COLDCARD RNG incident the public record, collected and explained
Informational only, and this site never asks for your seed words. details

Informational only. This is an open source collection of what others have published about the incident, together with an explanation of it. It is not financial, security or legal advice, and not a substitute for professional advice about your own situation. It is not affiliated with, endorsed by, or speaking for Coinkite. Material is attributed and quoted as published; where sources disagree their scenarios are kept separate with their assumptions rather than reconciled into one answer. Everything is meant to be checked against the linked evidence rather than taken on trust. Act on your own judgement about a particular situation. Editorial standards and corrections.

Do not disclose recovery material to a website, form, message or support account. This site never asks for it, and contributions containing recovery words or private keys are not accepted.

r/coldcard: what Coinkite could have done had it found the flaw first

reddit-vendor-counterfactual

https://www.reddit.com/r/coldcard/comments/1vduxyg/what_could_coinkite_have_done_if_they_discovered/

Latest reviewed change

source content difference between and

The Reddit thread gained a new participant comment proposing whitehat self-sweep or closed-source migration as vendor options.

seen +12 -0 full history below
 edited: false
 body:
 By now, I am no longer excluding the ‘retirement attack’ scenario. 😢
+
+comment: p2crga2
+parent: t3_1vduxyg
+author: _gianlucag_
+created_utc: 1786141225

First lines only. The complete diff is in the timeline below.

Organisation
reddit
Evidence role
Community discussion
Published
not established
Source changes
5
Detected differences
5
Unreviewed
0
Copies held
6

Every check is recorded, including checks that found no text change. A detected edit is therefore bounded between two checks. The publisher's exact save time is not observable from this record. Last checked .

  1. source content difference between and Current source content +12 -0

    The Reddit thread gained a new participant comment proposing whitehat self-sweep or closed-source migration as vendor options.

    seen · Captured here 17,219 chars
    What changed from the previous capture 12 lines
     edited: false
     body:
     By now, I am no longer excluding the ‘retirement attack’ scenario. 😢
    +
    +comment: p2crga2
    +parent: t3_1vduxyg
    +author: _gianlucag_
    +created_utc: 1786141225
    +edited: 1786141414
    +body:
    +The only viable option would have been to "steal" all the btc by themselves, effectively whitehat-ing their way out, then returning the bitcoins to the original owners.
    +
    +Or
    +
    +go partially "closed source" by removing the github account, dont disclose the issue, ask people, one by one, to recreate the seed and move their funds there
    
    Extracted text as captured
    post: 1vduxyg
    author: therealjeku
    created_utc: 1785708102
    title: What could Coinkite have done if they discovered the flaw first?
    body:
    Let’s be hypothetical and imagine Coinkite discovered this flaw on their own in, say, January 2026. What could they have done? 
    
    If they announced the flaw with a firmware fix then attackers could quickly get started on harvesting BTC before all the affected cards are safely transferred. If they announced a firmware fix but not the flaw, many people won’t bother updating their firmware. Hell, my MK4 sat for over two years in a safe.   Not to mention their new firmware code would be viewable and it would surely point out a fix for the RNG which would lead some to ascertain this huge underlying issue.
    
    Not to defend them, but I’m not sure they would have had any favourable way out of this mess having sold so many affected wallets over many years.
    
    comment: p1c3w9z
    parent: t3_1vduxyg
    author: Quirky-Reveal-1669
    created_utc: 1785708409
    edited: false
    body:
    No not true. The organization of the execution of this theft will have taken time. If CoinKite was the first with this knowledge, they would have first tried to communicate that a new seed should be generated with dice, and with a passphrase. No further detailed information given, just pressing the utmost urgency. After that, a firmware update would be the next step. 
    
    comment: p1c51f9
    parent: t1_p1c3w9z
    author: cilicia3k3
    created_utc: 1785708749
    edited: false
    body:
    The second they sent a private email to a YouTuber , let’s say Ben , it would be game over 
    
    comment: p1c8cwk
    parent: t1_p1c3w9z
    author: No_Position_8581
    created_utc: 1785709777
    edited: false
    body:
    Anything they did would have been a tip off. It would have saved more people but people would immediately start looking at their rng
    
    comment: p1caf84
    parent: t1_p1c8cwk
    author: Quirky-Reveal-1669
    created_utc: 1785710427
    edited: false

    Excerpt only. The complete copy is held offline and backs quotations on this site. The original publication remains the canonical public source.

  2. source content difference between and source content +8 -0

    New comment says the author no longer excludes the retirement attack scenario.

    seen · Captured here 16,781 chars
    What changed from the previous capture 8 lines
     edited: false
     body:
     Its game over as soon there is a whisper about there being an issue with seed generation entropy. It does not take long to find the weakness when knowing there is one.
    +
    +comment: p24tbwm
    +parent: t1_p2279bk
    +author: Quirky-Reveal-1669
    +created_utc: 1786048245
    +edited: false
    +body:
    +By now, I am no longer excluding the ‘retirement attack’ scenario. 😢
    
    Extracted text as captured
    post: 1vduxyg
    author: therealjeku
    created_utc: 1785708102
    title: What could Coinkite have done if they discovered the flaw first?
    body:
    Let’s be hypothetical and imagine Coinkite discovered this flaw on their own in, say, January 2026. What could they have done? 
    
    If they announced the flaw with a firmware fix then attackers could quickly get started on harvesting BTC before all the affected cards are safely transferred. If they announced a firmware fix but not the flaw, many people won’t bother updating their firmware. Hell, my MK4 sat for over two years in a safe.   Not to mention their new firmware code would be viewable and it would surely point out a fix for the RNG which would lead some to ascertain this huge underlying issue.
    
    Not to defend them, but I’m not sure they would have had any favourable way out of this mess having sold so many affected wallets over many years.
    
    comment: p1c3w9z
    parent: t3_1vduxyg
    author: Quirky-Reveal-1669
    created_utc: 1785708409
    edited: false
    body:
    No not true. The organization of the execution of this theft will have taken time. If CoinKite was the first with this knowledge, they would have first tried to communicate that a new seed should be generated with dice, and with a passphrase. No further detailed information given, just pressing the utmost urgency. After that, a firmware update would be the next step. 
    
    comment: p1c51f9
    parent: t1_p1c3w9z
    author: cilicia3k3
    created_utc: 1785708749
    edited: false
    body:
    The second they sent a private email to a YouTuber , let’s say Ben , it would be game over 
    
    comment: p1c8cwk
    parent: t1_p1c3w9z
    author: No_Position_8581
    created_utc: 1785709777
    edited: false
    body:
    Anything they did would have been a tip off. It would have saved more people but people would immediately start looking at their rng
    
    comment: p1caf84
    parent: t1_p1c8cwk
    author: Quirky-Reveal-1669
    created_utc: 1785710427
    edited: false

    Excerpt only. The complete copy is held offline and backs quotations on this site. The original publication remains the canonical public source.

  3. source content difference between and source content +10 -2

    One comment was edited (typo fix in the dice-roll weakness explanation) and a new comment argues it is game over once a seed-generation entropy weakness is whispered about.

    seen · Captured here 16,603 chars
    What changed from the previous capture 12 lines
     parent: t1_p1ccc66
     author: Charming-Designer944
     created_utc: 1785717372
    -edited: false
    +edited: 1786024058
     body:
     It's another issue entirely, but with a very similar result.
     
      - no minimum requirement on the number of dice rolls
      - easy to mix up the options of mixing dice rolls into the intenal entropy vs building the entropy entirely from the dice rolls alone.
     
    -Combined it can result in users selecting the option of only usinng the dice rolls, and then only perform a handful number of dice roolls thinking that the dice rolls are just additional security to the internal entropy, not replacing it entirely and not realize that they created a vere weak seed.
    +Combined it can result in users selecting the option of only usinng the dice rolls, and then only perform a handful number of dice roolls thinking that the dice rolls are just additional security to the internal entropy, not replacing it entirely and not realize that they created a very weak seed.
     
     I believe this issue is partially fixed in later firmwares, presenting a warning in main seed generation when using weak dice rolls, but still present when dice rolling a temporary seed.
     
     edited: false
     body:
     I would guess we are beyond that stage at this point, unfortunately. The awareness of the attack is widespread and sweeps are still occurring which means if there were a white hat phase, it would be concluded by now and the remainder we are seeing is black hat, or at least mixed with black hat.
    +
    +comment: p2279bk
    +parent: t1_p1c3w9z
    +author: Charming-Designer944
    +created_utc: 1786024345
    +edited: false
    +body:
    +Its game over as soon there is a whisper about there being an issue with seed generation entropy. It does not take long to find the weakness when knowing there is one.
    
    Extracted text as captured
    post: 1vduxyg
    author: therealjeku
    created_utc: 1785708102
    title: What could Coinkite have done if they discovered the flaw first?
    body:
    Let’s be hypothetical and imagine Coinkite discovered this flaw on their own in, say, January 2026. What could they have done? 
    
    If they announced the flaw with a firmware fix then attackers could quickly get started on harvesting BTC before all the affected cards are safely transferred. If they announced a firmware fix but not the flaw, many people won’t bother updating their firmware. Hell, my MK4 sat for over two years in a safe.   Not to mention their new firmware code would be viewable and it would surely point out a fix for the RNG which would lead some to ascertain this huge underlying issue.
    
    Not to defend them, but I’m not sure they would have had any favourable way out of this mess having sold so many affected wallets over many years.
    
    comment: p1c3w9z
    parent: t3_1vduxyg
    author: Quirky-Reveal-1669
    created_utc: 1785708409
    edited: false
    body:
    No not true. The organization of the execution of this theft will have taken time. If CoinKite was the first with this knowledge, they would have first tried to communicate that a new seed should be generated with dice, and with a passphrase. No further detailed information given, just pressing the utmost urgency. After that, a firmware update would be the next step. 
    
    comment: p1c51f9
    parent: t1_p1c3w9z
    author: cilicia3k3
    created_utc: 1785708749
    edited: false
    body:
    The second they sent a private email to a YouTuber , let’s say Ben , it would be game over 
    
    comment: p1c8cwk
    parent: t1_p1c3w9z
    author: No_Position_8581
    created_utc: 1785709777
    edited: false
    body:
    Anything they did would have been a tip off. It would have saved more people but people would immediately start looking at their rng
    
    comment: p1caf84
    parent: t1_p1c8cwk
    author: Quirky-Reveal-1669
    created_utc: 1785710427
    edited: false

    Excerpt only. The complete copy is held offline and backs quotations on this site. The original publication remains the canonical public source.

  4. source content difference between and source content +8 -0

    The Reddit thread gained 1 new comment.

    seen · Captured here 16,320 chars
    What changed from the previous capture 8 lines
     edited: false
     body:
     There would be several possible options, all of them better than the actual outcome.
    +
    +comment: p1pgk39
    +parent: t1_p1ef0ri
    +author: IInsulince
    +created_utc: 1785870028
    +edited: false
    +body:
    +I would guess we are beyond that stage at this point, unfortunately. The awareness of the attack is widespread and sweeps are still occurring which means if there were a white hat phase, it would be concluded by now and the remainder we are seeing is black hat, or at least mixed with black hat.
    
    Extracted text as captured
    post: 1vduxyg
    author: therealjeku
    created_utc: 1785708102
    title: What could Coinkite have done if they discovered the flaw first?
    body:
    Let’s be hypothetical and imagine Coinkite discovered this flaw on their own in, say, January 2026. What could they have done? 
    
    If they announced the flaw with a firmware fix then attackers could quickly get started on harvesting BTC before all the affected cards are safely transferred. If they announced a firmware fix but not the flaw, many people won’t bother updating their firmware. Hell, my MK4 sat for over two years in a safe.   Not to mention their new firmware code would be viewable and it would surely point out a fix for the RNG which would lead some to ascertain this huge underlying issue.
    
    Not to defend them, but I’m not sure they would have had any favourable way out of this mess having sold so many affected wallets over many years.
    
    comment: p1c3w9z
    parent: t3_1vduxyg
    author: Quirky-Reveal-1669
    created_utc: 1785708409
    edited: false
    body:
    No not true. The organization of the execution of this theft will have taken time. If CoinKite was the first with this knowledge, they would have first tried to communicate that a new seed should be generated with dice, and with a passphrase. No further detailed information given, just pressing the utmost urgency. After that, a firmware update would be the next step. 
    
    comment: p1c51f9
    parent: t1_p1c3w9z
    author: cilicia3k3
    created_utc: 1785708749
    edited: false
    body:
    The second they sent a private email to a YouTuber , let’s say Ben , it would be game over 
    
    comment: p1c8cwk
    parent: t1_p1c3w9z
    author: No_Position_8581
    created_utc: 1785709777
    edited: false
    body:
    Anything they did would have been a tip off. It would have saved more people but people would immediately start looking at their rng
    
    comment: p1caf84
    parent: t1_p1c8cwk
    author: Quirky-Reveal-1669
    created_utc: 1785710427
    edited: false

    Excerpt only. The complete copy is held offline and backs quotations on this site. The original publication remains the canonical public source.

  5. source content difference between and source content +8 -0

    1 new Reddit comment was posted, including iloverunning11.

    seen · Captured here 15,924 chars
    What changed from the previous capture 8 lines
     edited: false
     body:
     The flaw was found, then they had to search all the combinations and check if those wallets existed.  Gemini says they prepped for at least a month.  Had they not had time, they would have needed at least a 10 hours to find the flaw and learn the combinations and then a script running hours on the easiest ones.  There would have been plenty of time to move keys for most people.  Especially if the took the code offline and then told people to get a new seed key with dice, there would have been no clues to the issue
    +
    +comment: p1miln5
    +parent: t3_1vduxyg
    +author: iloverunning11
    +created_utc: 1785840497
    +edited: false
    +body:
    +There would be several possible options, all of them better than the actual outcome.
    
    Extracted text as captured
    post: 1vduxyg
    author: therealjeku
    created_utc: 1785708102
    title: What could Coinkite have done if they discovered the flaw first?
    body:
    Let’s be hypothetical and imagine Coinkite discovered this flaw on their own in, say, January 2026. What could they have done? 
    
    If they announced the flaw with a firmware fix then attackers could quickly get started on harvesting BTC before all the affected cards are safely transferred. If they announced a firmware fix but not the flaw, many people won’t bother updating their firmware. Hell, my MK4 sat for over two years in a safe.   Not to mention their new firmware code would be viewable and it would surely point out a fix for the RNG which would lead some to ascertain this huge underlying issue.
    
    Not to defend them, but I’m not sure they would have had any favourable way out of this mess having sold so many affected wallets over many years.
    
    comment: p1c3w9z
    parent: t3_1vduxyg
    author: Quirky-Reveal-1669
    created_utc: 1785708409
    edited: false
    body:
    No not true. The organization of the execution of this theft will have taken time. If CoinKite was the first with this knowledge, they would have first tried to communicate that a new seed should be generated with dice, and with a passphrase. No further detailed information given, just pressing the utmost urgency. After that, a firmware update would be the next step. 
    
    comment: p1c51f9
    parent: t1_p1c3w9z
    author: cilicia3k3
    created_utc: 1785708749
    edited: false
    body:
    The second they sent a private email to a YouTuber , let’s say Ben , it would be game over 
    
    comment: p1c8cwk
    parent: t1_p1c3w9z
    author: No_Position_8581
    created_utc: 1785709777
    edited: false
    body:
    Anything they did would have been a tip off. It would have saved more people but people would immediately start looking at their rng
    
    comment: p1caf84
    parent: t1_p1c8cwk
    author: Quirky-Reveal-1669
    created_utc: 1785710427
    edited: false

    Excerpt only. The complete copy is held offline and backs quotations on this site. The original publication remains the canonical public source.

  6. Earliest copy held
    seen · Captured here 15,735 chars
    Extracted text as captured
    post: 1vduxyg
    author: therealjeku
    created_utc: 1785708102
    title: What could Coinkite have done if they discovered the flaw first?
    body:
    Let’s be hypothetical and imagine Coinkite discovered this flaw on their own in, say, January 2026. What could they have done? 
    
    If they announced the flaw with a firmware fix then attackers could quickly get started on harvesting BTC before all the affected cards are safely transferred. If they announced a firmware fix but not the flaw, many people won’t bother updating their firmware. Hell, my MK4 sat for over two years in a safe.   Not to mention their new firmware code would be viewable and it would surely point out a fix for the RNG which would lead some to ascertain this huge underlying issue.
    
    Not to defend them, but I’m not sure they would have had any favourable way out of this mess having sold so many affected wallets over many years.
    
    comment: p1c3w9z
    parent: t3_1vduxyg
    author: Quirky-Reveal-1669
    created_utc: 1785708409
    edited: false
    body:
    No not true. The organization of the execution of this theft will have taken time. If CoinKite was the first with this knowledge, they would have first tried to communicate that a new seed should be generated with dice, and with a passphrase. No further detailed information given, just pressing the utmost urgency. After that, a firmware update would be the next step. 
    
    comment: p1c51f9
    parent: t1_p1c3w9z
    author: cilicia3k3
    created_utc: 1785708749
    edited: false
    body:
    The second they sent a private email to a YouTuber , let’s say Ben , it would be game over 
    
    comment: p1c8cwk
    parent: t1_p1c3w9z
    author: No_Position_8581
    created_utc: 1785709777
    edited: false
    body:
    Anything they did would have been a tip off. It would have saved more people but people would immediately start looking at their rng
    
    comment: p1caf84
    parent: t1_p1c8cwk
    author: Quirky-Reveal-1669
    created_utc: 1785710427
    edited: false

    Excerpt only. The complete copy is held offline and backs quotations on this site. The original publication remains the canonical public source.

How to check this yourself

The excerpts and plain unified diffs above show the text this project held and how it changed. To verify a quotation, compare it against the page itself or against the Internet Archive's copies, which are independent of this project.

Complete captures are held offline rather than mirrored here, so this page shows diffs and excerpts. If a quotation is ever disputed, the full copy can be produced. Ask.