COLDCARD RNG incident the public record, collected and explained
Informational only, and this site never asks for your seed words. details

Informational only. This is an open source collection of what others have published about the incident, together with an explanation of it. It is not financial, security or legal advice, and not a substitute for professional advice about your own situation. It is not affiliated with, endorsed by, or speaking for Coinkite. Material is attributed and quoted as published; where sources disagree their scenarios are kept separate with their assumptions rather than reconciled into one answer. Everything is meant to be checked against the linked evidence rather than taken on trust. Act on your own judgement about a particular situation. Editorial standards and corrections.

Do not disclose recovery material to a website, form, message or support account. This site never asks for it, and contributions containing recovery words or private keys are not accepted.

User reports their coldcard wallet being drained on Reddit

stackernews-first-drain-report

https://stacker.news/items/1536238

Latest reviewed change

source content difference between and

The thread added Murch's updated situation summary, including expanded device, entropy and passphrase assertions, alongside later community replies.

seen +84 -70 full history below
       "comments": {
         "comments": [
           {
+            "createdAt": "2026-08-05T21:35:21.769Z",
+            "text": "###### Summary of Situation as of this Time\n\n**ACTION RECOMMENDATION: PLEASE CAREFULLY MOVE FUNDS STORED ON COLDCARD WALLETS CREATED FROM DEVICE-GENERATED ENTROPY TO UNAFFECTED WALLETS *ASAP*.**\n\nAny funds on a **COLDCARD Mk3 using a firmware from version 4.0.1 (March 2021) to 4.1.9 (latest version until July 30th)**, where the entropy was only generated by the device, **should be considered compromised**. COLDCARD Mk4, Mk5, and Q are affected by the same issue to a lesser degree. Wallets generated by those devices are at risk of theft. Wallets created with externally generated entropy with at least 50 dice throws should not be exposed. Wallets that pair the device entropy with a passphrase are only as secure as the passphrase.  If you used a weak passphrase (less than 25 random characters or fewer than seven BIP39 words) and did not provide external entropy (at least fifty dice throws), your funds are at risk.\n\nCoinkite has released firmware updates for COLDCARD Mk3, Mk4, Mk5, and Q. Wallets generated with the new firmware should be secure. **Updating to the new firmware does *not make affected wallets secure*. Only new wallets generated with the new firmware are unaffected.** Coinkite put out a [security advisory](https://blog.coinkite.com/coldcard-mk3-seed-generation-warning/). The security advisory has been updated to include more devices, more details about the issue, and migration advice.\n\nBlock security researchers reports that the COLDCARD Mk2 is affected the same way as the Mk3.\n\nAnyone with access to a frontier AI model is capable of reproducing the attack. Especially if you have funds on a COLDCARD single-sig wallet created with wallet-generated entropy, please carefully **move your funds to an unaffected wallet ASAP**. Single-sig wallets with a weak passphrase, or multisig wallets that can be spent by a quorum of COLDCARD wallets or composed only of COLDCARD wallets created with device-generated entropy should be considered **at risk** and funds should also be moved.",
+            "user": {
+              "name": "Murch"
+            }

First lines only. The complete diff is in the timeline below.

Organisation
Stacker News
Evidence role
Community discussion
Published
2026-07-30
Source changes
4
Detected differences
6
Unreviewed
0
Copies held
7

The earliest incident thread identified on Stacker News: Murch relaying the first Reddit drain report while the recipient address was still collecting, the evening before Coinkite's disclosure. The drain claims quoted are the Reddit posters', unverified here; the thread's value is that it fixes when the incident first surfaced publicly and how the community read it in real time. Captured through the site's public GraphQL API: the rendered pages crash the capture tab, and the API answers POST from this host. The query fixes the captured surface to the item's title, text and two levels of comments, each with author and absolute timestamp.

Every check is recorded, including checks that found no text change. A detected edit is therefore bounded between two checks. The publisher's exact save time is not observable from this record. Last checked .

  1. source content difference between and source content +84 -70

    The thread added Murch's updated situation summary, including expanded device, entropy and passphrase assertions, alongside later community replies.

    seen · Captured here 22,028 chars
    What changed from the previous capture 154 lines
           "comments": {
             "comments": [
               {
    +            "createdAt": "2026-08-05T21:35:21.769Z",
    +            "text": "###### Summary of Situation as of this Time\n\n**ACTION RECOMMENDATION: PLEASE CAREFULLY MOVE FUNDS STORED ON COLDCARD WALLETS CREATED FROM DEVICE-GENERATED ENTROPY TO UNAFFECTED WALLETS *ASAP*.**\n\nAny funds on a **COLDCARD Mk3 using a firmware from version 4.0.1 (March 2021) to 4.1.9 (latest version until July 30th)**, where the entropy was only generated by the device, **should be considered compromised**. COLDCARD Mk4, Mk5, and Q are affected by the same issue to a lesser degree. Wallets generated by those devices are at risk of theft. Wallets created with externally generated entropy with at least 50 dice throws should not be exposed. Wallets that pair the device entropy with a passphrase are only as secure as the passphrase.  If you used a weak passphrase (less than 25 random characters or fewer than seven BIP39 words) and did not provide external entropy (at least fifty dice throws), your funds are at risk.\n\nCoinkite has released firmware updates for COLDCARD Mk3, Mk4, Mk5, and Q. Wallets generated with the new firmware should be secure. **Updating to the new firmware does *not make affected wallets secure*. Only new wallets generated with the new firmware are unaffected.** Coinkite put out a [security advisory](https://blog.coinkite.com/coldcard-mk3-seed-generation-warning/). The security advisory has been updated to include more devices, more details about the issue, and migration advice.\n\nBlock security researchers reports that the COLDCARD Mk2 is affected the same way as the Mk3.\n\nAnyone with access to a frontier AI model is capable of reproducing the attack. Especially if you have funds on a COLDCARD single-sig wallet created with wallet-generated entropy, please carefully **move your funds to an unaffected wallet ASAP**. Single-sig wallets with a weak passphrase, or multisig wallets that can be spent by a quorum of COLDCARD wallets or composed only of COLDCARD wallets created with device-generated entropy should be considered **at risk** and funds should also be moved.",
    +            "user": {
    +              "name": "Murch"
    +            }
    +          },
    +          {
    +            "createdAt": "2026-07-30T21:32:10.114Z",
    +            "text": "update with complete timeline/story from reddit OP: https://www.reddit.com/r/Bitcoin/comments/1vb6teq/wallet_drained_timeline/",
    +            "user": {
    +              "name": "k00b"
    +            }
    +          },
    +          {
    +            "createdAt": "2026-08-05T00:01:12.036Z",
    +            "text": "1m zap for @Murch  - This timely post certainly saved funds during an emergency. Thank you.",
    +            "user": {
    +              "name": "Kruw"
    +            }
    +          },
    +          {
    +            "createdAt": "2026-07-30T18:47:43.894Z",
    +            "text": "This is super weird. He says he only deposited to the wallet and never withdrew. If that's true, looks like he leaked his seed phrase. Doesn't seem like a Coldcard issue. Let's hold off for more info.",
    +            "user": {
    +              "name": "0xbitcoiner"
    +            }
    +          },
    +          {
    +            "createdAt": "2026-07-31T00:12:37.929Z",
    +            "text": "Block says they can confirm a second batch of transactions from before the batch that most people were made aware of:\n\nhttps://x.com/clay_garrett/status/2082980439367487724\n\nI think this is the same batch narceilo spotted:\n \nhttps://stacker.news/items/1536238/r/Scoresby?commentId=1536347",
    +            "user": {
    +              "name": "Scoresby"
    +            }
    +          },
    +          {
    +            "createdAt": "2026-08-05T00:25:07.022Z",
    +            "text": "Eeeh, _one million CCs stacked_?!",
    +            "user": {
    +              "name": "denlillaapan"
    +            }
    +          },
    +          {
    +            "createdAt": "2026-07-30T20:38:10.917Z",
    +            "text": "Kevin Loaec preliminary [conclusion](https://x.com/KLoaec/status/2082926304995762209):\n\n![](https://m.stacker.news/150212)\n\nLoaec is the founder of Wizardsardine and knows his way around bitcoin wallet stuff.",
    +            "user": {
    +              "name": "Scoresby"
    +            }
    +          },
    +          {
    +            "createdAt": "2026-07-31T00:08:32.130Z",
    +            "text": "###### Summary of Situation as of this Time\n\nAny funds on a **Coldcard Mk3 using a firmware version 4.0.1 (March 2021) or later, up to the *current* version**, where the entropy was generated by the Coldcard and it was not paired with a strong password, are at risk.\n\nCoinkite has put out a [security advisory](https://blog.coinkite.com/coldcard-mk3-seed-generation-warning/).\n\nIt looks like anyone with access to a regular LLM subscription is capable of reproducing the attack now. If this describes your wallet setup, please **move your funds to an unaffected wallet ASAP**. Please move deliberately enough to move your funds safely, people make mistakes when they rush.\n\nMk2 may also be at risk, unclear.",
    +            "user": {
    +              "name": "Murch"
    +            }
    +          },
    +          {
    +            "createdAt": "2026-08-05T23:04:46.927Z",
    +            "text": "I feel too bad anytime I hear of this.",
    +            "user": {
    +              "name": "Jacksoncarpenter"
    +            }
    +          },
    +          {
    +            "createdAt": "2026-07-31T18:54:14.562Z",
    +            "text": "anyone get any info on opendimes if they were affected at all?\nused them over the years to gift sats for weddings/graduations\n\nhavent seen much talk about them at all",
    +            "user": {
    +              "name": "falsefaucet"
    +            }
    +          },
    +          {
    +            "createdAt": "2026-08-01T00:30:58.841Z",
    +            "text": "Cannot trust other products from CoinKite either\n\nhttps://primal.net/e/nevent1qqs272yqcpr3awzapmhszf88yne3e8lh007y0ut2edtgjffpwxhgpcqdpnngp\n\nhttps://primal.net/e/nevent1qqsg9tzxn33k3agkg6qxclh0etqysh89u4cv6yjlz6y7ua9fsdlrt3gfvqtkw\n\n\n\n![](https://m.stacker.news/150417)\n\n![](https://m.stacker.news/150418)",
    +            "user": {
    +              "name": "satonymous"
    +            }
    +          },
    +          {
    +            "createdAt": "2026-07-30T23:17:38.208Z",
    +            "text": "Superbly fast and comprehensible coverage on the situation. Thank you SN community",
    +            "user": {
    +              "name": "didiplaywell"
    +            }
    +          },
    +          {
                 "createdAt": "2026-07-31T14:36:54.095Z",
                 "text": "###### Summary of Situation as of this Time\n\n**ACTION RECOMMENDATION: PLEASE CAREFULLY MOVE FUNDS STORED ON COLDCARD WALLETS CREATED FROM DEVICE-GENERATED ENTROPY TO UNAFFECTED WALLETS *ASAP*.**\n\nAny funds on a **COLDCARD Mk3 using a firmware from version 4.0.1 (March 2021) to 4.1.9 (latest version as of yesterday)**, where the entropy was only generated by the device, **should be considered compromised**. COLDCARD Mk4, Mk5, and Q are affected by the same issue to a lesser degree. Wallets generated by those devices are at risk of theft. Wallets that pair the device entropy with a strong passphrase or wallets created with externally generated entropy with at least 50 dice throws should not be exposed. If you used a weak passphrase and did not input external entropy (at least fifty dice throws), your funds are at risk.\n\nCoinkite has released firmware updates for COLDCARD Mk3, Mk4, Mk5, and Q. Wallets generated with the new firmware should be secure. **Updating to the new firmware does *not make affected wallets secure*. Only new wallets generated with the new firmware are unaffected.** Coinkite put out a [security advisory](https://blog.coinkite.com/coldcard-mk3-seed-generation-warning/). The security advisory has been updated to include more devices, more details about the issue, and migration advice.\n\nBlock security researchers reports that the COLDCARD Mk2 is affected the same way as the Mk3.\n\nAnyone with access to a frontier AI model is capable of reproducing the attack. Especially if you have funds on a COLDCARD single-sig wallet created with wallet-generated entropy, please carefully **move your funds to an unaffected wallet ASAP**. Single-sig wallets with a weak passphrase, or multisig wallets that can be spent by a quorum of COLDCARD wallets or composed only of COLDCARD wallets created with device-generated entropy should be considered **at risk** and funds should also be moved.",
                 "user": {
                   "name": "Murch"
    -            }
    -          },
    -          {
    -            "createdAt": "2026-07-30T21:32:10.114Z",
    -            "text": "update with complete timeline/story from reddit OP: https://www.reddit.com/r/Bitcoin/comments/1vb6teq/wallet_drained_timeline/",
    -            "user": {
    -              "name": "k00b"
    -            }
    -          },
    -          {
    -            "createdAt": "2026-08-05T00:01:12.036Z",
    -            "text": "1m zap for @Murch  - This timely post certainly saved funds during an emergency. Thank you.",
    -            "user": {
    -              "name": "Kruw"
    -            }
    -          },
    -          {
    -            "createdAt": "2026-07-30T18:47:43.894Z",
    -            "text": "This is super weird. He says he only deposited to the wallet and never withdrew. If that's true, looks like he leaked his seed phrase. Doesn't seem like a Coldcard issue. Let's hold off for more info.",
    -            "user": {
    -              "name": "0xbitcoiner"
    -            }
    -          },
    -          {
    -            "createdAt": "2026-07-31T00:12:37.929Z",
    -            "text": "Block says they can confirm a second batch of transactions from before the batch that most people were made aware of:\n\nhttps://x.com/clay_garrett/status/2082980439367487724\n\nI think this is the same batch narceilo spotted:\n \nhttps://stacker.news/items/1536238/r/Scoresby?commentId=1536347",
    -            "user": {
    -              "name": "Scoresby"
    -            }
    -          },
    -          {
    -            "createdAt": "2026-08-05T00:25:07.022Z",
    -            "text": "Eeeh, _one million CCs stacked_?!",
    -            "user": {
    -              "name": "denlillaapan"
    -            }
    -          },
    -          {
    -            "createdAt": "2026-07-30T20:38:10.917Z",
    -            "text": "Kevin Loaec preliminary [conclusion](https://x.com/KLoaec/status/2082926304995762209):\n\n![](https://m.stacker.news/150212)\n\nLoaec is the founder of Wizardsardine and knows his way around bitcoin wallet stuff.",
    -            "user": {
    -              "name": "Scoresby"
    -            }
    -          },
    -          {
    -            "createdAt": "2026-07-31T00:08:32.130Z",
    -            "text": "###### Summary of Situation as of this Time\n\nAny funds on a **Coldcard Mk3 using a firmware version 4.0.1 (March 2021) or later, up to the *current* version**, where the entropy was generated by the Coldcard and it was not paired with a strong password, are at risk.\n\nCoinkite has put out a [security advisory](https://blog.coinkite.com/coldcard-mk3-seed-generation-warning/).\n\nIt looks like anyone with access to a regular LLM subscription is capable of reproducing the attack now. If this describes your wallet setup, please **move your funds to an unaffected wallet ASAP**. Please move deliberately enough to move your funds safely, people make mistakes when they rush.\n\nMk2 may also be at risk, unclear.",
    -            "user": {
    -              "name": "Murch"
    -            }
    -          },
    -          {
    -            "createdAt": "2026-07-31T18:54:14.562Z",
    -            "text": "anyone get any info on opendimes if they were affected at all?\nused them over the years to gift sats for weddings/graduations\n\nhavent seen much talk about them at all",
    -            "user": {
    -              "name": "falsefaucet"
    -            }
    -          },
    -          {
    -            "createdAt": "2026-08-01T00:30:58.841Z",
    -            "text": "Cannot trust other products from CoinKite either\n\nhttps://primal.net/e/nevent1qqs272yqcpr3awzapmhszf88yne3e8lh007y0ut2edtgjffpwxhgpcqdpnngp\n\nhttps://primal.net/e/nevent1qqsg9tzxn33k3agkg6qxclh0etqysh89u4cv6yjlz6y7ua9fsdlrt3gfvqtkw\n\n\n\n![](https://m.stacker.news/150417)\n\n![](https://m.stacker.news/150418)",
    -            "user": {
    -              "name": "satonymous"
    -            }
    -          },
    -          {
    -            "createdAt": "2026-07-30T23:17:38.208Z",
    -            "text": "Superbly fast and comprehensible coverage on the situation. Thank you SN community",
    -            "user": {
    -              "name": "didiplaywell"
                 }
               },
               {
    
    Extracted text as captured
    {
      "data": {
        "item": {
          "comments": {
            "comments": [
              {
                "createdAt": "2026-08-05T21:35:21.769Z",
                "text": "###### Summary of Situation as of this Time\n\n**ACTION RECOMMENDATION: PLEASE CAREFULLY MOVE FUNDS STORED ON COLDCARD WALLETS CREATED FROM DEVICE-GENERATED ENTROPY TO UNAFFECTED WALLETS *ASAP*.**\n\nAny funds on a **COLDCARD Mk3 using a firmware from version 4.0.1 (March 2021) to 4.1.9 (latest version until July 30th)**, where the entropy was only generated by the device, **should be considered compromised**. COLDCARD Mk4, Mk5, and Q are affected by the same issue to a lesser degree. Wallets generated by those devices are at risk of theft. Wallets created with externally generated entropy with at least 50 dice throws should not be exposed. Wallets that pair the device entropy with a passphrase are only as secure as the passphrase.  If you used a weak passphrase (less than 25 random characters or fewer than seven BIP39 words) and did not provide external entropy (at least fifty dice throws), your funds are at risk.\n\nCoinkite has released firmware updates for COLDCARD Mk3, Mk4, Mk5, and Q. Wallets generated with the new firmware should be secure. **Updating to the new firmware does *not make affected wallets secure*. Only new wallets generated with the new firmware are unaffected.** Coinkite put out a [security advisory](https://blog.coinkite.com/coldcard-mk3-seed-generation-warning/). The security advisory has been updated to include more devices, more details about the issue, and migration advice.\n\nBlock security researchers reports that the COLDCARD Mk2 is affected the same way as the Mk3.\n\nAnyone with access to a frontier AI model is capable of reproducing the attack. Especially if you have funds on a COLDCARD single-sig wallet created with wallet-generated entropy, please carefully **move your funds to an unaffected wallet ASAP**. Single-sig wallets with a weak passphrase, or multisig wallets that can be spent by a quorum of COLDCARD wallets or composed only of COLDCARD wallets created with device-generated entropy should be considered **at risk** and funds should also be moved.",
                "user": {
                  "name": "Murch"
                }
              },
              {
                "createdAt": "2026-07-30T21:32:10.114Z",
                "text": "update with complete timeline/story from reddit OP: https://www.reddit.com/r/Bitcoin/comments/1vb6teq/wallet_drained_timeline/",
                "user": {
                  "name": "k00b"
                }
              },
              {
                "createdAt": "2026-08-05T00:01:12.036Z",
                "text": "1m zap for @Murch  - This timely post certainly saved funds during an emergency. Thank you.",
                "user": {
                  "name": "Kruw"
                }
              },
              {
                "createdAt": "2026-07-30T18:47:43.894Z",
                "text": "This is super weird. He says he only deposited to the wallet and never withdrew. If that's true, looks like he leaked his seed phrase. Doesn't seem like a Coldcard issue. Let's hold off for more info.",
                "user": {
                  "name": "0xbitcoiner"
                }
              },
              {
                "createdAt": "2026-07-31T00:12:37.929Z",
                "text": "Block says they can confirm a second batch of transactions from before the batch that most people were made aware of:\n\nhttps://x.com/clay_garrett/status/2082980439367487724\n\nI think this is the same batch narceilo spotted:\n \nhttps://stacker.news/items/1536238/r/Scoresby?commentId=1536347",
                "user": {
                  "name": "Scoresby"
                }
              },

    Excerpt only. The complete copy is held offline and backs quotations on this site. The original publication remains the canonical public source.

  2. source content difference between and source content +7 -0

    The thread gained a comment offering to connect someone with a purported drainer developer to review the tool and improve the wallet's defences.

    seen · Captured here 19,620 chars
    What changed from the previous capture 7 lines
                 "text": "![](https://m.stacker.news/150227)",
                 "user": {
                   "name": "npub1zapsats"
    +            }
    +          },
    +          {
    +            "createdAt": "2026-08-05T13:11:10.781Z",
    +            "text": "I know a person who builds drainers if you guys want I can urge him to sell that drainer to someone who can review the drainer and update the coldcard wallet to prevent such drains... I have that person in contact",
    +            "user": {
    +              "name": "QuietHorizon"
                 }
               },
               {
    
    Extracted text as captured
    {
      "data": {
        "item": {
          "comments": {
            "comments": [
              {
                "createdAt": "2026-07-31T14:36:54.095Z",
                "text": "###### Summary of Situation as of this Time\n\n**ACTION RECOMMENDATION: PLEASE CAREFULLY MOVE FUNDS STORED ON COLDCARD WALLETS CREATED FROM DEVICE-GENERATED ENTROPY TO UNAFFECTED WALLETS *ASAP*.**\n\nAny funds on a **COLDCARD Mk3 using a firmware from version 4.0.1 (March 2021) to 4.1.9 (latest version as of yesterday)**, where the entropy was only generated by the device, **should be considered compromised**. COLDCARD Mk4, Mk5, and Q are affected by the same issue to a lesser degree. Wallets generated by those devices are at risk of theft. Wallets that pair the device entropy with a strong passphrase or wallets created with externally generated entropy with at least 50 dice throws should not be exposed. If you used a weak passphrase and did not input external entropy (at least fifty dice throws), your funds are at risk.\n\nCoinkite has released firmware updates for COLDCARD Mk3, Mk4, Mk5, and Q. Wallets generated with the new firmware should be secure. **Updating to the new firmware does *not make affected wallets secure*. Only new wallets generated with the new firmware are unaffected.** Coinkite put out a [security advisory](https://blog.coinkite.com/coldcard-mk3-seed-generation-warning/). The security advisory has been updated to include more devices, more details about the issue, and migration advice.\n\nBlock security researchers reports that the COLDCARD Mk2 is affected the same way as the Mk3.\n\nAnyone with access to a frontier AI model is capable of reproducing the attack. Especially if you have funds on a COLDCARD single-sig wallet created with wallet-generated entropy, please carefully **move your funds to an unaffected wallet ASAP**. Single-sig wallets with a weak passphrase, or multisig wallets that can be spent by a quorum of COLDCARD wallets or composed only of COLDCARD wallets created with device-generated entropy should be considered **at risk** and funds should also be moved.",
                "user": {
                  "name": "Murch"
                }
              },
              {
                "createdAt": "2026-08-05T00:01:12.036Z",
                "text": "1m zap for @Murch  - This timely post certainly saved funds during an emergency. Thank you.",
                "user": {
                  "name": "Kruw"
                }
              },
              {
                "createdAt": "2026-08-05T00:25:07.022Z",
                "text": "Eeeh, _one million CCs stacked_?!",
                "user": {
                  "name": "denlillaapan"
                }
              },
              {
                "createdAt": "2026-07-30T20:38:10.917Z",
                "text": "Kevin Loaec preliminary [conclusion](https://x.com/KLoaec/status/2082926304995762209):\n\n![](https://m.stacker.news/150212)\n\nLoaec is the founder of Wizardsardine and knows his way around bitcoin wallet stuff.",
                "user": {
                  "name": "Scoresby"
                }
              },
              {
                "createdAt": "2026-07-31T18:54:14.562Z",
                "text": "anyone get any info on opendimes if they were affected at all?\nused them over the years to gift sats for weddings/graduations\n\nhavent seen much talk about them at all",
                "user": {
                  "name": "falsefaucet"
                }
              },

    Excerpt only. The complete copy is held offline and backs quotations on this site. The original publication remains the canonical public source.

  3. source content difference between and source content +7 -0

    The Stacker News thread gained a new participant reply.

    seen · Captured here 19,232 chars
    What changed from the previous capture 7 lines
                 "text": "1m zap for @Murch  - This timely post certainly saved funds during an emergency. Thank you.",
                 "user": {
                   "name": "Kruw"
    +            }
    +          },
    +          {
    +            "createdAt": "2026-08-05T00:25:07.022Z",
    +            "text": "Eeeh, _one million CCs stacked_?!",
    +            "user": {
    +              "name": "denlillaapan"
                 }
               },
               {
    
    Extracted text as captured
    {
      "data": {
        "item": {
          "comments": {
            "comments": [
              {
                "createdAt": "2026-07-31T14:36:54.095Z",
                "text": "###### Summary of Situation as of this Time\n\n**ACTION RECOMMENDATION: PLEASE CAREFULLY MOVE FUNDS STORED ON COLDCARD WALLETS CREATED FROM DEVICE-GENERATED ENTROPY TO UNAFFECTED WALLETS *ASAP*.**\n\nAny funds on a **COLDCARD Mk3 using a firmware from version 4.0.1 (March 2021) to 4.1.9 (latest version as of yesterday)**, where the entropy was only generated by the device, **should be considered compromised**. COLDCARD Mk4, Mk5, and Q are affected by the same issue to a lesser degree. Wallets generated by those devices are at risk of theft. Wallets that pair the device entropy with a strong passphrase or wallets created with externally generated entropy with at least 50 dice throws should not be exposed. If you used a weak passphrase and did not input external entropy (at least fifty dice throws), your funds are at risk.\n\nCoinkite has released firmware updates for COLDCARD Mk3, Mk4, Mk5, and Q. Wallets generated with the new firmware should be secure. **Updating to the new firmware does *not make affected wallets secure*. Only new wallets generated with the new firmware are unaffected.** Coinkite put out a [security advisory](https://blog.coinkite.com/coldcard-mk3-seed-generation-warning/). The security advisory has been updated to include more devices, more details about the issue, and migration advice.\n\nBlock security researchers reports that the COLDCARD Mk2 is affected the same way as the Mk3.\n\nAnyone with access to a frontier AI model is capable of reproducing the attack. Especially if you have funds on a COLDCARD single-sig wallet created with wallet-generated entropy, please carefully **move your funds to an unaffected wallet ASAP**. Single-sig wallets with a weak passphrase, or multisig wallets that can be spent by a quorum of COLDCARD wallets or composed only of COLDCARD wallets created with device-generated entropy should be considered **at risk** and funds should also be moved.",
                "user": {
                  "name": "Murch"
                }
              },
              {
                "createdAt": "2026-08-05T00:01:12.036Z",
                "text": "1m zap for @Murch  - This timely post certainly saved funds during an emergency. Thank you.",
                "user": {
                  "name": "Kruw"
                }
              },
              {
                "createdAt": "2026-08-05T00:25:07.022Z",
                "text": "Eeeh, _one million CCs stacked_?!",
                "user": {
                  "name": "denlillaapan"
                }
              },
              {
                "createdAt": "2026-07-30T20:38:10.917Z",
                "text": "Kevin Loaec preliminary [conclusion](https://x.com/KLoaec/status/2082926304995762209):\n\n![](https://m.stacker.news/150212)\n\nLoaec is the founder of Wizardsardine and knows his way around bitcoin wallet stuff.",
                "user": {
                  "name": "Scoresby"
                }
              },
              {
                "createdAt": "2026-07-31T18:54:14.562Z",
                "text": "anyone get any info on opendimes if they were affected at all?\nused them over the years to gift sats for weddings/graduations\n\nhavent seen much talk about them at all",
                "user": {
                  "name": "falsefaucet"
                }
              },

    Excerpt only. The complete copy is held offline and backs quotations on this site. The original publication remains the canonical public source.

  4. source content difference between and source content +7 -0

    The Stacker News thread gained a reply thanking Murch for the timely emergency post.

    seen · Captured here 19,024 chars
    What changed from the previous capture 7 lines
                 "text": "###### Summary of Situation as of this Time\n\n**ACTION RECOMMENDATION: PLEASE CAREFULLY MOVE FUNDS STORED ON COLDCARD WALLETS CREATED FROM DEVICE-GENERATED ENTROPY TO UNAFFECTED WALLETS *ASAP*.**\n\nAny funds on a **COLDCARD Mk3 using a firmware from version 4.0.1 (March 2021) to 4.1.9 (latest version as of yesterday)**, where the entropy was only generated by the device, **should be considered compromised**. COLDCARD Mk4, Mk5, and Q are affected by the same issue to a lesser degree. Wallets generated by those devices are at risk of theft. Wallets that pair the device entropy with a strong passphrase or wallets created with externally generated entropy with at least 50 dice throws should not be exposed. If you used a weak passphrase and did not input external entropy (at least fifty dice throws), your funds are at risk.\n\nCoinkite has released firmware updates for COLDCARD Mk3, Mk4, Mk5, and Q. Wallets generated with the new firmware should be secure. **Updating to the new firmware does *not make affected wallets secure*. Only new wallets generated with the new firmware are unaffected.** Coinkite put out a [security advisory](https://blog.coinkite.com/coldcard-mk3-seed-generation-warning/). The security advisory has been updated to include more devices, more details about the issue, and migration advice.\n\nBlock security researchers reports that the COLDCARD Mk2 is affected the same way as the Mk3.\n\nAnyone with access to a frontier AI model is capable of reproducing the attack. Especially if you have funds on a COLDCARD single-sig wallet created with wallet-generated entropy, please carefully **move your funds to an unaffected wallet ASAP**. Single-sig wallets with a weak passphrase, or multisig wallets that can be spent by a quorum of COLDCARD wallets or composed only of COLDCARD wallets created with device-generated entropy should be considered **at risk** and funds should also be moved.",
                 "user": {
                   "name": "Murch"
    +            }
    +          },
    +          {
    +            "createdAt": "2026-08-05T00:01:12.036Z",
    +            "text": "1m zap for @Murch  - This timely post certainly saved funds during an emergency. Thank you.",
    +            "user": {
    +              "name": "Kruw"
                 }
               },
               {
    
    Extracted text as captured
    {
      "data": {
        "item": {
          "comments": {
            "comments": [
              {
                "createdAt": "2026-07-31T14:36:54.095Z",
                "text": "###### Summary of Situation as of this Time\n\n**ACTION RECOMMENDATION: PLEASE CAREFULLY MOVE FUNDS STORED ON COLDCARD WALLETS CREATED FROM DEVICE-GENERATED ENTROPY TO UNAFFECTED WALLETS *ASAP*.**\n\nAny funds on a **COLDCARD Mk3 using a firmware from version 4.0.1 (March 2021) to 4.1.9 (latest version as of yesterday)**, where the entropy was only generated by the device, **should be considered compromised**. COLDCARD Mk4, Mk5, and Q are affected by the same issue to a lesser degree. Wallets generated by those devices are at risk of theft. Wallets that pair the device entropy with a strong passphrase or wallets created with externally generated entropy with at least 50 dice throws should not be exposed. If you used a weak passphrase and did not input external entropy (at least fifty dice throws), your funds are at risk.\n\nCoinkite has released firmware updates for COLDCARD Mk3, Mk4, Mk5, and Q. Wallets generated with the new firmware should be secure. **Updating to the new firmware does *not make affected wallets secure*. Only new wallets generated with the new firmware are unaffected.** Coinkite put out a [security advisory](https://blog.coinkite.com/coldcard-mk3-seed-generation-warning/). The security advisory has been updated to include more devices, more details about the issue, and migration advice.\n\nBlock security researchers reports that the COLDCARD Mk2 is affected the same way as the Mk3.\n\nAnyone with access to a frontier AI model is capable of reproducing the attack. Especially if you have funds on a COLDCARD single-sig wallet created with wallet-generated entropy, please carefully **move your funds to an unaffected wallet ASAP**. Single-sig wallets with a weak passphrase, or multisig wallets that can be spent by a quorum of COLDCARD wallets or composed only of COLDCARD wallets created with device-generated entropy should be considered **at risk** and funds should also be moved.",
                "user": {
                  "name": "Murch"
                }
              },
              {
                "createdAt": "2026-08-05T00:01:12.036Z",
                "text": "1m zap for @Murch  - This timely post certainly saved funds during an emergency. Thank you.",
                "user": {
                  "name": "Kruw"
                }
              },
              {
                "createdAt": "2026-07-30T20:38:10.917Z",
                "text": "Kevin Loaec preliminary [conclusion](https://x.com/KLoaec/status/2082926304995762209):\n\n![](https://m.stacker.news/150212)\n\nLoaec is the founder of Wizardsardine and knows his way around bitcoin wallet stuff.",
                "user": {
                  "name": "Scoresby"
                }
              },
              {
                "createdAt": "2026-07-31T18:54:14.562Z",
                "text": "anyone get any info on opendimes if they were affected at all?\nused them over the years to gift sats for weddings/graduations\n\nhavent seen much talk about them at all",
                "user": {
                  "name": "falsefaucet"
                }
              },
              {
                "createdAt": "2026-08-01T00:30:58.841Z",
                "text": "Cannot trust other products from CoinKite either\n\nhttps://primal.net/e/nevent1qqs272yqcpr3awzapmhszf88yne3e8lh007y0ut2edtgjffpwxhgpcqdpnngp\n\nhttps://primal.net/e/nevent1qqsg9tzxn33k3agkg6qxclh0etqysh89u4cv6yjlz6y7ua9fsdlrt3gfvqtkw\n\n\n\n![](https://m.stacker.news/150417)\n\n![](https://m.stacker.news/150418)",
                "user": {
                  "name": "satonymous"
                }
              },

    Excerpt only. The complete copy is held offline and backs quotations on this site. The original publication remains the canonical public source.

  5. Earliest copy held
    seen · Captured here 18,766 chars
    Extracted text as captured
    {
      "data": {
        "item": {
          "comments": {
            "comments": [
              {
                "createdAt": "2026-07-31T14:36:54.095Z",
                "text": "###### Summary of Situation as of this Time\n\n**ACTION RECOMMENDATION: PLEASE CAREFULLY MOVE FUNDS STORED ON COLDCARD WALLETS CREATED FROM DEVICE-GENERATED ENTROPY TO UNAFFECTED WALLETS *ASAP*.**\n\nAny funds on a **COLDCARD Mk3 using a firmware from version 4.0.1 (March 2021) to 4.1.9 (latest version as of yesterday)**, where the entropy was only generated by the device, **should be considered compromised**. COLDCARD Mk4, Mk5, and Q are affected by the same issue to a lesser degree. Wallets generated by those devices are at risk of theft. Wallets that pair the device entropy with a strong passphrase or wallets created with externally generated entropy with at least 50 dice throws should not be exposed. If you used a weak passphrase and did not input external entropy (at least fifty dice throws), your funds are at risk.\n\nCoinkite has released firmware updates for COLDCARD Mk3, Mk4, Mk5, and Q. Wallets generated with the new firmware should be secure. **Updating to the new firmware does *not make affected wallets secure*. Only new wallets generated with the new firmware are unaffected.** Coinkite put out a [security advisory](https://blog.coinkite.com/coldcard-mk3-seed-generation-warning/). The security advisory has been updated to include more devices, more details about the issue, and migration advice.\n\nBlock security researchers reports that the COLDCARD Mk2 is affected the same way as the Mk3.\n\nAnyone with access to a frontier AI model is capable of reproducing the attack. Especially if you have funds on a COLDCARD single-sig wallet created with wallet-generated entropy, please carefully **move your funds to an unaffected wallet ASAP**. Single-sig wallets with a weak passphrase, or multisig wallets that can be spent by a quorum of COLDCARD wallets or composed only of COLDCARD wallets created with device-generated entropy should be considered **at risk** and funds should also be moved.",
                "user": {
                  "name": "Murch"
                }
              },
              {
                "createdAt": "2026-07-30T20:38:10.917Z",
                "text": "Kevin Loaec preliminary [conclusion](https://x.com/KLoaec/status/2082926304995762209):\n\n![](https://m.stacker.news/150212)\n\nLoaec is the founder of Wizardsardine and knows his way around bitcoin wallet stuff.",
                "user": {
                  "name": "Scoresby"
                }
              },
              {
                "createdAt": "2026-07-31T18:54:14.562Z",
                "text": "anyone get any info on opendimes if they were affected at all?\nused them over the years to gift sats for weddings/graduations\n\nhavent seen much talk about them at all",
                "user": {
                  "name": "falsefaucet"
                }
              },
              {
                "createdAt": "2026-08-01T00:30:58.841Z",
                "text": "Cannot trust other products from CoinKite either\n\nhttps://primal.net/e/nevent1qqs272yqcpr3awzapmhszf88yne3e8lh007y0ut2edtgjffpwxhgpcqdpnngp\n\nhttps://primal.net/e/nevent1qqsg9tzxn33k3agkg6qxclh0etqysh89u4cv6yjlz6y7ua9fsdlrt3gfvqtkw\n\n\n\n![](https://m.stacker.news/150417)\n\n![](https://m.stacker.news/150418)",
                "user": {
                  "name": "satonymous"
                }
              },
              {
                "createdAt": "2026-07-30T23:17:38.208Z",
                "text": "Superbly fast and comprehensible coverage on the situation. Thank you SN community",
                "user": {
                  "name": "didiplaywell"
                }
              },

    Excerpt only. The complete copy is held offline and backs quotations on this site. The original publication remains the canonical public source.

2 presentation-noise differences. Sidebar, ticker and other page chrome churn that our review classified as not being changes to what the source says.
  • +60 -60 Comment ordering churn only: the same set of comments (Murch, Scoresby, satonymous, didiplaywell, 028559d218 and others) appears in a different order with no new or changed text.
  • +28 -28 The GraphQL response reordered already captured comments, including the existing advisory summary and timeline links. No comment text changed.
How to check this yourself

The excerpts and plain unified diffs above show the text this project held and how it changed. To verify a quotation, compare it against the page itself or against the Internet Archive's copies, which are independent of this project.

Complete captures are held offline rather than mirrored here, so this page shows diffs and excerpts. If a quotation is ever disputed, the full copy can be produced. Ask.