COLDCARD RNG incident the public record, collected and explained
Informational only, and this site never asks for your seed words. details

Informational only. This is an open source collection of what others have published about the incident, together with an explanation of it. It is not financial, security or legal advice, and not a substitute for professional advice about your own situation. It is not affiliated with, endorsed by, or speaking for Coinkite. Material is attributed and quoted as published; where sources disagree their scenarios are kept separate with their assumptions rather than reconciled into one answer. Everything is meant to be checked against the linked evidence rather than taken on trust. Act on your own judgement about a particular situation. Editorial standards and corrections.

Do not disclose recovery material to a website, form, message or support account. This site never asks for it, and contributions containing recovery words or private keys are not accepted.

r/Bitcoin: risks of multisig setups that include COLDCARD seeds

reddit-multisig-coldcard-seeds-risk

https://www.reddit.com/r/Bitcoin/comments/1ved6v3/risks_of_multisig_with_coldcard_seeds/

Organisation
reddit
Evidence role
Community discussion
Published
not established
Source changes
0
Detected differences
0
Unreviewed
0
Copies held
1

Every check is recorded, including checks that found no text change. A detected edit is therefore bounded between two checks. The publisher's exact save time is not observable from this record. Last checked .

  1. Earliest copy held Current
    seen · Captured here 1,438 chars
    Extracted text as captured
    post: 1ved6v3
    author: m0r0_on
    created_utc: 1785763071
    title: Risks of MultiSig with ColdCard Seeds
    body:
    Is there any threat that one should be aware of?  
    I heard a guy saying it was ok, but becomes tricky when spending with those seeds as signers because of the pub key exposure - and then the transaction can be front-run by someone who pays higher fees.  
    Are there other scenarios?
    
    What are the best options to migrate away in those cases?
    
    comment: p1fy9pa
    parent: t3_1ved6v3
    author: DarrelXero
    created_utc: 1785763350
    edited: false
    body:
    If the multisig qurom is meetable with ColdCards then funds are vulnerable in-flight with RBF sniping. Meaning if 2 of 3 of the keys in a multisig wallet were generated by affected ColdCard devices then they are vulnerable.
    
    If a minority of keys are ColdCard generated, funds are not vulnerable to this attack. If a ColdCard generated key is part of your multisig it should be replaced but it is not an emergency.
    
    comment: p1i87sw
    parent: t3_1ved6v3
    author: Few_Response_7028
    created_utc: 1785784570
    edited: false
    body:
    If you have 2/3 coldcards. You need to migrate immediately.  
    If you have not spent from that multisig, you are at least don't have a target on your back, but you will be drained eventually.
    
    Eventually you are likely to be brute forced, but you will be a later date target than the single sig folks.
    
    Use mara slipstream when you migrate and you can't be RNG attacked.
    
How to check this yourself

The excerpts and plain unified diffs above show the text this project held and how it changed. To verify a quotation, compare it against the page itself or against the Internet Archive's copies, which are independent of this project.

Complete captures are held offline rather than mirrored here, so this page shows diffs and excerpts. If a quotation is ever disputed, the full copy can be produced. Ask.