Damus
uncleJim21 · 18h
(4/N): **From TFTC Podcast (April 1, 2021):** > "Not a hack, but they had a vulnerability that was self-discovered. So they have a new firmware version, 4.0.1, or is it 0.01? 4.0.1. Yeah. You messed u...
uncleJim21 profile picture
(5/5):
### NVK Direct Appearances
1. **[SLP62 - Rodolfo Novak - Keeping Bitcoin Cypherpunk](https://www.stephanlivera.com/episode/62/)** (March 27, 2019)
- 🎧 [TRNG quote](https://pullthatupjamie.ai/share?clip=fc87b6c9-7cf7-a7a3-3ceb-816b809c8a03_p137)

2. **[SLP418 - NVK Tapsigner: Bitcoin Hardware for the Masses?](https://www.stephanlivera.com/episode/418/)** (October 4, 2022)
- 🎧 [Libngu scrutiny quote](https://pullthatupjamie.ai/share?clip=18f258a1-cf98-4171-ab30-7954f30ea982_p99)

### Community Analysis
3. **[Simply Bitcoin EP 1561 - NEW INFORMATION: Is it too dangerous to hold all your own Bitcoin???](https://podcasters.spotify.com/pod/show/simplybitcoin/episodes/NEW-INFORMATION-Is-it-too-dangerous-to-hold-all-your-own-Bitcoin-----EP-1561-e3mtv62)** (August 3, 2026)
- 🎧 [License change timeline](https://pullthatupjamie.ai/share?clip=0e0dcaee-4a8d-4a4a-9f57-056504769338_p132)

4. **UNGOVERNABLE - Unpacking the Coldcard Exploit | FREEDOM TECH FRIDAY 50** (August 1, 2026)
- 🎧 [LibNGU library origins](https://pullthatupjamie.ai/share?clip=483953a7-1e90-42b8-88a5-9a1213d37f3f-c88dfb2d-f3b6-4bea-bb5f-df1360822233_p58)
- 🎧 [Custom license discussion](https://pullthatupjamie.ai/share?clip=483953a7-1e90-42b8-88a5-9a1213d37f3f-c88dfb2d-f3b6-4bea-bb5f-df1360822233_p70)
- 🎧 [Entropy implementation bug](https://pullthatupjamie.ai/share?clip=483953a7-1e90-42b8-88a5-9a1213d37f3f-c88dfb2d-f3b6-4bea-bb5f-df1360822233_p61)

5. **Citadel Dispatch - CATASTROPHIC COLDCARD BUG** (August 3, 2026)

6. **Rabbit Hole Recap - Week of 2021.03.29** (March 29, 2021)
- Coverage of firmware 4.0.1 "self-discovered vulnerability"

7. **Coin Stories with Natalie Brunell - How to Set Up Cold Storage with ColdCard** (July 18, 2023)
- Dice roll feature explanation

---

## All Sources

All quotes sourced from **pullthatupjamie.ai** podcast index covering 120k+ hours of Bitcoin podcast content. Dates range from 2018-2026.

**Jamie API:** https://pullthatupjamie-nsh57.ondigitalocean.app

---

## Conclusion

The evidence suggests:

1. **The vulnerability was introduced intentionally or negligently** in the same massive commit that changed the license from GPL to a proprietary "Bitcoin only" license
2. **Marketing emphasized hardware RNG security** while the actual implementation failed to use it properly
3. **An early patch (4.0.1) may have been a partial fix** but the full scope was not disclosed
4. **The proprietary license likely reduced scrutiny** from the open source community
5. **Claims about "scrutiny" and not "YOLO-ing" code** were contradicted by the actual development practices

Whether this was malicious, incompetent, or a combination is unclear. What is clear is that NVK's public statements about Cold Card's security and development practices do not match the reality of what happened with firmware 4.0.

---

**Report compiled:** 2026-08-04
**Research by:** Jones (OpenClaw agent)
**Data source:** Jamie (pullthatupjamie.ai) podcast index
**Interactive version:** https://pullthatupjamie.ai


@. @Laser @Contra
1❤️1🐢1
uncleJim21 · 18h
Scan of possible NVK appearances: # NVK Podcast Appearances Mapped (2018-2026) ## Direct NVK Interviews & Appearances ### 2026 - **June 20, 2026** - TFTC #760: The State Is Farming You with NVK - **March 9, 2026** - Münzweg (German Bitcoin podcast) - Bitcoin Realtalk (mit Robin Linus) ### 2025 -...