COLDCARD RNG incident the public record, collected and explained
Informational only, and this site never asks for your seed words. details

Informational only. This is an open source collection of what others have published about the incident, together with an explanation of it. It is not financial, security or legal advice, and not a substitute for professional advice about your own situation. It is not affiliated with, endorsed by, or speaking for Coinkite. Material is attributed and quoted as published; where sources disagree their scenarios are kept separate with their assumptions rather than reconciled into one answer. Everything is meant to be checked against the linked evidence rather than taken on trust. Act on your own judgement about a particular situation. Editorial standards and corrections.

Do not disclose recovery material to a website, form, message or support account. This site never asks for it, and contributions containing recovery words or private keys are not accepted.

r/Bitcoin: podcast transcript cited in criticism of nvk's AI-audit response

reddit-nvk-ai-audit-podcast

https://www.reddit.com/r/Bitcoin/comments/1vgj17y/coldcard_ceo_rodolfo_novak_confessing_2_moths_ago/

Latest reviewed change

source content difference between and

The post gained a separator line and a link to a WalletScrutiny GitLab work item.

seen +3 -0 full history below
 
 Well, no one will say hardware wallets are bad, but it is time to make accountable hardware wallet vendors selling you unaudited shit and with no security in dept design. What is security in dept design or foolproof design? Well do not tell that rolling dice is optional but recommended, fucking do not allow the seed generation step to be completed without it. Specially if you ar going to say that AI reported bugs are crap and you have no external verified audit history of source code.
 
+_____
+https://gitlab.com/walletscrutiny/walletScrutinyCom/-/work_items/340
+
 comment: p1xm2dz
 parent: t3_1vgj17y

First lines only. The complete diff is in the timeline below.

Organisation
reddit
Evidence role
Community discussion
Published
not established
Source changes
2
Detected differences
2
Unreviewed
0
Copies held
3

Every check is recorded, including checks that found no text change. A detected edit is therefore bounded between two checks. The publisher's exact save time is not observable from this record. Last checked .

  1. source content difference between and Current source content +3 -0

    The post gained a separator line and a link to a WalletScrutiny GitLab work item.

    seen · Captured here 13,154 chars
    What changed from the previous capture 3 lines
     
     Well, no one will say hardware wallets are bad, but it is time to make accountable hardware wallet vendors selling you unaudited shit and with no security in dept design. What is security in dept design or foolproof design? Well do not tell that rolling dice is optional but recommended, fucking do not allow the seed generation step to be completed without it. Specially if you ar going to say that AI reported bugs are crap and you have no external verified audit history of source code.
     
    +_____
    +https://gitlab.com/walletscrutiny/walletScrutinyCom/-/work_items/340
    +
     comment: p1xm2dz
     parent: t3_1vgj17y
     author: Few_Response_7028
    
    Extracted text as captured
    post: 1vgj17y
    author: Fearless-Second-7230
    created_utc: 1785961723
    title: Coldcard CEO Rodolfo Novak confessing 2 moths ago in a podcast regarding AI audit bug reports: "Everything was like high like they said everything is like 'high high so it's like 'super dangerous"
    body:
    First this part, he recognizing is lame for bitcoin products to blame AI...
    
    Interviewer: "...The BIsq announcement thread mentioned that it is likely an AI powered attack. So maybe people using you know is it some North Korean group using Claude or Cursor or Mythos or something."
    
    Rodolfo Novak 'nvk'(18:53): "Yeah, but that's like you know that's that's like saying that they just encounter an adversary that's a little bit better than they are. \*I mean like you know the reality is people are trying to break stuff all the time and if you have like Bitcoin to be taken you know it just means that they had you know bad security.\*"
    
    \_\_\_\_\_\_\_
    
    There you have it. The guy in his own words impliying Coldcard has fucking bad security.
    
    But the interesting part is this one, where he arrogantly is downplaying the bug reports an AI audit tool is throwing:
    
    Interviewer (19:08): "Yeah, but I guess the point would be is there has the game changed, right? Is there a you know now this is a big new threat that people need to start thinking about which is basically AI assisted hacking?\[ ...\] like well there's AI assisted hacking and now we need AI assisted defense and you need to find you need you need to defend it uh and um that way"
    
    Rodolfo Novak 'nvk'(20:03): "so it's already happening we we got a preview a friend got a preview of the codec cyber or whatever they call it the KYC NDA version of their uh uh security assessment tools y uh you know the first thing he did was run after run it on the code card repo \[laughter\] And uh you know honestly like we we saw the the bug reports they're all like you know extremely mediocre stuff. 
    
    Uh everything was like high right like they they said everything is like high high so it's like super dangerous and everything was like completely false reporting. The tools are still abhorent. The quality of this this this hacking uh AI hacking is still ultra ultra crap."
    
    \[ END OF TRANSCRIPT PART \]
    
    \_\_\_\_\_\_\_
    
    Well, here is where things start to become a mess: 
    
    He is confessing they have extremely dangerous findings through AI but he just arrogantly is downplaying them. 
    
    But here in Jul 30 2026: https://blog.coinkite.com/entropy-technical-backgrounder/
    
     
    
    They mention:
    
    "The COLDCARD source code has always been open and publicly available, so we have to assume that someone used AI to review previous versions of our firmware and stumbled upon this issue. A few weeks ago, we used one of the best available AI models to review our code for security issues, and it did not find this bug or anything serious.
    
    Both attackers and defenders have the same AI tools, but today it did not help us, and only helped the bad guys." (No you idiot, you are confessing an AI showing you dangerous bugs and just arrogantly maybe not even  analizing them carefully).

    Excerpt only. The complete copy is held offline and backs quotations on this site. The original publication remains the canonical public source.

  2. source content difference between and source content +27 -3

    bobivy1234 edited their comment to add at the time to the claim about LLM audit tools flagging benign issues, and three new comments appeared, including first-hand reactions calling the developer criminally negligent and bobivy1234 replying that the podcast conversation proves little.

    seen · Captured here 13,078 chars
    What changed from the previous capture 30 lines
     parent: t3_1vgj17y
     author: bobivy1234
     created_utc: 1785965911
    -edited: false
    -body:
    -Cmon man we can hate on them all we want but in the context of the conversation, he said some friend's random assessment tool scanned the ColdCard repo and marked a bunch of benign stuff as 'high risk' which they validated were mediocre small issues as a broader discussion of LLMs still not being strong for these use cases.
    +edited: 1786016462
    +body:
    +Cmon man we can hate on them all we want but in the context of the conversation, he said some friend's random assessment tool scanned the ColdCard repo and marked a bunch of benign stuff as 'high risk' which they validated were mediocre small issues as a broader discussion of LLMs still not being strong for these use cases at the time.
     
     Yes missing the TRNG enablement in the codebase is a massive deal but also not worth putting out this conversation as some admission of intentional fraud of avoiding fixing discovered issues.
     
     
     sadly the sociopath devs rug pull in well ofuscated ways, by using shitcoin projects, icos, etc (x is enough evidence of his behavior and now he is deleting posts because he knows lawsuit is coming)....this guy knew the backdoor would be well covered by his "roll dice" narrative....those are the cover up to say "hey, look, but there were users not affected", but conveniently having a "bug" in its most critical component ..yeah, well implemented backdoor...
     
    +
    +comment: p21eya8
    +parent: t3_1vgj17y
    +author: MasaiRes
    +created_utc: 1786015488
    +edited: false
    +body:
    +The fact that people entrusted millions to this chancer is staggering.
    +
    +comment: p21hswg
    +parent: t1_p1xyd24
    +author: bobivy1234
    +created_utc: 1786016544
    +edited: false
    +body:
    +I don't disagree in general but we have no clue what that report said or what they fixed and didn't fix.  It's just some random conversation on a podcast and it isn't an out-of-left-field sentiment that LLMs and some of these new tools aren't quite hitting the mark yet.  The release of Fable and other pioneer models were a monumental leap but that has all been more recent.
    +
    +comment: p21v811
    +parent: t3_1vgj17y
    +author: ItsAlwaysThemBooBoo
    +created_utc: 1786020918
    +edited: false
    +body:
    +at worst hes a criminal who is behind this, and at best, hes a criminally negligent cunt who allowed a critical security flaw to be there for 5 years in a row without correcting.
    
    Extracted text as captured
    post: 1vgj17y
    author: Fearless-Second-7230
    created_utc: 1785961723
    title: Coldcard CEO Rodolfo Novak confessing 2 moths ago in a podcast regarding AI audit bug reports: "Everything was like high like they said everything is like 'high high so it's like 'super dangerous"
    body:
    First this part, he recognizing is lame for bitcoin products to blame AI...
    
    Interviewer: "...The BIsq announcement thread mentioned that it is likely an AI powered attack. So maybe people using you know is it some North Korean group using Claude or Cursor or Mythos or something."
    
    Rodolfo Novak 'nvk'(18:53): "Yeah, but that's like you know that's that's like saying that they just encounter an adversary that's a little bit better than they are. \*I mean like you know the reality is people are trying to break stuff all the time and if you have like Bitcoin to be taken you know it just means that they had you know bad security.\*"
    
    \_\_\_\_\_\_\_
    
    There you have it. The guy in his own words impliying Coldcard has fucking bad security.
    
    But the interesting part is this one, where he arrogantly is downplaying the bug reports an AI audit tool is throwing:
    
    Interviewer (19:08): "Yeah, but I guess the point would be is there has the game changed, right? Is there a you know now this is a big new threat that people need to start thinking about which is basically AI assisted hacking?\[ ...\] like well there's AI assisted hacking and now we need AI assisted defense and you need to find you need you need to defend it uh and um that way"
    
    Rodolfo Novak 'nvk'(20:03): "so it's already happening we we got a preview a friend got a preview of the codec cyber or whatever they call it the KYC NDA version of their uh uh security assessment tools y uh you know the first thing he did was run after run it on the code card repo \[laughter\] And uh you know honestly like we we saw the the bug reports they're all like you know extremely mediocre stuff. 
    
    Uh everything was like high right like they they said everything is like high high so it's like super dangerous and everything was like completely false reporting. The tools are still abhorent. The quality of this this this hacking uh AI hacking is still ultra ultra crap."
    
    \[ END OF TRANSCRIPT PART \]
    
    \_\_\_\_\_\_\_
    
    Well, here is where things start to become a mess: 
    
    He is confessing they have extremely dangerous findings through AI but he just arrogantly is downplaying them. 
    
    But here in Jul 30 2026: https://blog.coinkite.com/entropy-technical-backgrounder/
    
     
    
    They mention:
    
    "The COLDCARD source code has always been open and publicly available, so we have to assume that someone used AI to review previous versions of our firmware and stumbled upon this issue. A few weeks ago, we used one of the best available AI models to review our code for security issues, and it did not find this bug or anything serious.
    
    Both attackers and defenders have the same AI tools, but today it did not help us, and only helped the bad guys." (No you idiot, you are confessing an AI showing you dangerous bugs and just arrogantly maybe not even  analizing them carefully).

    Excerpt only. The complete copy is held offline and backs quotations on this site. The original publication remains the canonical public source.

  3. Earliest copy held
    seen · Captured here 12,128 chars
    Extracted text as captured
    post: 1vgj17y
    author: Fearless-Second-7230
    created_utc: 1785961723
    title: Coldcard CEO Rodolfo Novak confessing 2 moths ago in a podcast regarding AI audit bug reports: "Everything was like high like they said everything is like 'high high so it's like 'super dangerous"
    body:
    First this part, he recognizing is lame for bitcoin products to blame AI...
    
    Interviewer: "...The BIsq announcement thread mentioned that it is likely an AI powered attack. So maybe people using you know is it some North Korean group using Claude or Cursor or Mythos or something."
    
    Rodolfo Novak 'nvk'(18:53): "Yeah, but that's like you know that's that's like saying that they just encounter an adversary that's a little bit better than they are. \*I mean like you know the reality is people are trying to break stuff all the time and if you have like Bitcoin to be taken you know it just means that they had you know bad security.\*"
    
    \_\_\_\_\_\_\_
    
    There you have it. The guy in his own words impliying Coldcard has fucking bad security.
    
    But the interesting part is this one, where he arrogantly is downplaying the bug reports an AI audit tool is throwing:
    
    Interviewer (19:08): "Yeah, but I guess the point would be is there has the game changed, right? Is there a you know now this is a big new threat that people need to start thinking about which is basically AI assisted hacking?\[ ...\] like well there's AI assisted hacking and now we need AI assisted defense and you need to find you need you need to defend it uh and um that way"
    
    Rodolfo Novak 'nvk'(20:03): "so it's already happening we we got a preview a friend got a preview of the codec cyber or whatever they call it the KYC NDA version of their uh uh security assessment tools y uh you know the first thing he did was run after run it on the code card repo \[laughter\] And uh you know honestly like we we saw the the bug reports they're all like you know extremely mediocre stuff. 
    
    Uh everything was like high right like they they said everything is like high high so it's like super dangerous and everything was like completely false reporting. The tools are still abhorent. The quality of this this this hacking uh AI hacking is still ultra ultra crap."
    
    \[ END OF TRANSCRIPT PART \]
    
    \_\_\_\_\_\_\_
    
    Well, here is where things start to become a mess: 
    
    He is confessing they have extremely dangerous findings through AI but he just arrogantly is downplaying them. 
    
    But here in Jul 30 2026: https://blog.coinkite.com/entropy-technical-backgrounder/
    
     
    
    They mention:
    
    "The COLDCARD source code has always been open and publicly available, so we have to assume that someone used AI to review previous versions of our firmware and stumbled upon this issue. A few weeks ago, we used one of the best available AI models to review our code for security issues, and it did not find this bug or anything serious.
    
    Both attackers and defenders have the same AI tools, but today it did not help us, and only helped the bad guys." (No you idiot, you are confessing an AI showing you dangerous bugs and just arrogantly maybe not even  analizing them carefully).

    Excerpt only. The complete copy is held offline and backs quotations on this site. The original publication remains the canonical public source.

How to check this yourself

The excerpts and plain unified diffs above show the text this project held and how it changed. To verify a quotation, compare it against the page itself or against the Internet Archive's copies, which are independent of this project.

Complete captures are held offline rather than mirrored here, so this page shows diffs and excerpts. If a quotation is ever disputed, the full copy can be produced. Ask.