COLDCARD RNG incident the public record, collected and explained
Informational only, and this site never asks for your seed words. details

Informational only. This is an open source collection of what others have published about the incident, together with an explanation of it. It is not financial, security or legal advice, and not a substitute for professional advice about your own situation. It is not affiliated with, endorsed by, or speaking for Coinkite. Material is attributed and quoted as published; where sources disagree their scenarios are kept separate with their assumptions rather than reconciled into one answer. Everything is meant to be checked against the linked evidence rather than taken on trust. Act on your own judgement about a particular situation. Editorial standards and corrections.

Do not disclose recovery material to a website, form, message or support account. This site never asks for it, and contributions containing recovery words or private keys are not accepted.

Plain language Updated 15 Aug 2026

Published responses

A guide to what organisations and individuals published after the disclosure. Statements, code proposals, guidance, warnings and disputed accounts are kept in separate parts of the record so that one does not stand in for another.

The public response was not one story. It included statements from Coinkite and other vendors, proposed code changes, migration guidance, scam warnings, competing accounts of earlier disclosures and public legal organising. This section separates those records by what was published and links each summary to the captured material. It does not turn them into a verdict or a procedure from this site. V1

Four parts of the response record

Start with the kind of publication you want to inspect. Each destination opens with a short answer, then gives the claims, limits and source links needed to check it.

Statements

What organisations said and did

Coinkite's operational statements, custody-provider guidance, competing wallet vendors' responses, and community or organisational actions. These remain attributed statements unless the action is independently observable in the record.

Technical work

What researchers and developers published

Pull requests, commit-history reconstruction and post-disclosure tests are kept apart from shipped fixes. The AI page separately records what is known, and not known, about the original discovery method.

Guidance and warnings

What publishers told readers

Migration recommendations and claimed outcomes are recorded as published guidance, not instructions from this archive. Documented scam artefacts are separated from warnings about what might happen.

Accountability

What the competing records say

Coinkite's disclosure chronology is read alongside first-person and community accounts that do not fully agree with it. Terms, statutes, claimant organising and public legal disagreement are kept in a separate document register.

A short publication chronology

This is a route into the material, not a replacement for the full incident timeline. Dates below identify when the selected responses were published; each link opens the held source record. R2

  1. Custody providers publish migration guidance

    Unchained and Casa describe key rotation and multi-vendor threshold policies; competing wallet vendors publish their own scope statements.

  2. Technical proposals and reconstructions appear

    Upstream pull requests, independent commit reading and code-path analyses become part of the public record.

  3. Coinkite publishes operational updates

    The vendor reports shipment, stock, customer-outreach and migration-support actions, then acknowledges lasting damage.

  4. The vendor publishes a disclosure chronology

    The chronology adds a new primary document to earlier-warning and AI-review disputes already in circulation.

  5. OpenSats funds priority red-team support

    The grant organisation redirects its programme to fund people red-teaming Bitcoin software during the incident, including reimbursement of already-spent LLM review costs.

  6. Coinkite pauses its customer data-blanking practice

    Citing legal obligations arising from the incident, the vendor says it has temporarily suspended automatic deletion of customer records, with an opt-out on request.

What is not filed as a response

Earlier predictable-key incidents are background, not responses to this incident. They remain in the reference register. A Bitkey weakness published by Block on the same day was a different product and defect, so it is held only as an adjacent source record.

Evidence on this page 2 items
  1. V1
    Verified

    That every destination in the response map below is backed by registered sources and held captures

    Source The source register and individual evidence records maintained by this archive

  2. R2
    Reported

    The publication dates and attributed response summaries in the chronology entries below

    Source The publishers' captured statements, articles and repository records, linked in each entry