COLDCARD RNG incident the public record, collected and explained
Informational only, and this site never asks for your seed words. details

Informational only. This is an open source collection of what others have published about the incident, together with an explanation of it. It is not financial, security or legal advice, and not a substitute for professional advice about your own situation. It is not affiliated with, endorsed by, or speaking for Coinkite. Material is attributed and quoted as published; where sources disagree their scenarios are kept separate with their assumptions rather than reconciled into one answer. Everything is meant to be checked against the linked evidence rather than taken on trust. Act on your own judgement about a particular situation. Editorial standards and corrections.

Do not disclose recovery material to a website, form, message or support account. This site never asks for it, and contributions containing recovery words or private keys are not accepted.

r/Bitcoin: birthday-bound estimate of seed collisions from reduced entropy

reddit-seed-collision-odds

https://www.reddit.com/r/Bitcoin/comments/1vdr94r/93000_coldcardgenerated_seeds_is_all_it_takes_for/

Latest reviewed change

source content difference between and

The Reddit thread gained a new participant comment suggesting earlier 2021-2022 thefts could have been organic seed collisions.

seen +8 -0 full history below
 Yo fuck a coinkite. 
 
 So glad ColdCard wasn't my first device. 
+
+comment: p2cj9wr
+parent: t3_1vdr94r
+author: satoshisfeverdream
+created_utc: 1786138738

First lines only. The complete diff is in the timeline below.

Organisation
reddit
Evidence role
Community discussion
Published
not established
Source changes
2
Detected differences
2
Unreviewed
0
Copies held
3

Every check is recorded, including checks that found no text change. A detected edit is therefore bounded between two checks. The publisher's exact save time is not observable from this record. Last checked .

  1. source content difference between and Current source content +8 -0

    The Reddit thread gained a new participant comment suggesting earlier 2021-2022 thefts could have been organic seed collisions.

    seen · Captured here 10,093 chars
    What changed from the previous capture 8 lines
     Yo fuck a coinkite. 
     
     So glad ColdCard wasn't my first device. 
    +
    +comment: p2cj9wr
    +parent: t3_1vdr94r
    +author: satoshisfeverdream
    +created_utc: 1786138738
    +edited: false
    +body:
    +Supposedly there were some thefts reported back in 2021-2022 timeframe that could have simply been organic collisions.  
    
    Extracted text as captured
    post: 1vdr94r
    author: IsolatedNetworkNode
    created_utc: 1785699240
    title: 93,000 Coldcard-Generated Seeds Is All It Takes for a 50% Chance Two People End Up With the Same Wallet
    body:
    You probably heard the birthday paradox, having 23 people in a room creates a 50% chance that at least two of them share the same birthday.
    
    Applying it to the vulnerable search space in the ColdCard bug (Following reports that search space was reduced to 2\^32, approx 4 billion)
    
    50% collision odds ≈ √(2 × 4.3 billion) ≈ 93,000 ColdCard Wallet Generated Seeds.
    
    If this bug was somehow never discovered and Coldcard sold around 93k units that generated a seed on the vulnerable firmware, there would be a 50% chance that two innocent, unaware people would end up with the exact same seed phrase, and by extension every bitcoin address derived from it, giving each other access to the others funds.
    
    Just a fun thought experiment in these dark times.
    
    comment: p1bjfv9
    parent: t3_1vdr94r
    author: PrometheusFires
    created_utc: 1785702420
    edited: false
    body:
    Crazy scenario 
    
    comment: p1bvbee
    parent: t3_1vdr94r
    author: slvbtc
    created_utc: 1785705834
    edited: false
    body:
    This is why once every few months we saw people posting on reddit saying their funds were drained even after taking every precaution and doing nothing wrong.
    
    Instead of coinkite looking into these issues and checking for bugs they simply called these victims "crying panhandlers" and ignored them.
    
    
    
    comment: p1bykn8
    parent: t1_p1bvbee
    author: StarCommand1
    created_utc: 1785706797
    edited: false

    Excerpt only. The complete copy is held offline and backs quotations on this site. The original publication remains the canonical public source.

  2. source content difference between and source content +10 -0

    1 new Reddit comment was posted, by CompetitionDouble420, expressing relief at having used another device.

    seen · Captured here 9,864 chars
    What changed from the previous capture 10 lines
     edited: false
     body:
     Validate bitcoin to grandpa they said 
    +
    +comment: p1nqj03
    +parent: t3_1vdr94r
    +author: CompetitionDouble420
    +created_utc: 1785854400
    +edited: false
    +body:
    +Yo fuck a coinkite. 
    +
    +So glad ColdCard wasn't my first device. 
    
    Extracted text as captured
    post: 1vdr94r
    author: IsolatedNetworkNode
    created_utc: 1785699240
    title: 93,000 Coldcard-Generated Seeds Is All It Takes for a 50% Chance Two People End Up With the Same Wallet
    body:
    You probably heard the birthday paradox, having 23 people in a room creates a 50% chance that at least two of them share the same birthday.
    
    Applying it to the vulnerable search space in the ColdCard bug (Following reports that search space was reduced to 2\^32, approx 4 billion)
    
    50% collision odds ≈ √(2 × 4.3 billion) ≈ 93,000 ColdCard Wallet Generated Seeds.
    
    If this bug was somehow never discovered and Coldcard sold around 93k units that generated a seed on the vulnerable firmware, there would be a 50% chance that two innocent, unaware people would end up with the exact same seed phrase, and by extension every bitcoin address derived from it, giving each other access to the others funds.
    
    Just a fun thought experiment in these dark times.
    
    comment: p1bjfv9
    parent: t3_1vdr94r
    author: PrometheusFires
    created_utc: 1785702420
    edited: false
    body:
    Crazy scenario 
    
    comment: p1bvbee
    parent: t3_1vdr94r
    author: slvbtc
    created_utc: 1785705834
    edited: false
    body:
    This is why once every few months we saw people posting on reddit saying their funds were drained even after taking every precaution and doing nothing wrong.
    
    Instead of coinkite looking into these issues and checking for bugs they simply called these victims "crying panhandlers" and ignored them.
    
    
    
    comment: p1bykn8
    parent: t1_p1bvbee
    author: StarCommand1
    created_utc: 1785706797
    edited: false

    Excerpt only. The complete copy is held offline and backs quotations on this site. The original publication remains the canonical public source.

  3. Earliest copy held
    seen · Captured here 9,690 chars
    Extracted text as captured
    post: 1vdr94r
    author: IsolatedNetworkNode
    created_utc: 1785699240
    title: 93,000 Coldcard-Generated Seeds Is All It Takes for a 50% Chance Two People End Up With the Same Wallet
    body:
    You probably heard the birthday paradox, having 23 people in a room creates a 50% chance that at least two of them share the same birthday.
    
    Applying it to the vulnerable search space in the ColdCard bug (Following reports that search space was reduced to 2\^32, approx 4 billion)
    
    50% collision odds ≈ √(2 × 4.3 billion) ≈ 93,000 ColdCard Wallet Generated Seeds.
    
    If this bug was somehow never discovered and Coldcard sold around 93k units that generated a seed on the vulnerable firmware, there would be a 50% chance that two innocent, unaware people would end up with the exact same seed phrase, and by extension every bitcoin address derived from it, giving each other access to the others funds.
    
    Just a fun thought experiment in these dark times.
    
    comment: p1bjfv9
    parent: t3_1vdr94r
    author: PrometheusFires
    created_utc: 1785702420
    edited: false
    body:
    Crazy scenario 
    
    comment: p1bvbee
    parent: t3_1vdr94r
    author: slvbtc
    created_utc: 1785705834
    edited: false
    body:
    This is why once every few months we saw people posting on reddit saying their funds were drained even after taking every precaution and doing nothing wrong.
    
    Instead of coinkite looking into these issues and checking for bugs they simply called these victims "crying panhandlers" and ignored them.
    
    
    
    comment: p1bykn8
    parent: t1_p1bvbee
    author: StarCommand1
    created_utc: 1785706797
    edited: false

    Excerpt only. The complete copy is held offline and backs quotations on this site. The original publication remains the canonical public source.

How to check this yourself

The excerpts and plain unified diffs above show the text this project held and how it changed. To verify a quotation, compare it against the page itself or against the Internet Archive's copies, which are independent of this project.

Complete captures are held offline rather than mirrored here, so this page shows diffs and excerpts. If a quotation is ever disputed, the full copy can be produced. Ask.