r/coldcard: what Coinkite could have done had it found the flaw first
reddit-vendor-counterfactual
https://www.reddit.com/r/coldcard/comments/1vduxyg/what_could_coinkite_have_done_if_they_discovered/
Latest reviewed change
source content difference between and
The Reddit thread gained a new participant comment proposing whitehat self-sweep or closed-source migration as vendor options.
edited: false
body:
By now, I am no longer excluding the ‘retirement attack’ scenario. 😢
+
+comment: p2crga2
+parent: t3_1vduxyg
+author: _gianlucag_
+created_utc: 1786141225
First lines only. The complete diff is in the timeline below.
- Organisation
- Evidence role
- Community discussion
- Published
- not established
- Source changes
- 5
- Detected differences
- 5
- Unreviewed
- 0
- Copies held
- 6
Every check is recorded, including checks that found no text change. A detected edit is therefore bounded between two checks. The publisher's exact save time is not observable from this record. Last checked .
This post is held twice: here, with this project's own note on why it matters, and again as part of the conversation captured at , which is polled for changes. Both copies are the same post; neither is a separate event.
Snapshot and diff bodies for this chain monitor are held in the local evidence archive but withheld from the public site because they can contain the addresses of people who published nothing themselves. Capture times and reviewed change summaries remain available below.
Held captures
-
The Reddit thread gained a new participant comment proposing whitehat self-sweep or closed-source migration as vendor options.
Recovered from the Internet Archive rather than captured by this project. The row records that third-party provenance separately from captures made by this project.
What changed from the previous capture 12 lines
edited: false body: By now, I am no longer excluding the ‘retirement attack’ scenario. 😢 + +comment: p2crga2 +parent: t3_1vduxyg +author: _gianlucag_ +created_utc: 1786141225 +edited: 1786141414 +body: +The only viable option would have been to "steal" all the btc by themselves, effectively whitehat-ing their way out, then returning the bitcoins to the original owners. + +Or + +go partially "closed source" by removing the github account, dont disclose the issue, ask people, one by one, to recreate the seed and move their funds thereExtracted text as captured
post: 1vduxyg author: therealjeku created_utc: 1785708102 title: What could Coinkite have done if they discovered the flaw first? body: Let’s be hypothetical and imagine Coinkite discovered this flaw on their own in, say, January 2026. What could they have done? If they announced the flaw with a firmware fix then attackers could quickly get started on harvesting BTC before all the affected cards are safely transferred. If they announced a firmware fix but not the flaw, many people won’t bother updating their firmware. Hell, my MK4 sat for over two years in a safe. Not to mention their new firmware code would be viewable and it would surely point out a fix for the RNG which would lead some to ascertain this huge underlying issue. Not to defend them, but I’m not sure they would have had any favourable way out of this mess having sold so many affected wallets over many years. comment: p1c3w9z parent: t3_1vduxyg author: Quirky-Reveal-1669 created_utc: 1785708409 edited: false body: No not true. The organization of the execution of this theft will have taken time. If CoinKite was the first with this knowledge, they would have first tried to communicate that a new seed should be generated with dice, and with a passphrase. No further detailed information given, just pressing the utmost urgency. After that, a firmware update would be the next step. comment: p1c51f9 parent: t1_p1c3w9z author: cilicia3k3 created_utc: 1785708749 edited: false body: The second they sent a private email to a YouTuber , let’s say Ben , it would be game over comment: p1c8cwk parent: t1_p1c3w9z author: No_Position_8581 created_utc: 1785709777 edited: false body: Anything they did would have been a tip off. It would have saved more people but people would immediately start looking at their rng comment: p1caf84 parent: t1_p1c8cwk author: Quirky-Reveal-1669 created_utc: 1785710427 edited: falseExcerpt only. The complete copy is held offline and backs quotations on this site. The original publication remains the canonical public source.
-
New comment says the author no longer excludes the retirement attack scenario.
Recovered from the Internet Archive rather than captured by this project. The row records that third-party provenance separately from captures made by this project.
What changed from the previous capture 8 lines
edited: false body: Its game over as soon there is a whisper about there being an issue with seed generation entropy. It does not take long to find the weakness when knowing there is one. + +comment: p24tbwm +parent: t1_p2279bk +author: Quirky-Reveal-1669 +created_utc: 1786048245 +edited: false +body: +By now, I am no longer excluding the ‘retirement attack’ scenario. 😢Extracted text as captured
post: 1vduxyg author: therealjeku created_utc: 1785708102 title: What could Coinkite have done if they discovered the flaw first? body: Let’s be hypothetical and imagine Coinkite discovered this flaw on their own in, say, January 2026. What could they have done? If they announced the flaw with a firmware fix then attackers could quickly get started on harvesting BTC before all the affected cards are safely transferred. If they announced a firmware fix but not the flaw, many people won’t bother updating their firmware. Hell, my MK4 sat for over two years in a safe. Not to mention their new firmware code would be viewable and it would surely point out a fix for the RNG which would lead some to ascertain this huge underlying issue. Not to defend them, but I’m not sure they would have had any favourable way out of this mess having sold so many affected wallets over many years. comment: p1c3w9z parent: t3_1vduxyg author: Quirky-Reveal-1669 created_utc: 1785708409 edited: false body: No not true. The organization of the execution of this theft will have taken time. If CoinKite was the first with this knowledge, they would have first tried to communicate that a new seed should be generated with dice, and with a passphrase. No further detailed information given, just pressing the utmost urgency. After that, a firmware update would be the next step. comment: p1c51f9 parent: t1_p1c3w9z author: cilicia3k3 created_utc: 1785708749 edited: false body: The second they sent a private email to a YouTuber , let’s say Ben , it would be game over comment: p1c8cwk parent: t1_p1c3w9z author: No_Position_8581 created_utc: 1785709777 edited: false body: Anything they did would have been a tip off. It would have saved more people but people would immediately start looking at their rng comment: p1caf84 parent: t1_p1c8cwk author: Quirky-Reveal-1669 created_utc: 1785710427 edited: falseExcerpt only. The complete copy is held offline and backs quotations on this site. The original publication remains the canonical public source.
-
One comment was edited (typo fix in the dice-roll weakness explanation) and a new comment argues it is game over once a seed-generation entropy weakness is whispered about.
Recovered from the Internet Archive rather than captured by this project. The row records that third-party provenance separately from captures made by this project.
What changed from the previous capture 12 lines
parent: t1_p1ccc66 author: Charming-Designer944 created_utc: 1785717372 -edited: false +edited: 1786024058 body: It's another issue entirely, but with a very similar result. - no minimum requirement on the number of dice rolls - easy to mix up the options of mixing dice rolls into the intenal entropy vs building the entropy entirely from the dice rolls alone. -Combined it can result in users selecting the option of only usinng the dice rolls, and then only perform a handful number of dice roolls thinking that the dice rolls are just additional security to the internal entropy, not replacing it entirely and not realize that they created a vere weak seed. +Combined it can result in users selecting the option of only usinng the dice rolls, and then only perform a handful number of dice roolls thinking that the dice rolls are just additional security to the internal entropy, not replacing it entirely and not realize that they created a very weak seed. I believe this issue is partially fixed in later firmwares, presenting a warning in main seed generation when using weak dice rolls, but still present when dice rolling a temporary seed. edited: false body: I would guess we are beyond that stage at this point, unfortunately. The awareness of the attack is widespread and sweeps are still occurring which means if there were a white hat phase, it would be concluded by now and the remainder we are seeing is black hat, or at least mixed with black hat. + +comment: p2279bk +parent: t1_p1c3w9z +author: Charming-Designer944 +created_utc: 1786024345 +edited: false +body: +Its game over as soon there is a whisper about there being an issue with seed generation entropy. It does not take long to find the weakness when knowing there is one.Extracted text as captured
post: 1vduxyg author: therealjeku created_utc: 1785708102 title: What could Coinkite have done if they discovered the flaw first? body: Let’s be hypothetical and imagine Coinkite discovered this flaw on their own in, say, January 2026. What could they have done? If they announced the flaw with a firmware fix then attackers could quickly get started on harvesting BTC before all the affected cards are safely transferred. If they announced a firmware fix but not the flaw, many people won’t bother updating their firmware. Hell, my MK4 sat for over two years in a safe. Not to mention their new firmware code would be viewable and it would surely point out a fix for the RNG which would lead some to ascertain this huge underlying issue. Not to defend them, but I’m not sure they would have had any favourable way out of this mess having sold so many affected wallets over many years. comment: p1c3w9z parent: t3_1vduxyg author: Quirky-Reveal-1669 created_utc: 1785708409 edited: false body: No not true. The organization of the execution of this theft will have taken time. If CoinKite was the first with this knowledge, they would have first tried to communicate that a new seed should be generated with dice, and with a passphrase. No further detailed information given, just pressing the utmost urgency. After that, a firmware update would be the next step. comment: p1c51f9 parent: t1_p1c3w9z author: cilicia3k3 created_utc: 1785708749 edited: false body: The second they sent a private email to a YouTuber , let’s say Ben , it would be game over comment: p1c8cwk parent: t1_p1c3w9z author: No_Position_8581 created_utc: 1785709777 edited: false body: Anything they did would have been a tip off. It would have saved more people but people would immediately start looking at their rng comment: p1caf84 parent: t1_p1c8cwk author: Quirky-Reveal-1669 created_utc: 1785710427 edited: falseExcerpt only. The complete copy is held offline and backs quotations on this site. The original publication remains the canonical public source.
-
The Reddit thread gained 1 new comment.
Recovered from the Internet Archive rather than captured by this project. The row records that third-party provenance separately from captures made by this project.
What changed from the previous capture 8 lines
edited: false body: There would be several possible options, all of them better than the actual outcome. + +comment: p1pgk39 +parent: t1_p1ef0ri +author: IInsulince +created_utc: 1785870028 +edited: false +body: +I would guess we are beyond that stage at this point, unfortunately. The awareness of the attack is widespread and sweeps are still occurring which means if there were a white hat phase, it would be concluded by now and the remainder we are seeing is black hat, or at least mixed with black hat.Extracted text as captured
post: 1vduxyg author: therealjeku created_utc: 1785708102 title: What could Coinkite have done if they discovered the flaw first? body: Let’s be hypothetical and imagine Coinkite discovered this flaw on their own in, say, January 2026. What could they have done? If they announced the flaw with a firmware fix then attackers could quickly get started on harvesting BTC before all the affected cards are safely transferred. If they announced a firmware fix but not the flaw, many people won’t bother updating their firmware. Hell, my MK4 sat for over two years in a safe. Not to mention their new firmware code would be viewable and it would surely point out a fix for the RNG which would lead some to ascertain this huge underlying issue. Not to defend them, but I’m not sure they would have had any favourable way out of this mess having sold so many affected wallets over many years. comment: p1c3w9z parent: t3_1vduxyg author: Quirky-Reveal-1669 created_utc: 1785708409 edited: false body: No not true. The organization of the execution of this theft will have taken time. If CoinKite was the first with this knowledge, they would have first tried to communicate that a new seed should be generated with dice, and with a passphrase. No further detailed information given, just pressing the utmost urgency. After that, a firmware update would be the next step. comment: p1c51f9 parent: t1_p1c3w9z author: cilicia3k3 created_utc: 1785708749 edited: false body: The second they sent a private email to a YouTuber , let’s say Ben , it would be game over comment: p1c8cwk parent: t1_p1c3w9z author: No_Position_8581 created_utc: 1785709777 edited: false body: Anything they did would have been a tip off. It would have saved more people but people would immediately start looking at their rng comment: p1caf84 parent: t1_p1c8cwk author: Quirky-Reveal-1669 created_utc: 1785710427 edited: falseExcerpt only. The complete copy is held offline and backs quotations on this site. The original publication remains the canonical public source.
-
1 new Reddit comment was posted, including iloverunning11.
Recovered from the Internet Archive rather than captured by this project. The row records that third-party provenance separately from captures made by this project.
What changed from the previous capture 8 lines
edited: false body: The flaw was found, then they had to search all the combinations and check if those wallets existed. Gemini says they prepped for at least a month. Had they not had time, they would have needed at least a 10 hours to find the flaw and learn the combinations and then a script running hours on the easiest ones. There would have been plenty of time to move keys for most people. Especially if the took the code offline and then told people to get a new seed key with dice, there would have been no clues to the issue + +comment: p1miln5 +parent: t3_1vduxyg +author: iloverunning11 +created_utc: 1785840497 +edited: false +body: +There would be several possible options, all of them better than the actual outcome.Extracted text as captured
post: 1vduxyg author: therealjeku created_utc: 1785708102 title: What could Coinkite have done if they discovered the flaw first? body: Let’s be hypothetical and imagine Coinkite discovered this flaw on their own in, say, January 2026. What could they have done? If they announced the flaw with a firmware fix then attackers could quickly get started on harvesting BTC before all the affected cards are safely transferred. If they announced a firmware fix but not the flaw, many people won’t bother updating their firmware. Hell, my MK4 sat for over two years in a safe. Not to mention their new firmware code would be viewable and it would surely point out a fix for the RNG which would lead some to ascertain this huge underlying issue. Not to defend them, but I’m not sure they would have had any favourable way out of this mess having sold so many affected wallets over many years. comment: p1c3w9z parent: t3_1vduxyg author: Quirky-Reveal-1669 created_utc: 1785708409 edited: false body: No not true. The organization of the execution of this theft will have taken time. If CoinKite was the first with this knowledge, they would have first tried to communicate that a new seed should be generated with dice, and with a passphrase. No further detailed information given, just pressing the utmost urgency. After that, a firmware update would be the next step. comment: p1c51f9 parent: t1_p1c3w9z author: cilicia3k3 created_utc: 1785708749 edited: false body: The second they sent a private email to a YouTuber , let’s say Ben , it would be game over comment: p1c8cwk parent: t1_p1c3w9z author: No_Position_8581 created_utc: 1785709777 edited: false body: Anything they did would have been a tip off. It would have saved more people but people would immediately start looking at their rng comment: p1caf84 parent: t1_p1c8cwk author: Quirky-Reveal-1669 created_utc: 1785710427 edited: falseExcerpt only. The complete copy is held offline and backs quotations on this site. The original publication remains the canonical public source.
-
Recovered from the Internet Archive rather than captured by this project. The row records that third-party provenance separately from captures made by this project.
What changed from the previous capture 0 lines
Extracted text as captured
post: 1vduxyg author: therealjeku created_utc: 1785708102 title: What could Coinkite have done if they discovered the flaw first? body: Let’s be hypothetical and imagine Coinkite discovered this flaw on their own in, say, January 2026. What could they have done? If they announced the flaw with a firmware fix then attackers could quickly get started on harvesting BTC before all the affected cards are safely transferred. If they announced a firmware fix but not the flaw, many people won’t bother updating their firmware. Hell, my MK4 sat for over two years in a safe. Not to mention their new firmware code would be viewable and it would surely point out a fix for the RNG which would lead some to ascertain this huge underlying issue. Not to defend them, but I’m not sure they would have had any favourable way out of this mess having sold so many affected wallets over many years. comment: p1c3w9z parent: t3_1vduxyg author: Quirky-Reveal-1669 created_utc: 1785708409 edited: false body: No not true. The organization of the execution of this theft will have taken time. If CoinKite was the first with this knowledge, they would have first tried to communicate that a new seed should be generated with dice, and with a passphrase. No further detailed information given, just pressing the utmost urgency. After that, a firmware update would be the next step. comment: p1c51f9 parent: t1_p1c3w9z author: cilicia3k3 created_utc: 1785708749 edited: false body: The second they sent a private email to a YouTuber , let’s say Ben , it would be game over comment: p1c8cwk parent: t1_p1c3w9z author: No_Position_8581 created_utc: 1785709777 edited: false body: Anything they did would have been a tip off. It would have saved more people but people would immediately start looking at their rng comment: p1caf84 parent: t1_p1c8cwk author: Quirky-Reveal-1669 created_utc: 1785710427 edited: falseExcerpt only. The complete copy is held offline and backs quotations on this site. The original publication remains the canonical public source.
0 presentation-noise differences. Sidebar, ticker and other page chrome churn that our review classified as not being changes to what the source says.
The excerpts and plain unified diffs above show the text this project held and how it changed. To verify a quotation, compare it against the page itself or against the Internet Archive's copies, which are independent of this project.
Complete captures are held offline rather than mirrored here, so this page shows diffs and excerpts. If a quotation is ever disputed, the full copy can be produced. Ask.
Compare the screenshot or a quotation against the original while it is available.