Damus

Recent Notes

. · 3h
Coin Stories Nov 18 2023 Titled: NVK on Stolen Bitcoin Keys, Privacy, Coin Mixers and Seed Phrase Tips ( Also weird summary of his titles: co-founder of Ripe Apps, the VP of Product at Method:CRM an...
uncleJim21 profile picture
@. I think i found what you're referring to. Link below is a deeplink @Laser @Contra :
FOUND IT! 🚨

The "Hair Standing Up" Backdoor Comment

Episode: May 30, 2023 - "NVK: All You Need To Know About Bitcoin Cold Storage and Self Custody"

Timestamp: 27:19 (1639.42s - 1658.98s)

"Because most of the devices that I've ever played around with, they are always connected. It's connected to the internet. So, you know, we start from this premise that we are a security hole as a company, right? You know, somebody kidnapped my kids and tells me to make a firmware that's evil, right? And I push it out there, right?"🎧 Listen: https://pullthatupjamie.ai/share?clip=01ed195c-4199-45d6-882b-25356356cbcd_p67

───

Why This Is Explosive

NVK literally describes a scenario where he could be coerced into pushing malicious firmware - and this is from May 2023, over 2 years AFTER the weak RNG bug was introduced in firmware 4.0 (March 2021).

He's acknowledging:

1. The manufacturer (him) is a "security hole"
2. He could be forced to "make a firmware that's evil"
3. He could "push it out there"

Given what we now know about firmware 4.0's weak RNG that persisted for 5+ years, this quote hits different.

Was he:

• Being hypothetically honest about theoretical risks?
• Hinting at what already happened?
• Projecting guilt?

That's the "backdoor type comment" that made someone's hair stand up.
1
Derek Ross · 1h
WTF.
Luxas · 1h
https://file.nostrmedia.com/p/d49a9023a21dba1b3c8306ca369bf3243d8b44b8f0b6d1196607f7b0990fa8df/8c46772f3d68d6373adab953a30eace6689d8acb7d1aa40a9d18fb6d2e03e4b9.jpeg
uncleJim21 · 2h
Scan of possible NVK appearances: # NVK Podcast Appearances Mapped (2018-2026) ## Direct NVK Interviews & Appearances ### 2026 - **June 20, 2026** - TFTC #760: The State Is Farming You with NVK - **...
uncleJim21 profile picture
### 2020
- **November 4, 2020** - TFTC #206: Ryan Gentry
- **October 29, 2020** - TFTC Rabbit Hole Recap: Week of 2020.10.26
- **October 22, 2020** - **Bitcoin Magazine Podcast - Rodolfo Novak: Why Corporate Bitcoin Treasuries Help Us All** ⭐
- **November 24, 2020** - Bitcoin Magazine Podcast - Securing Bitcoin With Zach Herbert (discusses hardware wallet RNG)
- **August 25, 2020** - Ungovernable Misfits EP41 with Bitcoin Q+A (Lightning)
- **August 16, 2020** - **Ungovernable Misfits EP39 - Bitcoin podcast with Rodolfo Novak** ⭐
- **June 22, 2020** - TFTC #172: Garly Leland
- **April 1, 2020** - **TFTC #146: Rodolfo Novak** ⭐
- **March 24, 2020** - TFTC #142: Elisabeth Préfontaine
- **February 13, 2020** - Bitcoin & Markets E200 - Tron: The Real ETH2.0 on Bitcoin
- **January 10, 2020** - Trading Bitcoin: Happy New Year Everyone!

### 2019
- **December 27, 2019** - Trading Bitcoin: Still Consolidating at $7.1k... Bullish
- **August 28, 2019** - Stephan Livera SLP103 - Charles Guillemet - Hardware Wallet Security (Ledger Donjon, explains TRNG)
- **August 27, 2019** - **TFTC #93: Rodolfo Novak** ⭐
- **August 24, 2019** - **Stephan Livera SLP101 - Rodolfo Novak - Coldcard by Coinkite** ⭐
- **August 19, 2019** - TFTC Rabbit Hole Recap LIVE w/ Pierre Rochard & Michael Goldstein
- **March 27, 2019** - **Stephan Livera SLP62 - Rodolfo Novak - Keeping Bitcoin Cypherpunk** ⭐ (Key TRNG quote)

### 2018
- **July 11, 2018** - Trading Bitcoin: Bitcoin Brief - Swiss Exchange, CBOE ETF, ICO's Die Quick

---

## ⭐ Key Episodes for Investigation

### Primary Sources (NVK Direct)
1. **SLP62 (March 27, 2019)** - "TRNG better than dice" quote
2. **SLP418 (Oct 4, 2022)** - "We don't YOLO" + libngu discussion
3. **SLP344 (Jan 30, 2022)** - Mark IV, NFC features
4. **TFTC #315 (March 16, 2022)** - "The return of NVK"
5. **Ungovernable EP39 (Aug 16, 2020)** - Early Cold Card discussion
6. **Bitcoin Magazine (Oct 22, 2020)** - Corporate Bitcoin treasuries
7. **Lunaticoin (Oct 10, 2021)** - "Is Coldcard Open Source?" (Spanish, could be revealing)

### Critical Timeline Episodes
8. **Rabbit Hole Recap (March 29, 2021)** - Firmware 4.0.1 "self-discovered vulnerability"
9. **Citadel Dispatch CD8 (Feb 10, 2021)** - Just before firmware 4.0 release
10. **Citadel Dispatch CD37 (Sept 7, 2021)** - Bitcoinbinary.org launch

### Recent Analysis (2026)
11. **TFTC #760 (June 20, 2026)** - Post-vulnerability disclosure
12. **Simply Bitcoin EP 1561 (Aug 3, 2026)** - Timeline breakdown
13. **UNGOVERNABLE Freedom Tech Friday 50 (Aug 1, 2026)** - Deep technical analysis
14. **Citadel Dispatch (Aug 3, 2026)** - "Catastrophic Coldcard Bug"

---

## DocHex / Peter / Doc Search Results

**Finding:** Very limited podcast appearances for "DocHex" or "Peter" in the Bitcoin hardware wallet context within the Jamie corpus.

**Possible mentions:**
- Stephan Livera SLP101 (Aug 24, 2019) mentions "Peter, well, DocSachs on Twitter and NVK" in context of Libre hardware design
- The name may be referenced as "@DocHex" on Twitter/Nostr but rarely spoken aloud in podcasts
- May have been primarily a GitHub contributor rather than podcast guest

**Recommendation:**
- Check GitHub commits for libngu repository (if public)
- Search Twitter/Nostr for "@DocHex" or "@switck" mentions
- Look for yasmarang references on developer forums/mailing lists

---

## Outside Corpus - Potential Appearances to Check

These may exist but weren't indexed in Jamie (yet):

### YouTube/Video
- Bitcoin 2021 Miami conference talks
- BTC++ developer conferences
- Baltic Honeybadger appearances
- Adopting Bitcoin El Salvador

### Other Podcasts (may not be in corpus)
- What Bitcoin Did with Peter McCormack
- Bitcoin Fundamentals
- Bitcoin Rapid Fire
- Bitcoin Takeover
- Swan Signal

### Regional/Language
- Lunaticoin (Spanish) - Oct 2021 episode on "Is Coldcard Open Source?" could be very revealing
- German Bitcoin podcasts (Nodesignal, Münzweg) - several appearances

---

## Search Strategy Recommendations

For outside-corpus investigation:

1. **YouTube Search:**
- "NVK coldcard" + date filters (2020-2021)
- "Rodolfo Novak firmware 4"
- "NVK GPL license"

2. **Twitter/Nostr:**
- @nvk threads from Feb-April 2021
- @DocHex or @switck mentions
- yasmarang GitHub profile

3. **Reddit:**
- r/Bitcoin posts by NVK
- r/coldcard subreddit (if exists)
- Posts about firmware 4.0 release

4. **GitHub:**
- coldcard-firmware commits (March 2021)
- libngu repository (if public)
- Contributor: switck/yasmarang

---

**Report compiled:** 2026-08-04
**Total episodes found in Jamie corpus:** 40+
**Direct NVK interviews:** ~15
**Episodes mentioning NVK/Coldcard:** ~25


@Laser @. @Contra
1
uncleJim21 · 1h
nostr:npub1vjk0gp2l4qnte2uy2l3ya78m5ays4wc7wmd6k64gw5498g8tf49qtkd33q I lean toward malice at this point. Deeplink to "vulnerability" disclosure telling people to download still massively compromised firmware: https://www.pullthatupjamie.ai/app/share?clip=b91d3a30-163d-4b7b-9ffd-f1b3734c05e3_p310 ...
uncleJim21 · 2h
(5/5): ### NVK Direct Appearances 1. **[SLP62 - Rodolfo Novak - Keeping Bitcoin Cypherpunk](https://www.stephanlivera.com/episode/62/)** (March 27, 2019) - 🎧 [TRNG quote](https://pullthatupjamie...
uncleJim21 profile picture
Scan of possible NVK appearances:
# NVK Podcast Appearances Mapped (2018-2026)

## Direct NVK Interviews & Appearances

### 2026
- **June 20, 2026** - TFTC #760: The State Is Farming You with NVK
- **March 9, 2026** - Münzweg (German Bitcoin podcast) - Bitcoin Realtalk (mit Robin Linus)

### 2025
- **November 15, 2025** - Münzweg #203 Bitcoin ist vegetarisch
- **July 19, 2025** - Pleb UnderGround - Bitcoin Is Now Wallstreets Money Printer! (with Pierre Rochard)
- **July 9, 2025** - The Investor's Podcast BTC242: Bitcoin Core Vs. Knots w/ NVK
- **April 3, 2025** - Simply Bitcoin - $5.9T GIANT Launches NEW Bitcoin Retirement Product! (NVK guest)
- **May 22, 2025** - Nodesignal-Talk E231 - Specter DIY (mentions NVK)

### 2024
- **December 17, 2024** - The Robin Seyr Podcast - Why ALL ASSETS Will Go To 0 Against Bitcoin
- **November 6, 2024** - The Investor's Podcast BTC207: Bitcoin, AI, Nostr, and Hardware Manufacturing w/ NVK
- **September 4, 2024** - Ungovernable Misfits - Cold Storage Beef | The Confab 07: Zach Herbert (discusses NVK/reproducible builds)
- **August 21, 2024** - Stephan Livera SLP599 - Bitcoin Hardware Security Panel - NVK, Craig Raw, Rearden, Salvatoshi, AddBTC
- **June 28, 2024** - Rabbit Hole Recap #311: JULIAN ASSANGE FREE AT LAST (mentions Cold Card MK4 updates)
- **April 4, 2024** - Rabbit Hole Recap #299: GET ON THE BITCOIN TRAIN
- **February 8, 2024** - Rabbit Hole Recap #291: THE BANK RUNS CONTINUE (mentions NVK)
- **January 17, 2024** - The Investor's Podcast BTC165: Bitcoin's 2024 Technical Overview w/ NVK

### 2023
- **December 7, 2023** - Citadel Dispatch CD115: Nostr Adoption with Miljan (mentions NVK)
- **August 29, 2023** - Citadel Dispatch CD108: Bitcoin Dev Education and BTC++ (mentions NVK reproducible builds)
- **August 26, 2023** - Nodesignal-Talk E137 - Running a node is not enough (mentions NVK)
- **July 18, 2023** - Coin Stories with Natalie Brunell - How to Set Up Cold Storage with ColdCard (featuring BTC Sessions explaining NVK's product)
- **June 22, 2023** - Rabbit Hole Recap #258: You Can't Trust Prime Trust
- **April 22, 2023** - Bitcoin Magazine Podcast - Good Morning Bitcoin - KYC Is The Illicit Activity w/ Shinobi
- **January 12, 2023** - Rabbit Hole Recap #235: Party Rip at Bitcoin Park in Nashville (NVK present)

### 2022
- **November 27, 2022** - Ungovernable Misfits - Bitcoin monthly 0021 (mentions Trezor/hardware wallets)
- **October 7, 2022** - Rabbit Hole Recap #221: KYC/AML is Putting People in Danger (Cold Card MK4 v5.0.7)
- **October 4, 2022** - **Stephan Livera SLP418 - NVK Tapsigner: Bitcoin Hardware for the Masses?** ⭐
- **August 1, 2022** - Conan O'Brien Needs A Friend - B.J. Novak (unrelated)
- **July 18, 2022** - Bitcoin Magazine Podcast - Cold Card Wallets w/NVK ⭐
- **May 2, 2022** - Stephan Livera SLP372 - Sergej Kotliar (mentions NVK terminology)
- **April 26, 2022** - Stephan Livera SLP368 - BitcoinQNA - Bitcoin Seed Tool (mentions NVK/Cold Card)
- **April 1, 2022** - TFTC Rabbit Hole Recap #193: The unjust laws are on the rise
- **March 16, 2022** - **TFTC #315: The return of NVK** ⭐
- **February 23, 2022** - **The Investor's Podcast BTC066: Creating Bitcoin Products and Infrastructure w/ NVK** ⭐
- **February 4, 2022** - Stephan Livera SLP346 - Nicolas Burtey (mentions Cold Card/NVK)
- **January 30, 2022** - **Stephan Livera SLP344 - NVK - Coldcard Mk4, Tapsigner, Satscard** ⭐

### 2021
- **November 24, 2021** - This Week in Startups E1332 - Turner Novak (unrelated name match)
- **November 16, 2021** - Once Bitten! #210 - @BTCsessions (discusses hardware wallets)
- **November 12, 2021** - TFTC Rabbit Hole Recap: Bitcoin Week of 2021.11.08 (mentions NVK's BitcoinBlackFriday.org)
- **October 10, 2021** - **Lunaticoin L123.B - Is Coldcard Open Source? con Rodolfo Novak** ⭐ (Spanish)
- **September 16, 2021** - TFTC Rabbit Hole Recap: Week of 2021.09.13
- **September 7, 2021** - Citadel Dispatch CD37: building software from source code (mentions NVK's Bitcoinbinary.org)
- **April 1, 2021** - TFTC Rabbit Hole Recap (firmware 4.0.1 vulnerability)
- **March 29, 2021** - Rabbit Hole Recap - Week of 2021.03.29 (firmware 4.0.1 announcement) ⭐
- **February 10, 2021** - **Citadel Dispatch CD8: Corporate FOMO, BIPs, and Taproot with @futurepaul and @nvk** ⭐
- **January 21, 2021** - Bitcoin Magazine Podcast - How to Store Your Bitcoin w/ Douglas Bakkum (mentions RNG, for comparison)
1
uncleJim21 · 2h
### 2020 - **November 4, 2020** - TFTC #206: Ryan Gentry - **October 29, 2020** - TFTC Rabbit Hole Recap: Week of 2020.10.26 - **October 22, 2020** - **Bitcoin Magazine Podcast - Rodolfo Novak: Why Corporate Bitcoin Treasuries Help Us All** ⭐ - **November 24, 2020** - Bitcoin Magazine Podcast - Se...
uncleJim21 · 2h
(4/N): **From TFTC Podcast (April 1, 2021):** > "Not a hack, but they had a vulnerability that was self-discovered. So they have a new firmware version, 4.0.1, or is it 0.01? 4.0.1. Yeah. You messed u...
uncleJim21 profile picture
(5/5):
### NVK Direct Appearances
1. **[SLP62 - Rodolfo Novak - Keeping Bitcoin Cypherpunk](https://www.stephanlivera.com/episode/62/)** (March 27, 2019)
- 🎧 [TRNG quote](https://pullthatupjamie.ai/share?clip=fc87b6c9-7cf7-a7a3-3ceb-816b809c8a03_p137)

2. **[SLP418 - NVK Tapsigner: Bitcoin Hardware for the Masses?](https://www.stephanlivera.com/episode/418/)** (October 4, 2022)
- 🎧 [Libngu scrutiny quote](https://pullthatupjamie.ai/share?clip=18f258a1-cf98-4171-ab30-7954f30ea982_p99)

### Community Analysis
3. **[Simply Bitcoin EP 1561 - NEW INFORMATION: Is it too dangerous to hold all your own Bitcoin???](https://podcasters.spotify.com/pod/show/simplybitcoin/episodes/NEW-INFORMATION-Is-it-too-dangerous-to-hold-all-your-own-Bitcoin-----EP-1561-e3mtv62)** (August 3, 2026)
- 🎧 [License change timeline](https://pullthatupjamie.ai/share?clip=0e0dcaee-4a8d-4a4a-9f57-056504769338_p132)

4. **UNGOVERNABLE - Unpacking the Coldcard Exploit | FREEDOM TECH FRIDAY 50** (August 1, 2026)
- 🎧 [LibNGU library origins](https://pullthatupjamie.ai/share?clip=483953a7-1e90-42b8-88a5-9a1213d37f3f-c88dfb2d-f3b6-4bea-bb5f-df1360822233_p58)
- 🎧 [Custom license discussion](https://pullthatupjamie.ai/share?clip=483953a7-1e90-42b8-88a5-9a1213d37f3f-c88dfb2d-f3b6-4bea-bb5f-df1360822233_p70)
- 🎧 [Entropy implementation bug](https://pullthatupjamie.ai/share?clip=483953a7-1e90-42b8-88a5-9a1213d37f3f-c88dfb2d-f3b6-4bea-bb5f-df1360822233_p61)

5. **Citadel Dispatch - CATASTROPHIC COLDCARD BUG** (August 3, 2026)

6. **Rabbit Hole Recap - Week of 2021.03.29** (March 29, 2021)
- Coverage of firmware 4.0.1 "self-discovered vulnerability"

7. **Coin Stories with Natalie Brunell - How to Set Up Cold Storage with ColdCard** (July 18, 2023)
- Dice roll feature explanation

---

## All Sources

All quotes sourced from **pullthatupjamie.ai** podcast index covering 120k+ hours of Bitcoin podcast content. Dates range from 2018-2026.

**Jamie API:** https://pullthatupjamie-nsh57.ondigitalocean.app

---

## Conclusion

The evidence suggests:

1. **The vulnerability was introduced intentionally or negligently** in the same massive commit that changed the license from GPL to a proprietary "Bitcoin only" license
2. **Marketing emphasized hardware RNG security** while the actual implementation failed to use it properly
3. **An early patch (4.0.1) may have been a partial fix** but the full scope was not disclosed
4. **The proprietary license likely reduced scrutiny** from the open source community
5. **Claims about "scrutiny" and not "YOLO-ing" code** were contradicted by the actual development practices

Whether this was malicious, incompetent, or a combination is unclear. What is clear is that NVK's public statements about Cold Card's security and development practices do not match the reality of what happened with firmware 4.0.

---

**Report compiled:** 2026-08-04
**Research by:** Jones (OpenClaw agent)
**Data source:** Jamie (pullthatupjamie.ai) podcast index
**Interactive version:** https://pullthatupjamie.ai


@. @Laser @Contra
1
uncleJim21 · 2h
Scan of possible NVK appearances: # NVK Podcast Appearances Mapped (2018-2026) ## Direct NVK Interviews & Appearances ### 2026 - **June 20, 2026** - TFTC #760: The State Is Farming You with NVK - **March 9, 2026** - Münzweg (German Bitcoin podcast) - Bitcoin Realtalk (mit Robin Linus) ### 2025 -...
uncleJim21 · 2h
(3/N): **From Bitcoin Magazine Podcast (January 21, 2021) - Douglas Bakkum on RNG (for comparison):** > "We have two random number generators on two different chips inside the device. We also use some...
uncleJim21 profile picture
(4/N): **From TFTC Podcast (April 1, 2021):**
> "Not a hack, but they had a vulnerability that was self-discovered. So they have a new firmware version, 4.0.1, or is it 0.01? 4.0.1. Yeah. You messed up."

**Analysis:** Shortly after firmware 4.0 was released, a "self-discovered vulnerability" was patched in 4.0.1, but the details were kept secret "for the sake of users." This may have been an early discovery of the RNG issue, but it was downplayed and never fully disclosed until the community discovered it independently in August 2026.

---

### 5. Dice Roll Feature as Security Theater?

**From Coin Stories with Natalie Brunell (July 18, 2023) - BTC Sessions explaining Cold Card:**
> "If you don't trust NVK and CoinKite, that they're really generating numbers randomly in this device and that they've injected something, even though you can audit what the code is doing. **If you don't trust the random number generator, you can actually roll dice and add more randomness to the creation of your 24 words.** Wow. Yeah, that's probably too technical and over my head. So we'll just do the 24 word defaults."

**Analysis:** Cold Card marketed a dice-roll feature for users who didn't trust the internal RNG. In hindsight, this feature may have served as security theater - acknowledging RNG trust issues while the default path used a fundamentally broken implementation.

---

### 6. Reproducible Builds & Open Source Claims

**From Citadel Dispatch (September 7, 2021):**
> "So the main topic of the conversation today is building our software from source. Recently, NVK, who has been on the show many times, **launched a new project, Bitcoinbinary.org, to basically try and normalize the process of verifying that source code matches the binaries that people are installing**, the actual install files that people install."

**From Ungovernable Misfits (September 4, 2024) - Zach Herbert discussing reproducible builds:**
> "And then we make sure that we give them instructions to get it to match or update our process. And I think why a lot of people don't like them is because you get called out for it if it doesn't, if it doesn't match, if it's not reproducible. **And you can imagine like MVK getting pretty pissed off that, you know, they're saying he failed the reproducibility and he's saying, well, they just didn't follow my instructions.** I think the humble approach is, well, then our instructions weren't good enough, right? Or there was something wrong with our instructions."

**From Citadel Dispatch (April 16, 2025) - Rob Hamilton referencing NVK's license:**
> "And for us, we put a lot of time and effort into it. And just to be frank, for today, if we did open source it, it'd probably be closer to an MIT CC license. **The NVK the NVK license.** Yeah. **The NVK license.**"

**Analysis:** NVK promoted reproducible builds and code verification through Bitcoinbinary.org, yet Cold Card's own source-available (not open source) license and reproducibility issues made independent verification difficult. The "NVK license" became a reference point for other projects considering similar restrictions.

---

### 7. Recent Community Response (August 2026)

**From Citadel Dispatch - "CATASTROPHIC COLDCARD BUG" (August 3, 2026):**
> "**NVK rightfully deserves a lot of shit for his license change.**"

**Analysis:** The Bitcoin community's response has been strongly critical, with many pointing to the license change as enabling reduced scrutiny that may have allowed the RNG bug to persist undetected for years.

---

## Red Flags in Hindsight

1. **Massive single commit** (120 files) changed both licensing AND seed generation
2. **Custom "Bitcoin only" license** reduced community participation and review
3. **Anonymous library author** (@switck/yasmarang) with no known affiliation to Coinkite
4. **Quick 4.0.1 patch** with undisclosed vulnerability details
5. **Years of delay** before vulnerability was publicly disclosed by community researchers
6. **Marketing emphasis on TRNG security** while actual implementation used weak PRNG
7. **Dice roll feature** acknowledged RNG trust issues but didn't fix the default path

---

## Search Terms Used

High-priority terms searched:
- libngu / LibNgU
- switck / @switck / yasmarang
- ngu.random / ngu.random.bytes
- hardware RNG / true RNG / TRNG
- seed generation + firmware / rewrite
- entropy + Coldcard
- GPL + remove / replace
- firmware 4.0 / v4.0.0
- reproducible builds
- Trezor crypto / Trezor-derived

---

## Key Episodes Referenced (with Links)
1
uncleJim21 · 2h
(5/5): ### NVK Direct Appearances 1. **[SLP62 - Rodolfo Novak - Keeping Bitcoin Cypherpunk](https://www.stephanlivera.com/episode/62/)** (March 27, 2019) - 🎧 [TRNG quote](https://pullthatupjamie.ai/share?clip=fc87b6c9-7cf7-a7a3-3ceb-816b809c8a03_p137) 2. **[SLP418 - NVK Tapsigner: Bitcoin ...
uncleJim21 · 2h
(2/N): ## Key Findings ### 1. The March 2021 License Change & Code Rewrite **From Simply Bitcoin (August 3, 2026):** > "On January 8, 2021, ColdCard firmware 3.2.1 formally announced license change ...
uncleJim21 profile picture
(3/N):
**From Bitcoin Magazine Podcast (January 21, 2021) - Douglas Bakkum on RNG (for comparison):**
> "We have two random number generators on two different chips inside the device. We also use some randomness from the computer that's fed into that. We also use some randomness during the factory installation, a random number set, and also randomness from the user itself, a hash of their password. And so we cryptographically combine all that in order to generate your wallet."

**Analysis:** NVK claimed in 2019 that the secure element's TRNG was second only to dice for randomness. However, firmware 4.0 (March 2021) apparently failed to properly use the TRNG, instead relying on a weak PRNG from the libngu library.

---

### 3. NVK's Claims About Code Quality & Security Scrutiny

**From Stephan Livera Podcast SLP418 - "NVK Tapsigner: Bitcoin Hardware for the Masses?" (October 4, 2022) - NVK speaking about libngu:**
> "So we're working on adding that. I think we just made a PR to libngu, which is like glue for the actual like crypto library from core, libsec. So we're sort of like just, you know, progressing because **for us, it's a little bit different than other hardware wallets. We don't sort of YOLO transactions. You know, transactions on cold card, they are sanity checked and they have like a little bit more scrutiny before the device signs it.**"

**🎧 [Listen to clip](https://pullthatupjamie.ai/share?clip=18f258a1-cf98-4171-ab30-7954f30ea982_p99)** | **[Audio](https://audio.pullthatupjamie.ai/759235/18f258a1-cf98-4171-ab30-7954f30ea982.mp3)**

**From UNGOVERNABLE Podcast (August 1, 2026):**
> "that's that's where this bug was introduced, where it went from from calling the old the old source of entropy to calling something, within this library, within the LibNGU library. And, and whatever however it was wired up behind the scenes there, **it did not correctly, incorporate the entropy.** So I feel like there's I don't wanna say that like, decisively say that the decision to abandon, you know, free and open source software caused this. I don't think that's, like, a fair characterization."

**🎧 [Listen to clip](https://pullthatupjamie.ai/share?clip=483953a7-1e90-42b8-88a5-9a1213d37f3f-c88dfb2d-f3b6-4bea-bb5f-df1360822233_p61)** | **[Audio](https://audio.pullthatupjamie.ai/352598/483953a7-1e90-42b8-88a5-9a1213d37f3f-c88dfb2d-f3b6-4bea-bb5f-df1360822233.mp3)**

**Analysis:** NVK emphasized "scrutiny" and not "YOLO-ing" code changes. Yet the March 2021 firmware 4.0 release introduced a critical entropy flaw in a massive 120-file commit that changed both licensing and seed generation simultaneously.

---

### 4. The Quiet Firmware 4.0.1 "Fix"

**From Rabbit Hole Recap (Week of March 29, 2021):**
> "Not a hack, but they had a vulnerability that was self-discovered. So they have a new firmware version, 4.0.1, or is it 0.01? 4.0.1. Yeah. You messed up... **And you're only vulnerable if you had already upgraded to 4.0.0, which was their big upgrade. If it's not, then you're not vulnerable. I have no idea what this vulnerability is. NVK wouldn't tell me what it was for the sake of the users because he's afraid I was going to steal all your Bitcoin.** But yeah, upgrade."
2
uncleJim21 · 2h
(4/N): **From TFTC Podcast (April 1, 2021):** > "Not a hack, but they had a vulnerability that was self-discovered. So they have a new firmware version, 4.0.1, or is it 0.01? 4.0.1. Yeah. You messed up." **Analysis:** Shortly after firmware 4.0 was released, a "self-discovered vulnerability" was pa...
McCoy · 1h
wtf: "**From Rabbit Hole Recap (Week of March 29, 2021):** > "Not a hack, but they had a vulnerability that was self-discovered. So they have a new firmware version, 4.0.1, or is it 0.01? 4.0.1. Yeah. You messed up... **And you're only vulnerable if you had already upgraded to 4.0.0, which was their...
uncleJim21 · 2h
(1/N): Here's my first big deep dive it wasn't perfect but it has some interesting tidbits. Part I found most interesting was the fact that the RHR quote implies in March 2021 they were actively probi...
uncleJim21 profile picture
(2/N): ## Key Findings

### 1. The March 2021 License Change & Code Rewrite

**From Simply Bitcoin (August 3, 2026):**
> "On January 8, 2021, ColdCard firmware 3.2.1 formally announced license change from GPL to MIT CC on files which the GPL doesn't apply. CC is the common clause license addendum which is sourced available instead of completely Open source. On March 1, 2021, the first pass with Lib Ngu commit Remove the GPL Trezor derived crypto libraries and replace them with lib ngu. **That same 120 file commit change seed generation.** Lib ngu was licensed with the novel license for Bitcoin only license."

**🎧 [Listen to clip](https://pullthatupjamie.ai/share?clip=0e0dcaee-4a8d-4a4a-9f57-056504769338_p132)** | **[Audio](https://audio.pullthatupjamie.ai/4506555/0e0dcaee-4a8d-4a4a-9f57-056504769338.mp3)**

**From UNGOVERNABLE Podcast - "Unpacking the Coldcard Exploit" (August 1, 2026):**
> "Now that wasn't the only stated purpose. They were also adding in, like, the the new libsec stuff, and and they were working on that for a long time and and so on. But they ended up changing the code the the license of the code to what's called source available instead of open source, and they ended up using a new library. I don't know if it was written by Coldcard or if it was someone else because I don't think the guy who wrote it is is affiliated with the company, but it's called LibNGU."

**🎧 [Listen to clip](https://pullthatupjamie.ai/share?clip=483953a7-1e90-42b8-88a5-9a1213d37f3f-c88dfb2d-f3b6-4bea-bb5f-df1360822233_p58)** | **[Audio](https://audio.pullthatupjamie.ai/352598/483953a7-1e90-42b8-88a5-9a1213d37f3f-c88dfb2d-f3b6-4bea-bb5f-df1360822233.mp3)**

**From UNGOVERNABLE Podcast (August 1, 2026):**
> "And they released like, the this code change that caused the, you know, the Entropy bug in early twenty twenty one was a direct result of doing this major change to the code base. And it even said in the release notes, like, something along the lines of, like, **the last GPL code was removed.** And so they were able to fully and and officially swap the licenses. And this LibNGU library where it could have been, like, a great library that the whole space wanted to build on, but **they made up a a a software license, something like the something Bitcoin license. Like, it was just a made up software license. It's not it wasn't an open source license.**"

**🎧 [Listen to clip](https://pullthatupjamie.ai/share?clip=483953a7-1e90-42b8-88a5-9a1213d37f3f-c88dfb2d-f3b6-4bea-bb5f-df1360822233_p70)** | **[Audio](https://audio.pullthatupjamie.ai/352598/483953a7-1e90-42b8-88a5-9a1213d37f3f-c88dfb2d-f3b6-4bea-bb5f-df1360822233.mp3)**

**Analysis:** The vulnerability was introduced in the same commit that removed GPL code and implemented a custom, non-standard license. This proprietary license may have reduced community scrutiny of the code changes.

---

### 2. NVK's Claims About Hardware RNG Security

**From Stephan Livera Podcast SLP62 - "Rodolfo Novak - Keeping Bitcoin Cypherpunk" (March 27, 2019) - NVK speaking:**
> "And another nice thing, too, that you get with a secure element is a true random number generator, TRNG. So that's a very powerful random number generator. **Better than that, only the dice.** Yeah, right. Yeah."

**🎧 [Listen to clip](https://pullthatupjamie.ai/share?clip=fc87b6c9-7cf7-a7a3-3ceb-816b809c8a03_p137)** | **[Audio](https://audio.pullthatupjamie.ai/759235/fc87b6c9-7cf7-a7a3-3ceb-816b809c8a03.mp3)**

**From Stephan Livera Podcast SLP103 (August 28, 2019) - Charles Guillemet from Ledger explaining TRNGs:**
> "Hardware wallets are made with IC, with integrated circuit, and inside the circuit, there is often TRNG, which stands for True Random Number Generator. And this is a specific part of electronics. There are different kinds of design. Often, this is the three oscillators which runs in parallel and they are sampled at a very specific timing. And this very tiny source of entropy is amplified with different means."

**🎧 [Full Episode](https://www.stephanlivera.com/episode/103/)**
1
uncleJim21 · 2h
(3/N): **From Bitcoin Magazine Podcast (January 21, 2021) - Douglas Bakkum on RNG (for comparison):** > "We have two random number generators on two different chips inside the device. We also use some randomness from the computer that's fed into that. We also use some randomness during the factory i...
uncleJim21 · 2h
You can query to your heart's content here on our web app : https://www.pullthatupjamie.ai/app?view=agent or use our agent bindings to use it direclty with your clanker: https://www.pullthatupjamie.a...
uncleJim21 profile picture
(1/N): Here's my first big deep dive it wasn't perfect but it has some interesting tidbits. Part I found most interesting was the fact that the RHR quote implies in March 2021 they were actively probing security. I will do more:
# NVK Investigation Report: Statements on Cold Card Security (2018-2026)

**Research Focus:** Rodolfo Novak (NVK) statements regarding Cold Card security, entropy, seed generation, and the March 2021 firmware changes that introduced the weak RNG vulnerability.

**Context:** In August 2026, security researchers discovered that Cold Card firmware 4.0+ contained a critically weak random number generator that made wallets vulnerable to attacks. This report compiles NVK's public statements about security, the code changes, and entropy to identify potentially misleading claims.

---

## Executive Summary

### The Timeline
- **January 8, 2021**: ColdCard firmware 3.2.1 announced license change from GPL to MIT + Commons Clause
- **March 1, 2021**: Firmware 4.0 released with **libngu library** replacing GPL Trezor-derived crypto libraries
- **Same commit (120 files)**: Changed seed generation implementation
- **Shortly after**: Firmware 4.0.1 released to fix a "self-discovered vulnerability"
- **August 2026**: Community discovers the RNG vulnerability was far more severe than disclosed

### The Core Issue
The libngu library, created by an anonymous/pseudonymous developer (@switck/yasmarang), used a weak pseudo-random number generator (PRNG) instead of properly accessing the hardware's true random number generator (TRNG). This was introduced in the same commit that removed GPL code and changed the license to a custom "Bitcoin only" license.

---
1
uncleJim21 · 2h
(2/N): ## Key Findings ### 1. The March 2021 License Change & Code Rewrite **From Simply Bitcoin (August 3, 2026):** > "On January 8, 2021, ColdCard firmware 3.2.1 formally announced license change from GPL to MIT CC on files which the GPL doesn't apply. CC is the common clause license addendum wh...