THE COLDCARD BUG ODELL MENTIONED ON RHR IN 2021 WAS NOT THE RNG BUG
Claims circulating that a 2021 Rabbit Hole Recap episode proves Coinkite knew about the RNG vulnerability for years are incorrect.
The bug
@ODELLXYZ referenced was an entirely different issue affecting unreleased firmware v4.0.0, not the entropy/RNG flaw behind the recent wallet-draining attacks.
The issue was a USB serial REPL vulnerability.
According to Coinkite’s historical security disclosures, v4.0.0 was built and tested internally but never released publicly. Public users received v4.0.1, which already contained the fix.
The attack also required a malicious USB connection to the device. Matt Odell’s setup guides from the time explicitly instructed users to power the Coldcard from a battery instead of a laptop, a practice that would have mitigated this attack vector.
The 2021 podcast was discussing a legitimate security bug, but it was not the RNG vulnerability that enabled the 2026 thefts.