Coldcard Incident Timeline: Read the Current Evidence and Corrections
A guide to the manufacturer’s incident record, the distinction between reported losses and verified facts, and keeping handoff instructions current.
A record that can change
The original version of this article presented a precise loss total and a three-wave timeline without adequate sourcing. Those claims have been removed. The URL is retained so existing links reach this correction. Consult the manufacturer’s living security record and the 4 August public-record clarification for the dated response and subsequent guidance.
Distinguish the mechanism from an incident narrative
Coinkite describes a build/link integration error in the seed-generation path, rather than a hardware generator failing at runtime and deliberately falling back to weaker randomness. That distinction matters when describing the engineering failure. It does not determine the cause of every individual loss report. Avoid assigning exact affected-wallet counts, victim models or attacker infrastructure from an unsourced summary. A transaction visible on a blockchain does not, by itself, explain how control of the keys was obtained.
How to maintain your own decision record
Save the title, source address and date of the advisory you used. Separate what the manufacturer states from what another analyst infers. Record actions you completed and the checks that remain open. Revisit a saved summary when the official guidance changes; an old screenshot is not a current advisory. Keep this record private if it links wallet activity to an identifiable person or organisation. Never include recovery secrets in a support request or incident note shared with others.
Turn the lesson into a usable recovery plan
The person receiving your handoff needs to know which instructions are current and who can help. They do not need to reconstruct a sensational incident timeline before finding the relevant documents. Put a review date on your inventory, name the trusted contact and remove outdated instructions from the active packet. Preserve historical material separately if it is needed for accounting, evidence or other records.
Prepare the instructions your person would need
Keep wallet seed words and master passwords out of a general handoff message. Start with a non-secret inventory, document locations and a person to contact. ZeroLatch is an online conditional delivery service: check-ins keep a delivery on hold, and a missed deadline plus the safety period can make it eligible for release. Recipient access also depends on verification and service availability. Simple uses service-managed key recovery; Private requires a separate secret. Neither mode guarantees a financial or legal outcome.
Save the free handoff checklist, or try a fictional delivery without signup. The sample uses no real wallet data.
ZeroLatch Editorial Team
Published by ZeroLatch to explain future delivery and continuity planning. These guides are not independent reviews of our product. Read our editorial standards and corrections.
Disclaimer: The information provided in this article is for educational and informational purposes only and does not constitute legal, financial, or technical advice. ZeroLatch is a software service, not a law firm. We recommend consulting with qualified professionals regarding your specific estate planning, data privacy, and security needs.
Who would know where to begin with your wallets?
See a handoff with wallet-record locations and adviser contacts. ZeroLatch can release instructions after missed check-ins and a safety period; it does not secure wallets or transfer assets. Keep recovery secrets separately.
Write my instructions →Start a free draft without an account or card. Use harmless information. See the example first.