The Coldcard RNG Issue: Build Integration, Entropy and Verification
An evidence-scoped explanation of the seed-generation incident and what a software review can and cannot establish.
Correcting the mechanism
The earlier version called this an intentional runtime software fallback. The manufacturer’s 4 August clarification instead describes a link-time integration error that selected the general-purpose PRNG implementation. Hardware failure did not initiate a designed fallback. This correction removes unsupported certainty about implementation intent and attacker resources.
Why integration deserves its own verification
A review of a function in isolation cannot establish which implementation a shipped binary invokes. Build settings, symbols, dependencies and release artifacts all form part of the system. A useful review states the artifact examined and what was actually measured. It distinguishes source inspection, reproducible builds, device instrumentation and a complete independent audit. Finding one corrected path does not prove that every unrelated path is safe.
Reading a security claim carefully
Ask whether the evidence applies to the source, a particular binary, a device model or the operator’s actual setup. Look for dates and a clear account of open questions. Avoid converting an absence of detected problems into an absence of risk. The current security record is the place to check scope and remediation. If you hold an affected seed, use the linked official migration instructions rather than deriving a response from this conceptual explanation.
Apply the same discipline to a continuity service
A successful email job shows that a notification was processed; it does not show that a recipient decrypted and saved a file. A synthetic website demonstration explains a flow; it does not test real key custody. A credible handoff rehearsal checks the sender’s original file against what the authorised recipient can open, on the device they expect to use. Record the result and keep separate backups. These are practical acceptance checks rather than claims that an entire system has no defects.
Prepare the instructions your person would need
Keep wallet seed words and master passwords out of a general handoff message. Start with a non-secret inventory, document locations and a person to contact. ZeroLatch is an online conditional delivery service: check-ins keep a delivery on hold, and a missed deadline plus the safety period can make it eligible for release. Recipient access also depends on verification and service availability. Simple uses service-managed key recovery; Private requires a separate secret. Neither mode guarantees a financial or legal outcome.
Save the free handoff checklist, or try a fictional delivery without signup. The sample uses no real wallet data.
ZeroLatch Editorial Team
Published by ZeroLatch to explain future delivery and continuity planning. These guides are not independent reviews of our product. Read our editorial standards and corrections.
Disclaimer: The information provided in this article is for educational and informational purposes only and does not constitute legal, financial, or technical advice. ZeroLatch is a software service, not a law firm. We recommend consulting with qualified professionals regarding your specific estate planning, data privacy, and security needs.
Who would know where to begin with your wallets?
See a handoff with wallet-record locations and adviser contacts. ZeroLatch can release instructions after missed check-ins and a safety period; it does not secure wallets or transfer assets. Keep recovery secrets separately.
Write my instructions →Start a free draft without an account or card. Use harmless information. See the example first.