Why I believe #Coinkite defrauded #Coldcard customers. 🤫

64acf4055fa826bc...

npub1vjk0gp2l4qnte2uy2l3ya78m5ays4wc7wmd6k64gw5498g8tf49qtkd33q

hex

00000489c4477f27a4fd812c93b6ebbf6dd3e3250aebe10cb10175cd79dd9f1f

nevent

nevent1qqsqqqqy38zywle85n7cztynkm4m7mwnuvjs46lppjcszawd08we78cprpmhxue69uhhyetvv9ujuem4d36kwatvw5hx6mm9qgsxft85q406sf4u4wz90cjwlra6wjg2hv08dkatd25822jn5r456jsa52pch

Kind-1 (TextNote)

2026-08-22T20:52:25Z

Why I believe #Coinkite defrauded #Coldcard customers. 🤫

  1. CTO authored entropy vulnerability while pretending to be an external contributor. Coinkite props up CTO alias as an external dev in comms.

  2. CEO shared details with Odell that could only apply to the entropy vulnerability that had just gone out to customers. Odell then bragged about his self custody guide, implicating CEO.

  3. CTO always used the ifndef guard correctly in the Coldcard firmware, literally dozens of times, but shipped a singular misuse of the function under his alias, thus allowing customer funds to be swept remotely.

  4. In the same release the entropy vulnerability was distributed, the CTO had enabled the interactive debugger used to verify code changes on live Coldcard devices, which would plainly reveal that the false/pseudo Yasmarang entropy had been selected.

https://blossom.primal.net/7fbf5ad8e7af0682795e0c20d15200be252922b23f92275f8447c49fc88a9de5.jpg

原始 JSON

{
  "kind": 1,
  "id": "00000489c4477f27a4fd812c93b6ebbf6dd3e3250aebe10cb10175cd79dd9f1f",
  "pubkey": "64acf4055fa826bcab8457e24ef8fba7490abb1e76dbab6aa8752a53a0eb4d4a",
  "created_at": 1787431945,
  "tags": [
    [
      "t",
      "coinkite"
    ],
    [
      "t",
      "coldcard"
    ],
    [
      "imeta",
      "url https://blossom.primal.net/7fbf5ad8e7af0682795e0c20d15200be252922b23f92275f8447c49fc88a9de5.jpg",
      "m image/jpeg",
      "thumbhash iigGDYRdOOhph3hwaWl5dbiPg/45",
      "dim 990x691"
    ],
    [
      "client",
      "Dark Wisp"
    ],
    [
      "nonce",
      "295617",
      "18"
    ]
  ],
  "content": "Why I believe #Coinkite defrauded #Coldcard customers. 🤫\n\n1. CTO authored entropy vulnerability while pretending to be an external contributor. Coinkite props up CTO alias as an external dev in comms. \n\n2. CEO shared details with Odell that could only apply to the entropy vulnerability that had just gone out to customers. Odell then bragged about his self custody guide, implicating CEO. \n\n3. CTO always used the ifndef guard correctly in the Coldcard firmware, literally dozens of times, but shipped a singular misuse of the function under his alias, thus allowing customer funds to be swept remotely. \n\n4. In the same release the entropy vulnerability was distributed, the CTO had enabled the interactive debugger used to verify code changes on live Coldcard devices, which would plainly reveal that the false/pseudo Yasmarang entropy had been selected. \n\nhttps://blossom.primal.net/7fbf5ad8e7af0682795e0c20d15200be252922b23f92275f8447c49fc88a9de5.jpg",
  "sig": "af02216ec861b062a11887c804d78603a04a81181c5f9a3f3cf09b64e726c2aae70402a6169caade723f8a1866443b3a71d0a669ff40916dc8249b4a43b34a11"
}