<oembed><type>rich</type><version>1.0</version><author_name>whit (npub14d…w0xv0)</author_name><author_url>https://nostr.ae/npub14d7ezuzsy55f6c2f4k02r27yeexyj42a7uvsfu53xmpzx7z75mmsnw0xv0</author_url><provider_name>njump</provider_name><provider_url>https://nostr.ae</provider_url><html>🧾 COLDCARD: WHAT HAPPENED, WHO IS INVOLVED &amp; WHAT PLEBS SHOULD DO&#xA;&#xA;Color code&#xA;&#xA;🟦 CODE / PRODUCT&#xA;🟨 WARNING / INVESTIGATION&#xA;🟧 PUBLIC COMMUNICATION&#xA;🟩 CONFIRMED / FIX / RESPONSE&#xA;🟥 THEFT / ATTACKER ACTIVITY&#xA;💔 VICTIM ACTION&#xA;⬜ UNKNOWN / NEED MORE EVIDENCE&#xA;&#xA;Important: A person’s name appears because they have a documented role in the product, investigation, research, communication, or response. That does not mean they caused the vulnerability or participated in the theft. The attackers remain unidentified.&#xA;&#xA;⸻&#xA;&#xA;🟦 2021: THE VULNERABILITY ENTERS THE PRODUCT&#xA;&#xA;January–March 2021&#xA;&#xA;Coldcard integrates libNgU into its firmware.&#xA;&#xA;People/projects relevant to this stage:&#xA;&#xA;switck #libNgU&#xA;Peter D. Gray / doc-hex #ColdcardFirmware&#xA;Coldcard/Coinkite developers #Development&#xA;&#xA;The critical integration ultimately allowed wallet seed generation to reach a deterministic software PRNG rather than the intended hardware random-number generator.&#xA;&#xA;For affected older Mk2/Mk3 devices, later analysis puts effective entropy around 40 bits instead of the intended 128 bits. &#xA;&#xA;That turns an astronomically large seed-search problem into something attackers can potentially enumerate.&#xA;&#xA;⸻&#xA;&#xA;🟦 MARCH 1, 2021: THE CRITICAL CODE PATH CHANGES&#xA;&#xA;Coldcard seed generation moves into the new RNG architecture.&#xA;&#xA;The later reconstruction is essentially:&#xA;&#xA;Generate seed&#xA;&#xA;↓&#xA;&#xA;random.bytes()&#xA;&#xA;↓&#xA;&#xA;ngu.random.bytes()&#xA;&#xA;↓&#xA;&#xA;wrong rng_get() implementation&#xA;&#xA;↓&#xA;&#xA;software PRNG&#xA;&#xA;↓&#xA;&#xA;predictable-enough seed space&#xA;&#xA;⬜ Questions still worth answering:&#xA;&#xA;Who reviewed this specific change?&#xA;&#xA;Was RNG behavior tested on actual production hardware?&#xA;&#xA;Who verified which rng_get() implementation ended up in the finished binary?&#xA;&#xA;⸻&#xA;&#xA;🟦 MARCH 17, 2021: FIRMWARE 4.0.0 SHIPS&#xA;&#xA;Coldcard itself described the release as containing major internal cryptographic/BIP39 changes.&#xA;&#xA;People relevant organizationally:&#xA;&#xA;Rodolfo Novak / NVK #CoinkiteLeadership&#xA;Peter D. Gray / doc-hex #ColdcardFirmware&#xA;switck #libNgU&#xA;&#xA;Again, leadership involvement doesn’t establish authorship of the vulnerable code.&#xA;&#xA;⸻&#xA;&#xA;🟨 MARCH 29, 2021: ANOTHER SECURITY ISSUE IS FIXED&#xA;&#xA;Coldcard 4.0.1 fixes a security problem in 4.0.0.&#xA;&#xA;We have not established that this was the RNG problem.&#xA;&#xA;⬜ But it creates an important historical question:&#xA;&#xA;After finding a security problem immediately following a major cryptographic rewrite, was the rest of that rewrite comprehensively reviewed?&#xA;&#xA;⸻&#xA;&#xA;⏳ 2021 → 2026: THE FIVE-YEAR GAP&#xA;&#xA;This is one of the central mysteries.&#xA;&#xA;The vulnerable code exists.&#xA;&#xA;The source is public.&#xA;&#xA;Coldcard continues being used.&#xA;&#xA;People generate wallets.&#xA;&#xA;Yet the entropy defect apparently remains undetected.&#xA;&#xA;This is why:&#xA;&#xA;Open source means people CAN inspect code. It doesn’t mean somebody DID successfully verify every security-critical path.&#xA;&#xA;⸻&#xA;&#xA;⬜ 2021/22: CLAIMED EARLIER WARNING&#xA;&#xA;James O’Beirne #RNGResearch reportedly later said another person had raised an earlier concern.&#xA;&#xA;We still need the original communication before treating that as established notice.&#xA;&#xA;Status: LEAD, NOT CONCLUSION.&#xA;&#xA;⸻&#xA;&#xA;⬜ 2022: REPORTED SECURITY REVIEW&#xA;&#xA;There are claims concerning an outside security review containing RNG-related recommendations.&#xA;&#xA;The original report remains important evidence to obtain.&#xA;&#xA;Questions:&#xA;&#xA;What exactly did it say?&#xA;&#xA;Who received it?&#xA;&#xA;What recommendations were implemented?&#xA;&#xA;⸻&#xA;&#xA;🟨 MAY 2025: O’BEIRNE SAYS HE RAISES RNG CONCERNS&#xA;&#xA;James O’Beirne #RNGResearch&#xA;&#xA;O’Beirne says he examined the Coldcard RNG architecture, became concerned and raised the matter with Coinkite.&#xA;&#xA;⬜ The crucial missing evidence remains the original May 2025 correspondence.&#xA;&#xA;There is an enormous difference between:&#xA;&#xA;“I don’t like this library.”&#xA;&#xA;and:&#xA;&#xA;“Your seed generator may not actually be using the hardware RNG.”&#xA;&#xA;Until we see the communication, don’t collapse those possibilities together.&#xA;&#xA;⸻&#xA;&#xA;⬜ JUNE 2026: REPORTED AI-ASSISTED SECURITY REVIEW&#xA;&#xA;A review shortly before the attack has been reported.&#xA;&#xA;What we need:&#xA;&#xA;scope&#xA;&#xA;findings&#xA;&#xA;prompts&#xA;&#xA;RNG coverage&#xA;&#xA;seed-generation coverage&#xA;&#xA;Until those records are available, this remains an investigative question rather than proof someone missed a known vulnerability.&#xA;&#xA;⸻&#xA;&#xA;🟥 JULY 30, 2026: THE BITCOIN STARTS MOVING&#xA;&#xA;UNKNOWN ATTACKER(S) #UnknownAttackers&#xA;&#xA;Attackers apparently enumerate vulnerable Coldcard-generated seeds offline, derive addresses and sweep wallets.&#xA;&#xA;They don’t need to steal the physical Coldcard.&#xA;&#xA;They don’t need the victim to plug it in.&#xA;&#xA;They don’t necessarily need to phish the victim.&#xA;&#xA;They can attack the weak seed itself.&#xA;&#xA;Galaxy now confirms attackers began exploiting affected wallets at least by the early morning of July 30. &#xA;&#xA;⸻&#xA;&#xA;🟨 JULY 30: PLEBS START SOUNDING THE ALARM&#xA;&#xA;Victims report unexpected wallet drains.&#xA;&#xA;Then investigators begin connecting apparently unrelated cases.&#xA;&#xA;Kevin Loaec #EarlyWarning&#xA;&#xA;warns Coldcard users to check balances.&#xA;&#xA;↓&#xA;&#xA;Rodolfo Novak / NVK #CoinkiteResponse&#xA;&#xA;initially expresses skepticism that the reports demonstrate a systemic Coldcard failure.&#xA;&#xA;↓&#xA;&#xA;Rob Hamilton #OnChainInvestigation&#xA;&#xA;examines blockchain activity and identifies a larger pattern.&#xA;&#xA;↓&#xA;&#xA;Kevin Loaec #RNGResearch&#xA;&#xA;moves toward the weak-entropy hypothesis.&#xA;&#xA;↓&#xA;&#xA;James O’Beirne #UserWarning&#xA;&#xA;publicly warns affected users to move bitcoin.&#xA;&#xA;↓&#xA;&#xA;Rodolfo Novak / NVK #CoinkiteResponse&#xA;&#xA;changes his public position as evidence accumulates and Coinkite investigates.&#xA;&#xA;↓&#xA;&#xA;Greg Sanders / instagibbs #TechnicalReproduction&#xA;&#xA;independently reproduces/demonstrates the technical failure.&#xA;&#xA;That’s the critical transition:&#xA;&#xA;🟨 We think something is wrong&#xA;&#xA;becomes&#xA;&#xA;🟩 We can reproduce what’s wrong.&#xA;&#xA;⸻&#xA;&#xA;🟩 JULY 30–31: COINKITE CONFIRMS THE ENTROPY PROBLEM&#xA;&#xA;Emergency remediation follows.&#xA;&#xA;And here’s the thing every pleb needs burned into memory:&#xA;&#xA;Updating firmware does NOT fix a vulnerable seed.&#xA;&#xA;The weakness is embedded in the seed that already exists.&#xA;&#xA;A vulnerable wallet needs to be migrated to a newly generated safe seed, following current official guidance.&#xA;&#xA;The newest reporting continues to describe the failure as a software PRNG being reached instead of the intended hardware entropy source. &#xA;&#xA;⸻&#xA;&#xA;🟧 THE WARNING NETWORK FORMS&#xA;&#xA;People helping communicate/respond include:&#xA;&#xA;Matt Odell / ODELL #UserWarning&#xA;&#xA;Calle #SecurityResponse&#xA;&#xA;Ben Perrin / BTC Sessions #PublicEducation&#xA;&#xA;James O’Beirne #RNGResearch&#xA;&#xA;Kevin Loaec #EarlyWarning&#xA;&#xA;Rob Hamilton #OnChainInvestigation&#xA;&#xA;Greg Sanders / instagibbs #TechnicalReproduction&#xA;&#xA;They appear here because of their respective public roles.&#xA;&#xA;They are not being identified as attackers.&#xA;&#xA;⸻&#xA;&#xA;🟥 JULY 30 → AUGUST 6: MULTIPLE ATTACKERS&#xA;&#xA;Galaxy has now confirmed something particularly important:&#xA;&#xA;There wasn’t merely one identifiable attacker footprint.&#xA;&#xA;Researchers have identified at least 33 additional attacker footprints beyond the major waves and say with high confidence that multiple attackers were exploiting the vulnerability.&#xA;&#xA;They cannot determine whether every footprint represents a different person. &#xA;&#xA;That means don’t turn:&#xA;&#xA;“multiple attacker footprints”&#xA;&#xA;into:&#xA;&#xA;“33 hackers.”&#xA;&#xA;We don’t know that.&#xA;&#xA;⸻&#xA;&#xA;🟥 CURRENT CONFIRMED DAMAGE&#xA;&#xA;As of Galaxy’s August 14 accounting:&#xA;&#xA;190 victims directly contacted&#xA;&#xA;8,600+ addresses&#xA;&#xA;1,778.84 BTC confirmed stolen&#xA;&#xA;approximately $112.7 million at the valuation Galaxy used.&#xA;&#xA;And importantly:&#xA;&#xA;1,531 BTC was still sitting unmoved in attacker-controlled addresses.&#xA;&#xA;Approximately 246 BTC had moved onward.&#xA;&#xA;Of those moved funds, about 65% entered CoinJoin transactions, while the remainder continued through other on-chain paths, sometimes peel chains. Small amounts reached exchanges or interchain bridges. &#xA;&#xA;Galaxy has supplied attacker-address information to exchanges, compliance companies, investigators and law enforcement so funds might be frozen if they reach centralized intermediaries. &#xA;&#xA;So:&#xA;&#xA;Stolen does NOT necessarily mean investigators should give up.&#xA;&#xA;⸻&#xA;&#xA;💔 NOW: “MY BITCOIN IS STILL THERE”&#xA;&#xA;This person needs action, not investigation Twitter.&#xA;&#xA;First determine:&#xA;&#xA;Coldcard model&#xA;&#xA;firmware that generated the seed&#xA;&#xA;approximately when the seed was generated&#xA;&#xA;whether dice entropy was added&#xA;&#xA;whether a strong unique BIP39 passphrase exists&#xA;&#xA;whether BIP85 child wallets were derived&#xA;&#xA;whether multisig is involved&#xA;&#xA;Then follow the current official Coldcard migration instructions, not random screenshots or DMs.&#xA;&#xA;Do not simply:&#xA;&#xA;update firmware → keep same vulnerable seed → assume safe.&#xA;&#xA;That misses the core problem.&#xA;&#xA;⸻&#xA;&#xA;💔 “MY BITCOIN IS ALREADY GONE”&#xA;&#xA;Do not wipe everything in panic.&#xA;&#xA;Preserve evidence.&#xA;&#xA;Create a folder containing:&#xA;&#xA;Coldcard information&#xA;&#xA;Model&#xA;Firmware&#xA;Purchase date&#xA;Approximate seed-generation date&#xA;&#xA;Wallet information&#xA;&#xA;Public Bitcoin addresses&#xA;Transaction history&#xA;Whether singlesig/multisig&#xA;Whether BIP85 was used&#xA;Whether dice were used&#xA;Whether a passphrase existed&#xA;&#xA;Theft information&#xA;&#xA;TXID&#xA;Date/time&#xA;Amount&#xA;Destination address(es)&#xA;Screenshots&#xA;&#xA;Supporting records&#xA;&#xA;Coldcard purchase receipt&#xA;Exchange withdrawals showing how BTC reached the wallet&#xA;Relevant support emails&#xA;Warnings received&#xA;Communications concerning the incident&#xA;&#xA;But:&#xA;&#xA;🚨 NEVER PUT THE SEED PHRASE IN THE EVIDENCE PACKET.&#xA;&#xA;Also never send:&#xA;&#xA;BIP39 passphrase&#xA;&#xA;XPRV&#xA;&#xA;PIN&#xA;&#xA;private keys&#xA;&#xA;dice-roll sequence used to generate the wallet&#xA;&#xA;Investigators generally need the public transaction evidence, not the secret required to spend what’s left.&#xA;&#xA;⸻&#xA;&#xA;🏛️ REPORT IT&#xA;&#xA;For U.S. victims, the FBI explicitly asks cryptocurrency victims to report:&#xA;&#xA;wallet addresses&#xA;&#xA;amounts&#xA;&#xA;type of cryptocurrency&#xA;&#xA;transaction hashes / TXIDs&#xA;&#xA;dates and times&#xA;&#xA;plus other identifying information surrounding the incident. &#xA;&#xA;FBI Internet Crime Complaint Center⁠￼&#xA;&#xA;Victims can also contact their local FBI field office. &#xA;&#xA;Don’t assume:&#xA;&#xA;“Bitcoin transactions can’t be reversed, therefore reporting is pointless.”&#xA;&#xA;Blockchain transactions themselves aren’t reversed, but tracing can identify centralized touchpoints, and exchanges can freeze assets through their own processes or legal process. &#xA;&#xA;⸻&#xA;&#xA;🚨 THE SECOND ROBBERY&#xA;&#xA;This needs to become one of your loudest warnings.&#xA;&#xA;After somebody posts:&#xA;&#xA;“I lost 8 BTC.”&#xA;&#xA;They may receive:&#xA;&#xA;“I can recover it.”&#xA;&#xA;“I work with law enforcement.”&#xA;&#xA;“I traced the hacker.”&#xA;&#xA;“Send me $5,000 and I’ll freeze the wallet.”&#xA;&#xA;“Connect your wallet here.”&#xA;&#xA;“Send your seed so I can verify whether you’re affected.”&#xA;&#xA;NO.&#xA;&#xA;The FBI specifically warns that cryptocurrency recovery scammers target people who already lost crypto, including fake recovery companies and people pretending to have law-enforcement connections. &#xA;&#xA;Private recovery companies cannot issue seizure orders.&#xA;&#xA;Law enforcement doesn’t charge victims an investigation fee. &#xA;&#xA;And the current IC3 homepage itself warns that scammers are impersonating IC3. &#xA;&#xA;Nobody legitimately helping investigate this needs your seed phrase.&#xA;&#xA;⸻&#xA;&#xA;🧡 HOW ORDINARY PLEBS CAN HELP&#xA;&#xA;This may be the most important part of the entire project.&#xA;&#xA;You do not need to become a hacker.&#xA;&#xA;Help find Coldcard owners who aren’t terminally online.&#xA;&#xA;The person most endangered now may not be arguing about entropy on Nostr.&#xA;&#xA;It may be someone who:&#xA;&#xA;bought a Coldcard in 2022&#xA;&#xA;generated a seed&#xA;&#xA;put bitcoin on it&#xA;&#xA;put the Coldcard in a drawer&#xA;&#xA;and thinks:&#xA;&#xA;“Hardware wallet. I’m good.”&#xA;&#xA;Those people need the warning.&#xA;&#xA;Plebs can also:&#xA;&#xA;Archive public evidence.&#xA;&#xA;Preserve URLs, dates, screenshots and original context.&#xA;&#xA;Help victims organize evidence.&#xA;&#xA;Don’t ask for their seeds.&#xA;&#xA;Point victims toward official reporting.&#xA;&#xA;Don’t promise recovery.&#xA;&#xA;Translate the technical explanation into ordinary language.&#xA;&#xA;Weak randomness made some seeds guessable.&#xA;&#xA;That’s enough for most people.&#xA;&#xA;Watch for recovery scammers.&#xA;&#xA;They’re going to hunt the victim population.&#xA;&#xA;Don’t dox victims.&#xA;&#xA;Knowing that somebody owns substantial Bitcoin is itself dangerous information.&#xA;&#xA;Don’t accuse named people without evidence.&#xA;&#xA;Developers, executives, researchers, auditors, promoters and funders have different roles.&#xA;&#xA;Relationship ≠ responsibility.&#xA;&#xA;Responsibility ≠ criminality.&#xA;&#xA;Criminality requires evidence.&#xA;&#xA;⸻&#xA;&#xA;⚖️ AND KEEP OUR INVESTIGATION SEPARATE&#xA;&#xA;Our unanswered historical questions remain:&#xA;&#xA;⬜ Who reviewed the March 2021 RNG integration?&#xA;&#xA;⬜ What exactly happened during release security review?&#xA;&#xA;⬜ What was the unrelated 4.0.0 security issue?&#xA;&#xA;⬜ What did the reported 2022 review say about RNG?&#xA;&#xA;⬜ What exactly did James O’Beirne communicate in May 2025?&#xA;&#xA;⬜ Who received it?&#xA;&#xA;⬜ What was the scope of the reported June 2026 AI review?&#xA;&#xA;⬜ Were earlier unexplained wallet drains actually connected?&#xA;&#xA;⬜ Who were the attackers?&#xA;&#xA;⬜ Can centralized touchpoints eventually identify or freeze attacker funds?&#xA;&#xA;Those questions matter.&#xA;&#xA;But they come after protecting people who may still be exposed.&#xA;&#xA;⸻&#xA;&#xA;🧾 THE ENTIRE THING IN SIX WORDS&#xA;&#xA;CHECK → MIGRATE → PRESERVE → REPORT → WARN → VERIFY&#xA;&#xA;And underneath that:&#xA;&#xA;Don’t trust a DM. Don’t share seeds. Don’t accuse without receipts.&#xA;</html></oembed>