This is the thing I also can’t stop thinking about. It quickly leads you to conclude either extreme malice or extreme incompetence.
Login to reply
Replies (40)
My gut says extreme incompetence. Especially now that we have seen the shitty developer practices and reusing gpg keys for the nym account. Regardless- there is enough there to warrant suspicion of malice.
I keep thinking about the "people didn't do enough dice rolls" thing. If you needed at least 100 rolls why let the user only do a few like I've seen people mention?
Odell said that's what he was referring to in that clip going around of him telling people not to do the dice rolls because people were only doing a few and getting rugged.
Gross negligence or criminal intent. Hard to think of 3 possibly.
There was no weak entropy fallback. Stop giving air time to air head feds. The weak PRNG (Yasmarang) wasn’t Coinkite’s fallback. It’s MicroPython’s built-in general-purpose RNG — introduced upstream in May 2018, and it didn’t enter Coldcard seed generation until the libNgU migration in March 2021. Every language runtime ships something like this for ordinary randomness (shuffling, jitter, non-security stuff), and that’s fine on its own. Coinkite’s actual design intent was the opposite of a fallback: route seed generation exclusively through their hardware TRNG and never touch the software one. Setting MICROPY_HW_ENABLE_RNG=0 was them trying to switch the software path off. The bug is that the switch didn’t take, and the symbol quietly resolved to the runtime’s default instead. So the “fallback” was collateral inheritance from their platform, activated by a link-time mistake, not a corner someone chose to cut in the seed logic.
Funny watching you try to save face. I warned you about these bad actors and you laughed and blocked me. GFY
What episode is this?
Inside job CANNOT be ruled out.
NVK, from my impression, was constantly thinking and talking about security. Obsessed almost?
Not a single thought in 5 years about a probability of a bug in the RNG code, knowing perfectly well there were two implementations because one was explicitly disabled.
Very suspect indeed.
Another theory is incompetence, but he was friends with people who know about security, like on his podcast, so he surely would have been called out?
Whatever it is trust God the truth will be found.
It has to be extreme malice. Its hard to consider extreme incompetence for a security product of this kind. And then you have to factor in the fact that the code change was authored anonymously and merge by the CTO as shown by @Laser. Sounds dodgy as fuck.
View quoted note →
3rd though extremely unlikely option: This is what HWW wrench attacks look like.
Attacks on HWW makers, that is. IE they could have been forced to weaken the entropy by a 3rd party.
Agreed.
This one detail.
Plus the look of this Doc Hex guy.
Richard Heart body type.
Hard to trust.
Hadn’t considered that
The fallback was part of the hardware that they used and I don't really know if there was a way to "turn it off" or disable it.
If there was, it definitely should have been done. That said, I think a big part of the issue is that the team was small and clearly amateur or time constrained.
That it stayed for 5 years, I'd say amateur.
Either way they need to reimburse or face justice
They were a tiny company right, so they probably hired this work out to an Indian dev who only cared about getting the product to work so he could get paid
It should be ruled in
It would have been useful for him to say that on the spot and explain the consequences instead of a warning without explanation. Not blaming just stating. It may have helped me and others down the right path earlier.
Gates, Fauci, and friends reaping profits from orchestrated chaos. Incompetence is just a euphemism for deliberate destruction.
I have this really secure lock but if for any reason it fails I'm just going to leave the door open. Nobody designs security like that.
It’s truly the crux of it all.
If this is true, it does open the door to gross negligence being the cause again for me. Before reading this it had started to look more & more like a potential long-range exit scam that got uncovered by kimi3 ahead of time.
I think it would be interesting to find out if relatively small amounts of bitcoin had been regularly swept through this mechanism over the 5 years the bug existed.

Wouldn’t surprise me that the BTC media have jumped the gun, throwing accusations and hysteria. Seems highly unlikely to me that someone would plan an exit that anyone could see in plain sight if they took a decent look
thank you
Agree this alone has a plausible explanation. But is there an explanation for why the Coinkite CTO would submit the corrupt code under a pseudonymous account, pretending to interact with his real identity? Taken together this looks bad IMO. I’m sincerely open to a rational explanation.
I wouldn't hold your breath on reimbursement. They sold $250 devices and had salaries to pay. And unless there's really a conspiracy uncovered, being incorporated will likely protect the individuals from any personal liability or findings of criminality.
Coinkite will be liquidated but it'll barely put a dent in what was lost.
or extreme hubris, which lines up with their general attitude.
Jack is 1 degree removed from Nutlick which is 1 degree removed from Epstein. Mallers is compromised.
Or a mix of both ….
#Bitcoin #Coldcard #Entropy


Seen. Such HUBRIS.
#Bitcoin #Entropy


Yeah - mistake that the seed was derived from the Serial Number (MCU UIDl) that was likely linked to the customer data that they didn't delete lmao
The weakness was structural, not a privacy-of-serial-numbers problem. I’ve seen no evidence of the latter
If I was a victim, I would not give a fuck. They pay back or they face real justice.
I hope so people can organise, fund detectives, find them and give them what they deem deserving
Cold Card came back from silence to make an important announcment and tell you you're wrong HODL 

uncleJim21 (npub1g5…e9lcr) on Nostr
Short Text Note by uncleJim21
Buck passing thy name is Cold Card.
Funny cause LLMs often do NOT want to fail close…
@El Dorado the intent argument is unfalsifiable from outside. what is checkable is that an anonymous commit to the RNG reached a release with the CTO as the only reviewer.
Yes but multiple structural weaknesses.
Not plausible that they were all accidental imho.
I think he’s compromised but trying to sneak out the door.
(Before he’s forced to be more involved)