COLDCARD RNG incident the public record, collected and explained
Informational only, and this site never asks for your seed words. details

Informational only. This is an open source collection of what others have published about the incident, together with an explanation of it. It is not financial, security or legal advice, and not a substitute for professional advice about your own situation. It is not affiliated with, endorsed by, or speaking for Coinkite. Material is attributed and quoted as published; where sources disagree their scenarios are kept separate with their assumptions rather than reconciled into one answer. Everything is meant to be checked against the linked evidence rather than taken on trust. Act on your own judgement about a particular situation. Editorial standards and corrections.

Do not disclose recovery material to a website, form, message or support account. This site never asks for it, and contributions containing recovery words or private keys are not accepted.

r/Bitcoin: call for hardware-wallet vendor accountability and certification after the incident

reddit-nvk-scammer-regulation-call

https://www.reddit.com/r/Bitcoin/comments/1vji2nz/rodolfo_novak_coldcard_scammer_i_will_take_it/

Latest reviewed change

source content difference between and

A participant comment from cleankiwii was deleted, leaving only a [deleted] author marker and body.

seen +2 -2 full history below
 
 comment: p2lnwig
 parent: t3_1vji2nz
-author: cleankiwii
+author: [deleted]
 created_utc: 1786257883
 edited: false
 body:

First lines only. The complete diff is in the timeline below.

Organisation
reddit
Evidence role
Community discussion
Published
not established
Source changes
1
Detected differences
1
Unreviewed
0
Copies held
2

Every check is recorded, including checks that found no text change. A detected edit is therefore bounded between two checks. The publisher's exact save time is not observable from this record. Last checked .

  1. source content difference between and Current source content +2 -2

    A participant comment from cleankiwii was deleted, leaving only a [deleted] author marker and body.

    seen · Captured here 11,100 chars
    What changed from the previous capture 4 lines
     
     comment: p2lnwig
     parent: t3_1vji2nz
    -author: cleankiwii
    +author: [deleted]
     created_utc: 1786257883
     edited: false
     body:
    -what’s going on, are they selling closed source HW with a backdoor for their exit strategy?
    +[deleted]
     
     comment: p2lo14c
     parent: t3_1vji2nz
    
    Extracted text as captured
    post: 1vji2nz
    author: Fearless-Second-7230
    created_utc: 1786255861
    title: Rodolfo Novak, Coldcard scammer: "I will take it".
    body:
    "If quacks like a duck, then it probably is a duck."
    
    If Hardware Wallet vendors doing gross negligence do not get into the category of criminal fraud when they do not have certifications and code quality security and security in depth design, then anyone will just jump into space "selling lots of hardware" and doing exit by simply blaming "the hacker". 
    
    If an idiot scumbag wallet vendor gets angry when you question his shit, now you know what could be the end result.
    
    \_\_\_\_\_\_
    
    "The threat of a malicious manufacturer might seem small, but when it comes to companies that might go out of business in the next decade, the possibility of pulling an "exit scam" should not be discounted. The fact that this attack is virtually impossible to prove as a victim could provide additional motivation for malicious actors." (10 Nov 2022)
    
    https://blog.bitbox.swiss/en/how-almost-all-hardware-wallets-can-steal-your-seed/
    
    https://gitlab.com/walletscrutiny/walletScrutinyCom/-/work_items/340
    
    For the record. Bitbox, Coldcard, Trezor, Ledger, Bitkey, Jade. Central point applies to all the HWs, the fucking article is just to show the warnings there were out there, fucking do not trust neither on Bitbox or whatever shit even if they tell you they are ultra secure, etc, the focus point is make more aggressive accountability on Hardware Wallet vendors in general.
    
    Hardware Wallet manufacturing for commercial sale should be treated as a regulated, not something anyone (any idiot with an idea) can ship without independent security certification. 
    
    Vendors handling other people's life savings should face defense in depth certification requirements, with real liability, including criminal liability for gross negligence when they don't meet them. 
    _____
    Related articles regarding self-custody that need to be reexplored by Bitcoin community (tech oriented), Bitcoin needs to level up on self custody.
    
    https://www.turnkeylinux.org/blog/secure-bitcoin-transactions
    
    https://nakamotoinstitute.org/library/trusted-third-parties/
    
    https://nakamotoinstitute.org/mempool/bitcoins-rugged-individualism/
    
    
    comment: p2ll00s
    parent: t3_1vji2nz
    author: shadowmage666
    created_utc: 1786256458
    edited: false
    body:

    Excerpt only. The complete copy is held offline and backs quotations on this site. The original publication remains the canonical public source.

  2. Earliest copy held
    seen · Captured here 11,183 chars
    Extracted text as captured
    post: 1vji2nz
    author: Fearless-Second-7230
    created_utc: 1786255861
    title: Rodolfo Novak, Coldcard scammer: "I will take it".
    body:
    "If quacks like a duck, then it probably is a duck."
    
    If Hardware Wallet vendors doing gross negligence do not get into the category of criminal fraud when they do not have certifications and code quality security and security in depth design, then anyone will just jump into space "selling lots of hardware" and doing exit by simply blaming "the hacker". 
    
    If an idiot scumbag wallet vendor gets angry when you question his shit, now you know what could be the end result.
    
    \_\_\_\_\_\_
    
    "The threat of a malicious manufacturer might seem small, but when it comes to companies that might go out of business in the next decade, the possibility of pulling an "exit scam" should not be discounted. The fact that this attack is virtually impossible to prove as a victim could provide additional motivation for malicious actors." (10 Nov 2022)
    
    https://blog.bitbox.swiss/en/how-almost-all-hardware-wallets-can-steal-your-seed/
    
    https://gitlab.com/walletscrutiny/walletScrutinyCom/-/work_items/340
    
    For the record. Bitbox, Coldcard, Trezor, Ledger, Bitkey, Jade. Central point applies to all the HWs, the fucking article is just to show the warnings there were out there, fucking do not trust neither on Bitbox or whatever shit even if they tell you they are ultra secure, etc, the focus point is make more aggressive accountability on Hardware Wallet vendors in general.
    
    Hardware Wallet manufacturing for commercial sale should be treated as a regulated, not something anyone (any idiot with an idea) can ship without independent security certification. 
    
    Vendors handling other people's life savings should face defense in depth certification requirements, with real liability, including criminal liability for gross negligence when they don't meet them. 
    _____
    Related articles regarding self-custody that need to be reexplored by Bitcoin community (tech oriented), Bitcoin needs to level up on self custody.
    
    https://www.turnkeylinux.org/blog/secure-bitcoin-transactions
    
    https://nakamotoinstitute.org/library/trusted-third-parties/
    
    https://nakamotoinstitute.org/mempool/bitcoins-rugged-individualism/
    
    
    comment: p2ll00s
    parent: t3_1vji2nz
    author: shadowmage666
    created_utc: 1786256458
    edited: false
    body:

    Excerpt only. The complete copy is held offline and backs quotations on this site. The original publication remains the canonical public source.

How to check this yourself

The excerpts and plain unified diffs above show the text this project held and how it changed. To verify a quotation, compare it against the page itself or against the Internet Archive's copies, which are independent of this project.

Complete captures are held offline rather than mirrored here, so this page shows diffs and excerpts. If a quotation is ever disputed, the full copy can be produced. Ask.