Samson Mow Shares 5 Urgent Steps for Coldcard Users Facing Losses
Key Takeaways
Samson Mow urged victims to document every detail related to affected wallets.Users should report losses to police and cybercrime authorities immediately.Mow warned victims to ignore anyone promising to recover stolen bitcoin.
Samson Mow Outlines Immediate Actions for Affected Users
JAN3 CEO Samson Mow, who leads a Bitcoin technology company focused on accelerating hyperbitcoinization, posted five practical recommendations on X for users affected by the Coldcard random number generator (RNG) vulnerability on Aug. 1. His guidance emphasized preserving evidence, reporting thefts, watching coordinated fund-tracking efforts, and avoiding recovery scams as the incident raised broader concerns about self-custody security.
Mow wrote:
“The COLDCARD RNG vulnerability may be worse than an exchange hack. It hit at the core of sovereign bitcoin holders – it struck those who did all the research, understood why self-custody is important, and didn’t keep coins on exchanges.”
His first recommendation urged victims to document everything they know, including wallet addresses, dates, firmware versions, transaction details, and any other information that could help create a detailed record of the incident.
Mow also encouraged victims to file a police report because it would create an official record. He recommended contacting cybercrime units, national reporting portals such as the FBI’s Internet Crime Complaint Center, or specialized cryptocurrency crime task forces when available. His third recommendation instructed affected users to watch for coordinated efforts to track movements of stolen funds.
Preserve Evidence and Ignore Recovery Scams
Another key recommendation focused on preserving the affected Coldcard device and seed phrase instead of destroying them after the theft. Mow advised victims to retain the device, seed phrase, and PIN, explaining that they might need to prove ownership if stolen bitcoin eventually reaches an exchange and is frozen.
He also delivered his strongest warning against recovery scammers, cautioning victims never to share personal details or seed phrases, or send money to individuals claiming they can retrieve stolen cryptocurrency. The FBI has repeatedly warned that fraudsters often target victims of previous cryptocurrency thefts by offering fake recovery services that demand upfront payments or sensitive wallet information.
Security Lessons Extend Beyond One Hardware Wallet
Although Mow expressed sympathy for affected users, he also argued that the incident reinforces the importance of reducing single points of failure in bitcoin self-custody by using hardware from multiple vendors in a multisignature setup instead of relying on a single manufacturer.
Mow wrote:
“Self-custody is hard. If you advocate for self-custody, you should also be telling people to use a multi-vendor multisig setup. I’ve been saying this for years. Self-custody only works if you do it in a way that minimizes a single point of failure. Don’t trust any single vendor for hardware. Assume everyone is your adversary.”
He acknowledged that self-custody remains challenging for many users and urged the Bitcoin industry to become less critical of people choosing custodians, exchange-traded funds, or Bitcoin treasury companies. Mow maintained that there is no single correct way to hold bitcoin because every custody method carries tradeoffs.
Mow also urged affected users not to take rash action and to speak with someone if they needed support. He noted that many bitcoin holders have lost coins for different reasons and emphasized that individuals can rebuild after a loss.
Coinkite Response and Fallout Continue
Coinkite, the Toronto-based Bitcoin security hardware company behind Coldcard wallets, issued a security advisory urging users of affected devices to update to fixed firmware before generating new seeds and to migrate funds if their seed was created on vulnerable versions. The advisory also warns that firmware updates do not repair previously generated seeds and recommends verifying backups and running test transactions before moving funds.
Earlier reporting examined which Coldcard wallets appear most likely to face risk, how vulnerable seeds were generated, and the conditions that exposed affected users. Since then, the fallout has expanded. Affected users are considering potential legal action against Coinkite, while the attacker has received an unsolicited onchain message offering bitcoin laundering services.
