COLDCARD RNG incident the public record, collected and explained
Informational only, and this site never asks for your seed words. details

Informational only. This is an open source collection of what others have published about the incident, together with an explanation of it. It is not financial, security or legal advice, and not a substitute for professional advice about your own situation. It is not affiliated with, endorsed by, or speaking for Coinkite. Material is attributed and quoted as published; where sources disagree their scenarios are kept separate with their assumptions rather than reconciled into one answer. Everything is meant to be checked against the linked evidence rather than taken on trust. Act on your own judgement about a particular situation. Editorial standards and corrections.

Do not disclose recovery material to a website, form, message or support account. This site never asks for it, and contributions containing recovery words or private keys are not accepted.

Coldcard and the limits of “don't trust, verify”

stackernews-limits-dont-trust-verify

https://stacker.news/items/1539812

Latest reviewed change

source content difference between and

The Stacker News thread gained a new comment containing a violent threat.

seen +7 -0 full history below
             "text": "I read this article when you first put it up and thought it was great. It's especially true that, once the fuckup was made, it was already over and disclosing it would've led to chaos. \n\nThe one thing I'll say is about the idea they did everything right, and it's more for future reference because we have to learn things from this. \n\nDarthcoin has always said, \"Be your own bank — Think like a bank.\" Which also means thinking like whoever's in charge of vault security, and also like the armed guard up front. Banks have layered security. \n\nNow for instance: \n\n* Having your entire stash in one single wallet?\n* No passphrase? Or a weak passphrase?\n* Having a very very very large stash, protected in this one little place?\n\nWouldn't we recognize these as mistakes, even if this had never happened? What if you get wrench attacked? What if your seed (in whatever stupid way you imagine) gets exposed? And it's well known (at least here on SN) that the hardware wallet itself can draw unwanted attention versus other, totally inconspicuous options like a normie laptop or USB setup. \n\n**This doesn't impact how we speak to newbs**. A young guy can spend some time in lightning and Sparrow before moving to cold storage; it doesn't have to be overcomplicated and you can organically harden your security as you go.",
             "user": {
               "name": "Aeneas"
+            }
+          },
+          {
+            "createdAt": "2026-08-04T21:23:55.620Z",
+            "text": "> I know who you are now. And I will come there and stab a knife in your eyeballs on live stream for the world to see. You will not just suffer for one minute. I will make you paraplegic and let you suffer for weeks and starve to death while we celebrate. You made this bed for yourself, A.\n \n\nhttps://mempool.space/tx/3910552633d25e6c0360281c43651cd7ae3cc70257759db7a8c07bef6f2994d8?mode=details#:~:text=I%20know%20who%20you%20are%20now.%20And%20I%20will%20come%20there%20and%20stab%20a%20knife%20in%20your%20eyeballs%20on%20live%20stream%20for%20the%20world%20to%20see.%20You%20will%20not%20just%20suffer%20for%20one%20minute.%20I%20will%20make%20you%20paraplegic%20and%20let%20you%20suffer%20for%20weeks%20and%20starve%20to%20death%20while%20we%20celebrate.%20You%20made%20this%20bed%20for%20yourself%2C%20A.",

First lines only. The complete diff is in the timeline below.

Organisation
Stacker News
Evidence role
Community discussion
Published
2026-08-04
Source changes
1
Detected differences
1
Unreviewed
0
Copies held
2

bennet examining what the incident says about the limits of the “don't trust, verify” framing. A community debate about code review, product trust and self-custody practice, alongside stackernews-personal-responsibility and stackernews-dear-podcasters. The arguments in the thread are the posters' own, not verified here. Captured through the site's public GraphQL API: the rendered pages crash the capture tab, and the API answers POST from this host. The query fixes the captured surface to the item's title, text and two levels of comments, each with author and absolute timestamp.

Every check is recorded, including checks that found no text change. A detected edit is therefore bounded between two checks. The publisher's exact save time is not observable from this record. Last checked .

  1. source content difference between and Current source content +7 -0

    The Stacker News thread gained a new comment containing a violent threat.

    seen · Captured here 5,176 chars
    What changed from the previous capture 7 lines
                 "text": "I read this article when you first put it up and thought it was great. It's especially true that, once the fuckup was made, it was already over and disclosing it would've led to chaos. \n\nThe one thing I'll say is about the idea they did everything right, and it's more for future reference because we have to learn things from this. \n\nDarthcoin has always said, \"Be your own bank — Think like a bank.\" Which also means thinking like whoever's in charge of vault security, and also like the armed guard up front. Banks have layered security. \n\nNow for instance: \n\n* Having your entire stash in one single wallet?\n* No passphrase? Or a weak passphrase?\n* Having a very very very large stash, protected in this one little place?\n\nWouldn't we recognize these as mistakes, even if this had never happened? What if you get wrench attacked? What if your seed (in whatever stupid way you imagine) gets exposed? And it's well known (at least here on SN) that the hardware wallet itself can draw unwanted attention versus other, totally inconspicuous options like a normie laptop or USB setup. \n\n**This doesn't impact how we speak to newbs**. A young guy can spend some time in lightning and Sparrow before moving to cold storage; it doesn't have to be overcomplicated and you can organically harden your security as you go.",
                 "user": {
                   "name": "Aeneas"
    +            }
    +          },
    +          {
    +            "createdAt": "2026-08-04T21:23:55.620Z",
    +            "text": "> I know who you are now. And I will come there and stab a knife in your eyeballs on live stream for the world to see. You will not just suffer for one minute. I will make you paraplegic and let you suffer for weeks and starve to death while we celebrate. You made this bed for yourself, A.\n \n\nhttps://mempool.space/tx/3910552633d25e6c0360281c43651cd7ae3cc70257759db7a8c07bef6f2994d8?mode=details#:~:text=I%20know%20who%20you%20are%20now.%20And%20I%20will%20come%20there%20and%20stab%20a%20knife%20in%20your%20eyeballs%20on%20live%20stream%20for%20the%20world%20to%20see.%20You%20will%20not%20just%20suffer%20for%20one%20minute.%20I%20will%20make%20you%20paraplegic%20and%20let%20you%20suffer%20for%20weeks%20and%20starve%20to%20death%20while%20we%20celebrate.%20You%20made%20this%20bed%20for%20yourself%2C%20A.",
    +            "user": {
    +              "name": "denlillaapan"
                 }
               },
               {
    
    Extracted text as captured
    {
      "data": {
        "item": {
          "comments": {
            "comments": [
              {
                "createdAt": "2026-08-04T10:10:50.807Z",
                "text": "I really like this article. You do a nice job of explaining things clearly and I really like where you take it. Blaming this on AI is definitely scape-goatism:\n\n> the reality is almost too mundane to believe.\n\n> Pointing the finger at “a complex and subtle series of bugs” (to quote their postmortem), or at AI (for assisting in discovery of the issue) is an abdication of responsibility.\n\n> This was a build flag that didn’t do what its author thought it did. Human error, hiding in plain sight.\n\nAnd I especially appreciated the latter half of your article. I agree with this:\n\n> More people *should’ve* verified Coldcard’s code for themselves, absolutely. But have you studied the Bitcoin source code line by line? No? Then you’re *trusting* it, not verifying it for yourself. And that’s fine - for 99% of people, some degree of trust is unavoidable.\n\nI wonder though if it wouldn't be better for Bitcoin if the expectation was that influencers who accept sponsorship money retain a little more objectivity. I've never been sponsored to do anything, so I can't quite say how it feels, but I'm sure there is a lot of pressure to refrain from saying negative things about the sponsors products. Hopefully this incident is so bad that influencers are more willing to be critical.",
                "user": {
                  "name": "Scoresby"
                }
              },
              {
                "createdAt": "2026-08-04T16:13:25.203Z",
                "text": "I read this article when you first put it up and thought it was great. It's especially true that, once the fuckup was made, it was already over and disclosing it would've led to chaos. \n\nThe one thing I'll say is about the idea they did everything right, and it's more for future reference because we have to learn things from this. \n\nDarthcoin has always said, \"Be your own bank — Think like a bank.\" Which also means thinking like whoever's in charge of vault security, and also like the armed guard up front. Banks have layered security. \n\nNow for instance: \n\n* Having your entire stash in one single wallet?\n* No passphrase? Or a weak passphrase?\n* Having a very very very large stash, protected in this one little place?\n\nWouldn't we recognize these as mistakes, even if this had never happened? What if you get wrench attacked? What if your seed (in whatever stupid way you imagine) gets exposed? And it's well known (at least here on SN) that the hardware wallet itself can draw unwanted attention versus other, totally inconspicuous options like a normie laptop or USB setup. \n\n**This doesn't impact how we speak to newbs**. A young guy can spend some time in lightning and Sparrow before moving to cold storage; it doesn't have to be overcomplicated and you can organically harden your security as you go.",
                "user": {
                  "name": "Aeneas"
                }
              },
              {
                "createdAt": "2026-08-04T21:23:55.620Z",
                "text": "> I know who you are now. And I will come there and stab a knife in your eyeballs on live stream for the world to see. You will not just suffer for one minute. I will make you paraplegic and let you suffer for weeks and starve to death while we celebrate. You made this bed for yourself, A.\n \n\nhttps://mempool.space/tx/3910552633d25e6c0360281c43651cd7ae3cc70257759db7a8c07bef6f2994d8?mode=details#:~:text=I%20know%20who%20you%20are%20now.%20And%20I%20will%20come%20there%20and%20stab%20a%20knife%20in%20your%20eyeballs%20on%20live%20stream%20for%20the%20world%20to%20see.%20You%20will%20not%20just%20suffer%20for%20one%20minute.%20I%20will%20make%20you%20paraplegic%20and%20let%20you%20suffer%20for%20weeks%20and%20starve%20to%20death%20while%20we%20celebrate.%20You%20made%20this%20bed%20for%20yourself%2C%20A.",
                "user": {
                  "name": "denlillaapan"
                }
              },
              {
                "createdAt": "2026-08-04T10:49:17.878Z",
                "text": "This incident showed us that \"don't trust, verify\" also applies to the RNG.",
                "user": {
                  "name": "Filiprogrammer"
                }
              },
              {
                "createdAt": "2026-08-04T16:02:31.793Z",
                "text": "you could sweep the funds yourself and return them minus a finders fee.  \n\nre \"A seed generated on a flawed Coldcard is permanently weak, so responsible disclosure had nowhere to go.\"",
                "user": {
                  "name": "standardcrypto"
                }
              }

    Excerpt only. The complete copy is held offline and backs quotations on this site. The original publication remains the canonical public source.

  2. Earliest copy held
    seen · Captured here 4,187 chars
    Extracted text as captured
    {
      "data": {
        "item": {
          "comments": {
            "comments": [
              {
                "createdAt": "2026-08-04T10:10:50.807Z",
                "text": "I really like this article. You do a nice job of explaining things clearly and I really like where you take it. Blaming this on AI is definitely scape-goatism:\n\n> the reality is almost too mundane to believe.\n\n> Pointing the finger at “a complex and subtle series of bugs” (to quote their postmortem), or at AI (for assisting in discovery of the issue) is an abdication of responsibility.\n\n> This was a build flag that didn’t do what its author thought it did. Human error, hiding in plain sight.\n\nAnd I especially appreciated the latter half of your article. I agree with this:\n\n> More people *should’ve* verified Coldcard’s code for themselves, absolutely. But have you studied the Bitcoin source code line by line? No? Then you’re *trusting* it, not verifying it for yourself. And that’s fine - for 99% of people, some degree of trust is unavoidable.\n\nI wonder though if it wouldn't be better for Bitcoin if the expectation was that influencers who accept sponsorship money retain a little more objectivity. I've never been sponsored to do anything, so I can't quite say how it feels, but I'm sure there is a lot of pressure to refrain from saying negative things about the sponsors products. Hopefully this incident is so bad that influencers are more willing to be critical.",
                "user": {
                  "name": "Scoresby"
                }
              },
              {
                "createdAt": "2026-08-04T16:13:25.203Z",
                "text": "I read this article when you first put it up and thought it was great. It's especially true that, once the fuckup was made, it was already over and disclosing it would've led to chaos. \n\nThe one thing I'll say is about the idea they did everything right, and it's more for future reference because we have to learn things from this. \n\nDarthcoin has always said, \"Be your own bank — Think like a bank.\" Which also means thinking like whoever's in charge of vault security, and also like the armed guard up front. Banks have layered security. \n\nNow for instance: \n\n* Having your entire stash in one single wallet?\n* No passphrase? Or a weak passphrase?\n* Having a very very very large stash, protected in this one little place?\n\nWouldn't we recognize these as mistakes, even if this had never happened? What if you get wrench attacked? What if your seed (in whatever stupid way you imagine) gets exposed? And it's well known (at least here on SN) that the hardware wallet itself can draw unwanted attention versus other, totally inconspicuous options like a normie laptop or USB setup. \n\n**This doesn't impact how we speak to newbs**. A young guy can spend some time in lightning and Sparrow before moving to cold storage; it doesn't have to be overcomplicated and you can organically harden your security as you go.",
                "user": {
                  "name": "Aeneas"
                }
              },
              {
                "createdAt": "2026-08-04T10:49:17.878Z",
                "text": "This incident showed us that \"don't trust, verify\" also applies to the RNG.",
                "user": {
                  "name": "Filiprogrammer"
                }
              },
              {
                "createdAt": "2026-08-04T16:02:31.793Z",
                "text": "you could sweep the funds yourself and return them minus a finders fee.  \n\nre \"A seed generated on a flawed Coldcard is permanently weak, so responsible disclosure had nowhere to go.\"",
                "user": {
                  "name": "standardcrypto"
                }
              }
            ]
          },
          "createdAt": "2026-08-04T07:52:59.005Z",
          "text": "I don't see a version of this which ended without funds being stolen. A seed generated on a flawed Coldcard is permanently weak, so responsible disclosure had nowhere to go. \n\nI've written up the technical failure, why I don't buy blaming AI, and why I think the \"you were never really self-custodying\" line is so misguided.",
          "title": "Coldcard and the limits of “don't trust, verify”",
          "user": {
            "name": "bennet"

    Excerpt only. The complete copy is held offline and backs quotations on this site. The original publication remains the canonical public source.

How to check this yourself

The excerpts and plain unified diffs above show the text this project held and how it changed. To verify a quotation, compare it against the page itself or against the Internet Archive's copies, which are independent of this project.

Complete captures are held offline rather than mirrored here, so this page shows diffs and excerpts. If a quotation is ever disputed, the full copy can be produced. Ask.