COLDCARD RNG incident the public record, collected and explained
Informational only, and this site never asks for your seed words. details

Informational only. This is an open source collection of what others have published about the incident, together with an explanation of it. It is not financial, security or legal advice, and not a substitute for professional advice about your own situation. It is not affiliated with, endorsed by, or speaking for Coinkite. Material is attributed and quoted as published; where sources disagree their scenarios are kept separate with their assumptions rather than reconciled into one answer. Everything is meant to be checked against the linked evidence rather than taken on trust. Act on your own judgement about a particular situation. Editorial standards and corrections.

Do not disclose recovery material to a website, form, message or support account. This site never asks for it, and contributions containing recovery words or private keys are not accepted.

Trezor's CTO on the Cold Card Hack: Randomness, Trust, and What Comes Next

stackernews-trezor-cto-coldcard-hack

https://stacker.news/items/1542511

Organisation
Stacker News
Evidence role
Community discussion
Published
2026-08-07
Source changes
0
Detected differences
0
Unreviewed
0
Copies held
1

efrat interviewing Trezor CTO Tomáš Sušánka days after the Coldcard hack, covering entropy, Trezor's RNG design, open-source review limits, and multisig. A vendor competitor's perspective on the incident and what comes next, alongside trezor-coldcard-not-affected. The claims are the speakers' own, not verified here. Captured through the site's public GraphQL API: the rendered pages crash the capture tab, and the API answers POST from this host. The query fixes the captured surface to the item's title, text and two levels of comments, each with author and absolute timestamp.

Every check is recorded, including checks that found no text change. A detected edit is therefore bounded between two checks. The publisher's exact save time is not observable from this record. Last checked .

  1. Earliest copy held Current
    seen · Captured here 1,144 chars
    Extracted text as captured
    {
      "data": {
        "item": {
          "comments": {
            "comments": [
              {
                "createdAt": "2026-08-07T16:32:57.497Z",
                "text": "Looking forward to listening to this one.",
                "user": {
                  "name": "Scoresby"
                }
              },
              {
                "createdAt": "2026-08-07T16:29:17.400Z",
                "text": "🔗 Privacy-friendly: https://invidious.nerdvpn.de/watch?v=GLyqeR8D-FI",
                "user": {
                  "name": "YewTuBot"
                }
              }
            ]
          },
          "createdAt": "2026-08-07T16:07:00.113Z",
          "text": "Tomáš Sušánka is the CTO of Trezor @trezor.io. Days after the Cold Card hack, where a flawed RNG exposed seed phrases and led to 1,500+ BTC stolen, he joins Efrat for an urgent conversation answering questions from the Bitcoin community.\n\n⚡ What entropy actually is\n⚡ Trezor's four-source RNG\n⚡ Why open source ≠ secure\n⚡ The 5-year undetected bug\n⚡ Single device vs. multisig",
          "title": "NEW: Trezor's CTO on the Cold Card Hack: Randomness, Trust, and What Comes Next",
          "user": {
            "name": "efrat"
          }
        }
      }
    }
How to check this yourself

The excerpts and plain unified diffs above show the text this project held and how it changed. To verify a quotation, compare it against the page itself or against the Internet Archive's copies, which are independent of this project.

Complete captures are held offline rather than mirrored here, so this page shows diffs and excerpts. If a quotation is ever disputed, the full copy can be produced. Ask.