COLDCARD RNG incident the public record, collected and explained
Informational only, and this site never asks for your seed words. details

Informational only. This is an open source collection of what others have published about the incident, together with an explanation of it. It is not financial, security or legal advice, and not a substitute for professional advice about your own situation. It is not affiliated with, endorsed by, or speaking for Coinkite. Material is attributed and quoted as published; where sources disagree their scenarios are kept separate with their assumptions rather than reconciled into one answer. Everything is meant to be checked against the linked evidence rather than taken on trust. Act on your own judgement about a particular situation. Editorial standards and corrections.

Do not disclose recovery material to a website, form, message or support account. This site never asks for it, and contributions containing recovery words or private keys are not accepted.

r/coldcard: whether owners still trust Coinkite

reddit-still-trust-coinkite

https://www.reddit.com/r/coldcard/comments/1vc9jqu/do_you_guys_still_trust_coinkite/

Latest reviewed change

source content difference between and

The thread gained two comments from the same participant arguing that trusting Coinkite after the incident would be irrational.

seen +18 -0 full history below
 `#ifndef` vs `#if 0`
 
 This tiny error cost $100s of millions and an entire company and 15 years of rapport.
+
+comment: p2a66mr
+parent: t3_1vc9jqu
+author: Grouchy-Childhood-55
+created_utc: 1786116299

First lines only. The complete diff is in the timeline below.

Organisation
reddit
Evidence role
Community discussion
Published
not established
Source changes
4
Detected differences
4
Unreviewed
0
Copies held
5

Every check is recorded, including checks that found no text change. A detected edit is therefore bounded between two checks. The publisher's exact save time is not observable from this record. Last checked .

  1. source content difference between and Current source content +18 -0

    The thread gained two comments from the same participant arguing that trusting Coinkite after the incident would be irrational.

    seen · Captured here 27,642 chars
    What changed from the previous capture 18 lines
     `#ifndef` vs `#if 0`
     
     This tiny error cost $100s of millions and an entire company and 15 years of rapport.
    +
    +comment: p2a66mr
    +parent: t3_1vc9jqu
    +author: Grouchy-Childhood-55
    +created_utc: 1786116299
    +edited: false
    +body:
    +Trust Coinkite? Are you nuts? After learning about the people that run that clownshow? But you bought that expensive wallet and already stamped you seed phrase into steel. You should definitely trust Coinkite.
    +
    +comment: p2a7c47
    +parent: t1_p13vwbp
    +author: Grouchy-Childhood-55
    +created_utc: 1786116590
    +edited: false
    +body:
    +"All companies can do this, so this isn't so bad". This is a false equivalence. You KNOW that this company dropped the ball. Not a little, but a lot. You would be trusting the ego, dysfunctional culture, and sloppy practices/intentional incompetence that resulted in this mess.
    +
    +But by all means, continue throw money at those guys.
    
    Extracted text as captured
    post: 1vc9jqu
    author: Altruistic_Ear_9542
    created_utc: 1785547620
    title: Do you guys still trust Coinkite?
    body:
    I have a cold card Q and didn’t generate my seed using dice rolls so I quickly moved my bitcoin to my backup Tangem temporarily. My question to you guys is do you still trust and are willing to generate a new seed using the dice roll function? Or are you guys ditching coldcard completely? I’m not sure where i stand. I paid $300 for the Q and literally just stamped my seed into the $100 trezor keep metal capsule last week so I’m pissed…
    
    comment: p0znf9s
    parent: t3_1vc9jqu
    author: Filmexec21
    created_utc: 1785547781
    edited: false
    body:
    No
    
    comment: p0zni4g
    parent: t3_1vc9jqu
    author: angelus97
    created_utc: 1785547808
    edited: false
    body:
    Nah this company is done
    
    comment: p0znkfq
    parent: t3_1vc9jqu
    author: deny_by_default
    created_utc: 1785547830
    edited: false
    body:
     I got a Safe 7 first and created my seed on that.  I got a CCQ later and imported that same seed into it so I could access the wallet from both devices.  I know I'm not succeptible to this specific vulnerability, but now I'm wondering....what's going to be next? If something this big was overlooked, what else was overlooked?
    
    comment: p0znre8
    parent: t1_p0znkfq
    author: Altruistic_Ear_9542
    created_utc: 1785547899
    edited: false
    body:
    My thoughts too. I’m wondering how no one caught this tho?
    
    comment: p0zqzhi

    Excerpt only. The complete copy is held offline and backs quotations on this site. The original publication remains the canonical public source.

  2. source content difference between and source content +12 -0

    New comment from Outrageous-Lab-2138 attributing the incident to a one-line error, #ifndef vs #if 0, costing hundreds of millions.

    seen · Captured here 26,879 chars
    What changed from the previous capture 12 lines
     Removed post ...   [http://blog.coinkite.com/post/141836920461/time-to-be-your-own-bank](http://blog.coinkite.com/post/141836920461/time-to-be-your-own-bank)
     
     
    +
    +comment: p251dyp
    +parent: t3_1vc9jqu
    +author: Outrageous-Lab-2138
    +created_utc: 1786050361
    +edited: false
    +body:
    +The tragedy is that it all came down to one line of code:
    +
    +`#ifndef` vs `#if 0`
    +
    +This tiny error cost $100s of millions and an entire company and 15 years of rapport.
    
    Extracted text as captured
    post: 1vc9jqu
    author: Altruistic_Ear_9542
    created_utc: 1785547620
    title: Do you guys still trust Coinkite?
    body:
    I have a cold card Q and didn’t generate my seed using dice rolls so I quickly moved my bitcoin to my backup Tangem temporarily. My question to you guys is do you still trust and are willing to generate a new seed using the dice roll function? Or are you guys ditching coldcard completely? I’m not sure where i stand. I paid $300 for the Q and literally just stamped my seed into the $100 trezor keep metal capsule last week so I’m pissed…
    
    comment: p0znf9s
    parent: t3_1vc9jqu
    author: Filmexec21
    created_utc: 1785547781
    edited: false
    body:
    No
    
    comment: p0zni4g
    parent: t3_1vc9jqu
    author: angelus97
    created_utc: 1785547808
    edited: false
    body:
    Nah this company is done
    
    comment: p0znkfq
    parent: t3_1vc9jqu
    author: deny_by_default
    created_utc: 1785547830
    edited: false
    body:
     I got a Safe 7 first and created my seed on that.  I got a CCQ later and imported that same seed into it so I could access the wallet from both devices.  I know I'm not succeptible to this specific vulnerability, but now I'm wondering....what's going to be next? If something this big was overlooked, what else was overlooked?
    
    comment: p0znre8
    parent: t1_p0znkfq
    author: Altruistic_Ear_9542
    created_utc: 1785547899
    edited: false
    body:
    My thoughts too. I’m wondering how no one caught this tho?
    
    comment: p0zqzhi

    Excerpt only. The complete copy is held offline and backs quotations on this site. The original publication remains the canonical public source.

  3. source content difference between and source content +4 -4

    Flowa-Powa edited their comment, correcting "broken usb reader" to "broken SD card reader" and trimming trailing whitespace.

    seen · Captured here 26,603 chars
    What changed from the previous capture 8 lines
     parent: t3_1vc9jqu
     author: Flowa-Powa
     created_utc: 1785785896
    -edited: false
    -body:
    -My Coldcard Q has a broken usb reader, and now this omnishambles.
    +edited: 1786018845
    +body:
    +My Coldcard Q has a broken SD card reader, and now this omnishambles.
     
     It was a genuine error though. There was a very well designed randomiser built in, but it wasn't being used, and was deferring to a very low quality randomiser that the developer didn't even know existed.
     
     The real error was not empirically testing the output for entropy.
     
    -I don't know. I'm conflicted. If you update the firmware, generate with dice and layer a passphrase on top you really should be alright. 
    +I don't know. I'm conflicted. If you update the firmware, generate with dice and layer a passphrase on top you really should be alright.
     
     comment: p1ryc7f
     parent: t3_1vc9jqu
    
    Extracted text as captured
    post: 1vc9jqu
    author: Altruistic_Ear_9542
    created_utc: 1785547620
    title: Do you guys still trust Coinkite?
    body:
    I have a cold card Q and didn’t generate my seed using dice rolls so I quickly moved my bitcoin to my backup Tangem temporarily. My question to you guys is do you still trust and are willing to generate a new seed using the dice roll function? Or are you guys ditching coldcard completely? I’m not sure where i stand. I paid $300 for the Q and literally just stamped my seed into the $100 trezor keep metal capsule last week so I’m pissed…
    
    comment: p0znf9s
    parent: t3_1vc9jqu
    author: Filmexec21
    created_utc: 1785547781
    edited: false
    body:
    No
    
    comment: p0zni4g
    parent: t3_1vc9jqu
    author: angelus97
    created_utc: 1785547808
    edited: false
    body:
    Nah this company is done
    
    comment: p0znkfq
    parent: t3_1vc9jqu
    author: deny_by_default
    created_utc: 1785547830
    edited: false
    body:
     I got a Safe 7 first and created my seed on that.  I got a CCQ later and imported that same seed into it so I could access the wallet from both devices.  I know I'm not succeptible to this specific vulnerability, but now I'm wondering....what's going to be next? If something this big was overlooked, what else was overlooked?
    
    comment: p0znre8
    parent: t1_p0znkfq
    author: Altruistic_Ear_9542
    created_utc: 1785547899
    edited: false
    body:
    My thoughts too. I’m wondering how no one caught this tho?
    
    comment: p0zqzhi

    Excerpt only. The complete copy is held offline and backs quotations on this site. The original publication remains the canonical public source.

  4. source content difference between and source content +34 -0

    The thread gained a personal account alleging loss of a Coinkite exchange balance in 2016 and citing historical terms, followed by the author's distrust of the company and self-custody.

    seen · Captured here 26,595 chars
    What changed from the previous capture 34 lines
     The real error was not empirically testing the output for entropy.
     
     I don't know. I'm conflicted. If you update the firmware, generate with dice and layer a passphrase on top you really should be alright. 
    +
    +comment: p1ryc7f
    +parent: t3_1vc9jqu
    +author: AliveDrumming
    +created_utc: 1785896413
    +edited: false
    +body:
    +I believe CoinKite are the criminal behind this.    
    +  
    +They stole my Bitcoin in Jan 2016.  At that time, they were an exchange where I had purchased Bitcoin from Australia.   They advised me a public key (of sorts), and later emailed me stating they had closed down and charged me (and others) their remaining balances for the trouble.  They stated they would concentrate on hardware devices instead of running an exchange.  I would never have purchased anything more from these folk. 
    +
    +From the email that got sent to spam and ignored, "We will charge a termination fee equal to the remaining Balances on May 27th.(extended)
    +
    +We reserve the right to cancel the Grace Period, without notice, any time after April the 11th.
    +
    +Grace Period Extension Over (June 10th, 75 days!)
    +
    +
    +
    +We will charge a termination fee equal to the remaining Balances.
    +
    +https://coinkite.com/terms"
    +
    +Now, of course, with hindsight and education, I would have immediately sent the BTC to my own created BTC wallet (using dice).   After completing a thorough survey of self-custody, I came to the conclusion that it is too risky, and the custody of the banking system has a lot going for it. 
    +
    +CoinKite = Once a thief, always a thief!
    +
    +Ref's
    +
    +[https://www.reddit.com/r/Bitcoin/comments/4ca4b8/coinkite\_closing\_down\_web\_wallet/](https://www.reddit.com/r/Bitcoin/comments/4ca4b8/coinkite_closing_down_web_wallet/)
    +
    +Removed post ...   [http://blog.coinkite.com/post/141836920461/time-to-be-your-own-bank](http://blog.coinkite.com/post/141836920461/time-to-be-your-own-bank)
    +
    +
    
    Extracted text as captured
    post: 1vc9jqu
    author: Altruistic_Ear_9542
    created_utc: 1785547620
    title: Do you guys still trust Coinkite?
    body:
    I have a cold card Q and didn’t generate my seed using dice rolls so I quickly moved my bitcoin to my backup Tangem temporarily. My question to you guys is do you still trust and are willing to generate a new seed using the dice roll function? Or are you guys ditching coldcard completely? I’m not sure where i stand. I paid $300 for the Q and literally just stamped my seed into the $100 trezor keep metal capsule last week so I’m pissed…
    
    comment: p0znf9s
    parent: t3_1vc9jqu
    author: Filmexec21
    created_utc: 1785547781
    edited: false
    body:
    No
    
    comment: p0zni4g
    parent: t3_1vc9jqu
    author: angelus97
    created_utc: 1785547808
    edited: false
    body:
    Nah this company is done
    
    comment: p0znkfq
    parent: t3_1vc9jqu
    author: deny_by_default
    created_utc: 1785547830
    edited: false
    body:
     I got a Safe 7 first and created my seed on that.  I got a CCQ later and imported that same seed into it so I could access the wallet from both devices.  I know I'm not succeptible to this specific vulnerability, but now I'm wondering....what's going to be next? If something this big was overlooked, what else was overlooked?
    
    comment: p0znre8
    parent: t1_p0znkfq
    author: Altruistic_Ear_9542
    created_utc: 1785547899
    edited: false
    body:
    My thoughts too. I’m wondering how no one caught this tho?
    
    comment: p0zqzhi

    Excerpt only. The complete copy is held offline and backs quotations on this site. The original publication remains the canonical public source.

  5. Earliest copy held
    seen · Captured here 24,943 chars
    Extracted text as captured
    post: 1vc9jqu
    author: Altruistic_Ear_9542
    created_utc: 1785547620
    title: Do you guys still trust Coinkite?
    body:
    I have a cold card Q and didn’t generate my seed using dice rolls so I quickly moved my bitcoin to my backup Tangem temporarily. My question to you guys is do you still trust and are willing to generate a new seed using the dice roll function? Or are you guys ditching coldcard completely? I’m not sure where i stand. I paid $300 for the Q and literally just stamped my seed into the $100 trezor keep metal capsule last week so I’m pissed…
    
    comment: p0znf9s
    parent: t3_1vc9jqu
    author: Filmexec21
    created_utc: 1785547781
    edited: false
    body:
    No
    
    comment: p0zni4g
    parent: t3_1vc9jqu
    author: angelus97
    created_utc: 1785547808
    edited: false
    body:
    Nah this company is done
    
    comment: p0znkfq
    parent: t3_1vc9jqu
    author: deny_by_default
    created_utc: 1785547830
    edited: false
    body:
     I got a Safe 7 first and created my seed on that.  I got a CCQ later and imported that same seed into it so I could access the wallet from both devices.  I know I'm not succeptible to this specific vulnerability, but now I'm wondering....what's going to be next? If something this big was overlooked, what else was overlooked?
    
    comment: p0znre8
    parent: t1_p0znkfq
    author: Altruistic_Ear_9542
    created_utc: 1785547899
    edited: false
    body:
    My thoughts too. I’m wondering how no one caught this tho?
    
    comment: p0zqzhi

    Excerpt only. The complete copy is held offline and backs quotations on this site. The original publication remains the canonical public source.

How to check this yourself

The excerpts and plain unified diffs above show the text this project held and how it changed. To verify a quotation, compare it against the page itself or against the Internet Archive's copies, which are independent of this project.

Complete captures are held offline rather than mirrored here, so this page shows diffs and excerpts. If a quotation is ever disputed, the full copy can be produced. Ask.