NVK responds to COLDCARD community.
Coinkite CEO NVK published a statement addressing the COLDCARD entropy vulnerability. "I'm sorry and I'm devastated," he wrote.
"As a team that has dedicated our lives to securing the Bitcoin held by millions of individuals, businesses, and families, this is our core responsibility, and we fell short."
NVK said the company has shipped a firmware hotfix that removes the software fallback path entirely, but stressed it does not fix seeds already generated on vulnerable firmware.
"If your seed was generated before the fix, it needs to be individually migrated to a new seed. A firmware update alone cannot do that for you."
He urged anyone who knows a COLDCARD owner to help spread the word, noting the company does not store customer information.
"We know an apology doesn't return anyone's funds. We know we'll have to earn back our users' trust. That starts with being open and telling the truth about how this happened."
NVK closed with a warning to the broader developer community: "AI-assisted code review can now find latent bugs at a speed that is outpacing even the industry's most seasoned experts. If your firmware is open-source or has ever been public, assume it's already being read by attackers and defenders alike."