COLDCARD RNG incident the public record, collected and explained
Informational only, and this site never asks for your seed words. details

Informational only. This is an open source collection of what others have published about the incident, together with an explanation of it. It is not financial, security or legal advice, and not a substitute for professional advice about your own situation. It is not affiliated with, endorsed by, or speaking for Coinkite. Material is attributed and quoted as published; where sources disagree their scenarios are kept separate with their assumptions rather than reconciled into one answer. Everything is meant to be checked against the linked evidence rather than taken on trust. Act on your own judgement about a particular situation. Editorial standards and corrections.

Do not disclose recovery material to a website, form, message or support account. This site never asks for it, and contributions containing recovery words or private keys are not accepted.

Plain language Updated 15 Aug 2026

What was disclosed before?

Five days into the incident, Coinkite published a history of every security finding it says has affected COLDCARD since 2019. It is useful, and it is the vendor's own account of the vendor's own record. This page holds the document, sets out the three entries that touch this bug, and shows where it disagrees with other people.

On 4 August 2026 Coinkite published a page listing 23 security-relevant events affecting COLDCARD since 2019, 12 of them with public evidence of coordinated disclosure. This archive captured it the following day. V1 Three of its entries bear directly on the July 2026 bug: a paid review in 2022 that examined random-number generation, an internal AI review that closed five weeks before the theft, and a firmware-version boundary the page draws twice. It is primary material worth reading. It is also self-selected: Coinkite chose what the list contains, how each entry is labelled and what counts as coordinated, and several entries rest on private correspondence nobody outside the company can check.

The page was announced in the same 4 August update that described the submodule-boundary theory and the frontier-model tests. R2 Coinkite's stated reason was that "researchers, journalists, and security teams doing their own review need a definitive record to work from". What follows takes it at that word and reads it as a source.

What the page is, and what Coinkite says it is not

Scope, counts, and the vendor's own three caveats

The page describes itself as a record of "public security research, coordinated disclosures, professional reviews, internal findings, and security advisories affecting COLDCARD", covering 2019 to 2026. Entries are tagged Coordinated, Credited fix, Vendor/internal, Cross-wallet, Overlap, Incident/advisory or AI, and each carries a product scope, a public status and a named reporter where one exists.

Three caveats are the vendor's own, stated on the page, and they are worth preserving because they constrain how the document can fairly be used:

  • It presents itself as "a chronology, not a count of independent vulnerabilities or a product score".
  • Its "no public evidence" label "means none was found in the cited record; it does not prove that something never happened privately".
  • It says raw event counts "should not be used to compare hardware wallets", because older, open and heavily researched products accumulate more public findings.

That last point cuts against a use the document might otherwise invite, and it is correct as far as it goes. The counts still do work for Coinkite, though: a page that opens on 23 events and 12 coordinated disclosures presents a record of engagement with researchers, which is the contested question this history sits inside. V3

A 2022 paid review that examined random-number generation

Recommendations the page says are not all shown as adopted

The chronology's entry for 1 to 14 March 2022 records a paid private review before the first public Mk4 release, attributed to "Lazy Ninja". It says the review examined SE2-backed PIN derivation, PIN-attempt rate limiting, MCU firewall coverage and random-number generation, and that during the review the runtime random-number generator was seeded with authenticated entropy from both secure elements.

The entry then records something the vendor was not obliged to publish. Further suggestions, including additional bootloader RNG conditioning and reseed hooks, were logged as defence in depth, and in the page's own words "the public firmware history does not show that all were adopted". R4

Two limits keep this in proportion. The review was Mk4 pre-release work in 2022, while the defect at issue here entered through the March 2021 change that routed seed generation through the affected library, and its effect differed by device class, so a recommendation adopted or declined for the Mk4 bootloader does not straightforwardly map onto it. And the entry rests on correspondence this archive cannot inspect, so the scope, the wording of the recommendations and the reason any were not adopted are Coinkite's account of a private document. U5

An AI review closed five weeks before the theft

85 candidate findings, triaged internally, none of them this bug

The chronology records an enterprise AI review of the firmware running from 1 May to 26 June 2026. It reports 85 candidate findings, 8 high, 37 medium, 20 low and 20 informational, each manually reviewed by Coinkite. Most of the high group is described as false positives, intended behaviour, documented trade-offs or unreachable paths, with two exceptions that received fixes. The review is recorded as closed on 26 June, with all items fixed, rejected, accepted as design choices or tracked elsewhere. R6

The theft began on 30 July, about five weeks after that review closed. The chronology does not claim the review covered the seed-generation path, and it lists the flows it did reach: CCC and SSSP, signing, Seed XOR, Key Teleport, PSBT handling, QR, USB, NFC and the WIF Store. On the page's own account, then, a substantial AI-assisted review of this firmware ran to completion weeks before the incident without the seed-generation defect appearing in its output. R7 This is the same class of evidence as the pre-incident and post-incident model tests set out on the AI page, and it carries the same limit: without the prompts and scope, a miss is not measurable.

On 7 August the COLDCARD account added a claim about how the defect was eventually found rather than about what its own review had covered: it said it believes it took the latest LLM models to find it. R8 Nothing in that post adds prompts, scope or transcripts to the 26 June entry, so it does not move the grading above.

The version boundary the chronology draws twice

The vendor's stated reason for beginning at 4.0.1, and where it differs from this record

Two separate entries do the same work. A 2021 vendor note records that firmware 4.0.0 shipped with a USB serial REPL enabled, and states that 4.0.0 was built, signed and tested internally but never released publicly, making 4.0.1 the first public 4.x binary. The 2026 incident entry then states that Block traces the RNG implementation to the v4.0.0 source lineage, that Coinkite did not publicly release v4.0.0 as a signed binary, and that "the affected-user range therefore begins at v4.0.1". R9

That boundary is not the one Block publishes, or the one this archive records. Block's engineering disclosure classifies Mk2 and Mk3 v4.0.0 as affected, describing the path as first appearing in "released firmware v4.0.0" on 17 March 2021, and the firmware record carries the same published range. The chronology's own wording keeps the two accounts distinguishable: it grants that Block traces the implementation to the v4.0.0 lineage, and rests the narrower figure on distribution rather than on the contents of the build. The disagreement is therefore about whether that build reached the public. R10 Neither party publishes distribution figures, and this archive holds none, so the difference is recorded on both pages rather than settled on either.

What the chronology does not contain

A May 2025 report is described elsewhere and does not appear here

James O'Beirne's 4 August first-person account says he audited the firmware in May 2025, became concerned about the RNG path and the libngu constants, and reported it to the COLDCARD team, where he says it was dismissed. R11

The chronology carries no May 2025 entry. Between the March 2022 review and the September 2025 Delta PIN disclosure it records nothing at all, and no entry anywhere in it describes a randomness or libngu report before the incident. V12 It is unchanged on that point: the page has been polled through 8 August and its text hash has not moved since capture.

O'Beirne's account widened on 7 August. Replying to a Coinkite correction about where the weak generator came from, O'Beirne wrote that COLDCARD did fall back to weak entropy, that the copy in libngu was weaker still because it used hardcoded constants, and that "you were warned about this particular issue by me and at least one other person 4 years before me". That is a claim of a second, earlier report, around 2021, by someone he does not name. He linked the libngu source lines carrying the constants; he attached no report or correspondence for either warning. R13

Coinkite's public position the same day runs the other way. Answering a critic, the COLDCARD account wrote that "the bug lived in public for 5yrs, even third party researchers didn't find it", adding that it believes the latest models were needed to find it. R14 A third prior-warning claim, unrelated to O'Beirne's and made by neither party, is also held: a 2 August thread pointing to a video said to show the BTCRecover maintainer warning about COLDCARD entropy two years before the incident. The video is not captured here, and nothing establishes that any such warning reached Coinkite. U15

Neither account settles the other, and this page does not try to. By the chronology's own stated convention an absence means only that nothing was found in the cited record, and the cited record is one the vendor assembled. By the same token a first-person recollection published during an incident, with no contemporaneous artefact attached, is not a document either. What can be said is narrow and worth saying plainly: one party describes a report and now a second, earlier one by another person, the other party's published history of reports contains neither and says researchers did not find the bug at all, and no artefact has surfaced that would decide it. U16

A contested reading of the same history

A community thread argues the pattern runs the other way

Before the chronology existed, Vlad Costea published a thread arguing that Coinkite's handling of past disclosures showed a pattern, including a 2019 disclosure he says was rewarded with merchandise and a later researcher who he says disclosed to other vendors but not to Coinkite. R17

The two documents overlap on events and emphasise different parts of them. Coinkite's 2019 entries are tagged Coordinated and name their reporters. Costea describes how he says reports were received, a detail the chronology's coordination tag does not address. For the May 2020 factory-reset finding, the chronology lists the mitigation as "disputed", records no bootloader retrofit, and says the linked vendor response is no longer available. V18 Reception is not something either document can settle. Both are held.

The reception question resurfaced on 7 August, with the vendor invoking the standard itself. Answering a critic, the COLDCARD account wrote: "As promised we are doing all the investigation we can to get to the bottom of it. We are devastated. The hacker could have done the right thing and responsibly disclosed." R19 The line was quoted back at the company repeatedly through the day, and more than one reply turned it into the reception question this section is about, one asking whether roughly five separate researchers had disclosed to Coinkite and been mocked for it. No captured artefact enumerates pre-incident disclosures of this defect, so that number is a characterisation and not a count this archive can check. R20

Claim register

Disclosure-history claims and their evidence basis V21 R22
ClaimEvidence basisWhat supports it
Coinkite published a 23-event disclosure history on 4 August 2026. Verified Captured by this archive on 5 August. The counts, tags and caveats quoted on this page are read from that capture.
A paid 2022 review examined random-number generation before the first Mk4 release. Reported Coinkite's entry, sourced to private paid review correspondence that this archive cannot inspect.
Some RNG-related recommendations from that review are not shown as adopted. Reported Coinkite's own wording. Whether adopting them would have affected this defect is not established.
An AI-assisted firmware review closed on 26 June 2026 without surfacing this defect. Reported Coinkite's entry, with an 85-finding breakdown. No prompts, transcripts or scope definition are published, so the coverage of the seed path cannot be checked.
The affected range begins at firmware 4.0.1 because 4.0.0 was never publicly released. Reported Stated in two separate entries. Block publishes the wider v4.0.0 lineage, so the boundary is contested; the difference is carried in the 4.0.0/4.0.1 entry above.
The chronology contains no May 2025 entry and no pre-incident randomness report. Verified Read directly from the capture. By the page's own convention this is an absence in a vendor-assembled record, not proof that nothing was reported.
A randomness concern was reported to Coinkite in May 2025. Unverified O'Beirne's first-person account, with no contemporaneous artefact attached, against a vendor history that does not record it.
Coinkite was also warned about this issue by another person around 2021. Reported O'Beirne's 7 August reply, which names no one and attaches no report for either warning. A second, unrelated prior-warning claim, about a video said to predate the incident by two years, is held and is likewise unverified.
No third-party researcher found the bug in the five years it was public. Reported The COLDCARD account's 7 August reply. It does not address O'Beirne's account, which contradicts it, and no artefact settles the two.
Coinkite's handling of past disclosures shows an adverse pattern. Unverified Costea's characterisation, contested by the chronology's own tagging of the same events. Reception is not recorded by either document.
What would change the status

A contemporaneous report, ticket or correspondence from May 2025 would settle the O'Beirne question in one direction or the other, as would the earlier warning he now says another person made, or the name of the person who made it. The 2022 review's written recommendations, or a statement of which were declined and why, would move that entry from vendor summary to document. The AI review's scope definition would show whether the seed path was ever in range. Until any of those appear, the entries above stay as they are graded. U23

Evidence on this page 23 items
  1. V1
    Verified

    That the page exists, was published under Coinkite's own name, and states the 23-event and 12-coordinated-record counts described here

    Source Coinkite's security disclosure history, checked against the capture held by this archive

  2. R2
    Reported

    That Coinkite announced the disclosure-history page in its 4 August public-record post

    Source COLDCARD's captured 4 August public-record update

  3. V3
    Verified

    The three quoted caveats and the two headline counts, as they appear on the captured page

    Source Quotations checked against the captured Coinkite disclosure history; the reading of what the counts do is this archive's

  4. R4
    Reported

    The 2022 review's scope, its RNG-related recommendations, and Coinkite's statement that the public firmware history does not show all of them were adopted

    Source Coinkite's disclosure history, which sources this entry to private paid review correspondence not available to this archive

  5. U5
    Unverified

    Whether the 2022 review's unadopted RNG recommendations would have prevented or surfaced the defect in this incident

    Source No captured artefact shows the review's contents, and the entry is a vendor summary of private correspondence

  6. R6
    Reported

    The AI review's dates, its 85-finding breakdown, its triage outcomes and its closure on 26 June 2026

    Source Coinkite's disclosure history, which sources the entry to a private internal review and firmware commit 9b131b2; the private issues, finding links, internal pull requests and reviewer identities are stated as not publicly linked

  7. R7
    Reported · contested

    That a completed AI-assisted firmware review closing 26 June 2026 did not surface the seed-generation defect

    Source Coinkite's own account; no prompts, transcripts, scope definition or evaluation protocol are published, so the review's coverage of the seed path cannot be checked here

  8. R8
    Reported · contested

    Coinkite's 7 August statement that it believes the latest LLM models were needed to find the defect

    Source The COLDCARD account's captured 7 August reply; the discovery claim is the vendor's and no test, prompt or transcript supporting it is published. The same post's companion claim, that third-party researchers did not find the bug, is disputed and is set out below

  9. R9
    Reported

    The chronology's account that firmware 4.0.0 was never publicly released and that the affected range therefore begins at 4.0.1

    Source Coinkite's disclosure history, sourced there to the Mk3 release history, a 4.0.0 to 4.0.1 source comparison, a historical signing manifest and the public binary archive

  10. R10
    Reported · contested

    That the chronology's 4.0.1 lower bound is narrower than the v4.0.0 boundary published by Block and recorded by this archive, and that the difference turns on distribution rather than on the contents of the 17 March 2021 build

    Source Block's engineering disclosure, which tabulates Mk2 and Mk3 v4.0.0 to v4.1.9 and dates the path to released firmware v4.0.0 on 17 March 2021, read against the captured chronology; held capture of 31 Jul 2026

  11. R11
    Reported · contested

    O'Beirne's account of a May 2025 audit, an RNG and libngu concern, and a report to the team that he says was dismissed

    Source James O'Beirne's captured 4 August posts, which attach no contemporaneous report or correspondence

  12. V12
    Verified

    That the captured chronology contains no May 2025 entry and no pre-incident randomness or libngu report

    Source Read directly from the captured page, whose 2025 section begins at the September 2025 Delta PIN disclosure

  13. R13
    Reported · contested

    O'Beirne's 7 August claim that Coinkite was warned about this issue by him and by at least one other person about four years earlier

    Source James O'Beirne's captured 7 August reply to the COLDCARD account; the earlier warning names no person, gives no date beyond four years before his own, and no report or correspondence is attached for either

  14. R14
    Reported · contested

    Coinkite's 7 August statement that the defect went unfound by third-party researchers for five years

    Source The COLDCARD account's captured 7 August reply, which does not address O'Beirne's account directly; the two statements are irreconcilable as read, and no artefact settles which is right

  15. U15
    Unverified

    Whether the video described in that thread exists as characterised, whether it warned about COLDCARD entropy, and whether any warning it contained reached Coinkite

    Source A captured Stacker News thread whose author makes the claim; the linked video is not held by this archive as of a 15 August 2026 recheck and the thread attaches no correspondence

  16. U16
    Unverified · contested

    Whether a randomness concern was reported to Coinkite in May 2025, whether an earlier warning was made around 2021, and how either was handled

    Source Accounts that do not reconcile, with no contemporaneous report, correspondence or ticket captured on any side as of a 15 August 2026 recheck of the chronology and of both parties' captured posts

  17. R17
    Reported · contested

    Costea's characterisation of a pattern in Coinkite's handling of past disclosures, including the merchandise reward and the researcher who bypassed Coinkite

    Source Vlad Costea's 31 July thread, preserved as an X capture; the characterisations are the author's and are not verified here

  18. V18
    Verified

    That the chronology lists the May 2020 factory-reset entry with a disputed mitigation, no bootloader retrofit, and a vendor-response permalink recorded as no longer available

    Source Read directly from the captured page

  19. R19
    Reported

    That the COLDCARD account published that statement, including its appeal to responsible disclosure, on 7 August 2026, and that this archive holds several 7 August posts quoting the line back at the company

    Source The COLDCARD account's captured 7 August reply, and the captured replies and quote-posts registered the same day

  20. R20
    Reported · contested

    The claim that several researchers responsibly disclosed this defect to Coinkite before the incident and were ridiculed

    Source A captured 7 August reply to the COLDCARD account; the figure and the characterisation are the poster's, no researcher is named and no disclosure artefact is attached

  21. V21
    Verified

    The rows below marked Verified, each read directly from the captured chronology

    Source Coinkite's security disclosure history as held by this archive

  22. R22
    Reported

    The rows below marked Reported, each attributed to the party that published it

    Source Coinkite's chronology, O'Beirne's 4 and 7 August posts, the COLDCARD account's 7 August replies and Costea's 31 July thread, all captured

  23. U23
    Unverified

    Whether pre-incident reviews or reports covered the seed-generation path, and how any such report was handled

    Source Every relevant entry rests on private material that had not been published; no artefact in the captured record resolved them as of a 15 August 2026 recheck, which added two further statements but no document