COLDCARD RNG incident the public record, collected and explained
Informational only, and this site never asks for your seed words. details

Informational only. This is an open source collection of what others have published about the incident, together with an explanation of it. It is not financial, security or legal advice, and not a substitute for professional advice about your own situation. It is not affiliated with, endorsed by, or speaking for Coinkite. Material is attributed and quoted as published; where sources disagree their scenarios are kept separate with their assumptions rather than reconciled into one answer. Everything is meant to be checked against the linked evidence rather than taken on trust. Act on your own judgement about a particular situation. Editorial standards and corrections.

Do not disclose recovery material to a website, form, message or support account. This site never asks for it, and contributions containing recovery words or private keys are not accepted.

Unchained key-replacement help article

unchained-help-replace-keys

https://help.unchained.com/how-do-i-replace-the-keys-to-my-vault

Latest reviewed change

source content difference between and

Unchained added billing-plan context for subscription transfers and an alternative withdrawal procedure using the new vault's copied deposit address when Internal transfer is unavailable.

seen +3 -3 full history below
 Log in to your Unchained account.
 Ensure you have two secure, uncompromised keys available to build the new vault. You may need to setup and add new keys to your account.
 Navigate to the vault creation flow and set up your new vault.
-Ensure you select the option to transfer your existing subscription to this new vault. This will activate your 30-day grace period.
-Once your new vault is active, initiate a transaction sending all of the bitcoin from your old vault to your new vault.
-When initiating the withdrawal on your old vault, you can choose “Internal transfer” and select the new vault.
+Ensure you select the option to transfer your existing subscription to this new vault. This will activate your 30-day grace period. Some clients will not see this option due to being grandfathered into an account-level billing plan.
+Once your new vault is active, initiate a withdrawal transaction sending all of the bitcoin from your old vault to your new vault.

First lines only. The complete diff is in the timeline below.

Organisation
Unchained
Evidence role
Custody guidance
Published
not established
Source changes
4
Detected differences
4
Unreviewed
0
Copies held
5

Unchained's help-centre article on replacing vault keys, updated with incident-specific guidance: it names the July/August 2026 Coldcard vulnerability, tells clients with two Coldcard-generated keys to consider broadcasting via Slipstream, and says to use only Coldcard firmware from 31 Jul 2026 or later. The page shows no last-updated stamp, which is exactly why it needs capture: this is where Unchained's operational client guidance lives and it can change without notice.

Every check is recorded, including checks that found no text change. A detected edit is therefore bounded between two checks. The publisher's exact save time is not observable from this record. Last checked .

  1. source content difference between and Current source content +3 -3

    Unchained added billing-plan context for subscription transfers and an alternative withdrawal procedure using the new vault's copied deposit address when Internal transfer is unavailable.

    seen · Captured here 4,187 chars
    What changed from the previous capture 6 lines
     Log in to your Unchained account.
     Ensure you have two secure, uncompromised keys available to build the new vault. You may need to setup and add new keys to your account.
     Navigate to the vault creation flow and set up your new vault.
    -Ensure you select the option to transfer your existing subscription to this new vault. This will activate your 30-day grace period.
    -Once your new vault is active, initiate a transaction sending all of the bitcoin from your old vault to your new vault.
    -When initiating the withdrawal on your old vault, you can choose “Internal transfer” and select the new vault.
    +Ensure you select the option to transfer your existing subscription to this new vault. This will activate your 30-day grace period. Some clients will not see this option due to being grandfathered into an account-level billing plan.
    +Once your new vault is active, initiate a withdrawal transaction sending all of the bitcoin from your old vault to your new vault.
    +When initiating the withdrawal on your old vault, you can choose Internal transfer and select the new vault. If you don't see the internal transfer option, then navigate to your new vault and copy the deposit address. Then return to your old vault, create the withdrawal, and paste the address in the address field. Double check that it looks the same as the address you copied.
     If you have 2 Coldcard-generated keys and are affected by the July/August 2026 Coldcard vulnerability, be aware of the option to broadcast your transaction using Slipstream. This is unnecessary if you only have 1 Coldcard-generated key.
     Once the transaction is confirmed, your funds are safely secured in the new vault. You can then close the old vault.
     If you encounter any issues or have questions regarding your specific vault configuration, please contact our support team for guidance before proceeding.
    
    Extracted text as captured
    Skip to content
    Open main navigation
    Close main navigation
    How can we help?
    There are no suggestions because the search field is empty.
    Knowledge Base
    Keys
    Coldcard
    How do I replace the keys to my vault?
    You can replace multiple keys with one step by building a new vault
    Creating a new vault is our recommended alternative to using our key replacement feature, especially if you need to rotate multiple keys. By following these instructions to create a new vault and manually sweeping your funds into it, you gain a cleaner, safer, and more flexible process.
    Note about IRA vaults: If you have an IRA vault, you may use this method. Ensure that you are building the new vault within the same IRA account. Once finished, please close the old IRA vault. You should only have one active vault per IRA account.
    Moving bitcoin between vaults within the same IRA account is not treated as a taxable distribution, provided the bitcoin remains within the IRA account and is not transferred to a personal wallet or another account outside the IRA.
    You may see a big red warning on the deposit address for your new IRA vault. The warning is intended to prevent an outside deposit from being sent directly to an IRA vault without going through the approved contribution or rollover process. You may proceed when you are using this workflow to move bitcoin between vaults in the same IRA account. Do not disregard the warning for bitcoin coming from a personal wallet, exchange, or any other source outside the IRA.
    How to create a new vault and move your funds
    Log in to your Unchained account.
    Ensure you have two secure, uncompromised keys available to build the new vault. You may need to setup and add new keys to your account.
    Navigate to the vault creation flow and set up your new vault.
    Ensure you select the option to transfer your existing subscription to this new vault. This will activate your 30-day grace period. Some clients will not see this option due to being grandfathered into an account-level billing plan.
    Once your new vault is active, initiate a withdrawal transaction sending all of the bitcoin from your old vault to your new vault.
    When initiating the withdrawal on your old vault, you can choose Internal transfer and select the new vault. If you don't see the internal transfer option, then navigate to your new vault and copy the deposit address. Then return to your old vault, create the withdrawal, and paste the address in the address field. Double check that it looks the same as the address you copied.
    If you have 2 Coldcard-generated keys and are affected by the July/August 2026 Coldcard vulnerability, be aware of the option to broadcast your transaction using Slipstream. This is unnecessary if you only have 1 Coldcard-generated key.
    Once the transaction is confirmed, your funds are safely secured in the new vault. You can then close the old vault.
    If you encounter any issues or have questions regarding your specific vault configuration, please contact our support team for guidance before proceeding.
    Keys
    Getting started
    Device checks
    Key replacements and recovery
    Trezor
    Ledger
    Coldcard
    BitBox
    Jade
    Vaults
    Setting up a vault
    Receiving a deposit
    Making a withdrawal
    Vault navigation
    UTXO management
    Connections

    Excerpt only. The complete copy is held offline and backs quotations on this site. The original publication remains the canonical public source.

  2. source content difference between and source content +3 -2

    The help article's IRA note was reworded to "Note about IRA vaults" and gained a new sentence stating that moving bitcoin between vaults within the same IRA account is not treated as a taxable distribution, provided the bitcoin stays within the IRA.

    seen · Captured here 3,807 chars
    What changed from the previous capture 5 lines
     How do I replace the keys to my vault?
     You can replace multiple keys with one step by building a new vault
     Creating a new vault is our recommended alternative to using our key replacement feature, especially if you need to rotate multiple keys. By following these instructions to create a new vault and manually sweeping your funds into it, you gain a cleaner, safer, and more flexible process.
    -Note: If you have an IRA vault, you may use this method. Ensure that you are building the new vault within the same IRA account. Once finished, please close the old IRA vault. You should only have one active vault per IRA account.
    -You may see a big red warning on the deposit address for your new IRA vault. The warning is intended to prevent an outside deposit from being sent directly to an IRA vault without going through the approved contribution or rollover process. You may proceed when you are using this workflow to move bitcoin between vaults in the same IRA account. Do not disregard the warning for bitcoin coming from a personal wallet, exchange, or any other source outside the IRA.
    +Note about IRA vaults: If you have an IRA vault, you may use this method. Ensure that you are building the new vault within the same IRA account. Once finished, please close the old IRA vault. You should only have one active vault per IRA account.
    +Moving bitcoin between vaults within the same IRA account is not treated as a taxable distribution, provided the bitcoin remains within the IRA account and is not transferred to a personal wallet or another account outside the IRA.
    +You may see a big red warning on the deposit address for your new IRA vault. The warning is intended to prevent an outside deposit from being sent directly to an IRA vault without going through the approved contribution or rollover process. You may proceed when you are using this workflow to move bitcoin between vaults in the same IRA account. Do not disregard the warning for bitcoin coming from a personal wallet, exchange, or any other source outside the IRA.
     How to create a new vault and move your funds
     Log in to your Unchained account.
     Ensure you have two secure, uncompromised keys available to build the new vault. You may need to setup and add new keys to your account.
    
    Extracted text as captured
    Skip to content
    Open main navigation
    Close main navigation
    How can we help?
    There are no suggestions because the search field is empty.
    Knowledge Base
    Keys
    Coldcard
    How do I replace the keys to my vault?
    You can replace multiple keys with one step by building a new vault
    Creating a new vault is our recommended alternative to using our key replacement feature, especially if you need to rotate multiple keys. By following these instructions to create a new vault and manually sweeping your funds into it, you gain a cleaner, safer, and more flexible process.
    Note about IRA vaults: If you have an IRA vault, you may use this method. Ensure that you are building the new vault within the same IRA account. Once finished, please close the old IRA vault. You should only have one active vault per IRA account.
    Moving bitcoin between vaults within the same IRA account is not treated as a taxable distribution, provided the bitcoin remains within the IRA account and is not transferred to a personal wallet or another account outside the IRA.
    You may see a big red warning on the deposit address for your new IRA vault. The warning is intended to prevent an outside deposit from being sent directly to an IRA vault without going through the approved contribution or rollover process. You may proceed when you are using this workflow to move bitcoin between vaults in the same IRA account. Do not disregard the warning for bitcoin coming from a personal wallet, exchange, or any other source outside the IRA.
    How to create a new vault and move your funds
    Log in to your Unchained account.
    Ensure you have two secure, uncompromised keys available to build the new vault. You may need to setup and add new keys to your account.
    Navigate to the vault creation flow and set up your new vault.
    Ensure you select the option to transfer your existing subscription to this new vault. This will activate your 30-day grace period.
    Once your new vault is active, initiate a transaction sending all of the bitcoin from your old vault to your new vault.
    When initiating the withdrawal on your old vault, you can choose “Internal transfer” and select the new vault.
    If you have 2 Coldcard-generated keys and are affected by the July/August 2026 Coldcard vulnerability, be aware of the option to broadcast your transaction using Slipstream. This is unnecessary if you only have 1 Coldcard-generated key.
    Once the transaction is confirmed, your funds are safely secured in the new vault. You can then close the old vault.
    If you encounter any issues or have questions regarding your specific vault configuration, please contact our support team for guidance before proceeding.
    Keys
    Getting started
    Device checks
    Key replacements and recovery
    Trezor
    Ledger
    Coldcard
    BitBox
    Jade
    Vaults
    Setting up a vault
    Receiving a deposit
    Making a withdrawal
    Vault navigation
    UTXO management
    Connections

    Excerpt only. The complete copy is held offline and backs quotations on this site. The original publication remains the canonical public source.

  3. source content difference between and source content +1 -1

    The new IRA vault warning paragraph was reworded: "Unchained's workflow" became "this workflow". No other text changed.

    seen · Captured here 3,558 chars
    What changed from the previous capture 2 lines
     You can replace multiple keys with one step by building a new vault
     Creating a new vault is our recommended alternative to using our key replacement feature, especially if you need to rotate multiple keys. By following these instructions to create a new vault and manually sweeping your funds into it, you gain a cleaner, safer, and more flexible process.
     Note: If you have an IRA vault, you may use this method. Ensure that you are building the new vault within the same IRA account. Once finished, please close the old IRA vault. You should only have one active vault per IRA account.
    -You may see a big red warning on the deposit address for your new IRA vault. The warning is intended to prevent an outside deposit from being sent directly to an IRA vault without going through the approved contribution or rollover process. You may proceed when you are using Unchained's workflow to move bitcoin between vaults in the same IRA account. Do not disregard the warning for bitcoin coming from a personal wallet, exchange, or any other source outside the IRA.
    +You may see a big red warning on the deposit address for your new IRA vault. The warning is intended to prevent an outside deposit from being sent directly to an IRA vault without going through the approved contribution or rollover process. You may proceed when you are using this workflow to move bitcoin between vaults in the same IRA account. Do not disregard the warning for bitcoin coming from a personal wallet, exchange, or any other source outside the IRA.
     How to create a new vault and move your funds
     Log in to your Unchained account.
     Ensure you have two secure, uncompromised keys available to build the new vault. You may need to setup and add new keys to your account.
    
    Extracted text as captured
    Skip to content
    Open main navigation
    Close main navigation
    How can we help?
    There are no suggestions because the search field is empty.
    Knowledge Base
    Keys
    Coldcard
    How do I replace the keys to my vault?
    You can replace multiple keys with one step by building a new vault
    Creating a new vault is our recommended alternative to using our key replacement feature, especially if you need to rotate multiple keys. By following these instructions to create a new vault and manually sweeping your funds into it, you gain a cleaner, safer, and more flexible process.
    Note: If you have an IRA vault, you may use this method. Ensure that you are building the new vault within the same IRA account. Once finished, please close the old IRA vault. You should only have one active vault per IRA account.
    You may see a big red warning on the deposit address for your new IRA vault. The warning is intended to prevent an outside deposit from being sent directly to an IRA vault without going through the approved contribution or rollover process. You may proceed when you are using this workflow to move bitcoin between vaults in the same IRA account. Do not disregard the warning for bitcoin coming from a personal wallet, exchange, or any other source outside the IRA.
    How to create a new vault and move your funds
    Log in to your Unchained account.
    Ensure you have two secure, uncompromised keys available to build the new vault. You may need to setup and add new keys to your account.
    Navigate to the vault creation flow and set up your new vault.
    Ensure you select the option to transfer your existing subscription to this new vault. This will activate your 30-day grace period.
    Once your new vault is active, initiate a transaction sending all of the bitcoin from your old vault to your new vault.
    When initiating the withdrawal on your old vault, you can choose “Internal transfer” and select the new vault.
    If you have 2 Coldcard-generated keys and are affected by the July/August 2026 Coldcard vulnerability, be aware of the option to broadcast your transaction using Slipstream. This is unnecessary if you only have 1 Coldcard-generated key.
    Once the transaction is confirmed, your funds are safely secured in the new vault. You can then close the old vault.
    If you encounter any issues or have questions regarding your specific vault configuration, please contact our support team for guidance before proceeding.
    Keys
    Getting started
    Device checks
    Key replacements and recovery
    Trezor
    Ledger
    Coldcard
    BitBox
    Jade
    Vaults
    Setting up a vault
    Receiving a deposit
    Making a withdrawal
    Vault navigation
    UTXO management
    Connections
    Making a connection

    Excerpt only. The complete copy is held offline and backs quotations on this site. The original publication remains the canonical public source.

  4. source content difference between and source content +1 -0

    The help article added a paragraph explaining the big red warning shown on the deposit address of a new IRA vault: it exists to block outside deposits that skip the approved contribution or rollover process, and may be bypassed only when moving bitcoin between vaults in the same IRA account.

    seen · Captured here 3,565 chars
    What changed from the previous capture 1 lines
     You can replace multiple keys with one step by building a new vault
     Creating a new vault is our recommended alternative to using our key replacement feature, especially if you need to rotate multiple keys. By following these instructions to create a new vault and manually sweeping your funds into it, you gain a cleaner, safer, and more flexible process.
     Note: If you have an IRA vault, you may use this method. Ensure that you are building the new vault within the same IRA account. Once finished, please close the old IRA vault. You should only have one active vault per IRA account.
    +You may see a big red warning on the deposit address for your new IRA vault. The warning is intended to prevent an outside deposit from being sent directly to an IRA vault without going through the approved contribution or rollover process. You may proceed when you are using Unchained's workflow to move bitcoin between vaults in the same IRA account. Do not disregard the warning for bitcoin coming from a personal wallet, exchange, or any other source outside the IRA.
     How to create a new vault and move your funds
     Log in to your Unchained account.
     Ensure you have two secure, uncompromised keys available to build the new vault. You may need to setup and add new keys to your account.
    
    Extracted text as captured
    Skip to content
    Open main navigation
    Close main navigation
    How can we help?
    There are no suggestions because the search field is empty.
    Knowledge Base
    Keys
    Coldcard
    How do I replace the keys to my vault?
    You can replace multiple keys with one step by building a new vault
    Creating a new vault is our recommended alternative to using our key replacement feature, especially if you need to rotate multiple keys. By following these instructions to create a new vault and manually sweeping your funds into it, you gain a cleaner, safer, and more flexible process.
    Note: If you have an IRA vault, you may use this method. Ensure that you are building the new vault within the same IRA account. Once finished, please close the old IRA vault. You should only have one active vault per IRA account.
    You may see a big red warning on the deposit address for your new IRA vault. The warning is intended to prevent an outside deposit from being sent directly to an IRA vault without going through the approved contribution or rollover process. You may proceed when you are using Unchained's workflow to move bitcoin between vaults in the same IRA account. Do not disregard the warning for bitcoin coming from a personal wallet, exchange, or any other source outside the IRA.
    How to create a new vault and move your funds
    Log in to your Unchained account.
    Ensure you have two secure, uncompromised keys available to build the new vault. You may need to setup and add new keys to your account.
    Navigate to the vault creation flow and set up your new vault.
    Ensure you select the option to transfer your existing subscription to this new vault. This will activate your 30-day grace period.
    Once your new vault is active, initiate a transaction sending all of the bitcoin from your old vault to your new vault.
    When initiating the withdrawal on your old vault, you can choose “Internal transfer” and select the new vault.
    If you have 2 Coldcard-generated keys and are affected by the July/August 2026 Coldcard vulnerability, be aware of the option to broadcast your transaction using Slipstream. This is unnecessary if you only have 1 Coldcard-generated key.
    Once the transaction is confirmed, your funds are safely secured in the new vault. You can then close the old vault.
    If you encounter any issues or have questions regarding your specific vault configuration, please contact our support team for guidance before proceeding.
    Keys
    Getting started
    Device checks
    Key replacements and recovery
    Trezor
    Ledger
    Coldcard
    BitBox
    Jade
    Vaults
    Setting up a vault
    Receiving a deposit
    Making a withdrawal
    Vault navigation
    UTXO management
    Connections
    Making a connection

    Excerpt only. The complete copy is held offline and backs quotations on this site. The original publication remains the canonical public source.

  5. Earliest copy held
    seen · Captured here 3,093 chars
    Extracted text as captured
    Skip to content
    Open main navigation
    Close main navigation
    How can we help?
    There are no suggestions because the search field is empty.
    Knowledge Base
    Keys
    Coldcard
    How do I replace the keys to my vault?
    You can replace multiple keys with one step by building a new vault
    Creating a new vault is our recommended alternative to using our key replacement feature, especially if you need to rotate multiple keys. By following these instructions to create a new vault and manually sweeping your funds into it, you gain a cleaner, safer, and more flexible process.
    Note: If you have an IRA vault, you may use this method. Ensure that you are building the new vault within the same IRA account. Once finished, please close the old IRA vault. You should only have one active vault per IRA account.
    How to create a new vault and move your funds
    Log in to your Unchained account.
    Ensure you have two secure, uncompromised keys available to build the new vault. You may need to setup and add new keys to your account.
    Navigate to the vault creation flow and set up your new vault.
    Ensure you select the option to transfer your existing subscription to this new vault. This will activate your 30-day grace period.
    Once your new vault is active, initiate a transaction sending all of the bitcoin from your old vault to your new vault.
    When initiating the withdrawal on your old vault, you can choose “Internal transfer” and select the new vault.
    If you have 2 Coldcard-generated keys and are affected by the July/August 2026 Coldcard vulnerability, be aware of the option to broadcast your transaction using Slipstream. This is unnecessary if you only have 1 Coldcard-generated key.
    Once the transaction is confirmed, your funds are safely secured in the new vault. You can then close the old vault.
    If you encounter any issues or have questions regarding your specific vault configuration, please contact our support team for guidance before proceeding.
    Keys
    Getting started
    Device checks
    Key replacements and recovery
    Trezor
    Ledger
    Coldcard
    BitBox
    Jade
    Vaults
    Setting up a vault
    Receiving a deposit
    Making a withdrawal
    Vault navigation
    UTXO management
    Connections
    Making a connection
    Sharing keys

    Excerpt only. The complete copy is held offline and backs quotations on this site. The original publication remains the canonical public source.

How to check this yourself

The excerpts and plain unified diffs above show the text this project held and how it changed. To verify a quotation, compare it against the page itself or against the Internet Archive's copies, which are independent of this project.

Complete captures are held offline rather than mirrored here, so this page shows diffs and excerpts. If a quotation is ever disputed, the full copy can be produced. Ask.