The release notes also repeat the thing that keeps getting lost in these threads. Installing it does not make an existing seed safe. If the seed was generated on affected firmware between 2021 and July this year, it is the same seed after the update as before it, and the fix is a new seed on fixed firmware plus moving the coins.

Nothing can make an existing seed safe.
A seed phrase can't be changed, and ColdCard seeds were guessable.
Changing a seedphrase creates a new wallet and it does not do anything for the existing wallet and seedphrase.
Does the above highlight help?
My bad! So we agree!
I absolutely disagree with the idea of keeping the Coldcard, though. If you haven't lost any funds, I'd consider moving them to a reputable signing device like SeedSigner, and throw that thing to the trash.
Let me make it clear that I don't recommend that anyone other than highly technical people do anything with any of Coinkite's products. I consider them unsafe. Yes, it's 'playing with fire', but at the same time, so is playing with ANY hardware device at this point in time.
Nope.
Just because Cold Card showed a very high level of vulnerability, arrogance and stupidness, that does not put all hardware wallets into the same category.
Frequently I find relativistic arguments that put similar categories of items in the same group to be close to retarded. It is like seeing some politicians as corrupt and evil and then also seeing that a variety of other politicians showing similar corrupt and evil attributes, and then proclaiming that all politicians are the same, when they are not. Some are more corrupt and evil than others, and some are not corrupt and/or evil.
Similar arguments can be made in regards to hardware wallets. Some have greater vulnerabilities than others, and some even have corrupt and/or evil players, such as the coinkite team has shown themselves to be (at least NVK and the CTO and maybe some others on the team who were in a position of knowing about the various RNG vulnerabilities and not doing anything about it).
Indeed, playing with Bitcoin itself is now and always has been 'playing with fire.'
That is a bit much @tvbcof. You must have difficulties viewing some of the nuances of the world. Everything in the world is not black or white.
SeedSigner has the distinct advantage of letting the user have more control of the supply chain. The potential in-built weakness (at the 'pi' or processor level) are unlikely to be narrowly targeted toward subverting crypto-currency except insofar as they may exist to attack cryptography generally. I've not researched the SeedSigner project in detail, but I would assume that they now (or will be soon) taking pains to deal with the entropy issue, and there will always be the issues associated with cold attacks on storage of secrets for any hardware device.
I would mention again that I hope people do NOT throw these things in the trash. They could be useful for further analysis in some sort of an attempt to further understand this fairly devastating attack on the Bitcoin community at large.
I don't have any arguments (enlightened or otherwise) regarding these points.
I am not a lawyer, but according to the official story (which studiously avoids any 'conspiracy theories') I'm not really sure I see a crime here. Or at least not one which anyone is likely to get more than a slap on the wrist for. We have:
- a simple mistake from some device maker/seller,
- someone(s) found they could obtain shared control of keys represented in a public blockchain and availed themselves of the discovery.
Well under the law there are criminal charges that are brought by the state, and there are civil charges that can be brought by other individuals and/or by the state.
If we presume that you are ONLY referring to criminal law (especially since you used the term "crime," then whether or not there is a violation of a statute or some common law standard, we have to look at the crime that we are alleging to have had taken place to see its the evidence that would be argued to show that a violation that took place - perhaps something like fraud or maybe some other crime could be alleged? Let's just go through the elements of fraud to figure out how such a crime could be prosecuted:
1) misrepresentation of material facts
CC marketed itself as the gold standard and seems to have had misrepresented how its random number generation was taking place.
2) knowledge of their misrepresentations
Even if coinkite might not have had know about the flaw in the software, after several complaints of loss of funds they should have had become aware at some point in time prior to July 30, 2026. there were a lot of customer complaints from 2021 and then also some specific report in May 2025.. so then there was reckless disregard for the truth. The standard is not negligence as you suggested @tvbcof
3) intent to deceive
This might be a bit of a harder hurdle if we cannot find that Coinkite personally profited. Even if it were to be argued that a "retirement plan" was in place, it would likely need to be shown that there was an intent to steal the funds by key principles of the company, otherwise maybe if intention was shown to be by key principles, then the individuals might be criminally charged rather than the company.
4) reasonable reliance of the victims on the false statements
This one can probably be easily proved in that many clients relied on the supposed good coinkite security features and the clients took adequate and sufficient measures to secure their coins and to believe that their coins were secure.
5) damage or economic loss
the damage and economic losses were extensive.
So, yeah, 3 is probably the hardest of the elements to show.
At this point there is no provable evidence that either Coinkite deliberately sabotaged their hardware with the intent to defraud, or that there was any collusion between Coinkite and the various parties who picked up the dropped private keys.
I doubt that the situation is as much of a slam dunk as you are proclaiming it to be, even though prosecutors would have some discretion in regards to whether they believe that they have enough evidence to prosecute.
Indeed, it's kind of a weird sin-like thing to even think that way here in 2026.
I personally think it likely that both deliberate sabotage and collusion to engineer a lifting of BTC probably did occur, but that means nothing. Even if it did, it doesn't seem to me like something which would get anyone into serious trouble...at least in a formal court of law.
If there is evidence of deliberate sabotage and collusion to engineer a lifting of the BTC, then that would go towards the 3rd element, so yeah, it still might not be clear if the evidence is strong enough to prosecute.
Actually, foreknowledge of the hack would possibly yield greater monetary benefit in terms of various kinds of 'insider trading', or in terms of getting compensated (or just a pat on the head for doing God's work) by entities who benefited (e.g., coin custodians who won keys as the whole system shifted away from faith in self-custody), but nobody gets in trouble for that kind of stuff these days.
Sure, insider trading is another kind of a crime, and of course, it would have different elements. I have not been hearing too much about any claims of insider trading of Coinkite and especially since insider trading rules seem to apply to public companies rather than private companies. I am pretty sure that Coinkite is a private company.