COLDCARD RNG incident the public record, collected and explained
Informational only, and this site never asks for your seed words. details

Informational only. This is an open source collection of what others have published about the incident, together with an explanation of it. It is not financial, security or legal advice, and not a substitute for professional advice about your own situation. It is not affiliated with, endorsed by, or speaking for Coinkite. Material is attributed and quoted as published; where sources disagree their scenarios are kept separate with their assumptions rather than reconciled into one answer. Everything is meant to be checked against the linked evidence rather than taken on trust. Act on your own judgement about a particular situation. Editorial standards and corrections.

Do not disclose recovery material to a website, form, message or support account. This site never asks for it, and contributions containing recovery words or private keys are not accepted.

Swan's code-review pipeline published as a template

skwp-2085475419386519875

https://x.com/skwp/status/2085475419386519875

Captured screenshot of the post by @skwp, posted 6 Aug 2026, 21:17 UTC
@skwp posted captured full-size capture → original post →
Author
@skwp
Organisation
independent
Evidence role
social statement
Posted
Capture status
capture held

Yan Pritzker describes the process Swan uses for every change that reaches production, a deterministically orchestrated LLM pipeline plus GitHub lockdowns and rules, with a human review required afterwards, and invites other teams to copy it. The attached diagram sets out the detail: five review lenses run in parallel with at least three required to succeed, covering architecture, semantic, performance, security and quality; a change-request gate requiring a ticket link; supply-chain and static analysis with extended security queries, a manifest CVE gate failing on high, third-party actions vendored through an internal mirror and network egress locked at install; and a final human review in which code owners and the security team sign off and agent-authored changes need independent human approval. Held because the incident turned AI code review into a live argument, and this is a concrete published process rather than a position on it, usable as a document by anyone assessing that argument. Pritzker is at Swan and the post promotes Swan's own engineering practice. Nothing here establishes that the pipeline works as described or that it would have caught this defect.

This post is registered as evidence and has a locally held capture. The original remains the canonical publication.

How to check this yourself

Compare the screenshot or a quotation against the original while it is available.