COLDCARD RNG incident the public record, collected and explained
Informational only, and this site never asks for your seed words. details

Informational only. This is an open source collection of what others have published about the incident, together with an explanation of it. It is not financial, security or legal advice, and not a substitute for professional advice about your own situation. It is not affiliated with, endorsed by, or speaking for Coinkite. Material is attributed and quoted as published; where sources disagree their scenarios are kept separate with their assumptions rather than reconciled into one answer. Everything is meant to be checked against the linked evidence rather than taken on trust. Act on your own judgement about a particular situation. Editorial standards and corrections.

Do not disclose recovery material to a website, form, message or support account. This site never asks for it, and contributions containing recovery words or private keys are not accepted.

Plain language Updated 15 Aug 2026

Incident-related scams and warnings

This record separates events supported by an artefact or first-person report from warnings about what might happen, and keeps a June campaign from being misdated as a response to the July disclosure.

The held record contains a Telegram impersonation artefact, four first-hand reports of phishing email sent to COLDCARD and Trezor owners, a repository that offered to reproduce the defect and was reported to carry an infostealer, an impersonation account on X, Trezor's report of increased phishing attempts and a first-person account of a migration into an impostor wallet app. Four vendors also published warnings about anticipated scams. Those warnings are preserved as statements by their publishers, not evidence that every described event occurred. Coinkite's own urgent migration language closely resembled the pretext an impersonator could use. V1

The vendor instruction and the scam pretext overlapped

On 1 August Coinkite wrote: "Please treat this as urgent. Follow the advisory for your model, upgrade your device, generate a new seed, and carefully move your funds."

Vendor warnings preserved below responded to this overlap by telling readers where firmware should come from, which contacts to distrust and which recovery material no support channel should request.

What is documented

The post-disclosure reports below are held as captures. One includes the underlying image, reproduced here from the archive. The rest are attributed reports whose screenshots are held inside the captured posts rather than reproduced on this page, and each carries the limits stated with it.

A dated prediction, then a dated artefact

On 31 July at about 14:59 UTC, Jameson Lopp wrote that it was "only a matter of time" before phishing mail claiming to be Coinkite security notices went out, trying to get readers to enter their seed words into a malicious site. R2 On 1 August at 18:02 UTC he quote-tweeted that post with a screenshot and the caption "The scammers have updated their playbooks." The prediction is a warning; the screenshot is an artefact. A warning published on 31 July does not become an event because something arrived on 1 August.

A Telegram account impersonating COLDCARD

The screenshot Lopp published shows a Telegram conversation opened by an account whose display name is "COLDCARD WALLET". The message is dated August 1 at 03:38 and reads, with the recipient's name blacked out: "Hello [redacted] Checking out on our database got you were one of our first users", followed by "I hope youre got an update about the hardware, I hope you were able to transfer your funds safely".

Telegram conversation screenshot. The header shows a contact named COLDCARD WALLET with a blue check mark, above buttons reading ADD CONTACT and BLOCK USER, and a line explaining that the blue mark is a mark for Premium subscribers. A contact card below reads COLDCARD WALLET, Not a contact, Phone number United States, Registration March 2026, and a warning reading Not an official account. Under a date divider reading August 1, one message at 03:38 reads: Hello, followed by a blacked-out name, Checking out on our database got you were one of our first users. I hope youre got an update about the hardware, I hope you were able to transfer your funds safely.
Reported by Jameson Lopp on 1 August 2026. A Telegram account using the display name "COLDCARD WALLET" messages a recipient about the incident. Telegram's own contact panel is visible above the message: the account is marked "Not a contact" and "Not an official account", the phone number is registered in the United States, the account was registered in March 2026, and the blue mark beside the name is labelled by Telegram itself as "a mark for Premium subscribers". The recipient's name is redacted in the image as published. Captured . R3
What makes this message hard to catch

It asks for nothing. No link, no attachment, no request for seed words, no form. It opens a conversation and waits, which defeats the advice most owners have internalised, because "never type your seed" cannot fire against a message that has not asked for one. Whatever the request turns out to be, it arrives after the account has been treated as a correspondent rather than a stranger.

The blue mark is not verification. Telegram's own panel, visible in the same screenshot, explains that the mark denotes a Premium subscriber, which is a paid feature, and separately flags the account as "Not an official account". The platform contradicts the display name in the same view, and the contradiction is easy to scroll past.

The pretext is the vendor's own. "I hope you were able to transfer your funds safely" is a paraphrase of the advisory quoted above. An owner who read the advisory has already had this thought.

Phishing email reported first-hand

Four separate first-hand reports of incident-themed phishing email are held, dated 3 to 5 August. On 3 August a poster on r/coldcard reported a security advisory email from [email protected], a lookalike domain, offering to schedule a ten-minute session, and a second from [email protected]. A commenter in the same thread reported mail purporting to come from Ledger and claiming that Ledger was also affected because it used shared code libraries. R4

On 4 August at 03:24 UTC American HODL published four screenshots of a message urging him to download a "Coldcard Desktop App MK3 4.2.0", writing that "there never was, is or will be a coldcard desktop app". The screenshots show a message headed "Important Security Update — Coldcard MK3 4.2.0 Release and Required Action" and opening "Dear Coldcard Community", which apologises, numbers its instructions, tells the reader to "generate a brand-new seed phrase within the updated application" and then to "carefully migrate your assets from your previous wallet to the newly created wallet", directs anyone needing assistance to "our official support channels", and ends in a red button reading "Download MK3 4.2.0 Update". R5 The two instructions it numbers — generate a new seed, then carefully move the funds across — are the two instructions in Coinkite's own migration appeal quoted at the top of this page.

Twelve minutes later Bitcoin Rothbard published a fifth screenshot with the caption "I got this one from 'Trezor'", quote-showing American HODL's images beneath it. The held capture shows an email headed "Message From Our Ceo" under a Trezor logo, addressed to "Hello Trezor Users", which links a Fortune article about the COLDCARD losses and then states that "CoinKite is a hardware wallet company which we were partnered with. We shared source code, internal tools, and updates. While our Suite was not directly effected, a lot of our infrastructure relied on CoinKite." It closes with a link to "our latest version in our web suite" and the sign-off "CEO - Matej Zak". R6 The shared-source-code claim in that screenshot runs against Trezor's own published position: the incident email Trezor sent its users, as reproduced by a poster in a held r/Bitcoin thread, states that "Trezor does not use Coldcard's firmware or code", and Trezor's own captured posts of 4 and 5 August say its devices are not affected. R7

On 5 August at 20:02 UTC Margot Paez published a screenshot of a further email posing as Trezor support, named the sending address as [email protected] and told readers not to click its green button. The held capture shows a "CRITICAL SECURITY BULLETIN" headed "TROPIC01 CHIP SECURITY PROTOCOL UPDATE", dated 5 August 2026 and given the reference TB-SEC-2026-00796, asserting an anomaly in the secure element verification protocol of "ALL Trezor hardware wallet models" and requiring readers to run a diagnostic test through a support portal, ending in a green button reading "ACCESS SUPPORT PORTAL NOW". R8 This one carries no COLDCARD pretext at all: it is a Trezor-branded alarm about a Trezor part, reported six days after the COLDCARD disclosure.

These are reports with artefacts attached, not captures of the messages themselves: this archive holds the posts, and the screenshots inside them, not the underlying email. Two of the four name Trezor rather than Coinkite. In the same r/Bitcoin thread about the incident email Trezor sent its own users, one commenter wrote that they had received "3 or 4 scam 'Trezor' emails before I got the real one". R9

A repository baited with the defect itself

On 5 August jrakibi warned that a repository which had gained many stars in 24 hours, and which claimed to reproduce the vulnerable COLDCARD RNG, pulled a dependency that downloaded and executed an infostealer searching for wallet seeds, private keys and passwords. The finding is described as LLM-assisted. The repository is not named or linked here, and this archive has neither run nor reviewed it. R10 Later the same day satsie described having starred that repository while using an LLM to understand the attack, then unstarring it once it was identified, and wrote that "the attacks are coming in from all angles". R11 The bait in this case is reproduction of the defect, so the people reached are those investigating the incident rather than the owners moving funds.

Impersonation during the response

On 5 August Rob Hamilton, an AnchorWatch co-founder whose chain analysis and migration warning are part of this record, wrote that he was no longer reachable by direct message because of "way too many scammers pretending to be media and even sometimes fake victims trying to get me to click links", and named colleagues as the contact route instead. R12 Hours later, early on 6 August, SoapMiner posted "I'm a complete idiot. I just got scammed", warned others and linked an account whose handle is a near miss of Hamilton's. R13 Separately, on 3 August, Joe Carlasare published a screenshot captioned "Scummy people trying to prey on fear" and "THIS IS FAKE. SHARE". The post's text does not say what the screenshot shows, so what was being called fake is legible only in the attached image. R14

Trezor reports increased phishing attempts

On 4 August, Trezor said it was already seeing an increase in phishing attempts following the disclosure. It warned users never to share a wallet backup, never to follow migration instructions from unsolicited contact and to enter a backup only on the Trezor device during recovery. R15 The increase is therefore a vendor report rather than a measurable incident count in this archive. The safety rules can still be checked directly against the captured post.

A reported fake-wallet migration loss

On 2 August, @lunymoon13 reported losing 6.06 BTC after reacting to the incident and moving funds into what the author described as a fake Wasabi app found in Apple's App Store. R16 The report is not independently verified. It records a distinct failure mode in which incident-driven migration was redirected through software selected under pressure.

What belongs to an earlier campaign, and is dated accordingly

two items that name Coinkite and predate this incident

Both items below circulate widely and predate this incident. They carry the highest misinformation risk on this page, because recirculating them as evidence of post-disclosure phishing is a date error that would be very easy to make in good faith.

The June 2026 paper campaign

From 20 June 2026 a physical letter impersonating Coinkite was reported first-hand with photographs. The letter used a post-quantum firmware-upgrade pretext and carried a 30 June deadline. On 24 June Coinkite published a response, "Paper spam attempts", which states that Coinkite would never send a paper letter, that the mail is a scam to steal coins, that Coinkite deletes customer data including physical addresses after 120 days, and that it uses no external customer-relationship tooling. Coinkite attributes the targeting data to aggregated leaks from other companies and says an audit of its own servers found no reason to suspect a breach. V17 Some people reporting the letters inferred a Coinkite data leak. Coinkite denies a breach. Both positions are recorded here and neither is adopted. R18

The 120-day practice named in that June statement has since changed. On 7 August 2026, first listed on its blog index as 6 August and then retimestamped, Coinkite published "Update on Customer Data Retention", which says that records are normally blanked automatically after 120 days with only email address and country of residence retained, and that this automated blanking has been temporarily suspended because of legal obligations arising from the incident. Customers who want the standard policy applied to their own data are asked to confirm that by contacting [email protected]. The retention change belongs to the vendor's statements and to the legal record and is treated there; it is noted here because the June statement quoted above rests on the practice that changed, and because the vendor's stated channel for the request is an email address. V19

This is a separate event, five weeks before the entropy disclosure. Presenting the June letter as post-disclosure phishing is a date error. As of 15 August 2026 this archive has found no evidence of a fresh letter wave posted after 30 July. Postal delay means an absence of reports that week would not settle the question either way.

The generic "do not open links from wallet brands" warning

A general warning about links in messages purporting to come from wallet brands circulated before this incident. R20 No artefact of it and no attribution for it are held here, it predates the 30 July disclosure, and it is not specific to this incident. It is recorded so that its recirculation is not mistaken for a report of something new.

What vendors warned about, which is not the same as what happened

From 31 July through 4 August, four vendors of competing hardware or software published scam guidance alongside their statements about this incident. V21 Everything in this section is a warning. None of it is a report that the described thing occurred, and none of it should be cited as one. Their lists overlap, so the rules are deduplicated and attributed below rather than printed four times.

  • Any email or message carrying a firmware update is hostile, whoever the sender appears to be. Blockstream
  • Never type your seed words into a website, form or "checker" tool, and treat any request to verify a seed somewhere as hostile. Blockstream, Foundation, Trezor
  • No vendor DMs you first or asks for your seed words. Treat unprompted messages offering help, and anyone claiming to be Foundation or Coinkite staff, the same way. Blockstream, Foundation, Wizardsardine
  • Never follow wallet-migration instructions from unsolicited emails, messages or phone calls. Trezor
  • Pressure is the mechanism: scams need you to act before you check, and anyone saying your funds are at risk and they can help is applying it. Scams "will multiply in the coming days". Blockstream, Foundation, Wizardsardine
  • Expect fake "recovery services" offering to get stolen coins back for a fee. Foundation, Wizardsardine
  • Do not install software found in a hurry, do not buy a device from an unknown seller, and distrust search results and sponsored links for wallet software. Wizardsardine, Foundation
  • Requests to share your screen or install remote-access software have no legitimate place in this. Foundation

Captures: Blockstream (Jade), 31 July 2026 · Foundation (Passport), 31 July 2026 · Wizardsardine (Liana), 1 August 2026 · Trezor (Trezor), 4 August 2026

KeychainX, which identifies itself as a paid wallet-recovery firm, warns on its incident page that any service promising to recover already-swept Bitcoin for a fee is "a second scam aimed at people already harmed by the first". R22 The distinction it draws is between recovering a lost key and reversing a completed spend, which the page says no service can do.

The same question runs through the held community threads, in both directions. On 5 August, commenters on a first-hand loss thread described a paid-recovery pattern that escalates fee after fee, and argued that its real product is identity data: one wrote that victims would be asked to "verify their ownership of the bitcoin or coldcard hardware by providing those kinds of details, when in reality they cannot help the victims in any way", and another that a genuine whitehat would not charge for a recovery service. R23 On 6 August, in a captured r/coldcard thread about keeping affected devices, a commenter wrote "I love how people think that money can't be clawed back", without naming a mechanism, a case or a party who could do it. U24 Both are recorded as the form the recovery question takes in the record, and neither is adopted. What the archive holds on recovery itself is set out on the funds page: no recovery, seizure or payout has been reported in any captured source, and a 3 August relay of white-hat drains said to be underway is unconfirmed and names no amounts.

An absence in the vendor response

no scam guidance appears alongside the entropy advisory

As of 15 August 2026, Coinkite has published no scam or phishing guidance alongside the entropy advisory, and the advisory itself contains no text about impersonation, checker tools or which contact channels are official. V25 This is stated as an absence observed in the held captures, and it is worth recording precisely because Coinkite demonstrably publishes this kind of guidance: it did so on 24 June, in detail, for the paper campaign. No motive is attributed here, the advisory has been revised repeatedly since 30 July, and this is a statement about what the held captures contain on a given date rather than a characterisation of the vendor's conduct.

Activity that resembles the warning patterns

three reports not established here as fraudulent

These entries resemble patterns named in the warnings above. The available evidence does not establish them as fraud, so the behaviour pattern is recorded without applying that label to the party.

Swan Bitcoin's withdrawal-pause email

Swan Bitcoin is reported to have emailed customers on 31 July pausing withdrawals to wallets labelled as COLDCARD and asking recipients to reply to the email. The report describes a company protective measure. It is also, structurally, an unsolicited email about a wallet, sent during a crisis, that asks you to respond to it, which is the exact shape of the warning pattern published by the vendors above. The resemblance does not make the reported email fraudulent. R26

A law firm's victim-acquisition page

A law firm is running a page recruiting affected owners as potential claimants, published 31 July 2026 and first captured by this archive on 4 August. The page self-labels as advertising. Client solicitation after a mass loss event is legal marketing. It is separated here from the "recovery service" warning above, which concerns promises to reverse a completed spend. The captured page offers a possible legal claim against a counterparty, not retrieval of coins from the chain. V27

An emailed "Trezor Advisory" screenshot

Around 2 August a recipient posted a screenshot of an email presented as a Trezor advisory and classified it as a phishing attempt. That classification is the recipient's, it has not been confirmed by Trezor, and this archive holds no capture of the message. Internal inconsistencies in the screenshot have been noted by others. This archive does not adjudicate it, and it is recorded here only so that it is not repeated as an established case. Two further Trezor-branded phishing reports, dated 4 and 5 August, are described above and are held as captures; this archive has not established whether the screenshot described here is one of them or a separate item, so it is kept recorded separately rather than merged into them. U28

Evidence on this page 28 items
  1. V1
    Verified

    That Coinkite's own published guidance instructs owners to treat the situation as urgent, upgrade, generate a new seed and move funds

    Source COLDCARD advisory and the 1 August migration appeal, as captured

  2. R2
    Reported

    Lopp's 31 July forecast that phishing mail posing as Coinkite security notices would follow the disclosure

    Source Jameson Lopp, posted 31 July 2026 at 14:59 UTC; a forecast, not a report of an event

  3. R3
    Reported

    The existence and content of the Telegram impersonation screenshot above, and the interface details visible in it

    Source Jameson Lopp published the screenshot on 1 August 2026 at 18:02 UTC. He does not say who received it and the recipient is redacted, so this is an artefact he published rather than an account of something he received. No vendor has confirmed or denied it

  4. R4
    Reported

    The r/coldcard reports of security-advisory email from the lookalike domains named, and the reported Ledger-branded mail in the same thread

    Source BarAdministrative999 and commenters, r/coldcard, 3 August 2026, as captured; the sender addresses and the classification as phishing are the posters' own, and no message is held here

  5. R5
    Reported

    The existence and visible content of the COLDCARD desktop-app phishing screenshots, and the statement that no COLDCARD desktop application exists

    Source americanhodl8's captured X post of 4 August 2026 with four attached screenshots, read off the held capture; the message itself is not held, the report of receiving it is his own, and Coinkite has not commented on it in any held capture

  6. R6
    Reported

    The existence and visible content of the screenshot presented as an email from Trezor's chief executive

    Source BitcoinRothbard's captured X post of 4 August 2026, read off the held capture; the post text says only that he received it, the message is not held, and Trezor has neither confirmed nor denied this specific item in any held capture

  7. R7
    Reported

    That the Trezor incident email, as reproduced by a poster, states Trezor does not use Coldcard's firmware or code

    Source Text of the Trezor email as reproduced in the captured r/Bitcoin thread; the reproduction is the poster's and the message itself is not held, while Trezor's captured posts of 4 and 5 August state the same not-affected scope in the vendor's own voice

  8. R8
    Reported

    The existence and visible content of the screenshot presented as a critical Trezor security bulletin, and the sending address named for it

    Source jyn_urso's captured X post of 5 August 2026, read off the held capture; the address, the receipt and the classification are as published by the reporter, and the message is not held here

  9. R9
    Reported

    The commenter's report of receiving several scam emails branded as Trezor before the genuine one

    Source Comment in the captured r/Bitcoin thread on Trezor's incident email; a single unverified account, held as a capture and not corroborated elsewhere in this archive

  10. R10
    Reported

    The report that a repository claiming to reproduce the vulnerable RNG pulled a dependency executing an infostealer

    Source jrakibi's captured X post of 5 August 2026; the finding is the reporter's LLM-assisted review, is not verified here, and no independent confirmation is held

  11. R11
    Reported

    satsie's first-person account of starring and then unstarring the repository while researching the attack

    Source satsie's captured X post of 5 August 2026, crediting jrakibi for the check; a first-person account, not verified here

  12. R12
    Reported

    Rob Hamilton's statement that he closed his direct messages because of impersonators posing as media and as victims

    Source Rob1Ham's captured X post of 5 August 2026; his own account of messages he received, none of which is held here. He co-founded AnchorWatch and originated the Slipstream migration recommendation this record holds elsewhere

  13. R13
    Reported

    SoapMiner's first-person report of being scammed and the linked account whose handle closely resembles Rob Hamilton's

    Source soapminer1's captured X post of 6 August 2026; the post does not state what was taken or by what means, and the linked account is not held as a capture here

  14. R14
    Reported

    Joe Carlasare's 3 August warning that a post preying on holder fears was fake

    Source JoeCarlasare's captured X post of 3 August 2026 with one attached screenshot; the post text identifies neither the account nor the content it calls fake, and nothing else in this archive identifies it

  15. R15
    Reported

    Trezor's report of increased phishing attempts and its quoted safety guidance

    Source Captured primary post from Trezor; the post provides no phishing message, count, channel breakdown or measurement method

  16. R16
    Reported

    The first-person report of a 6.06 BTC loss through an impostor Wasabi app during migration

    Source @lunymoon13's captured primary X post of 2 August 2026; no transaction identifier, app-listing artefact or independent confirmation is held

  17. V17
    Verified

    Coinkite's 24 June 2026 statement about the paper campaign, including the never-a-paper-letter position, the 120-day address deletion and the no-breach finding

    Source Coinkite, 'Paper spam attempts', published 24 June 2026, as captured

  18. R18
    Reported

    The first-hand reports and photographs of the June letter itself, its 30 June deadline, and the inference by some reporters that a Coinkite data leak explains the targeting

    Source First-hand r/Bitcoin and r/coldcard reports with photographs, 20 and 29 June 2026, held as captures; Coinkite's response is held and denies a breach, and neither position is adopted

  19. V19
    Verified

    Coinkite's 7 August 2026 statement that automated 120-day blanking is temporarily suspended, and that customers wanting the standard policy applied should contact the support address

    Source Coinkite, 'Update on Customer Data Retention', as captured; the displayed publication date moved from 6 to 7 August between two captures of the blog index

  20. R20
    Reported

    The generic pre-disclosure wallet-brand link warning

    Source unthocks's captured r/Bitcoin post, published 22 July 2026, warns against messages claiming a hardware wallet is compromised; it is a community warning, not evidence of a COLDCARD-specific post-disclosure event

  21. V21
    Verified

    That Blockstream, Foundation, Wizardsardine and Trezor published the scam guidance summarised below, on the dates shown

    Source Held captures of each vendor's published statement; the guidance is predictive, while Trezor separately reports an increase in phishing attempts without publishing a specimen or count

  22. R22
    Reported

    KeychainX's statement that paid recovery of already-swept coins is a second scam, and its own commercial position

    Source KeychainX reference page, as captured; KeychainX identifies itself on the page as a wallet-recovery firm that sells paid recovery, which bears on how the advice reads without making it wrong

  23. R23
    Reported

    The community descriptions of a paid-recovery and identity-harvesting pattern in the captured loss thread

    Source Comments dated 5 August 2026 in the captured r/Bitcoin thread on a 0.7 BTC loss; assertions by named posters about a pattern, with no instance evidenced, and not adopted here

  24. U24
    Unverified

    The assertion that swept funds can be clawed back

    Source Comment by DeepAd8888 dated 6 August 2026 in the captured r/coldcard thread on device disposal; the comment gives no mechanism and nothing else in this archive supports or refutes it as of a 15 August 2026 recheck

  25. V25
    Verified

    That no scam, phishing or impersonation guidance appears in the held captures of the COLDCARD advisory as of 15 August 2026

    Source Held captures and unchanged index polls of the advisory through 15 Aug 2026 searched for scam, phishing and impersonation text; the absence is of published text, and is not a claim about anything Coinkite may have communicated elsewhere

  26. R26
    Reported

    The reported Swan Bitcoin withdrawal-pause email

    Source Stacker News thread quoting the email, captured 4 Aug 2026; the email text is the poster's exhibit and is not verified against Swan

  27. V27
    Verified

    The existence and stated content of the law firm's claimant page

    Source Stoltmann Law claimant-intake page, published 31 Jul 2026, held as a capture

  28. U28
    Unverified

    The emailed Trezor advisory screenshot that a recipient classified as a phishing attempt

    Source The specific phishing-classified screenshot is not held in this archive as of a 15 August 2026 recheck; a genuine Trezor incident email is captured separately at reddit-trezor-user-alert-email and Trezor's own posts state the same not-affected scope