Samson Mow, CEO of JAN3, a Bitcoin technology company focused on accelerating hyperbitcoinization, published five practical recommendations on August 1st on X for users affected by the Coldcard random number generator (RNG) vulnerability. His recommendations emphasized preserving evidence, reporting thefts, monitoring coordinated fund recovery efforts, and avoiding fraudulent "recovery" schemes, as this incident has raised broader concerns about self-custody security.
Mow wrote:
"The COLDCARD RNG vulnerability could be worse than an exchange hack. It strikes at the very core of independent Bitcoin holders — those who diligently researched, understood the importance of self-custody, and did not keep their coins on exchanges."
In his first recommendation, he urged affected users to document all their information, including wallet addresses, dates, firmware versions, transaction details, and any other data that could help create a detailed incident report.
Mow also called on victims to file police reports, as this creates an official record. He recommended contacting cybercrime units, national reporting portals such as the FBI's Internet Crime Complaint Center, or specialized cryptocurrency crime task forces where available. In his third recommendation, he advised affected users to follow coordinated efforts to trace the movement of stolen funds.
Preserve Evidence and Ignore Fraudulent Recovery Offers
Another key recommendation concerned preserving the affected Coldcard device and seed phrase instead of destroying them after the theft. Mow advised victims to keep the device, seed phrase, and PIN, explaining that they might need to prove ownership if the stolen bitcoins eventually land on an exchange and are frozen.
He also issued his strongest warning against scammers offering recovery services, urging victims never to disclose personal information or seed phrases, and never to send money to anyone claiming they can recover stolen cryptocurrency. The FBI has repeatedly warned that scammers often target victims of previous cryptocurrency thefts, offering fake recovery services that require upfront payment or the disclosure of sensitive wallet information.
Security Lessons Extend Beyond One Hardware Wallet
While expressing sympathy for affected users, Mow also noted that this incident further highlights the importance of reducing single points of failure in Bitcoin self-custody by using hardware from multiple manufacturers in a multisignature setup, rather than relying on a single vendor.
Mow wrote:
"Self-custody is difficult. If you advocate for self-custody, you should also advise people to use a multi-vendor multisig configuration. I have been saying this for years. Self-custody works only if you structure it to minimize failure points. Do not trust hardware from any single vendor. Assume that everyone is your adversary."
He acknowledged that self-custody remains challenging for many users and urged the Bitcoin community to be less critical of those who choose custodians, exchange-traded funds, or Bitcoin asset management companies. Mow emphasized that there is no single right way to hold Bitcoin, as each storage method involves certain trade-offs.
Mow also urged affected users not to act rashly and to seek help if they need support. He noted that many Bitcoin holders have lost coins for various reasons and stressed that people can rebuild their position after a loss.
Coinkite's Response and Fallout Continues
Coinkite, a Toronto-based company specializing in Bitcoin security hardware and behind Coldcard wallets, issued a security advisory urging users of affected devices to update their firmware to a patched version before generating new seeds and to move funds if their seed was created on vulnerable versions. The advisory also notes that updating the firmware does not fix previously generated seeds and recommends checking backups and performing test transactions before moving funds.
Previous reports have examined which Coldcard wallets are most likely at risk, how vulnerable seeds were generated, and the conditions that led to affected users' vulnerability. Since then, the fallout from the incident has expanded. Affected users are considering legal action against Coinkite, while the perpetrator received an unsolicited on-chain message offering money laundering services for the bitcoins.
end-content







