COLDCARD RNG incident the public record, collected and explained
Informational only, and this site never asks for your seed words. details

Informational only. This is an open source collection of what others have published about the incident, together with an explanation of it. It is not financial, security or legal advice, and not a substitute for professional advice about your own situation. It is not affiliated with, endorsed by, or speaking for Coinkite. Material is attributed and quoted as published; where sources disagree their scenarios are kept separate with their assumptions rather than reconciled into one answer. Everything is meant to be checked against the linked evidence rather than taken on trust. Act on your own judgement about a particular situation. Editorial standards and corrections.

Do not disclose recovery material to a website, form, message or support account. This site never asks for it, and contributions containing recovery words or private keys are not accepted.

PSA: Advice Regarding the Coldcard Bug - Exploit - Hack - Theft

stackernews-psa-advice

https://stacker.news/items/1538049

Organisation
Stacker News
Evidence role
Community discussion
Published
2026-08-01
Source changes
0
Detected differences
0
Unreviewed
0
Copies held
1

BITC0IN's PSA with owner advice, including the Mk3-without-passphrase case. Community guidance from the response window; specific claims are the author's and partly contested in replies. Captured through the site's public GraphQL API: the rendered pages crash the capture tab, and the API answers POST from this host. The query fixes the captured surface to the item's title, text and two levels of comments, each with author and absolute timestamp.

Every check is recorded, including checks that found no text change. A detected edit is therefore bounded between two checks. The publisher's exact save time is not observable from this record. Last checked .

  1. Earliest copy held Current
    seen · Captured here 4,043 chars
    Extracted text as captured
    {
      "data": {
        "item": {
          "comments": {
            "comments": [
              {
                "createdAt": "2026-08-02T00:21:59.662Z",
                "text": "If you trusted Cold Card to properly use their secure element, how can you be sure they properly used your dice roll entropy? I know you can check the outputs with a CLI script but who actually does that?\n\nI'd go even farther and say just ditch Cold Card altogether. You have nothing to gain by staying and everything to lose.",
                "user": {
                  "name": "UncleJim21"
                }
              },
              {
                "createdAt": "2026-08-02T04:29:35.696Z",
                "text": "Interesting post... I just disagree with putting your funds on an exchange since it's like Russian roulette (don't get involved with any of them) as it's not recommended.\nBlockstream wallets are quite secure and are not under attack, as their creators have already announced!",
                "user": {
                  "name": "mkmloom"
                }
              }
            ]
          },
          "createdAt": "2026-08-01T22:24:20.088Z",
          "text": "![](https://m.stacker.news/150512)\n\nI’m just going to write, this won’t be polished.\n\n**If you have/use a coldcard MK3 without a passphrase, that wasn’t setup with 100+ dice rolls, you need to move your funds out of that coldcard as soon as possible to safe harbor.**\n\n*If you have/use a coldcard MK4/5/Q without a passphrase, that wasn’t setup with 100+ dice rolls, you need to move your funds out of that coldcard sooner then latter to safe harbor.*\n\nIf you have/use a coldcard MK3/MK4/5/Q with a passphrase and/or that was setup with 100+ dice rolls, you have more time. It could very well be safe for the long term too, but you’d be wise to migrate to safer harbor eventually.\n\n**If you use any of these devices and forget what your setup is, you need to move to safe harbor as soon as possible.**\n\n----------------------------------------------------------------------------------------------------------------------\n\n**What is safe harbor at this point in time? For MK3’s with no passphrase/no dice – literally anything else. Hot wallets are better in this moment in time (blue wallet, sparrow wallet). Exchanges are also an option. Adding a 16 character passphrase on top of your Mk3 wallet is also an option and helps. Another hardware wallet from a different vendor is better too. Anything else is better at this moment. Your funds are at severe risk in a mk3 here. But none of these safe harbours are long term solutions, they’re short term safety nets for an extreme situation. Consider your safe harbour options carefully and pick the strongest one for your situation.**\n\n*Safe harbor for the MK4/5/Q’s with no dice/no passphrase is the same situation to be honest. Get it off somewhere else, anywhere else.*\n\n**Before moving to hot wallets/exchanges please consider if you have other more secure options available. A spare hardware wallet from another vendor, trezor, ledger etc might be better in this moment too.**\n\nIdeally for everyone else not in the extreme conditions, migrating away from coldcard eventually is probably wise here for several reasons I won’t get into yet, but are probably obvious. A 2/3 Multisig setup from multiple different hardware wallet brands is ideal long term, and guards against this attack/bug. Seedsigner, Krux, Trezor Model 5 Bitcoin only version, are good options to consider for such a multsig arrangement at this point in time. I don’t believe it wise to reuse coldcards for long term storage even if updated at this point in time. This article (link below) is a good follow up on entropy generation offline with analog methods. This guards against this coldcard attack/bug.\n\n[https://btcmaxis.com/article.html?id=7554e7cb-d8aa-45d5-95c8-adea8d87ea23](https://btcmaxis.com/article.html?id=7554e7cb-d8aa-45d5-95c8-adea8d87ea23)",
          "title": "PSA: Advice Regarding the Coldcard Bug - Exploit - Hack - Theft",
          "user": {
            "name": "BITC0IN"
          }
        }
      }
    }
How to check this yourself

The excerpts and plain unified diffs above show the text this project held and how it changed. To verify a quotation, compare it against the page itself or against the Internet Archive's copies, which are independent of this project.

Complete captures are held offline rather than mirrored here, so this page shows diffs and excerpts. If a quotation is ever disputed, the full copy can be produced. Ask.