COLDCARD RNG incident the public record, collected and explained
Informational only, and this site never asks for your seed words. details

Informational only. This is an open source collection of what others have published about the incident, together with an explanation of it. It is not financial, security or legal advice, and not a substitute for professional advice about your own situation. It is not affiliated with, endorsed by, or speaking for Coinkite. Material is attributed and quoted as published; where sources disagree their scenarios are kept separate with their assumptions rather than reconciled into one answer. Everything is meant to be checked against the linked evidence rather than taken on trust. Act on your own judgement about a particular situation. Editorial standards and corrections.

Do not disclose recovery material to a website, form, message or support account. This site never asks for it, and contributions containing recovery words or private keys are not accepted.

r/Bitcoin: call for a community audit of Trezor's open-source code

reddit-trezor-community-audit-call

https://www.reddit.com/r/Bitcoin/comments/1veoo6t/as_a_community_we_should_fully_audit_trezors_open/

Latest reviewed change

source content difference between and

The thread gained a short off-topic reply.

seen +8 -0 full history below
 edited: false
 body:
 AI is better at finding exploits than securing them for the very specific reason that cybersecurity is inherently assymetrical, even for humans. It is always harder to secure a system than break it, just like it's always harder to make a card castle than knock one down. The security professional has to protect against all imaginable threats; the hacker just has to find one vulnerability.
+
+comment: p29hzd2
+parent: t1_p1iotom
+author: Accomplished-Net1378
+created_utc: 1786109769

First lines only. The complete diff is in the timeline below.

Organisation
reddit
Evidence role
Community discussion
Published
not established
Source changes
16
Detected differences
16
Unreviewed
0
Copies held
17

Every check is recorded, including checks that found no text change. A detected edit is therefore bounded between two checks. The publisher's exact save time is not observable from this record. Last checked .

  1. source content difference between and Current source content +8 -0

    The thread gained a short off-topic reply.

    seen · Captured here 20,621 chars
    What changed from the previous capture 8 lines
     edited: false
     body:
     AI is better at finding exploits than securing them for the very specific reason that cybersecurity is inherently assymetrical, even for humans. It is always harder to secure a system than break it, just like it's always harder to make a card castle than knock one down. The security professional has to protect against all imaginable threats; the hacker just has to find one vulnerability.
    +
    +comment: p29hzd2
    +parent: t1_p1iotom
    +author: Accomplished-Net1378
    +created_utc: 1786109769
    +edited: false
    +body:
    +Had fun. For sure 😄 
    
    Extracted text as captured
    post: 1veoo6t
    author: CeramicDrip
    created_utc: 1785788226
    title: As a community, we should fully audit Trezor’s open source software
    body:
    Basically the title.
    
    Im sure we all want to determine what the safest hardware wallet is after this whole ColdCard scenario. So i propose that we audit Trezor as a community. They have stood the test of time, but now its time to test their code.
    
    Im a software engineer and im willing to help in whatever way possible, with some experience in cryptography. 
    
    comment: p1in4b3
    parent: t3_1veoo6t
    author: TheresNoSecondBest
    created_utc: 1785788487
    edited: false
    body:
    >Im sure we all want to determine what the safest hardware wallet is
    
    Then forget Trezor, audit JadePlus, Krux and SeedSigner instead. 
    
    comment: p1iob9o
    parent: t3_1veoo6t
    author: TheBigLR901
    created_utc: 1785788803
    edited: false
    body:
    Apparently you can just run it through AI, let it noodle on the code for 8 minutes,  and it will list any security issues.
    
    comment: p1iojpf
    parent: t1_p1in4b3
    author: RedditTooAddictive
    created_utc: 1785788865
    edited: false
    body:
    Why?
    
    comment: p1iotom
    parent: t3_1veoo6t
    author: lovemyhawks

    Excerpt only. The complete copy is held offline and backs quotations on this site. The original publication remains the canonical public source.

  2. source content difference between and source content +8 -0

    New comment from Ok-Mammoth552 arguing AI is better at finding exploits than securing systems because cybersecurity is inherently asymmetrical.

    seen · Captured here 20,489 chars
    What changed from the previous capture 8 lines
     edited: false
     body:
     What is a good tool or tutorial to use for flipping the coin method that is trusted? After rolling dice or flipping a coin, how does that translate to BIP 39 seed and passphrase? 
    +
    +comment: p22lwaj
    +parent: t1_p1j6frl
    +author: Ok-Mammoth552
    +created_utc: 1786028234
    +edited: false
    +body:
    +AI is better at finding exploits than securing them for the very specific reason that cybersecurity is inherently assymetrical, even for humans. It is always harder to secure a system than break it, just like it's always harder to make a card castle than knock one down. The security professional has to protect against all imaginable threats; the hacker just has to find one vulnerability.
    
    Extracted text as captured
    post: 1veoo6t
    author: CeramicDrip
    created_utc: 1785788226
    title: As a community, we should fully audit Trezor’s open source software
    body:
    Basically the title.
    
    Im sure we all want to determine what the safest hardware wallet is after this whole ColdCard scenario. So i propose that we audit Trezor as a community. They have stood the test of time, but now its time to test their code.
    
    Im a software engineer and im willing to help in whatever way possible, with some experience in cryptography. 
    
    comment: p1in4b3
    parent: t3_1veoo6t
    author: TheresNoSecondBest
    created_utc: 1785788487
    edited: false
    body:
    >Im sure we all want to determine what the safest hardware wallet is
    
    Then forget Trezor, audit JadePlus, Krux and SeedSigner instead. 
    
    comment: p1iob9o
    parent: t3_1veoo6t
    author: TheBigLR901
    created_utc: 1785788803
    edited: false
    body:
    Apparently you can just run it through AI, let it noodle on the code for 8 minutes,  and it will list any security issues.
    
    comment: p1iojpf
    parent: t1_p1in4b3
    author: RedditTooAddictive
    created_utc: 1785788865
    edited: false
    body:
    Why?
    
    comment: p1iotom
    parent: t3_1veoo6t
    author: lovemyhawks

    Excerpt only. The complete copy is held offline and backs quotations on this site. The original publication remains the canonical public source.

  3. source content difference between and source content +8 -0

    Reddit added a request for a trusted method to turn dice or coin entropy into a BIP39 seed and passphrase.

    seen · Captured here 19,995 chars
    What changed from the previous capture 8 lines
     I’ve seen these things on Star Wars, Watto called them chance cubes, I’m sure that we as a community could come up with some sort of IRL proxy for this sort of thing? Perhaps we could make these cubes even more random by numbering the sides? Or, if we like binary chance, maybe we just streamline the physical product by redesigning it with only two faces?
     
     Then all we really have to worry about it making sure we generate our seed phrases well away from any Jedi. And I feel like we can all do that much easier and more reliably than trusting each other to learn cryptography.
    +
    +comment: p1z14hs
    +parent: t1_p1mfq6d
    +author: privacymatterznow
    +created_utc: 1785979194
    +edited: false
    +body:
    +What is a good tool or tutorial to use for flipping the coin method that is trusted? After rolling dice or flipping a coin, how does that translate to BIP 39 seed and passphrase? 
    
    Extracted text as captured
    post: 1veoo6t
    author: CeramicDrip
    created_utc: 1785788226
    title: As a community, we should fully audit Trezor’s open source software
    body:
    Basically the title.
    
    Im sure we all want to determine what the safest hardware wallet is after this whole ColdCard scenario. So i propose that we audit Trezor as a community. They have stood the test of time, but now its time to test their code.
    
    Im a software engineer and im willing to help in whatever way possible, with some experience in cryptography. 
    
    comment: p1in4b3
    parent: t3_1veoo6t
    author: TheresNoSecondBest
    created_utc: 1785788487
    edited: false
    body:
    >Im sure we all want to determine what the safest hardware wallet is
    
    Then forget Trezor, audit JadePlus, Krux and SeedSigner instead. 
    
    comment: p1iob9o
    parent: t3_1veoo6t
    author: TheBigLR901
    created_utc: 1785788803
    edited: false
    body:
    Apparently you can just run it through AI, let it noodle on the code for 8 minutes,  and it will list any security issues.
    
    comment: p1iojpf
    parent: t1_p1in4b3
    author: RedditTooAddictive
    created_utc: 1785788865
    edited: false
    body:
    Why?
    
    comment: p1iotom
    parent: t3_1veoo6t
    author: lovemyhawks

    Excerpt only. The complete copy is held offline and backs quotations on this site. The original publication remains the canonical public source.

  4. source content difference between and source content +14 -0

    Reddit served an additional comment proposing physical randomness, such as dice, instead of device-generated seed phrases.

    seen · Captured here 19,708 chars
    What changed from the previous capture 14 lines
     edited: false
     body:
     So funny
    +
    +comment: p1tbbty
    +parent: t3_1veoo6t
    +author: SmartPipe3882
    +created_utc: 1785916975
    +edited: 1785917173
    +body:
    +What about if, instead of trusting each other - completely without vetting, on Reddit of all places - instead of Trezor-et-al, we just don’t generate seed phrases on device if we’re that concerned that the generation process is compromised?
    +
    +Use genuine physical randomness to select from the 1024 words.
    +
    +I’ve seen these things on Star Wars, Watto called them chance cubes, I’m sure that we as a community could come up with some sort of IRL proxy for this sort of thing? Perhaps we could make these cubes even more random by numbering the sides? Or, if we like binary chance, maybe we just streamline the physical product by redesigning it with only two faces?
    +
    +Then all we really have to worry about it making sure we generate our seed phrases well away from any Jedi. And I feel like we can all do that much easier and more reliably than trusting each other to learn cryptography.
    
    Extracted text as captured
    post: 1veoo6t
    author: CeramicDrip
    created_utc: 1785788226
    title: As a community, we should fully audit Trezor’s open source software
    body:
    Basically the title.
    
    Im sure we all want to determine what the safest hardware wallet is after this whole ColdCard scenario. So i propose that we audit Trezor as a community. They have stood the test of time, but now its time to test their code.
    
    Im a software engineer and im willing to help in whatever way possible, with some experience in cryptography. 
    
    comment: p1in4b3
    parent: t3_1veoo6t
    author: TheresNoSecondBest
    created_utc: 1785788487
    edited: false
    body:
    >Im sure we all want to determine what the safest hardware wallet is
    
    Then forget Trezor, audit JadePlus, Krux and SeedSigner instead. 
    
    comment: p1iob9o
    parent: t3_1veoo6t
    author: TheBigLR901
    created_utc: 1785788803
    edited: false
    body:
    Apparently you can just run it through AI, let it noodle on the code for 8 minutes,  and it will list any security issues.
    
    comment: p1iojpf
    parent: t1_p1in4b3
    author: RedditTooAddictive
    created_utc: 1785788865
    edited: false
    body:
    Why?
    
    comment: p1iotom
    parent: t3_1veoo6t
    author: lovemyhawks

    Excerpt only. The complete copy is held offline and backs quotations on this site. The original publication remains the canonical public source.

  5. source content difference between and source content +8 -0

    The Reddit thread gained a reply to the preceding participant comment.

    seen · Captured here 18,715 chars
    What changed from the previous capture 8 lines
     edited: false
     body:
     IM NOT ENCRYPTING I'M TRAVELLING. I DO NOT CONSENT TO CREATING JOINDER WITH THE BLOCKCHAIN
    +
    +comment: p1r8ra7
    +parent: t1_p1r47ee
    +author: curiousengineer601
    +created_utc: 1785888083
    +edited: false
    +body:
    +So funny
    
    Extracted text as captured
    post: 1veoo6t
    author: CeramicDrip
    created_utc: 1785788226
    title: As a community, we should fully audit Trezor’s open source software
    body:
    Basically the title.
    
    Im sure we all want to determine what the safest hardware wallet is after this whole ColdCard scenario. So i propose that we audit Trezor as a community. They have stood the test of time, but now its time to test their code.
    
    Im a software engineer and im willing to help in whatever way possible, with some experience in cryptography. 
    
    comment: p1in4b3
    parent: t3_1veoo6t
    author: TheresNoSecondBest
    created_utc: 1785788487
    edited: false
    body:
    >Im sure we all want to determine what the safest hardware wallet is
    
    Then forget Trezor, audit JadePlus, Krux and SeedSigner instead. 
    
    comment: p1iob9o
    parent: t3_1veoo6t
    author: TheBigLR901
    created_utc: 1785788803
    edited: false
    body:
    Apparently you can just run it through AI, let it noodle on the code for 8 minutes,  and it will list any security issues.
    
    comment: p1iojpf
    parent: t1_p1in4b3
    author: RedditTooAddictive
    created_utc: 1785788865
    edited: false
    body:
    Why?
    
    comment: p1iotom
    parent: t3_1veoo6t
    author: lovemyhawks

    Excerpt only. The complete copy is held offline and backs quotations on this site. The original publication remains the canonical public source.

  6. source content difference between and source content +8 -0

    The Reddit thread gained a new participant comment.

    seen · Captured here 18,598 chars
    What changed from the previous capture 8 lines
     To systemically go through the codebase requires organization and knowledge. The people with the skills are probably working real jobs for money which leaves the trezor validation team to check the code.
     
     For some reason anytime someone yells audit I think of those first amendment auditors that annoy me by the post office
    +
    +comment: p1r47ee
    +parent: t1_p1qx2hy
    +author: Kooriki
    +created_utc: 1785886632
    +edited: false
    +body:
    +IM NOT ENCRYPTING I'M TRAVELLING. I DO NOT CONSENT TO CREATING JOINDER WITH THE BLOCKCHAIN
    
    Extracted text as captured
    post: 1veoo6t
    author: CeramicDrip
    created_utc: 1785788226
    title: As a community, we should fully audit Trezor’s open source software
    body:
    Basically the title.
    
    Im sure we all want to determine what the safest hardware wallet is after this whole ColdCard scenario. So i propose that we audit Trezor as a community. They have stood the test of time, but now its time to test their code.
    
    Im a software engineer and im willing to help in whatever way possible, with some experience in cryptography. 
    
    comment: p1in4b3
    parent: t3_1veoo6t
    author: TheresNoSecondBest
    created_utc: 1785788487
    edited: false
    body:
    >Im sure we all want to determine what the safest hardware wallet is
    
    Then forget Trezor, audit JadePlus, Krux and SeedSigner instead. 
    
    comment: p1iob9o
    parent: t3_1veoo6t
    author: TheBigLR901
    created_utc: 1785788803
    edited: false
    body:
    Apparently you can just run it through AI, let it noodle on the code for 8 minutes,  and it will list any security issues.
    
    comment: p1iojpf
    parent: t1_p1in4b3
    author: RedditTooAddictive
    created_utc: 1785788865
    edited: false
    body:
    Why?
    
    comment: p1iotom
    parent: t3_1veoo6t
    author: lovemyhawks

    Excerpt only. The complete copy is held offline and backs quotations on this site. The original publication remains the canonical public source.

  7. source content difference between and source content +36 -0

    The Reddit thread gained comments comparing entropy designs and debating what a community audit can accomplish.

    seen · Captured here 18,410 chars
    What changed from the previous capture 36 lines
     body:
     [removed]
     
    +comment: p1llcdn
    +parent: t1_p1lektv
    +author: Full-Atmosphere-4818
    +created_utc: 1785824472
    +edited: false
    +body:
    +According to someone on another thread, Ledger AND Tangem have only one way to make the entropy vs several methods for other options. The third one that had only one method was ColdCard. 
    +
     comment: p1lp6nq
     parent: t3_1veoo6t
     author: joeyx22lm
     And if you're not money laundering (using bitcoin?), you're probably safest leaving it in a US based exchange, where there is regulatory oversight.
     
     Want to be a cyberpunk defi tech boi, store your seed phrase alongside your PGP key.
    +
    +comment: p1ltzte
    +parent: t1_p1ipx3q
    +author: Spy008
    +created_utc: 1785828649
    +edited: false
    +body:
    +Not wasting my time responding to each comment. My point is there is A LOT of eyes on Trezor’s code.
    +
    +For open source to be secure you need two things Time + target. The longer the time (history of working) the better the security is, the more appealing/lucrative the target is the better the security is.
    +
    +Think of it this way you’re a researcher- finding a flaw in Trezor’s code would get you on the front page news. Finding a flaw in SuperDuperSecurityTheater wallet might have some random guy mention it on Reddit. (Hell even the constant repetition of the physical vulnerability of model 1 and T get a front page news article every few years someone rediscovers it)
    +
    +Audit the code, idc, but the chance that some random Redditor is going to find anything that experienced professionals in the field havent is near 0.
    +
    +But but coldcard… no one was looking at this crap. Literally the incentive (Target) was incredibly small, outside of this sub where it was constantly peddled. coldcard’s user base was small and their business practices did nothing to encourage outside scrutiny.
     
     comment: p1m7jed
     parent: t1_p1ja9ho
     edited: false
     body:
     Are we even in the same discussion here?? You said the Safe 5 is air gapped. It’s not. Full stop. 
    +
    +comment: p1qx2hy
    +parent: t1_p1iotom
    +author: curiousengineer601
    +created_utc: 1785884407
    +edited: false
    +body:
    +Lol. The vast majority of people don’t have any of the skills needed to contribute to any ‘audit’.
    +
    +To systemically go through the codebase requires organization and knowledge. The people with the skills are probably working real jobs for money which leaves the trezor validation team to check the code.
    +
    +For some reason anytime someone yells audit I think of those first amendment auditors that annoy me by the post office
    
    Extracted text as captured
    post: 1veoo6t
    author: CeramicDrip
    created_utc: 1785788226
    title: As a community, we should fully audit Trezor’s open source software
    body:
    Basically the title.
    
    Im sure we all want to determine what the safest hardware wallet is after this whole ColdCard scenario. So i propose that we audit Trezor as a community. They have stood the test of time, but now its time to test their code.
    
    Im a software engineer and im willing to help in whatever way possible, with some experience in cryptography. 
    
    comment: p1in4b3
    parent: t3_1veoo6t
    author: TheresNoSecondBest
    created_utc: 1785788487
    edited: false
    body:
    >Im sure we all want to determine what the safest hardware wallet is
    
    Then forget Trezor, audit JadePlus, Krux and SeedSigner instead. 
    
    comment: p1iob9o
    parent: t3_1veoo6t
    author: TheBigLR901
    created_utc: 1785788803
    edited: false
    body:
    Apparently you can just run it through AI, let it noodle on the code for 8 minutes,  and it will list any security issues.
    
    comment: p1iojpf
    parent: t1_p1in4b3
    author: RedditTooAddictive
    created_utc: 1785788865
    edited: false
    body:
    Why?
    
    comment: p1iotom
    parent: t3_1veoo6t
    author: lovemyhawks

    Excerpt only. The complete copy is held offline and backs quotations on this site. The original publication remains the canonical public source.

  8. source content difference between and source content +8 -0

    The Reddit thread gained 1 new comment.

    seen · Captured here 16,399 chars
    What changed from the previous capture 8 lines
     edited: false
     body:
     So it's air gapped because you don't see the value in it, even though it's not actually air gapped?
    +
    +comment: p1pxocf
    +parent: t1_p1pf488
    +author: deny_by_default
    +created_utc: 1785874513
    +edited: false
    +body:
    +Are we even in the same discussion here?? You said the Safe 5 is air gapped. It’s not. Full stop. 
    
    Extracted text as captured
    post: 1veoo6t
    author: CeramicDrip
    created_utc: 1785788226
    title: As a community, we should fully audit Trezor’s open source software
    body:
    Basically the title.
    
    Im sure we all want to determine what the safest hardware wallet is after this whole ColdCard scenario. So i propose that we audit Trezor as a community. They have stood the test of time, but now its time to test their code.
    
    Im a software engineer and im willing to help in whatever way possible, with some experience in cryptography. 
    
    comment: p1in4b3
    parent: t3_1veoo6t
    author: TheresNoSecondBest
    created_utc: 1785788487
    edited: false
    body:
    >Im sure we all want to determine what the safest hardware wallet is
    
    Then forget Trezor, audit JadePlus, Krux and SeedSigner instead. 
    
    comment: p1iob9o
    parent: t3_1veoo6t
    author: TheBigLR901
    created_utc: 1785788803
    edited: false
    body:
    Apparently you can just run it through AI, let it noodle on the code for 8 minutes,  and it will list any security issues.
    
    comment: p1iojpf
    parent: t1_p1in4b3
    author: RedditTooAddictive
    created_utc: 1785788865
    edited: false
    body:
    Why?
    
    comment: p1iotom
    parent: t3_1veoo6t
    author: lovemyhawks

    Excerpt only. The complete copy is held offline and backs quotations on this site. The original publication remains the canonical public source.

  9. source content difference between and source content +8 -0

    The Reddit thread gained 1 new comment.

    seen · Captured here 16,195 chars
    What changed from the previous capture 8 lines
     edited: false
     body:
     Thats done absolutely zilch to harm its security. 
    +
    +comment: p1pp5ky
    +parent: t1_p1pf488
    +author: Laukess
    +created_utc: 1785872262
    +edited: false
    +body:
    +So it's air gapped because you don't see the value in it, even though it's not actually air gapped?
    
    Extracted text as captured
    post: 1veoo6t
    author: CeramicDrip
    created_utc: 1785788226
    title: As a community, we should fully audit Trezor’s open source software
    body:
    Basically the title.
    
    Im sure we all want to determine what the safest hardware wallet is after this whole ColdCard scenario. So i propose that we audit Trezor as a community. They have stood the test of time, but now its time to test their code.
    
    Im a software engineer and im willing to help in whatever way possible, with some experience in cryptography. 
    
    comment: p1in4b3
    parent: t3_1veoo6t
    author: TheresNoSecondBest
    created_utc: 1785788487
    edited: false
    body:
    >Im sure we all want to determine what the safest hardware wallet is
    
    Then forget Trezor, audit JadePlus, Krux and SeedSigner instead. 
    
    comment: p1iob9o
    parent: t3_1veoo6t
    author: TheBigLR901
    created_utc: 1785788803
    edited: false
    body:
    Apparently you can just run it through AI, let it noodle on the code for 8 minutes,  and it will list any security issues.
    
    comment: p1iojpf
    parent: t1_p1in4b3
    author: RedditTooAddictive
    created_utc: 1785788865
    edited: false
    body:
    Why?
    
    comment: p1iotom
    parent: t3_1veoo6t
    author: lovemyhawks

    Excerpt only. The complete copy is held offline and backs quotations on this site. The original publication remains the canonical public source.

  10. source content difference between and source content +8 -0

    The Reddit thread gained 1 new comment.

    seen · Captured here 15,998 chars
    What changed from the previous capture 8 lines
     edited: false
     body:
     It’s still not air gapped by definition. That’s my point. 
    +
    +comment: p1pf488
    +parent: t1_p1pcn0y
    +author: ItsAlwaysThemBooBoo
    +created_utc: 1785869661
    +edited: false
    +body:
    +Thats done absolutely zilch to harm its security. 
    
    Extracted text as captured
    post: 1veoo6t
    author: CeramicDrip
    created_utc: 1785788226
    title: As a community, we should fully audit Trezor’s open source software
    body:
    Basically the title.
    
    Im sure we all want to determine what the safest hardware wallet is after this whole ColdCard scenario. So i propose that we audit Trezor as a community. They have stood the test of time, but now its time to test their code.
    
    Im a software engineer and im willing to help in whatever way possible, with some experience in cryptography. 
    
    comment: p1in4b3
    parent: t3_1veoo6t
    author: TheresNoSecondBest
    created_utc: 1785788487
    edited: false
    body:
    >Im sure we all want to determine what the safest hardware wallet is
    
    Then forget Trezor, audit JadePlus, Krux and SeedSigner instead. 
    
    comment: p1iob9o
    parent: t3_1veoo6t
    author: TheBigLR901
    created_utc: 1785788803
    edited: false
    body:
    Apparently you can just run it through AI, let it noodle on the code for 8 minutes,  and it will list any security issues.
    
    comment: p1iojpf
    parent: t1_p1in4b3
    author: RedditTooAddictive
    created_utc: 1785788865
    edited: false
    body:
    Why?
    
    comment: p1iotom
    parent: t3_1veoo6t
    author: lovemyhawks

    Excerpt only. The complete copy is held offline and backs quotations on this site. The original publication remains the canonical public source.

  11. source content difference between and source content +16 -0

    The Reddit thread gained 2 new comments.

    seen · Captured here 15,838 chars
    What changed from the previous capture 16 lines
     edited: false
     body:
     Correct, that is what I understand. 
    +
    +comment: p1pc0z1
    +parent: t1_p1khsvi
    +author: ItsAlwaysThemBooBoo
    +created_utc: 1785868886
    +edited: false
    +body:
    +Means nothing. A cable isnt a major security breach. 
    +
    +comment: p1pcn0y
    +parent: t1_p1pc0z1
    +author: deny_by_default
    +created_utc: 1785869042
    +edited: false
    +body:
    +It’s still not air gapped by definition. That’s my point. 
    
    Extracted text as captured
    post: 1veoo6t
    author: CeramicDrip
    created_utc: 1785788226
    title: As a community, we should fully audit Trezor’s open source software
    body:
    Basically the title.
    
    Im sure we all want to determine what the safest hardware wallet is after this whole ColdCard scenario. So i propose that we audit Trezor as a community. They have stood the test of time, but now its time to test their code.
    
    Im a software engineer and im willing to help in whatever way possible, with some experience in cryptography. 
    
    comment: p1in4b3
    parent: t3_1veoo6t
    author: TheresNoSecondBest
    created_utc: 1785788487
    edited: false
    body:
    >Im sure we all want to determine what the safest hardware wallet is
    
    Then forget Trezor, audit JadePlus, Krux and SeedSigner instead. 
    
    comment: p1iob9o
    parent: t3_1veoo6t
    author: TheBigLR901
    created_utc: 1785788803
    edited: false
    body:
    Apparently you can just run it through AI, let it noodle on the code for 8 minutes,  and it will list any security issues.
    
    comment: p1iojpf
    parent: t1_p1in4b3
    author: RedditTooAddictive
    created_utc: 1785788865
    edited: false
    body:
    Why?
    
    comment: p1iotom
    parent: t3_1veoo6t
    author: lovemyhawks

    Excerpt only. The complete copy is held offline and backs quotations on this site. The original publication remains the canonical public source.

  12. source content difference between and source content +4 -18

    An existing Reddit comment no longer appeared in the captured thread.

    seen · Captured here 15,511 chars
    What changed from the previous capture 22 lines
     
     comment: p1ja9ho
     parent: t1_p1iob9o
    -author: naked_number_one
    +author: [deleted]
     created_utc: 1785794819
     edited: false
     body:
    -You can actually verify if AI security audit as good as you think. This bug went public only a few days ago, which is after the training cutoff of basically every model people are running. That’s a rare clean condition: the model can’t have memorized the disclosure, the CVE, or any blog post, because none of that existed when it was trained.
    -
    -So the setup is simple. Check out the ColdCard code from before the fix, reset the git history so the model can’t see the patch, and run Claude Code (or whatever tool you prefer) with only local file access enabled, so it can’t look anything up online. Then prompt it to audit the code and see if it actually finds the bug.
    -
    -If it does, that’s real capability rather than recalled disclosure. Given how many people are suddenly pushing AI for security audits, this feels like a perfect chance to test the claim under conditions that actually rule AI ability to cheat.
    -
    -To make it honest make sure the prompt is generic, something like “audit this codebase for vulnerabilities,” don’t steer it toward the right file or bug class.
    +[removed]
     
     comment: p1jaf4k
     parent: t1_p1j5xd0
     
     comment: p1lkpg1
     parent: t1_p1ke7j5
    -author: naked_number_one
    +author: [deleted]
     created_utc: 1785824170
     edited: false
     body:
    -Your opinion adds a lot to this discussion!
    +[removed]
     
     comment: p1lp6nq
     parent: t3_1veoo6t
     body:
     I'd like the help, but unfortunately, I have zero experience coding software.  I'm just a mid level IT admin and tech support guy who dropped out of community college.
     
    -comment: p1nm10f
    -parent: t1_p1m7jed
    -author: naked_number_one
    -created_utc: 1785853204
    -edited: false
    -body:
    -[ Removed by Reddit ]
    -
     comment: p1oeuxw
     parent: t1_p1lkpg1
     author: SquiggerDigger
    
    Extracted text as captured
    post: 1veoo6t
    author: CeramicDrip
    created_utc: 1785788226
    title: As a community, we should fully audit Trezor’s open source software
    body:
    Basically the title.
    
    Im sure we all want to determine what the safest hardware wallet is after this whole ColdCard scenario. So i propose that we audit Trezor as a community. They have stood the test of time, but now its time to test their code.
    
    Im a software engineer and im willing to help in whatever way possible, with some experience in cryptography. 
    
    comment: p1in4b3
    parent: t3_1veoo6t
    author: TheresNoSecondBest
    created_utc: 1785788487
    edited: false
    body:
    >Im sure we all want to determine what the safest hardware wallet is
    
    Then forget Trezor, audit JadePlus, Krux and SeedSigner instead. 
    
    comment: p1iob9o
    parent: t3_1veoo6t
    author: TheBigLR901
    created_utc: 1785788803
    edited: false
    body:
    Apparently you can just run it through AI, let it noodle on the code for 8 minutes,  and it will list any security issues.
    
    comment: p1iojpf
    parent: t1_p1in4b3
    author: RedditTooAddictive
    created_utc: 1785788865
    edited: false
    body:
    Why?
    
    comment: p1iotom
    parent: t3_1veoo6t
    author: lovemyhawks

    Excerpt only. The complete copy is held offline and backs quotations on this site. The original publication remains the canonical public source.

  13. source content difference between and source content +16 -0

    The Reddit thread gained 2 new comments.

    seen · Captured here 16,751 chars
    What changed from the previous capture 16 lines
     Yes and offering a verbatim repeat of what an AI bot would tell me is helping the conversation too
     
     That's like saying generative images is artistry 
    +
    +comment: p1okrpj
    +parent: t1_p1k51go
    +author: Dashizz6357
    +created_utc: 1785862141
    +edited: false
    +body:
    +So would this be seed phrases generated prior to the bug? Everything I’m seeing is that those are safe.
    +
    +comment: p1olcdi
    +parent: t1_p1okrpj
    +author: RaiseLife1651
    +created_utc: 1785862282
    +edited: false
    +body:
    +Correct, that is what I understand. 
    
    Extracted text as captured
    post: 1veoo6t
    author: CeramicDrip
    created_utc: 1785788226
    title: As a community, we should fully audit Trezor’s open source software
    body:
    Basically the title.
    
    Im sure we all want to determine what the safest hardware wallet is after this whole ColdCard scenario. So i propose that we audit Trezor as a community. They have stood the test of time, but now its time to test their code.
    
    Im a software engineer and im willing to help in whatever way possible, with some experience in cryptography. 
    
    comment: p1in4b3
    parent: t3_1veoo6t
    author: TheresNoSecondBest
    created_utc: 1785788487
    edited: false
    body:
    >Im sure we all want to determine what the safest hardware wallet is
    
    Then forget Trezor, audit JadePlus, Krux and SeedSigner instead. 
    
    comment: p1iob9o
    parent: t3_1veoo6t
    author: TheBigLR901
    created_utc: 1785788803
    edited: false
    body:
    Apparently you can just run it through AI, let it noodle on the code for 8 minutes,  and it will list any security issues.
    
    comment: p1iojpf
    parent: t1_p1in4b3
    author: RedditTooAddictive
    created_utc: 1785788865
    edited: false
    body:
    Why?
    
    comment: p1iotom
    parent: t3_1veoo6t
    author: lovemyhawks

    Excerpt only. The complete copy is held offline and backs quotations on this site. The original publication remains the canonical public source.

  14. source content difference between and source content +10 -0

    The Reddit thread gained 1 new comment.

    seen · Captured here 16,406 chars
    What changed from the previous capture 10 lines
     edited: false
     body:
     [ Removed by Reddit ]
    +
    +comment: p1oeuxw
    +parent: t1_p1lkpg1
    +author: SquiggerDigger
    +created_utc: 1785860664
    +edited: false
    +body:
    +Yes and offering a verbatim repeat of what an AI bot would tell me is helping the conversation too
    +
    +That's like saying generative images is artistry 
    
    Extracted text as captured
    post: 1veoo6t
    author: CeramicDrip
    created_utc: 1785788226
    title: As a community, we should fully audit Trezor’s open source software
    body:
    Basically the title.
    
    Im sure we all want to determine what the safest hardware wallet is after this whole ColdCard scenario. So i propose that we audit Trezor as a community. They have stood the test of time, but now its time to test their code.
    
    Im a software engineer and im willing to help in whatever way possible, with some experience in cryptography. 
    
    comment: p1in4b3
    parent: t3_1veoo6t
    author: TheresNoSecondBest
    created_utc: 1785788487
    edited: false
    body:
    >Im sure we all want to determine what the safest hardware wallet is
    
    Then forget Trezor, audit JadePlus, Krux and SeedSigner instead. 
    
    comment: p1iob9o
    parent: t3_1veoo6t
    author: TheBigLR901
    created_utc: 1785788803
    edited: false
    body:
    Apparently you can just run it through AI, let it noodle on the code for 8 minutes,  and it will list any security issues.
    
    comment: p1iojpf
    parent: t1_p1in4b3
    author: RedditTooAddictive
    created_utc: 1785788865
    edited: false
    body:
    Why?
    
    comment: p1iotom
    parent: t3_1veoo6t
    author: lovemyhawks

    Excerpt only. The complete copy is held offline and backs quotations on this site. The original publication remains the canonical public source.

  15. source content difference between and source content +16 -0

    2 new Reddit comments were posted, including 00-SilverShot,naked_number_one.

    seen · Captured here 16,152 chars
    What changed from the previous capture 16 lines
     edited: false
     body:
     How safe is electrum ?
    +
    +comment: p1nlffv
    +parent: t3_1veoo6t
    +author: 00-SilverShot
    +created_utc: 1785853042
    +edited: false
    +body:
    +I'd like the help, but unfortunately, I have zero experience coding software.  I'm just a mid level IT admin and tech support guy who dropped out of community college.
    +
    +comment: p1nm10f
    +parent: t1_p1m7jed
    +author: naked_number_one
    +created_utc: 1785853204
    +edited: false
    +body:
    +[ Removed by Reddit ]
    
    Extracted text as captured
    post: 1veoo6t
    author: CeramicDrip
    created_utc: 1785788226
    title: As a community, we should fully audit Trezor’s open source software
    body:
    Basically the title.
    
    Im sure we all want to determine what the safest hardware wallet is after this whole ColdCard scenario. So i propose that we audit Trezor as a community. They have stood the test of time, but now its time to test their code.
    
    Im a software engineer and im willing to help in whatever way possible, with some experience in cryptography. 
    
    comment: p1in4b3
    parent: t3_1veoo6t
    author: TheresNoSecondBest
    created_utc: 1785788487
    edited: false
    body:
    >Im sure we all want to determine what the safest hardware wallet is
    
    Then forget Trezor, audit JadePlus, Krux and SeedSigner instead. 
    
    comment: p1iob9o
    parent: t3_1veoo6t
    author: TheBigLR901
    created_utc: 1785788803
    edited: false
    body:
    Apparently you can just run it through AI, let it noodle on the code for 8 minutes,  and it will list any security issues.
    
    comment: p1iojpf
    parent: t1_p1in4b3
    author: RedditTooAddictive
    created_utc: 1785788865
    edited: false
    body:
    Why?
    
    comment: p1iotom
    parent: t3_1veoo6t
    author: lovemyhawks

    Excerpt only. The complete copy is held offline and backs quotations on this site. The original publication remains the canonical public source.

  16. source content difference between and source content +50 -0

    6 new Reddit comments were posted, including jungle,opossum_cz,Murky_Ad6160.

    seen · Captured here 15,753 chars
    What changed from the previous capture 50 lines
     edited: false
     body:
     Wouldn't (or shouldn't) frontier models refuse to do this?
    +
    +comment: p1m9mu8
    +parent: t1_p1jeplf
    +author: jungle
    +created_utc: 1785836473
    +edited: false
    +body:
    +Also go back the git history. If previous versions had a weak random generation, no updates would have fixed those wallets.
    +
    +comment: p1mfq6d
    +parent: t1_p1lektv
    +author: opossum_cz
    +created_utc: 1785839277
    +edited: false
    +body:
    +Do you know what is great? You don't need to, don't generate seeds on the devices at all. Flip a fucking coin.
    +
    +comment: p1mk60k
    +parent: t3_1veoo6t
    +author: Murky_Ad6160
    +created_utc: 1785841136
    +edited: false
    +body:
    +I use OneKey and I never see it mentioned. Is it not good?
    +
    +comment: p1msfe7
    +parent: t3_1veoo6t
    +author: SuchTrezorVeryCrypto
    +created_utc: 1785844270
    +edited: false
    +body:
    +Hi from Trezor,
    +
    +do it
    +
    +comment: p1n5byu
    +parent: t1_p1leqxd
    +author: Final_Bite_7228
    +created_utc: 1785848484
    +edited: false
    +body:
    +Hey! Community!
    +
    +comment: p1n9g84
    +parent: t3_1veoo6t
    +author: Beatrix_0000
    +created_utc: 1785849702
    +edited: false
    +body:
    +How safe is electrum ?
    
    Extracted text as captured
    post: 1veoo6t
    author: CeramicDrip
    created_utc: 1785788226
    title: As a community, we should fully audit Trezor’s open source software
    body:
    Basically the title.
    
    Im sure we all want to determine what the safest hardware wallet is after this whole ColdCard scenario. So i propose that we audit Trezor as a community. They have stood the test of time, but now its time to test their code.
    
    Im a software engineer and im willing to help in whatever way possible, with some experience in cryptography. 
    
    comment: p1in4b3
    parent: t3_1veoo6t
    author: TheresNoSecondBest
    created_utc: 1785788487
    edited: false
    body:
    >Im sure we all want to determine what the safest hardware wallet is
    
    Then forget Trezor, audit JadePlus, Krux and SeedSigner instead. 
    
    comment: p1iob9o
    parent: t3_1veoo6t
    author: TheBigLR901
    created_utc: 1785788803
    edited: false
    body:
    Apparently you can just run it through AI, let it noodle on the code for 8 minutes,  and it will list any security issues.
    
    comment: p1iojpf
    parent: t1_p1in4b3
    author: RedditTooAddictive
    created_utc: 1785788865
    edited: false
    body:
    Why?
    
    comment: p1iotom
    parent: t3_1veoo6t
    author: lovemyhawks

    Excerpt only. The complete copy is held offline and backs quotations on this site. The original publication remains the canonical public source.

  17. Earliest copy held
    seen · Captured here 14,782 chars
    Extracted text as captured
    post: 1veoo6t
    author: CeramicDrip
    created_utc: 1785788226
    title: As a community, we should fully audit Trezor’s open source software
    body:
    Basically the title.
    
    Im sure we all want to determine what the safest hardware wallet is after this whole ColdCard scenario. So i propose that we audit Trezor as a community. They have stood the test of time, but now its time to test their code.
    
    Im a software engineer and im willing to help in whatever way possible, with some experience in cryptography. 
    
    comment: p1in4b3
    parent: t3_1veoo6t
    author: TheresNoSecondBest
    created_utc: 1785788487
    edited: false
    body:
    >Im sure we all want to determine what the safest hardware wallet is
    
    Then forget Trezor, audit JadePlus, Krux and SeedSigner instead. 
    
    comment: p1iob9o
    parent: t3_1veoo6t
    author: TheBigLR901
    created_utc: 1785788803
    edited: false
    body:
    Apparently you can just run it through AI, let it noodle on the code for 8 minutes,  and it will list any security issues.
    
    comment: p1iojpf
    parent: t1_p1in4b3
    author: RedditTooAddictive
    created_utc: 1785788865
    edited: false
    body:
    Why?
    
    comment: p1iotom
    parent: t3_1veoo6t
    author: lovemyhawks

    Excerpt only. The complete copy is held offline and backs quotations on this site. The original publication remains the canonical public source.

How to check this yourself

The excerpts and plain unified diffs above show the text this project held and how it changed. To verify a quotation, compare it against the page itself or against the Internet Archive's copies, which are independent of this project.

Complete captures are held offline rather than mirrored here, so this page shows diffs and excerpts. If a quotation is ever disputed, the full copy can be produced. Ask.