerpts. If a quotation is ever disputed, the full copy can be produced. Ask.