{
  "schema": "https://cc-vuln.org/schemas/source-register-v1.json",
  "incident": "coldcard-entropy-2026",
  "archive_last_capture": "2026-08-15T14:23:50Z",
  "interpretation": {
    "publication_time": "When the source says it published, when established.",
    "capture_time": "When this project observed and stored a source state.",
    "revision_window": "The bounded interval between the last old state and first new state held.",
    "source_content": "Relevant text served by the publisher changed. This does not verify the new claim.",
    "capture_noise": "The detected difference came from dynamic chrome or collection mechanics.",
    "unreviewed": "The difference has not yet been reviewed for capture noise.",
    "gone": "The origin stopped serving this source. It is no longer polled, and the held capture is the only remaining copy known to this archive."
  },
  "coverage": {
    "denominators": {
      "web_sources": 447,
      "x_posts": 930,
      "nostr_posts": 2
    },
    "web_sources_by_kind": {
      "aggregator": 3,
      "analysis": 7,
      "chain-monitor": 10,
      "community-discussion": 290,
      "custody-guidance": 2,
      "government-legal": 2,
      "government-record": 1,
      "independent-analysis": 16,
      "independent-technical-analysis": 2,
      "org-statement": 1,
      "primary-data": 10,
      "primary-method": 1,
      "repo-commit": 2,
      "repo-file": 5,
      "repo-patch": 17,
      "repo-pr": 21,
      "reporting": 24,
      "research": 4,
      "vendor-advisory": 3,
      "vendor-docs": 3,
      "vendor-index": 4,
      "vendor-legal": 1,
      "vendor-releases": 1,
      "vendor-response": 5,
      "vendor-statement": 7,
      "victim-account": 5
    },
    "web_sources_by_organisation": {
      "3z": 2,
      "afilini": 1,
      "Álvaro P.": 1,
      "Android Developers": 1,
      "BitBox": 1,
      "Bitcoin Magazine": 4,
      "Bitcoin Optech": 1,
      "Bitcoin.com News": 2,
      "Bitcoin.org": 1,
      "bitcoin++ Insider Edition": 1,
      "BitcoinTalk": 12,
      "BleepingComputer": 1,
      "Block": 2,
      "Blockchain Unmasked": 1,
      "Blockstream": 1,
      "Bloomberg": 1,
      "Casa": 3,
      "Chainabuse": 7,
      "ChainCatcher": 1,
      "Checkonchain": 1,
      "Citadel21": 1,
      "CKTRIPWIRE": 2,
      "Coin360": 1,
      "CoinDesk": 3,
      "Coinkite": 31,
      "community tracker": 8,
      "crypto.news": 1,
      "Debian": 1,
      "Delving Bitcoin": 1,
      "DK27ss": 1,
      "dylanleclair1": 1,
      "Foundation": 1,
      "Hacker News": 2,
      "Karma-X": 1,
      "Kelbie": 1,
      "KeychainX": 1,
      "Ledger": 3,
      "Luke Childs": 1,
      "MARA": 2,
      "mempool.space Research": 1,
      "Milk Sad research team": 1,
      "NCFA Canada": 1,
      "NewsBTC": 1,
      "Nick Farrow": 1,
      "NIST National Vulnerability Database": 1,
      "nobuxpt": 1,
      "nvk.wtf": 3,
      "Ontario e-Laws": 2,
      "OpenSats": 1,
      "Orange Surf": 1,
      "r/Bitcoin": 4,
      "r/coldcard": 1,
      "r/ledgerwallet": 1,
      "reddit": 206,
      "SamSamskies": 1,
      "SatSigner": 1,
      "SeedSigner": 1,
      "Sparrow": 1,
      "Stacker News": 74,
      "Stoltmann Law": 1,
      "switck": 19,
      "TFTC": 1,
      "The Block": 1,
      "The Hacker News": 1,
      "The Rage": 1,
      "Trezor": 1,
      "Unchained": 1,
      "Unciphered": 1,
      "unspecified": 5,
      "Web3 is Going Just Great": 1,
      "Wizardsardine": 2
    },
    "social_posts_by_platform": {
      "nostr": 2,
      "x": 930
    },
    "social_posts_by_organisation": {
      "AnchorWatch": 16,
      "Bitcoin News": 6,
      "Bitcoin Policy Institute": 1,
      "Bitcoin Security Consortium": 1,
      "Block": 6,
      "Blockchain Commons": 1,
      "Blockchain Unmasked": 1,
      "BTCPay Server": 2,
      "Bull Bitcoin": 2,
      "Casa": 9,
      "Coinkite": 19,
      "Cointelegraph": 1,
      "ColdHodl": 1,
      "Foundation": 5,
      "Foundation Devices": 7,
      "FutureBit": 1,
      "Galaxy": 1,
      "Galaxy Research": 24,
      "HardBlock": 1,
      "HRF": 1,
      "Kraken": 1,
      "Ledger": 2,
      "Liana Wallet": 1,
      "MARA": 2,
      "MARA Foundation": 1,
      "nostr": 2,
      "Nunchuk": 9,
      "Onramp Bitcoin": 1,
      "OpenSats": 3,
      "Satochip": 1,
      "Strike": 2,
      "TFTC": 2,
      "The Bitcoin Layer": 1,
      "The Block": 1,
      "Trust Wallet": 1,
      "Unchained": 16,
      "unspecified": 779,
      "Wizardsardine": 1
    },
    "web_sources_by_current_poll_state": {
      "guard-miss": 2,
      "ok": 290,
      "skipped": 126,
      "unreachable": 29
    },
    "web_sources_by_capture_count": {
      "multiple": 281,
      "one": 165,
      "zero": 1
    },
    "publication_date_range": {
      "known_items": 1098,
      "earliest": "2008-05-13",
      "latest": "2026-08-15"
    },
    "capture_date_range": {
      "first": "2026-07-31T01:56:33Z",
      "last": "2026-08-15T14:23:50Z",
      "snapshots": 2244
    }
  },
  "web_sources": [
    {
      "id": "coinkite-backgrounder",
      "title": "Entropy technical backgrounder",
      "url": "https://blog.coinkite.com/entropy-technical-backgrounder/",
      "organisation": "Coinkite",
      "kind": "vendor-advisory",
      "role": "Vendor advisory",
      "publication_time": "2026-07-30",
      "note": "Publisher-dated 30 July. Revised to add Mk4/Q/Mk5 scope and later the Mk3 4.2.0 fix; exact revision times are unresolved.",
      "gone": null,
      "capture": {
        "status": "held",
        "copies": 7,
        "first_observed": "2026-08-01T00:17:31Z",
        "last_observed": "2026-08-14T23:39:53Z",
        "last_checked": "2026-08-15T14:23:00Z"
      },
      "differences": [
        {
          "observed_at": "2026-08-14T23:39:53Z",
          "window_start": "2026-08-08T15:54:13Z",
          "window_end": "2026-08-14T23:39:53Z",
          "status": "source-content",
          "summary": "Coinkite added a Current guidance banner dated August 14, 2026 pointing to the security-status page and the step-by-step migration guide, with a note that firmware updates alone do not repair an affected seed.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 2,
          "removed_lines": 0
        },
        {
          "observed_at": "2026-08-08T15:54:13Z",
          "window_start": "2026-08-08T14:54:00Z",
          "window_end": "2026-08-08T15:54:13Z",
          "status": "source-content",
          "summary": "Coinkite added a 'What Happened, in Simple Terms' section explaining Yasmarang, the build and link integration error, and clarifying that the hardware TRNG did not fail at runtime; 'software fallback' wording was tightened to 'fallback' elsewhere.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 24,
          "removed_lines": 37
        },
        {
          "observed_at": "2026-08-08T14:54:00Z",
          "window_start": "2026-08-04T17:05:32Z",
          "window_end": "2026-08-08T14:54:00Z",
          "status": "source-content",
          "summary": "The backgrounder added an August 8 update and a new section clarifying that the phrase 'software fallback' refers to MicroPython's upstream Yasmarang implementation selected during the build, not an intentional runtime failover from the hardware TRNG. The body also rewords most occurrences of 'fallback' to 'software PRNG implementation' or similar.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 37,
          "removed_lines": 7
        },
        {
          "observed_at": "2026-08-04T17:05:32Z",
          "window_start": "2026-08-01T18:44:29Z",
          "window_end": "2026-08-04T17:05:32Z",
          "status": "capture-noise",
          "summary": "Only line wrapping around the term PRNG changed in extraction. The source text did not change.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 3,
          "removed_lines": 2
        },
        {
          "observed_at": "2026-08-01T18:44:29Z",
          "window_start": "2026-08-01T14:02:31Z",
          "window_end": "2026-08-01T18:44:29Z",
          "status": "source-content",
          "summary": "Coinkite moved the backgrounder's update stamp to August 1, 2026 at 2:35 p.m. EDT and replaced Mk3 with Mk2 or Mk3 throughout: the affected firmware range became 'The affected Mk2 and Mk3 firmware range is 4.0.1 through 4.1.9', the seeded-PRNG analysis became 'On Mk2 and Mk3, the active PRNG was seeded primarily from device and timing state', the hotfix list became 'Version 4.2.0 for Mk2 and Mk3', and the migration steps and the pointer to the dedicated advisory were rewritten the same way.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 11,
          "removed_lines": 10
        },
        {
          "observed_at": "2026-08-01T14:02:31Z",
          "window_start": "2026-08-01T00:17:31Z",
          "window_end": "2026-08-01T14:02:31Z",
          "status": "source-content",
          "summary": "Coinkite replaced the backgrounder's fixed-firmware banner with an August 1 update stating that funds are at risk unless the seed was created with at least 50 independent private dice rolls and the wallet is protected by a strong, unique BIP-39 passphrase, added a paragraph qualifying what counts as such a passphrase, and added a sentence calling the reduced search space a direct security risk rather than a theoretical possibility for wallets meeting neither condition.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 15,
          "removed_lines": 3
        }
      ]
    },
    {
      "id": "coinkite-mk3-advisory",
      "title": "Mk3 security advisory",
      "url": "https://blog.coinkite.com/coldcard-mk3-seed-generation-warning/",
      "organisation": "Coinkite",
      "kind": "vendor-advisory",
      "role": "Vendor advisory",
      "publication_time": "2026-07-30",
      "note": "The original narrow advisory. Stated Mk4/Q/Mk5 'not affected based on our early analysis'.",
      "gone": null,
      "capture": {
        "status": "held",
        "copies": 6,
        "first_observed": "2026-07-31T01:56:33Z",
        "last_observed": "2026-08-14T23:39:55Z",
        "last_checked": "2026-08-15T14:23:02Z"
      },
      "differences": [
        {
          "observed_at": "2026-08-14T23:39:55Z",
          "window_start": "2026-08-01T18:44:33Z",
          "window_end": "2026-08-14T23:39:55Z",
          "status": "source-content",
          "summary": "Coinkite added a Current guidance banner dated August 14, 2026 pointing to the security-status page and the step-by-step migration guide, with a note that firmware updates alone do not repair an affected seed.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 2,
          "removed_lines": 0
        },
        {
          "observed_at": "2026-08-01T18:44:33Z",
          "window_start": "2026-08-01T14:02:34Z",
          "window_end": "2026-08-01T18:44:33Z",
          "status": "source-content",
          "summary": "Fourth recorded revision of the advisory, and the one that resolves the Mk2 question this archive had tracked as open. The update stamp moved to August 1, 2026 at 2:35 p.m. EDT and every Mk3-only statement about the defect and its fix now names both models: the fixed-firmware list reads 'Mk2/Mk3: version 4.2.0 or later', the affected range reads 'The issue is present on Mk2 and Mk3 firmware versions 4.0.1 through 4.1.9 inclusive', the at-risk sentence covers 'a seed generated on Mk2 or Mk3 version 4.0.1 (March 2021) through 4.1.9', and the release is described as 'Fixed Mk2/Mk3 firmware version 4.2.0' from the 'official Mk2/Mk3 download page'. The one-device migration section, the optional dice-only section and the closing migration steps were rewritten from Mk3-only to Mk2-or-Mk3 wording. Until this revision the vendor downloads-page listing was the only vendor evidence placing the Mk2 in the affected range or the hotfix. The published lower bound is unchanged at 4.0.1 for both models, so the v4.0.0 divergence recorded on the firmware page is untouched.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 30,
          "removed_lines": 29
        },
        {
          "observed_at": "2026-08-01T14:02:34Z",
          "window_start": "2026-08-01T00:17:31Z",
          "window_end": "2026-08-01T14:02:34Z",
          "status": "source-content",
          "summary": "Third recorded revision of the advisory. It now carries 'Updated August 1, 2026 at 9:35 a.m. EDT' and replaces the blanket warning that Mk3 4.0.1 to 4.1.9 users' funds 'may be at risk' with a conditional statement that funds are at risk unless the seed was created with at least 50 fair, independent, private dice rolls and the wallet is protected by a strong, unique BIP-39 passphrase. The passphrase section changed in both directions: it now states that reduced seed entropy alone is not enough to reach a passphrase wallet, and separately that a strong passphrase does not repair the seed, that passphrase users should also migrate, and that an uncertain passphrase means treating funds as at risk and migrating immediately.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 19,
          "removed_lines": 10
        },
        {
          "observed_at": "2026-08-01T00:17:31Z",
          "window_start": "2026-07-31T07:30:23Z",
          "window_end": "2026-08-01T00:17:31Z",
          "status": "source-content",
          "summary": "Coinkite announced fixed firmware for every affected model and release track, including Mk3 4.2.0, and rewrote the one-device migration guidance.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": true,
          "added_lines": 66,
          "removed_lines": 53
        },
        {
          "observed_at": "2026-07-31T07:30:23Z",
          "window_start": "2026-07-31T01:56:33Z",
          "window_end": "2026-07-31T07:30:23Z",
          "status": "source-content",
          "summary": "Coinkite expanded the affected scope to Mk4, Mk5 and Q, added dice guidance, and revised the passphrase and migration sections.",
          "inherited_from_wayback": true,
          "baseline_inherited_from_wayback": true,
          "added_lines": 56,
          "removed_lines": 19
        }
      ]
    },
    {
      "id": "coinkite-blog-index",
      "title": "Coinkite blog index",
      "url": "https://blog.coinkite.com/",
      "organisation": "Coinkite",
      "kind": "vendor-index",
      "role": "Vendor publication index",
      "publication_time": null,
      "note": "Coinkite's publication index, retained to detect additional incident material.",
      "gone": null,
      "capture": {
        "status": "held",
        "copies": 8,
        "first_observed": "2026-08-01T00:17:31Z",
        "last_observed": "2026-08-08T15:54:17Z",
        "last_checked": "2026-08-15T14:23:04Z"
      },
      "differences": [
        {
          "observed_at": "2026-08-08T15:54:17Z",
          "window_start": "2026-08-08T14:54:03Z",
          "window_end": "2026-08-08T15:54:17Z",
          "status": "source-content",
          "summary": "The blog index changed the linked backgrounder's display from the software-PRNG cause line to 'Technical Deep Dive into the Entropy Issue'.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 1,
          "removed_lines": 1
        },
        {
          "observed_at": "2026-08-08T14:54:03Z",
          "window_start": "2026-08-07T13:19:43Z",
          "window_end": "2026-08-08T14:54:03Z",
          "status": "source-content",
          "summary": "The blog index entry for the entropy technical backgrounder changed its title from 'Technical Deep Dive into the Entropy Issue' to a longer headline about the software PRNG cause.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 1,
          "removed_lines": 1
        },
        {
          "observed_at": "2026-08-07T13:19:43Z",
          "window_start": "2026-08-07T11:19:21Z",
          "window_end": "2026-08-07T13:19:43Z",
          "status": "source-content",
          "summary": "The displayed date of the new \"Update on Customer Data Retention\" post moved from Aug 6, 2026 to Aug 7, 2026; the publisher retimestamped it. No other index change.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 1,
          "removed_lines": 1
        },
        {
          "observed_at": "2026-08-07T11:19:21Z",
          "window_start": "2026-08-04T20:36:14Z",
          "window_end": "2026-08-07T11:19:21Z",
          "status": "source-content",
          "summary": "New post listed: \"Update on Customer Data Retention\", dated Aug 6, 2026, about a temporary change to Coinkite's customer-data retention and blanking practices following the incident.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 3,
          "removed_lines": 0
        },
        {
          "observed_at": "2026-08-04T20:36:14Z",
          "window_start": "2026-08-03T11:38:26Z",
          "window_end": "2026-08-04T20:36:14Z",
          "status": "source-content",
          "summary": "The official blog index added “Adding to the Public Record on Our Ongoing Investigation.”",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 3,
          "removed_lines": 0
        },
        {
          "observed_at": "2026-08-03T11:38:26Z",
          "window_start": "2026-08-01T14:02:36Z",
          "window_end": "2026-08-03T11:38:26Z",
          "status": "source-content",
          "summary": "Coinkite published a new post, 'Update, Sunday' dated Aug 2, 2026, described as an update on the COLDCARD firmware vulnerability, customer support, affected inventory and migration. It now sits atop the blog index.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 3,
          "removed_lines": 0
        },
        {
          "observed_at": "2026-08-01T14:02:36Z",
          "window_start": "2026-08-01T00:17:31Z",
          "window_end": "2026-08-01T14:02:36Z",
          "status": "source-content",
          "summary": "The blog index excerpt for the advisory changed with the advisory itself, from 'Coinkite is warning users who generated a seed using a COLDCARD on firmware versions 4.0.1 throug...' to 'Funds from affected COLDCARD seeds are at risk if the seed lacks 50 independent, private dice rol...'.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 1,
          "removed_lines": 1
        }
      ]
    },
    {
      "id": "coinkite-historical-disclosures",
      "title": "COLDCARD security disclosure history",
      "url": "https://coinkite.com/historical-disclosures",
      "organisation": "Coinkite",
      "kind": "vendor-index",
      "role": "Vendor publication index",
      "publication_time": "2026-08-04",
      "note": "Coinkite's own chronology of public security research, coordinated disclosures,\npaid private reviews, internal findings and advisories affecting COLDCARD,\nannounced in the vendor's 4 August public-record post\n(coldcardwallet-2084731768632991801). At first capture it self-reports 23\nsecurity-relevant events from 2019 onward, 12 of them with public evidence of\ncoordinated disclosure, with coverage stated through 4 August 2026.\n\nThe page states its own limits, and they are worth preserving: it presents\nitself as a chronology rather than a count of independent vulnerabilities or a\nproduct score, and its \"no public evidence\" label means none was found in the\ncited record rather than that nothing happened privately. Several entries cite\nprivate correspondence or paid review that this archive cannot inspect.\nSelection, classification and wording are the vendor's throughout, which is why\nit is held for dated revision comparison: what is added, reworded or dropped\nfrom a self-published disclosure history is itself the record.\n",
      "gone": null,
      "capture": {
        "status": "held",
        "copies": 2,
        "first_observed": "2026-08-05T03:02:23Z",
        "last_observed": "2026-08-08T14:54:05Z",
        "last_checked": "2026-08-15T14:23:05Z"
      },
      "differences": [
        {
          "observed_at": "2026-08-08T14:54:05Z",
          "window_start": "2026-08-05T03:02:23Z",
          "window_end": "2026-08-08T14:54:05Z",
          "status": "source-content",
          "summary": "The page updated its coverage date to August 8, replaced the 'COLDCARD Security Advisory' heading with 'COLDCARD Security Status', rewrote the entropy issue description as a build-integration and symbol-resolution defect rather than an intentional fallback, and added upstream MicroPython and build-configuration sources.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 11,
          "removed_lines": 6
        }
      ]
    },
    {
      "id": "coinkite-data-retention-update",
      "title": "Update on Customer Data Retention",
      "url": "https://blog.coinkite.com/update-on-customer-data-retention/",
      "organisation": "Coinkite",
      "kind": "vendor-statement",
      "role": "Vendor statement",
      "publication_time": "2026-08-07",
      "note": "The vendor's own post on a temporary change to its customer-data retention and\nblanking practices after the incident. Registered 7 August 2026 because the\nrecord already held the 2 August outreach exchange — Coinkite saying customer\npersonal data is deleted and many customers were therefore unreachable\n(coldcard-pii-policy), Satochip asking how store customers received emails\nunder a 90-day premise (satochip-data-retention-question), and the June paper\nspam post's 120-day figure — with no primary statement reconciling them. The\nblog index (coinkite-blog-index) carried this post on 7 August; its displayed\ndate moved from Aug 6 to Aug 7 between two captures of that index, so the\npublisher retimestamped it and the published date above is the one currently\nshown rather than a resolved publication time.\n\nAt first capture the post states that Coinkite's standard practice is to blank\ncustomer records automatically after 120 days, retaining only email address and\ncountry of residence, with accelerated blanking available on request; that the\nautomated blanking process is temporarily suspended because of legal\nobligations arising from the incident, including preservation of records that\nmay be relevant to \"ongoing and anticipated legal proceedings\"; and that a\ncustomer may ask to be exempted from the preservation and have the standard\npolicy applied. It is the vendor's own account of its retention practice and of\nwhy it changed, not an independently checkable fact about what is stored.\n",
      "gone": null,
      "capture": {
        "status": "held",
        "copies": 1,
        "first_observed": "2026-08-07T15:37:12Z",
        "last_observed": "2026-08-07T15:37:12Z",
        "last_checked": "2026-08-15T14:23:09Z"
      },
      "differences": []
    },
    {
      "id": "coldcard-downloads",
      "title": "COLDCARD firmware downloads",
      "url": "https://coldcard.com/downloads",
      "organisation": "Coinkite",
      "kind": "vendor-releases",
      "role": "Firmware release index",
      "publication_time": null,
      "note": "Which firmware is actually being offered, and when it appeared.",
      "gone": null,
      "capture": {
        "status": "held",
        "copies": 4,
        "first_observed": "2026-08-01T00:17:31Z",
        "last_observed": "2026-08-12T00:05:17Z",
        "last_checked": "2026-08-15T14:23:10Z"
      },
      "differences": [
        {
          "observed_at": "2026-08-12T00:05:17Z",
          "window_start": "2026-08-08T13:54:00Z",
          "window_end": "2026-08-12T00:05:17Z",
          "status": "source-content",
          "summary": "The page removed three Telegram references.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 0,
          "removed_lines": 3
        },
        {
          "observed_at": "2026-08-08T13:54:00Z",
          "window_start": "2026-08-01T14:02:38Z",
          "window_end": "2026-08-08T13:54:00Z",
          "status": "source-content",
          "summary": "Coinkite softened the advisory banner, added fixed-release labels to every supported firmware version, and replaced the Read advisory link with a Check status link.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 10,
          "removed_lines": 7
        },
        {
          "observed_at": "2026-08-01T14:02:38Z",
          "window_start": "2026-08-01T00:17:31Z",
          "window_end": "2026-08-01T14:02:38Z",
          "status": "source-content",
          "summary": "The site-wide advisory banner hardened from 'Seeds generated on firmware 4.0.1 or later may be at risk' to 'Seeds generated on firmware 4.0.1 (2021 or later) are at risk'.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 1,
          "removed_lines": 1
        }
      ]
    },
    {
      "id": "mara-slipstream-portal",
      "title": "MARA Slipstream transaction-submission portal",
      "url": "https://slipstream.mara.com/",
      "organisation": "MARA",
      "kind": "vendor-docs",
      "role": "Vendor documentation",
      "publication_time": null,
      "note": "Live submission portal used to check the public client-code, fee and submission interface described on the threshold-wallet migration page.",
      "gone": null,
      "capture": {
        "status": "held",
        "copies": 3,
        "first_observed": "2026-08-01T09:15:12Z",
        "last_observed": "2026-08-06T03:50:39Z",
        "last_checked": "2026-08-15T14:23:13Z"
      },
      "differences": [
        {
          "observed_at": "2026-08-06T03:50:39Z",
          "window_start": "2026-08-03T02:02:01Z",
          "window_end": "2026-08-06T03:50:39Z",
          "status": "source-content",
          "summary": "The portal dropped the client-code requirement text (REGISTER, \"Client codes are currently required to submit transactions.\" and \"Apply for a client code here.\"), consistent with MARA's 3 Aug 2026 permissionless announcement (mara-slipstream-permissionless); it now carries the current-rate text without the code requirement. Classified by hand: the change had been masked as blocked polls since 3 Aug 09:03Z because the registry's required_text still expected the removed sentence.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 0,
          "removed_lines": 3
        },
        {
          "observed_at": "2026-08-03T02:02:01Z",
          "window_start": "2026-08-01T09:15:12Z",
          "window_end": "2026-08-03T02:02:01Z",
          "status": "source-content",
          "summary": "The portal's stated minimum fee rate changed from the higher of 2x the mempool priority fee rate or 2 sats/vByte to the higher of 1x or 1 sats/vByte, a halving of the published submission floor.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 1,
          "removed_lines": 1
        }
      ]
    },
    {
      "id": "mara-slipstream-api",
      "title": "MARA Slipstream API documentation",
      "url": "https://slipstream.mara.com/docs/",
      "organisation": "MARA",
      "kind": "vendor-docs",
      "role": "Vendor documentation",
      "publication_time": null,
      "note": "Official OpenAPI description captured through its stable JSON endpoint. It documents admission rules, best-effort handling and the request schema.",
      "gone": null,
      "capture": {
        "status": "held",
        "copies": 2,
        "first_observed": "2026-08-01T09:15:18Z",
        "last_observed": "2026-08-03T09:06:15Z",
        "last_checked": "2026-08-15T12:24:21Z"
      },
      "differences": [
        {
          "observed_at": "2026-08-03T09:06:15Z",
          "window_start": "2026-08-01T09:15:18Z",
          "window_end": "2026-08-03T09:06:15Z",
          "status": "source-content",
          "summary": "The Slipstream OpenAPI description lowered its stated minimum fee rate from the higher of 2x the mempool priority fee or 2 sats/vByte to the higher of 1x or 1 sats/vByte, and the client_code examples in the transaction submission endpoints changed from 'Client code' to 'Optional code to identify the user'.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 3,
          "removed_lines": 3
        }
      ]
    },
    {
      "id": "cc-changelog",
      "title": "COLDCARD firmware changelog",
      "url": "https://raw.githubusercontent.com/Coldcard/firmware/master/releases/ChangeLog.md",
      "organisation": "Coinkite",
      "kind": "repo-file",
      "role": "Repository file",
      "publication_time": null,
      "note": null,
      "gone": null,
      "capture": {
        "status": "held",
        "copies": 1,
        "first_observed": "2026-08-01T00:17:31Z",
        "last_observed": "2026-08-01T00:17:31Z",
        "last_checked": "2026-08-15T12:24:23Z"
      },
      "differences": []
    },
    {
      "id": "cc-history-mk3",
      "title": "Mk3 firmware history",
      "url": "https://raw.githubusercontent.com/Coldcard/firmware/master/releases/History-Mk3.md",
      "organisation": "Coinkite",
      "kind": "repo-file",
      "role": "Repository file",
      "publication_time": null,
      "note": "Carries the 4.2.0 entry and the do-not-generate banner.",
      "gone": null,
      "capture": {
        "status": "held",
        "copies": 1,
        "first_observed": "2026-08-01T00:17:31Z",
        "last_observed": "2026-08-01T00:17:31Z",
        "last_checked": "2026-08-15T12:24:24Z"
      },
      "differences": []
    },
    {
      "id": "cc-history-mk",
      "title": "Mk4 and Mk5 firmware history",
      "url": "https://raw.githubusercontent.com/Coldcard/firmware/master/releases/History-Mk.md",
      "organisation": "Coinkite",
      "kind": "repo-file",
      "role": "Repository file",
      "publication_time": null,
      "note": null,
      "gone": null,
      "capture": {
        "status": "held",
        "copies": 1,
        "first_observed": "2026-08-01T00:17:31Z",
        "last_observed": "2026-08-01T00:17:31Z",
        "last_checked": "2026-08-15T12:24:26Z"
      },
      "differences": []
    },
    {
      "id": "cc-history-q",
      "title": "Q firmware history",
      "url": "https://raw.githubusercontent.com/Coldcard/firmware/master/releases/History-Q.md",
      "organisation": "Coinkite",
      "kind": "repo-file",
      "role": "Repository file",
      "publication_time": null,
      "note": null,
      "gone": null,
      "capture": {
        "status": "held",
        "copies": 1,
        "first_observed": "2026-08-01T00:17:31Z",
        "last_observed": "2026-08-01T00:17:31Z",
        "last_checked": "2026-08-15T12:24:28Z"
      },
      "differences": []
    },
    {
      "id": "libngu-random-c",
      "title": "libngu random.c",
      "url": "https://raw.githubusercontent.com/switck/libngu/master/ngu/random.c",
      "organisation": "switck",
      "kind": "repo-file",
      "role": "Repository file",
      "publication_time": null,
      "note": "The #ifndef guard and the generator. On 5 Aug 2026 upstream merged #61, replacing Yasmarang with a SHA-256 Hash-DRBG and rejecting reseeds under 32 bytes; the guard's presence test is unchanged. Still tracked for any further upstream revision, including the open value-check proposal #58.",
      "gone": null,
      "capture": {
        "status": "held",
        "copies": 5,
        "first_observed": "2026-08-01T00:23:36Z",
        "last_observed": "2026-08-12T04:35:57Z",
        "last_checked": "2026-08-15T12:24:30Z"
      },
      "differences": [
        {
          "observed_at": "2026-08-12T04:35:57Z",
          "window_start": "2026-08-07T19:21:34Z",
          "window_end": "2026-08-12T04:35:57Z",
          "status": "source-content",
          "summary": "The random.c implementation was refactored behind random_backend.h, replacing the platform-specific CHIP_TRNG macros with a checked chip_trng_read helper, and corrected the bit-length and mask calculations used during range reduction.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 22,
          "removed_lines": 57
        },
        {
          "observed_at": "2026-08-07T19:21:34Z",
          "window_start": "2026-08-06T16:26:26Z",
          "window_end": "2026-08-07T19:21:34Z",
          "status": "source-content",
          "summary": "The preprocessor guard around the RNG was narrowed from MICROPY_HW_ENABLE_RNG == 0 to MICROPY_HW_ENABLE_RNG == 0 && NGU_STM32_EXTERNAL_RNG_GET != 1.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 1,
          "removed_lines": 1
        },
        {
          "observed_at": "2026-08-06T16:26:26Z",
          "window_start": "2026-08-05T14:18:23Z",
          "window_end": "2026-08-06T16:26:26Z",
          "status": "source-content",
          "summary": "random.c on master changed with the merged HW-TRNG enforcement: build now errors unless MICROPY_HW_ENABLE_RNG, Linux uses getrandom() via a checked helper instead of random(), and random_bytes() rejects negative counts.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 15,
          "removed_lines": 4
        },
        {
          "observed_at": "2026-08-05T14:18:23Z",
          "window_start": "2026-08-01T00:23:36Z",
          "window_end": "2026-08-05T14:18:23Z",
          "status": "source-content",
          "summary": "The random-number implementation replaces Yasmarang with a SHA-256 Hash-DRBG seeded from 32 checked chip-TRNG words. It also rejects seed inputs shorter than 32 bytes and routes random-word generation through the new byte generator.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 63,
          "removed_lines": 29
        }
      ]
    },
    {
      "id": "libngu-pr-58",
      "title": "libngu PR #58",
      "url": "https://github.com/switck/libngu/pull/58",
      "organisation": "switck",
      "kind": "repo-pr",
      "role": "Repository pull request",
      "publication_time": null,
      "note": "Incident-response PR open with no maintainer response present in the 1 Aug 2026 capture. Retained to record later review or status changes.",
      "gone": null,
      "capture": {
        "status": "held",
        "copies": 7,
        "first_observed": "2026-08-01T03:25:23Z",
        "last_observed": "2026-08-14T08:24:50Z",
        "last_checked": "2026-08-15T12:24:32Z"
      },
      "differences": [
        {
          "observed_at": "2026-08-14T08:24:50Z",
          "window_start": "2026-08-12T04:36:00Z",
          "window_end": "2026-08-14T08:24:50Z",
          "status": "capture-noise",
          "summary": "Only GitHub header chrome changed. The 'Sign in' and 'Appearance settings' labels split onto separate lines, and the search prompt changed from 'Type / to search' to 'Search/'.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 5,
          "removed_lines": 3
        },
        {
          "observed_at": "2026-08-12T04:36:00Z",
          "window_start": "2026-08-06T16:26:28Z",
          "window_end": "2026-08-12T04:36:00Z",
          "status": "capture-noise",
          "summary": "Only GitHub reaction metadata changed: the thumbs-up count and reacting-account list updated, with no change to the pull-request discussion or patch text.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 5,
          "removed_lines": 0
        },
        {
          "observed_at": "2026-08-06T16:26:28Z",
          "window_start": "2026-08-04T16:08:34Z",
          "window_end": "2026-08-06T16:26:28Z",
          "status": "source-content",
          "summary": "PR #58 \"Enforce HW TRNG\" was merged by switck on Aug 6, 2026 as commit e9d5e80; status flipped from Open to Merged.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 12,
          "removed_lines": 5
        },
        {
          "observed_at": "2026-08-04T16:08:34Z",
          "window_start": "2026-08-01T08:11:50Z",
          "window_end": "2026-08-04T16:08:34Z",
          "status": "capture-noise",
          "summary": "Only GitHub navigation and search-dialog chrome rendered differently. The pull request content did not change.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 3,
          "removed_lines": 23
        },
        {
          "observed_at": "2026-08-01T08:11:50Z",
          "window_start": "2026-08-01T03:50:17Z",
          "window_end": "2026-08-01T08:11:50Z",
          "status": "capture-noise",
          "summary": "Only the thumbs-up reaction total and reacting-account list changed; the pull-request discussion and patch text were unchanged.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 3,
          "removed_lines": 3
        },
        {
          "observed_at": "2026-08-01T03:50:17Z",
          "window_start": "2026-08-01T03:25:23Z",
          "window_end": "2026-08-01T03:50:17Z",
          "status": "capture-noise",
          "summary": "Only GitHub repository navigation counters changed.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 2,
          "removed_lines": 2
        }
      ]
    },
    {
      "id": "libngu-pr-58-patch",
      "title": "libngu PR #58 patch",
      "url": "https://github.com/switck/libngu/pull/58.patch",
      "organisation": "switck",
      "kind": "repo-patch",
      "role": "Repository patch",
      "publication_time": null,
      "note": "Patch content for the open incident-response proposal. Kept separately from the conversation and review-state capture.",
      "gone": null,
      "capture": {
        "status": "held",
        "copies": 1,
        "first_observed": "2026-08-01T06:39:23Z",
        "last_observed": "2026-08-01T06:39:23Z",
        "last_checked": "2026-08-15T12:24:34Z"
      },
      "differences": []
    },
    {
      "id": "libngu-pr-59",
      "title": "libngu PR #59",
      "url": "https://github.com/switck/libngu/pull/59",
      "organisation": "switck",
      "kind": "repo-pr",
      "role": "Repository pull request",
      "publication_time": null,
      "note": "Broad incident-response PR. On 1 Aug the maintainer called the diff too large and the author offered a three-PR split.",
      "gone": null,
      "capture": {
        "status": "held",
        "copies": 7,
        "first_observed": "2026-08-01T03:25:24Z",
        "last_observed": "2026-08-14T08:24:55Z",
        "last_checked": "2026-08-15T12:24:37Z"
      },
      "differences": [
        {
          "observed_at": "2026-08-14T08:24:55Z",
          "window_start": "2026-08-12T04:36:09Z",
          "window_end": "2026-08-14T08:24:55Z",
          "status": "capture-noise",
          "summary": "Only GitHub header chrome changed. The 'Sign in' and 'Appearance settings' labels split onto separate lines, and the search prompt changed from 'Type / to search' to 'Search/'.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 5,
          "removed_lines": 3
        },
        {
          "observed_at": "2026-08-12T04:36:09Z",
          "window_start": "2026-08-07T06:09:47Z",
          "window_end": "2026-08-12T04:36:09Z",
          "status": "capture-noise",
          "summary": "Only GitHub contributor-role labels rendered on the page; the pull-request state, discussion and patch text were unchanged.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 3,
          "removed_lines": 0
        },
        {
          "observed_at": "2026-08-07T06:09:47Z",
          "window_start": "2026-08-04T16:08:41Z",
          "window_end": "2026-08-07T06:09:47Z",
          "status": "source-content",
          "summary": "The author edited the closing comment: successor PRs #63 and #64 were retitled to \"random: reject two-word entropy cycles\" and \"random: harden entropy backends and state handling\".",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 2,
          "removed_lines": 2
        },
        {
          "observed_at": "2026-08-04T16:08:41Z",
          "window_start": "2026-08-01T16:08:11Z",
          "window_end": "2026-08-04T16:08:41Z",
          "status": "capture-noise",
          "summary": "Only GitHub navigation and search-dialog chrome rendered differently. The pull request content did not change.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 3,
          "removed_lines": 23
        },
        {
          "observed_at": "2026-08-01T16:08:11Z",
          "window_start": "2026-08-01T03:50:19Z",
          "window_end": "2026-08-01T16:08:11Z",
          "status": "source-content",
          "summary": "The pull request was closed by its author in favour of a three-pull-request stack (#62, #63 and #64) described as summing to a byte-identical tree, with a suggested review order and an offer to reopen.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 20,
          "removed_lines": 2
        },
        {
          "observed_at": "2026-08-01T03:50:19Z",
          "window_start": "2026-08-01T03:25:24Z",
          "window_end": "2026-08-01T03:50:19Z",
          "status": "source-content",
          "summary": "The pull-request author added a comment offering to split the proposal into three smaller changes; GitHub navigation counters also changed.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 14,
          "removed_lines": 2
        }
      ]
    },
    {
      "id": "libngu-pr-59-patch",
      "title": "libngu PR #59 patch",
      "url": "https://github.com/switck/libngu/pull/59.patch",
      "organisation": "switck",
      "kind": "repo-patch",
      "role": "Repository patch",
      "publication_time": null,
      "note": "Patch content for the open incident-response proposal. Kept separately from the conversation and review-state capture.",
      "gone": null,
      "capture": {
        "status": "held",
        "copies": 1,
        "first_observed": "2026-08-01T06:39:31Z",
        "last_observed": "2026-08-01T06:39:31Z",
        "last_checked": "2026-08-15T12:24:40Z"
      },
      "differences": []
    },
    {
      "id": "libngu-pr-60",
      "title": "libngu PR #60: full-width reseeding",
      "url": "https://github.com/switck/libngu/pull/60",
      "organisation": "switck",
      "kind": "repo-pr",
      "role": "Repository pull request",
      "publication_time": null,
      "note": "Open incident-response proposal to absorb a bytes-like seed into all Yasmarang state words. Companion to Coldcard/firmware PR #691.",
      "gone": null,
      "capture": {
        "status": "held",
        "copies": 6,
        "first_observed": "2026-08-01T06:21:09Z",
        "last_observed": "2026-08-14T23:41:37Z",
        "last_checked": "2026-08-15T12:24:42Z"
      },
      "differences": [
        {
          "observed_at": "2026-08-14T23:41:37Z",
          "window_start": "2026-08-14T08:25:01Z",
          "window_end": "2026-08-14T23:41:37Z",
          "status": "source-content",
          "summary": "The pull-request state changed from Draft to Closed.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 1,
          "removed_lines": 1
        },
        {
          "observed_at": "2026-08-14T08:25:01Z",
          "window_start": "2026-08-04T16:08:47Z",
          "window_end": "2026-08-14T08:25:01Z",
          "status": "capture-noise",
          "summary": "Only GitHub header chrome changed. The 'Sign in' and 'Appearance settings' labels split onto separate lines, and the search prompt changed from 'Type / to search' to 'Search/'.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 5,
          "removed_lines": 3
        },
        {
          "observed_at": "2026-08-04T16:08:47Z",
          "window_start": "2026-08-01T17:41:16Z",
          "window_end": "2026-08-04T16:08:47Z",
          "status": "capture-noise",
          "summary": "Only GitHub navigation and search-dialog chrome rendered differently. The pull request content did not change.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 3,
          "removed_lines": 23
        },
        {
          "observed_at": "2026-08-01T17:41:16Z",
          "window_start": "2026-08-01T16:08:18Z",
          "window_end": "2026-08-01T17:41:16Z",
          "status": "source-content",
          "summary": "The inline cross-reference to Coldcard/firmware#691 changed from Open to Draft, reflecting a real state change on that pull request rather than rendering variance. Nothing else moved: no discussion, review or patch text on this pull request changed. The underlying state change is captured directly on coldcard-firmware-pr-691 at 20260801T174121Z, so this entry is the same event seen from the linked repository.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 1,
          "removed_lines": 1
        },
        {
          "observed_at": "2026-08-01T16:08:18Z",
          "window_start": "2026-08-01T06:21:09Z",
          "window_end": "2026-08-01T16:08:18Z",
          "status": "source-content",
          "summary": "Two contributors reviewed the reseed change, the author pushed a second commit rejecting a zero-length seed and documenting a roughly 72-bit state ceiling, a reviewer argued for removing Yasmarang entirely and announced a competing pull request, and the author closed this one in favour of #61.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 78,
          "removed_lines": 7
        }
      ]
    },
    {
      "id": "libngu-pr-60-patch",
      "title": "libngu PR #60 patch",
      "url": "https://github.com/switck/libngu/pull/60.patch",
      "organisation": "switck",
      "kind": "repo-patch",
      "role": "Repository patch",
      "publication_time": null,
      "note": "Patch content for the open full-width reseed proposal. Kept separately from the conversation and review-state capture.",
      "gone": null,
      "capture": {
        "status": "held",
        "copies": 2,
        "first_observed": "2026-08-01T06:39:32Z",
        "last_observed": "2026-08-01T16:08:21Z",
        "last_checked": "2026-08-15T12:24:45Z"
      },
      "differences": [
        {
          "observed_at": "2026-08-01T16:08:21Z",
          "window_start": "2026-08-01T06:39:32Z",
          "window_end": "2026-08-01T16:08:21Z",
          "status": "source-content",
          "summary": "The published patch series gained a second commit adding a ValueError on an empty seed, a regression test and a comment documenting the generator's roughly 72-bit independent state.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 61,
          "removed_lines": 1
        }
      ]
    },
    {
      "id": "libngu-pr-61",
      "title": "libngu PR #61: SHA-256 Hash-DRBG and a full-width reseed API",
      "url": "https://github.com/switck/libngu/pull/61",
      "organisation": "switck",
      "kind": "repo-pr",
      "role": "Repository pull request",
      "publication_time": null,
      "note": "The live upstream proposal after #59 and #60 were closed by their authors on 1 August. Replaces the generator with a SHA-256 Hash-DRBG and requires a reseed seed of at least 32 bytes, rejecting the old four-byte integer call. Coldcard/firmware PR #691 was rewritten to depend on this one.",
      "gone": null,
      "capture": {
        "status": "held",
        "copies": 9,
        "first_observed": "2026-08-03T11:55:59Z",
        "last_observed": "2026-08-14T23:41:42Z",
        "last_checked": "2026-08-15T12:24:48Z"
      },
      "differences": [
        {
          "observed_at": "2026-08-14T23:41:42Z",
          "window_start": "2026-08-14T08:25:07Z",
          "window_end": "2026-08-14T23:41:42Z",
          "status": "source-content",
          "summary": "The pull-request state changed from Draft to Closed.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 1,
          "removed_lines": 1
        },
        {
          "observed_at": "2026-08-14T08:25:07Z",
          "window_start": "2026-08-12T04:36:26Z",
          "window_end": "2026-08-14T08:25:07Z",
          "status": "capture-noise",
          "summary": "Only GitHub header chrome changed. The 'Sign in' and 'Appearance settings' labels split onto separate lines, and the search prompt changed from 'Type / to search' to 'Search/'.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 5,
          "removed_lines": 3
        },
        {
          "observed_at": "2026-08-12T04:36:26Z",
          "window_start": "2026-08-07T19:21:51Z",
          "window_end": "2026-08-12T04:36:26Z",
          "status": "source-content",
          "summary": "The pull request state changed from Open to Merged, and the page rendered additional contributor labels.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 2,
          "removed_lines": 1
        },
        {
          "observed_at": "2026-08-07T19:21:51Z",
          "window_start": "2026-08-07T06:10:03Z",
          "window_end": "2026-08-07T19:21:51Z",
          "status": "source-content",
          "summary": "The pull request state changed from Open to Closed.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 1,
          "removed_lines": 1
        },
        {
          "observed_at": "2026-08-07T06:10:03Z",
          "window_start": "2026-08-05T14:18:43Z",
          "window_end": "2026-08-07T06:10:03Z",
          "status": "source-content",
          "summary": "PR #61 gained a referenced-by section dated Aug 7, 2026: the new PR stack #62 (Closed), #63 (Open) and #64 (Open) now references it.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 10,
          "removed_lines": 0
        },
        {
          "observed_at": "2026-08-05T14:18:43Z",
          "window_start": "2026-08-04T16:08:52Z",
          "window_end": "2026-08-05T14:18:43Z",
          "status": "source-content",
          "summary": "The pull request status changed from open to merged, showing that its six commits were merged into the upstream master branch on 5 August 2026.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 11,
          "removed_lines": 5
        },
        {
          "observed_at": "2026-08-04T16:08:52Z",
          "window_start": "2026-08-04T13:37:48Z",
          "window_end": "2026-08-04T16:08:52Z",
          "status": "capture-noise",
          "summary": "Only GitHub navigation and search-dialog chrome rendered differently. The pull request content did not change.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 3,
          "removed_lines": 23
        },
        {
          "observed_at": "2026-08-04T13:37:48Z",
          "window_start": "2026-08-03T11:55:59Z",
          "window_end": "2026-08-04T13:37:48Z",
          "status": "source-content",
          "summary": "A new pull-request comment proposed incorporating Hash_DRBG, including bounds on hash_df requests and wiping stack temporaries.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 12,
          "removed_lines": 0
        }
      ]
    },
    {
      "id": "libngu-pr-61-patch",
      "title": "libngu PR #61 patch",
      "url": "https://github.com/switck/libngu/pull/61.patch",
      "organisation": "switck",
      "kind": "repo-patch",
      "role": "Repository patch",
      "publication_time": null,
      "note": "Patch content for the current upstream proposal. Kept separately from the conversation and review-state capture.",
      "gone": null,
      "capture": {
        "status": "held",
        "copies": 1,
        "first_observed": "2026-08-03T11:56:00Z",
        "last_observed": "2026-08-03T11:56:00Z",
        "last_checked": "2026-08-15T12:24:50Z"
      },
      "differences": []
    },
    {
      "id": "libngu-pr-62",
      "title": "libngu PR #62: HMAC_DRBG core, verified against NIST CAVP vectors",
      "url": "https://github.com/switck/libngu/pull/62",
      "organisation": "switck",
      "kind": "repo-pr",
      "role": "Repository pull request",
      "publication_time": null,
      "note": "First of the three-PR split of #59 that its author offered on 1 August, and the only one closed: at first capture on 7 Aug 2026 the page shows jgmontoya wanting to merge one commit and a state of Closed. The commit adds an HMAC_DRBG (SP 800-90A 10.1.2, SHA-256) as a self-contained core for the RNG rework that follows, built on the SHA-256 backend libngu already uses rather than on mbedtls' allocating HMAC layer, and states it was checked by a host-compiled harness against official NIST CAVP vectors through both backends. Registered from its own page because the record had been describing this stack from titles rendered on the #59 and #61 pages. Whether the closure was withdrawal, supersession or rejection is not stated on the captured page, and this project does not infer it.\n",
      "gone": null,
      "capture": {
        "status": "held",
        "copies": 4,
        "first_observed": "2026-08-07T15:45:24Z",
        "last_observed": "2026-08-14T08:25:12Z",
        "last_checked": "2026-08-15T12:24:53Z"
      },
      "differences": [
        {
          "observed_at": "2026-08-14T08:25:12Z",
          "window_start": "2026-08-12T04:36:36Z",
          "window_end": "2026-08-14T08:25:12Z",
          "status": "capture-noise",
          "summary": "Only GitHub header chrome changed. The 'Sign in' and 'Appearance settings' labels split onto separate lines, and the search prompt changed from 'Type / to search' to 'Search/'.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 5,
          "removed_lines": 3
        },
        {
          "observed_at": "2026-08-12T04:36:36Z",
          "window_start": "2026-08-07T19:21:57Z",
          "window_end": "2026-08-12T04:36:36Z",
          "status": "source-content",
          "summary": "The pull request state changed from Open to Merged, and the page rendered additional contributor labels.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 3,
          "removed_lines": 1
        },
        {
          "observed_at": "2026-08-07T19:21:57Z",
          "window_start": "2026-08-07T15:45:24Z",
          "window_end": "2026-08-07T19:21:57Z",
          "status": "source-content",
          "summary": "The pull request state changed from Open to Closed.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 1,
          "removed_lines": 1
        }
      ]
    },
    {
      "id": "libngu-pr-62-patch",
      "title": "libngu PR #62 patch",
      "url": "https://github.com/switck/libngu/pull/62.patch",
      "organisation": "switck",
      "kind": "repo-patch",
      "role": "Repository patch",
      "publication_time": null,
      "note": "Patch content for #62. Kept separately from the conversation and review-state capture.",
      "gone": null,
      "capture": {
        "status": "held",
        "copies": 1,
        "first_observed": "2026-08-07T15:45:31Z",
        "last_observed": "2026-08-07T15:45:31Z",
        "last_checked": "2026-08-15T12:24:55Z"
      },
      "differences": []
    },
    {
      "id": "libngu-pr-63",
      "title": "libngu PR #63: reject two-word entropy cycles",
      "url": "https://github.com/switck/libngu/pull/63",
      "organisation": "switck",
      "kind": "repo-pr",
      "role": "Repository pull request",
      "publication_time": null,
      "note": "Second of the three-PR split of #59, open at first capture on 7 Aug 2026 with one commit. Registered from its own page rather than from the title shown on #59 and #61.\n",
      "gone": null,
      "capture": {
        "status": "held",
        "copies": 4,
        "first_observed": "2026-08-07T15:45:26Z",
        "last_observed": "2026-08-14T08:25:17Z",
        "last_checked": "2026-08-15T12:24:58Z"
      },
      "differences": [
        {
          "observed_at": "2026-08-14T08:25:17Z",
          "window_start": "2026-08-12T04:36:45Z",
          "window_end": "2026-08-14T08:25:17Z",
          "status": "capture-noise",
          "summary": "Only GitHub header chrome changed. The 'Sign in' and 'Appearance settings' labels split onto separate lines, and the search prompt changed from 'Type / to search' to 'Search/'.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 5,
          "removed_lines": 3
        },
        {
          "observed_at": "2026-08-12T04:36:45Z",
          "window_start": "2026-08-07T19:22:03Z",
          "window_end": "2026-08-12T04:36:45Z",
          "status": "source-content",
          "summary": "The pull request state changed from Open to Merged, and the page rendered additional contributor labels.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 3,
          "removed_lines": 1
        },
        {
          "observed_at": "2026-08-07T19:22:03Z",
          "window_start": "2026-08-07T15:45:26Z",
          "window_end": "2026-08-07T19:22:03Z",
          "status": "source-content",
          "summary": "The author closed the pull request and posted a comment explaining that the extra A, B, A rejection is not justified by STM32 documentation or SP 800-90B and will be dropped from the rebase of #64.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 20,
          "removed_lines": 2
        }
      ]
    },
    {
      "id": "libngu-pr-63-patch",
      "title": "libngu PR #63 patch",
      "url": "https://github.com/switck/libngu/pull/63.patch",
      "organisation": "switck",
      "kind": "repo-patch",
      "role": "Repository patch",
      "publication_time": null,
      "note": "Patch content for #63. Kept separately from the conversation and review-state capture.",
      "gone": null,
      "capture": {
        "status": "held",
        "copies": 1,
        "first_observed": "2026-08-07T15:45:33Z",
        "last_observed": "2026-08-07T15:45:33Z",
        "last_checked": "2026-08-15T12:25:01Z"
      },
      "differences": []
    },
    {
      "id": "libngu-pr-64",
      "title": "libngu PR #64: harden entropy backends and state handling",
      "url": "https://github.com/switck/libngu/pull/64",
      "organisation": "switck",
      "kind": "repo-pr",
      "role": "Repository pull request",
      "publication_time": null,
      "note": "Third of the three-PR split of #59, open at first capture on 7 Aug 2026 with three commits: rejecting two-word entropy cycles, hardening entropy backend boundaries, and gating the backend contracts in tests. Registered from its own page rather than from the title shown on #59 and #61.\n",
      "gone": null,
      "capture": {
        "status": "held",
        "copies": 6,
        "first_observed": "2026-08-07T15:45:27Z",
        "last_observed": "2026-08-14T08:25:22Z",
        "last_checked": "2026-08-15T12:25:03Z"
      },
      "differences": [
        {
          "observed_at": "2026-08-14T08:25:22Z",
          "window_start": "2026-08-12T04:36:54Z",
          "window_end": "2026-08-14T08:25:22Z",
          "status": "capture-noise",
          "summary": "Only GitHub header chrome changed. The 'Sign in' and 'Appearance settings' labels split onto separate lines, and the search prompt changed from 'Type / to search' to 'Search/'.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 5,
          "removed_lines": 3
        },
        {
          "observed_at": "2026-08-12T04:36:54Z",
          "window_start": "2026-08-09T10:28:11Z",
          "window_end": "2026-08-12T04:36:54Z",
          "status": "source-content",
          "summary": "The pull request was merged, its commit count increased from three to four, and a new review comment addressed the MICROPY_PY_STM backend selector.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 39,
          "removed_lines": 6
        },
        {
          "observed_at": "2026-08-09T10:28:11Z",
          "window_start": "2026-08-08T01:52:36Z",
          "window_end": "2026-08-09T10:28:11Z",
          "status": "source-content",
          "summary": "Reviewer scgbckbone approved the pull request and left two comments, a general approval and a nit on the MICROPY_PY_STM conditional. The reviewer and participant counts updated accordingly.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 59,
          "removed_lines": 2
        },
        {
          "observed_at": "2026-08-08T01:52:36Z",
          "window_start": "2026-08-07T19:22:08Z",
          "window_end": "2026-08-08T01:52:36Z",
          "status": "source-content",
          "summary": "The pull-request description was rewritten to match a force-pushed branch with revised commits, including the backend gate matrix and updated contract language.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 56,
          "removed_lines": 29
        },
        {
          "observed_at": "2026-08-07T19:22:08Z",
          "window_start": "2026-08-07T15:45:27Z",
          "window_end": "2026-08-07T19:22:08Z",
          "status": "source-content",
          "summary": "The pull request state changed from Open to Closed.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 1,
          "removed_lines": 1
        }
      ]
    },
    {
      "id": "libngu-pr-64-patch",
      "title": "libngu PR #64 patch",
      "url": "https://github.com/switck/libngu/pull/64.patch",
      "organisation": "switck",
      "kind": "repo-patch",
      "role": "Repository patch",
      "publication_time": null,
      "note": "Patch content for #64. Kept separately from the conversation and review-state capture.",
      "gone": null,
      "capture": {
        "status": "held",
        "copies": 3,
        "first_observed": "2026-08-07T15:45:34Z",
        "last_observed": "2026-08-12T04:36:58Z",
        "last_checked": "2026-08-15T12:25:06Z"
      },
      "differences": [
        {
          "observed_at": "2026-08-12T04:36:58Z",
          "window_start": "2026-08-08T01:52:38Z",
          "window_end": "2026-08-12T04:36:58Z",
          "status": "source-content",
          "summary": "The published patch series grew from three to four commits, adding a compile-gate commit that selects the STM32 backend when the stm module is disabled.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 43,
          "removed_lines": 3
        },
        {
          "observed_at": "2026-08-08T01:52:38Z",
          "window_start": "2026-08-07T15:45:34Z",
          "window_end": "2026-08-08T01:52:38Z",
          "status": "source-content",
          "summary": "The published patch series was force-pushed, replacing the entropy-health commit with the backend-boundary commit and adding an external STM32 rng_get gate commit.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 104,
          "removed_lines": 206
        }
      ]
    },
    {
      "id": "libngu-pr-68",
      "title": "libngu PR #68: bugfix: coldcard external rng get",
      "url": "https://github.com/switck/libngu/pull/68",
      "organisation": "switck",
      "kind": "repo-pr",
      "role": "Repository pull request",
      "publication_time": null,
      "note": "Merged 7 Aug 2026. Referenced from Coldcard/firmware PR #707 as a required libngu change for the external RNG get path. Registered during the 7 Aug 2026 claim sweep to fill a source the record had been describing from titles on other pages.\n",
      "gone": null,
      "capture": {
        "status": "held",
        "copies": 2,
        "first_observed": "2026-08-07T18:03:36Z",
        "last_observed": "2026-08-14T08:25:28Z",
        "last_checked": "2026-08-15T12:25:09Z"
      },
      "differences": [
        {
          "observed_at": "2026-08-14T08:25:28Z",
          "window_start": "2026-08-07T18:03:36Z",
          "window_end": "2026-08-14T08:25:28Z",
          "status": "capture-noise",
          "summary": "Only GitHub header chrome changed. The 'Sign in' and 'Appearance settings' labels split onto separate lines, and the search prompt changed from 'Type / to search' to 'Search/'.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 5,
          "removed_lines": 3
        }
      ]
    },
    {
      "id": "libngu-pr-68-patch",
      "title": "libngu PR #68 patch",
      "url": "https://github.com/switck/libngu/pull/68.patch",
      "organisation": "switck",
      "kind": "repo-patch",
      "role": "Repository patch",
      "publication_time": null,
      "note": "Patch content for #68. Kept separately from the conversation and review-state capture.",
      "gone": null,
      "capture": {
        "status": "held",
        "copies": 1,
        "first_observed": "2026-08-07T18:03:37Z",
        "last_observed": "2026-08-07T18:03:37Z",
        "last_checked": "2026-08-15T12:25:11Z"
      },
      "differences": []
    },
    {
      "id": "libngu-pr-56",
      "title": "libngu PR #56: Make Schnorr & MuSig2 optional NGU features",
      "url": "https://github.com/switck/libngu/pull/56",
      "organisation": "switck",
      "kind": "repo-pr",
      "role": "Repository pull request",
      "publication_time": null,
      "note": "Merged 6 Aug 2026. Referenced from Coldcard/firmware PR #707 over flash-space concerns with the updated libngu dependency. Registered during the 7 Aug 2026 claim sweep to fill a source the record had been describing from titles on other pages.\n",
      "gone": null,
      "capture": {
        "status": "held",
        "copies": 2,
        "first_observed": "2026-08-07T18:03:39Z",
        "last_observed": "2026-08-14T08:25:33Z",
        "last_checked": "2026-08-15T12:25:14Z"
      },
      "differences": [
        {
          "observed_at": "2026-08-14T08:25:33Z",
          "window_start": "2026-08-07T18:03:39Z",
          "window_end": "2026-08-14T08:25:33Z",
          "status": "capture-noise",
          "summary": "Only GitHub header chrome changed. The 'Sign in' and 'Appearance settings' labels split onto separate lines, and the search prompt changed from 'Type / to search' to 'Search/'.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 5,
          "removed_lines": 3
        }
      ]
    },
    {
      "id": "libngu-pr-56-patch",
      "title": "libngu PR #56 patch",
      "url": "https://github.com/switck/libngu/pull/56.patch",
      "organisation": "switck",
      "kind": "repo-patch",
      "role": "Repository patch",
      "publication_time": null,
      "note": "Patch content for #56. Kept separately from the conversation and review-state capture.",
      "gone": null,
      "capture": {
        "status": "held",
        "copies": 1,
        "first_observed": "2026-08-07T18:03:41Z",
        "last_observed": "2026-08-07T18:03:41Z",
        "last_checked": "2026-08-15T12:25:16Z"
      },
      "differences": []
    },
    {
      "id": "coldcard-firmware-pr-691",
      "title": "COLDCARD firmware PR #691: pass the full secure-element digest",
      "url": "https://github.com/Coldcard/firmware/pull/691",
      "organisation": "Coinkite",
      "kind": "repo-pr",
      "role": "Repository pull request",
      "publication_time": null,
      "note": "Open incident-response proposal to remove the firmware-side four-byte truncation. Depends on the libngu PR #60 change.",
      "gone": null,
      "capture": {
        "status": "held",
        "copies": 8,
        "first_observed": "2026-08-01T06:21:15Z",
        "last_observed": "2026-08-14T23:42:14Z",
        "last_checked": "2026-08-15T12:25:19Z"
      },
      "differences": [
        {
          "observed_at": "2026-08-14T23:42:14Z",
          "window_start": "2026-08-14T08:25:39Z",
          "window_end": "2026-08-14T23:42:14Z",
          "status": "source-content",
          "summary": "The pull-request state changed from Draft to Closed, and doc-hex closed it on August 14, 2026.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 5,
          "removed_lines": 2
        },
        {
          "observed_at": "2026-08-14T08:25:39Z",
          "window_start": "2026-08-12T04:37:21Z",
          "window_end": "2026-08-14T08:25:39Z",
          "status": "capture-noise",
          "summary": "Only GitHub header chrome changed. The 'Sign in' and 'Appearance settings' labels split onto separate lines, and the search prompt changed from 'Type / to search' to 'Search/'.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 5,
          "removed_lines": 3
        },
        {
          "observed_at": "2026-08-12T04:37:21Z",
          "window_start": "2026-08-04T16:08:59Z",
          "window_end": "2026-08-12T04:37:21Z",
          "status": "source-content",
          "summary": "A reviewer noted that the change is already covered by PR #713 commit d16d47b and asked the author to close this draft, and a collaborator asked the author to double-check and close.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 40,
          "removed_lines": 1
        },
        {
          "observed_at": "2026-08-04T16:08:59Z",
          "window_start": "2026-08-01T17:41:21Z",
          "window_end": "2026-08-04T16:08:59Z",
          "status": "capture-noise",
          "summary": "Only GitHub navigation and search-dialog chrome rendered differently. The pull request content did not change.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 3,
          "removed_lines": 23
        },
        {
          "observed_at": "2026-08-01T17:41:21Z",
          "window_start": "2026-08-01T16:08:24Z",
          "window_end": "2026-08-01T17:41:21Z",
          "status": "source-content",
          "summary": "The author marked the pull request as a draft at 16:13 and rewrote its description. The submodule bump note became a re-pin to the companion RNG fix, and the stated dependency moved from switck/libngu#60 to #61, described as replacing the generator with a SHA-256 Hash-DRBG and making reseed() require a seed of at least 32 bytes, so this firmware change becomes a prerequisite for #61 booting on-device. GitHub edited-comment and loading-error chrome appeared in the same capture.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 17,
          "removed_lines": 9
        },
        {
          "observed_at": "2026-08-01T16:08:24Z",
          "window_start": "2026-08-01T07:34:40Z",
          "window_end": "2026-08-01T16:08:24Z",
          "status": "source-content",
          "summary": "The pull request gained a further comment repeating the request to raise the libngu changes as a separate pull request against the libngu repository, linking switck/libngu#60; reaction totals were normalized in the same capture.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 12,
          "removed_lines": 0
        },
        {
          "observed_at": "2026-08-01T07:34:40Z",
          "window_start": "2026-08-01T06:21:15Z",
          "window_end": "2026-08-01T07:34:40Z",
          "status": "source-content",
          "summary": "A COLDCARD firmware collaborator asked the author to move the libngu changes into a separate pull request; GitHub review metadata and navigation chrome also changed.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 31,
          "removed_lines": 2
        }
      ]
    },
    {
      "id": "coldcard-firmware-pr-707",
      "title": "COLDCARD firmware PR #707: require external entropy for each new wallet",
      "url": "https://github.com/Coldcard/firmware/pull/707",
      "organisation": "Coinkite",
      "kind": "repo-pr",
      "role": "Repository pull request",
      "publication_time": null,
      "note": "A seven-commit proposal in the vendor's own firmware repository, open at first capture on 7 Aug 2026, opened by scgbckbone from a branch named improve_seed_gen-public. Its commits mix secure-element entropy into seed generation, reseed with the full 32-byte digest rather than a truncated one, require external entropy for every new master seed and for CCC and temporary seeds, warn before dice-only seed generation, and bump libngu so that the SHA-256 Hash-DRBG replaces Yasmarang. Registered 7 Aug 2026 after being reported in reddit-user-entropy-options; it is the vendor-side counterpart to the upstream libngu proposals already held, and its state is whatever the newest capture shows rather than what the record said when it was registered.\n",
      "gone": null,
      "capture": {
        "status": "held",
        "copies": 4,
        "first_observed": "2026-08-07T15:45:35Z",
        "last_observed": "2026-08-14T23:42:17Z",
        "last_checked": "2026-08-15T12:25:21Z"
      },
      "differences": [
        {
          "observed_at": "2026-08-14T23:42:17Z",
          "window_start": "2026-08-14T08:25:42Z",
          "window_end": "2026-08-14T23:42:17Z",
          "status": "source-content",
          "summary": "The pull-request state changed from Open to Closed.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 1,
          "removed_lines": 1
        },
        {
          "observed_at": "2026-08-14T08:25:42Z",
          "window_start": "2026-08-07T19:22:26Z",
          "window_end": "2026-08-14T08:25:42Z",
          "status": "capture-noise",
          "summary": "Only GitHub header chrome changed. The 'Sign in' and 'Appearance settings' labels split onto separate lines, and the search prompt changed from 'Type / to search' to 'Search/'.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 5,
          "removed_lines": 3
        },
        {
          "observed_at": "2026-08-07T19:22:26Z",
          "window_start": "2026-08-07T15:45:35Z",
          "window_end": "2026-08-07T19:22:26Z",
          "status": "source-content",
          "summary": "The author closed the pull request and commented that it is replaced by strictly better #713, which improves seed generation with microsecond-resolution timing.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 23,
          "removed_lines": 2
        }
      ]
    },
    {
      "id": "coldcard-firmware-pr-707-patch",
      "title": "COLDCARD firmware PR #707 patch",
      "url": "https://github.com/Coldcard/firmware/pull/707.patch",
      "organisation": "Coinkite",
      "kind": "repo-patch",
      "role": "Repository patch",
      "publication_time": null,
      "note": "Patch content for #707. Kept separately from the conversation and review-state capture.",
      "gone": null,
      "capture": {
        "status": "held",
        "copies": 1,
        "first_observed": "2026-08-07T15:45:37Z",
        "last_observed": "2026-08-07T15:45:37Z",
        "last_checked": "2026-08-15T12:25:24Z"
      },
      "differences": []
    },
    {
      "id": "coldcard-firmware-pr-713",
      "title": "COLDCARD firmware PR #713: improve seed generation - mash timing with microsecond-resolution",
      "url": "https://github.com/Coldcard/firmware/pull/713",
      "organisation": "Coinkite",
      "kind": "repo-pr",
      "role": "Repository pull request",
      "publication_time": null,
      "note": "Opened by scgbckbone 7 Aug 2026 and explicitly aims to replace PR #707. It improves #707's mash method by hashing microsecond-resolution timing at the raw key edge, requires 128 presses, and credits one timing bit per press following Peter Todd's push-button RNG model. Registered during the 7 Aug 2026 claim sweep when #707 was found closed in favour of this proposal.\n",
      "gone": null,
      "capture": {
        "status": "held",
        "copies": 7,
        "first_observed": "2026-08-07T18:03:42Z",
        "last_observed": "2026-08-14T23:42:23Z",
        "last_checked": "2026-08-15T12:25:27Z"
      },
      "differences": [
        {
          "observed_at": "2026-08-14T23:42:23Z",
          "window_start": "2026-08-14T08:25:49Z",
          "window_end": "2026-08-14T23:42:23Z",
          "status": "source-content",
          "summary": "The pull request was merged after a force-push replaced its commit series with eight rewritten commits, and scgbckbone commented that it is superseded by #727.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 60,
          "removed_lines": 32
        },
        {
          "observed_at": "2026-08-14T08:25:49Z",
          "window_start": "2026-08-13T19:25:48Z",
          "window_end": "2026-08-14T08:25:49Z",
          "status": "capture-noise",
          "summary": "Only GitHub header chrome changed. The 'Sign in' and 'Appearance settings' labels split onto separate lines, and the search prompt changed from 'Type / to search' to 'Search/'.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 5,
          "removed_lines": 3
        },
        {
          "observed_at": "2026-08-13T19:25:48Z",
          "window_start": "2026-08-13T12:54:18Z",
          "window_end": "2026-08-13T19:25:48Z",
          "status": "source-content",
          "summary": "The pull-request event log updated from two force-pushes to three, recording a new force-push of the improve_seed_gen-mash-timing branch from 69edb16 to c81f966 at 14:15 UTC on 13 August 2026.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 13,
          "removed_lines": 13
        },
        {
          "observed_at": "2026-08-13T12:54:18Z",
          "window_start": "2026-08-12T17:26:02Z",
          "window_end": "2026-08-13T12:54:18Z",
          "status": "source-content",
          "summary": "The pull request gained an eighth commit and a new author comment responding to review feedback, explaining why timing resolution, set-size crediting and API scope were kept as-is while unifying dice, coin and mash collectors and their on-screen strings.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 55,
          "removed_lines": 3
        },
        {
          "observed_at": "2026-08-12T17:26:02Z",
          "window_start": "2026-08-12T04:37:37Z",
          "window_end": "2026-08-12T17:26:02Z",
          "status": "source-content",
          "summary": "A new comment from doc-hex proposed unifying dice, mosh and coin-flip UX, crediting entropy by the set size of unique values received, and using a hardware timer at maximum speed sampled on key-edge events rather than precise key-gap timing. GitHub loading-error chrome and the participant count also changed.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 22,
          "removed_lines": 1
        },
        {
          "observed_at": "2026-08-12T04:37:37Z",
          "window_start": "2026-08-07T18:03:42Z",
          "window_end": "2026-08-12T04:37:37Z",
          "status": "source-content",
          "summary": "The branch was force-pushed to commit 11d8130 with a five-commit series, and the conversation gained cross-references to PR #691 and #700 plus an author self-review comment.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 78,
          "removed_lines": 15
        }
      ]
    },
    {
      "id": "coldcard-firmware-pr-713-patch",
      "title": "COLDCARD firmware PR #713 patch",
      "url": "https://github.com/Coldcard/firmware/pull/713.patch",
      "organisation": "Coinkite",
      "kind": "repo-patch",
      "role": "Repository patch",
      "publication_time": null,
      "note": "Patch content for #713. Kept separately from the conversation and review-state capture.",
      "gone": null,
      "capture": {
        "status": "held",
        "copies": 5,
        "first_observed": "2026-08-07T18:03:44Z",
        "last_observed": "2026-08-14T23:42:25Z",
        "last_checked": "2026-08-15T12:25:29Z"
      },
      "differences": [
        {
          "observed_at": "2026-08-14T23:42:25Z",
          "window_start": "2026-08-13T19:25:51Z",
          "window_end": "2026-08-14T23:42:25Z",
          "status": "source-content",
          "summary": "The patch series was rewritten with new commit hashes and each commit now carries a bugfix note about preventing Seed Vault access through Seed XOR restore in Delta Mode.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 27,
          "removed_lines": 22
        },
        {
          "observed_at": "2026-08-13T19:25:51Z",
          "window_start": "2026-08-13T12:54:21Z",
          "window_end": "2026-08-13T19:25:51Z",
          "status": "source-content",
          "summary": "The published patch was rewritten at commit c81f966: the diff shrank, symbol-entropy specs were refactored from a tuple of dicts into a namedtuple, coin-flip minimums and derived domain separators were introduced, and the key-mashing collector switched to a PressRelease helper.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 73,
          "removed_lines": 83
        },
        {
          "observed_at": "2026-08-13T12:54:21Z",
          "window_start": "2026-08-12T04:37:41Z",
          "window_end": "2026-08-13T12:54:21Z",
          "status": "source-content",
          "summary": "The published patch series expanded from seven to eight commits, adding a patch that deduplicates dice and coin entropy collection into a shared symbol collector and refactors mash key handling.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 290,
          "removed_lines": 7
        },
        {
          "observed_at": "2026-08-12T04:37:41Z",
          "window_start": "2026-08-07T18:03:44Z",
          "window_end": "2026-08-12T04:37:41Z",
          "status": "source-content",
          "summary": "The published patch was force-pushed, replacing the earlier seven-commit series with a five-commit series that revises the mash-entropy implementation, adds a testing fixture, and disables MicroPython threads for the unix port.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 68,
          "removed_lines": 53
        }
      ]
    },
    {
      "id": "coldcard-firmware-pr-697",
      "title": "COLDCARD firmware PR #697: feed full SE hash into ngu.random.reseed",
      "url": "https://github.com/Coldcard/firmware/pull/697",
      "organisation": "Coinkite",
      "kind": "repo-pr",
      "role": "Repository pull request",
      "publication_time": null,
      "note": "Closed unmerged 5 Aug 2026. Referenced from the Coldcard/firmware PR #707 page as the earlier full-width reseed proposal; the page says it was superseded by #707. Registered during the 7 Aug 2026 claim sweep to fill a source the record had been describing from titles on other pages.\n",
      "gone": null,
      "capture": {
        "status": "held",
        "copies": 2,
        "first_observed": "2026-08-07T18:03:46Z",
        "last_observed": "2026-08-14T08:25:54Z",
        "last_checked": "2026-08-15T12:25:32Z"
      },
      "differences": [
        {
          "observed_at": "2026-08-14T08:25:54Z",
          "window_start": "2026-08-07T18:03:46Z",
          "window_end": "2026-08-14T08:25:54Z",
          "status": "capture-noise",
          "summary": "Only GitHub header chrome changed. The 'Sign in' and 'Appearance settings' labels split onto separate lines, and the search prompt changed from 'Type / to search' to 'Search/'.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 5,
          "removed_lines": 3
        }
      ]
    },
    {
      "id": "coldcard-firmware-pr-697-patch",
      "title": "COLDCARD firmware PR #697 patch",
      "url": "https://github.com/Coldcard/firmware/pull/697.patch",
      "organisation": "Coinkite",
      "kind": "repo-patch",
      "role": "Repository patch",
      "publication_time": null,
      "note": "Patch content for #697. Kept separately from the conversation and review-state capture.",
      "gone": null,
      "capture": {
        "status": "held",
        "copies": 1,
        "first_observed": "2026-08-07T18:03:47Z",
        "last_observed": "2026-08-07T18:03:47Z",
        "last_checked": "2026-08-15T12:25:34Z"
      },
      "differences": []
    },
    {
      "id": "coldcard-firmware-pr-691-patch",
      "title": "COLDCARD firmware PR #691 patch",
      "url": "https://github.com/Coldcard/firmware/pull/691.patch",
      "organisation": "Coinkite",
      "kind": "repo-patch",
      "role": "Repository patch",
      "publication_time": null,
      "note": "Patch content for the open firmware-side full-digest proposal. Kept separately from the conversation and review-state capture.",
      "gone": null,
      "capture": {
        "status": "held",
        "copies": 2,
        "first_observed": "2026-08-01T06:39:34Z",
        "last_observed": "2026-08-06T03:22:47Z",
        "last_checked": "2026-08-15T12:25:37Z"
      },
      "differences": [
        {
          "observed_at": "2026-08-06T03:22:47Z",
          "window_start": "2026-08-01T06:39:34Z",
          "window_end": "2026-08-06T03:22:47Z",
          "status": "capture-noise",
          "summary": "Only the displayed Git patch index abbreviations gained one hexadecimal character. The patch content did not change.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 2,
          "removed_lines": 2
        }
      ]
    },
    {
      "id": "coldcard-firmware-pr-692",
      "title": "COLDCARD firmware PR #692: recover the TRNG after a seed/clock error",
      "url": "https://github.com/Coldcard/firmware/pull/692",
      "organisation": "Coinkite",
      "kind": "repo-pr",
      "role": "Repository pull request",
      "publication_time": null,
      "note": "Community proposal (Silexperience210, 3 Aug 2026) arguing the 31 July hotfix leaves the STM32 RNG latched after a single seed/clock error, so every later call faults forever; proposed a recovery path. Closed unmerged. Related to the post-hotfix bricking reports.",
      "gone": null,
      "capture": {
        "status": "held",
        "copies": 3,
        "first_observed": "2026-08-05T03:49:01Z",
        "last_observed": "2026-08-14T08:26:02Z",
        "last_checked": "2026-08-15T12:25:39Z"
      },
      "differences": [
        {
          "observed_at": "2026-08-14T08:26:02Z",
          "window_start": "2026-08-05T14:18:56Z",
          "window_end": "2026-08-14T08:26:02Z",
          "status": "capture-noise",
          "summary": "Only GitHub header chrome changed. The 'Sign in' and 'Appearance settings' labels split onto separate lines, and the search prompt changed from 'Type / to search' to 'Search/'.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 5,
          "removed_lines": 3
        },
        {
          "observed_at": "2026-08-05T14:18:56Z",
          "window_start": "2026-08-05T03:49:01Z",
          "window_end": "2026-08-05T14:18:56Z",
          "status": "source-content",
          "summary": "No change to this pull request's own state: #692 remains Closed, closed unmerged by its author on 4 August 2026. The detected difference is the cross-referenced #693 entry on the page flipping from Open to Merged; #693 was merged into Coldcard/firmware master on 5 August 2026. (Hand-corrected 6 Aug 2026; the agent classification misread the reference badge as this PR's own status.)",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 1,
          "removed_lines": 1
        }
      ]
    },
    {
      "id": "coldcard-firmware-pr-692-patch",
      "title": "COLDCARD firmware PR #692 patch",
      "url": "https://github.com/Coldcard/firmware/pull/692.patch",
      "organisation": "Coinkite",
      "kind": "repo-patch",
      "role": "Repository patch",
      "publication_time": null,
      "note": "Patch content for the TRNG error-recovery proposal. Kept separately from the conversation and review-state capture.",
      "gone": null,
      "capture": {
        "status": "held",
        "copies": 1,
        "first_observed": "2026-08-05T03:49:02Z",
        "last_observed": "2026-08-05T03:49:02Z",
        "last_checked": "2026-08-15T12:25:42Z"
      },
      "differences": []
    },
    {
      "id": "coldcard-firmware-pr-693",
      "title": "COLDCARD firmware PR #693: detect RNG_SR_SEIS and RNG_SR_SECS, retry and fail closed",
      "url": "https://github.com/Coldcard/firmware/pull/693",
      "organisation": "Coinkite",
      "kind": "repo-pr",
      "role": "Repository pull request",
      "publication_time": null,
      "note": "Bugfix (scgbckbone, 3 Aug 2026) detecting the STM32 RNG status error flags, retrying safely and failing closed. Named by Coinkite's 4 Aug 2026 notice as the fix for the post-hotfix TRNG fault behind the bricking reports.",
      "gone": null,
      "capture": {
        "status": "held",
        "copies": 3,
        "first_observed": "2026-08-06T02:39:12Z",
        "last_observed": "2026-08-14T08:26:07Z",
        "last_checked": "2026-08-15T12:25:45Z"
      },
      "differences": [
        {
          "observed_at": "2026-08-14T08:26:07Z",
          "window_start": "2026-08-13T19:26:09Z",
          "window_end": "2026-08-14T08:26:07Z",
          "status": "capture-noise",
          "summary": "Only GitHub header chrome changed. The 'Sign in' and 'Appearance settings' labels split onto separate lines, and the search prompt changed from 'Type / to search' to 'Search/'.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 5,
          "removed_lines": 3
        },
        {
          "observed_at": "2026-08-13T19:26:09Z",
          "window_start": "2026-08-06T02:39:12Z",
          "window_end": "2026-08-13T19:26:09Z",
          "status": "source-content",
          "summary": "The pull-request status changed from Open to Merged.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 1,
          "removed_lines": 1
        }
      ]
    },
    {
      "id": "coldcard-firmware-pr-693-patch",
      "title": "COLDCARD firmware PR #693 patch",
      "url": "https://github.com/Coldcard/firmware/pull/693.patch",
      "organisation": "Coinkite",
      "kind": "repo-patch",
      "role": "Repository patch",
      "publication_time": null,
      "note": "Patch content for the RNG error-flag detection and retry proposal. Kept separately from the conversation and review-state capture.",
      "gone": null,
      "capture": {
        "status": "held",
        "copies": 1,
        "first_observed": "2026-08-06T02:39:25Z",
        "last_observed": "2026-08-06T02:39:25Z",
        "last_checked": "2026-08-15T12:25:47Z"
      },
      "differences": []
    },
    {
      "id": "coldcard-firmware-pr-689",
      "title": "COLDCARD firmware PR #689: Mk3 RNG hotfix",
      "url": "https://github.com/Coldcard/firmware/pull/689",
      "organisation": "Coinkite",
      "kind": "repo-pr",
      "role": "Repository pull request",
      "publication_time": null,
      "note": "Merged source-level Mk3 hotfix. Captures the pull-request provenance and merged source commit associated with 4.2.0; the signed release record is separate.",
      "gone": null,
      "capture": {
        "status": "held",
        "copies": 3,
        "first_observed": "2026-08-01T06:23:08Z",
        "last_observed": "2026-08-14T09:53:53Z",
        "last_checked": "2026-08-15T12:53:01Z"
      },
      "differences": [
        {
          "observed_at": "2026-08-14T09:53:53Z",
          "window_start": "2026-08-04T16:18:51Z",
          "window_end": "2026-08-14T09:53:53Z",
          "status": "capture-noise",
          "summary": "Only GitHub header chrome changed. The 'Sign in' and 'Appearance settings' labels split onto separate lines, and the search prompt changed from 'Type / to search' to 'Search/'. The pull request content was unchanged.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 5,
          "removed_lines": 3
        },
        {
          "observed_at": "2026-08-04T16:18:51Z",
          "window_start": "2026-08-01T06:23:08Z",
          "window_end": "2026-08-04T16:18:51Z",
          "status": "capture-noise",
          "summary": "Only GitHub navigation and search-dialog chrome rendered differently. The pull request content did not change.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 3,
          "removed_lines": 23
        }
      ]
    },
    {
      "id": "coldcard-firmware-pr-689-patch",
      "title": "COLDCARD firmware PR #689 patch",
      "url": "https://github.com/Coldcard/firmware/pull/689.patch",
      "organisation": "Coinkite",
      "kind": "repo-patch",
      "role": "Repository patch",
      "publication_time": null,
      "note": "Patch content for the merged Mk3 v4-legacy hotfix. Kept separately from the pull-request conversation capture.",
      "gone": null,
      "capture": {
        "status": "held",
        "copies": 1,
        "first_observed": "2026-08-01T06:39:35Z",
        "last_observed": "2026-08-01T06:39:35Z",
        "last_checked": "2026-08-15T12:53:04Z"
      },
      "differences": []
    },
    {
      "id": "coldcard-firmware-pr-690",
      "title": "COLDCARD firmware PR #690: Edge RNG hotfix",
      "url": "https://github.com/Coldcard/firmware/pull/690",
      "organisation": "Coinkite",
      "kind": "repo-pr",
      "role": "Repository pull request",
      "publication_time": null,
      "note": "Merged Edge source and release-history integration. Captures the pull-request provenance behind the published 6.6.0X and 6.6.0QX releases.",
      "gone": null,
      "capture": {
        "status": "held",
        "copies": 3,
        "first_observed": "2026-08-01T06:23:13Z",
        "last_observed": "2026-08-14T09:53:58Z",
        "last_checked": "2026-08-15T12:53:06Z"
      },
      "differences": [
        {
          "observed_at": "2026-08-14T09:53:58Z",
          "window_start": "2026-08-04T16:18:57Z",
          "window_end": "2026-08-14T09:53:58Z",
          "status": "capture-noise",
          "summary": "Only GitHub header chrome changed. The 'Sign in' and 'Appearance settings' labels split onto separate lines, and the search prompt changed from 'Type / to search' to 'Search/'. The pull request content was unchanged.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 5,
          "removed_lines": 3
        },
        {
          "observed_at": "2026-08-04T16:18:57Z",
          "window_start": "2026-08-01T06:23:13Z",
          "window_end": "2026-08-04T16:18:57Z",
          "status": "capture-noise",
          "summary": "Only GitHub navigation and search-dialog chrome rendered differently. The pull request content did not change.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 3,
          "removed_lines": 23
        }
      ]
    },
    {
      "id": "coldcard-firmware-pr-690-patch",
      "title": "COLDCARD firmware PR #690 patch",
      "url": "https://github.com/Coldcard/firmware/pull/690.patch",
      "organisation": "Coinkite",
      "kind": "repo-patch",
      "role": "Repository patch",
      "publication_time": null,
      "note": "Patch content for the merged Edge hotfix. Kept separately from the pull-request conversation capture.",
      "gone": null,
      "capture": {
        "status": "held",
        "copies": 1,
        "first_observed": "2026-08-01T06:39:36Z",
        "last_observed": "2026-08-01T06:39:36Z",
        "last_checked": "2026-08-15T12:53:09Z"
      },
      "differences": []
    },
    {
      "id": "coldcard-firmware-mainline-hotfix",
      "title": "COLDCARD mainline RNG hotfix commit ca724637",
      "url": "https://github.com/Coldcard/firmware/commit/ca72463709f4e3f8964952039d5caf955f566a87.patch",
      "organisation": "Coinkite",
      "kind": "repo-commit",
      "role": "Repository commit",
      "publication_time": null,
      "note": "Immutable patch for the direct mainline source commit contained in the normal Mk4/Mk5 v5.6.0 and Q v1.5.0Q release histories.",
      "gone": null,
      "capture": {
        "status": "held",
        "copies": 1,
        "first_observed": "2026-08-01T06:39:38Z",
        "last_observed": "2026-08-01T06:39:38Z",
        "last_checked": "2026-08-15T12:53:11Z"
      },
      "differences": []
    },
    {
      "id": "bitcoinorg-pr-4905",
      "title": "Bitcoin.org PR #4905: remove COLDCARD listings",
      "url": "https://github.com/bitcoin-dot-org/Bitcoin.org/pull/4905",
      "organisation": "Bitcoin.org",
      "kind": "repo-pr",
      "role": "Repository pull request",
      "publication_time": null,
      "note": "Merged community-response record. Bitcoin.org removed its COLDCARD and COLDCARD Q listings under the site's published wallet-listing criterion after the incident.",
      "gone": null,
      "capture": {
        "status": "held",
        "copies": 5,
        "first_observed": "2026-08-01T06:25:42Z",
        "last_observed": "2026-08-14T09:54:05Z",
        "last_checked": "2026-08-15T12:53:13Z"
      },
      "differences": [
        {
          "observed_at": "2026-08-14T09:54:05Z",
          "window_start": "2026-08-06T10:09:10Z",
          "window_end": "2026-08-14T09:54:05Z",
          "status": "capture-noise",
          "summary": "Only GitHub header chrome changed. The 'Sign in' and 'Appearance settings' labels split onto separate lines, and the search prompt changed from 'Type / to search' to 'Search/'. The pull request content was unchanged.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 5,
          "removed_lines": 3
        },
        {
          "observed_at": "2026-08-06T10:09:10Z",
          "window_start": "2026-08-04T16:19:05Z",
          "window_end": "2026-08-06T10:09:10Z",
          "status": "source-content",
          "summary": "The linked issue #4906 (\"Actual live website is stuck behind master\") shown on the PR page changed state from Open to Closed.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 1,
          "removed_lines": 1
        },
        {
          "observed_at": "2026-08-04T16:19:05Z",
          "window_start": "2026-08-02T15:01:15Z",
          "window_end": "2026-08-04T16:19:05Z",
          "status": "capture-noise",
          "summary": "Only GitHub navigation and search-dialog chrome rendered differently. The pull request content did not change.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 3,
          "removed_lines": 23
        },
        {
          "observed_at": "2026-08-02T15:01:15Z",
          "window_start": "2026-08-01T06:25:42Z",
          "window_end": "2026-08-02T15:01:15Z",
          "status": "source-content",
          "summary": "The PR timeline gained a cross-reference: Overtorment mentioned PR 4905 from the newly opened PR 4906, titled Actual live website is stuck behind master.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 6,
          "removed_lines": 0
        }
      ]
    },
    {
      "id": "satsigner-pr-468",
      "title": "SatSigner PR #468: entropy audit and hardening",
      "url": "https://github.com/satsigner/satsigner/pull/468",
      "organisation": "SatSigner",
      "kind": "repo-pr",
      "role": "Repository pull request",
      "publication_time": null,
      "note": "Open downstream response prompted by the COLDCARD disclosure. The author reports that SatSigner's default path was sound and proposes fixes for separate optional dice and coin paths.",
      "gone": null,
      "capture": {
        "status": "held",
        "copies": 7,
        "first_observed": "2026-08-01T06:25:47Z",
        "last_observed": "2026-08-14T08:26:13Z",
        "last_checked": "2026-08-15T12:25:50Z"
      },
      "differences": [
        {
          "observed_at": "2026-08-14T08:26:13Z",
          "window_start": "2026-08-04T16:09:04Z",
          "window_end": "2026-08-14T08:26:13Z",
          "status": "capture-noise",
          "summary": "Only GitHub header chrome changed. The 'Sign in' and 'Appearance settings' labels split onto separate lines, and the search prompt changed from 'Type / to search' to 'Search/'. The pull request content was unchanged.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 5,
          "removed_lines": 3
        },
        {
          "observed_at": "2026-08-04T16:09:04Z",
          "window_start": "2026-08-04T13:38:00Z",
          "window_end": "2026-08-04T16:09:04Z",
          "status": "capture-noise",
          "summary": "Only GitHub navigation and search-dialog chrome rendered differently. The pull request content did not change.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 3,
          "removed_lines": 23
        },
        {
          "observed_at": "2026-08-04T13:38:00Z",
          "window_start": "2026-08-03T18:44:41Z",
          "window_end": "2026-08-04T13:38:00Z",
          "status": "source-content",
          "summary": "A referenced commit was added, resolving translation-key conflicts and adopting the entropy coin and dice descriptions from this pull request.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 12,
          "removed_lines": 0
        },
        {
          "observed_at": "2026-08-03T18:44:41Z",
          "window_start": "2026-08-03T14:43:05Z",
          "window_end": "2026-08-03T18:44:41Z",
          "status": "source-content",
          "summary": "The entropy-hardening PR was merged: pedromvpg approved, Psycarlo merged 9 commits into master on Aug 3 and deleted the fix/entropy branch. Two late commits (\"fix: fixes\", \"fix: lint\") were added since the previous capture.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 33,
          "removed_lines": 9
        },
        {
          "observed_at": "2026-08-03T14:43:05Z",
          "window_start": "2026-08-03T13:13:55Z",
          "window_end": "2026-08-03T14:43:05Z",
          "status": "source-content",
          "summary": "The pull request grew from 2 commits to 7, and its commit tab and file counts changed with it.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 85,
          "removed_lines": 30
        },
        {
          "observed_at": "2026-08-03T13:13:55Z",
          "window_start": "2026-08-01T06:25:47Z",
          "window_end": "2026-08-03T13:13:55Z",
          "status": "source-content",
          "summary": "Pull request 468 went from one commit to two: a merge of master into the fix/entropy branch (commit 4b7824f) was added on top of the original entropy-hardening commit, and the participant count rose from one to two. The PR remains open.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 6,
          "removed_lines": 4
        }
      ]
    },
    {
      "id": "seedsigner-pr-962",
      "title": "SeedSigner PR #962: withdrawn camera-entropy hardening proposal",
      "url": "https://github.com/SeedSigner/seedsigner/pull/962",
      "organisation": "SeedSigner",
      "kind": "repo-pr",
      "role": "Repository pull request",
      "publication_time": null,
      "note": "Closed without merge after the author said the proposed histogram thresholds did not measure sensor entropy. Retained as a correction record, not evidence of a SeedSigner vulnerability.",
      "gone": null,
      "capture": {
        "status": "held",
        "copies": 5,
        "first_observed": "2026-08-01T06:25:52Z",
        "last_observed": "2026-08-14T09:54:08Z",
        "last_checked": "2026-08-15T12:53:16Z"
      },
      "differences": [
        {
          "observed_at": "2026-08-14T09:54:08Z",
          "window_start": "2026-08-07T14:21:23Z",
          "window_end": "2026-08-14T09:54:08Z",
          "status": "capture-noise",
          "summary": "Only GitHub header chrome changed. The 'Sign in' and 'Appearance settings' labels split onto separate lines, and the search prompt changed from 'Type / to search' to 'Search/'. The pull request content was unchanged.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 5,
          "removed_lines": 3
        },
        {
          "observed_at": "2026-08-07T14:21:23Z",
          "window_start": "2026-08-04T16:19:08Z",
          "window_end": "2026-08-07T14:21:23Z",
          "status": "capture-noise",
          "summary": "GitHub timeline chrome only: the cross-referenced PR #980 card in the timeline now renders a 19 tasks counter. The closed pull request's own content did not change.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 1,
          "removed_lines": 0
        },
        {
          "observed_at": "2026-08-04T16:19:08Z",
          "window_start": "2026-08-04T03:05:52Z",
          "window_end": "2026-08-04T16:19:08Z",
          "status": "capture-noise",
          "summary": "Only GitHub navigation and search-dialog chrome rendered differently. The pull request content did not change.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 3,
          "removed_lines": 23
        },
        {
          "observed_at": "2026-08-04T03:05:52Z",
          "window_start": "2026-08-01T06:25:52Z",
          "window_end": "2026-08-04T03:05:52Z",
          "status": "source-content",
          "summary": "The pull request timeline gained a cross-reference: ronaldstoner mentioned PR #962 from the open PR #980, 'tests: add some entropy pipeline regression tests with NIST SP 800-22...', on Aug 4, 2026. The PR itself remains closed.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 6,
          "removed_lines": 0
        }
      ]
    },
    {
      "id": "coinkite-terms",
      "title": "Coinkite terms of sale",
      "url": "https://coinkite.com/terms",
      "organisation": "Coinkite",
      "kind": "vendor-legal",
      "role": "Legal terms",
      "publication_time": "2024-11-27",
      "note": "Terms of Sale. Caps aggregate liability at the purchase price, disclaims\nwarranties, reserves arbitration at Coinkite's sole option, waives class actions\nand selects Ontario law. Quoted on /response/legal/ alongside sections 2, 7 and\n8 of Ontario's Consumer Protection Act, 2002, which e-Laws listed as in force\nwhen checked on 1 Aug 2026. Whether those provisions apply to a particular\nbuyer or claim requires case-specific legal analysis. The terms are retained\nfor dated revision comparison.\n",
      "gone": null,
      "capture": {
        "status": "held",
        "copies": 3,
        "first_observed": "2026-08-01T03:25:25Z",
        "last_observed": "2026-08-08T14:56:50Z",
        "last_checked": "2026-08-15T12:25:53Z"
      },
      "differences": [
        {
          "observed_at": "2026-08-08T14:56:50Z",
          "window_start": "2026-08-01T16:08:33Z",
          "window_end": "2026-08-08T14:56:50Z",
          "status": "source-content",
          "summary": "The terms page replaced the 'COLDCARD Security Advisory' banner with a 'COLDCARD Security Status' banner stating that fixed firmware is available and affected seeds still require migration, and added a link to the Security & Transparency directory.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 5,
          "removed_lines": 3
        },
        {
          "observed_at": "2026-08-01T16:08:33Z",
          "window_start": "2026-08-01T03:25:25Z",
          "window_end": "2026-08-01T16:08:33Z",
          "status": "source-content",
          "summary": "The site-wide advisory banner on the terms page hardened from 'Seeds generated on firmware 4.0.1 or later may be at risk' to 'Seeds generated on firmware 4.0.1 (2021 or later) are at risk', matching the downloads page.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 1,
          "removed_lines": 1
        }
      ]
    },
    {
      "id": "ontario-consumer-protection-act-2002",
      "title": "Consumer Protection Act, 2002",
      "url": "https://www.ontario.ca/laws/statute/02c30",
      "organisation": "Ontario e-Laws",
      "kind": "government-legal",
      "role": "Government legislation",
      "publication_time": null,
      "note": "Official current consolidation used for the application, non-waiver, arbitration and class-proceeding provisions summarised on the legal-context page.",
      "gone": null,
      "capture": {
        "status": "held",
        "copies": 1,
        "first_observed": "2026-08-01T09:15:18Z",
        "last_observed": "2026-08-01T09:15:18Z",
        "last_checked": "2026-08-15T12:25:55Z"
      },
      "differences": []
    },
    {
      "id": "ontario-consumer-protection-act-2023",
      "title": "Consumer Protection Act, 2023",
      "url": "https://www.ontario.ca/laws/statute/23c23",
      "organisation": "Ontario e-Laws",
      "kind": "government-legal",
      "role": "Government legislation",
      "publication_time": null,
      "note": "Official statute page used to check commencement status. The page stated on 1 August 2026 that the Act was not yet in force and would commence by proclamation.",
      "gone": null,
      "capture": {
        "status": "held",
        "copies": 1,
        "first_observed": "2026-08-01T09:15:20Z",
        "last_observed": "2026-08-01T09:15:20Z",
        "last_checked": "2026-08-15T12:25:58Z"
      },
      "differences": []
    },
    {
      "id": "block-disclosure",
      "title": "Predictable RNG fallback and 32-bit reseed",
      "url": "https://engineering.block.xyz/blog/predictable-rng-fallback-and-32-bit-reseed-in-coldcard-firmware",
      "organisation": "Block",
      "kind": "research",
      "role": "Primary technical research",
      "publication_time": "2026-07-30",
      "note": null,
      "gone": null,
      "capture": {
        "status": "held",
        "copies": 2,
        "first_observed": "2026-07-31T03:29:24Z",
        "last_observed": "2026-08-01T00:17:31Z",
        "last_checked": "2026-08-15T12:53:19Z"
      },
      "differences": []
    },
    {
      "id": "threez-mk3-rng-disclosure",
      "title": "Mk3 binary reversal and bounded proof of concept",
      "url": "https://raw.githubusercontent.com/3z/coldcard-mk3-rng-disclosure/main/README.md",
      "organisation": "3z",
      "kind": "independent-analysis",
      "role": "Independent primary analysis",
      "publication_time": "2026-07-31",
      "note": "Independent binary-level comparison of vulnerable and fixed Mk3 firmware, with\na synthetic proof of concept. The repository deliberately excludes enumeration,\nwallet-recovery and fund-targeting capability. Its candidate-state analysis is\nthe author's model and is not treated here as a population measurement.\n",
      "gone": null,
      "capture": {
        "status": "held",
        "copies": 1,
        "first_observed": "2026-08-01T05:59:38Z",
        "last_observed": "2026-08-01T05:59:38Z",
        "last_checked": "2026-08-15T12:26:02Z"
      },
      "differences": []
    },
    {
      "id": "threez-mk3-rng-disclosure-pinned",
      "title": "Mk3 bounded proof README at e17d833b",
      "url": "https://raw.githubusercontent.com/3z/coldcard-mk3-rng-disclosure/e17d833bc02371ef779e66e25a78c755e57039ef/README.md",
      "organisation": "3z",
      "kind": "repo-commit",
      "role": "Repository commit",
      "publication_time": "2026-07-31",
      "note": "Immutable README revision used by the fixed synthetic Mk3 regression vector. The separate main-branch source remains registered for change detection.",
      "gone": null,
      "capture": {
        "status": "held",
        "copies": 1,
        "first_observed": "2026-08-01T06:39:38Z",
        "last_observed": "2026-08-01T06:39:38Z",
        "last_checked": "2026-08-15T12:53:22Z"
      },
      "differences": []
    },
    {
      "id": "kelbie-rng-postmortem",
      "title": "Chain-derived COLDCARD RNG postmortem",
      "url": "https://raw.githubusercontent.com/Kelbie/coldcard-rng-postmortem/main/README.md",
      "organisation": "Kelbie",
      "kind": "independent-analysis",
      "role": "Independent primary analysis",
      "publication_time": "2026-07-31",
      "note": "Rapidly updated independent postmortem built from frozen chain data and public\nreports. It documents its derivation and attribution rules, but its wave\ngrouping, entity attribution and counterfactual conclusions remain the author's\nanalysis rather than facts established by the chain alone.\n",
      "gone": {
        "since": "20260804T011339Z",
        "http_status": "404",
        "observed": "Last read unchanged at 00:43 UTC on 4 August 2026 and 404 at 01:13, so the\nwithdrawal falls in that half hour. Rechecked on 6 August 2026: the raw file\nand the repository page both 404 under three different user agents, while\nanother repository on the same account answers 200 from this host and the\naccount's public repository listing no longer includes this one. That is the\norigin withdrawing the material rather than a block on this collector. Whether\nit was deleted, renamed or made private is not established here. The nine\ncaptures held, spanning 1 to 3 August 2026, are as far as this archive can tell\nthe only remaining public copies.\n"
      },
      "capture": {
        "status": "held",
        "copies": 9,
        "first_observed": "2026-08-01T05:59:38Z",
        "last_observed": "2026-08-03T23:13:22Z",
        "last_checked": "2026-08-04T00:43:36Z"
      },
      "differences": [
        {
          "observed_at": "2026-08-03T23:13:22Z",
          "window_start": "2026-08-03T17:42:24Z",
          "window_end": "2026-08-03T23:13:22Z",
          "status": "source-content",
          "summary": "Two figures were corrected (the same-four-blocks wave count moved from 291 to 286 addresses, and sweeps that paid more in fees than the coins were worth moved from 27 to 31) and the fee analysis was rewritten: the fixed size-table part is now given as 42 or 53 vbytes with two build variants, and the estimate now described as running from a vbyte under to 239 over.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 7,
          "removed_lines": 6
        },
        {
          "observed_at": "2026-08-03T17:42:24Z",
          "window_start": "2026-08-03T03:02:18Z",
          "window_end": "2026-08-03T17:42:24Z",
          "status": "source-content",
          "summary": "The postmortem moved its headline figures to 1,432.48 BTC swept from 5,477 addresses across ten waves, retitled itself coldcard.rip, and documented a tenth wave paid to Taproot that entered via an abuse report. It also added methodology sections on what a report claims versus corroborates (reported_inputs, ATTESTATIONS, voice) and revised rebuild timing notes.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 46,
          "removed_lines": 17
        },
        {
          "observed_at": "2026-08-03T03:02:18Z",
          "window_start": "2026-08-02T23:01:41Z",
          "window_end": "2026-08-03T03:02:18Z",
          "status": "source-content",
          "summary": "The README added a CORROBORATING_REPORTS input for reports that name an already tracked sweep without identifying the claimant, and updated timeline path references from timeline.tsx to a timeline directory.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 5,
          "removed_lines": 2
        },
        {
          "observed_at": "2026-08-02T23:01:41Z",
          "window_start": "2026-08-02T03:37:34Z",
          "window_end": "2026-08-02T23:01:41Z",
          "status": "source-content",
          "summary": "The headline figures changed to 1,431.97 BTC swept from 5,415 addresses across nine waves, reflecting a newly derived wave.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 1,
          "removed_lines": 1
        },
        {
          "observed_at": "2026-08-02T03:37:34Z",
          "window_start": "2026-08-02T01:32:59Z",
          "window_end": "2026-08-02T03:37:34Z",
          "status": "source-content",
          "summary": "The headline was updated to 1,367.07 BTC swept from 4,620 addresses across eight waves, and the README added a bun run facts step that rewrites marked prose blocks after each data refresh.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 16,
          "removed_lines": 8
        },
        {
          "observed_at": "2026-08-02T01:32:59Z",
          "window_start": "2026-08-01T17:12:00Z",
          "window_end": "2026-08-02T01:32:59Z",
          "status": "source-content",
          "summary": "The postmortem rewrote its data pipeline from a mempool.space API fetcher to a local Python block store, documented the resumed 31 July sweeping as 207.73 BTC from 1,918 addresses, and reworked its wave-grouping and fee-analysis sections.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 120,
          "removed_lines": 158
        },
        {
          "observed_at": "2026-08-01T17:12:00Z",
          "window_start": "2026-08-01T16:07:15Z",
          "window_end": "2026-08-01T17:12:00Z",
          "status": "source-content",
          "summary": "The README added derivation sections on grouping waves into families by build traits rather than configuration dials, on fee pricing and its lack of correlation with value, on wave colour, and on re-applying Block's published seven-property fingerprint across the whole record, plus a new fingerprint script in the file map.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 43,
          "removed_lines": 3
        },
        {
          "observed_at": "2026-08-01T16:07:15Z",
          "window_start": "2026-08-01T05:59:38Z",
          "window_end": "2026-08-01T16:07:15Z",
          "status": "source-content",
          "summary": "The README renamed waves from ordinal numbers to block heights throughout, so 'wave 3' became 'wave 960188' and Block's 'waves 1 and 2' became 'waves 960183 and 960185'.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 4,
          "removed_lines": 4
        }
      ]
    },
    {
      "id": "alvap-weak-rng-research",
      "title": "Reproducible firmware and chain investigation",
      "url": "https://raw.githubusercontent.com/alva-p/coldcard-weak-rng-research/main/README.md",
      "organisation": "Álvaro P.",
      "kind": "independent-analysis",
      "role": "Independent primary analysis",
      "publication_time": "2026-07-31",
      "note": "Independent re-derivation of fix commits, on-chain movements and vulnerable\nversus patched firmware symbols. Its README excludes real-seed recovery and\nlabels unfinished work explicitly; deeper repository files include public\ntransaction identifiers and are not mirrored by this archive.\n",
      "gone": null,
      "capture": {
        "status": "held",
        "copies": 1,
        "first_observed": "2026-08-01T05:59:38Z",
        "last_observed": "2026-08-01T05:59:38Z",
        "last_checked": "2026-08-15T12:26:04Z"
      },
      "differences": []
    },
    {
      "id": "nickfarrow-coldcard-audit-2026-06-17",
      "title": "COLDCARD firmware security audit dated 17 June 2026",
      "url": "https://gist.github.com/nickfarrow/4e97c71c8f1acd01aedce671621081d2",
      "organisation": "Nick Farrow",
      "kind": "independent-analysis",
      "role": "Independent primary analysis",
      "publication_time": "2026-08-02",
      "note": "Read-only security audit published as a gist on 2 Aug 2026 and dated 17 June\n2026, weeks before the incident became public. Weak RNG was in its stated\nscope and its bottom line clears the RNG, signing path and fee logic; the\nconfirmed findings are a physical-access secure-element parser overflow and\ndefense-in-depth gaps. Part of the record of what pre-incident review did\nand did not catch.\n",
      "gone": null,
      "capture": {
        "status": "held",
        "copies": 1,
        "first_observed": "2026-08-05T03:49:04Z",
        "last_observed": "2026-08-05T03:49:04Z",
        "last_checked": "2026-08-15T12:26:06Z"
      },
      "differences": []
    },
    {
      "id": "debian-openssl-dsa-1571",
      "title": "Debian Security Advisory DSA-1571-1",
      "url": "https://lists.debian.org/debian-security-announce/2008/msg00152.html",
      "organisation": "Debian",
      "kind": "vendor-advisory",
      "role": "Vendor advisory",
      "publication_time": "2008-05-13",
      "note": "Primary Debian advisory for CVE-2008-0166, including the affected release period and instruction to regenerate cryptographic key material.",
      "gone": null,
      "capture": {
        "status": "held",
        "copies": 1,
        "first_observed": "2026-08-01T09:15:22Z",
        "last_observed": "2026-08-01T09:15:22Z",
        "last_checked": "2026-08-05T01:20:17Z"
      },
      "differences": []
    },
    {
      "id": "android-securerandom-2013",
      "title": "Some SecureRandom thoughts",
      "url": "https://android-developers.googleblog.com/2013/08/some-securerandom-thoughts.html",
      "organisation": "Android Developers",
      "kind": "vendor-statement",
      "role": "Vendor statement",
      "publication_time": "2013-08-14",
      "note": "Primary Android statement on improper PRNG initialization affecting some cryptographic applications, including Bitcoin wallets.",
      "gone": null,
      "capture": {
        "status": "held",
        "copies": 1,
        "first_observed": "2026-08-01T09:15:34Z",
        "last_observed": "2026-08-01T09:15:34Z",
        "last_checked": "2026-08-05T01:20:31Z"
      },
      "differences": []
    },
    {
      "id": "unciphered-randstorm-disclosure",
      "title": "Disclosure of vulnerable Bitcoin wallet library",
      "url": "https://www.unciphered.com/disclosure-of-vulnerable-bitcoin-wallet-library-2/",
      "organisation": "Unciphered",
      "kind": "research",
      "role": "Primary technical research",
      "publication_time": "2023-11-14",
      "note": "Primary Randstorm disclosure describing vulnerable BitcoinJS-derived browser wallets and the browser- and date-dependent attack surface.",
      "gone": null,
      "capture": {
        "status": "held",
        "copies": 1,
        "first_observed": "2026-08-01T09:15:35Z",
        "last_observed": "2026-08-01T09:15:35Z",
        "last_checked": "2026-08-05T01:20:35Z"
      },
      "differences": []
    },
    {
      "id": "milksad-disclosure",
      "title": "Milk Sad vulnerability disclosure",
      "url": "https://milksad.info/disclosure.html",
      "organisation": "Milk Sad research team",
      "kind": "research",
      "role": "Primary technical research",
      "publication_time": "2023-08-08",
      "note": "Primary disclosure for CVE-2023-39910, including the 32-bit MT19937 seed funnel, partial impact accounting and comparison with the Trust Wallet incident.",
      "gone": null,
      "capture": {
        "status": "held",
        "copies": 1,
        "first_observed": "2026-08-01T09:15:35Z",
        "last_observed": "2026-08-01T09:15:35Z",
        "last_checked": "2026-08-05T01:20:38Z"
      },
      "differences": []
    },
    {
      "id": "nvd-cve-2023-31290",
      "title": "CVE-2023-31290 vulnerability record",
      "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-31290",
      "organisation": "NIST National Vulnerability Database",
      "kind": "government-record",
      "role": "Government vulnerability record",
      "publication_time": "2023-04-27",
      "note": "Official vulnerability record for the Trust Wallet browser-extension generator, affected versions, 32-bit entropy bound and reported exploitation period.",
      "gone": null,
      "capture": {
        "status": "held",
        "copies": 1,
        "first_observed": "2026-08-01T09:15:37Z",
        "last_observed": "2026-08-01T09:15:37Z",
        "last_checked": "2026-08-05T01:20:42Z"
      },
      "differences": []
    },
    {
      "id": "bitbox-not-affected",
      "title": "BitBox is not affected",
      "url": "https://blog.bitbox.swiss/en/bitbox-is-not-affected-by-the-coldcard-rng-vulnerability/",
      "organisation": "BitBox",
      "kind": "vendor-statement",
      "role": "Vendor statement",
      "publication_time": "2026-07-31",
      "note": null,
      "gone": null,
      "capture": {
        "status": "held",
        "copies": 3,
        "first_observed": "2026-08-01T00:46:13Z",
        "last_observed": "2026-08-04T15:18:04Z",
        "last_checked": "2026-08-15T12:53:24Z"
      },
      "differences": [
        {
          "observed_at": "2026-08-04T15:18:04Z",
          "window_start": "2026-08-03T09:36:55Z",
          "window_end": "2026-08-04T15:18:04Z",
          "status": "capture-noise",
          "summary": "The site's rotating related-post cards and post count changed. The BitBox statement itself did not change.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 9,
          "removed_lines": 4
        },
        {
          "observed_at": "2026-08-03T09:36:55Z",
          "window_start": "2026-08-01T00:46:13Z",
          "window_end": "2026-08-03T09:36:55Z",
          "status": "capture-noise",
          "summary": "Only site chrome changed: the site-wide footer products list dropped the BitBoxBase entry. The not-affected statement text was unchanged.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 0,
          "removed_lines": 1
        }
      ]
    },
    {
      "id": "jade-not-affected",
      "title": "Jade is unaffected",
      "url": "https://blog.blockstream.com/jade-unaffected-coldcard-vulnerability/",
      "organisation": "Blockstream",
      "kind": "vendor-statement",
      "role": "Vendor statement",
      "publication_time": "2026-07-31",
      "note": null,
      "gone": null,
      "capture": {
        "status": "held",
        "copies": 2,
        "first_observed": "2026-08-01T00:46:16Z",
        "last_observed": "2026-08-03T15:09:31Z",
        "last_checked": "2026-08-15T12:53:27Z"
      },
      "differences": [
        {
          "observed_at": "2026-08-03T15:09:31Z",
          "window_start": "2026-08-01T00:46:16Z",
          "window_end": "2026-08-03T15:09:31Z",
          "status": "source-content",
          "summary": "Blockstream rewrote Step 4 of its migration guidance: the heading changed from \"Retire the Old Recovery Phrase Safely\" to \"Hold Onto Your Old Device and Recovery Phrase\", and the instructions to verify the old wallet is empty and then destroy the old backup were removed. The post now tells readers to keep the old phrase in case funds become recoverable later.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 0,
          "removed_lines": 7
        }
      ]
    },
    {
      "id": "passport-not-affected",
      "title": "Passport is not affected",
      "url": "https://community.foundation.xyz/t/important-passport-is-not-affected-by-the-coldcard-seed-vulnerability/1147",
      "organisation": "Foundation",
      "kind": "vendor-statement",
      "role": "Vendor statement",
      "publication_time": "2026-07-31",
      "note": "The statement adds that a COLDCARD-generated seed imported into a Passport remains at risk.",
      "gone": null,
      "capture": {
        "status": "held",
        "copies": 3,
        "first_observed": "2026-08-01T00:46:19Z",
        "last_observed": "2026-08-03T02:34:08Z",
        "last_checked": "2026-08-15T12:53:30Z"
      },
      "differences": [
        {
          "observed_at": "2026-08-03T02:34:08Z",
          "window_start": "2026-08-01T16:09:53Z",
          "window_end": "2026-08-03T02:34:08Z",
          "status": "capture-correction",
          "summary": "The HTTP capture received Discourse's 173 KB JavaScript application shell instead of the 32 KB crawler-rendered page the extractor reads, so extraction returned empty while the post itself remains present in the served page metadata. The publisher did not remove the statement.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 0,
          "removed_lines": 66
        },
        {
          "observed_at": "2026-08-01T16:09:53Z",
          "window_start": "2026-08-01T00:46:19Z",
          "window_end": "2026-08-01T16:09:53Z",
          "status": "source-content",
          "summary": "Foundation added a reply to the thread saying manual firmware updates outside Envoy are scheduled for the next but one release, with no definitive timeframe committed.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 4,
          "removed_lines": 0
        }
      ]
    },
    {
      "id": "trezor-coldcard-not-affected",
      "title": "Trezor devices are not affected",
      "url": "https://trezor.io/blog/news/coldcard-vulnerability-trezor-devices-are-not-affected",
      "organisation": "Trezor",
      "kind": "vendor-statement",
      "role": "Vendor statement",
      "publication_time": "2026-08-05",
      "note": "The article the twelve-post FAQ thread points at. Covers who may need to move funds, how Trezor backups are generated, and the related scam wave.",
      "gone": null,
      "capture": {
        "status": "held",
        "copies": 5,
        "first_observed": "2026-08-06T08:09:56Z",
        "last_observed": "2026-08-14T23:48:25Z",
        "last_checked": "2026-08-15T12:53:33Z"
      },
      "differences": [
        {
          "observed_at": "2026-08-14T23:48:25Z",
          "window_start": "2026-08-13T14:24:52Z",
          "window_end": "2026-08-14T23:48:25Z",
          "status": "capture-noise",
          "summary": "Only the repeated author-tagline line 'Sharing insights on crypto, security & self-custody' appeared in the header and author bio areas; the article text was unchanged.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 2,
          "removed_lines": 0
        },
        {
          "observed_at": "2026-08-13T14:24:52Z",
          "window_start": "2026-08-12T05:08:10Z",
          "window_end": "2026-08-13T14:24:52Z",
          "status": "capture-noise",
          "summary": "Only rotating related-content cards below the article changed, swapping a 'Permissionless storage with Suite Sync' entry for a 'Recent customer data exposed in shipping provider incident' entry, and the article text was unchanged.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 3,
          "removed_lines": 3
        },
        {
          "observed_at": "2026-08-12T05:08:10Z",
          "window_start": "2026-08-06T16:38:01Z",
          "window_end": "2026-08-12T05:08:10Z",
          "status": "capture-noise",
          "summary": "Only the page's language-selector menu changed, adding Simplified Chinese and Indonesian entries.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 2,
          "removed_lines": 0
        },
        {
          "observed_at": "2026-08-06T16:38:01Z",
          "window_start": "2026-08-06T08:09:56Z",
          "window_end": "2026-08-06T16:38:01Z",
          "status": "source-content",
          "summary": "Trezor edited the article: the migration sentence for ex-Coldcard wallets now says \"follow these instructions\" instead of \"follow Coinkite's official guidance\", and \"wallet backup\" was shortened to \"wallet\".",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 1,
          "removed_lines": 1
        }
      ]
    },
    {
      "id": "bitcoinmag-fix-and-ai",
      "title": "Coinkite releases fixed firmware",
      "url": "https://bitcoinmagazine.com/business/coinkite-releases-fixed-firmware-after-coldcard-bug-ai-likely-involved-in-the-hack",
      "organisation": "Bitcoin Magazine",
      "kind": "reporting",
      "role": "Reporting",
      "publication_time": "2026-07-31",
      "note": "Secondary reporting that quotes Peter Todd endorsing Slipstream as a submission option after Rob Hamilton's earlier recommendation.",
      "gone": null,
      "capture": {
        "status": "held",
        "copies": 6,
        "first_observed": "2026-08-01T00:46:22Z",
        "last_observed": "2026-08-14T03:24:56Z",
        "last_checked": "2026-08-15T12:53:35Z"
      },
      "differences": [
        {
          "observed_at": "2026-08-14T03:24:56Z",
          "window_start": "2026-08-13T20:54:04Z",
          "window_end": "2026-08-14T03:24:56Z",
          "status": "capture-noise",
          "summary": "Only Bitcoin Magazine site chrome changed: social links were listed one per line, related article cards rotated, and section counters incremented.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 5,
          "removed_lines": 11
        },
        {
          "observed_at": "2026-08-13T20:54:04Z",
          "window_start": "2026-08-12T11:55:01Z",
          "window_end": "2026-08-13T20:54:04Z",
          "status": "capture-noise",
          "summary": "Only Bitcoin Magazine site chrome changed: social links were listed one per line, related article cards rotated, and section counters incremented.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 21,
          "removed_lines": 15
        },
        {
          "observed_at": "2026-08-12T11:55:01Z",
          "window_start": "2026-08-12T05:08:15Z",
          "window_end": "2026-08-12T11:55:01Z",
          "status": "capture-noise",
          "summary": "Only Bitcoin Magazine's rotating LATEST NEWS rail and category counters changed; the article body was unchanged.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 8,
          "removed_lines": 8
        },
        {
          "observed_at": "2026-08-12T05:08:15Z",
          "window_start": "2026-08-07T20:50:41Z",
          "window_end": "2026-08-12T05:08:15Z",
          "status": "capture-noise",
          "summary": "Only rotating related-story headlines and the site article counter changed; the article text was unchanged.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 10,
          "removed_lines": 10
        },
        {
          "observed_at": "2026-08-07T20:50:41Z",
          "window_start": "2026-08-01T00:46:22Z",
          "window_end": "2026-08-07T20:50:41Z",
          "status": "capture-noise",
          "summary": "Only the homepage's rotating article list and category counters changed; the target article's own text was not in the diff.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 21,
          "removed_lines": 21
        }
      ]
    },
    {
      "id": "tftc-who-must-move",
      "title": "Who must move their coins",
      "url": "https://www.tftc.io/coldcard-rng-failed-move-your-coins",
      "organisation": "TFTC",
      "kind": "analysis",
      "role": "Secondary analysis",
      "publication_time": "2026-07-31",
      "note": "Migration protocol plus a warning about scam recovery services.",
      "gone": null,
      "capture": {
        "status": "held",
        "copies": 2,
        "first_observed": "2026-08-01T00:46:24Z",
        "last_observed": "2026-08-01T03:08:27Z",
        "last_checked": "2026-08-15T12:53:37Z"
      },
      "differences": [
        {
          "observed_at": "2026-08-01T03:08:27Z",
          "window_start": "2026-08-01T00:46:24Z",
          "window_end": "2026-08-01T03:08:27Z",
          "status": "capture-noise",
          "summary": "Only rotating related-content cards below the article changed.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 10,
          "removed_lines": 10
        }
      ]
    },
    {
      "id": "theblock-galaxy-total",
      "title": "Galaxy loss estimate reporting",
      "url": "https://www.theblock.co/post/410332/bitcoin-losses-linked-coldcard-vulnerability-70-million-galaxy-research",
      "organisation": "The Block",
      "kind": "reporting",
      "role": "Reporting",
      "publication_time": "2026-07-31",
      "note": "Galaxy Research figures: 1,196 addresses, 1,082.65 BTC, 41-minute window.",
      "gone": null,
      "capture": {
        "status": "held",
        "copies": 10,
        "first_observed": "2026-08-01T00:46:26Z",
        "last_observed": "2026-08-08T12:02:51Z",
        "last_checked": "2026-08-15T12:53:40Z"
      },
      "differences": [
        {
          "observed_at": "2026-08-08T12:02:51Z",
          "window_start": "2026-08-07T03:34:58Z",
          "window_end": "2026-08-08T12:02:51Z",
          "status": "capture-correction",
          "summary": "The earlier capture held only the Cloudflare security-verification challenge; the new capture obtained the article text and site chrome.",
          "inherited_from_wayback": true,
          "baseline_inherited_from_wayback": false,
          "added_lines": 61,
          "removed_lines": 8
        },
        {
          "observed_at": "2026-08-07T03:34:58Z",
          "window_start": "2026-08-03T14:46:59Z",
          "window_end": "2026-08-07T03:34:58Z",
          "status": "capture-noise",
          "summary": "The capture received a Cloudflare security-verification interstitial instead of the article body. No incident article text changed.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 8,
          "removed_lines": 67
        },
        {
          "observed_at": "2026-08-03T14:46:59Z",
          "window_start": "2026-08-02T15:02:03Z",
          "window_end": "2026-08-03T14:46:59Z",
          "status": "capture-noise",
          "summary": "Only the site chrome's rotating Latest Crypto News rail changed to a fresh set of unrelated headlines. The Galaxy article text was unchanged.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 9,
          "removed_lines": 8
        },
        {
          "observed_at": "2026-08-02T15:02:03Z",
          "window_start": "2026-08-01T22:26:20Z",
          "window_end": "2026-08-02T15:02:03Z",
          "status": "capture-noise",
          "summary": "Only the rotating Latest Crypto News rail changed: an unrelated Reuters headline about an Iran-linked exchange gained the word wallets. The Galaxy article text was unchanged.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 1,
          "removed_lines": 1
        },
        {
          "observed_at": "2026-08-01T22:26:20Z",
          "window_start": "2026-08-01T16:10:02Z",
          "window_end": "2026-08-01T22:26:20Z",
          "status": "capture-noise",
          "summary": "Only the site chrome's rotating latest-news list changed; the incident article text, including its Galaxy total, was unchanged.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 4,
          "removed_lines": 4
        },
        {
          "observed_at": "2026-08-01T16:10:02Z",
          "window_start": "2026-08-01T08:12:59Z",
          "window_end": "2026-08-01T16:10:02Z",
          "status": "capture-noise",
          "summary": "Only the site chrome's rotating latest-news list changed; the incident article text was unchanged.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 2,
          "removed_lines": 2
        },
        {
          "observed_at": "2026-08-01T08:12:59Z",
          "window_start": "2026-08-01T03:22:37Z",
          "window_end": "2026-08-01T08:12:59Z",
          "status": "capture-noise",
          "summary": "The live market-ticker region was temporarily unavailable; the incident article text was unchanged.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 1,
          "removed_lines": 6
        },
        {
          "observed_at": "2026-08-01T03:22:37Z",
          "window_start": "2026-08-01T03:08:28Z",
          "window_end": "2026-08-01T03:22:37Z",
          "status": "capture-noise",
          "summary": "Only live cryptocurrency ticker values in the site navigation changed.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 4,
          "removed_lines": 4
        },
        {
          "observed_at": "2026-08-01T03:08:28Z",
          "window_start": "2026-08-01T00:46:26Z",
          "window_end": "2026-08-01T03:08:28Z",
          "status": "capture-noise",
          "summary": "Only live cryptocurrency ticker values in the site navigation changed.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 5,
          "removed_lines": 5
        }
      ]
    },
    {
      "id": "reddit-drained-timeline",
      "title": "Wallet drained timeline",
      "url": "https://www.reddit.com/r/Bitcoin/comments/1vb6teq/wallet_drained_timeline/",
      "organisation": "r/Bitcoin",
      "kind": "victim-account",
      "role": "First-hand account",
      "publication_time": "2026-07-31",
      "note": "A first-hand account posted while the sweep was still being worked out, before\nthe cause was publicly identified. A rendered capture from 1 Aug 2026 holds the\noriginal post and 25 comments locally. Public snapshot and diff text\nare withheld because the account contains identifying and wallet-specific\ndetails.",
      "gone": null,
      "capture": {
        "status": "held",
        "copies": 3,
        "first_observed": "2026-08-04T03:23:22Z",
        "last_observed": "2026-08-05T09:49:15Z",
        "last_checked": "2026-08-15T14:23:21Z"
      },
      "differences": [
        {
          "observed_at": "2026-08-05T09:49:15Z",
          "window_start": "2026-08-04T12:06:34Z",
          "window_end": "2026-08-05T09:49:15Z",
          "status": "source-content",
          "summary": "A participant's account was deleted, replacing several of its comments with deleted placeholders. The removed comments discussed the RNG issue, proposed seed-handling approaches and broader hardware-wallet custody risks.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 10,
          "removed_lines": 101
        },
        {
          "observed_at": "2026-08-04T12:06:34Z",
          "window_start": "2026-08-04T03:23:22Z",
          "window_end": "2026-08-04T12:06:34Z",
          "status": "source-content",
          "summary": "One new comment was posted: iloverunning11 speculating that victims will collectively sue Coinkite into chapter 11 and recover something like 15 to 20 cents on the dollar.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 8,
          "removed_lines": 0
        }
      ]
    },
    {
      "id": "reddit-full-panic-drain-report",
      "title": "Full panic - one of my wallets was drained",
      "url": "https://www.reddit.com/r/Bitcoin/comments/1vatgl4/full_panic_one_of_my_wallets_was_drained/",
      "organisation": "r/Bitcoin",
      "kind": "victim-account",
      "role": "First-hand account",
      "publication_time": "2026-07-30",
      "note": "The first public drain report, posted on 30 Jul 2026 while the sweep was still\nongoing: a wallet untouched since 2021, drained for roughly 0.8 BTC. This is\nthe thread Kevin Loaec's call for corroboration and the first Stacker News\nreport both reference, which makes it the start of the public record.",
      "gone": null,
      "capture": {
        "status": "held",
        "copies": 14,
        "first_observed": "2026-08-05T03:49:05Z",
        "last_observed": "2026-08-15T14:23:28Z",
        "last_checked": "2026-08-15T14:23:28Z"
      },
      "differences": [
        {
          "observed_at": "2026-08-15T14:23:28Z",
          "window_start": "2026-08-15T07:23:48Z",
          "window_end": "2026-08-15T14:23:28Z",
          "status": "source-content",
          "summary": "The thread lost a comment by Aflockofants arguing that Bitcoin has become a get-rich-quick scheme for wealthy Westerners.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 0,
          "removed_lines": 10
        },
        {
          "observed_at": "2026-08-15T07:23:48Z",
          "window_start": "2026-08-14T13:23:59Z",
          "window_end": "2026-08-15T07:23:48Z",
          "status": "source-content",
          "summary": "A comment by SharpGame83 was redacted: the author became [deleted] and the body became [removed].",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 2,
          "removed_lines": 3
        },
        {
          "observed_at": "2026-08-14T13:23:59Z",
          "window_start": "2026-08-14T06:23:28Z",
          "window_end": "2026-08-14T13:23:59Z",
          "status": "source-content",
          "summary": "A comment recommending Trezor and a hidden passphrase wallet was added, and a comment advising victims to broadcast timestamped signed messages with the compromised key was removed.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 10,
          "removed_lines": 9
        },
        {
          "observed_at": "2026-08-14T06:23:28Z",
          "window_start": "2026-08-13T15:23:30Z",
          "window_end": "2026-08-14T06:23:28Z",
          "status": "source-content",
          "summary": "A comment by mindylynx reading 'aaand that's why i still use paper wallets' was removed from the thread.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 0,
          "removed_lines": 8
        },
        {
          "observed_at": "2026-08-13T15:23:30Z",
          "window_start": "2026-08-12T16:24:19Z",
          "window_end": "2026-08-13T15:23:30Z",
          "status": "source-content",
          "summary": "The comment by Important-Level6672 comparing crypto thefts to fiat-era heists was removed from the thread.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 0,
          "removed_lines": 13
        },
        {
          "observed_at": "2026-08-12T16:24:19Z",
          "window_start": "2026-08-12T00:05:39Z",
          "window_end": "2026-08-12T16:24:19Z",
          "status": "source-content",
          "summary": "One comment in the thread was removed and its author line changed to [deleted], replacing the original supportive text with [removed].",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 2,
          "removed_lines": 10
        },
        {
          "observed_at": "2026-08-12T00:05:39Z",
          "window_start": "2026-08-09T02:56:41Z",
          "window_end": "2026-08-12T00:05:39Z",
          "status": "source-content",
          "summary": "Reddit deleted or removed the original post author and several comments, replacing the author with [deleted] and comment bodies with [removed].",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 2,
          "removed_lines": 20
        },
        {
          "observed_at": "2026-08-09T02:56:41Z",
          "window_start": "2026-08-07T18:20:37Z",
          "window_end": "2026-08-09T02:56:41Z",
          "status": "source-content",
          "summary": "The thread gained two comments discussing whether a passphrase is strong enough to protect a drained wallet and lost one spam-style comment.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 16,
          "removed_lines": 10
        },
        {
          "observed_at": "2026-08-07T18:20:37Z",
          "window_start": "2026-08-07T17:22:04Z",
          "window_end": "2026-08-07T18:20:37Z",
          "status": "source-content",
          "summary": "A new [deleted]-author comment was added to the thread saying \"Yeah stay away from these scam coins. Invest in the stock market\".",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 0,
          "removed_lines": 8
        },
        {
          "observed_at": "2026-08-07T17:22:04Z",
          "window_start": "2026-08-06T21:26:15Z",
          "window_end": "2026-08-07T17:22:04Z",
          "status": "source-content",
          "summary": "The author line of one comment changed from the username miscellanalous to [deleted].",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 1,
          "removed_lines": 1
        },
        {
          "observed_at": "2026-08-06T21:26:15Z",
          "window_start": "2026-08-06T19:25:47Z",
          "window_end": "2026-08-06T21:26:15Z",
          "status": "source-content",
          "summary": "A comment by Bmoses99 saying the drain may have been part of a broader theft was removed from the thread.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 0,
          "removed_lines": 8
        },
        {
          "observed_at": "2026-08-06T19:25:47Z",
          "window_start": "2026-08-05T09:49:23Z",
          "window_end": "2026-08-06T19:25:47Z",
          "status": "source-content",
          "summary": "ambiguous: the only change is a new collapsed-replies stub under comment p0ssb37, indicating that comment gained replies the capture does not expand.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 2,
          "removed_lines": 0
        },
        {
          "observed_at": "2026-08-05T09:49:23Z",
          "window_start": "2026-08-05T03:49:05Z",
          "window_end": "2026-08-05T09:49:23Z",
          "status": "source-content",
          "summary": "A participant's account was deleted, replacing three comments with deleted placeholders. The removed comments discussed possible causes of the drain and the participant's stated seed-verification and seed-generation practices.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 8,
          "removed_lines": 16
        }
      ]
    },
    {
      "id": "coldcard-watch",
      "title": "COLDCARD funds flow monitor",
      "url": "https://coldcardwatch.com/",
      "organisation": "community tracker",
      "kind": "chain-monitor",
      "role": "Chain monitor",
      "publication_time": null,
      "note": "The tracker expanded on 1 Aug from the first 1,195-address episode to two\nepisodes totalling 2,321 addresses and 1,128.4717 BTC. It includes a\nbrowser-local address checker and follows spends from the consolidation\naddresses hop by hop. It labels the first episode 29 July without stating a\ntimezone; the corresponding on-chain window begins 30 July at 01:10 UTC.\nOperator anonymous; figures cross-check against Galaxy's published map for the\nfirst episode. The original host, coldcard-watch.vercel.app, stopped resolving\nat 21:43 UTC on 3 Aug 2026; the same tracker (identical page, headline and\nlast-drain figures) was found serving at coldcardwatch.com on 4 Aug 2026 and\nthe registry URL moved with it.\n",
      "gone": null,
      "capture": {
        "status": "held",
        "copies": 11,
        "first_observed": "2026-08-01T02:34:03Z",
        "last_observed": "2026-08-07T03:32:34Z",
        "last_checked": "2026-08-15T14:23:52Z"
      },
      "differences": [
        {
          "observed_at": "2026-08-07T03:32:34Z",
          "window_start": "2026-08-04T08:06:12Z",
          "window_end": "2026-08-07T03:32:34Z",
          "status": "source-content",
          "summary": "Verified drained total rose from 1,366.5774 to 1,405.0671 BTC and verified drained addresses from 4,580 to 4,925. The site also renamed itself from Coldcard Sweep Watch to Coldcard Watch and split its view filter into Verified, Attested and Suspected.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 11,
          "removed_lines": 5
        },
        {
          "observed_at": "2026-08-04T08:06:12Z",
          "window_start": "2026-08-03T04:03:04Z",
          "window_end": "2026-08-04T08:06:12Z",
          "status": "source-content",
          "summary": "First capture at the new coldcardwatch.com domain after the vercel.app host stopped resolving. The tracker replaced its browser-local address-checker form with a published full address list ('Is an address in the set? ... this page has no form and collects nothing') and changed its footer to 'Independent security research'. The headline figure is unchanged at 1,366.5774 BTC across 4,580 addresses.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 4,
          "removed_lines": 6
        },
        {
          "observed_at": "2026-08-03T04:03:04Z",
          "window_start": "2026-08-02T23:02:06Z",
          "window_end": "2026-08-03T04:03:04Z",
          "status": "source-content",
          "summary": "Added a View switcher with Confirmed and Potential options above the verified-minimums disclaimer, so the tracker now separates confirmed clusters from potential ones. The headline figures and disclaimer text were unchanged.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 3,
          "removed_lines": 0
        },
        {
          "observed_at": "2026-08-02T23:02:06Z",
          "window_start": "2026-08-02T21:01:44Z",
          "window_end": "2026-08-02T23:02:06Z",
          "status": "source-content",
          "summary": "The tracker's headline moved from 1,359.1829 BTC across 4,312 verified addresses to 1,366.5774 BTC across 4,580, and its address-check copy changed with it. The cluster description of three windows on 30 and 31 July was unchanged.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 3,
          "removed_lines": 3
        },
        {
          "observed_at": "2026-08-02T21:01:44Z",
          "window_start": "2026-08-02T00:59:57Z",
          "window_end": "2026-08-02T21:01:44Z",
          "status": "source-content",
          "summary": "The tracker rewrote its affected-firmware notes, saying signed Mk3 builds 5.0.1 and 5.0.3 shipped after the change that caused the fault and are listed as at risk, and that 4.0.1 is the first distributed vulnerable version. It added that Coinkite emailed affected customers on 2 August with a phishing warning, and expanded the dice-roll and passphrase guidance with Coinkite's bit-strength figures.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 3,
          "removed_lines": 3
        },
        {
          "observed_at": "2026-08-02T00:59:57Z",
          "window_start": "2026-08-01T17:43:04Z",
          "window_end": "2026-08-02T00:59:57Z",
          "status": "source-content",
          "summary": "The tracker's headline moved from 1,158.8480 BTC across 2,686 verified addresses to 1,359.1829 BTC across 4,312, and its address-check copy changed with it. The cluster description of three windows on 30 and 31 July was unchanged.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 3,
          "removed_lines": 3
        },
        {
          "observed_at": "2026-08-01T17:43:04Z",
          "window_start": "2026-08-01T14:03:09Z",
          "window_end": "2026-08-01T17:43:04Z",
          "status": "source-content",
          "summary": "The tracker's headline moved from 1,128.6633 BTC across 2,334 verified addresses to 1,158.8480 BTC across 2,686, and its address-check copy changed with it. The cluster description of three windows on 30 and 31 July was unchanged.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 3,
          "removed_lines": 3
        },
        {
          "observed_at": "2026-08-01T14:03:09Z",
          "window_start": "2026-08-01T13:01:10Z",
          "window_end": "2026-08-01T14:03:09Z",
          "status": "source-content",
          "summary": "The tracker moved from two episodes to three clusters by adding 13 addresses in block 960455, changed the destination set from four addresses to six, revised the same-block count for the last drained address from 250 to 237, and added an explanatory note about the two-scale timeline.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 4,
          "removed_lines": 3
        },
        {
          "observed_at": "2026-08-01T13:01:10Z",
          "window_start": "2026-08-01T05:28:59Z",
          "window_end": "2026-08-01T13:01:10Z",
          "status": "source-content",
          "summary": "The tracker added dashboard, address-list and methodology navigation, described its figures as verified minimums and a floor rather than totals, and changed its checkable address set from 2,321 to 2,334.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 11,
          "removed_lines": 6
        },
        {
          "observed_at": "2026-08-01T05:28:59Z",
          "window_start": "2026-08-01T02:34:03Z",
          "window_end": "2026-08-01T05:28:59Z",
          "status": "source-content",
          "summary": "The tracker expanded from the first 1,195-address episode to two episodes totalling 2,321 addresses and changed its headline from 1,082.5696 BTC to 1,128.4717 BTC.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 9,
          "removed_lines": 9
        }
      ]
    },
    {
      "id": "coldcard-hack-tracker",
      "title": "COLDCARD hack tracker",
      "url": "https://coldcard-hack-tracker.vercel.app/",
      "organisation": "community tracker",
      "kind": "chain-monitor",
      "role": "Chain monitor",
      "publication_time": null,
      "note": "Second, independent tracker of the same four holding addresses. States the\naccounting precision the reporting rounded: 1,082.65 BTC drained, 1,082.57 BTC\narrived, the difference paid to miners as fees. Cites Galaxy, Coinkite and Block.\nThe page is client-rendered. The empty shell from the first capture is preserved\nas a capture correction, followed by complete rendered captures.\n\nThe operator rebuilt the page on 2 August 2026 around a five-wave model, which\nrenamed the section heading this capture previously keyed on. The guard string\nmoved from that heading to \"Watched holdings\"; \"Holding 1\" and \"Movement feed\"\nare retained because they appear only after the client-side data resolves, so an\nunrendered shell still fails the check rather than entering the record.\n",
      "gone": null,
      "capture": {
        "status": "held",
        "copies": 141,
        "first_observed": "2026-08-01T02:34:16Z",
        "last_observed": "2026-08-15T13:23:54Z",
        "last_checked": "2026-08-15T14:23:54Z"
      },
      "differences": [
        {
          "observed_at": "2026-08-15T13:23:54Z",
          "window_start": "2026-08-15T07:24:10Z",
          "window_end": "2026-08-15T13:23:54Z",
          "status": "source-content",
          "summary": "The tracker added a new Hop 1 movement of 0.241352 BTC from the Aug 1 hop vault at block 960,658.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 8,
          "removed_lines": 0
        },
        {
          "observed_at": "2026-08-15T07:24:10Z",
          "window_start": "2026-08-15T01:24:27Z",
          "window_end": "2026-08-15T07:24:10Z",
          "status": "source-content",
          "summary": "The tracker removed the Holding 1 HOP 1 movement entry showing 0.241352 BTC sent from the Aug 1 hop vault in block 960,658.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 0,
          "removed_lines": 8
        },
        {
          "observed_at": "2026-08-15T01:24:27Z",
          "window_start": "2026-08-14T23:40:48Z",
          "window_end": "2026-08-15T01:24:27Z",
          "status": "source-content",
          "summary": "The tracker updated its Galaxy attribution to the Aug 14 $112M update, raising high-confidence losses from 1,719 to 1,778.84 BTC, adding a new Aug 2 vault movement of about 64.9 BTC, and noting no confirmed attack after Aug 6.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 17,
          "removed_lines": 6
        },
        {
          "observed_at": "2026-08-14T23:40:48Z",
          "window_start": "2026-08-14T00:24:42Z",
          "window_end": "2026-08-14T23:40:48Z",
          "status": "source-content",
          "summary": "The movement feed removed the Aug 2 vault entry that had reported -64.90373764 BTC moved in block 961,065 to bc1pynd6...7h92.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 0,
          "removed_lines": 7
        },
        {
          "observed_at": "2026-08-14T00:24:42Z",
          "window_start": "2026-08-13T19:24:12Z",
          "window_end": "2026-08-14T00:24:42Z",
          "status": "source-content",
          "summary": "The tracker added a Wave 1 forensics section attributed to Praveen Perera, reporting that 328 weak Mk3 seeds were reconstructed covering 1,042 of 1,195 Wave 1 sources (949.7 BTC), with 153 sources (~133 BTC) still unexplained.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 4,
          "removed_lines": 0
        },
        {
          "observed_at": "2026-08-13T19:24:12Z",
          "window_start": "2026-08-13T13:24:11Z",
          "window_end": "2026-08-13T19:24:12Z",
          "status": "source-content",
          "summary": "The movement feed advanced from block 962,196 to block 962,295 and recorded a new 5.35785418 BTC hop-2 movement from the Wave 4 park vault, splitting onward to two bech32 destinations.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 11,
          "removed_lines": 3
        },
        {
          "observed_at": "2026-08-13T13:24:11Z",
          "window_start": "2026-08-13T02:23:54Z",
          "window_end": "2026-08-13T13:24:11Z",
          "status": "source-content",
          "summary": "The tracker updated its CK tripwire honeypot notes to reflect a second low-pass honeypot sweep on August 13 and maintained the approximately 11-bit frontier figure.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 2,
          "removed_lines": 2
        },
        {
          "observed_at": "2026-08-13T02:23:54Z",
          "window_start": "2026-08-12T16:24:42Z",
          "window_end": "2026-08-13T02:23:54Z",
          "status": "source-content",
          "summary": "The movement feed recorded a new Wave 4 park hop-1 spend of 0.01573188 BTC at block 962,196, replacing the previous last-movement entry at block 961,731.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 11,
          "removed_lines": 3
        },
        {
          "observed_at": "2026-08-12T16:24:42Z",
          "window_start": "2026-08-12T00:06:28Z",
          "window_end": "2026-08-12T16:24:42Z",
          "status": "source-content",
          "summary": "The tracker added ColeTU's weak-passphrase experiment to its guidance and honeypot scoreboard, raised the observed brute-force frontier to about 11 bits, and added a SlowMist Aug. 12 section reproducing the Mk3 4.1.9 attack chain and reconciling its Wave 4 label with the tracker's Early Aug 2 vault.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 6,
          "removed_lines": 2
        },
        {
          "observed_at": "2026-08-12T00:06:28Z",
          "window_start": "2026-08-09T22:45:23Z",
          "window_end": "2026-08-12T00:06:28Z",
          "status": "source-content",
          "summary": "The tracker updated its watched balances and UTXO counts, removed some hop entries from the movement feed, and relabeled a destination as a Quidax deposit.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 6,
          "removed_lines": 22
        },
        {
          "observed_at": "2026-08-09T22:45:23Z",
          "window_start": "2026-08-09T21:45:15Z",
          "window_end": "2026-08-09T22:45:23Z",
          "status": "source-content",
          "summary": "The movement feed added a new Hop 1 spend of 0.02374887 BTC from the Wave 4 park vault at block 960,794 to bc1qhfdz...3wcx.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 8,
          "removed_lines": 0
        },
        {
          "observed_at": "2026-08-09T21:45:15Z",
          "window_start": "2026-08-09T20:44:20Z",
          "window_end": "2026-08-09T21:45:15Z",
          "status": "source-content",
          "summary": "The tracker raised its total watched balance from 1,367.16826524 BTC to 1,367.16828024 BTC, the bc1qq85v2c holding balance rose from 562.02139594 BTC to 562.02141094 BTC, and its HELD count moved from 57 to 58. The movement feed also lost the HOP 1 entry from Wave 4.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 5,
          "removed_lines": 13
        },
        {
          "observed_at": "2026-08-09T20:44:20Z",
          "window_start": "2026-08-09T14:42:55Z",
          "window_end": "2026-08-09T20:44:20Z",
          "status": "source-content",
          "summary": "The tracker raised its total watched balance from 1,367.16824986 BTC to 1,367.16826524 BTC, and the bc1qq85v2c holding balance rose from 562.02138056 BTC to 562.02139594 BTC while its HELD count moved from 56 to 57. The movement-feed total changed in the same capture.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 5,
          "removed_lines": 5
        },
        {
          "observed_at": "2026-08-09T14:42:55Z",
          "window_start": "2026-08-09T13:42:55Z",
          "window_end": "2026-08-09T14:42:55Z",
          "status": "source-content",
          "summary": "The tracker relabeled one destination as a Bybit deposit and removed several older Wave 4 park hop entries from the movement feed. It also updated its dice/passphrase honeypot notes to report that ~5-bit low/dice honeypots were swept by Aug 8, with mid/high passphrase bands still live.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 3,
          "removed_lines": 27
        },
        {
          "observed_at": "2026-08-09T13:42:55Z",
          "window_start": "2026-08-09T11:58:31Z",
          "window_end": "2026-08-09T13:42:55Z",
          "status": "source-content",
          "summary": "The movement feed updated from block 961,598 to block 961,731 and added new Hop 1 and Hop 2 spends, including a 0.0077407 BTC movement from the Wave 4 park vault and a 0.00308496 BTC onward spend.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 19,
          "removed_lines": 3
        },
        {
          "observed_at": "2026-08-09T11:58:31Z",
          "window_start": "2026-08-09T10:58:19Z",
          "window_end": "2026-08-09T11:58:31Z",
          "status": "source-content",
          "summary": "The movement feed added a new −0.50980268 BTC spend from the Evening vault at block 960,666.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 7,
          "removed_lines": 0
        },
        {
          "observed_at": "2026-08-09T10:58:19Z",
          "window_start": "2026-08-09T08:58:05Z",
          "window_end": "2026-08-09T10:58:19Z",
          "status": "source-content",
          "summary": "The movement feed removed a -0.50980268 BTC entry from the Evening vault.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 0,
          "removed_lines": 7
        },
        {
          "observed_at": "2026-08-09T08:58:05Z",
          "window_start": "2026-08-09T07:57:49Z",
          "window_end": "2026-08-09T08:58:05Z",
          "status": "source-content",
          "summary": "The movement feed reintroduced the Wave 4 park hop-1 entry that the preceding capture had removed.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 8,
          "removed_lines": 0
        },
        {
          "observed_at": "2026-08-09T07:57:49Z",
          "window_start": "2026-08-09T06:57:29Z",
          "window_end": "2026-08-09T07:57:49Z",
          "status": "source-content",
          "summary": "The movement feed removed the Wave 4 park hop-1 entry and added a new −64.90373764 BTC movement from the Aug 2 vault at block 961,065.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 7,
          "removed_lines": 8
        },
        {
          "observed_at": "2026-08-09T06:57:29Z",
          "window_start": "2026-08-08T23:56:30Z",
          "window_end": "2026-08-09T06:57:29Z",
          "status": "source-content",
          "summary": "The movement feed dropped a 64.9037 BTC line item that had moved from the Aug 2 vault to bc1pynd6...7h92 in block 961,065.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 0,
          "removed_lines": 7
        },
        {
          "observed_at": "2026-08-08T23:56:30Z",
          "window_start": "2026-08-08T19:55:53Z",
          "window_end": "2026-08-08T23:56:30Z",
          "status": "source-content",
          "summary": "The tracker updated several watched balances and Holding 1's UTXO count rose from 55 to 56 while its held status remained unchanged.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 5,
          "removed_lines": 5
        },
        {
          "observed_at": "2026-08-08T19:55:53Z",
          "window_start": "2026-08-08T15:55:03Z",
          "window_end": "2026-08-08T19:55:53Z",
          "status": "source-content",
          "summary": "The watched total changed from 1,367.16822948 to 1,367.16823448 BTC, one holding balance shifted by 0.00000500 BTC, and Holding 1's UTXO count increased from 54 to 55.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 5,
          "removed_lines": 5
        },
        {
          "observed_at": "2026-08-08T15:55:03Z",
          "window_start": "2026-08-08T14:54:49Z",
          "window_end": "2026-08-08T15:55:03Z",
          "status": "source-content",
          "summary": "The movement feed added a new 0.00768211 BTC Hop 1 spend from Wave 4 park in block 961,598, replacing the earlier block 961,543 entry.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 11,
          "removed_lines": 3
        },
        {
          "observed_at": "2026-08-08T14:54:49Z",
          "window_start": "2026-08-08T13:54:39Z",
          "window_end": "2026-08-08T14:54:49Z",
          "status": "capture-noise",
          "summary": "The -0.02374887 BTC Hop 1 entry that left the movement feed in the previous capture has returned, restoring the same two Hop 1 lines as before. The back-and-forth is client-rendered ordering or hydration churn, not a new on-chain event.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 8,
          "removed_lines": 0
        },
        {
          "observed_at": "2026-08-08T13:54:39Z",
          "window_start": "2026-08-08T08:23:48Z",
          "window_end": "2026-08-08T13:54:39Z",
          "status": "source-content",
          "summary": "The tracker dropped the -0.02374887 BTC Hop 1 entry from the movement feed, leaving only the second input for the same transaction.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 0,
          "removed_lines": 8
        },
        {
          "observed_at": "2026-08-08T08:23:48Z",
          "window_start": "2026-08-08T03:23:00Z",
          "window_end": "2026-08-08T08:23:48Z",
          "status": "source-content",
          "summary": "A new Wave 4 park movement of 0.00462205 BTC arrived in block 961,543, raising BALANCE ON WATCH to 1,367.16822948 BTC, lowering MOVED to 118.60751472 BTC, and increasing the HELD count to 54.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 16,
          "removed_lines": 8
        },
        {
          "observed_at": "2026-08-08T03:23:00Z",
          "window_start": "2026-08-07T21:20:56Z",
          "window_end": "2026-08-08T03:23:00Z",
          "status": "source-content",
          "summary": "Dust-sized movement only: BALANCE ON WATCH rose by 0.000005 BTC to 1,367.16819948 and MOVED fell by the same amount to 118.60754472, with the holding-address balances adjusting to match. No new movement-feed entry and no change to STILL HELD.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 5,
          "removed_lines": 5
        },
        {
          "observed_at": "2026-08-07T21:20:56Z",
          "window_start": "2026-08-07T20:20:56Z",
          "window_end": "2026-08-07T21:20:56Z",
          "status": "source-content",
          "summary": "The movement feed gained a row for a 64.90373764 BTC spend out of the Aug 2 vault bc1q0rvn…5q6m at block 961,065, to bc1pynd6…7h92. The block is older than rows the feed already carried, so the tracker backfilled an earlier movement into its feed rather than observing one live. Headline MOVED and STILL HELD are unchanged at 118.6075 BTC and 92.0 percent apart from dust.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 7,
          "removed_lines": 0
        },
        {
          "observed_at": "2026-08-07T20:20:56Z",
          "window_start": "2026-08-07T19:20:57Z",
          "window_end": "2026-08-07T20:20:56Z",
          "status": "source-content",
          "summary": "The tracker updated several holding balances and UTXO counts, including Holding 1 and Holding 2, and removed a prior movement feed entry for the evening vault.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 8,
          "removed_lines": 15
        },
        {
          "observed_at": "2026-08-07T19:20:57Z",
          "window_start": "2026-08-07T16:22:35Z",
          "window_end": "2026-08-07T19:20:57Z",
          "status": "capture-noise",
          "summary": "Only live blockchain counters moved: the watched totals and Holding 1 balance shifted by a few sats, the HELD count for an address rose from 50 to 51, and the live fiat value line changed.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 5,
          "removed_lines": 5
        },
        {
          "observed_at": "2026-08-07T16:22:35Z",
          "window_start": "2026-08-07T13:20:28Z",
          "window_end": "2026-08-07T16:22:35Z",
          "status": "source-content",
          "summary": "The tracker updated its Galaxy attribution to the Aug 7 $111M update: high-confidence losses rose from 1,596 BTC across about 7,300 addresses to 1,719 BTC across 8,092 addresses, the candidate ceiling rose from about 2,055 BTC to 2,300+ BTC, and the attacker count estimate changed from at least 15 to 25 plus attack patterns. Footprint O is now noted as folded into Galaxy's Aug 7 confirmed footprint set.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 8,
          "removed_lines": 4
        },
        {
          "observed_at": "2026-08-07T13:20:28Z",
          "window_start": "2026-08-07T12:20:16Z",
          "window_end": "2026-08-07T13:20:28Z",
          "status": "source-content",
          "summary": "Tracker prose updated for the Wave 2 collector emptying: the collector entry now says it was emptied Aug 7 (block 961368) into a hop still holding ~30.18 BTC, and the Galaxy Research source note is qualified to say Waves 1-3 coins were unmoved as of Aug 3.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 3,
          "removed_lines": 3
        },
        {
          "observed_at": "2026-08-07T12:20:16Z",
          "window_start": "2026-08-07T11:20:03Z",
          "window_end": "2026-08-07T12:20:16Z",
          "status": "source-content",
          "summary": "The 0.00046352 BTC hop spend confirmed at block 961,428 and LAST MOVEMENT updated to it. The two f02164a9 consolidation rows dropped in the previous capture are back.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 11,
          "removed_lines": 4
        },
        {
          "observed_at": "2026-08-07T11:20:03Z",
          "window_start": "2026-08-07T10:19:52Z",
          "window_end": "2026-08-07T11:20:03Z",
          "status": "source-content",
          "summary": "New unconfirmed hop-1 spend of 0.00046352 BTC from the Wave 4 park hop added to the movement feed. Two feed rows for the f02164a9 consolidation were temporarily dropped; they return in the next capture.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 8,
          "removed_lines": 7
        },
        {
          "observed_at": "2026-08-07T10:19:52Z",
          "window_start": "2026-08-07T08:19:21Z",
          "window_end": "2026-08-07T10:19:52Z",
          "status": "source-content",
          "summary": "Movement feed extended: a new hop-1 spend of 0.02324129 BTC from the Wave 4 park hop at block 961,404 plus three hop-2 entries, and LAST MOVEMENT updated. Wave 2 vault also gained a dust UTXO (3 to 4).",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 40,
          "removed_lines": 8
        },
        {
          "observed_at": "2026-08-07T08:19:21Z",
          "window_start": "2026-08-07T05:40:07Z",
          "window_end": "2026-08-07T08:19:21Z",
          "status": "source-content",
          "summary": "Holding 3 received a dust input (89.6232889 to 89.6232989 BTC, UTXOs 2 to 3). BALANCE ON WATCH and MOVED shifted by the same dust amount.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 5,
          "removed_lines": 5
        },
        {
          "observed_at": "2026-08-07T05:40:07Z",
          "window_start": "2026-08-07T03:39:47Z",
          "window_end": "2026-08-07T05:40:07Z",
          "status": "source-content",
          "summary": "The 30.18476329 BTC Wave 2 collector spend confirmed at block 961,368 and LAST MOVEMENT was updated to it. Holding 1 gained another dust UTXO (49 to 50).",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 9,
          "removed_lines": 9
        },
        {
          "observed_at": "2026-08-07T03:39:47Z",
          "window_start": "2026-08-06T19:26:16Z",
          "window_end": "2026-08-07T03:39:47Z",
          "status": "source-content",
          "summary": "Wave 2 collector bc1qmd5m5k...9n8jp6 was emptied: 30.18476329 BTC moved out in a then-unconfirmed spend, its status flipped to PARTIAL with a 0.00002 BTC dust leftover, MOVED rose from 88.42 to 118.61 BTC and STILL HELD fell from 94.0% to 92.0%.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 326,
          "removed_lines": 106
        },
        {
          "observed_at": "2026-08-06T19:26:16Z",
          "window_start": "2026-08-06T13:25:18Z",
          "window_end": "2026-08-06T19:26:16Z",
          "status": "source-content",
          "summary": "Holding 1 gained another dust input (562.02124901 to 562.02126439 BTC, UTXOs 44 to 45). The same capture also failed to render the live fiat conversions, collapsing the <live-fiat-value> placeholders to \"USD pending\"; that part is rendering noise.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 113,
          "removed_lines": 326
        },
        {
          "observed_at": "2026-08-06T13:25:18Z",
          "window_start": "2026-08-06T11:25:01Z",
          "window_end": "2026-08-06T13:25:18Z",
          "status": "source-content",
          "summary": "Another dust-sized input to Holding 1: 562.02123901 to 562.02124901 BTC, UTXOs 43 to 44. Headline totals moved accordingly.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 5,
          "removed_lines": 5
        },
        {
          "observed_at": "2026-08-06T11:25:01Z",
          "window_start": "2026-08-06T05:24:15Z",
          "window_end": "2026-08-06T11:25:01Z",
          "status": "source-content",
          "summary": "Small inbound dust on Holding 1: balance 562.02113901 to 562.02123901 BTC, UTXOs 42 to 43. BALANCE ON WATCH and MOVED totals shifted by the same dust amount.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 5,
          "removed_lines": 5
        },
        {
          "observed_at": "2026-08-06T05:24:15Z",
          "window_start": "2026-08-06T01:54:27Z",
          "window_end": "2026-08-06T05:24:15Z",
          "status": "source-content",
          "summary": "The tracker updated two watched holding balances by small amounts and raised their displayed transaction counts, from 40 to 42 and from 1 to 2. Its aggregate held and swept BTC totals changed accordingly.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 8,
          "removed_lines": 8
        },
        {
          "observed_at": "2026-08-06T01:54:27Z",
          "window_start": "2026-08-05T23:54:28Z",
          "window_end": "2026-08-06T01:54:27Z",
          "status": "source-content",
          "summary": "The tracker revised watched and moved balances, added its operator-attributed claimed ETH route through THORChain to Tornado Cash, and changed which later movements it excludes from the feed.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 34,
          "removed_lines": 156
        },
        {
          "observed_at": "2026-08-05T23:54:28Z",
          "window_start": "2026-08-05T22:53:44Z",
          "window_end": "2026-08-05T23:54:28Z",
          "status": "source-content",
          "summary": "The tracker added a hop-two 1.29140163 BTC fan-out record and removed an earlier 0.69135523 BTC Aug. 1 vault movement from the displayed feed.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 8,
          "removed_lines": 7
        },
        {
          "observed_at": "2026-08-05T22:53:44Z",
          "window_start": "2026-08-05T21:53:23Z",
          "window_end": "2026-08-05T22:53:44Z",
          "status": "source-content",
          "summary": "The tracker added further hop-two fan-out records while removing an older Aug. 1 hop-one record from the visible movement feed.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 16,
          "removed_lines": 8
        },
        {
          "observed_at": "2026-08-05T21:53:23Z",
          "window_start": "2026-08-05T20:52:54Z",
          "window_end": "2026-08-05T21:53:23Z",
          "status": "source-content",
          "summary": "The tracker reported a small increase in the watched balance and additional hop-two movements, including a 1.29140163 BTC fan-out at block 961,204.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 22,
          "removed_lines": 6
        },
        {
          "observed_at": "2026-08-05T20:52:54Z",
          "window_start": "2026-08-05T18:51:59Z",
          "window_end": "2026-08-05T20:52:54Z",
          "status": "source-content",
          "summary": "The tracker recorded another 0.00000890 BTC increase at one watched holding, raised its held output count from 35 to 36, and added a 1.29140163 BTC Hop 2 movement with hundreds of outputs.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 21,
          "removed_lines": 5
        },
        {
          "observed_at": "2026-08-05T18:51:59Z",
          "window_start": "2026-08-05T17:51:42Z",
          "window_end": "2026-08-05T18:51:59Z",
          "status": "source-content",
          "summary": "The tracker added a 1.29140163 BTC Hop 2 transaction from the Aug. 2 vault path at block 961076 and its destination, while the live movement feed dropped an older Hop 1 entry.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 8,
          "removed_lines": 8
        },
        {
          "observed_at": "2026-08-05T17:51:42Z",
          "window_start": "2026-08-05T16:51:38Z",
          "window_end": "2026-08-05T17:51:42Z",
          "status": "source-content",
          "summary": "The tracker added a 1.29140163 BTC movement from the Aug. 2 vault path at block 961187, with hundreds of listed outputs, and restored a previously absent Hop 1 entry in the feed.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 17,
          "removed_lines": 1
        },
        {
          "observed_at": "2026-08-05T16:51:38Z",
          "window_start": "2026-08-05T15:51:23Z",
          "window_end": "2026-08-05T16:51:38Z",
          "status": "source-content",
          "summary": "The tracker recorded a 0.00001538 BTC increase at one watched holding and raised its listed held output count from 34 to 35. Its movement feed also no longer showed an older small Hop 1 transaction.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 5,
          "removed_lines": 13
        },
        {
          "observed_at": "2026-08-05T15:51:23Z",
          "window_start": "2026-08-05T14:51:18Z",
          "window_end": "2026-08-05T15:51:23Z",
          "status": "source-content",
          "summary": "The tracker now says some equal-denomination outputs reached Hyperunit, while qualifying that this does not prove a common operator and continuing to distinguish the unique residual path.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 1,
          "removed_lines": 1
        },
        {
          "observed_at": "2026-08-05T14:51:18Z",
          "window_start": "2026-08-05T10:50:32Z",
          "window_end": "2026-08-05T14:51:18Z",
          "status": "source-content",
          "summary": "The tracker replaced a short description of an Aug. 4 trail with a five-step account of a Taproot hop and subsequent Wasabi-style CoinJoin cascade, including residual amounts, blocks and still-live outputs.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 14,
          "removed_lines": 1
        },
        {
          "observed_at": "2026-08-05T10:50:32Z",
          "window_start": "2026-08-05T07:50:03Z",
          "window_end": "2026-08-05T10:50:32Z",
          "status": "source-content",
          "summary": "The tracker’s balance on watch increased by 0.00001000 BTC while its moved total fell by the same amount, and Holding 1 gained one UTXO while remaining HELD.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 5,
          "removed_lines": 5
        },
        {
          "observed_at": "2026-08-05T07:50:03Z",
          "window_start": "2026-08-05T05:49:16Z",
          "window_end": "2026-08-05T07:50:03Z",
          "status": "source-content",
          "summary": "The tracker added a Hop 2 transaction (11a3edd2...df46c1) moving 1.29140163 BTC from the Aug. 2 vault's Hop 1 trail in block 961,084, and listed more than 380 output destinations.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 8,
          "removed_lines": 0
        },
        {
          "observed_at": "2026-08-05T05:49:16Z",
          "window_start": "2026-08-05T02:17:44Z",
          "window_end": "2026-08-05T05:49:16Z",
          "status": "source-content",
          "summary": "The tracker added a Hop 2 transaction (65c79326...638de0) moving 1.29140163 BTC from the Aug. 2 vault's Hop 1 trail in block 961,077, and listed its 335 output destinations.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 8,
          "removed_lines": 0
        },
        {
          "observed_at": "2026-08-05T02:17:44Z",
          "window_start": "2026-08-05T00:39:40Z",
          "window_end": "2026-08-05T02:17:44Z",
          "status": "source-content",
          "summary": "The tracker advanced its chain data to block 961,093 and added a Hop 2 transaction from the Aug. 2 vault, plus a later Hop 1 movement from the Wave 4 park.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 17,
          "removed_lines": 1
        },
        {
          "observed_at": "2026-08-05T00:39:40Z",
          "window_start": "2026-08-05T00:09:36Z",
          "window_end": "2026-08-05T00:39:40Z",
          "status": "source-content",
          "summary": "The tracker added confirmed second-hop movements, including a new CoinJoin, and updated its assessment of the Aug. 2 vault trail.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 45,
          "removed_lines": 5
        },
        {
          "observed_at": "2026-08-05T00:09:36Z",
          "window_start": "2026-08-04T23:39:28Z",
          "window_end": "2026-08-05T00:09:36Z",
          "status": "source-content",
          "summary": "The tracker reported a second CoinJoin for the Aug. 2 vault residual, relabelled several P2TR transfers, and removed an Arkham attribution.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 40,
          "removed_lines": 157
        },
        {
          "observed_at": "2026-08-04T23:39:28Z",
          "window_start": "2026-08-04T22:39:19Z",
          "window_end": "2026-08-04T23:39:28Z",
          "status": "source-content",
          "summary": "The tracker added new unconfirmed hop movements from the P2TR vault and revised its movement feed.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 94,
          "removed_lines": 95
        },
        {
          "observed_at": "2026-08-04T22:39:19Z",
          "window_start": "2026-08-04T22:09:14Z",
          "window_end": "2026-08-04T22:39:19Z",
          "status": "source-content",
          "summary": "The tracker restored and added several historical Wave 4 and P2TR-vault movements, while removing several older hop entries.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 95,
          "removed_lines": 38
        },
        {
          "observed_at": "2026-08-04T22:09:14Z",
          "window_start": "2026-08-04T21:39:06Z",
          "window_end": "2026-08-04T22:09:14Z",
          "status": "source-content",
          "summary": "The tracker added a 0.00544006 BTC movement, revised destination labels, and removed several previously listed movements.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 90,
          "removed_lines": 149
        },
        {
          "observed_at": "2026-08-04T21:39:06Z",
          "window_start": "2026-08-04T21:09:02Z",
          "window_end": "2026-08-04T21:39:06Z",
          "status": "source-content",
          "summary": "The tracker added CoinJoin detail for the Aug. 2 vault movement and labeled several destinations as OP_RETURN messenger hubs.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 5,
          "removed_lines": 5
        },
        {
          "observed_at": "2026-08-04T21:09:02Z",
          "window_start": "2026-08-04T20:38:56Z",
          "window_end": "2026-08-04T21:09:02Z",
          "status": "source-content",
          "summary": "The tracker recorded a 64.90373154 BTC CoinJoin movement from the Aug. 2 vault and updated watched-holdings and Wave 4 movement records.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 60,
          "removed_lines": 58
        },
        {
          "observed_at": "2026-08-04T20:38:56Z",
          "window_start": "2026-08-04T19:38:54Z",
          "window_end": "2026-08-04T20:38:56Z",
          "status": "source-content",
          "summary": "The tracker updated its displayed balance totals and transaction trail as monitored funds moved.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 94,
          "removed_lines": 96
        },
        {
          "observed_at": "2026-08-04T19:38:54Z",
          "window_start": "2026-08-04T18:38:35Z",
          "window_end": "2026-08-04T19:38:54Z",
          "status": "source-content",
          "summary": "The tracker updated its displayed balance totals and transaction trail as monitored funds moved.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 72,
          "removed_lines": 69
        },
        {
          "observed_at": "2026-08-04T18:38:35Z",
          "window_start": "2026-08-04T17:38:21Z",
          "window_end": "2026-08-04T18:38:35Z",
          "status": "source-content",
          "summary": "The tracker added a cash-out trail for the later P2TR vault and updated the latest movement.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 233,
          "removed_lines": 216
        },
        {
          "observed_at": "2026-08-04T17:38:21Z",
          "window_start": "2026-08-04T16:08:07Z",
          "window_end": "2026-08-04T17:38:21Z",
          "status": "source-content",
          "summary": "The tracker updated watched balances and movement records for the later P2TR vault.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 107,
          "removed_lines": 109
        },
        {
          "observed_at": "2026-08-04T16:08:07Z",
          "window_start": "2026-08-04T14:07:48Z",
          "window_end": "2026-08-04T16:08:07Z",
          "status": "source-content",
          "summary": "The tracker recorded new outbound spending from the P2TR vault, increasing reported moved holdings from 6.81368697 BTC to 10.82430037 BTC.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 326,
          "removed_lines": 124
        },
        {
          "observed_at": "2026-08-04T14:07:48Z",
          "window_start": "2026-08-04T13:07:40Z",
          "window_end": "2026-08-04T14:07:48Z",
          "status": "source-content",
          "summary": "One duplicate-looking hop record was removed from the tracker’s watched-address listing.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 0,
          "removed_lines": 8
        },
        {
          "observed_at": "2026-08-04T13:07:40Z",
          "window_start": "2026-08-04T09:07:06Z",
          "window_end": "2026-08-04T13:07:40Z",
          "status": "source-content",
          "summary": "The tracker added Galaxy’s Aug. 3 high-confidence and candidate-Wave-4 totals, its estimate of at least 15 attackers, and a Chainabuse victim linkage for the early Aug. 2 consolidation.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 11,
          "removed_lines": 3
        },
        {
          "observed_at": "2026-08-04T09:07:06Z",
          "window_start": "2026-08-04T06:06:32Z",
          "window_end": "2026-08-04T09:07:06Z",
          "status": "source-content",
          "summary": "The movement feed gained a new HOP 2 entry: transaction 49dd2935...d49564 moved 0.24 BTC in block 960,668 from the Hop 2 address that descends from the Evening vault via bc1qzkap...6e4z, onward to bc1qprkj...jr98.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 8,
          "removed_lines": 0
        },
        {
          "observed_at": "2026-08-04T06:06:32Z",
          "window_start": "2026-08-04T03:05:19Z",
          "window_end": "2026-08-04T06:06:32Z",
          "status": "source-content",
          "summary": "The tracker removed a Hop 2 movement entry (tx 49dd2935...d49564, 0.24 BTC onward from bc1qzkap...6e4z to bc1qprkj...jr98 in block 960,668) from its evening-vault movement chain. No balances or other entries changed in this capture.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 0,
          "removed_lines": 8
        },
        {
          "observed_at": "2026-08-04T03:05:19Z",
          "window_start": "2026-08-04T01:44:59Z",
          "window_end": "2026-08-04T03:05:19Z",
          "status": "source-content",
          "summary": "The tracker added a 'Known waves only, total most likely higher' caveat under its headline and reworded the watched-holdings note from 'tracked clusters' to 'known waves'. The on-watch balance and moved figure shifted slightly (1,476.78438105 and 6.81368697 BTC), and Holding 1 and Holding 2 live balances and UTXO counts moved while both stayed HELD.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 11,
          "removed_lines": 9
        },
        {
          "observed_at": "2026-08-04T01:44:59Z",
          "window_start": "2026-08-04T00:44:47Z",
          "window_end": "2026-08-04T01:44:59Z",
          "status": "source-content",
          "summary": "The tracker annotated Wave 3 vault 6 as a Chainabuse victim's ~5.39 BTC Mk3 drain parked into that vault, and rewrote the Wave 4 Chainabuse victim label into a single inline attribution. The live UTXO counts for the Wave 4 vaults also moved off zero (62, 1 and 129 UTXOs respectively) while balances stayed HELD.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 5,
          "removed_lines": 5
        },
        {
          "observed_at": "2026-08-04T00:44:47Z",
          "window_start": "2026-08-03T21:44:06Z",
          "window_end": "2026-08-04T00:44:47Z",
          "status": "source-content",
          "summary": "The tracker added a new P2TR wave (Aug 1-3, 46.97389047 BTC watched across 3 Kelbie-reported Taproot sinks, ~5 sat/vB 1-vout sweeps, one corroborated by a Chainabuse victim report), credited Kevin Kelbie for it, and raised the totals: stolen from 1,876.83359078 to 1,923.80748125 BTC across 8 waves, balance on watch from 1,429.81046458 to 1,476.78435505 BTC.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 51,
          "removed_lines": 8
        },
        {
          "observed_at": "2026-08-03T21:44:06Z",
          "window_start": "2026-08-03T20:44:04Z",
          "window_end": "2026-08-03T21:44:06Z",
          "status": "source-content",
          "summary": "The tracker recorded a new hop-2 movement: 0.47797906 BTC spent at block 960,832 from a Hop 2 address downstream of the Wave 4 park, sent to 15 outputs. The movement feed gained the corresponding entry.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 11,
          "removed_lines": 3
        },
        {
          "observed_at": "2026-08-03T20:44:04Z",
          "window_start": "2026-08-03T19:43:47Z",
          "window_end": "2026-08-03T20:44:04Z",
          "status": "source-content",
          "summary": "The tracker withdrew the Hop 2 spend of 0.47797906 BTC at block 960,832 from its movement feed; the last movement is now the earlier Hop 1 spend of 0.50633044 BTC at block 960,822. Watched balances drifted upward again and Holding 1's UTXO count rose from 24 to 28.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 8,
          "removed_lines": 16
        },
        {
          "observed_at": "2026-08-03T19:43:47Z",
          "window_start": "2026-08-03T17:43:34Z",
          "window_end": "2026-08-03T19:43:47Z",
          "status": "source-content",
          "summary": "The watched balance rose from 1,429.81024343 to 1,429.81028381 BTC, the moved total dipped by the same roughly 0.00004 BTC, and Holding 1's displayed UTXO count rose from 21 to 24 while its status stayed HELD.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 5,
          "removed_lines": 5
        },
        {
          "observed_at": "2026-08-03T17:43:34Z",
          "window_start": "2026-08-03T16:43:39Z",
          "window_end": "2026-08-03T17:43:34Z",
          "status": "source-content",
          "summary": "The tracker's watched balance and moved totals shifted slightly and Holding 1 gained a UTXO, the last-movement card pointed at an earlier block, and the movement feed added a methodology line (\"Stops at known exchange, bridge, and service-hub exits\") while dropping many older hop-2 entries and adding a few new ones.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 32,
          "removed_lines": 225
        },
        {
          "observed_at": "2026-08-03T16:43:39Z",
          "window_start": "2026-08-03T15:10:40Z",
          "window_end": "2026-08-03T16:43:39Z",
          "status": "source-content",
          "summary": "The tracker added a large batch of new outbound hop transactions from the Wave 4 park address 324H9uyT...5CYq (blocks 960,810 to 960,882, several over 45 BTC each, one still unconfirmed), reinstated the 0.45 and 0.44999667 BTC Aug 1 vault hops while dropping two other vault hops, and nudged the watched balance to 1,429.81019684 BTC with Holding 1 at 20 UTXOs. It also added a Multisig urgency and Slipstream guidance section and a Nunchuk entry to its reading list.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 247,
          "removed_lines": 24
        },
        {
          "observed_at": "2026-08-03T15:10:40Z",
          "window_start": "2026-08-03T14:12:59Z",
          "window_end": "2026-08-03T15:10:40Z",
          "status": "source-content",
          "summary": "The tracker removed two hop transactions (a 0.45 BTC hop and a 0.44999667 BTC hop through 3P3K2MQw...Lfgy) from its chain trace, and expanded its migration guidance: it now cites an open firmware PR arguing that a sticky TRNG fault after the hotfix can lock the keypad before login, alongside the existing bricking warning.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 1,
          "removed_lines": 17
        },
        {
          "observed_at": "2026-08-03T14:12:59Z",
          "window_start": "2026-08-03T13:13:04Z",
          "window_end": "2026-08-03T14:12:59Z",
          "status": "source-content",
          "summary": "The Watched holdings paragraph was revised: the remaining roughly 440.2 BTC is now described as mostly unwatched Wave 4 destinations (a sparse still-held sample) plus smaller or unmatched Wave 3 vaults and fees, and the different-operators caveat now lists the community waves by name. The Balance on Watch stat block also moved above the Still Held block, which is presentational.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 8,
          "removed_lines": 8
        },
        {
          "observed_at": "2026-08-03T13:13:04Z",
          "window_start": "2026-08-03T09:06:04Z",
          "window_end": "2026-08-03T13:13:04Z",
          "status": "source-content",
          "summary": "The cash-out section expanded from two rails to three, adding a roughly 0.27 BTC rail from the evening vault through bc1qdt6c and bc1qs86u into two KuCoin deposits (emptied Aug 3 01:22 UTC). The Wave 4 note now also explains the tracker's 443.34 BTC figure as Galaxy's revised 448.73 BTC minus six destinations with prior on-chain history, and reconciles it against press totals near 1,816 BTC.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 6,
          "removed_lines": 6
        },
        {
          "observed_at": "2026-08-03T09:06:04Z",
          "window_start": "2026-08-03T05:03:12Z",
          "window_end": "2026-08-03T09:06:04Z",
          "status": "source-content",
          "summary": "The movement feed added a Hop 2 spend of 0.47797906 BTC at block 960,832 from the Hop 1 destination of the Wave 4 park vault, paid out across 15 addresses, and the Last Movement panel updated to match. No balance or status lines changed in this capture.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 11,
          "removed_lines": 3
        },
        {
          "observed_at": "2026-08-03T05:03:12Z",
          "window_start": "2026-08-03T04:03:07Z",
          "window_end": "2026-08-03T05:03:12Z",
          "status": "source-content",
          "summary": "The tracker restated Wave 4 as a pattern-match-only estimate (no victim report yet) of about 443.34 BTC across 703 addresses after filtering out 89 multisigs and 6 prior-history destinations, raising the headline total from 1,822.42 to 1,876.83 BTC. The Wave 4 park vault 1N8knQCf emptied (about 2.82 BTC onward to Coinbase Prime Custody at block 960,818), lifting MOVED to 6.81 BTC and adding new hop-1 movement entries.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 39,
          "removed_lines": 22
        },
        {
          "observed_at": "2026-08-03T04:03:07Z",
          "window_start": "2026-08-03T03:02:48Z",
          "window_end": "2026-08-03T04:03:07Z",
          "status": "source-content",
          "summary": "Removed the '1:1 destination sample (still held at add)' annotation row from eight Wave 4 park address entries, and dropped the footer provenance line (core vaults live via snapshot, Wave 3 from cron snapshot, incident facts from Galaxy Research and community cluster reports), leaving only the not-affiliated disclaimer. Balances and statuses were unchanged.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 1,
          "removed_lines": 9
        },
        {
          "observed_at": "2026-08-03T03:02:48Z",
          "window_start": "2026-08-03T02:02:36Z",
          "window_end": "2026-08-03T03:02:48Z",
          "status": "source-content",
          "summary": "Recorded the first Wave 4 park movement: about 2.79 BTC peeled to a Bullish.com deposit plus a 4.28 BTC second-hop distribution, lifting MOVED from 1.20 to 3.99 BTC and dropping STILL HELD to 99.7 percent.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 38,
          "removed_lines": 15
        },
        {
          "observed_at": "2026-08-03T02:02:36Z",
          "window_start": "2026-08-03T01:02:29Z",
          "window_end": "2026-08-03T02:02:36Z",
          "status": "source-content",
          "summary": "Added a Likely Wave 4 section attributed to Alex Thorn (388.92748828 BTC, 462 victims to 216 fresh 1:1 destinations, blocks 960,778 to 960,792) and raised the total stolen figure from 1,433.49 to 1,822.42 BTC across seven waves.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 108,
          "removed_lines": 23
        },
        {
          "observed_at": "2026-08-03T01:02:29Z",
          "window_start": "2026-08-03T00:02:17Z",
          "window_end": "2026-08-03T01:02:29Z",
          "status": "source-content",
          "summary": "Expanded the ETH rail from about 0.24 to about 11.7 ETH with a traced path through vanity hops into a 23 ETH KuCoin deposit, and added Erik, a Mk3 testing-device victim swept in the early Aug 2 consolidation.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 17,
          "removed_lines": 13
        },
        {
          "observed_at": "2026-08-03T00:02:17Z",
          "window_start": "2026-08-02T23:02:08Z",
          "window_end": "2026-08-03T00:02:17Z",
          "status": "source-content",
          "summary": "Recast the P2SH cash-out hub as a service hub, weakened the Ocean-peel claim from a strong same-operator link to same exit venue, not proof of same operator, and described the BTC rail as a likely custodial or swap deposit.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 20,
          "removed_lines": 20
        },
        {
          "observed_at": "2026-08-02T23:02:08Z",
          "window_start": "2026-08-02T22:01:58Z",
          "window_end": "2026-08-02T23:02:08Z",
          "status": "source-content",
          "summary": "The LOWER RISK guidance now says weak passphrases are not enough, citing a BTC Sessions report of a confirmed Mk3 drain behind a two-word passphrase. Live-counter jitter and the feed and footer rendering churn also appear in the same capture.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 15,
          "removed_lines": 15
        },
        {
          "observed_at": "2026-08-02T22:01:58Z",
          "window_start": "2026-08-02T21:01:47Z",
          "window_end": "2026-08-02T22:01:58Z",
          "status": "capture-noise",
          "summary": "Only the footer cron-snapshot timestamp advanced, from Aug 3, 04:07 AM to 05:22 AM.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 1,
          "removed_lines": 1
        },
        {
          "observed_at": "2026-08-02T21:01:47Z",
          "window_start": "2026-08-02T20:01:37Z",
          "window_end": "2026-08-02T21:01:47Z",
          "status": "source-content",
          "summary": "Added a MIGRATE BEFORE YOU UPGRADE section warning that the hotfix can brick a unit whose weak seed is its only signer, citing community reports including Jameson Lopp. Live counters and the footer snapshot timestamp also moved in the same capture.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 8,
          "removed_lines": 6
        },
        {
          "observed_at": "2026-08-02T20:01:37Z",
          "window_start": "2026-08-02T19:01:26Z",
          "window_end": "2026-08-02T20:01:37Z",
          "status": "capture-noise",
          "summary": "Same live-counter jitter (balances up roughly 0.00001 BTC, UTXO counts up one) plus the movement-feed origin lines and footer snapshot line flip-flopping back to their previous renderings.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 29,
          "removed_lines": 29
        },
        {
          "observed_at": "2026-08-02T19:01:26Z",
          "window_start": "2026-08-02T18:01:31Z",
          "window_end": "2026-08-02T19:01:26Z",
          "status": "capture-noise",
          "summary": "Only live counters and rendering state moved: watched balances drifted by sub-0.0001 BTC, the movement-feed origin lines rendered in their expanded hop-path form, and the footer snapshot line changed wording and timestamp. No claim on the page changed.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 12,
          "removed_lines": 12
        },
        {
          "observed_at": "2026-08-02T18:01:31Z",
          "window_start": "2026-08-02T17:01:07Z",
          "window_end": "2026-08-02T18:01:31Z",
          "status": "capture-noise",
          "summary": "Only the footer cron snapshot timestamp advanced (Aug 3, 12:49 AM to 01:54 AM).",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 1,
          "removed_lines": 1
        },
        {
          "observed_at": "2026-08-02T17:01:07Z",
          "window_start": "2026-08-02T16:01:06Z",
          "window_end": "2026-08-02T17:01:07Z",
          "status": "capture-noise",
          "summary": "Only the footer cron snapshot timestamp advanced (Aug 2, 11:35 PM to Aug 3, 12:49 AM).",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 1,
          "removed_lines": 1
        },
        {
          "observed_at": "2026-08-02T16:01:06Z",
          "window_start": "2026-08-02T15:06:32Z",
          "window_end": "2026-08-02T16:01:06Z",
          "status": "capture-noise",
          "summary": "Only the footer cron snapshot timestamp advanced (Aug 2, 11:01 PM to 11:35 PM).",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 1,
          "removed_lines": 1
        },
        {
          "observed_at": "2026-08-02T15:06:32Z",
          "window_start": "2026-08-02T15:00:51Z",
          "window_end": "2026-08-02T15:06:32Z",
          "status": "capture-noise",
          "summary": "Only the footer cron snapshot timestamp advanced (Aug 2, 10:56 PM to 11:01 PM).",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 1,
          "removed_lines": 1
        },
        {
          "observed_at": "2026-08-02T15:00:51Z",
          "window_start": "2026-08-02T13:00:25Z",
          "window_end": "2026-08-02T15:00:51Z",
          "status": "source-content",
          "summary": "The tracker added a sixth wave, an early Aug 2 consolidation of 64.90947964 BTC from about 795 addresses into one vault attributed to a community Mk2 report by Marius Offchain, raising its headline total from 1,368.58411114 to 1,433.49359078 BTC. It also added an Aug 2 cash-out section describing BTC and ETH (THORChain, Orbiter) rails and restructured each wave summary into SCOPE/BLOCKS/FEE fields.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 113,
          "removed_lines": 57
        },
        {
          "observed_at": "2026-08-02T13:00:25Z",
          "window_start": "2026-08-02T12:00:15Z",
          "window_end": "2026-08-02T13:00:25Z",
          "status": "capture-noise",
          "summary": "A partially hydrated render of the client-side page: balances reverted to pre-095953Z values, hop labels rendered as provenance chains with truncated addresses dropping out, and the footer lost its mempool.space clause; the next capture restored all of it.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 14,
          "removed_lines": 14
        },
        {
          "observed_at": "2026-08-02T12:00:15Z",
          "window_start": "2026-08-02T09:59:53Z",
          "window_end": "2026-08-02T12:00:15Z",
          "status": "capture-noise",
          "summary": "Only the footer cron snapshot timestamp advanced (Aug 2, 05:32 PM to 07:11 PM).",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 1,
          "removed_lines": 1
        },
        {
          "observed_at": "2026-08-02T09:59:53Z",
          "window_start": "2026-08-02T07:58:48Z",
          "window_end": "2026-08-02T09:59:53Z",
          "status": "capture-noise",
          "summary": "Only live-polled counters moved: balance on watch and Holding 1 shifted by about 546 sats with the UTXO count going 11 to 12, the MOVED figure decreased (impossible for settled spends, so a mixed render), and the footer cron timestamp advanced.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 6,
          "removed_lines": 6
        },
        {
          "observed_at": "2026-08-02T07:58:48Z",
          "window_start": "2026-08-02T07:53:38Z",
          "window_end": "2026-08-02T07:58:48Z",
          "status": "capture-noise",
          "summary": "The alerts indicator flipped from Off to Blocked, the notification-permission state of the capture browser, and the footer cron timestamp was reformatted (2 Aug, 15:28 to Aug 2, 03:28 PM) with the snapshot instant unchanged.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 2,
          "removed_lines": 2
        },
        {
          "observed_at": "2026-08-02T07:53:38Z",
          "window_start": "2026-08-02T05:48:03Z",
          "window_end": "2026-08-02T07:53:38Z",
          "status": "capture-noise",
          "summary": "Only the footer cron snapshot clock advanced (2 Aug, 13:21 to 15:28); balances, holdings and the movement feed were unchanged.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 1,
          "removed_lines": 1
        },
        {
          "observed_at": "2026-08-02T05:48:03Z",
          "window_start": "2026-08-02T05:15:26Z",
          "window_end": "2026-08-02T05:48:03Z",
          "status": "source-content",
          "summary": "The Wave 3 watch list grew from 74 to 78 vaults (about 184.97 BTC) with four newly added vaults, and the attribution text now says the matches were cross-checked against the public COLDCARD RNG chain map.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 76,
          "removed_lines": 56
        },
        {
          "observed_at": "2026-08-02T05:15:26Z",
          "window_start": "2026-08-02T04:40:38Z",
          "window_end": "2026-08-02T05:15:26Z",
          "status": "source-content",
          "summary": "The tracker removed the 1.05 BTC vault bc1qm5z7e2 from its Wave 3 watch list, cutting the count from 75 to 74 vaults and the watched total to 180.23598197 BTC with no matching movement-feed entry, a delisting rather than a spend.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 109,
          "removed_lines": 114
        },
        {
          "observed_at": "2026-08-02T04:40:38Z",
          "window_start": "2026-08-02T04:09:06Z",
          "window_end": "2026-08-02T04:40:38Z",
          "status": "source-content",
          "summary": "A new hop-2 spend of 0.269792 BTC in block 960,669 became the last movement, and the evening-wave narrative was rewritten: both watched holdings emptied Aug 1-2 and stolen hops plus the Ocean miner peel consolidated into the same P2SH address 3KMmeqPe, which the tracker presents as a same-operator link.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 16,
          "removed_lines": 8
        },
        {
          "observed_at": "2026-08-02T04:09:06Z",
          "window_start": "2026-08-02T03:06:55Z",
          "window_end": "2026-08-02T04:09:06Z",
          "status": "source-content",
          "summary": "The evening vault emptied (0.50980268 BTC, now marked EMPTIED), the moved total rose to 1.20115791 BTC, and the feed added confirmed hop-1 and hop-2 spends across blocks 960,658 to 960,668, several peeling toward P2SH destinations.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 60,
          "removed_lines": 13
        },
        {
          "observed_at": "2026-08-02T03:06:55Z",
          "window_start": "2026-08-02T02:35:33Z",
          "window_end": "2026-08-02T03:06:55Z",
          "status": "source-content",
          "summary": "The movement feed dropped the earlier confirmed 0.06042459 BTC entry and showed the unconfirmed 0.69135523 BTC spend from the Aug 1 hop vault as the last movement.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 5,
          "removed_lines": 12
        },
        {
          "observed_at": "2026-08-02T02:35:33Z",
          "window_start": "2026-08-02T00:59:59Z",
          "window_end": "2026-08-02T02:35:33Z",
          "status": "source-content",
          "summary": "The tracker narrowed its Wave 3 watch from 221 vaults to 75 higher-value matches of at least 0.5 BTC (about 181.29 BTC), and recorded the first outbound movement: the Aug 1 hop vault showed EMPTIED with 0.69135523 BTC moved and the movement feed listed its first transactions.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 42,
          "removed_lines": 754
        },
        {
          "observed_at": "2026-08-02T00:59:59Z",
          "window_start": "2026-08-02T00:31:24Z",
          "window_end": "2026-08-02T00:59:59Z",
          "status": "source-content",
          "summary": "The tracker added a Wave 3 section watching 221 fingerprint-matched P2WSH vaults (about 201.45 BTC) with a new attribution rationale, raising its consolidated figure from 1,160.19028 BTC to 1,361.64515804 BTC and rewriting the footer for the live-plus-cron-snapshot model.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 1166,
          "removed_lines": 26
        },
        {
          "observed_at": "2026-08-02T00:31:24Z",
          "window_start": "2026-08-02T00:17:55Z",
          "window_end": "2026-08-02T00:31:24Z",
          "status": "capture-noise",
          "summary": "Fiat price data failed to resolve in this capture: the header fell back to Across tracked clusters, table fiat lines collapsed to USD pending, and the footer named another rotating fallback mirror. BTC balances and holdings were unchanged.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 12,
          "removed_lines": 36
        },
        {
          "observed_at": "2026-08-02T00:17:55Z",
          "window_start": "2026-08-02T00:11:02Z",
          "window_end": "2026-08-02T00:17:55Z",
          "status": "capture-noise",
          "summary": "Only the live fiat spot figure moved and the footer named a different fallback explorer mirror (mempool.emzy.de instead of mempool.space); BTC balances and movement state were unchanged.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 2,
          "removed_lines": 2
        },
        {
          "observed_at": "2026-08-02T00:11:02Z",
          "window_start": "2026-08-01T21:52:43Z",
          "window_end": "2026-08-02T00:11:02Z",
          "status": "source-content",
          "summary": "The operator rebuilt the tracker around a five-wave model: the July 31 entry split into Galaxy Wave 2 and a new Galaxy Wave 3 spanning Jul 31 to Aug 1, the headline total moved from 1,130.09411114 to 1,368.58411114 BTC, consolidated holdings from 1,130.00551671 to 1,160.19028 BTC, and the July 30 heading was renamed from Galaxy fingerprint to Galaxy Wave 1.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 56,
          "removed_lines": 30
        },
        {
          "observed_at": "2026-08-01T21:52:43Z",
          "window_start": "2026-08-01T21:21:08Z",
          "window_end": "2026-08-01T21:52:43Z",
          "status": "capture-noise",
          "summary": "Only the live fiat conversion changed; the BTC totals, cluster descriptions and movement state were unchanged.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 1,
          "removed_lines": 1
        },
        {
          "observed_at": "2026-08-01T21:21:08Z",
          "window_start": "2026-08-01T20:50:08Z",
          "window_end": "2026-08-01T21:21:08Z",
          "status": "source-content",
          "summary": "The evening-wave description gained a clause noting that the Kelbie vault also occurred on 31 July; the live fiat conversion changed in the same capture.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 2,
          "removed_lines": 2
        },
        {
          "observed_at": "2026-08-01T20:50:08Z",
          "window_start": "2026-08-01T20:18:43Z",
          "window_end": "2026-08-01T20:50:08Z",
          "status": "capture-noise",
          "summary": "Only the live fiat conversion changed; the BTC totals, cluster descriptions and movement state were unchanged.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 1,
          "removed_lines": 1
        },
        {
          "observed_at": "2026-08-01T20:18:43Z",
          "window_start": "2026-08-01T19:47:28Z",
          "window_end": "2026-08-01T20:18:43Z",
          "status": "capture-noise",
          "summary": "Only the live fiat conversion changed; the BTC totals, cluster descriptions and movement state were unchanged.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 1,
          "removed_lines": 1
        },
        {
          "observed_at": "2026-08-01T19:47:28Z",
          "window_start": "2026-08-01T19:16:23Z",
          "window_end": "2026-08-01T19:47:28Z",
          "status": "source-content",
          "summary": "The tracked total rose to 1,130.09411114 BTC after a delayed 0.19 BTC victim consolidation joined the Aug 1 hop vault. The tracker also recorded an Ocean block-960511 miner payout that touched the hop address and was peeled off, listing it as a possible lead that it does not count as stolen.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 14,
          "removed_lines": 10
        },
        {
          "observed_at": "2026-08-01T19:16:23Z",
          "window_start": "2026-08-01T18:45:24Z",
          "window_end": "2026-08-01T19:16:23Z",
          "status": "source-content",
          "summary": "The tracker added a 'TOTAL STOLEN' headline of 1,129.90257437 BTC with a four-wave breakdown chart, and raised the balance on watch to 1,130.00551671 BTC after a second UTXO reached the Aug 1 hop vault.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 37,
          "removed_lines": 5
        },
        {
          "observed_at": "2026-08-01T18:45:24Z",
          "window_start": "2026-08-01T17:43:06Z",
          "window_end": "2026-08-01T18:45:24Z",
          "status": "source-content",
          "summary": "The tracked total rose from 1,129.31416148 to 1,129.81397994 BTC, a separate 'Aug 1 hop vault' holding was added to the evening-wave cluster, the risk checklist gained Mk3 5.0.1 to 5.0.3, a seed-origin item and revised passphrase wording, and WizardSardine and Kevin Loaec were added as sources.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 27,
          "removed_lines": 11
        },
        {
          "observed_at": "2026-08-01T17:43:06Z",
          "window_start": "2026-08-01T17:12:32Z",
          "window_end": "2026-08-01T17:43:06Z",
          "status": "source-content",
          "summary": "The tracker restated its movement feed in terms of the reported consolidation only: the earlier outbound spend and unconfirmed hop were removed from the feed, last movement returned to 'Unmoved', and a note was added that later surplus passing through a vault is ignored while the reported balance remains.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 6,
          "removed_lines": 17
        },
        {
          "observed_at": "2026-08-01T17:12:32Z",
          "window_start": "2026-08-01T16:41:20Z",
          "window_end": "2026-08-01T17:12:32Z",
          "status": "source-content",
          "summary": "The tracker added an unconfirmed hop-1 movement of 0.4998206 BTC onward from the followed destination of the evening vault's first outbound spend.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 8,
          "removed_lines": 0
        },
        {
          "observed_at": "2026-08-01T16:41:20Z",
          "window_start": "2026-08-01T16:07:44Z",
          "window_end": "2026-08-01T16:41:20Z",
          "status": "source-content",
          "summary": "The tracker withdrew the Mk4 attribution for the 1 August morning wave, recording the seed as Mk3-origin, removed the 'Mk4 is in scope now' panel, and recorded the first outbound spend of 0.4099166 BTC from the evening vault at 16:33 UTC.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 12,
          "removed_lines": 11
        },
        {
          "observed_at": "2026-08-01T16:07:44Z",
          "window_start": "2026-08-01T15:36:39Z",
          "window_end": "2026-08-01T16:07:44Z",
          "status": "source-content",
          "summary": "The tracker's watched balance rose from 1,129.31416148 BTC to 1,129.6240794 BTC and the evening vault's displayed balance and UTXO count changed, while the reported consolidated figure for that vault stayed at 0.50980268 BTC.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 3,
          "removed_lines": 3
        },
        {
          "observed_at": "2026-08-01T15:36:39Z",
          "window_start": "2026-08-01T15:05:28Z",
          "window_end": "2026-08-01T15:36:39Z",
          "status": "source-content",
          "summary": "The tracker added an 'Aug 1 morning wave' cluster with a new vault address holding 0.33203236 BTC from 16 sweeps, described it as including a reported Mk4 RNG and duress-wallet honeypot attributed to Tomer Strolight while noting the device model is not visible on chain, added an 'Mk4 is in scope now' panel, and changed its headline to a running total.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 25,
          "removed_lines": 8
        },
        {
          "observed_at": "2026-08-01T15:05:28Z",
          "window_start": "2026-08-01T14:34:18Z",
          "window_end": "2026-08-01T15:05:28Z",
          "status": "source-content",
          "summary": "The tracker replaced its likely-exposed paragraph with a per-model vulnerable and fixed version table covering Mk3, Mk4, Mk5, Q and both Edge tracks, and moved the evening vault's block reference from the row label into the cluster description.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 11,
          "removed_lines": 3
        },
        {
          "observed_at": "2026-08-01T14:34:18Z",
          "window_start": "2026-08-01T14:03:11Z",
          "window_end": "2026-08-01T14:34:18Z",
          "status": "source-content",
          "summary": "The tracker rewrote its reader-guidance section against the August 1 advisory and Block's writeup, added a 'beyond the main seed' item covering paper-wallet keys, Seed XOR masks and Key Teleport, clone and Secure Notes material, moved the Galaxy scope figures into the cluster card, and replaced its short source labels with descriptive per-source summaries including CoinDesk and Clay Garrett. Holding 2's UTXO count also changed from one to two.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 33,
          "removed_lines": 15
        },
        {
          "observed_at": "2026-08-01T14:03:11Z",
          "window_start": "2026-08-01T13:01:13Z",
          "window_end": "2026-08-01T14:03:11Z",
          "status": "source-content",
          "summary": "The tracker added a third cluster, an 'Evening wave' of 31 July with its own 0.50980268 BTC vault attributed to Evan Schoenberg, restated every holding at full satoshi precision, and changed its headline from 1,128.56 BTC across two clusters to 1,129.06986038 BTC across three.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 29,
          "removed_lines": 15
        },
        {
          "observed_at": "2026-08-01T13:01:13Z",
          "window_start": "2026-08-01T10:26:29Z",
          "window_end": "2026-08-01T13:01:13Z",
          "status": "source-content",
          "summary": "The monitor changed Holding 1's displayed UTXO count from ten to eleven while its BTC balance and held status remained unchanged.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 1,
          "removed_lines": 1
        },
        {
          "observed_at": "2026-08-01T10:26:29Z",
          "window_start": "2026-08-01T09:53:15Z",
          "window_end": "2026-08-01T10:26:29Z",
          "status": "source-content",
          "summary": "The monitor changed Holding 1's displayed UTXO count from nine to ten while its BTC balance and held status remained unchanged.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 1,
          "removed_lines": 1
        },
        {
          "observed_at": "2026-08-01T09:53:15Z",
          "window_start": "2026-08-01T08:35:21Z",
          "window_end": "2026-08-01T09:53:15Z",
          "status": "source-content",
          "summary": "The monitor changed Holding 1's displayed UTXO count from eight to nine while its BTC balance and held status remained unchanged.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 1,
          "removed_lines": 1
        },
        {
          "observed_at": "2026-08-01T08:35:21Z",
          "window_start": "2026-08-01T08:18:05Z",
          "window_end": "2026-08-01T08:35:21Z",
          "status": "capture-correction",
          "summary": "The rendered capture again held the monitor's hydrated chain data after the preceding temporary loading-state capture.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 61,
          "removed_lines": 14
        },
        {
          "observed_at": "2026-08-01T08:18:05Z",
          "window_start": "2026-08-01T08:13:31Z",
          "window_end": "2026-08-01T08:18:05Z",
          "status": "capture-noise",
          "summary": "The rendered capture held the monitor's temporary loading state instead of its hydrated chain data.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 14,
          "removed_lines": 61
        },
        {
          "observed_at": "2026-08-01T08:13:31Z",
          "window_start": "2026-08-01T03:51:09Z",
          "window_end": "2026-08-01T08:13:31Z",
          "status": "source-content",
          "summary": "The monitor changed Holding 1's displayed UTXO count from seven to eight while its BTC balance and held status remained unchanged.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 1,
          "removed_lines": 1
        },
        {
          "observed_at": "2026-08-01T03:51:09Z",
          "window_start": "2026-08-01T03:22:57Z",
          "window_end": "2026-08-01T03:51:09Z",
          "status": "source-content",
          "summary": "The tracker added a separately attributed 45.91 BTC post-scan cluster and changed its headline total; live fiat figures also changed in the same capture.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 64,
          "removed_lines": 43
        },
        {
          "observed_at": "2026-08-01T03:22:57Z",
          "window_start": "2026-08-01T03:05:58Z",
          "window_end": "2026-08-01T03:22:57Z",
          "status": "capture-noise",
          "summary": "Only live fiat conversions changed; the BTC balances and movement state were unchanged.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 6,
          "removed_lines": 6
        },
        {
          "observed_at": "2026-08-01T03:05:58Z",
          "window_start": "2026-08-01T02:59:29Z",
          "window_end": "2026-08-01T03:05:58Z",
          "status": "capture-noise",
          "summary": "Only live fiat conversions changed; the BTC balances and movement state were unchanged.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 6,
          "removed_lines": 6
        },
        {
          "observed_at": "2026-08-01T02:59:29Z",
          "window_start": "2026-08-01T02:34:16Z",
          "window_end": "2026-08-01T02:59:29Z",
          "status": "capture-correction",
          "summary": "The browser capture obtained the rendered tracker after the initial scripted capture held an empty client-side shell.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 105,
          "removed_lines": 0
        }
      ]
    },
    {
      "id": "coldcard-rip-tracker",
      "title": "coldcard.rip incident tracker",
      "url": "https://coldcard.rip/",
      "organisation": "community tracker",
      "kind": "chain-monitor",
      "role": "Chain monitor",
      "publication_time": null,
      "note": "Kevin Kelbie's rebuilt tracker, successor to the railway deployment announced\n2 August 2026. Self-described as AI-compiled and not independently\nfact-checked. Reorganises the incident into ten waves: the three first-night\nwaves matching Block's published totals, the 31 July 45.9 BTC cluster now\nintegrated as wave 960345 (1,126 swept addresses, vault\nbc1qtfrwa4j6rmj9rsgspv6a0yjumkg39js2numu75), and six further waves through\nblock 960,737, each anchored with named claimant, Chainabuse and Galaxy\nevidence. Snapshot of 3 August 2026 17:07:58Z states 1,433.13 BTC swept from\n5,477 addresses. The header snapshot clock advances with the operator's\nrebuilds and no existing normalizer matches it; if it drifts without content\nchange, classify the churn rather than rewriting captures.\n\nThe operator rebuilt the page again on 5 August 2026 around plates (\"The\nsweep\", \"Flow chart\", \"Routes\", \"Address ledger\", \"Evidence\"), which removed\nthe \"How the waves are evidenced\" heading this capture keyed on and shortened\n\"Data snapshot\" to \"Snapshot\". Every poll from 4 August 01:45 recorded a\nblocked capture against that missing string, so the record shows no change\nacross a live rebuild. The guard now keys on the two headline figure labels\nplus \"tracked sweeps took\", the standfirst clause carrying the swept total,\naddress count and post-fee receipt: the strings the site reads are the\nstrings that gate the capture.\n",
      "gone": null,
      "capture": {
        "status": "held",
        "copies": 3,
        "first_observed": "2026-08-03T21:51:24Z",
        "last_observed": "2026-08-05T08:28:24Z",
        "last_checked": "2026-08-15T14:24:07Z"
      },
      "differences": [
        {
          "observed_at": "2026-08-05T08:28:24Z",
          "window_start": "2026-08-03T23:44:45Z",
          "window_end": "2026-08-05T08:28:24Z",
          "status": "source-content",
          "summary": "The tracker was rebuilt into abbreviated numbered plates, replacing detailed address, wave-evidence, fingerprint and route-accounting sections with headline totals and short labels. It now states that it is unaffiliated with Coinkite or COLDCARD and describes the tracked funds as tentative inferences from victim reports and on-chain heuristics.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 27,
          "removed_lines": 1792
        },
        {
          "observed_at": "2026-08-03T23:44:45Z",
          "window_start": "2026-08-03T21:51:24Z",
          "window_end": "2026-08-03T23:44:45Z",
          "status": "source-content",
          "summary": "Substantive revision of the Galaxy cross-check for wave 960395: the comparison moved from \"explained difference\" to \"unresolved\", with new analysis concluding Galaxy's 300th sweep is unidentified and its coins never reached a vault. Balance-at-snapshot figures updated (1,432.45888972 BTC, dust payments 17 to 26), the Taproot wave 960737 fee-base reading was corrected to a build constant rather than an output-size match, and the data snapshot stamp advanced to 2026-08-03 22:59:15Z.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 16,
          "removed_lines": 13
        }
      ]
    },
    {
      "id": "coldcard-rip-sweep",
      "title": "coldcard.rip: the sweep",
      "url": "https://coldcard.rip/sweep",
      "organisation": "community tracker",
      "kind": "chain-monitor",
      "role": "Chain monitor",
      "publication_time": null,
      "note": "The swept totals behind the index headline: UTXOs, confirmed sweep\ntransactions and BTC, broken down by wave. Self-described as AI-compiled and\nnot independently fact-checked, like the rest of this tracker.\n",
      "gone": null,
      "capture": {
        "status": "held",
        "copies": 1,
        "first_observed": "2026-08-05T08:30:29Z",
        "last_observed": "2026-08-05T08:30:29Z",
        "last_checked": "2026-08-15T14:24:09Z"
      },
      "differences": []
    },
    {
      "id": "coldcard-rip-flow",
      "title": "coldcard.rip: flow chart",
      "url": "https://coldcard.rip/flow",
      "organisation": "community tracker",
      "kind": "chain-monitor",
      "role": "Chain monitor",
      "publication_time": null,
      "note": "Wave-by-wave flow from swept addresses to destinations, the largest of the\ntracker's data pages. Overlaps Galaxy's published flow-of-funds mapping\nwithout being derived from it; where the two disagree, both are held.\n",
      "gone": null,
      "capture": {
        "status": "held",
        "copies": 1,
        "first_observed": "2026-08-05T08:31:07Z",
        "last_observed": "2026-08-05T08:31:07Z",
        "last_checked": "2026-08-15T14:24:11Z"
      },
      "differences": []
    },
    {
      "id": "coldcard-rip-routes",
      "title": "coldcard.rip: routes and balances",
      "url": "https://coldcard.rip/routes",
      "organisation": "community tracker",
      "kind": "chain-monitor",
      "role": "Chain monitor",
      "publication_time": null,
      "note": "Where the proceeds sit now, and how much of the swept total is still at\ntracked destinations. This is the page that would move first if the operator\nspent from a holding address, so it is the one worth rechecking.\n",
      "gone": null,
      "capture": {
        "status": "held",
        "copies": 1,
        "first_observed": "2026-08-05T08:30:30Z",
        "last_observed": "2026-08-05T08:30:30Z",
        "last_checked": "2026-08-15T14:24:13Z"
      },
      "differences": []
    },
    {
      "id": "coldcard-rip-ledger",
      "title": "coldcard.rip: address ledger",
      "url": "https://coldcard.rip/ledger",
      "organisation": "community tracker",
      "kind": "chain-monitor",
      "role": "Chain monitor",
      "publication_time": null,
      "note": "The swept-address ledger, filterable by wave through query parameters the\nindex links (`?ledger=source&wave=N`). Registered at the unparameterised URL:\nthe wave views are the same ledger sorted, and capturing ten of them would\nrecord one dataset ten times. Published address sets are publishable here\nunder the 3 August 2026 decision.\n",
      "gone": null,
      "capture": {
        "status": "held",
        "copies": 1,
        "first_observed": "2026-08-05T08:30:31Z",
        "last_observed": "2026-08-05T08:30:31Z",
        "last_checked": "2026-08-15T14:24:15Z"
      },
      "differences": []
    },
    {
      "id": "coldcard-rip-attribution",
      "title": "coldcard.rip: how the waves are evidenced",
      "url": "https://coldcard.rip/attribution",
      "organisation": "community tracker",
      "kind": "chain-monitor",
      "role": "Chain monitor",
      "publication_time": null,
      "note": "The tracker's own account of what each wave attribution rests on, naming the\nclaimants and public sources behind ten waves. This is the page that makes\nthe rest of the tracker checkable, and it carried the heading the index\ncapture keyed on until the 5 August rebuild moved it here.\n",
      "gone": null,
      "capture": {
        "status": "held",
        "copies": 1,
        "first_observed": "2026-08-05T08:30:32Z",
        "last_observed": "2026-08-05T08:30:32Z",
        "last_checked": "2026-08-15T14:24:17Z"
      },
      "differences": []
    },
    {
      "id": "optech-416",
      "title": "Bitcoin Optech Newsletter #416",
      "url": "https://bitcoinops.org/en/newsletters/2026/07/31/",
      "organisation": "Bitcoin Optech",
      "kind": "analysis",
      "role": "Secondary analysis",
      "publication_time": "2026-07-31",
      "note": "Newsletter #416 led with the incident. It carries the unitemised estimate 'exceed 1,000 BTC' and dates the theft transactions to 29 July, possibly consistent with a US-local date; the newsletter does not state a timezone.",
      "gone": null,
      "capture": {
        "status": "held",
        "copies": 2,
        "first_observed": "2026-08-01T02:53:20Z",
        "last_observed": "2026-08-05T21:05:13Z",
        "last_checked": "2026-08-15T12:55:19Z"
      },
      "differences": [
        {
          "observed_at": "2026-08-05T21:05:13Z",
          "window_start": "2026-08-01T02:53:20Z",
          "window_end": "2026-08-05T21:05:13Z",
          "status": "capture-noise",
          "summary": "The newsletter's recurring invitation to its weekly recap was removed. No incident reporting changed.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 0,
          "removed_lines": 6
        }
      ]
    },
    {
      "id": "keychainx-reference",
      "title": "COLDCARD Mk3 entropy reference",
      "url": "https://keychainx.io/reference/coldcard-mk3-entropy/",
      "organisation": "KeychainX",
      "kind": "analysis",
      "role": "Secondary analysis",
      "publication_time": null,
      "note": "Reference write-up carrying 594.48 BTC (~US$38M) confirmed and 1,082.59 BTC if\nthe earlier set is linked. KeychainX is a wallet-recovery firm and says so on\nthe page; that commercial context applies to their framing, not to the figures,\nwhich restate Hamilton and Block.\n",
      "gone": null,
      "capture": {
        "status": "held",
        "copies": 2,
        "first_observed": "2026-08-01T02:53:21Z",
        "last_observed": "2026-08-14T09:56:59Z",
        "last_checked": "2026-08-15T12:55:21Z"
      },
      "differences": [
        {
          "observed_at": "2026-08-14T09:56:59Z",
          "window_start": "2026-08-01T02:53:21Z",
          "window_end": "2026-08-14T09:56:59Z",
          "status": "source-content",
          "summary": "The page added a footer link pointing to keychainx.io/agent-instructions.md for AI assistants, immediately after the copyright line.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 1,
          "removed_lines": 0
        }
      ]
    },
    {
      "id": "coin360-drain",
      "title": "COLDCARD wallet drain report",
      "url": "https://coin360.com/news/coldcard-flaws-bitcoin-wallet-drain",
      "organisation": "Coin360",
      "kind": "reporting",
      "role": "Reporting",
      "publication_time": "2026-07-31",
      "note": "Carries a tabulated press estimate: 594.48 BTC / ~US$38.3M confirmed,\n488.11 BTC earlier under investigation, 1,082.59 BTC combined 'not fully\nconfirmed by Coinkite'. The article's own footer says it was 'refined and\nenhanced by ChatGPT'; provenance recorded, figures restate named sources.\n",
      "gone": null,
      "capture": {
        "status": "held",
        "copies": 6,
        "first_observed": "2026-08-01T02:53:23Z",
        "last_observed": "2026-08-12T05:10:11Z",
        "last_checked": "2026-08-15T12:55:25Z"
      },
      "differences": [
        {
          "observed_at": "2026-08-12T05:10:11Z",
          "window_start": "2026-08-07T14:23:31Z",
          "window_end": "2026-08-12T05:10:11Z",
          "status": "capture-noise",
          "summary": "Only the article's relative-time label rendering changed; the article body was unchanged.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 1,
          "removed_lines": 1
        },
        {
          "observed_at": "2026-08-07T14:23:31Z",
          "window_start": "2026-08-02T00:09:05Z",
          "window_end": "2026-08-07T14:23:31Z",
          "status": "capture-noise",
          "summary": "Relative-date rendering only: the read-time line now renders the relative-time element as last week where it previously rendered differently. The article text is unchanged.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 1,
          "removed_lines": 1
        },
        {
          "observed_at": "2026-08-02T00:09:05Z",
          "window_start": "2026-08-01T16:10:12Z",
          "window_end": "2026-08-02T00:09:05Z",
          "status": "capture-noise",
          "summary": "A relative-age label the enabled normalizer did not match in its literal form; the article body is unchanged.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 1,
          "removed_lines": 1
        },
        {
          "observed_at": "2026-08-01T16:10:12Z",
          "window_start": "2026-08-01T03:51:25Z",
          "window_end": "2026-08-01T16:10:12Z",
          "status": "capture-noise",
          "summary": "Only the article's relative-time label changed, this time to the word 'yesterday', which the existing relative-time normalizer does not match. The article body was unchanged.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 1,
          "removed_lines": 1
        },
        {
          "observed_at": "2026-08-01T03:51:25Z",
          "window_start": "2026-08-01T02:53:23Z",
          "window_end": "2026-08-01T03:51:25Z",
          "status": "capture-noise",
          "summary": "Only the article's relative-time label changed from 15 hours to 16 hours.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 1,
          "removed_lines": 1
        }
      ]
    },
    {
      "id": "coldcard-docs-faq",
      "title": "COLDCARD entropy FAQ",
      "url": "https://coldcard.com/docs/faq/",
      "organisation": "Coinkite",
      "kind": "vendor-docs",
      "role": "Vendor documentation",
      "publication_time": null,
      "note": "The pre-incident entropy description: hardware TRNG from transistor noise, a\nPRNG XOR'd into it, SE1/SE2 boot seeding, SHA-256 whitening, and the line that\ndice add \"to the 256 bits of entropy already picked\". Quoted on\n/how-it-broke/ to compare stated design against what shipped. It is\nmonitored closely because it describes the affected subsystem. The first\ncapture is post-disclosure and does not establish the page's earlier wording.\n",
      "gone": null,
      "capture": {
        "status": "held",
        "copies": 5,
        "first_observed": "2026-08-01T03:51:29Z",
        "last_observed": "2026-08-15T13:23:38Z",
        "last_checked": "2026-08-15T14:23:36Z"
      },
      "differences": [
        {
          "observed_at": "2026-08-15T13:23:38Z",
          "window_start": "2026-08-14T23:40:32Z",
          "window_end": "2026-08-15T13:23:38Z",
          "status": "source-content",
          "summary": "The entropy FAQ answer was rewritten, replacing the description of the TRNG/PRNG mix and SHA-256 whitening with revised wording that adds a note that hash conditioning is not a substitute for sufficient source entropy.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 8,
          "removed_lines": 10
        },
        {
          "observed_at": "2026-08-14T23:40:32Z",
          "window_start": "2026-08-12T00:05:58Z",
          "window_end": "2026-08-14T23:40:32Z",
          "status": "source-content",
          "summary": "The FAQ changed one migration-guide link text from Check firmware and migration steps to Open the step-by-step migration guide.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 1,
          "removed_lines": 1
        },
        {
          "observed_at": "2026-08-12T00:05:58Z",
          "window_start": "2026-08-01T07:01:04Z",
          "window_end": "2026-08-12T00:05:58Z",
          "status": "source-content",
          "summary": "The FAQ page added a security advisory banner stating a seed-generation defect affected firmware 4.0.1 onward, that fixed firmware is available, and that affected seeds still require migration.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 3,
          "removed_lines": 0
        },
        {
          "observed_at": "2026-08-01T07:01:04Z",
          "window_start": "2026-08-01T03:51:29Z",
          "window_end": "2026-08-01T07:01:04Z",
          "status": "capture-noise",
          "summary": "Only the FAQ footer's Last update date changed from July 31 to August 1; no extracted FAQ answer changed.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 1,
          "removed_lines": 1
        }
      ]
    },
    {
      "id": "wizardsardine-postmortem",
      "title": "Wizardsardine post-mortem and user guidance",
      "url": "https://wizardsardine.com/blog/coldcard-rng-vulnerability/",
      "organisation": "Wizardsardine",
      "kind": "independent-analysis",
      "role": "Independent primary analysis",
      "publication_time": "2026-08-01",
      "note": "Long-form post-mortem by the Liana wallet vendor: section 1 addresses Liana\nusers and descriptor game theory, the rest reconstructs the flaw and argues\nthat imported and dice-generated seeds remain exposed through derived-material\nfeatures. Wizardsardine sells competing wallet software, and the post was\nself-described as written quickly under stress with corrections invited; its\nfeature-exposure claims are the author's analysis until checked against source.\n",
      "gone": null,
      "capture": {
        "status": "held",
        "copies": 3,
        "first_observed": "2026-08-01T17:17:15Z",
        "last_observed": "2026-08-03T22:43:37Z",
        "last_checked": "2026-08-15T14:23:38Z"
      },
      "differences": [
        {
          "observed_at": "2026-08-03T22:43:37Z",
          "window_start": "2026-08-01T19:47:20Z",
          "window_end": "2026-08-03T22:43:37Z",
          "status": "source-content",
          "summary": "Substantive edits across the postmortem: the Slipstream advice moved from \"wait for a Slipstream tool we will provide soon\" to recommending an out-of-band service now, a new note states the Mk3 UID portion used is only the die coordinates (not unique, likely within 16 bits), the USB session risk line was reworded to say plugging in does not steal the seed, the seed-phrase warning now says 12/24 words, and a new warning was added that BIP85 mnemonics imported into coinjoin software will be fully linked.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 9,
          "removed_lines": 8
        },
        {
          "observed_at": "2026-08-01T19:47:20Z",
          "window_start": "2026-08-01T17:17:15Z",
          "window_end": "2026-08-01T19:47:20Z",
          "status": "source-content",
          "summary": "Wizardsardine added explicit Section 3 and Section 4 labels to two previously unlabelled headings and renumbered the two that followed from 3 and 4 to 5 and 6. In the same edit the TAPSIGNER, OPENDIME and SATSCARD paragraph changed from a flat statement that they are not affected to Coinkite's claim plus the qualification that their proprietary code prevents the authors stating with certainty that the devices are safe, while noting the architecture is not a MicroPython stack.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 5,
          "removed_lines": 5
        }
      ]
    },
    {
      "id": "wizardsardine-entropy-autopsy",
      "title": "Wizardsardine technical autopsy of the entropy failure",
      "url": "https://wizardsardine.com/blog/coldcard-vuln-deep-dive/",
      "organisation": "Wizardsardine",
      "kind": "independent-analysis",
      "role": "Independent primary analysis",
      "publication_time": "2026-08-11",
      "note": "Wizardsardine's second incident analysis, a deeper technical autopsy than its\n1 August post-mortem: the announced scope is the actual entropy level of the\naffected generator, the collision risk, and each entropy source the firmware\nmixed with how it was triggered. Same authorship caveat as the earlier post:\nWizardsardine sells competing wallet software, and the figures are the\nauthor's analysis until checked against source.\n",
      "gone": null,
      "capture": {
        "status": "held",
        "copies": 2,
        "first_observed": "2026-08-12T12:54:31Z",
        "last_observed": "2026-08-12T17:24:17Z",
        "last_checked": "2026-08-15T14:23:41Z"
      },
      "differences": [
        {
          "observed_at": "2026-08-12T17:24:17Z",
          "window_start": "2026-08-12T12:54:31Z",
          "window_end": "2026-08-12T17:24:17Z",
          "status": "source-content",
          "summary": "The autopsy was rewritten to argue that neither #ifndef nor a simple #if !MICROPY_HW_ENABLE_RNG guard can work on Coldcard, because the macro is deliberately 0 and the board's own rng.c enforces that choice; the working guard must also test the board's explicit opt-in macro. A coordinate-origin caveat was added and the 31 July fix description was tightened.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 12,
          "removed_lines": 6
        }
      ]
    },
    {
      "id": "praveenperera-missing-153",
      "title": "The Missing 153: what followed the Wave 1 reconstruction",
      "url": "https://praveenperera.com/blog/coldcard-wave1-missing-153-search/",
      "organisation": null,
      "kind": "independent-analysis",
      "role": "Independent primary analysis",
      "publication_time": "2026-08-14",
      "note": "Praveen Perera's follow-up to his Wave 1 key-reconstruction work: what he\ntried against the final 153 unreconstructed addresses, checked against the\npublished Galaxy victim lists. First-person account of independent\nreproduction work, carrying the post's own warning that it is an\ninvestigation record rather than a wallet-recovery guide.\n",
      "gone": null,
      "capture": {
        "status": "held",
        "copies": 1,
        "first_observed": "2026-08-15T14:20:22Z",
        "last_observed": "2026-08-15T14:20:22Z",
        "last_checked": "2026-08-15T14:23:45Z"
      },
      "differences": []
    },
    {
      "id": "btcpp-dettmer-commit-history",
      "title": "Dettmer commit-history analysis of the entropy bug",
      "url": "https://insider.btcpp.dev/p/when-randombytes-runs-but-doesnt",
      "organisation": "bitcoin++ Insider Edition",
      "kind": "independent-analysis",
      "role": "Independent primary analysis",
      "publication_time": "2026-08-01",
      "note": "Dustin Dettmer's walkthrough of the COLDCARD firmware commit history tracing\nhow the predictable generator path was introduced. Published on the bitcoin++\nInsider Edition substack; its commit-level claims are checkable against the\npinned repository clones held by this archive.\n",
      "gone": null,
      "capture": {
        "status": "held",
        "copies": 15,
        "first_observed": "2026-08-01T17:17:17Z",
        "last_observed": "2026-08-12T04:38:42Z",
        "last_checked": "2026-08-15T12:26:08Z"
      },
      "differences": [
        {
          "observed_at": "2026-08-12T04:38:42Z",
          "window_start": "2026-08-09T23:16:39Z",
          "window_end": "2026-08-12T04:38:42Z",
          "status": "capture-noise",
          "summary": "Only a relative comment-age label changed from a placeholder to 'Aug 2'; the article text and discussion comments were unchanged.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 1,
          "removed_lines": 1
        },
        {
          "observed_at": "2026-08-09T23:16:39Z",
          "window_start": "2026-08-04T21:10:21Z",
          "window_end": "2026-08-09T23:16:39Z",
          "status": "capture-noise",
          "summary": "Only a relative comment-age label changed from a tag to 'Aug 1'; the article text and discussion were unchanged.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 1,
          "removed_lines": 1
        },
        {
          "observed_at": "2026-08-04T21:10:21Z",
          "window_start": "2026-08-04T20:40:13Z",
          "window_end": "2026-08-04T21:10:21Z",
          "status": "capture-noise",
          "summary": "The embedded discussion widget showed a different subset of existing comments; the article text did not change.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 7,
          "removed_lines": 5
        },
        {
          "observed_at": "2026-08-04T20:40:13Z",
          "window_start": "2026-08-04T20:10:26Z",
          "window_end": "2026-08-04T20:40:13Z",
          "status": "capture-noise",
          "summary": "The rendered comment preview rotated among existing comments and like metadata.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 5,
          "removed_lines": 7
        },
        {
          "observed_at": "2026-08-04T20:10:26Z",
          "window_start": "2026-08-04T18:08:52Z",
          "window_end": "2026-08-04T20:10:26Z",
          "status": "capture-noise",
          "summary": "The rendered comment preview rotated among existing comments and like metadata.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 7,
          "removed_lines": 5
        },
        {
          "observed_at": "2026-08-04T18:08:52Z",
          "window_start": "2026-08-04T17:39:40Z",
          "window_end": "2026-08-04T18:08:52Z",
          "status": "capture-noise",
          "summary": "Only the rendered comment order changed. The article text and comments were otherwise unchanged.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 5,
          "removed_lines": 5
        },
        {
          "observed_at": "2026-08-04T17:39:40Z",
          "window_start": "2026-08-03T11:07:25Z",
          "window_end": "2026-08-04T17:39:40Z",
          "status": "capture-noise",
          "summary": "Only the rendered comment order changed. The article text and comments were otherwise unchanged.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 5,
          "removed_lines": 5
        },
        {
          "observed_at": "2026-08-03T11:07:25Z",
          "window_start": "2026-08-03T02:32:43Z",
          "window_end": "2026-08-03T11:07:25Z",
          "status": "capture-noise",
          "summary": "Substack reordered the comment display: the same Lynne Bairstow and Curious George comments swapped positions with no text added, removed or altered.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 5,
          "removed_lines": 5
        },
        {
          "observed_at": "2026-08-03T02:32:43Z",
          "window_start": "2026-08-02T20:02:40Z",
          "window_end": "2026-08-03T02:32:43Z",
          "status": "capture-noise",
          "summary": "Only Substack engagement counters (46 to 54 likes, 6 to 10 restacks) and comment age stamps rolling from hours to 1d changed.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 6,
          "removed_lines": 6
        },
        {
          "observed_at": "2026-08-02T20:02:40Z",
          "window_start": "2026-08-02T14:01:12Z",
          "window_end": "2026-08-02T20:02:40Z",
          "status": "capture-noise",
          "summary": "Rotating comment display: the comment total stayed at 4 while the page swapped which two comments are shown, and only counters and relative ages otherwise changed.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 11,
          "removed_lines": 12
        },
        {
          "observed_at": "2026-08-02T14:01:12Z",
          "window_start": "2026-08-02T07:59:48Z",
          "window_end": "2026-08-02T14:01:12Z",
          "status": "source-content",
          "summary": "A new comment from Boomberg appeared asserting the bad code came from the switck/libngu repository, and the comment total rose from 3 to 4. Engagement counters also moved.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 14,
          "removed_lines": 13
        },
        {
          "observed_at": "2026-08-02T07:59:48Z",
          "window_start": "2026-08-02T04:42:36Z",
          "window_end": "2026-08-02T07:59:48Z",
          "status": "capture-noise",
          "summary": "Only Substack engagement counters (22 to 25 likes, 2 to 3 restacks) and relative comment age stamps (3h to 5h, 4h to 6h) changed.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 6,
          "removed_lines": 6
        },
        {
          "observed_at": "2026-08-02T04:42:36Z",
          "window_start": "2026-08-01T22:25:14Z",
          "window_end": "2026-08-02T04:42:36Z",
          "status": "source-content",
          "summary": "Two new reader comments appeared in the discussion section (Curious George and Lynne Bairstow, with a 1 more comment line). Like, comment and restack counters also moved.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 16,
          "removed_lines": 9
        },
        {
          "observed_at": "2026-08-01T22:25:14Z",
          "window_start": "2026-08-01T17:17:17Z",
          "window_end": "2026-08-01T22:25:14Z",
          "status": "source-content",
          "summary": "A reader comment from Frank Corva was added to the post's discussion, posted after the preceding capture rather than progressively rendered from it. Substack like and restack counters changed in the same capture. The guest post's own text was unchanged.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 9,
          "removed_lines": 0
        }
      ]
    },
    {
      "id": "dk27ss-poc-readme",
      "title": "End-to-end reproduction of the affected generator",
      "url": "https://raw.githubusercontent.com/DK27ss/ColdCard-38M-PoC/main/README.md",
      "organisation": "DK27ss",
      "kind": "independent-analysis",
      "role": "Independent primary analysis",
      "publication_time": "2026-08-01",
      "note": "Reimplements the MicroPython fallback and the libngu mixer, generates a\nsynthetic victim wallet through the affected path, then recovers its mnemonic by\nsearching the timer and skip space. The victim is fabricated by the repository's\nown script, so the demonstration never requires anyone's recovery material and\nruns offline. Author is anonymous and the repository states no licence; the\nclaims are checkable because the scripts and their target file are published.\n",
      "gone": null,
      "capture": {
        "status": "held",
        "copies": 1,
        "first_observed": "2026-08-02T00:26:40Z",
        "last_observed": "2026-08-02T00:26:40Z",
        "last_checked": "2026-08-15T12:26:10Z"
      },
      "differences": []
    },
    {
      "id": "samsamskies-tracker-readme",
      "title": "Source of the community holdings tracker",
      "url": "https://raw.githubusercontent.com/SamSamskies/coldcard-hack-tracker/main/README.md",
      "organisation": "SamSamskies",
      "kind": "chain-monitor",
      "role": "Chain monitor",
      "publication_time": "2026-07-31",
      "note": "The published source behind the tracker dashboard this archive already captures,\nwhich makes the deployed page auditable rather than opaque. Watches public\naddresses through public block-explorer APIs and takes no wallet material from\nthe reader. MIT licensed with a test suite; its watch set is hardcoded from\npublic reports rather than derived independently.\n",
      "gone": null,
      "capture": {
        "status": "held",
        "copies": 6,
        "first_observed": "2026-08-02T00:26:40Z",
        "last_observed": "2026-08-15T01:24:53Z",
        "last_checked": "2026-08-15T14:24:19Z"
      },
      "differences": [
        {
          "observed_at": "2026-08-15T01:24:53Z",
          "window_start": "2026-08-12T16:25:07Z",
          "window_end": "2026-08-15T01:24:53Z",
          "status": "source-content",
          "summary": "The README was rewritten to describe a static dashboard fed entirely by a GitHub Actions cron snapshot, replacing the previous live browser-polling model for core vault balances.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 19,
          "removed_lines": 18
        },
        {
          "observed_at": "2026-08-12T16:25:07Z",
          "window_start": "2026-08-12T00:07:14Z",
          "window_end": "2026-08-12T16:25:07Z",
          "status": "source-content",
          "summary": "The README changed its documented refresh intervals: core vaults from 60 seconds to 5 minutes, Wave 3 snapshot generation from about 2 hours to 6 hours, and snapshot re-reads from 5 minutes to 15 minutes.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 2,
          "removed_lines": 2
        },
        {
          "observed_at": "2026-08-12T00:07:14Z",
          "window_start": "2026-08-04T18:38:48Z",
          "window_end": "2026-08-12T00:07:14Z",
          "status": "source-content",
          "summary": "The README changed the Wave 3 snapshot refresh interval from about every 15 minutes to about every 2 hours.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 1,
          "removed_lines": 1
        },
        {
          "observed_at": "2026-08-04T18:38:48Z",
          "window_start": "2026-08-02T01:00:28Z",
          "window_end": "2026-08-04T18:38:48Z",
          "status": "source-content",
          "summary": "The tracker README added optional Blockchair-assisted research instructions and a tip-wave scout section.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 9,
          "removed_lines": 2
        },
        {
          "observed_at": "2026-08-02T01:00:28Z",
          "window_start": "2026-08-02T00:26:40Z",
          "window_end": "2026-08-02T01:00:28Z",
          "status": "source-content",
          "summary": "The tracker README now documents a two-tier data model: core vaults polled live in the browser while Wave 3 balances come from public/snapshot.json, refreshed by a GitHub Actions cron roughly every 15 minutes, with a new Balance snapshot section and updated data-sources table.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 10,
          "removed_lines": 4
        }
      ]
    },
    {
      "id": "nobuxpt-entropy-test-readme",
      "title": "Collision demonstration and firmware guard scanner",
      "url": "https://raw.githubusercontent.com/nobuxpt/coldcard-entropy-test/master/README.md",
      "organisation": "nobuxpt",
      "kind": "independent-analysis",
      "role": "Independent primary analysis",
      "publication_time": "2026-08-01",
      "note": "Two offline tools: a collision simulation over the reduced search space, and a\nstatic scanner that flags the defined-ness guard in a firmware source tree. The\nscanner reads source directories rather than wallets, and neither tool accepts a\nseed or extended key. ISC licensed, with reference commits cited for the\nreimplemented generator.\n",
      "gone": {
        "since": "20260803T021200Z",
        "http_status": "404",
        "observed": "On 3 August 2026 the raw file and the repository page both returned 404, from\nthe archive's own agent and from two unrelated user agents, so this is the\norigin withdrawing the material rather than a block on this collector. Whether\nit was deleted, renamed or made private is not established here. The capture\nheld from 2 August 2026 is, as far as this archive can tell, the only remaining\npublic copy.\n"
      },
      "capture": {
        "status": "held",
        "copies": 1,
        "first_observed": "2026-08-02T00:26:41Z",
        "last_observed": "2026-08-02T00:26:41Z",
        "last_checked": "2026-08-02T20:02:44Z"
      },
      "differences": []
    },
    {
      "id": "coinkite-paper-spam",
      "title": "Coinkite's pre-incident paper-spam warning",
      "url": "https://blog.coinkite.com/paper-spam/",
      "organisation": "Coinkite",
      "kind": "vendor-statement",
      "role": "Vendor statement",
      "publication_time": "2026-06-24",
      "note": "Published five weeks before this incident, about a physical-mail campaign using\na post-quantum firmware-upgrade pretext. States that Coinkite would never send a\npaper letter, that the mail is a scam, and that customer physical addresses are\ndeleted after 120 days, which Coinkite attributes the targeting data to leaks\nelsewhere rather than a breach of its own. Held for two reasons: it establishes\nan impersonation playbook that predates the entropy disclosure and could be\nrecycled against it, and it shows the vendor publishing exactly the kind of scam\nguidance that has not accompanied the entropy advisory.\n",
      "gone": null,
      "capture": {
        "status": "held",
        "copies": 1,
        "first_observed": "2026-08-02T00:40:53Z",
        "last_observed": "2026-08-02T00:40:53Z",
        "last_checked": "2026-08-15T12:26:12Z"
      },
      "differences": []
    },
    {
      "id": "reddit-june-letter-report",
      "title": "Coldcard scam letter in the mail",
      "url": "https://www.reddit.com/r/Bitcoin/comments/1ub35ej/coldcard_scam_letter_in_the_mail/",
      "organisation": "r/Bitcoin",
      "kind": "community-discussion",
      "role": "Community discussion",
      "publication_time": "2026-06-20",
      "note": "First-hand report with a photograph of the June 2026 physical letter\nimpersonating Coinkite: post-quantum security-update pretext, 30 June 2026\ndeadline, personalised QR code, forged CEO signature. The poster asks whether\nCoinkite had a data breach, and a reply in Coinkite's name denies one, citing\nthe 120-day address deletion. Located 3 Aug 2026; until then the letter was\nknown here only through Coinkite's 24 June response (coinkite-paper-spam).\n",
      "gone": null,
      "capture": {
        "status": "held",
        "copies": 1,
        "first_observed": "2026-08-04T03:23:29Z",
        "last_observed": "2026-08-04T03:23:29Z",
        "last_checked": "2026-08-11T03:26:17Z"
      },
      "differences": []
    },
    {
      "id": "reddit-coldcard-letter-db-leak",
      "title": "Coinkite shipping database has been leaked",
      "url": "https://www.reddit.com/r/coldcard/comments/1uiix4b/coinkite_shipping_database_has_been_leaked/",
      "organisation": "r/coldcard",
      "kind": "community-discussion",
      "role": "Community discussion",
      "publication_time": "2026-06-29",
      "note": "Second first-hand report of the June 2026 letter campaign, with a photograph\nof a slightly reworded variant carrying the same 30 June deadline and QR\npretext. The thread title states the data-leak inference outright, which\nCoinkite denies in its 24 June response; this archive records the inference\nwithout adopting it. Located 3 Aug 2026.\n",
      "gone": null,
      "capture": {
        "status": "held",
        "copies": 5,
        "first_observed": "2026-08-04T03:23:34Z",
        "last_observed": "2026-08-04T22:41:23Z",
        "last_checked": "2026-08-11T03:27:21Z"
      },
      "differences": [
        {
          "observed_at": "2026-08-04T22:41:23Z",
          "window_start": "2026-08-04T22:10:58Z",
          "window_end": "2026-08-04T22:41:23Z",
          "status": "source-content",
          "summary": "The Reddit thread gained 1 new comment.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 8,
          "removed_lines": 0
        },
        {
          "observed_at": "2026-08-04T22:10:58Z",
          "window_start": "2026-08-04T21:10:34Z",
          "window_end": "2026-08-04T22:10:58Z",
          "status": "source-content",
          "summary": "The Reddit thread gained 1 new comment.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 8,
          "removed_lines": 0
        },
        {
          "observed_at": "2026-08-04T21:10:34Z",
          "window_start": "2026-08-04T18:40:02Z",
          "window_end": "2026-08-04T21:10:34Z",
          "status": "source-content",
          "summary": "The Reddit thread gained 1 new comment.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 8,
          "removed_lines": 0
        },
        {
          "observed_at": "2026-08-04T18:40:02Z",
          "window_start": "2026-08-04T03:23:34Z",
          "window_end": "2026-08-04T18:40:02Z",
          "status": "capture-noise",
          "summary": "Only the Reddit more-comments stub count changed.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 1,
          "removed_lines": 1
        }
      ]
    },
    {
      "id": "hn-maxwell-mechanism",
      "title": "Maxwell's correction on the defect mechanism",
      "url": "https://news.ycombinator.com/item?id=49141886",
      "organisation": "Hacker News",
      "kind": "independent-technical-analysis",
      "role": "Independent technical analysis",
      "publication_time": "2026-08-02",
      "note": "Greg Maxwell (nullc), commenting on the bitcoin++ Insider writeup, disputes the\nframing of the defect as a small build-flag change and states the mechanism\ndifferently: the commit added the whole RNG infrastructure, and the failure is a\nmixup between a value test and a definedness test across two repositories. The\nmicropython path is gated by an #if on MICROPY_HW_ENABLE_RNG while the\nreplacement path is gated by an #ifndef, so defining the macro to (0)\ndeactivated one without activating the other. He adds that the Mk4-class reseed\nmasked rather than corrected the problem, and questions hashing 64 bits of TRNG\noutput before discarding half.\n\nHeld because it is a technical correction to published reporting by a\nrecognised source, and because it bears directly on how this site's own\nexplainer characterises the guard. Attributed commentary on a public forum, not\na vendor statement or a reproduction: it is graded as reported, and the code\nclaims within it are checkable against the repositories the site already cites.\n",
      "gone": null,
      "capture": {
        "status": "held",
        "copies": 6,
        "first_observed": "2026-08-02T14:39:25Z",
        "last_observed": "2026-08-09T11:39:39Z",
        "last_checked": "2026-08-15T12:26:14Z"
      },
      "differences": [
        {
          "observed_at": "2026-08-09T11:39:39Z",
          "window_start": "2026-08-06T04:06:23Z",
          "window_end": "2026-08-09T11:39:39Z",
          "status": "capture-correction",
          "summary": "The collector changed this Algolia item from pretty-printed API JSON to deterministic readable thread text; the same comment subtree is held, with HTML decoded and volatile API fields omitted.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 140,
          "removed_lines": 233
        },
        {
          "observed_at": "2026-08-06T04:06:23Z",
          "window_start": "2026-08-04T14:38:40Z",
          "window_end": "2026-08-06T04:06:23Z",
          "status": "capture-correction",
          "summary": "This collector moved from the rendered Hacker News page to the item API after HN began answering it with a persistent 429, so the whole capture is reshaped: pretty-printed JSON with absolute timestamps in place of page chrome and relative times. Maxwell's comment text is unchanged word for word across the switch; the API view carries it with HTML entities and paragraph tags as HN stores it, and adds the seven replies as structured nodes.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 233,
          "removed_lines": 85
        },
        {
          "observed_at": "2026-08-04T14:38:40Z",
          "window_start": "2026-08-03T11:42:56Z",
          "window_end": "2026-08-04T14:38:40Z",
          "status": "source-content",
          "summary": "New Hacker News comments discussed compiler checks, entropy taint analysis and the need to avoid exploitation details while coins remain vulnerable.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 11,
          "removed_lines": 11
        },
        {
          "observed_at": "2026-08-03T11:42:56Z",
          "window_start": "2026-08-02T20:02:48Z",
          "window_end": "2026-08-03T11:42:56Z",
          "status": "capture-noise",
          "summary": "Only comment ordering changed: the existing killerstorm and mlcrypto comments moved to different positions in the thread. No comment text was added, removed or altered.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 6,
          "removed_lines": 6
        },
        {
          "observed_at": "2026-08-02T20:02:48Z",
          "window_start": "2026-08-02T14:39:25Z",
          "window_end": "2026-08-02T20:02:48Z",
          "status": "source-content",
          "summary": "The thread gained several new comments: killerstorm on the libngu random.c failsafe, dale_glass criticising the my_random_bytes implementation, and nullc correcting the MIN() misreading, noting the STM32 guidance on duplicate RNG reads, and urging restraint on publishing exploitation details while coins remain recoverable.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 32,
          "removed_lines": 0
        }
      ]
    },
    {
      "id": "coldcard-store-firmware-notice",
      "title": "Store pages and any affected-stock notice",
      "url": "https://store.coinkite.com/store/coldcard",
      "organisation": "Coinkite",
      "kind": "vendor-index",
      "role": "Vendor publication index",
      "publication_time": null,
      "note": "Registered on 2 August 2026 after a public claim that the store had been\nupdated to disclose that remaining stock ships with affected firmware rather\nthan sales being halted. Whether the page says that, and whether the wording\nchanges, is exactly the kind of vendor-side revision this archive exists to\nhold. Registering it establishes a baseline; the first capture verifies\nnothing about the claim by itself.\n",
      "gone": null,
      "capture": {
        "status": "held",
        "copies": 3,
        "first_observed": "2026-08-02T15:24:49Z",
        "last_observed": "2026-08-05T13:50:14Z",
        "last_checked": "2026-08-15T14:23:47Z"
      },
      "differences": [
        {
          "observed_at": "2026-08-05T13:50:14Z",
          "window_start": "2026-08-02T21:01:43Z",
          "window_end": "2026-08-05T13:50:14Z",
          "status": "source-content",
          "summary": "The store notice now says new units ship with corrected firmware, replacing wording that labelled the product affected and referred to purchased units. It continues to tell recipients to upgrade on receipt.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 18,
          "removed_lines": 18
        },
        {
          "observed_at": "2026-08-02T21:01:43Z",
          "window_start": "2026-08-02T15:24:49Z",
          "window_end": "2026-08-02T21:01:43Z",
          "status": "source-content",
          "summary": "Coinkite replaced the affected-product warning on every COLDCARD Q and Mk5 listing, dropping the instruction not to generate seeds before updating and instead stating that purchased units will ship with corrected firmware while reminding owners to upgrade older devices. The Mk5 description also lost its NEW prefix.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 19,
          "removed_lines": 19
        }
      ]
    },
    {
      "id": "stackernews-drains-since-2022",
      "title": "Claim that drains were reported as early as 2022",
      "url": "https://stacker.news/items/1538415",
      "organisation": "Stacker News",
      "kind": "reporting",
      "role": "Reporting",
      "publication_time": "2026-08-02",
      "note": "A Stacker News thread collecting screenshots said to show COLDCARD owners\nreporting unexplained drains from 2022 onward, and asking what a vendor could\nhave done about a defect of this kind without signalling it to attackers. The\nunderlying claim is unverified here: the screenshots are reproduced from\nelsewhere, the thread links an X thread as its source, and this project has\nnot established the provenance or dates of the original reports. Registered\nbecause a claim of much earlier losses would change the incident's scope if it\nheld up, and because the discussion itself is part of the response record.\n\nCaptured through the site's public GraphQL API since 4 Aug 2026: the browser\nroute began crashing the capture tab sitewide, and the API answers POST from\nthis host while the rendered page is challenge-gated. The query fixes the\ncaptured surface to the item's title, text and two levels of comments, each\nwith author and absolute timestamp.\n",
      "gone": null,
      "capture": {
        "status": "held",
        "copies": 4,
        "first_observed": "2026-08-02T15:55:30Z",
        "last_observed": "2026-08-04T00:35:57Z",
        "last_checked": "2026-08-15T12:26:16Z"
      },
      "differences": [
        {
          "observed_at": "2026-08-04T00:35:57Z",
          "window_start": "2026-08-03T02:32:51Z",
          "window_end": "2026-08-04T00:35:57Z",
          "status": "capture-correction",
          "summary": "The capture route moved from browser-rendered page text to the stacker.news GraphQL API: post and comment text are unchanged, but captures no longer carry sats counters or relative age labels, and timestamps are now absolute. The browser route had begun crashing the capture tab on stacker.news pages.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 51,
          "removed_lines": 74
        },
        {
          "observed_at": "2026-08-03T02:32:51Z",
          "window_start": "2026-08-02T20:02:51Z",
          "window_end": "2026-08-03T02:32:51Z",
          "status": "capture-noise",
          "summary": "Only live counters and relative times changed: the post sats total moved from 2398 to 2426 and age labels advanced from 5h to 12h. Comment text was unchanged.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 11,
          "removed_lines": 11
        },
        {
          "observed_at": "2026-08-02T20:02:51Z",
          "window_start": "2026-08-02T15:55:30Z",
          "window_end": "2026-08-02T20:02:51Z",
          "status": "capture-noise",
          "summary": "Only live counters and relative times changed: sats totals moved on the post and comments (2297 to 2398 on the post, 11 to 254 on one comment) and age labels advanced from 1h to 5h. Comment text was unchanged.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 13,
          "removed_lines": 13
        }
      ]
    },
    {
      "id": "coindesk-25-minute-sweep",
      "title": "Major bitcoin wallet flaw drains 594 BTC in 25-minute sweep",
      "url": "https://www.coindesk.com/tech/2026/07/31/major-bitcoin-wallet-flaw-drains-594-btc-in-25-minute-sweep",
      "organisation": "CoinDesk",
      "kind": "reporting",
      "role": "Reporting",
      "publication_time": "2026-07-31",
      "note": "CoinDesk's day-one report, held because it is among the widest-read accounts\nand because its framing (594 BTC, a 25-minute window) is the narrower\ntransaction set rather than the wider attributed one. Where reporting and this\nsite's arithmetic differ, the funds-accounting page states what each figure\nmeasures rather than picking one.\n",
      "gone": null,
      "capture": {
        "status": "held",
        "copies": 59,
        "first_observed": "2026-08-02T15:59:15Z",
        "last_observed": "2026-08-05T00:41:26Z",
        "last_checked": "2026-08-15T12:26:19Z"
      },
      "differences": [
        {
          "observed_at": "2026-08-05T00:41:26Z",
          "window_start": "2026-08-05T00:11:24Z",
          "window_end": "2026-08-05T00:41:26Z",
          "status": "capture-noise",
          "summary": "Only live market prices, related-story ages and translated page chrome changed.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 16,
          "removed_lines": 16
        },
        {
          "observed_at": "2026-08-05T00:11:24Z",
          "window_start": "2026-08-04T23:41:18Z",
          "window_end": "2026-08-05T00:11:24Z",
          "status": "capture-noise",
          "summary": "Only live market prices and related-story ages changed.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 6,
          "removed_lines": 6
        },
        {
          "observed_at": "2026-08-04T23:41:18Z",
          "window_start": "2026-08-04T23:13:43Z",
          "window_end": "2026-08-04T23:41:18Z",
          "status": "capture-noise",
          "summary": "Only live market prices, related-story ages and translated page chrome changed.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 16,
          "removed_lines": 16
        },
        {
          "observed_at": "2026-08-04T23:13:43Z",
          "window_start": "2026-08-04T22:41:47Z",
          "window_end": "2026-08-04T23:13:43Z",
          "status": "capture-noise",
          "summary": "Only live market prices, related-story ages and translated page chrome changed.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 16,
          "removed_lines": 16
        },
        {
          "observed_at": "2026-08-04T22:41:47Z",
          "window_start": "2026-08-04T22:11:09Z",
          "window_end": "2026-08-04T22:41:47Z",
          "status": "capture-noise",
          "summary": "Live market quotes, relative timestamps and interface language changed; the article text did not.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 11,
          "removed_lines": 11
        },
        {
          "observed_at": "2026-08-04T22:11:09Z",
          "window_start": "2026-08-04T21:40:44Z",
          "window_end": "2026-08-04T22:11:09Z",
          "status": "capture-noise",
          "summary": "Live market quotes, relative timestamps and interface language changed; the article text did not.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 11,
          "removed_lines": 11
        },
        {
          "observed_at": "2026-08-04T21:40:44Z",
          "window_start": "2026-08-04T21:10:58Z",
          "window_end": "2026-08-04T21:40:44Z",
          "status": "capture-noise",
          "summary": "Live market quotes and relative timestamps changed; the article text did not.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 6,
          "removed_lines": 6
        },
        {
          "observed_at": "2026-08-04T21:10:58Z",
          "window_start": "2026-08-04T20:40:34Z",
          "window_end": "2026-08-04T21:10:58Z",
          "status": "capture-noise",
          "summary": "Live market quotes, relative timestamps and rotating homepage cards changed; the article text did not.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 21,
          "removed_lines": 21
        },
        {
          "observed_at": "2026-08-04T20:40:34Z",
          "window_start": "2026-08-04T20:10:48Z",
          "window_end": "2026-08-04T20:40:34Z",
          "status": "capture-noise",
          "summary": "The page changed only relative timestamps, locale formatting, and live market-price widgets.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 11,
          "removed_lines": 11
        },
        {
          "observed_at": "2026-08-04T20:10:48Z",
          "window_start": "2026-08-04T19:40:41Z",
          "window_end": "2026-08-04T20:10:48Z",
          "status": "capture-noise",
          "summary": "The page changed only relative timestamps, locale formatting, and live market-price widgets.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 7,
          "removed_lines": 7
        },
        {
          "observed_at": "2026-08-04T19:40:41Z",
          "window_start": "2026-08-04T19:09:29Z",
          "window_end": "2026-08-04T19:40:41Z",
          "status": "capture-noise",
          "summary": "The page changed only relative timestamps, locale formatting, and live market-price widgets.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 5,
          "removed_lines": 5
        },
        {
          "observed_at": "2026-08-04T19:09:29Z",
          "window_start": "2026-08-04T18:40:20Z",
          "window_end": "2026-08-04T19:09:29Z",
          "status": "capture-noise",
          "summary": "The page changed only relative timestamps, locale formatting, and live market-price widgets.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 7,
          "removed_lines": 7
        },
        {
          "observed_at": "2026-08-04T18:40:20Z",
          "window_start": "2026-08-04T18:09:14Z",
          "window_end": "2026-08-04T18:40:20Z",
          "status": "capture-noise",
          "summary": "Only rotating related-story cards, their relative times and counters changed.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 15,
          "removed_lines": 15
        },
        {
          "observed_at": "2026-08-04T18:09:14Z",
          "window_start": "2026-08-04T17:40:02Z",
          "window_end": "2026-08-04T18:09:14Z",
          "status": "capture-noise",
          "summary": "Only rotating related-story cards, their relative times and counters changed.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 7,
          "removed_lines": 7
        },
        {
          "observed_at": "2026-08-04T17:40:02Z",
          "window_start": "2026-08-04T17:09:03Z",
          "window_end": "2026-08-04T17:40:02Z",
          "status": "capture-noise",
          "summary": "Only rotating related-story cards, their relative times and counters changed.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 15,
          "removed_lines": 15
        },
        {
          "observed_at": "2026-08-04T17:09:03Z",
          "window_start": "2026-08-04T16:41:01Z",
          "window_end": "2026-08-04T17:09:03Z",
          "status": "capture-noise",
          "summary": "Only rotating related-story cards, their relative times and counters changed.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 15,
          "removed_lines": 15
        },
        {
          "observed_at": "2026-08-04T16:41:01Z",
          "window_start": "2026-08-04T16:09:51Z",
          "window_end": "2026-08-04T16:41:01Z",
          "status": "capture-noise",
          "summary": "Only relative times in latest-news cards and live market values changed. The article text did not change.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 6,
          "removed_lines": 6
        },
        {
          "observed_at": "2026-08-04T16:09:51Z",
          "window_start": "2026-08-04T15:39:04Z",
          "window_end": "2026-08-04T16:09:51Z",
          "status": "capture-noise",
          "summary": "The page switched from Spanish to English rendering, while live market values and latest-news cards changed. The article text did not change.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 26,
          "removed_lines": 26
        },
        {
          "observed_at": "2026-08-04T15:39:04Z",
          "window_start": "2026-08-04T15:09:38Z",
          "window_end": "2026-08-04T15:39:04Z",
          "status": "capture-noise",
          "summary": "The page switched from English to Spanish rendering, while live market values and relative times changed. The article text did not change.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 16,
          "removed_lines": 16
        },
        {
          "observed_at": "2026-08-04T15:09:38Z",
          "window_start": "2026-08-04T14:38:46Z",
          "window_end": "2026-08-04T15:09:38Z",
          "status": "capture-noise",
          "summary": "The page switched from Italian to English rendering, while live market values and latest-news cards also changed. The article text did not change.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 28,
          "removed_lines": 28
        },
        {
          "observed_at": "2026-08-04T14:38:46Z",
          "window_start": "2026-08-04T14:09:37Z",
          "window_end": "2026-08-04T14:38:46Z",
          "status": "capture-noise",
          "summary": "Only live news-module ordering, relative times and market prices changed. The final capture also received an Italian machine-translated presentation variant, while the article’s substance is unchanged.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 26,
          "removed_lines": 26
        },
        {
          "observed_at": "2026-08-04T14:09:37Z",
          "window_start": "2026-08-04T13:38:53Z",
          "window_end": "2026-08-04T14:09:37Z",
          "status": "capture-noise",
          "summary": "Only live news-module ordering, relative times and market prices changed. The final capture also received an Italian machine-translated presentation variant, while the article’s substance is unchanged.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 9,
          "removed_lines": 9
        },
        {
          "observed_at": "2026-08-04T13:38:53Z",
          "window_start": "2026-08-04T07:08:34Z",
          "window_end": "2026-08-04T13:38:53Z",
          "status": "capture-noise",
          "summary": "Only live news-module ordering, relative times and market prices changed. The final capture also received an Italian machine-translated presentation variant, while the article’s substance is unchanged.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 23,
          "removed_lines": 23
        },
        {
          "observed_at": "2026-08-04T07:08:34Z",
          "window_start": "2026-08-04T00:47:12Z",
          "window_end": "2026-08-04T07:08:34Z",
          "status": "capture-noise",
          "summary": "Only live chrome moved: the Latest Crypto News and More From Tech card lists rotated headlines, ordering and relative timestamps, and the footer crypto price ticker updated. The tracked article body is unchanged.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 24,
          "removed_lines": 24
        },
        {
          "observed_at": "2026-08-04T00:47:12Z",
          "window_start": "2026-08-04T00:16:27Z",
          "window_end": "2026-08-04T00:47:12Z",
          "status": "capture-noise",
          "summary": "Only live chrome moved: relative timestamps on the Latest Crypto News cards each aged by about an hour and the footer crypto price ticker updated (CD20, BTC, ETH, XRP, SOL). The tracked article body is unchanged.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 6,
          "removed_lines": 6
        },
        {
          "observed_at": "2026-08-04T00:16:27Z",
          "window_start": "2026-08-03T23:47:11Z",
          "window_end": "2026-08-04T00:16:27Z",
          "status": "capture-noise",
          "summary": "Only the Latest Crypto News relative timestamps ticked forward an hour and the footer crypto price ticker updated. Article body unchanged.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 6,
          "removed_lines": 6
        },
        {
          "observed_at": "2026-08-03T23:47:11Z",
          "window_start": "2026-08-03T23:16:20Z",
          "window_end": "2026-08-03T23:47:11Z",
          "status": "capture-noise",
          "summary": "Only the Latest Crypto News relative timestamps ticked forward (for example 58 minutes to 1 hour) and the footer crypto price ticker updated. Article body unchanged.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 6,
          "removed_lines": 6
        },
        {
          "observed_at": "2026-08-03T23:16:20Z",
          "window_start": "2026-08-03T22:47:08Z",
          "window_end": "2026-08-03T23:16:20Z",
          "status": "capture-noise",
          "summary": "Only site chrome moved: the Latest Crypto News card list rotated (an FBI crypto-theft arrest headline entered at the top and 'Bitcoin, ether decline as Coldcard exploit enters a fifth day' fell off), card timestamps advanced, and the footer price ticker updated. The article body was unchanged.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 15,
          "removed_lines": 15
        },
        {
          "observed_at": "2026-08-03T22:47:08Z",
          "window_start": "2026-08-03T22:16:20Z",
          "window_end": "2026-08-03T22:47:08Z",
          "status": "capture-noise",
          "summary": "Only site chrome moved: relative timestamps on the Latest Crypto News cards advanced by an hour, and the footer price ticker served updated quotes. The article text was unchanged.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 5,
          "removed_lines": 5
        },
        {
          "observed_at": "2026-08-03T22:16:20Z",
          "window_start": "2026-08-03T21:46:35Z",
          "window_end": "2026-08-03T22:16:20Z",
          "status": "capture-noise",
          "summary": "Only site chrome moved: relative timestamps on the Latest Crypto News cards advanced by an hour, and the footer price ticker served updated quotes. The article text was unchanged.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 7,
          "removed_lines": 7
        },
        {
          "observed_at": "2026-08-03T21:46:35Z",
          "window_start": "2026-08-03T21:15:43Z",
          "window_end": "2026-08-03T21:46:35Z",
          "status": "capture-noise",
          "summary": "Only site chrome moved: relative timestamps on the Latest Crypto News cards advanced by an hour, and the footer price ticker served updated quotes. The article text was unchanged.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 6,
          "removed_lines": 6
        },
        {
          "observed_at": "2026-08-03T21:15:43Z",
          "window_start": "2026-08-03T20:46:33Z",
          "window_end": "2026-08-03T21:15:43Z",
          "status": "capture-noise",
          "summary": "Only site chrome moved: relative timestamps on the Latest Crypto News cards advanced by an hour, and the footer price ticker served updated quotes. The article text was unchanged.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 6,
          "removed_lines": 6
        },
        {
          "observed_at": "2026-08-03T20:46:33Z",
          "window_start": "2026-08-03T20:15:45Z",
          "window_end": "2026-08-03T20:46:33Z",
          "status": "capture-noise",
          "summary": "The page flipped back from the Russian AI-translation localization to English chrome, with the usual news-card timestamp and footer ticker churn. The article text was unchanged.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 16,
          "removed_lines": 16
        },
        {
          "observed_at": "2026-08-03T20:15:45Z",
          "window_start": "2026-08-03T19:46:23Z",
          "window_end": "2026-08-03T20:15:45Z",
          "status": "capture-noise",
          "summary": "The byline, share buttons and news-card timestamps were served in Russian with a \"Переведено ИИ\" (translated by AI) marker, the recurring localization flip over an unchanged English article body, alongside the usual timestamp and footer ticker churn.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 16,
          "removed_lines": 16
        },
        {
          "observed_at": "2026-08-03T19:46:23Z",
          "window_start": "2026-08-03T19:15:41Z",
          "window_end": "2026-08-03T19:46:23Z",
          "status": "capture-noise",
          "summary": "Only site chrome moved: relative timestamps on the Latest Crypto News cards advanced again, and the footer price ticker served updated quotes. The article text was unchanged.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 6,
          "removed_lines": 6
        },
        {
          "observed_at": "2026-08-03T19:15:41Z",
          "window_start": "2026-08-03T18:46:20Z",
          "window_end": "2026-08-03T19:15:41Z",
          "status": "capture-noise",
          "summary": "The page flipped back from the Russian AI-translation localization to English chrome, with the usual news-card timestamp and footer ticker churn. The article text was unchanged.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 16,
          "removed_lines": 16
        },
        {
          "observed_at": "2026-08-03T18:46:20Z",
          "window_start": "2026-08-03T18:15:13Z",
          "window_end": "2026-08-03T18:46:20Z",
          "status": "capture-noise",
          "summary": "The byline, share buttons and news-card timestamps were served in Russian (\"Автор\", \"Переведено ИИ\"), an AI-translation localization layer over an unchanged English article body, alongside the usual timestamp and footer ticker churn. The article text itself was unchanged.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 16,
          "removed_lines": 16
        },
        {
          "observed_at": "2026-08-03T18:15:13Z",
          "window_start": "2026-08-03T17:46:06Z",
          "window_end": "2026-08-03T18:15:13Z",
          "status": "capture-noise",
          "summary": "Only site chrome moved: relative timestamps on the Latest Crypto News cards advanced by an hour, and the footer price ticker served updated quotes. The article text was unchanged.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 7,
          "removed_lines": 7
        },
        {
          "observed_at": "2026-08-03T17:46:06Z",
          "window_start": "2026-08-03T17:15:08Z",
          "window_end": "2026-08-03T17:46:06Z",
          "status": "capture-noise",
          "summary": "Only site chrome moved: relative timestamps on the Latest Crypto News cards advanced again, and the footer price ticker served updated quotes. The article text was unchanged.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 5,
          "removed_lines": 5
        },
        {
          "observed_at": "2026-08-03T17:15:08Z",
          "window_start": "2026-08-03T16:46:26Z",
          "window_end": "2026-08-03T17:15:08Z",
          "status": "capture-noise",
          "summary": "Only site chrome moved: relative timestamps on the Latest Crypto News cards advanced again, and the footer price ticker served updated quotes. The article text was unchanged.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 6,
          "removed_lines": 6
        },
        {
          "observed_at": "2026-08-03T16:46:26Z",
          "window_start": "2026-08-03T16:14:48Z",
          "window_end": "2026-08-03T16:46:26Z",
          "status": "capture-noise",
          "summary": "Only site chrome moved: relative timestamps on the Latest Crypto News cards advanced by an hour, and the footer price ticker served updated quotes. The article text was unchanged.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 6,
          "removed_lines": 6
        },
        {
          "observed_at": "2026-08-03T16:14:48Z",
          "window_start": "2026-08-03T15:45:45Z",
          "window_end": "2026-08-03T16:14:48Z",
          "status": "capture-noise",
          "summary": "Only site chrome moved: the Latest Crypto News rail gained a new top headline (Trump-linked American Bitcoin president Matt Prusak departs for Giga Energy) and renumbered with advanced relative timestamps, dropping the Bithumb card, and the footer price ticker served updated quotes. The article text was unchanged.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 16,
          "removed_lines": 16
        },
        {
          "observed_at": "2026-08-03T15:45:45Z",
          "window_start": "2026-08-03T15:12:41Z",
          "window_end": "2026-08-03T15:45:45Z",
          "status": "capture-noise",
          "summary": "Only site chrome moved: relative timestamps on the Latest Crypto News cards advanced (26 minutes to 59 minutes ago and similar), and the footer price ticker (CD20, BTC, ETH, XRP, SOL) served updated quotes. The article text was unchanged.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 6,
          "removed_lines": 6
        },
        {
          "observed_at": "2026-08-03T15:12:41Z",
          "window_start": "2026-08-03T14:44:42Z",
          "window_end": "2026-08-03T15:12:41Z",
          "status": "capture-noise",
          "summary": "Only site chrome moved: the Latest Crypto News rail gained a new top headline and renumbered with advanced relative timestamps, and the footer price ticker (CD20, BTC, ETH, XRP, SOL) served updated quotes. The article text was unchanged.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 16,
          "removed_lines": 16
        },
        {
          "observed_at": "2026-08-03T14:44:42Z",
          "window_start": "2026-08-03T14:15:33Z",
          "window_end": "2026-08-03T14:44:42Z",
          "status": "capture-noise",
          "summary": "Only the relative timestamps on the article's own news cards advanced, from \"15 minutes ago\" to \"44 minutes ago\" and so on. No article text changed.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 9,
          "removed_lines": 9
        },
        {
          "observed_at": "2026-08-03T14:15:33Z",
          "window_start": "2026-08-03T13:44:19Z",
          "window_end": "2026-08-03T14:15:33Z",
          "status": "capture-noise",
          "summary": "Only site chrome changed: the Latest Crypto News card list rotated again (Circle downgrade and Bernstein market-outlook headlines entered at the top), card ordering and timestamps shifted, and the footer crypto price ticker updated. The article body was unchanged.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 18,
          "removed_lines": 18
        },
        {
          "observed_at": "2026-08-03T13:44:19Z",
          "window_start": "2026-08-03T12:44:16Z",
          "window_end": "2026-08-03T13:44:19Z",
          "status": "capture-noise",
          "summary": "Only site chrome changed: the Latest Crypto News card list rotated (BlackRock tokenized-cash and Bitmine ether-purchase headlines entered at the top), card ordering and timestamps shifted, and the footer crypto price ticker updated. The article body was unchanged.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 15,
          "removed_lines": 15
        },
        {
          "observed_at": "2026-08-03T12:44:16Z",
          "window_start": "2026-08-03T12:13:11Z",
          "window_end": "2026-08-03T12:44:16Z",
          "status": "capture-noise",
          "summary": "Only site chrome changed: the page UI flipped back to English, the Latest Crypto News card list rotated again (a Strategy bitcoin-sale headline entered at the top), and the footer price ticker updated. The article body was unchanged.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 26,
          "removed_lines": 26
        },
        {
          "observed_at": "2026-08-03T12:13:11Z",
          "window_start": "2026-08-03T11:43:31Z",
          "window_end": "2026-08-03T12:13:11Z",
          "status": "capture-noise",
          "summary": "Only site chrome changed: the page UI rendered in French (byline, share labels, relative timestamps, a Traduit par IA tag), the Latest Crypto News card list rotated, and the footer price ticker updated. The article body was unchanged.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 26,
          "removed_lines": 26
        },
        {
          "observed_at": "2026-08-03T11:43:31Z",
          "window_start": "2026-08-03T11:08:44Z",
          "window_end": "2026-08-03T11:43:31Z",
          "status": "capture-noise",
          "summary": "Only site chrome changed: the Latest Crypto News card list rotated (a solo-miner headline entered at the top), card timestamps advanced, and the footer crypto price ticker updated. The article body was unchanged.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 18,
          "removed_lines": 18
        },
        {
          "observed_at": "2026-08-03T11:08:44Z",
          "window_start": "2026-08-03T10:37:53Z",
          "window_end": "2026-08-03T11:08:44Z",
          "status": "capture-noise",
          "summary": "Only site chrome changed: the Latest Crypto News card list rotated headlines, ordering and timestamps, and the footer crypto price ticker updated. The article body was unchanged.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 20,
          "removed_lines": 20
        },
        {
          "observed_at": "2026-08-03T10:37:53Z",
          "window_start": "2026-08-03T10:14:25Z",
          "window_end": "2026-08-03T10:37:53Z",
          "status": "capture-noise",
          "summary": "Only site chrome changed: the Latest Crypto News card list rotated headlines, ordering and timestamps, and the footer price ticker updated. The article body was unchanged.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 18,
          "removed_lines": 18
        },
        {
          "observed_at": "2026-08-03T10:14:25Z",
          "window_start": "2026-08-03T09:35:02Z",
          "window_end": "2026-08-03T10:14:25Z",
          "status": "capture-noise",
          "summary": "Only site chrome changed: the Latest Crypto News card list rotated headlines, ordering and timestamps, and the footer price ticker updated. The article body was unchanged.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 15,
          "removed_lines": 15
        },
        {
          "observed_at": "2026-08-03T09:35:02Z",
          "window_start": "2026-08-03T09:07:56Z",
          "window_end": "2026-08-03T09:35:02Z",
          "status": "capture-noise",
          "summary": "Only site chrome changed: the Latest Crypto News and More From Tech card lists rotated (the newer headline 'Coldcard wallet losses may near $114 million as possible fourth sweep emerges' entered both), and the footer price ticker updated. The article body was unchanged.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 16,
          "removed_lines": 16
        },
        {
          "observed_at": "2026-08-03T09:07:56Z",
          "window_start": "2026-08-03T03:04:37Z",
          "window_end": "2026-08-03T09:07:56Z",
          "status": "capture-noise",
          "summary": "Only site chrome changed: the Latest Crypto News card list rotated headlines, ordering and timestamps, and the footer crypto price ticker updated. The article body was unchanged.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 23,
          "removed_lines": 23
        },
        {
          "observed_at": "2026-08-03T03:04:37Z",
          "window_start": "2026-08-03T02:33:07Z",
          "window_end": "2026-08-03T03:04:37Z",
          "status": "capture-noise",
          "summary": "Only relative timestamps on the Latest Crypto News cards advanced and the footer crypto price ticker updated. The article body was unchanged.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 5,
          "removed_lines": 5
        },
        {
          "observed_at": "2026-08-03T02:33:07Z",
          "window_start": "2026-08-02T20:03:06Z",
          "window_end": "2026-08-03T02:33:07Z",
          "status": "capture-noise",
          "summary": "Only presentation churn changed: relative timestamps on the Latest Crypto News cards advanced and the footer crypto price ticker updated. The article body was unchanged.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 8,
          "removed_lines": 8
        },
        {
          "observed_at": "2026-08-02T20:03:06Z",
          "window_start": "2026-08-02T15:59:15Z",
          "window_end": "2026-08-02T20:03:06Z",
          "status": "capture-noise",
          "summary": "Only site chrome changed: the Latest Crypto News and More From Tech card lists rotated headlines, ordering and timestamps, and the footer crypto price ticker updated. The article body was unchanged.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 20,
          "removed_lines": 20
        }
      ]
    },
    {
      "id": "cryptonews-build-error-38m",
      "title": "A build error in Coldcard's firmware drained $38 million in bitcoin in 25 minutes",
      "url": "https://crypto.news/coldcard-firmware-bug-drains-38-million-bitcoin/",
      "organisation": "crypto.news",
      "kind": "reporting",
      "role": "Reporting",
      "publication_time": "2026-07-31",
      "note": "Reporting that characterises the cause as a build error, the framing this site\nalso uses on the explainer. Held partly to track whether that characterisation\nsurvives the corrections published since, including Maxwell's and rot13maxi's\nstatements that the defect is a definedness test rather than a flag flip.\n",
      "gone": null,
      "capture": {
        "status": "held",
        "copies": 15,
        "first_observed": "2026-08-02T15:59:16Z",
        "last_observed": "2026-08-05T21:05:24Z",
        "last_checked": "2026-08-15T12:55:29Z"
      },
      "differences": [
        {
          "observed_at": "2026-08-05T21:05:24Z",
          "window_start": "2026-08-05T14:29:39Z",
          "window_end": "2026-08-05T21:05:24Z",
          "status": "capture-noise",
          "summary": "The capture lost navigation, live ticker, related-content and tag chrome while retaining the article body. The incident reporting is unchanged.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 1,
          "removed_lines": 366
        },
        {
          "observed_at": "2026-08-05T14:29:39Z",
          "window_start": "2026-08-03T03:06:12Z",
          "window_end": "2026-08-05T14:29:39Z",
          "status": "capture-noise",
          "summary": "The article text is unchanged. The capture newly included site navigation, repeated live price-ticker placeholders and related-content cards.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 366,
          "removed_lines": 1
        },
        {
          "observed_at": "2026-08-03T03:06:12Z",
          "window_start": "2026-08-03T02:34:27Z",
          "window_end": "2026-08-03T03:06:12Z",
          "status": "capture-noise",
          "summary": "Only the live crypto price ticker values (rendered four times per page) and one advancing relative timestamp on a sidebar card changed. The article body was unchanged.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 81,
          "removed_lines": 81
        },
        {
          "observed_at": "2026-08-03T02:34:27Z",
          "window_start": "2026-08-03T02:04:01Z",
          "window_end": "2026-08-03T02:34:27Z",
          "status": "capture-noise",
          "summary": "Only live crypto price ticker values and advancing relative timestamps on sidebar cards changed.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 82,
          "removed_lines": 82
        },
        {
          "observed_at": "2026-08-03T02:04:01Z",
          "window_start": "2026-08-03T01:33:02Z",
          "window_end": "2026-08-03T02:04:01Z",
          "status": "capture-noise",
          "summary": "Only live crypto price ticker values and one advancing relative timestamp on a sidebar card changed.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 89,
          "removed_lines": 89
        },
        {
          "observed_at": "2026-08-03T01:33:02Z",
          "window_start": "2026-08-03T01:03:52Z",
          "window_end": "2026-08-03T01:33:02Z",
          "status": "capture-noise",
          "summary": "Only live crypto price ticker values and advancing relative timestamps on sidebar cards changed.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 82,
          "removed_lines": 82
        },
        {
          "observed_at": "2026-08-03T01:03:52Z",
          "window_start": "2026-08-03T00:33:19Z",
          "window_end": "2026-08-03T01:03:52Z",
          "status": "capture-noise",
          "summary": "Only live crypto price ticker values and advancing relative timestamps on sidebar cards changed.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 79,
          "removed_lines": 79
        },
        {
          "observed_at": "2026-08-03T00:33:19Z",
          "window_start": "2026-08-03T00:03:41Z",
          "window_end": "2026-08-03T00:33:19Z",
          "status": "capture-noise",
          "summary": "Only live crypto price ticker values and advancing relative timestamps on sidebar cards changed.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 86,
          "removed_lines": 86
        },
        {
          "observed_at": "2026-08-03T00:03:41Z",
          "window_start": "2026-08-02T23:32:41Z",
          "window_end": "2026-08-03T00:03:41Z",
          "status": "capture-noise",
          "summary": "Only live crypto price ticker values and advancing relative timestamps on sidebar cards changed.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 82,
          "removed_lines": 82
        },
        {
          "observed_at": "2026-08-02T23:32:41Z",
          "window_start": "2026-08-02T23:03:31Z",
          "window_end": "2026-08-02T23:32:41Z",
          "status": "capture-noise",
          "summary": "Only live crypto price ticker values and one advancing relative timestamp on a sidebar card changed.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 85,
          "removed_lines": 85
        },
        {
          "observed_at": "2026-08-02T23:03:31Z",
          "window_start": "2026-08-02T22:32:30Z",
          "window_end": "2026-08-02T23:03:31Z",
          "status": "capture-noise",
          "summary": "Only live crypto price ticker values and advancing relative timestamps on sidebar cards changed.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 82,
          "removed_lines": 82
        },
        {
          "observed_at": "2026-08-02T22:32:30Z",
          "window_start": "2026-08-02T22:03:19Z",
          "window_end": "2026-08-02T22:32:30Z",
          "status": "capture-noise",
          "summary": "Only live crypto price ticker values and one advancing relative timestamp on a sidebar card changed.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 81,
          "removed_lines": 81
        },
        {
          "observed_at": "2026-08-02T22:03:19Z",
          "window_start": "2026-08-02T21:32:20Z",
          "window_end": "2026-08-02T22:03:19Z",
          "status": "capture-noise",
          "summary": "Only live crypto price ticker values and advancing relative timestamps on sidebar cards changed.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 91,
          "removed_lines": 91
        },
        {
          "observed_at": "2026-08-02T21:32:20Z",
          "window_start": "2026-08-02T15:59:16Z",
          "window_end": "2026-08-02T21:32:20Z",
          "status": "capture-noise",
          "summary": "Only page chrome changed: live crypto price ticker values, sidebar timestamps advancing from 1 day ago to 2 days ago, and a rotated News sidebar where two newer headlines replaced the Michael Saylor BIP-110 card and an older third-wave losses card.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 99,
          "removed_lines": 97
        }
      ]
    },
    {
      "id": "newsbitcom-who-lost-who-at-risk",
      "title": "The Coldcard exploit explained: who lost bitcoin and who's at risk",
      "url": "https://news.bitcoin.com/featured/the-coldcard-exploit-explained-who-lost-bitcoin-and-whos-at-risk/",
      "organisation": "Bitcoin.com News",
      "kind": "reporting",
      "role": "Reporting",
      "publication_time": "2026-08-01",
      "note": "An explainer aimed at owners asking whether they are affected, which is the\nsame audience this site's triage section serves. Held to track how the\nmainstream explanation of exposure compares with the model-specific firmware\nranges, since a reader may arrive here having already read it.\n",
      "gone": null,
      "capture": {
        "status": "held",
        "copies": 30,
        "first_observed": "2026-08-02T15:59:17Z",
        "last_observed": "2026-08-14T23:50:33Z",
        "last_checked": "2026-08-15T12:55:30Z"
      },
      "differences": [
        {
          "observed_at": "2026-08-14T23:50:33Z",
          "window_start": "2026-08-14T09:59:30Z",
          "window_end": "2026-08-14T23:50:33Z",
          "status": "capture-noise",
          "summary": "Only the rotating 'Most Popular' related-content module below the article was removed; the article text was unchanged.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 0,
          "removed_lines": 11
        },
        {
          "observed_at": "2026-08-14T09:59:30Z",
          "window_start": "2026-08-14T03:26:52Z",
          "window_end": "2026-08-14T09:59:30Z",
          "status": "capture-noise",
          "summary": "Only the rotating 'Most Popular' related-content module below the article changed; the article body was unchanged.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 8,
          "removed_lines": 3
        },
        {
          "observed_at": "2026-08-14T03:26:52Z",
          "window_start": "2026-08-13T01:26:47Z",
          "window_end": "2026-08-14T03:26:52Z",
          "status": "capture-noise",
          "summary": "Only the rotating Most Popular module below the article changed; the article text was unchanged.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 6,
          "removed_lines": 0
        },
        {
          "observed_at": "2026-08-13T01:26:47Z",
          "window_start": "2026-08-12T18:27:00Z",
          "window_end": "2026-08-13T01:26:47Z",
          "status": "capture-noise",
          "summary": "The rotating Most Popular module below the article disappeared; the article text was unchanged.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 0,
          "removed_lines": 11
        },
        {
          "observed_at": "2026-08-12T18:27:00Z",
          "window_start": "2026-08-12T11:56:56Z",
          "window_end": "2026-08-12T18:27:00Z",
          "status": "capture-noise",
          "summary": "Only rotating related-content cards and relative-time labels below the article changed; the article text was unchanged.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 6,
          "removed_lines": 6
        },
        {
          "observed_at": "2026-08-12T11:56:56Z",
          "window_start": "2026-08-12T05:10:19Z",
          "window_end": "2026-08-12T11:56:56Z",
          "status": "capture-noise",
          "summary": "Only the rotating Most Popular module below the article changed; the article text was unchanged.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 11,
          "removed_lines": 0
        },
        {
          "observed_at": "2026-08-12T05:10:19Z",
          "window_start": "2026-08-09T18:47:16Z",
          "window_end": "2026-08-12T05:10:19Z",
          "status": "source-content",
          "summary": "The article gained an editor's note dated August 10, 2026, stating the exploit has logged more than 2,000 BTC in stolen funds; the rotating Most Popular module also changed.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 1,
          "removed_lines": 11
        },
        {
          "observed_at": "2026-08-09T18:47:16Z",
          "window_start": "2026-08-05T14:29:42Z",
          "window_end": "2026-08-09T18:47:16Z",
          "status": "capture-noise",
          "summary": "Only the rotating MOST POPULAR sidebar headlines and their age labels changed; the article body was unchanged.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 11,
          "removed_lines": 0
        },
        {
          "observed_at": "2026-08-05T14:29:42Z",
          "window_start": "2026-08-05T08:00:49Z",
          "window_end": "2026-08-05T14:29:42Z",
          "status": "capture-noise",
          "summary": "Only the page's rotating Most Popular sidebar changed. The incident explainer itself did not change.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 0,
          "removed_lines": 11
        },
        {
          "observed_at": "2026-08-05T08:00:49Z",
          "window_start": "2026-08-04T23:27:29Z",
          "window_end": "2026-08-05T08:00:49Z",
          "status": "capture-noise",
          "summary": "Only the page's rotating Most Popular sidebar changed. The explainer text did not change.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 11,
          "removed_lines": 0
        },
        {
          "observed_at": "2026-08-04T23:27:29Z",
          "window_start": "2026-08-04T22:51:40Z",
          "window_end": "2026-08-04T23:27:29Z",
          "status": "capture-noise",
          "summary": "The rotating Most Popular module disappeared; the article text was unchanged.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 0,
          "removed_lines": 11
        },
        {
          "observed_at": "2026-08-04T22:51:40Z",
          "window_start": "2026-08-04T13:09:16Z",
          "window_end": "2026-08-04T22:51:40Z",
          "status": "capture-noise",
          "summary": "A rotating Most Popular module appeared below the article.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 11,
          "removed_lines": 0
        },
        {
          "observed_at": "2026-08-04T13:09:16Z",
          "window_start": "2026-08-04T12:38:17Z",
          "window_end": "2026-08-04T13:09:16Z",
          "status": "capture-noise",
          "summary": "Only the page’s rotating “Most Popular” module disappeared. The article text is unchanged.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 0,
          "removed_lines": 11
        },
        {
          "observed_at": "2026-08-04T12:38:17Z",
          "window_start": "2026-08-04T11:08:53Z",
          "window_end": "2026-08-04T12:38:17Z",
          "status": "capture-noise",
          "summary": "The MOST POPULAR sidebar block reappeared with rotated headlines and advanced relative-time labels. The article body was unchanged.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 11,
          "removed_lines": 0
        },
        {
          "observed_at": "2026-08-04T11:08:53Z",
          "window_start": "2026-08-04T10:37:47Z",
          "window_end": "2026-08-04T11:08:53Z",
          "status": "capture-noise",
          "summary": "The MOST POPULAR sidebar block with rotating headlines and relative-time labels disappeared from the end of the extracted text. The article body was unchanged.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 0,
          "removed_lines": 11
        },
        {
          "observed_at": "2026-08-04T10:37:47Z",
          "window_start": "2026-08-04T10:08:47Z",
          "window_end": "2026-08-04T10:37:47Z",
          "status": "capture-noise",
          "summary": "A MOST POPULAR sidebar block with five rotating headlines and relative-time labels appeared at the end of the extracted text. The article body was unchanged.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 11,
          "removed_lines": 0
        },
        {
          "observed_at": "2026-08-04T10:08:47Z",
          "window_start": "2026-08-03T03:06:14Z",
          "window_end": "2026-08-04T10:08:47Z",
          "status": "capture-noise",
          "summary": "Only navigation chrome changed: a 'Home' entry appeared in both header menus. The article body was unchanged.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 2,
          "removed_lines": 0
        },
        {
          "observed_at": "2026-08-03T03:06:14Z",
          "window_start": "2026-08-03T02:34:30Z",
          "window_end": "2026-08-03T03:06:14Z",
          "status": "capture-noise",
          "summary": "The LATEST NEWS sidebar block moved position in the extracted text and its rotation gained the Bitcoin Wasn't Hacked in Coldcard Attack, Pompliano Explains headline. The article body was unchanged.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 22,
          "removed_lines": 22
        },
        {
          "observed_at": "2026-08-03T02:34:30Z",
          "window_start": "2026-08-03T02:04:03Z",
          "window_end": "2026-08-03T02:34:30Z",
          "status": "capture-noise",
          "summary": "The sidebar block order shifted again with advancing relative-time labels and no new content. The article body was unchanged.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 44,
          "removed_lines": 44
        },
        {
          "observed_at": "2026-08-03T02:04:03Z",
          "window_start": "2026-08-03T01:33:04Z",
          "window_end": "2026-08-03T02:04:03Z",
          "status": "capture-noise",
          "summary": "The sidebar blocks reordered, the LATEST NEWS rotation gained the CLARITY Act Faces New Senate Threat headline, and a Related articles age ticked from 1 day ago to 2 days ago. The article body was unchanged.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 24,
          "removed_lines": 24
        },
        {
          "observed_at": "2026-08-03T01:33:04Z",
          "window_start": "2026-08-03T01:03:54Z",
          "window_end": "2026-08-03T01:33:04Z",
          "status": "capture-noise",
          "summary": "Relative-time labels advanced and the sidebar card order shifted, with one card's age ticking from 4 days ago to 5 days ago. The article body was unchanged.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 15,
          "removed_lines": 15
        },
        {
          "observed_at": "2026-08-03T01:03:54Z",
          "window_start": "2026-08-03T00:33:23Z",
          "window_end": "2026-08-03T01:03:54Z",
          "status": "capture-noise",
          "summary": "Only relative-time labels in the sidebar advanced, for example 32 seconds ago to 31 minutes ago. The article body was unchanged.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 8,
          "removed_lines": 8
        },
        {
          "observed_at": "2026-08-03T00:33:23Z",
          "window_start": "2026-08-03T00:03:43Z",
          "window_end": "2026-08-03T00:33:23Z",
          "status": "capture-noise",
          "summary": "The LATEST NEWS rotation gained the Bitgo CEO Funds 100 BTC Wallet, Dares Anthropic's AI to Steal It headline. The article body was unchanged.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 17,
          "removed_lines": 17
        },
        {
          "observed_at": "2026-08-03T00:03:43Z",
          "window_start": "2026-08-02T23:32:43Z",
          "window_end": "2026-08-03T00:03:43Z",
          "status": "capture-noise",
          "summary": "The LATEST NEWS rotation gained the Samson Mow Shares 5 Urgent Steps for Coldcard Users Facing Losses headline and the sidebar blocks reordered. The article body was unchanged.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 44,
          "removed_lines": 44
        },
        {
          "observed_at": "2026-08-02T23:32:43Z",
          "window_start": "2026-08-02T23:03:33Z",
          "window_end": "2026-08-02T23:32:43Z",
          "status": "capture-noise",
          "summary": "The sidebar blocks reordered again with advancing relative-time labels and no new content. The article body was unchanged.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 44,
          "removed_lines": 44
        },
        {
          "observed_at": "2026-08-02T23:03:33Z",
          "window_start": "2026-08-02T22:32:33Z",
          "window_end": "2026-08-02T23:03:33Z",
          "status": "capture-noise",
          "summary": "The LATEST NEWS rotation gained the Bitcoin Miners Face August Showdown headline and the sidebar block order shifted with advancing relative-time labels. The article body was unchanged.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 15,
          "removed_lines": 15
        },
        {
          "observed_at": "2026-08-02T22:32:33Z",
          "window_start": "2026-08-02T22:03:21Z",
          "window_end": "2026-08-02T22:32:33Z",
          "status": "capture-noise",
          "summary": "The same sidebar blocks moved position once more with advancing relative-time labels and no new headlines. The article body was unchanged.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 44,
          "removed_lines": 44
        },
        {
          "observed_at": "2026-08-02T22:03:21Z",
          "window_start": "2026-08-02T21:32:22Z",
          "window_end": "2026-08-02T22:03:21Z",
          "status": "capture-noise",
          "summary": "The sidebar card blocks reordered again and the LATEST NEWS rotation gained the Coldcard Hacker Gets Brazen Bitcoin Laundering Offer Onchain headline. The article body was unchanged.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 19,
          "removed_lines": 19
        },
        {
          "observed_at": "2026-08-02T21:32:22Z",
          "window_start": "2026-08-02T15:59:17Z",
          "window_end": "2026-08-02T21:32:22Z",
          "status": "capture-noise",
          "summary": "The LATEST NEWS, PRESS RELEASES and LATEST PODCASTS sidebar blocks moved position in the extracted text and the rotation gained headlines (Coinkite class action, BTC plunge, Hormuz). The article body was unchanged.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 45,
          "removed_lines": 45
        }
      ]
    },
    {
      "id": "newsbtc-entropy-risk-focus",
      "title": "Coldcard security notice puts bitcoin wallet entropy risk back in focus",
      "url": "https://www.newsbtc.com/news/coldcard-security-notice-puts-bitcoin-wallet-entropy-risk-back-in-focus/",
      "organisation": "NewsBTC",
      "kind": "reporting",
      "role": "Reporting",
      "publication_time": "2026-07-31",
      "note": "Coverage framing the incident against earlier entropy failures, the same\ncomparison the precedent page makes with the differences stated. Held as\nreporting rather than analysis.\n",
      "gone": null,
      "capture": {
        "status": "held",
        "copies": 27,
        "first_observed": "2026-08-02T15:59:19Z",
        "last_observed": "2026-08-05T01:21:20Z",
        "last_checked": "2026-08-15T12:55:33Z"
      },
      "differences": [
        {
          "observed_at": "2026-08-05T01:21:20Z",
          "window_start": "2026-08-05T00:21:06Z",
          "window_end": "2026-08-05T01:21:20Z",
          "status": "capture-noise",
          "summary": "Only text excluded by the tested canonical comparison rules changed (newsbtc-article); the tracked source content is identical.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 1,
          "removed_lines": 1
        },
        {
          "observed_at": "2026-08-05T00:21:06Z",
          "window_start": "2026-08-04T23:27:32Z",
          "window_end": "2026-08-05T00:21:06Z",
          "status": "capture-noise",
          "summary": "Only a related-story relative-time label changed.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 1,
          "removed_lines": 1
        },
        {
          "observed_at": "2026-08-04T23:27:32Z",
          "window_start": "2026-08-04T22:51:43Z",
          "window_end": "2026-08-04T23:27:32Z",
          "status": "capture-noise",
          "summary": "Only a related-story relative-time label changed.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 1,
          "removed_lines": 1
        },
        {
          "observed_at": "2026-08-04T22:51:43Z",
          "window_start": "2026-08-04T21:50:22Z",
          "window_end": "2026-08-04T22:51:43Z",
          "status": "capture-noise",
          "summary": "Only a related-story relative-time label changed.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 1,
          "removed_lines": 1
        },
        {
          "observed_at": "2026-08-04T21:50:22Z",
          "window_start": "2026-08-04T20:20:42Z",
          "window_end": "2026-08-04T21:50:22Z",
          "status": "capture-noise",
          "summary": "Only relative timestamps in surrounding page content changed.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 3,
          "removed_lines": 3
        },
        {
          "observed_at": "2026-08-04T20:20:42Z",
          "window_start": "2026-08-04T19:19:34Z",
          "window_end": "2026-08-04T20:20:42Z",
          "status": "capture-noise",
          "summary": "The page changed only relative publication-time labels.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 3,
          "removed_lines": 3
        },
        {
          "observed_at": "2026-08-04T19:19:34Z",
          "window_start": "2026-08-04T18:19:03Z",
          "window_end": "2026-08-04T19:19:34Z",
          "status": "capture-noise",
          "summary": "The page changed only relative publication-time labels.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 2,
          "removed_lines": 2
        },
        {
          "observed_at": "2026-08-04T18:19:03Z",
          "window_start": "2026-08-04T17:49:28Z",
          "window_end": "2026-08-04T18:19:03Z",
          "status": "capture-noise",
          "summary": "Only a relative-time label advanced.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 1,
          "removed_lines": 1
        },
        {
          "observed_at": "2026-08-04T17:49:28Z",
          "window_start": "2026-08-04T16:21:20Z",
          "window_end": "2026-08-04T17:49:28Z",
          "status": "capture-noise",
          "summary": "Only a relative-time label advanced.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 1,
          "removed_lines": 1
        },
        {
          "observed_at": "2026-08-04T16:21:20Z",
          "window_start": "2026-08-04T15:50:53Z",
          "window_end": "2026-08-04T16:21:20Z",
          "status": "capture-noise",
          "summary": "Only a relative time on a related-news card changed. The article's entropy-risk reporting did not change.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 1,
          "removed_lines": 1
        },
        {
          "observed_at": "2026-08-04T15:50:53Z",
          "window_start": "2026-08-04T11:38:07Z",
          "window_end": "2026-08-04T15:50:53Z",
          "status": "capture-noise",
          "summary": "Rotating related-news and promotional cards changed. The article's entropy-risk reporting did not change.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 7,
          "removed_lines": 7
        },
        {
          "observed_at": "2026-08-04T11:38:07Z",
          "window_start": "2026-08-04T10:37:50Z",
          "window_end": "2026-08-04T11:38:07Z",
          "status": "capture-noise",
          "summary": "Only a relative-time label on a Related News sidebar card advanced (23 hours ago to 1 day ago). The article body was unchanged.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 1,
          "removed_lines": 1
        },
        {
          "observed_at": "2026-08-04T10:37:50Z",
          "window_start": "2026-08-04T10:08:49Z",
          "window_end": "2026-08-04T10:37:50Z",
          "status": "capture-noise",
          "summary": "Only a relative-time label on a Related News sidebar card advanced (22 hours ago to 23 hours ago). The article body was unchanged.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 1,
          "removed_lines": 1
        },
        {
          "observed_at": "2026-08-04T10:08:49Z",
          "window_start": "2026-08-04T03:08:34Z",
          "window_end": "2026-08-04T10:08:49Z",
          "status": "capture-noise",
          "summary": "Only relative-time labels on sidebar cards advanced (a Related News card from 15 hours ago to 22 hours ago, a Premium Sponsors card from 19 hours ago to 1 day ago). The article body was unchanged.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 2,
          "removed_lines": 2
        },
        {
          "observed_at": "2026-08-04T03:08:34Z",
          "window_start": "2026-08-03T20:48:59Z",
          "window_end": "2026-08-04T03:08:34Z",
          "status": "capture-noise",
          "summary": "Only relative-time labels on the Related News and Premium Sponsors cards advanced (for example 10 to 15 hours ago, 2 to 3 days ago). The article text was unchanged.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 3,
          "removed_lines": 3
        },
        {
          "observed_at": "2026-08-03T20:48:59Z",
          "window_start": "2026-08-03T14:47:16Z",
          "window_end": "2026-08-03T20:48:59Z",
          "status": "capture-noise",
          "summary": "Only relative-time labels on the sidebar and Related News cards advanced (for example 2 days to 3 days ago, 4 hours to 10 hours ago). The article text was unchanged.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 6,
          "removed_lines": 6
        },
        {
          "observed_at": "2026-08-03T14:47:16Z",
          "window_start": "2026-08-03T13:47:30Z",
          "window_end": "2026-08-03T14:47:16Z",
          "status": "capture-noise",
          "summary": "Only relative age labels in the related-news and press-release sidebar advanced (3 to 4 hours ago, 7 to 8 hours ago). The article text was unchanged.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 2,
          "removed_lines": 2
        },
        {
          "observed_at": "2026-08-03T13:47:30Z",
          "window_start": "2026-08-03T13:18:41Z",
          "window_end": "2026-08-03T13:47:30Z",
          "status": "capture-noise",
          "summary": "Only the same two sidebar card timestamps advanced again (to 3 hours ago and 7 hours ago). The article body was unchanged.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 2,
          "removed_lines": 2
        },
        {
          "observed_at": "2026-08-03T13:18:41Z",
          "window_start": "2026-08-03T12:15:30Z",
          "window_end": "2026-08-03T13:18:41Z",
          "status": "capture-noise",
          "summary": "Only two sidebar card timestamps advanced (a Related News card from 1 hour ago to 2 hours ago, a Press Releases card from 5 hours ago to 6 hours ago). The article body was unchanged.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 2,
          "removed_lines": 2
        },
        {
          "observed_at": "2026-08-03T12:15:30Z",
          "window_start": "2026-08-03T11:48:01Z",
          "window_end": "2026-08-03T12:15:30Z",
          "status": "capture-noise",
          "summary": "Only one sidebar Related News card timestamp advanced (59 minutes ago to 1 hour ago). The article body was unchanged.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 1,
          "removed_lines": 1
        },
        {
          "observed_at": "2026-08-03T11:48:01Z",
          "window_start": "2026-08-03T10:42:37Z",
          "window_end": "2026-08-03T11:48:01Z",
          "status": "capture-noise",
          "summary": "Only sidebar chrome changed: the Related News card lists rotated headlines in both locales and a Press Releases card timestamp advanced from 4 hours ago to 5 hours ago. The article body was unchanged.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 8,
          "removed_lines": 8
        },
        {
          "observed_at": "2026-08-03T10:42:37Z",
          "window_start": "2026-08-03T09:38:39Z",
          "window_end": "2026-08-03T10:42:37Z",
          "status": "capture-noise",
          "summary": "Only a relative timestamp on a Press Releases sidebar card advanced from 3 hours ago to 4 hours ago. The article body was unchanged.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 1,
          "removed_lines": 1
        },
        {
          "observed_at": "2026-08-03T09:38:39Z",
          "window_start": "2026-08-03T09:10:22Z",
          "window_end": "2026-08-03T09:38:39Z",
          "status": "capture-noise",
          "summary": "Only a relative timestamp on a Press Releases sidebar card advanced from 2 hours ago to 3 hours ago. The article body was unchanged.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 1,
          "removed_lines": 1
        },
        {
          "observed_at": "2026-08-03T09:10:22Z",
          "window_start": "2026-08-02T22:03:24Z",
          "window_end": "2026-08-03T09:10:22Z",
          "status": "capture-noise",
          "summary": "Only sidebar chrome changed: the Press Releases list added a new sponsored card and dropped an older Japanese-language card. The article body was unchanged.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 2,
          "removed_lines": 2
        },
        {
          "observed_at": "2026-08-02T22:03:24Z",
          "window_start": "2026-08-02T21:32:24Z",
          "window_end": "2026-08-02T22:03:24Z",
          "status": "capture-noise",
          "summary": "Only relative timestamps in the Related News section advanced from 1 day ago to 2 days ago. The article body was unchanged.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 3,
          "removed_lines": 3
        },
        {
          "observed_at": "2026-08-02T21:32:24Z",
          "window_start": "2026-08-02T15:59:19Z",
          "window_end": "2026-08-02T21:32:24Z",
          "status": "capture-noise",
          "summary": "Only relative timestamps on the related-articles cards advanced from 1 day ago to 2 days ago. The article body was unchanged.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 3,
          "removed_lines": 3
        }
      ]
    },
    {
      "id": "hn-dettmer-writeup-thread",
      "title": "Hacker News discussion of the bitcoin++ writeup",
      "url": "https://news.ycombinator.com/item?id=49140405",
      "organisation": "Hacker News",
      "kind": "reporting",
      "role": "Reporting",
      "publication_time": "2026-08-02",
      "note": "The thread on Dettmer's commit-history writeup, and the place where the\ncorrection this archive already holds separately was published: Greg Maxwell's\ncomment disputing the small-flag-change framing sits inside it, registered as\nhn-maxwell-mechanism. Held for the discussion around that correction rather\nthan for the article itself, which is tracked as btcpp-dettmer-commit-history.\n\nThe held text recursively flattens the item tree by stable comment id, decodes\nthe API's HTML and omits point totals, so a new or edited comment stays loud\nwithout vote changes producing revisions.\n",
      "gone": null,
      "capture": {
        "status": "held",
        "copies": 11,
        "first_observed": "2026-08-03T01:27:54Z",
        "last_observed": "2026-08-09T11:39:40Z",
        "last_checked": "2026-08-15T12:26:22Z"
      },
      "differences": [
        {
          "observed_at": "2026-08-09T11:39:40Z",
          "window_start": "2026-08-07T06:11:39Z",
          "window_end": "2026-08-09T11:39:40Z",
          "status": "capture-correction",
          "summary": "The collector changed this Algolia item from pretty-printed API JSON to deterministic readable thread text; the same discussion tree is held, with HTML decoded and volatile API fields omitted.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 500,
          "removed_lines": 916
        },
        {
          "observed_at": "2026-08-07T06:11:39Z",
          "window_start": "2026-08-06T04:06:24Z",
          "window_end": "2026-08-07T06:11:39Z",
          "status": "source-content",
          "summary": "New comment by jki275 (2026-08-07T01:18:26Z) replying to nullc about what telegraphs competence. No other thread changes.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 17,
          "removed_lines": 1
        },
        {
          "observed_at": "2026-08-06T04:06:24Z",
          "window_start": "2026-08-05T20:54:59Z",
          "window_end": "2026-08-06T04:06:24Z",
          "status": "capture-correction",
          "summary": "Same move to the Hacker News item API as hn-maxwell-mechanism, for the same 429. The thread is now held as pretty-printed JSON: 58 nodes with absolute timestamps, replacing the rendered page and its relative times. No comment text changed across the switch.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 900,
          "removed_lines": 264
        },
        {
          "observed_at": "2026-08-05T20:54:59Z",
          "window_start": "2026-08-04T18:09:17Z",
          "window_end": "2026-08-05T20:54:59Z",
          "status": "source-content",
          "summary": "The discussion gained a comment arguing that COLDCARD documentation had explained dice-based seed generation, while noting that this does not absolve the vendor.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 10,
          "removed_lines": 7
        },
        {
          "observed_at": "2026-08-04T18:09:17Z",
          "window_start": "2026-08-04T15:39:08Z",
          "window_end": "2026-08-04T18:09:17Z",
          "status": "capture-noise",
          "summary": "Only the rendered order of existing Hacker News comments changed.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 7,
          "removed_lines": 7
        },
        {
          "observed_at": "2026-08-04T15:39:08Z",
          "window_start": "2026-08-04T14:38:50Z",
          "window_end": "2026-08-04T15:39:08Z",
          "status": "capture-noise",
          "summary": "An existing comment moved within the captured reply ordering. No Hacker News comment text was added, edited or removed.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 4,
          "removed_lines": 4
        },
        {
          "observed_at": "2026-08-04T14:38:50Z",
          "window_start": "2026-08-04T13:38:56Z",
          "window_end": "2026-08-04T14:38:50Z",
          "status": "source-content",
          "summary": "A further Hacker News comment was added to the discussion; surrounding comments were reordered by thread position.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 10,
          "removed_lines": 10
        },
        {
          "observed_at": "2026-08-04T13:38:56Z",
          "window_start": "2026-08-03T15:45:47Z",
          "window_end": "2026-08-04T13:38:56Z",
          "status": "source-content",
          "summary": "New Hacker News comments were added to the discussion, including discussion of software-engineering practice and implementation choices.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 67,
          "removed_lines": 64
        },
        {
          "observed_at": "2026-08-03T15:45:47Z",
          "window_start": "2026-08-03T12:13:14Z",
          "window_end": "2026-08-03T15:45:47Z",
          "status": "capture-noise",
          "summary": "Only the live score counter moved, from 93 to 94 points; the comment count stayed at 55 and no comment text changed.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 1,
          "removed_lines": 1
        },
        {
          "observed_at": "2026-08-03T12:13:14Z",
          "window_start": "2026-08-03T01:27:54Z",
          "window_end": "2026-08-03T12:13:14Z",
          "status": "capture-noise",
          "summary": "Only live counters and comment ordering changed: the story score went from 92 to 93 points and several existing comments (koolba, coldbrewed, killerstorm, smithcoin, nullc) moved to different positions. No comment text was added, removed or altered.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 20,
          "removed_lines": 20
        }
      ]
    },
    {
      "id": "unchained-help-replace-keys",
      "title": "Unchained key-replacement help article",
      "url": "https://help.unchained.com/how-do-i-replace-the-keys-to-my-vault",
      "organisation": "Unchained",
      "kind": "custody-guidance",
      "role": "Custody guidance",
      "publication_time": null,
      "note": "Unchained's help-centre article on replacing vault keys, updated with\nincident-specific guidance: it names the July/August 2026 Coldcard\nvulnerability, tells clients with two Coldcard-generated keys to consider\nbroadcasting via Slipstream, and says to use only Coldcard firmware from\n31 Jul 2026 or later. The page shows no last-updated stamp, which is exactly\nwhy it needs capture: this is where Unchained's operational client guidance\nlives and it can change without notice.\n",
      "gone": null,
      "capture": {
        "status": "held",
        "copies": 5,
        "first_observed": "2026-08-03T02:08:44Z",
        "last_observed": "2026-08-05T20:55:11Z",
        "last_checked": "2026-08-15T12:26:24Z"
      },
      "differences": [
        {
          "observed_at": "2026-08-05T20:55:11Z",
          "window_start": "2026-08-03T19:46:32Z",
          "window_end": "2026-08-05T20:55:11Z",
          "status": "source-content",
          "summary": "Unchained added billing-plan context for subscription transfers and an alternative withdrawal procedure using the new vault's copied deposit address when Internal transfer is unavailable.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 3,
          "removed_lines": 3
        },
        {
          "observed_at": "2026-08-03T19:46:32Z",
          "window_start": "2026-08-03T16:46:41Z",
          "window_end": "2026-08-03T19:46:32Z",
          "status": "source-content",
          "summary": "The help article's IRA note was reworded to \"Note about IRA vaults\" and gained a new sentence stating that moving bitcoin between vaults within the same IRA account is not treated as a taxable distribution, provided the bitcoin stays within the IRA.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 3,
          "removed_lines": 2
        },
        {
          "observed_at": "2026-08-03T16:46:41Z",
          "window_start": "2026-08-03T16:14:56Z",
          "window_end": "2026-08-03T16:46:41Z",
          "status": "source-content",
          "summary": "The new IRA vault warning paragraph was reworded: \"Unchained's workflow\" became \"this workflow\". No other text changed.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 1,
          "removed_lines": 1
        },
        {
          "observed_at": "2026-08-03T16:14:56Z",
          "window_start": "2026-08-03T02:08:44Z",
          "window_end": "2026-08-03T16:14:56Z",
          "status": "source-content",
          "summary": "The help article added a paragraph explaining the big red warning shown on the deposit address of a new IRA vault: it exists to block outside deposits that skip the approved contribution or rollover process, and may be bypassed only when moving bitcoin between vaults in the same IRA account.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 1,
          "removed_lines": 0
        }
      ]
    },
    {
      "id": "casa-support-coldcard-troubleshooting",
      "title": "Casa Coldcard troubleshooting support page",
      "url": "https://support.casa.io/knowledge/coldcard-troubleshooting",
      "organisation": "Casa",
      "kind": "custody-guidance",
      "role": "Custody guidance",
      "publication_time": null,
      "note": "Casa's standing Coldcard support document. As of 3 Aug 2026 Casa has published\nno blog post on the incident; its only public statements are two X posts\n(casa-incident-guidance, nneuman-casa-migration-video). Registered as the page\nwhere written guidance would land, so any edit is recorded.\n",
      "gone": null,
      "capture": {
        "status": "held",
        "copies": 2,
        "first_observed": "2026-08-03T02:08:45Z",
        "last_observed": "2026-08-06T22:57:51Z",
        "last_checked": "2026-08-15T12:26:26Z"
      },
      "differences": [
        {
          "observed_at": "2026-08-06T22:57:51Z",
          "window_start": "2026-08-03T02:08:45Z",
          "window_end": "2026-08-06T22:57:51Z",
          "status": "source-content",
          "summary": "Casa added a security advisory banner (updated August 1, 2026) warning of the Coldcard seed-generation flaw and recommending the device be replaced, and the page date moved from March 4, 2026 to August 6, 2026.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 2,
          "removed_lines": 1
        }
      ]
    },
    {
      "id": "casa-blog-index",
      "title": "Casa blog index",
      "url": "https://blog.casa.io/",
      "organisation": "Casa",
      "kind": "vendor-index",
      "role": "Vendor publication index",
      "publication_time": null,
      "note": "Watch page. As of 3 Aug 2026 the newest post is 15 days old and there is no\nincident post; registered so the appearance of one is captured with timing.\n",
      "gone": null,
      "capture": {
        "status": "held",
        "copies": 17,
        "first_observed": "2026-08-03T02:08:46Z",
        "last_observed": "2026-08-12T23:55:49Z",
        "last_checked": "2026-08-15T12:26:28Z"
      },
      "differences": [
        {
          "observed_at": "2026-08-12T23:55:49Z",
          "window_start": "2026-08-12T04:39:11Z",
          "window_end": "2026-08-12T23:55:49Z",
          "status": "capture-noise",
          "summary": "Only relative-time labels in the blog index rolled forward (7 days to 8 days, an hour to a day, 5 days to 6 days); no post title, author or featured flag changed.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 4,
          "removed_lines": 4
        },
        {
          "observed_at": "2026-08-12T04:39:11Z",
          "window_start": "2026-08-09T16:46:47Z",
          "window_end": "2026-08-12T04:39:11Z",
          "status": "source-content",
          "summary": "The index gained a new post by Jameson Lopp, relative publication-time labels advanced, and an older post rotated out of the visible list.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 10,
          "removed_lines": 11
        },
        {
          "observed_at": "2026-08-09T16:46:47Z",
          "window_start": "2026-08-07T06:11:49Z",
          "window_end": "2026-08-09T16:46:47Z",
          "status": "capture-noise",
          "summary": "Only relative post timestamps on the Casa blog index rolled. No incident post appeared and no article body changed.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 4,
          "removed_lines": 4
        },
        {
          "observed_at": "2026-08-07T06:11:49Z",
          "window_start": "2026-08-06T22:57:53Z",
          "window_end": "2026-08-07T06:11:49Z",
          "status": "capture-noise",
          "summary": "Relative-time aging only: the Jameson Lopp post went from \"4 hours ago\" to \"6 hours ago\". No items added, removed or edited.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 1,
          "removed_lines": 1
        },
        {
          "observed_at": "2026-08-06T22:57:53Z",
          "window_start": "2026-08-06T16:28:02Z",
          "window_end": "2026-08-06T22:57:53Z",
          "status": "source-content",
          "summary": "Blog index changed: a new post \"The Rise of the Machines\" by Jameson Lopp (4 hours ago) appeared, and the older card \"The security review every serious bitcoiner should do in 2026\" rotated out of the AI category section.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 4,
          "removed_lines": 4
        },
        {
          "observed_at": "2026-08-06T16:28:02Z",
          "window_start": "2026-08-05T20:55:15Z",
          "window_end": "2026-08-06T16:28:02Z",
          "status": "capture-noise",
          "summary": "Live relative-date counters: post age labels rolled over (\"a day ago\" to \"2 days ago\", \"21 days ago\" to \"22 days ago\"); no posts added or removed.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 3,
          "removed_lines": 3
        },
        {
          "observed_at": "2026-08-05T20:55:15Z",
          "window_start": "2026-08-05T14:20:22Z",
          "window_end": "2026-08-05T20:55:15Z",
          "status": "capture-noise",
          "summary": "Casa's relative-age labels changed from 21 hours ago to a day ago. No article or incident-watch content changed.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 2,
          "removed_lines": 2
        },
        {
          "observed_at": "2026-08-05T14:20:22Z",
          "window_start": "2026-08-05T00:11:44Z",
          "window_end": "2026-08-05T14:20:22Z",
          "status": "capture-noise",
          "summary": "Only relative publication-time labels on existing blog cards advanced, from hours or days ago to later relative times. No post title or article content changed.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 3,
          "removed_lines": 3
        },
        {
          "observed_at": "2026-08-05T00:11:44Z",
          "window_start": "2026-08-04T22:42:06Z",
          "window_end": "2026-08-05T00:11:44Z",
          "status": "source-content",
          "summary": "Casa added the Bitcoin security category to its Coldcard vulnerability article in the blog index.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 3,
          "removed_lines": 2
        },
        {
          "observed_at": "2026-08-04T22:42:06Z",
          "window_start": "2026-08-04T21:41:02Z",
          "window_end": "2026-08-04T22:42:06Z",
          "status": "capture-noise",
          "summary": "The index changed relative times and repeated the existing Coldcard article in its featured presentation.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 6,
          "removed_lines": 1
        },
        {
          "observed_at": "2026-08-04T21:41:02Z",
          "window_start": "2026-08-04T19:40:51Z",
          "window_end": "2026-08-04T21:41:02Z",
          "status": "capture-noise",
          "summary": "Only the relative publication time on the existing Coldcard article changed.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 1,
          "removed_lines": 1
        },
        {
          "observed_at": "2026-08-04T19:40:51Z",
          "window_start": "2026-08-04T18:40:40Z",
          "window_end": "2026-08-04T19:40:51Z",
          "status": "capture-noise",
          "summary": "The blog index changed only its live author and relative-time metadata.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 2,
          "removed_lines": 2
        },
        {
          "observed_at": "2026-08-04T18:40:40Z",
          "window_start": "2026-08-04T18:09:24Z",
          "window_end": "2026-08-04T18:40:40Z",
          "status": "capture-noise",
          "summary": "Only relative publication-time labels advanced on the blog index.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 1,
          "removed_lines": 1
        },
        {
          "observed_at": "2026-08-04T18:09:24Z",
          "window_start": "2026-08-04T17:09:14Z",
          "window_end": "2026-08-04T18:09:24Z",
          "status": "capture-noise",
          "summary": "Only relative publication-time labels advanced on the blog index.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 1,
          "removed_lines": 1
        },
        {
          "observed_at": "2026-08-04T17:09:14Z",
          "window_start": "2026-08-03T11:43:49Z",
          "window_end": "2026-08-04T17:09:14Z",
          "status": "source-content",
          "summary": "Casa added its Coldcard vulnerability explainer to the blog index.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 6,
          "removed_lines": 7
        },
        {
          "observed_at": "2026-08-03T11:43:49Z",
          "window_start": "2026-08-03T02:08:46Z",
          "window_end": "2026-08-03T11:43:49Z",
          "status": "capture-noise",
          "summary": "Only relative date labels on the blog index cards shifted (15 days ago to 19 days ago, 23 days ago to a month ago). No post was added, removed or retitled.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 2,
          "removed_lines": 2
        }
      ]
    },
    {
      "id": "checkonchain-coldcard-psa",
      "title": "Checkonchain PSA on the Coldcard exploit",
      "url": "https://newsletter.checkonchain.com/p/psa-addressing-the-coldcard-exploit",
      "organisation": "Checkonchain",
      "kind": "independent-analysis",
      "role": "Independent primary analysis",
      "publication_time": null,
      "note": "James Check's subscriber PSA with step-by-step owner guidance. Held as\nindependent incident-response guidance from an analyst, not a custody\nprovider; registered in this section because it circulated as the kind of\nclient notice providers were sending.\n",
      "gone": null,
      "capture": {
        "status": "held",
        "copies": 17,
        "first_observed": "2026-08-03T02:08:46Z",
        "last_observed": "2026-08-12T05:10:28Z",
        "last_checked": "2026-08-15T12:55:35Z"
      },
      "differences": [
        {
          "observed_at": "2026-08-12T05:10:28Z",
          "window_start": "2026-08-09T05:29:57Z",
          "window_end": "2026-08-12T05:10:28Z",
          "status": "capture-noise",
          "summary": "Only Substack engagement counters and comment counts changed; the post text was unchanged.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 4,
          "removed_lines": 4
        },
        {
          "observed_at": "2026-08-09T05:29:57Z",
          "window_start": "2026-08-08T16:26:52Z",
          "window_end": "2026-08-09T05:29:57Z",
          "status": "capture-noise",
          "summary": "Only relative date labels rolled from '8d' to 'Aug 1'; the PSA text was unchanged.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 2,
          "removed_lines": 2
        },
        {
          "observed_at": "2026-08-08T16:26:52Z",
          "window_start": "2026-08-07T20:52:39Z",
          "window_end": "2026-08-08T16:26:52Z",
          "status": "capture-noise",
          "summary": "Only relative-time labels rolled from 7d to 8d on two comments; the PSA text was unchanged.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 2,
          "removed_lines": 2
        },
        {
          "observed_at": "2026-08-07T20:52:39Z",
          "window_start": "2026-08-07T14:23:41Z",
          "window_end": "2026-08-07T20:52:39Z",
          "status": "capture-noise",
          "summary": "Only a relative-age label changed from 6d to 7d; the PSA text was unchanged.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 1,
          "removed_lines": 1
        },
        {
          "observed_at": "2026-08-07T14:23:41Z",
          "window_start": "2026-08-06T16:38:28Z",
          "window_end": "2026-08-07T14:23:41Z",
          "status": "capture-noise",
          "summary": "Relative-date rollover only: the age label on Ricardo Santiago's reply changed from 6d to 7d. No comment text changed.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 1,
          "removed_lines": 1
        },
        {
          "observed_at": "2026-08-06T16:38:28Z",
          "window_start": "2026-08-05T14:29:49Z",
          "window_end": "2026-08-06T16:38:28Z",
          "status": "capture-noise",
          "summary": "Relative comment ages ticked from 5d to 6d on two comments. No new comments, replies or edits.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 2,
          "removed_lines": 2
        },
        {
          "observed_at": "2026-08-05T14:29:49Z",
          "window_start": "2026-08-04T18:19:05Z",
          "window_end": "2026-08-05T14:29:49Z",
          "status": "capture-noise",
          "summary": "Only two relative-time labels advanced from 4d to 5d. No PSA content changed.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 2,
          "removed_lines": 2
        },
        {
          "observed_at": "2026-08-04T18:19:05Z",
          "window_start": "2026-08-04T14:18:49Z",
          "window_end": "2026-08-04T18:19:05Z",
          "status": "capture-noise",
          "summary": "Only the relative-time label advanced from 4d to 3d.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 1,
          "removed_lines": 1
        },
        {
          "observed_at": "2026-08-04T14:18:49Z",
          "window_start": "2026-08-04T10:08:51Z",
          "window_end": "2026-08-04T14:18:49Z",
          "status": "capture-noise",
          "summary": "Only the visible reaction count rose from 83 to 84 and a relative-time label advanced by a day. The PSA and replies are otherwise unchanged.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 3,
          "removed_lines": 3
        },
        {
          "observed_at": "2026-08-04T10:08:51Z",
          "window_start": "2026-08-04T03:08:37Z",
          "window_end": "2026-08-04T10:08:51Z",
          "status": "capture-noise",
          "summary": "Only the Substack engagement counters moved, likes from 81 to 83 and restacks from 13 to 14, in both renderings of each counter. The PSA text was unchanged.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 4,
          "removed_lines": 4
        },
        {
          "observed_at": "2026-08-04T03:08:37Z",
          "window_start": "2026-08-03T20:49:01Z",
          "window_end": "2026-08-04T03:08:37Z",
          "status": "capture-noise",
          "summary": "Only the Substack like counter moved, from 80 to 81 in both renderings of the counter. The PSA text was unchanged.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 2,
          "removed_lines": 2
        },
        {
          "observed_at": "2026-08-03T20:49:01Z",
          "window_start": "2026-08-03T15:13:01Z",
          "window_end": "2026-08-03T20:49:01Z",
          "status": "capture-noise",
          "summary": "Only engagement counters and relative-time labels moved: the post's reaction count rose from 78 to 80 and two comment timestamps rolled from 2d to 3d. No post or comment text changed.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 4,
          "removed_lines": 4
        },
        {
          "observed_at": "2026-08-03T15:13:01Z",
          "window_start": "2026-08-03T14:47:18Z",
          "window_end": "2026-08-03T15:13:01Z",
          "status": "capture-noise",
          "summary": "Only Substack live counters and comment age rounding moved: the like total under the post went from 79 to 78 in both renderings of the counter, and two comments flipped from 3d back to 2d. The PSA text was unchanged.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 4,
          "removed_lines": 4
        },
        {
          "observed_at": "2026-08-03T14:47:18Z",
          "window_start": "2026-08-03T11:13:22Z",
          "window_end": "2026-08-03T14:47:18Z",
          "status": "capture-noise",
          "summary": "Only Substack live counters and comment ages moved: the like total under the post rose from 78 to 79 in both renderings of the counter, and two comments aged from 2d to 3d. The PSA text was unchanged.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 4,
          "removed_lines": 4
        },
        {
          "observed_at": "2026-08-03T11:13:22Z",
          "window_start": "2026-08-03T09:10:24Z",
          "window_end": "2026-08-03T11:13:22Z",
          "status": "capture-noise",
          "summary": "Only live counters changed: like and restack totals rose (76 to 78, 22 to 24), one comment's reply count grew from 1 to 3, and the collapsed comment count went from 20 to 22. The PSA text was unchanged.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 6,
          "removed_lines": 6
        },
        {
          "observed_at": "2026-08-03T09:10:24Z",
          "window_start": "2026-08-03T02:08:46Z",
          "window_end": "2026-08-03T09:10:24Z",
          "status": "capture-noise",
          "summary": "Only the Substack engagement counters changed: the like total under the post rose from 74 to 76 in both renderings of the counter. The PSA text was unchanged.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 2,
          "removed_lines": 2
        }
      ]
    },
    {
      "id": "chaincatcher-nunchuk-response",
      "title": "ChainCatcher on Nunchuk's platform-key statement",
      "url": "https://www.chaincatcher.com/en/article/2279664",
      "organisation": "ChainCatcher",
      "kind": "reporting",
      "role": "Reporting",
      "publication_time": null,
      "note": "Secondary account of Nunchuk's statement that some platform keys were\ngenerated on Coldcard Mk4 devices, that the platform derives independent keys\nvia custom logic rather than using the seeds directly, and that Nunchuk\nexpects attackers could eventually incorporate derived keys. The primary post\nfor this statement has not been located; this capture holds the claim until\nit is, and should be supplemented or replaced when the primary is found.\ncsbastiat-nunchuk-criticism carries a screenshot of the statement text\nitself, which corroborates the wording quoted here.\n",
      "gone": null,
      "capture": {
        "status": "held",
        "copies": 48,
        "first_observed": "2026-08-03T02:08:47Z",
        "last_observed": "2026-08-05T00:51:07Z",
        "last_checked": "2026-08-15T12:55:37Z"
      },
      "differences": [
        {
          "observed_at": "2026-08-05T00:51:07Z",
          "window_start": "2026-08-05T00:21:11Z",
          "window_end": "2026-08-05T00:51:07Z",
          "status": "capture-noise",
          "summary": "Only text excluded by the tested canonical comparison rules changed (chaincatcher-article); the tracked source content is identical.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 32,
          "removed_lines": 32
        },
        {
          "observed_at": "2026-08-05T00:21:11Z",
          "window_start": "2026-08-04T23:51:08Z",
          "window_end": "2026-08-05T00:21:11Z",
          "status": "capture-noise",
          "summary": "Only the page's live cryptocurrency ticker values and unrelated news rail changed.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 36,
          "removed_lines": 36
        },
        {
          "observed_at": "2026-08-04T23:51:08Z",
          "window_start": "2026-08-04T23:27:36Z",
          "window_end": "2026-08-04T23:51:08Z",
          "status": "capture-noise",
          "summary": "Only the page's live cryptocurrency ticker values changed.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 32,
          "removed_lines": 30
        },
        {
          "observed_at": "2026-08-04T23:27:36Z",
          "window_start": "2026-08-04T22:51:48Z",
          "window_end": "2026-08-04T23:27:36Z",
          "status": "capture-noise",
          "summary": "Only the page's live cryptocurrency ticker values and unrelated news rail changed.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 30,
          "removed_lines": 32
        },
        {
          "observed_at": "2026-08-04T22:51:48Z",
          "window_start": "2026-08-04T22:21:11Z",
          "window_end": "2026-08-04T22:51:48Z",
          "status": "capture-noise",
          "summary": "Only the page's live cryptocurrency ticker values changed.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 30,
          "removed_lines": 30
        },
        {
          "observed_at": "2026-08-04T22:21:11Z",
          "window_start": "2026-08-04T21:50:31Z",
          "window_end": "2026-08-04T22:21:11Z",
          "status": "capture-noise",
          "summary": "Only the page's live cryptocurrency price ticker changed.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 30,
          "removed_lines": 30
        },
        {
          "observed_at": "2026-08-04T21:50:31Z",
          "window_start": "2026-08-04T21:20:31Z",
          "window_end": "2026-08-04T21:50:31Z",
          "status": "capture-noise",
          "summary": "Only the page's live cryptocurrency price ticker changed.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 30,
          "removed_lines": 30
        },
        {
          "observed_at": "2026-08-04T21:20:31Z",
          "window_start": "2026-08-04T20:50:39Z",
          "window_end": "2026-08-04T21:20:31Z",
          "status": "capture-noise",
          "summary": "Only the page's live cryptocurrency price ticker changed.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 30,
          "removed_lines": 30
        },
        {
          "observed_at": "2026-08-04T20:50:39Z",
          "window_start": "2026-08-04T20:20:46Z",
          "window_end": "2026-08-04T20:50:39Z",
          "status": "capture-noise",
          "summary": "Only the page's live cryptocurrency price ticker changed.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 30,
          "removed_lines": 30
        },
        {
          "observed_at": "2026-08-04T20:20:46Z",
          "window_start": "2026-08-04T19:50:18Z",
          "window_end": "2026-08-04T20:20:46Z",
          "status": "capture-noise",
          "summary": "The page changed only its live cryptocurrency price ticker and related market widgets.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 30,
          "removed_lines": 30
        },
        {
          "observed_at": "2026-08-04T19:50:18Z",
          "window_start": "2026-08-04T19:19:38Z",
          "window_end": "2026-08-04T19:50:18Z",
          "status": "capture-noise",
          "summary": "The page changed only its live cryptocurrency price ticker and related market widgets.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 30,
          "removed_lines": 30
        },
        {
          "observed_at": "2026-08-04T19:19:38Z",
          "window_start": "2026-08-04T18:50:33Z",
          "window_end": "2026-08-04T19:19:38Z",
          "status": "capture-noise",
          "summary": "The page changed only its live cryptocurrency price ticker and related market widgets.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 30,
          "removed_lines": 30
        },
        {
          "observed_at": "2026-08-04T18:50:33Z",
          "window_start": "2026-08-04T18:19:08Z",
          "window_end": "2026-08-04T18:50:33Z",
          "status": "capture-noise",
          "summary": "The page changed only its live cryptocurrency price ticker and related market widgets.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 30,
          "removed_lines": 30
        },
        {
          "observed_at": "2026-08-04T18:19:08Z",
          "window_start": "2026-08-04T17:49:32Z",
          "window_end": "2026-08-04T18:19:08Z",
          "status": "capture-noise",
          "summary": "Only live cryptocurrency price and percentage tickers changed.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 30,
          "removed_lines": 30
        },
        {
          "observed_at": "2026-08-04T17:49:32Z",
          "window_start": "2026-08-04T17:19:18Z",
          "window_end": "2026-08-04T17:49:32Z",
          "status": "capture-noise",
          "summary": "Only live cryptocurrency price and percentage tickers changed.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 30,
          "removed_lines": 30
        },
        {
          "observed_at": "2026-08-04T17:19:18Z",
          "window_start": "2026-08-04T16:51:04Z",
          "window_end": "2026-08-04T17:19:18Z",
          "status": "capture-noise",
          "summary": "Only live cryptocurrency price and percentage tickers changed.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 30,
          "removed_lines": 30
        },
        {
          "observed_at": "2026-08-04T16:51:04Z",
          "window_start": "2026-08-04T16:21:25Z",
          "window_end": "2026-08-04T16:51:04Z",
          "status": "capture-noise",
          "summary": "Only live cryptocurrency price and percentage tickers changed.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 32,
          "removed_lines": 32
        },
        {
          "observed_at": "2026-08-04T16:21:25Z",
          "window_start": "2026-08-04T15:50:57Z",
          "window_end": "2026-08-04T16:21:25Z",
          "status": "capture-noise",
          "summary": "Live cryptocurrency prices and rotating related-reading cards changed. The Nunchuk response itself did not change.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 34,
          "removed_lines": 34
        },
        {
          "observed_at": "2026-08-04T15:50:57Z",
          "window_start": "2026-08-04T15:18:42Z",
          "window_end": "2026-08-04T15:50:57Z",
          "status": "capture-noise",
          "summary": "Only the page's live cryptocurrency-price ticker changed. The Nunchuk response itself did not change.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 30,
          "removed_lines": 30
        },
        {
          "observed_at": "2026-08-04T15:18:42Z",
          "window_start": "2026-08-04T14:48:20Z",
          "window_end": "2026-08-04T15:18:42Z",
          "status": "capture-noise",
          "summary": "Live cryptocurrency prices and rotating related-reading cards changed. The Nunchuk response itself did not change.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 32,
          "removed_lines": 32
        },
        {
          "observed_at": "2026-08-04T14:48:20Z",
          "window_start": "2026-08-04T14:18:51Z",
          "window_end": "2026-08-04T14:48:20Z",
          "status": "capture-noise",
          "summary": "Live cryptocurrency prices and rotating related-reading cards changed. The Nunchuk response itself did not change.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 32,
          "removed_lines": 32
        },
        {
          "observed_at": "2026-08-04T14:18:51Z",
          "window_start": "2026-08-04T13:47:58Z",
          "window_end": "2026-08-04T14:18:51Z",
          "status": "capture-noise",
          "summary": "Only the duplicated live cryptocurrency ticker changed; later captures also rotated unrelated related-reading links. The Nunchuk response itself is unchanged.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 34,
          "removed_lines": 34
        },
        {
          "observed_at": "2026-08-04T13:47:58Z",
          "window_start": "2026-08-04T13:09:23Z",
          "window_end": "2026-08-04T13:47:58Z",
          "status": "capture-noise",
          "summary": "Only the duplicated live cryptocurrency ticker changed; later captures also rotated unrelated related-reading links. The Nunchuk response itself is unchanged.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 32,
          "removed_lines": 32
        },
        {
          "observed_at": "2026-08-04T13:09:23Z",
          "window_start": "2026-08-04T12:38:24Z",
          "window_end": "2026-08-04T13:09:23Z",
          "status": "capture-noise",
          "summary": "Only the duplicated live cryptocurrency ticker changed; later captures also rotated unrelated related-reading links. The Nunchuk response itself is unchanged.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 30,
          "removed_lines": 30
        },
        {
          "observed_at": "2026-08-04T12:38:24Z",
          "window_start": "2026-08-04T12:09:21Z",
          "window_end": "2026-08-04T12:38:24Z",
          "status": "capture-noise",
          "summary": "Same chrome churn again: updated price ticker quotes and a rotated Related reading card list. The article text was unchanged.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 32,
          "removed_lines": 32
        },
        {
          "observed_at": "2026-08-04T12:09:21Z",
          "window_start": "2026-08-04T11:38:11Z",
          "window_end": "2026-08-04T12:09:21Z",
          "status": "capture-noise",
          "summary": "Same chrome churn again: updated price ticker quotes and a rotated Related reading card list. The article text was unchanged.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 32,
          "removed_lines": 32
        },
        {
          "observed_at": "2026-08-04T11:38:11Z",
          "window_start": "2026-08-04T11:09:00Z",
          "window_end": "2026-08-04T11:38:11Z",
          "status": "capture-noise",
          "summary": "Same chrome churn again: updated price ticker quotes and a rotated Related reading card list. The article text was unchanged.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 32,
          "removed_lines": 32
        },
        {
          "observed_at": "2026-08-04T11:09:00Z",
          "window_start": "2026-08-04T10:37:54Z",
          "window_end": "2026-08-04T11:09:00Z",
          "status": "capture-noise",
          "summary": "Only the duplicated live cryptocurrency price ticker served updated quotes and the Related reading cards rotated headlines. The Nunchuk article text was unchanged.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 32,
          "removed_lines": 32
        },
        {
          "observed_at": "2026-08-04T10:37:54Z",
          "window_start": "2026-08-04T10:08:53Z",
          "window_end": "2026-08-04T10:37:54Z",
          "status": "capture-noise",
          "summary": "Only the duplicated live cryptocurrency price ticker in the site header served updated quotes. The Nunchuk article text was unchanged.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 30,
          "removed_lines": 30
        },
        {
          "observed_at": "2026-08-04T10:08:53Z",
          "window_start": "2026-08-04T03:08:39Z",
          "window_end": "2026-08-04T10:08:53Z",
          "status": "capture-noise",
          "summary": "Only live chrome moved: the duplicated header price tickers served updated quotes, the Related reading flash-news cards rotated to newer headlines, and a footer 'AWS' link disappeared. The Nunchuk article text was unchanged.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 36,
          "removed_lines": 37
        },
        {
          "observed_at": "2026-08-04T03:08:39Z",
          "window_start": "2026-08-03T20:49:04Z",
          "window_end": "2026-08-04T03:08:39Z",
          "status": "capture-noise",
          "summary": "Only live chrome moved: the duplicated header price tickers served updated quotes, and the Related reading flash-news cards rotated to newer headlines. The Nunchuk article text was unchanged.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 36,
          "removed_lines": 36
        },
        {
          "observed_at": "2026-08-03T20:49:04Z",
          "window_start": "2026-08-03T15:13:03Z",
          "window_end": "2026-08-03T20:49:04Z",
          "status": "capture-noise",
          "summary": "Only live chrome moved: the duplicated header price tickers served updated quotes, and the Related reading flash-news cards rotated to newer headlines. The article text was unchanged.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 36,
          "removed_lines": 34
        },
        {
          "observed_at": "2026-08-03T15:13:03Z",
          "window_start": "2026-08-03T14:47:20Z",
          "window_end": "2026-08-03T15:13:03Z",
          "status": "capture-noise",
          "summary": "Only the live price ticker in the site header served updated values (rendered twice), and the rotating Related reading rail swapped two cards for one new headline. The article text was unchanged.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 30,
          "removed_lines": 32
        },
        {
          "observed_at": "2026-08-03T14:47:20Z",
          "window_start": "2026-08-03T14:18:06Z",
          "window_end": "2026-08-03T14:47:20Z",
          "status": "capture-noise",
          "summary": "Only the live price ticker in the site header served updated values (BTC, ETH and the other listed quotes each showed new prices and 24h changes, rendered twice). The article text was unchanged.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 30,
          "removed_lines": 30
        },
        {
          "observed_at": "2026-08-03T14:18:06Z",
          "window_start": "2026-08-03T13:47:34Z",
          "window_end": "2026-08-03T14:18:06Z",
          "status": "capture-noise",
          "summary": "Only page chrome changed: the duplicated live cryptocurrency price ticker updated its quotes and a new flash-news item (an ancient-miner 500 BTC transfer headline) entered the rotating sidebar list. The Nunchuk article text was unchanged.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 32,
          "removed_lines": 30
        },
        {
          "observed_at": "2026-08-03T13:47:34Z",
          "window_start": "2026-08-03T13:18:53Z",
          "window_end": "2026-08-03T13:47:34Z",
          "status": "capture-noise",
          "summary": "Only page chrome changed: the duplicated live cryptocurrency price ticker updated its quotes and one flash-news sidebar item (a BlackRock IBIT transfer headline) dropped off the rotating list. The Nunchuk article text was unchanged.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 30,
          "removed_lines": 32
        },
        {
          "observed_at": "2026-08-03T13:18:53Z",
          "window_start": "2026-08-03T12:46:47Z",
          "window_end": "2026-08-03T13:18:53Z",
          "status": "capture-noise",
          "summary": "Only the duplicated live cryptocurrency price ticker updated its quotes. The Nunchuk article text was unchanged.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 30,
          "removed_lines": 30
        },
        {
          "observed_at": "2026-08-03T12:46:47Z",
          "window_start": "2026-08-03T12:15:35Z",
          "window_end": "2026-08-03T12:46:47Z",
          "status": "capture-noise",
          "summary": "Only page chrome changed: the duplicated live cryptocurrency price ticker updated its quotes and the related-reading cards rotated to newer headlines. The Nunchuk article text was unchanged.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 34,
          "removed_lines": 34
        },
        {
          "observed_at": "2026-08-03T12:15:35Z",
          "window_start": "2026-08-03T11:48:05Z",
          "window_end": "2026-08-03T12:15:35Z",
          "status": "capture-noise",
          "summary": "Only page chrome changed: the duplicated live cryptocurrency price ticker updated its quotes and the related-reading cards rotated to newer headlines. The Nunchuk article text was unchanged.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 36,
          "removed_lines": 34
        },
        {
          "observed_at": "2026-08-03T11:48:05Z",
          "window_start": "2026-08-03T11:13:25Z",
          "window_end": "2026-08-03T11:48:05Z",
          "status": "capture-noise",
          "summary": "Only the duplicated live cryptocurrency price ticker updated its quotes. The Nunchuk article text was unchanged.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 30,
          "removed_lines": 30
        },
        {
          "observed_at": "2026-08-03T11:13:25Z",
          "window_start": "2026-08-03T10:42:41Z",
          "window_end": "2026-08-03T11:13:25Z",
          "status": "capture-noise",
          "summary": "Only page chrome changed: the duplicated live cryptocurrency price ticker updated its quotes and the related-reading cards rotated to newer headlines. The Nunchuk article text was unchanged.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 34,
          "removed_lines": 34
        },
        {
          "observed_at": "2026-08-03T10:42:41Z",
          "window_start": "2026-08-03T10:16:58Z",
          "window_end": "2026-08-03T10:42:41Z",
          "status": "capture-noise",
          "summary": "Only page chrome changed: the duplicated live price ticker updated its quotes and the related-reading cards rotated again. The Nunchuk article text was unchanged.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 32,
          "removed_lines": 34
        },
        {
          "observed_at": "2026-08-03T10:16:58Z",
          "window_start": "2026-08-03T09:38:43Z",
          "window_end": "2026-08-03T10:16:58Z",
          "status": "capture-noise",
          "summary": "Only page chrome changed: the duplicated live price ticker updated its quotes and the related-reading cards rotated to newer headlines. The Nunchuk article text was unchanged.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 34,
          "removed_lines": 34
        },
        {
          "observed_at": "2026-08-03T09:38:43Z",
          "window_start": "2026-08-03T09:10:26Z",
          "window_end": "2026-08-03T09:38:43Z",
          "status": "capture-noise",
          "summary": "Only page chrome changed: the duplicated live price ticker updated its quotes and the related-reading cards cycled again. The Nunchuk article text was unchanged.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 34,
          "removed_lines": 30
        },
        {
          "observed_at": "2026-08-03T09:10:26Z",
          "window_start": "2026-08-03T03:06:19Z",
          "window_end": "2026-08-03T09:10:26Z",
          "status": "capture-noise",
          "summary": "Only page chrome changed: the duplicated live cryptocurrency price ticker updated its quotes and the related-reading cards rotated to newer headlines. The Nunchuk article text was unchanged.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 32,
          "removed_lines": 36
        },
        {
          "observed_at": "2026-08-03T03:06:19Z",
          "window_start": "2026-08-03T02:34:36Z",
          "window_end": "2026-08-03T03:06:19Z",
          "status": "capture-noise",
          "summary": "Only page chrome changed: the duplicated live cryptocurrency price ticker updated its quotes and the related-reading cards rotated to newer headlines. The Nunchuk article text was unchanged.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 36,
          "removed_lines": 36
        },
        {
          "observed_at": "2026-08-03T02:34:36Z",
          "window_start": "2026-08-03T02:08:47Z",
          "window_end": "2026-08-03T02:34:36Z",
          "status": "capture-noise",
          "summary": "Only page chrome changed: the duplicated live cryptocurrency price ticker updated its quotes and the rotating related-reading cards cycled to newer headlines. The Nunchuk article text is unchanged.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 36,
          "removed_lines": 34
        }
      ]
    },
    {
      "id": "stackernews-prior-warning-video",
      "title": "Claim that the BTCRecover maintainer warned about COLDCARD two years ago",
      "url": "https://stacker.news/items/1538447",
      "organisation": "Stacker News",
      "kind": "reporting",
      "role": "Reporting",
      "publication_time": "2026-08-02",
      "note": "A Stacker News thread linking a YouTube video (youtu.be/oj_W3xOlt6U) said to\nshow the BTCRecover maintainer warning about COLDCARD entropy two years before\nthe incident, and claiming NVK had blocked him on X. The prior-warning claim\nand the block claim are the thread author's; neither is verified here, and the\nvideo itself is not captured by this archive.\n\nCaptured through the site's public GraphQL API: the browser route crashes the\ncapture tab on stacker.news pages, and the API answers POST from this host\nwhile the rendered page is challenge-gated. The query fixes the captured\nsurface to the item's title, text and two levels of comments, each with author\nand absolute timestamp.\n",
      "gone": null,
      "capture": {
        "status": "held",
        "copies": 2,
        "first_observed": "2026-08-04T00:16:40Z",
        "last_observed": "2026-08-04T00:35:56Z",
        "last_checked": "2026-08-15T12:26:30Z"
      },
      "differences": [
        {
          "observed_at": "2026-08-04T00:35:56Z",
          "window_start": "2026-08-04T00:16:40Z",
          "window_end": "2026-08-04T00:35:56Z",
          "status": "capture-correction",
          "summary": "The capture route moved from the crashing browser tab to the stacker.news GraphQL API. The preceding snapshot (20260804T001640Z), written by a scheduled poll that overlapped maintenance with the old configuration, held the MARA Slipstream portal text read from a stale tab after the stacker.news tab crashed, not the thread. This capture is the thread's first real content, and a tab-identity check now refuses to file a page whose host does not match the source.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 44,
          "removed_lines": 20
        }
      ]
    },
    {
      "id": "reddit-wallet-brand-link-warning",
      "title": "r/Bitcoin: warning about emails from hardware-wallet brands",
      "url": "https://www.reddit.com/r/Bitcoin/comments/1v31ivo/if_you_got_any_email_from_any_of_your_cold_wallet/",
      "organisation": "reddit",
      "kind": "community-discussion",
      "role": "Community discussion",
      "publication_time": null,
      "note": null,
      "gone": null,
      "capture": {
        "status": "held",
        "copies": 1,
        "first_observed": "2026-08-04T03:23:38Z",
        "last_observed": "2026-08-04T03:23:38Z",
        "last_checked": "2026-08-11T03:33:32Z"
      },
      "differences": []
    },
    {
      "id": "reddit-ai-discovery-thread",
      "title": "r/Bitcoin thread on the Claude Code vulnerability-audit reproduction",
      "url": "https://www.reddit.com/r/Bitcoin/comments/1vddeuy/",
      "organisation": "r/Bitcoin",
      "kind": "community-discussion",
      "role": "Community discussion",
      "publication_time": "2026-08-02",
      "note": "A discussion thread claiming an LLM prompted only to \"check for\nvulnerabilities\" surfaced the defect after eight minutes, and asserting the\ntheft exceeded $100m. Both figures are the thread's own; the post-publication\ndiscovery reproductions this archive holds are attributed on /response/ai/.\nCaptured for how the AI-discovery framing spread in community venues.\n",
      "gone": null,
      "capture": {
        "status": "held",
        "copies": 17,
        "first_observed": "2026-08-04T03:23:41Z",
        "last_observed": "2026-08-08T21:27:44Z",
        "last_checked": "2026-08-11T03:34:36Z"
      },
      "differences": [
        {
          "observed_at": "2026-08-08T21:27:44Z",
          "window_start": "2026-08-08T14:57:43Z",
          "window_end": "2026-08-08T21:27:44Z",
          "status": "source-content",
          "summary": "The thread gained a new comment blaming speculators and defending open-source code, while an earlier open-versus-closed-source comment was replaced and the live comment count expanded.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 10,
          "removed_lines": 12
        },
        {
          "observed_at": "2026-08-08T14:57:43Z",
          "window_start": "2026-08-07T12:51:19Z",
          "window_end": "2026-08-08T14:57:43Z",
          "status": "source-content",
          "summary": "The thread gained a new comment asking someone to run Claude prompts against Trezor and Ledger codebases and share the results, and the visible more-stub parent pointer shifted from p18crfw to p18c95s.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 9,
          "removed_lines": 9
        },
        {
          "observed_at": "2026-08-07T12:51:19Z",
          "window_start": "2026-08-07T06:11:58Z",
          "window_end": "2026-08-07T12:51:19Z",
          "status": "source-content",
          "summary": "A large reshuffle: roughly ten previously collapsed comments are now expanded (a subthread on whether dev teams should pay for AI code review) and several low-quality comments (insults, \"prove it\", court-payout speculation) disappeared.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 69,
          "removed_lines": 59
        },
        {
          "observed_at": "2026-08-07T06:11:58Z",
          "window_start": "2026-08-06T16:28:11Z",
          "window_end": "2026-08-07T06:11:58Z",
          "status": "source-content",
          "summary": "Two duplicated RollingMeteors comments disappeared and two new comments were added: one asserting the developer did it on purpose, one recounting that the team was allegedly aware of the test-only bug.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 18,
          "removed_lines": 28
        },
        {
          "observed_at": "2026-08-06T16:28:11Z",
          "window_start": "2026-08-06T09:55:50Z",
          "window_end": "2026-08-06T16:28:11Z",
          "status": "source-content",
          "summary": "A comment by THE_RETARD_AGITATOR (\"honestly, good\") was deleted, and one new comment by Valnaya says it is crazy this was not caught sooner.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 9,
          "removed_lines": 9
        },
        {
          "observed_at": "2026-08-06T09:55:50Z",
          "window_start": "2026-08-06T03:24:32Z",
          "window_end": "2026-08-06T09:55:50Z",
          "status": "source-content",
          "summary": "Two earlier comments disappeared (a \"wtf are you talking about?\" reply and a comment claiming GPG signatures prove switck is doc-hex), and one new Spanish-language comment argues self-generated entropy avoids the bug.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 12,
          "removed_lines": 18
        },
        {
          "observed_at": "2026-08-06T03:24:32Z",
          "window_start": "2026-08-05T20:55:25Z",
          "window_end": "2026-08-06T03:24:32Z",
          "status": "source-content",
          "summary": "Reddit now marks the original author and one comment as deleted or removed, removes linked examples from that comment, and adds a later reply.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 14,
          "removed_lines": 24
        },
        {
          "observed_at": "2026-08-05T20:55:25Z",
          "window_start": "2026-08-05T14:20:32Z",
          "window_end": "2026-08-05T20:55:25Z",
          "status": "source-content",
          "summary": "Reddit served five additional comments about the audit framing, source availability and inside-job speculation, while four previously held comments were omitted from this response.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 52,
          "removed_lines": 32
        },
        {
          "observed_at": "2026-08-05T14:20:32Z",
          "window_start": "2026-08-05T07:52:25Z",
          "window_end": "2026-08-05T14:20:32Z",
          "status": "source-content",
          "summary": "Reddit served new comments discussing the distinction between an exploit and deliberate theft, including speculation about a vendor employee, while several earlier comments were omitted from the captured thread surface.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 47,
          "removed_lines": 45
        },
        {
          "observed_at": "2026-08-05T07:52:25Z",
          "window_start": "2026-08-04T17:40:22Z",
          "window_end": "2026-08-05T07:52:25Z",
          "status": "source-content",
          "summary": "Two earlier discussion comments disappeared, including a sceptical reply about the AI framing, and the thread gained two new replies advocating physical entropy and praising the vulnerability-audit example.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 19,
          "removed_lines": 19
        },
        {
          "observed_at": "2026-08-04T17:40:22Z",
          "window_start": "2026-08-04T16:10:19Z",
          "window_end": "2026-08-04T17:40:22Z",
          "status": "source-content",
          "summary": "An existing Reddit comment no longer appeared in the captured thread.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 2,
          "removed_lines": 10
        },
        {
          "observed_at": "2026-08-04T16:10:19Z",
          "window_start": "2026-08-04T14:39:08Z",
          "window_end": "2026-08-04T16:10:19Z",
          "status": "source-content",
          "summary": "The captured reply tree gained a collapsed more-stub indicating two additional replies under an existing comment.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 1,
          "removed_lines": 17
        },
        {
          "observed_at": "2026-08-04T14:39:08Z",
          "window_start": "2026-08-04T14:10:05Z",
          "window_end": "2026-08-04T14:39:08Z",
          "status": "source-content",
          "summary": "An existing comment was deleted: its author and body now appear as “[deleted]”.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 4,
          "removed_lines": 6
        },
        {
          "observed_at": "2026-08-04T14:10:05Z",
          "window_start": "2026-08-04T13:39:13Z",
          "window_end": "2026-08-04T14:10:05Z",
          "status": "source-content",
          "summary": "1 new Reddit comment was posted, including Peking_Meerschaum.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 10,
          "removed_lines": 20
        },
        {
          "observed_at": "2026-08-04T13:39:13Z",
          "window_start": "2026-08-04T07:09:08Z",
          "window_end": "2026-08-04T13:39:13Z",
          "status": "source-content",
          "summary": "3 new Reddit comments were posted, including Crazy__Donkey,No-Newspaper8600,hrad95.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 34,
          "removed_lines": 35
        },
        {
          "observed_at": "2026-08-04T07:09:08Z",
          "window_start": "2026-08-04T03:23:41Z",
          "window_end": "2026-08-04T07:09:08Z",
          "status": "source-content",
          "summary": "Three comments and their subthread (frankster p18ac4g, Level-Set5770 p18bgi4, frankster p18g2ma) disappeared from the thread, three new comments were posted (Either_Display_6624 p1kg6wz, Shepinion p1lcxyy, djscoox p1lmvzg), and the more-stub reply count under t1_p189g94 rose from 4 to 12.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 27,
          "removed_lines": 29
        }
      ]
    },
    {
      "id": "intangiblecoins-wave4-confirmed-pastebin",
      "title": "Original wave-4 confirmed-address Pastebin",
      "url": "https://pastebin.com/6AG9s0pP",
      "organisation": null,
      "kind": "primary-data",
      "role": "Source",
      "publication_time": "2026-08-03T00:38:25Z",
      "note": "The address list linked from the original @intangiblecoins wave-4 thread. Captured from Pastebin's normal public page, which is permitted by its robots.txt; the disallowed /raw/ endpoint is not used.",
      "gone": null,
      "capture": {
        "status": "held",
        "copies": 1,
        "first_observed": "2026-08-06T03:49:53Z",
        "last_observed": "2026-08-06T03:49:53Z",
        "last_checked": "2026-08-06T03:49:53Z"
      },
      "differences": []
    },
    {
      "id": "intangiblecoins-wave4-pending-pastebin",
      "title": "Original wave-4 pending-transaction Pastebin",
      "url": "https://pastebin.com/zR5Wk2cz",
      "organisation": null,
      "kind": "primary-data",
      "role": "Source",
      "publication_time": "2026-08-03T01:01:36Z",
      "note": "The pending-transaction list linked from the original @intangiblecoins wave-4 thread. Captured from Pastebin's normal public page, which is permitted by its robots.txt; the disallowed /raw/ endpoint is not used.",
      "gone": null,
      "capture": {
        "status": "held",
        "copies": 1,
        "first_observed": "2026-08-06T03:49:54Z",
        "last_observed": "2026-08-06T03:49:54Z",
        "last_checked": "2026-08-06T03:49:54Z"
      },
      "differences": []
    },
    {
      "id": "profedustream-mapping-json",
      "title": "profedustream on-chain mapping graph export",
      "url": "https://fromsmash.com/Map-analysis-ColdCard#json-graph",
      "organisation": null,
      "kind": "primary-data",
      "role": "Source",
      "publication_time": "2026-08-02",
      "note": "The 6.44 MB JSON graph file downloaded from the public Smash transfer linked by profedustream's announcement post. The transfer reports that it was created on 2 August 2026 and modified on 3 August. Frozen after acquisition because Smash file-download URLs are short-lived.",
      "gone": null,
      "capture": {
        "status": "held",
        "copies": 1,
        "first_observed": "2026-08-06T03:50:24Z",
        "last_observed": "2026-08-06T03:50:24Z",
        "last_checked": "2026-08-06T03:50:24Z"
      },
      "differences": []
    },
    {
      "id": "profedustream-mapping-prompt",
      "title": "Method prompt accompanying profedustream's mapping export",
      "url": "https://fromsmash.com/Map-analysis-ColdCard#method-prompt",
      "organisation": null,
      "kind": "primary-method",
      "role": "Source",
      "publication_time": "2026-08-02",
      "note": "The Prompt.txt file delivered beside the JSON graph in profedustream's public Smash transfer. It specifies the graph schema and requested viewer behaviour, and is held because it documents how to interpret the export. Frozen after acquisition because Smash file-download URLs are short-lived.",
      "gone": null,
      "capture": {
        "status": "held",
        "copies": 1,
        "first_observed": "2026-08-06T03:50:29Z",
        "last_observed": "2026-08-06T03:50:29Z",
        "last_checked": "2026-08-06T03:50:29Z"
      },
      "differences": []
    },
    {
      "id": "bitkey-relationship-enrollment-report",
      "title": "Relationship-enrollment bug in Bitkey",
      "url": "https://bitkey.world/blog/relationship-enrollment-bug-in-bitkey",
      "organisation": "Block",
      "kind": "vendor-response",
      "role": "Vendor response",
      "publication_time": "2026-08-03",
      "note": "Block's full vendor report on the Bitkey relationship-enrollment bug reported\nby 1440000bytes: enrollment secrets and 2nd-generation action-proof nonces\ncame from kotlin.random.Random, a non-cryptographic generator, so a\ncompromised service observing enough related outputs could predict a later\nSPAKE2 enrollment secret. The report states no evidence of customer impact,\nscopes the practical path to 2nd-generation devices with inheritance or\nrecovery enrollment, and says a mobile-app patch moving the secrets to a\ncryptographically secure RNG was submitted to the app stores the same day.\nVendor statement about its own product; the bug is distinct from the COLDCARD\nRNG flaw, and the patch had not shipped or been independently reviewed at\ncapture.\n",
      "gone": null,
      "capture": {
        "status": "held",
        "copies": 47,
        "first_observed": "2026-08-03T09:20:59Z",
        "last_observed": "2026-08-15T14:23:50Z",
        "last_checked": "2026-08-15T14:23:50Z"
      },
      "differences": [
        {
          "observed_at": "2026-08-15T14:23:50Z",
          "window_start": "2026-08-15T13:23:50Z",
          "window_end": "2026-08-15T14:23:50Z",
          "status": "capture-noise",
          "summary": "The trailing page-title line Relationship-enrollment bug in Bitkey | Bitkey toggled off again; the report body was unchanged.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 0,
          "removed_lines": 1
        },
        {
          "observed_at": "2026-08-15T13:23:50Z",
          "window_start": "2026-08-15T03:23:57Z",
          "window_end": "2026-08-15T13:23:50Z",
          "status": "capture-noise",
          "summary": "The trailing page-title line Relationship-enrollment bug in Bitkey | Bitkey toggled on again at the end of the extracted text; the report body was unchanged.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 1,
          "removed_lines": 0
        },
        {
          "observed_at": "2026-08-15T03:23:57Z",
          "window_start": "2026-08-15T01:24:24Z",
          "window_end": "2026-08-15T03:23:57Z",
          "status": "capture-noise",
          "summary": "The trailing page-title line 'Relationship-enrollment bug in Bitkey | Bitkey' toggled off at the end of the extracted text; the report body was unchanged.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 0,
          "removed_lines": 1
        },
        {
          "observed_at": "2026-08-15T01:24:24Z",
          "window_start": "2026-08-14T23:40:44Z",
          "window_end": "2026-08-15T01:24:24Z",
          "status": "capture-noise",
          "summary": "The trailing page-title line 'Relationship-enrollment bug in Bitkey | Bitkey' toggled on again at the end of the extracted text; the report body was unchanged.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 1,
          "removed_lines": 0
        },
        {
          "observed_at": "2026-08-14T23:40:44Z",
          "window_start": "2026-08-14T14:23:48Z",
          "window_end": "2026-08-14T23:40:44Z",
          "status": "capture-noise",
          "summary": "The trailing page-title line Relationship-enrollment bug in Bitkey | Bitkey toggled off again at the end of the extracted text; the report body was unchanged.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 0,
          "removed_lines": 1
        },
        {
          "observed_at": "2026-08-14T14:23:48Z",
          "window_start": "2026-08-14T13:24:19Z",
          "window_end": "2026-08-14T14:23:48Z",
          "status": "capture-noise",
          "summary": "The trailing page-title line 'Relationship-enrollment bug in Bitkey | Bitkey' toggled on again at the end of the extracted text; the report body was unchanged.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 1,
          "removed_lines": 0
        },
        {
          "observed_at": "2026-08-14T13:24:19Z",
          "window_start": "2026-08-14T12:23:58Z",
          "window_end": "2026-08-14T13:24:19Z",
          "status": "capture-noise",
          "summary": "The trailing page-title line 'Relationship-enrollment bug in Bitkey | Bitkey' toggled off again at the end of the extracted text; the report body was unchanged.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 0,
          "removed_lines": 1
        },
        {
          "observed_at": "2026-08-14T12:23:58Z",
          "window_start": "2026-08-14T11:24:28Z",
          "window_end": "2026-08-14T12:23:58Z",
          "status": "capture-noise",
          "summary": "The trailing page-title line 'Relationship-enrollment bug in Bitkey | Bitkey' toggled on again at the end of the extracted text; the report body was unchanged.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 1,
          "removed_lines": 0
        },
        {
          "observed_at": "2026-08-14T11:24:28Z",
          "window_start": "2026-08-14T10:24:17Z",
          "window_end": "2026-08-14T11:24:28Z",
          "status": "capture-noise",
          "summary": "The trailing page-title line 'Relationship-enrollment bug in Bitkey | Bitkey' toggled off again at the end of the extracted text; the report body was unchanged.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 0,
          "removed_lines": 1
        },
        {
          "observed_at": "2026-08-14T10:24:17Z",
          "window_start": "2026-08-14T06:23:48Z",
          "window_end": "2026-08-14T10:24:17Z",
          "status": "capture-noise",
          "summary": "The trailing page-title line 'Relationship-enrollment bug in Bitkey | Bitkey' toggled on again at the end of the extracted text; the report body was unchanged.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 1,
          "removed_lines": 0
        },
        {
          "observed_at": "2026-08-14T06:23:48Z",
          "window_start": "2026-08-14T05:23:49Z",
          "window_end": "2026-08-14T06:23:48Z",
          "status": "capture-noise",
          "summary": "The captured text no longer includes a trailing copy of the HTML title tag; the article heading and body were unchanged.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 0,
          "removed_lines": 1
        },
        {
          "observed_at": "2026-08-14T05:23:49Z",
          "window_start": "2026-08-13T22:24:37Z",
          "window_end": "2026-08-14T05:23:49Z",
          "status": "source-content",
          "summary": "The page title changed to include a trailing pipe and product name, reading 'Relationship-enrollment bug in Bitkey | Bitkey'.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 1,
          "removed_lines": 0
        },
        {
          "observed_at": "2026-08-13T22:24:37Z",
          "window_start": "2026-08-13T21:24:33Z",
          "window_end": "2026-08-13T22:24:37Z",
          "status": "capture-noise",
          "summary": "The page title tag was no longer extracted at the end of the captured text; the report body was unchanged.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 0,
          "removed_lines": 1
        },
        {
          "observed_at": "2026-08-13T21:24:33Z",
          "window_start": "2026-08-13T20:24:28Z",
          "window_end": "2026-08-13T21:24:33Z",
          "status": "capture-noise",
          "summary": "Only the page title tag was newly extracted at the end of the captured text; the report body was unchanged.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 1,
          "removed_lines": 0
        },
        {
          "observed_at": "2026-08-13T20:24:28Z",
          "window_start": "2026-08-13T18:23:52Z",
          "window_end": "2026-08-13T20:24:28Z",
          "status": "capture-noise",
          "summary": "Only the page title suffix '| Bitkey' was removed; the report text was unchanged.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 0,
          "removed_lines": 1
        },
        {
          "observed_at": "2026-08-13T18:23:52Z",
          "window_start": "2026-08-13T17:24:38Z",
          "window_end": "2026-08-13T18:23:52Z",
          "status": "capture-noise",
          "summary": "The trailing 'Relationship-enrollment bug in Bitkey | Bitkey' page-title line toggled on again after the footer, and the article body was unchanged.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 1,
          "removed_lines": 0
        },
        {
          "observed_at": "2026-08-13T17:24:38Z",
          "window_start": "2026-08-13T16:23:57Z",
          "window_end": "2026-08-13T17:24:38Z",
          "status": "capture-noise",
          "summary": "The trailing 'Relationship-enrollment bug in Bitkey | Bitkey' page-title line toggled off again after the footer, and the article body was unchanged.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 0,
          "removed_lines": 1
        },
        {
          "observed_at": "2026-08-13T16:23:57Z",
          "window_start": "2026-08-13T14:23:47Z",
          "window_end": "2026-08-13T16:23:57Z",
          "status": "source-content",
          "summary": "Block's report now displays the title line \"Relationship-enrollment bug in Bitkey | Bitkey\" after the page header, where the previous capture showed no title.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 1,
          "removed_lines": 0
        },
        {
          "observed_at": "2026-08-13T14:23:47Z",
          "window_start": "2026-08-13T12:23:48Z",
          "window_end": "2026-08-13T14:23:47Z",
          "status": "capture-noise",
          "summary": "The trailing 'Relationship-enrollment bug in Bitkey | Bitkey' page-title line toggled off again after the footer, and the article body was unchanged.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 0,
          "removed_lines": 1
        },
        {
          "observed_at": "2026-08-13T12:23:48Z",
          "window_start": "2026-08-13T11:23:51Z",
          "window_end": "2026-08-13T12:23:48Z",
          "status": "capture-noise",
          "summary": "The trailing page-title line with the site-name suffix reappeared in the extracted text after the footer, continuing the earlier capture-noise pattern; the article body was unchanged.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 1,
          "removed_lines": 0
        },
        {
          "observed_at": "2026-08-13T11:23:51Z",
          "window_start": "2026-08-13T10:24:28Z",
          "window_end": "2026-08-13T11:23:51Z",
          "status": "capture-noise",
          "summary": "The trailing page-title line with the site-name suffix disappeared from the extracted text again, repeating the earlier capture-noise pattern; the article body was unchanged.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 0,
          "removed_lines": 1
        },
        {
          "observed_at": "2026-08-13T10:24:28Z",
          "window_start": "2026-08-13T08:53:47Z",
          "window_end": "2026-08-13T10:24:28Z",
          "status": "capture-noise",
          "summary": "The trailing page-title line with the site-name suffix reappeared in the extracted text; the article body was unchanged.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 1,
          "removed_lines": 0
        },
        {
          "observed_at": "2026-08-13T08:53:47Z",
          "window_start": "2026-08-13T07:53:48Z",
          "window_end": "2026-08-13T08:53:47Z",
          "status": "capture-noise",
          "summary": "Only the trailing page-title line with the site-name suffix disappeared from the extracted text; the article body was unchanged.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 0,
          "removed_lines": 1
        },
        {
          "observed_at": "2026-08-13T07:53:48Z",
          "window_start": "2026-08-13T04:24:00Z",
          "window_end": "2026-08-13T07:53:48Z",
          "status": "source-content",
          "summary": "The rendered report title now reads 'Relationship-enrollment bug in Bitkey | Bitkey'.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 1,
          "removed_lines": 0
        },
        {
          "observed_at": "2026-08-13T04:24:00Z",
          "window_start": "2026-08-13T02:23:50Z",
          "window_end": "2026-08-13T04:24:00Z",
          "status": "capture-noise",
          "summary": "The trailing page-title line Relationship-enrollment bug in Bitkey | Bitkey toggled off again after the footer, mirroring the preceding capture's toggle-on; the article body was unchanged.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 0,
          "removed_lines": 1
        },
        {
          "observed_at": "2026-08-13T02:23:50Z",
          "window_start": "2026-08-13T01:23:45Z",
          "window_end": "2026-08-13T02:23:50Z",
          "status": "capture-noise",
          "summary": "The trailing page-title line Relationship-enrollment bug in Bitkey | Bitkey toggled on again after the footer, and the article body was unchanged.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 1,
          "removed_lines": 0
        },
        {
          "observed_at": "2026-08-13T01:23:45Z",
          "window_start": "2026-08-13T00:23:56Z",
          "window_end": "2026-08-13T01:23:45Z",
          "status": "capture-noise",
          "summary": "The trailing 'Relationship-enrollment bug in Bitkey | Bitkey' title line toggled off again after the footer; the article body was unchanged.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 0,
          "removed_lines": 1
        },
        {
          "observed_at": "2026-08-13T00:23:56Z",
          "window_start": "2026-08-12T23:24:41Z",
          "window_end": "2026-08-13T00:23:56Z",
          "status": "capture-noise",
          "summary": "The trailing 'Relationship-enrollment bug in Bitkey | Bitkey' title line toggled on again after the footer; the article body was unchanged.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 1,
          "removed_lines": 0
        },
        {
          "observed_at": "2026-08-12T23:24:41Z",
          "window_start": "2026-08-12T22:24:27Z",
          "window_end": "2026-08-12T23:24:41Z",
          "status": "capture-noise",
          "summary": "Only the trailing page-title line with the site-name suffix disappeared from the extracted text; the article body was unchanged.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 0,
          "removed_lines": 1
        },
        {
          "observed_at": "2026-08-12T22:24:27Z",
          "window_start": "2026-08-12T21:24:27Z",
          "window_end": "2026-08-12T22:24:27Z",
          "status": "source-content",
          "summary": "The page title line 'Relationship-enrollment bug in Bitkey | Bitkey' reappeared after being removed in the preceding capture.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 1,
          "removed_lines": 0
        },
        {
          "observed_at": "2026-08-12T21:24:27Z",
          "window_start": "2026-08-12T20:24:16Z",
          "window_end": "2026-08-12T21:24:27Z",
          "status": "source-content",
          "summary": "The source removed the 'Relationship-enrollment bug in Bitkey | Bitkey' title line that the preceding capture had added.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 0,
          "removed_lines": 1
        },
        {
          "observed_at": "2026-08-12T20:24:16Z",
          "window_start": "2026-08-12T17:24:24Z",
          "window_end": "2026-08-12T20:24:16Z",
          "status": "source-content",
          "summary": "The page title or heading changed to include the source's own title, 'Relationship-enrollment bug in Bitkey | Bitkey', replacing the previous wording.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 1,
          "removed_lines": 0
        },
        {
          "observed_at": "2026-08-12T17:24:24Z",
          "window_start": "2026-08-12T16:24:38Z",
          "window_end": "2026-08-12T17:24:24Z",
          "status": "capture-noise",
          "summary": "The page title or header line that appeared in the preceding capture is absent again; no report body text changed, so this is extraction variance.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 0,
          "removed_lines": 1
        },
        {
          "observed_at": "2026-08-12T16:24:38Z",
          "window_start": "2026-08-12T06:06:47Z",
          "window_end": "2026-08-12T16:24:38Z",
          "status": "source-content",
          "summary": "The page title or header now reads 'Relationship-enrollment bug in Bitkey | Bitkey', which was not present in the previous extracted text.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 1,
          "removed_lines": 0
        },
        {
          "observed_at": "2026-08-12T06:06:47Z",
          "window_start": "2026-08-12T04:06:30Z",
          "window_end": "2026-08-12T06:06:47Z",
          "status": "source-content",
          "summary": "The page title was removed or changed by the publisher.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 0,
          "removed_lines": 1
        },
        {
          "observed_at": "2026-08-12T04:06:30Z",
          "window_start": "2026-08-08T12:54:25Z",
          "window_end": "2026-08-12T04:06:30Z",
          "status": "capture-noise",
          "summary": "The page title gained a site-name suffix again; no report body text changed.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 1,
          "removed_lines": 0
        },
        {
          "observed_at": "2026-08-08T12:54:25Z",
          "window_start": "2026-08-08T11:54:20Z",
          "window_end": "2026-08-08T12:54:25Z",
          "status": "capture-noise",
          "summary": "The page title lost its site-name suffix; no report body text changed.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 0,
          "removed_lines": 1
        },
        {
          "observed_at": "2026-08-08T11:54:20Z",
          "window_start": "2026-08-07T12:20:12Z",
          "window_end": "2026-08-08T11:54:20Z",
          "status": "capture-noise",
          "summary": "The page title gained a site-name suffix; no report body text changed.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 1,
          "removed_lines": 0
        },
        {
          "observed_at": "2026-08-07T12:20:12Z",
          "window_start": "2026-08-07T11:19:59Z",
          "window_end": "2026-08-07T12:20:12Z",
          "status": "capture-noise",
          "summary": "Rendering artifact: the stray page title line added in the previous capture disappeared again; the article body is unchanged.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 0,
          "removed_lines": 1
        },
        {
          "observed_at": "2026-08-07T11:19:59Z",
          "window_start": "2026-08-05T19:51:35Z",
          "window_end": "2026-08-07T11:19:59Z",
          "status": "capture-noise",
          "summary": "Rendering artifact: the page title line \"Relationship-enrollment bug in Bitkey | Bitkey\" appeared at the end of the extracted text after the cart chrome; the article body is unchanged.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 1,
          "removed_lines": 0
        },
        {
          "observed_at": "2026-08-05T19:51:35Z",
          "window_start": "2026-08-05T18:51:19Z",
          "window_end": "2026-08-05T19:51:35Z",
          "status": "capture-noise",
          "summary": "The transient document-title line was no longer included by the extractor. No vendor-report content changed.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 0,
          "removed_lines": 1
        },
        {
          "observed_at": "2026-08-05T18:51:19Z",
          "window_start": "2026-08-05T04:48:22Z",
          "window_end": "2026-08-05T18:51:19Z",
          "status": "capture-noise",
          "summary": "The extractor temporarily included the document title. No vendor-report content changed.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 1,
          "removed_lines": 0
        },
        {
          "observed_at": "2026-08-05T04:48:22Z",
          "window_start": "2026-08-05T03:17:36Z",
          "window_end": "2026-08-05T04:48:22Z",
          "status": "capture-noise",
          "summary": "The page-title chrome line ('Relationship-enrollment bug in Bitkey | Bitkey') disappeared from the extracted text again. The vendor report body was unchanged.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 0,
          "removed_lines": 1
        },
        {
          "observed_at": "2026-08-05T03:17:36Z",
          "window_start": "2026-08-04T11:06:41Z",
          "window_end": "2026-08-05T03:17:36Z",
          "status": "capture-noise",
          "summary": "The page-title chrome line ('Relationship-enrollment bug in Bitkey | Bitkey') reappeared in the extracted text. The vendor report body was unchanged.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 1,
          "removed_lines": 0
        },
        {
          "observed_at": "2026-08-04T11:06:41Z",
          "window_start": "2026-08-04T10:36:29Z",
          "window_end": "2026-08-04T11:06:41Z",
          "status": "capture-noise",
          "summary": "The page-title chrome line ('Relationship-enrollment bug in Bitkey | Bitkey') that had newly appeared after the cart footer in the previous capture disappeared again. The report body was unchanged.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 0,
          "removed_lines": 1
        },
        {
          "observed_at": "2026-08-04T10:36:29Z",
          "window_start": "2026-08-03T09:20:59Z",
          "window_end": "2026-08-04T10:36:29Z",
          "status": "capture-noise",
          "summary": "Only the page title chrome ('Relationship-enrollment bug in Bitkey | Bitkey') newly appeared appended at the end of the extracted text after the cart footer. The report body was unchanged.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 1,
          "removed_lines": 0
        }
      ]
    },
    {
      "id": "karmax-post-hotfix-disclosure",
      "title": "Post-hotfix full disclosure and 39 unpatched findings",
      "url": "https://karma-x.io/blog/post/75/",
      "organisation": "Karma-X",
      "kind": "independent-technical-analysis",
      "role": "Independent technical analysis",
      "publication_time": "2026-08-02",
      "note": "Primary source behind the VULN-109 prior-discovery claim. States that a September 2025 private audit flagged the single-source RNG class (SE TRNG disabled at the source, ae.c:666) and was never submitted after an earlier report (VULN-023) got a same-day fix but no CVE or advisory. Cross-checks the audit against v5.6.0 and claims 39 findings remain unfixed, plus two new ones (Delta-mode message-signing gap, kleptography channel via R-value grinding), with full detail said to be delivered to Coinkite in parallel with publication. The September 2025 audit itself is not public, so the prior-discovery claim rests on the author's account.\n",
      "gone": null,
      "capture": {
        "status": "held",
        "copies": 3,
        "first_observed": "2026-08-04T01:14:17Z",
        "last_observed": "2026-08-06T09:55:57Z",
        "last_checked": "2026-08-15T12:26:32Z"
      },
      "differences": [
        {
          "observed_at": "2026-08-06T09:55:57Z",
          "window_start": "2026-08-05T14:20:39Z",
          "window_end": "2026-08-06T09:55:57Z",
          "status": "source-content",
          "summary": "Post edited: the Mk3 action item gained an UPDATE noting Coinkite has issued firmware 4.2.0 for Mk2 and Mk3 after previously saying the line would receive no further updates.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 1,
          "removed_lines": 1
        },
        {
          "observed_at": "2026-08-05T14:20:39Z",
          "window_start": "2026-08-04T01:14:17Z",
          "window_end": "2026-08-05T14:20:39Z",
          "status": "source-content",
          "summary": "The author revised their account of why the prior finding was not submitted, adding that it had not been fully analysed and replacing an explicit retrospective admission with a statement that they lost interest in unpaid, unacknowledged research.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 2,
          "removed_lines": 2
        }
      ]
    },
    {
      "id": "nvkwtf-articles",
      "title": "nvk.wtf articles index",
      "url": "https://nvk.wtf/articles",
      "organisation": "nvk.wtf",
      "kind": "aggregator",
      "role": "Aggregator",
      "publication_time": null,
      "note": "Index of third-party reporting and research on the incident, each entry linked\nout to its source. The site is an aggregator run alongside promotion of\ncompeting open-source hardware (SeedSigner, BTClock, Passport) and takes an\nopenly critical stance toward NVK and Coinkite, so its selection and summaries\nare editorial and interested; the operator is not named on the site. Tracked\nfor what it chooses to include and when, and as a discovery feed: anything it\nsurfaces is followed to the primary and registered there, never cited from\nthis copy. SPA with no feed or API; every path serves the app shell, so\ncapture goes through the browser.\n",
      "gone": null,
      "capture": {
        "status": "held",
        "copies": 4,
        "first_observed": "2026-08-04T03:28:09Z",
        "last_observed": "2026-08-12T05:10:36Z",
        "last_checked": "2026-08-15T12:55:40Z"
      },
      "differences": [
        {
          "observed_at": "2026-08-12T05:10:36Z",
          "window_start": "2026-08-04T23:27:39Z",
          "window_end": "2026-08-12T05:10:36Z",
          "status": "source-content",
          "summary": "The articles index added a seventh entry, a Wizardsardine technical autopsy by Loic Morel dated August 11, 2026.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 12,
          "removed_lines": 1
        },
        {
          "observed_at": "2026-08-04T23:27:39Z",
          "window_start": "2026-08-04T22:51:52Z",
          "window_end": "2026-08-04T23:27:39Z",
          "status": "capture-noise",
          "summary": "The article-index controls reordered and displayed its article count; the listed articles were unchanged.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 5,
          "removed_lines": 2
        },
        {
          "observed_at": "2026-08-04T22:51:52Z",
          "window_start": "2026-08-04T03:28:09Z",
          "window_end": "2026-08-04T22:51:52Z",
          "status": "capture-noise",
          "summary": "The article-index filter controls rendered in this capture; the listed articles were unchanged.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 3,
          "removed_lines": 0
        }
      ]
    },
    {
      "id": "nvkwtf-receipts",
      "title": "nvk.wtf receipts index",
      "url": "https://nvk.wtf/receipts",
      "organisation": "nvk.wtf",
      "kind": "aggregator",
      "role": "Aggregator",
      "publication_time": null,
      "note": "Screenshots of NVK posts, some already deleted, kept with dates and, where one\nexists, a link to an independent archive; solicits further screenshots via the\n#wtfnvk hashtag. Same operator and stance caveats as nvkwtf-articles. The\nscreenshots are third-hand material: anything that matters here is captured\nfrom the original post or the independent archive it links before it backs a\nclaim.\n",
      "gone": null,
      "capture": {
        "status": "held",
        "copies": 3,
        "first_observed": "2026-08-04T03:28:16Z",
        "last_observed": "2026-08-07T14:23:55Z",
        "last_checked": "2026-08-15T12:55:49Z"
      },
      "differences": [
        {
          "observed_at": "2026-08-07T14:23:55Z",
          "window_start": "2026-08-06T04:00:31Z",
          "window_end": "2026-08-07T14:23:55Z",
          "status": "source-content",
          "summary": "The receipts index grew from 13 to 14, adding a screenshot of an August 2023 exchange in which thorie argued a user cannot practically verify the absence of a backdoor in a hardware wallet and NVK replied by repeating the phrase in alternating capitals.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 6,
          "removed_lines": 1
        },
        {
          "observed_at": "2026-08-06T04:00:31Z",
          "window_start": "2026-08-04T03:28:16Z",
          "window_end": "2026-08-06T04:00:31Z",
          "status": "source-content",
          "summary": "The operator widened the page from NVK's own posts to what the Coldcard side published or endorsed, including the COLDCARD account, Coinkite staff and NVK's reposts, added sort and year filters and a receipt count, and grew the index from 7 screenshots to 13. The gap since 4 Aug is this collector's: a stale required_text marker blocked 36 consecutive polls, so intermediate states of this page were never captured and this diff spans the whole rewrite.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 71,
          "removed_lines": 17
        }
      ]
    },
    {
      "id": "nvkwtf-reactions",
      "title": "nvk.wtf reactions index",
      "url": "https://nvk.wtf/reactions",
      "organisation": "nvk.wtf",
      "kind": "aggregator",
      "role": "Aggregator",
      "publication_time": null,
      "note": "Full quotes of other people's public posts about the vulnerability, each\nlinked to the original. Same operator and stance caveats as nvkwtf-articles.\nTreated as a discovery feed only: quoted material is registered and captured\nat its source. Circularity watch: should it ever quote cc-vuln.org material,\nthat is this archive reflected back, not independent corroboration.\n",
      "gone": null,
      "capture": {
        "status": "held",
        "copies": 4,
        "first_observed": "2026-08-04T03:28:24Z",
        "last_observed": "2026-08-04T23:29:29Z",
        "last_checked": "2026-08-15T12:56:00Z"
      },
      "differences": [
        {
          "observed_at": "2026-08-04T23:29:29Z",
          "window_start": "2026-08-04T22:53:41Z",
          "window_end": "2026-08-04T23:29:29Z",
          "status": "capture-noise",
          "summary": "The reactions index displayed its count; the listed reactions were unchanged.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 3,
          "removed_lines": 0
        },
        {
          "observed_at": "2026-08-04T22:53:41Z",
          "window_start": "2026-08-04T10:10:47Z",
          "window_end": "2026-08-04T22:53:41Z",
          "status": "capture-noise",
          "summary": "The reactions-index sort controls rendered in this capture; the listed reactions were unchanged.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 2,
          "removed_lines": 0
        },
        {
          "observed_at": "2026-08-04T10:10:47Z",
          "window_start": "2026-08-04T03:28:24Z",
          "window_end": "2026-08-04T10:10:47Z",
          "status": "source-content",
          "summary": "The page added a new entry quoting Leo Wandersleb's August 2021 X thread asking where the Coldcard Mk3 gets its entropy (concluding the default is the secure-element TRNG alone), with an editorial note and links to the Coldcard FAQ and the WalletScrutiny Mk3 review.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 24,
          "removed_lines": 0
        }
      ]
    },
    {
      "id": "stackernews-galaxy-updated-total",
      "title": "Galaxy's updated accounting: 1,596 BTC from ~7,300 addresses",
      "url": "https://stacker.news/items/1539646",
      "organisation": "Stacker News",
      "kind": "reporting",
      "role": "Reporting",
      "publication_time": "2026-08-04",
      "note": "Stacker News thread by Scoresby reproducing Galaxy Digital's updated\nflow-of-funds accounting: high-confidence 1,596 BTC stolen from about 7,300\naddresses across three confirmed waves plus 14 smaller incidents, with a\nsuspected-but-unconfirmed total near 2,000 BTC, and Wave 4 unconfirmed by any\nvictim at posting time. A relay of Galaxy's own update, succeeding the 1,082.65\nBTC figure in glxyresearch-flow-map; the numbers are Galaxy's, not this\narchive's.\n",
      "gone": null,
      "capture": {
        "status": "held",
        "copies": 1,
        "first_observed": "2026-08-04T03:29:30Z",
        "last_observed": "2026-08-04T03:29:30Z",
        "last_checked": "2026-08-15T12:26:35Z"
      },
      "differences": []
    },
    {
      "id": "reddit-ledgerwallet-drain-comment",
      "title": "r/ledgerwallet seed-entropy thread carrying the 2022 drain claim",
      "url": "https://www.reddit.com/r/ledgerwallet/comments/167bgjr/comment/kumtghc/",
      "organisation": "r/ledgerwallet",
      "kind": "victim-account",
      "role": "First-hand account",
      "publication_time": "2024-03-13",
      "note": "Primary behind the claimed years-old drain report that circulated as\nscreenshots after the July 2026 disclosure (zenulabidin-drain-report-screenshot,\nbtctherapist-prior-drain-report). Economy-Cash6726's two-year-old comment in an\nr/ledgerwallet seed-entropy thread claims a Coldcard Mk4 was drained after\ngenerating a 12-word seed without dice rolls; resurfaced after the disclosure,\nthe author dates the drain to 2022 and claims the vendor blocked them when they\nreported it. The thread's own replies contest the account: the author is quoted\ndescribing a Python script used to produce dice rolls, which contradicts \"no\ndice rolls\". First-hand claim, disputed in place, not verified here. Surfaced\nvia the nvk.wtf reactions index (nvkwtf-reactions).\n",
      "gone": null,
      "capture": {
        "status": "held",
        "copies": 1,
        "first_observed": "2026-08-04T03:45:54Z",
        "last_observed": "2026-08-04T03:45:54Z",
        "last_checked": "2026-08-15T12:26:38Z"
      },
      "differences": []
    },
    {
      "id": "stackernews-first-drain-report",
      "title": "User reports their coldcard wallet being drained on Reddit",
      "url": "https://stacker.news/items/1536238",
      "organisation": "Stacker News",
      "kind": "community-discussion",
      "role": "Community discussion",
      "publication_time": "2026-07-30",
      "note": "The earliest incident thread identified on Stacker News: Murch relaying the first Reddit drain report while the recipient address was still collecting, the evening before Coinkite's disclosure. The drain claims quoted are the Reddit posters', unverified here; the thread's value is that it fixes when the incident first surfaced publicly and how the community read it in real time. Captured through the site's public GraphQL API: the rendered pages crash the capture tab, and the API answers POST from this host. The query fixes the captured surface to the item's title, text and two levels of comments, each with author and absolute timestamp.\n",
      "gone": null,
      "capture": {
        "status": "held",
        "copies": 7,
        "first_observed": "2026-08-04T04:14:54Z",
        "last_observed": "2026-08-06T09:56:09Z",
        "last_checked": "2026-08-09T23:17:36Z"
      },
      "differences": [
        {
          "observed_at": "2026-08-06T09:56:09Z",
          "window_start": "2026-08-06T03:24:51Z",
          "window_end": "2026-08-06T09:56:09Z",
          "status": "capture-noise",
          "summary": "Comment ordering churn only: the same set of comments (Murch, Scoresby, satonymous, didiplaywell, 028559d218 and others) appears in a different order with no new or changed text.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 60,
          "removed_lines": 60
        },
        {
          "observed_at": "2026-08-06T03:24:51Z",
          "window_start": "2026-08-05T20:55:44Z",
          "window_end": "2026-08-06T03:24:51Z",
          "status": "source-content",
          "summary": "The thread added Murch's updated situation summary, including expanded device, entropy and passphrase assertions, alongside later community replies.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 84,
          "removed_lines": 70
        },
        {
          "observed_at": "2026-08-05T20:55:44Z",
          "window_start": "2026-08-05T14:20:51Z",
          "window_end": "2026-08-05T20:55:44Z",
          "status": "capture-noise",
          "summary": "The GraphQL response reordered already captured comments, including the existing advisory summary and timeline links. No comment text changed.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 28,
          "removed_lines": 28
        },
        {
          "observed_at": "2026-08-05T14:20:51Z",
          "window_start": "2026-08-05T00:42:18Z",
          "window_end": "2026-08-05T14:20:51Z",
          "status": "source-content",
          "summary": "The thread gained a comment offering to connect someone with a purported drainer developer to review the tool and improve the wallet's defences.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 7,
          "removed_lines": 0
        },
        {
          "observed_at": "2026-08-05T00:42:18Z",
          "window_start": "2026-08-05T00:12:11Z",
          "window_end": "2026-08-05T00:42:18Z",
          "status": "source-content",
          "summary": "The Stacker News thread gained a new participant reply.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 7,
          "removed_lines": 0
        },
        {
          "observed_at": "2026-08-05T00:12:11Z",
          "window_start": "2026-08-04T04:14:54Z",
          "window_end": "2026-08-05T00:12:11Z",
          "status": "source-content",
          "summary": "The Stacker News thread gained a reply thanking Murch for the timely emergency post.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 7,
          "removed_lines": 0
        }
      ]
    },
    {
      "id": "stackernews-rng-analysis-by-device",
      "title": "Coldcard RNG Vulnerability Analysis by Device & Firmware",
      "url": "https://stacker.news/items/1536654",
      "organisation": "Stacker News",
      "kind": "community-discussion",
      "role": "Community discussion",
      "publication_time": "2026-07-31",
      "note": "itsrealfake's device-and-firmware breakdown of which COLDCARD models and firmware ranges carried the RNG defect. The post body is a single image, which this text-only capture does not hold; the comment discussion is captured. The analysis is the author's, not verified here. Captured through the site's public GraphQL API: the rendered pages crash the capture tab, and the API answers POST from this host. The query fixes the captured surface to the item's title, text and two levels of comments, each with author and absolute timestamp.\n",
      "gone": null,
      "capture": {
        "status": "held",
        "copies": 2,
        "first_observed": "2026-08-04T04:14:58Z",
        "last_observed": "2026-08-08T01:54:42Z",
        "last_checked": "2026-08-09T23:17:38Z"
      },
      "differences": [
        {
          "observed_at": "2026-08-08T01:54:42Z",
          "window_start": "2026-08-04T04:14:58Z",
          "window_end": "2026-08-08T01:54:42Z",
          "status": "capture-noise",
          "summary": "Only the JSON ordering of existing comments changed; their text and timestamps were unchanged.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 7,
          "removed_lines": 7
        }
      ]
    },
    {
      "id": "stackernews-dice-roll-sound",
      "title": "keep your f*ing coins off the exchange: dice-roll seed generation is sound",
      "url": "https://stacker.news/items/1536709",
      "organisation": "Stacker News",
      "kind": "community-discussion",
      "role": "Community discussion",
      "publication_time": "2026-07-31",
      "note": "itsrealfake arguing that dice-roll seed generation was safe from the RNG bug and urging owners not to retreat to exchanges. Bears on the dice and mitigations pages; the safety claim is the author's reasoning, contested in the thread's own replies, and not verified here. Captured through the site's public GraphQL API: the rendered pages crash the capture tab, and the API answers POST from this host. The query fixes the captured surface to the item's title, text and two levels of comments, each with author and absolute timestamp.\n",
      "gone": null,
      "capture": {
        "status": "held",
        "copies": 1,
        "first_observed": "2026-08-04T04:15:01Z",
        "last_observed": "2026-08-04T04:15:01Z",
        "last_checked": "2026-08-09T23:17:41Z"
      },
      "differences": []
    },
    {
      "id": "stackernews-firmware-vulnerability-announcement",
      "title": "Coldcard Mk2, Mk3, Mk4, Mk5, and Q Firmware Security Vulnerability",
      "url": "https://stacker.news/items/1536720",
      "organisation": "Stacker News",
      "kind": "community-discussion",
      "role": "Community discussion",
      "publication_time": "2026-07-31",
      "note": "Stacker News co-founder k00b relaying the vulnerability announcement, citing Block's report for the affected model and firmware ranges. The main announcement thread on the site and a principal venue for owner questions on day one. Captured through the site's public GraphQL API: the rendered pages crash the capture tab, and the API answers POST from this host. The query fixes the captured surface to the item's title, text and two levels of comments, each with author and absolute timestamp.\n",
      "gone": null,
      "capture": {
        "status": "held",
        "copies": 1,
        "first_observed": "2026-08-04T04:15:04Z",
        "last_observed": "2026-08-04T04:15:04Z",
        "last_checked": "2026-08-09T23:17:44Z"
      },
      "differences": []
    },
    {
      "id": "stackernews-entropy-technical-deep-dive",
      "title": "Technical Deep Dive into the Entropy Issue",
      "url": "https://stacker.news/items/1536739",
      "organisation": "Stacker News",
      "kind": "community-discussion",
      "role": "Community discussion",
      "publication_time": "2026-07-31",
      "note": "itsrealfake's technical walkthrough of the entropy failure, stressing that a firmware update does not repair an already-generated weak seed. The technical claims are the author's; where they overlap the vendor and Block accounts those primaries are registered separately. Captured through the site's public GraphQL API: the rendered pages crash the capture tab, and the API answers POST from this host. The query fixes the captured surface to the item's title, text and two levels of comments, each with author and absolute timestamp.\n",
      "gone": null,
      "capture": {
        "status": "held",
        "copies": 1,
        "first_observed": "2026-08-04T04:15:07Z",
        "last_observed": "2026-08-04T04:15:07Z",
        "last_checked": "2026-08-09T23:17:46Z"
      },
      "differences": []
    },
    {
      "id": "stackernews-airgap-hot-take",
      "title": "Hot take: The airgap didn't save Coldcard. A USB cable might have",
      "url": "https://stacker.news/items/1536826",
      "organisation": "Stacker News",
      "kind": "community-discussion",
      "role": "Community discussion",
      "publication_time": "2026-07-31",
      "note": "sime arguing that airgapping protects against exfiltration, not against generating a bad seed, so a connected wallet mixing host entropy could have fared better. A design-philosophy dispute relevant to the mitigations pages; the claim is the author's and contested. Captured through the site's public GraphQL API: the rendered pages crash the capture tab, and the API answers POST from this host. The query fixes the captured surface to the item's title, text and two levels of comments, each with author and absolute timestamp.\n",
      "gone": null,
      "capture": {
        "status": "held",
        "copies": 1,
        "first_observed": "2026-08-04T04:15:10Z",
        "last_observed": "2026-08-04T04:15:10Z",
        "last_checked": "2026-08-07T00:04:37Z"
      },
      "differences": []
    },
    {
      "id": "stackernews-spouse-response",
      "title": "What is your spouse's response to the ColdCard entropy vulnerability?",
      "url": "https://stacker.news/items/1536864",
      "organisation": "Stacker News",
      "kind": "community-discussion",
      "role": "Community discussion",
      "publication_time": "2026-07-31",
      "note": "Scoresby asking how owners' spouses responded to the vulnerability. Community colour on how the incident landed inside households; part of the response record. Captured through the site's public GraphQL API: the rendered pages crash the capture tab, and the API answers POST from this host. The query fixes the captured surface to the item's title, text and two levels of comments, each with author and absolute timestamp.\n",
      "gone": null,
      "capture": {
        "status": "held",
        "copies": 2,
        "first_observed": "2026-08-04T04:15:13Z",
        "last_observed": "2026-08-04T10:10:59Z",
        "last_checked": "2026-08-07T00:04:40Z"
      },
      "differences": [
        {
          "observed_at": "2026-08-04T10:10:59Z",
          "window_start": "2026-08-04T04:15:13Z",
          "window_end": "2026-08-04T10:10:59Z",
          "status": "capture-noise",
          "summary": "Only comment ordering changed in the API response: billytheked's comment moved from below didiplaywell's to the top of the list. No comment text was added, edited or removed; this is ranking-order churn.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 7,
          "removed_lines": 7
        }
      ]
    },
    {
      "id": "stackernews-optech-416-thread",
      "title": "COLDCARD, CLN disclosures, zk proof of reserves - Bitcoin Optech Newsletter #416",
      "url": "https://stacker.news/items/1536932",
      "organisation": "Stacker News",
      "kind": "community-discussion",
      "role": "Community discussion",
      "publication_time": "2026-07-31",
      "note": "schmidty linking Bitcoin Optech newsletter #416, which warned about the COLDCARD vulnerability. The newsletter itself is registered as optech-416; this source holds the Stacker News discussion of it. Captured through the site's public GraphQL API: the rendered pages crash the capture tab, and the API answers POST from this host. The query fixes the captured surface to the item's title, text and two levels of comments, each with author and absolute timestamp.\n",
      "gone": null,
      "capture": {
        "status": "held",
        "copies": 1,
        "first_observed": "2026-08-04T04:15:16Z",
        "last_observed": "2026-08-04T04:15:16Z",
        "last_checked": "2026-08-07T00:04:42Z"
      },
      "differences": []
    },
    {
      "id": "stackernews-mempool-fees-prediction",
      "title": "Will MemPool fees be significantly higher today because of the ColdCard issue?",
      "url": "https://stacker.news/items/1536955",
      "organisation": "Stacker News",
      "kind": "community-discussion",
      "role": "Community discussion",
      "publication_time": "2026-07-31",
      "note": "Wumbo asking whether emergency sweeps to new wallets would move mempool fees on day one. Small thread, held because fee impact is part of the incident's measurable fallout and Galaxy's fee analysis is registered elsewhere. Captured through the site's public GraphQL API: the rendered pages crash the capture tab, and the API answers POST from this host. The query fixes the captured surface to the item's title, text and two levels of comments, each with author and absolute timestamp.\n",
      "gone": null,
      "capture": {
        "status": "held",
        "copies": 1,
        "first_observed": "2026-08-04T04:15:19Z",
        "last_observed": "2026-08-04T04:15:19Z",
        "last_checked": "2026-08-07T00:04:45Z"
      },
      "differences": []
    },
    {
      "id": "stackernews-crowdsource-short-guide",
      "title": "Let's crowdsource a very short guide for people who used Coldcards",
      "url": "https://stacker.news/items/1536996",
      "organisation": "Stacker News",
      "kind": "community-discussion",
      "role": "Community discussion",
      "publication_time": "2026-07-31",
      "note": "Scoresby crowdsourcing a short migration guide for COLDCARD owners, with the author warning he would delete it if stackers found serious flaws. Community guidance drafted in public on day one; individual steps are contested in the replies and not endorsed here. Captured through the site's public GraphQL API: the rendered pages crash the capture tab, and the API answers POST from this host. The query fixes the captured surface to the item's title, text and two levels of comments, each with author and absolute timestamp.\n",
      "gone": null,
      "capture": {
        "status": "held",
        "copies": 1,
        "first_observed": "2026-08-04T04:15:23Z",
        "last_observed": "2026-08-04T04:15:23Z",
        "last_checked": "2026-08-09T23:17:49Z"
      },
      "differences": []
    },
    {
      "id": "stackernews-pleb-economist-13",
      "title": "Pleb Economist #13: ColdCard and the Law of Large Numbers",
      "url": "https://stacker.news/items/1537022",
      "organisation": "Stacker News",
      "kind": "community-discussion",
      "role": "Community discussion",
      "publication_time": "2026-07-31",
      "note": "SimpleStacker's Pleb Economist column on the incident and the law of large numbers: with enough users, rare weak-entropy events become certainties. Opinion, attributed to the author. Captured through the site's public GraphQL API: the rendered pages crash the capture tab, and the API answers POST from this host. The query fixes the captured surface to the item's title, text and two levels of comments, each with author and absolute timestamp.\n",
      "gone": null,
      "capture": {
        "status": "held",
        "copies": 1,
        "first_observed": "2026-08-04T04:15:26Z",
        "last_observed": "2026-08-04T04:15:26Z",
        "last_checked": "2026-08-07T00:04:48Z"
      },
      "differences": []
    },
    {
      "id": "stackernews-self-custody-scale",
      "title": "Can self custody actually scale",
      "url": "https://stacker.news/items/1537107",
      "organisation": "Stacker News",
      "kind": "community-discussion",
      "role": "Community discussion",
      "publication_time": "2026-07-31",
      "note": "HardMoney asking whether self custody can scale to the masses when seasoned users doing most things right were still exposed. Part of the self-custody-tractability debate the incident reopened. Captured through the site's public GraphQL API: the rendered pages crash the capture tab, and the API answers POST from this host. The query fixes the captured surface to the item's title, text and two levels of comments, each with author and absolute timestamp.\n",
      "gone": null,
      "capture": {
        "status": "held",
        "copies": 1,
        "first_observed": "2026-08-04T04:15:30Z",
        "last_observed": "2026-08-04T04:15:30Z",
        "last_checked": "2026-08-07T00:04:51Z"
      },
      "differences": []
    },
    {
      "id": "stackernews-nvk-statement",
      "title": "To all Coinkite users and the entire Bitcoin community - NVK",
      "url": "https://stacker.news/items/1537172",
      "organisation": "Stacker News",
      "kind": "community-discussion",
      "role": "Community discussion",
      "publication_time": "2026-07-31",
      "note": "Scoresby reposting NVK's 'To all Coinkite users and the entire Bitcoin community' statement, urging owners to move funds before reading further. The statement text is NVK's; this source captures it as circulated on Stacker News plus the community response. Captured through the site's public GraphQL API: the rendered pages crash the capture tab, and the API answers POST from this host. The query fixes the captured surface to the item's title, text and two levels of comments, each with author and absolute timestamp.\n",
      "gone": null,
      "capture": {
        "status": "held",
        "copies": 1,
        "first_observed": "2026-08-04T04:15:33Z",
        "last_observed": "2026-08-04T04:15:33Z",
        "last_checked": "2026-08-09T23:17:51Z"
      },
      "differences": []
    },
    {
      "id": "stackernews-false-promise-commercial-hww",
      "title": "The False Promise of Commercial Hardware Wallets",
      "url": "https://stacker.news/items/1537204",
      "organisation": "Stacker News",
      "kind": "community-discussion",
      "role": "Community discussion",
      "publication_time": "2026-07-31",
      "note": "hasherstacker's essay 'The False Promise of Commercial Hardware Wallets', arguing the incident indicts the product category rather than one vendor. Opinion, attributed to the author. Captured through the site's public GraphQL API: the rendered pages crash the capture tab, and the API answers POST from this host. The query fixes the captured surface to the item's title, text and two levels of comments, each with author and absolute timestamp.\n",
      "gone": null,
      "capture": {
        "status": "held",
        "copies": 1,
        "first_observed": "2026-08-04T04:17:58Z",
        "last_observed": "2026-08-04T04:17:58Z",
        "last_checked": "2026-08-07T00:04:53Z"
      },
      "differences": []
    },
    {
      "id": "stackernews-legal-responsibility",
      "title": "Is Coldcard legally responsible for the lost of the funds?",
      "url": "https://stacker.news/items/1537215",
      "organisation": "Stacker News",
      "kind": "community-discussion",
      "role": "Community discussion",
      "publication_time": "2026-07-31",
      "note": "Bitcoiner1 asking whether Coinkite is legally responsible for the lost funds. Early community framing of the liability question; no legal reasoning here is endorsed. Captured through the site's public GraphQL API: the rendered pages crash the capture tab, and the API answers POST from this host. The query fixes the captured surface to the item's title, text and two levels of comments, each with author and absolute timestamp.\n",
      "gone": null,
      "capture": {
        "status": "held",
        "copies": 1,
        "first_observed": "2026-08-04T04:15:38Z",
        "last_observed": "2026-08-04T04:15:38Z",
        "last_checked": "2026-08-07T00:04:56Z"
      },
      "differences": []
    },
    {
      "id": "stackernews-replacement-wallets",
      "title": "What are the best hardware wallets to replace a coldcard",
      "url": "https://stacker.news/items/1537353",
      "organisation": "Stacker News",
      "kind": "community-discussion",
      "role": "Community discussion",
      "publication_time": "2026-07-31",
      "note": "HardMoney asking what hardware wallets should replace a COLDCARD. A migration-destination thread; mention of any product here is the posters', not a recommendation by this project. Captured through the site's public GraphQL API: the rendered pages crash the capture tab, and the API answers POST from this host. The query fixes the captured surface to the item's title, text and two levels of comments, each with author and absolute timestamp.\n",
      "gone": null,
      "capture": {
        "status": "held",
        "copies": 1,
        "first_observed": "2026-08-04T04:15:41Z",
        "last_observed": "2026-08-04T04:15:41Z",
        "last_checked": "2026-08-07T00:04:59Z"
      },
      "differences": []
    },
    {
      "id": "stackernews-exchanges-no-psa",
      "title": "In case you thought self custody was mainstream...",
      "url": "https://stacker.news/items/1537407",
      "organisation": "Stacker News",
      "kind": "community-discussion",
      "role": "Community discussion",
      "publication_time": "2026-07-31",
      "note": "Scoresby checking exchange social accounts and finding no COLDCARD warnings, with screenshots. Held as evidence of provider silence in the first day, complementing the custody-coverage record; the screenshots themselves are images this text capture does not hold. Captured through the site's public GraphQL API: the rendered pages crash the capture tab, and the API answers POST from this host. The query fixes the captured surface to the item's title, text and two levels of comments, each with author and absolute timestamp.\n",
      "gone": null,
      "capture": {
        "status": "held",
        "copies": 1,
        "first_observed": "2026-08-04T04:15:44Z",
        "last_observed": "2026-08-04T04:15:44Z",
        "last_checked": "2026-08-07T00:05:01Z"
      },
      "differences": []
    },
    {
      "id": "stackernews-media-ai-anatomy",
      "title": "Coldcard, the Media, and the Anatomy of AI Retardation",
      "url": "https://stacker.news/items/1537410",
      "organisation": "Stacker News",
      "kind": "community-discussion",
      "role": "Community discussion",
      "publication_time": "2026-07-31",
      "note": "Aeneas on the media coverage of the incident and AI-generated commentary, engaging with Coinkite's technical backgrounder. Opinion and media criticism, attributed to the author. Captured through the site's public GraphQL API: the rendered pages crash the capture tab, and the API answers POST from this host. The query fixes the captured surface to the item's title, text and two levels of comments, each with author and absolute timestamp.\n",
      "gone": null,
      "capture": {
        "status": "held",
        "copies": 1,
        "first_observed": "2026-08-04T04:15:47Z",
        "last_observed": "2026-08-04T04:15:47Z",
        "last_checked": "2026-08-07T00:05:04Z"
      },
      "differences": []
    },
    {
      "id": "stackernews-swan-email",
      "title": "Swan Email Re Cold Card Hack",
      "url": "https://stacker.news/items/1537427",
      "organisation": "Stacker News",
      "kind": "community-discussion",
      "role": "Community discussion",
      "publication_time": "2026-07-31",
      "note": "siggy47 describing an email Swan sent clients about the incident. Provider communications that reach clients by email rather than public posts are otherwise uncapturable; this thread is the public trace of one. The email text is quoted by the poster, not verified against Swan. Captured through the site's public GraphQL API: the rendered pages crash the capture tab, and the API answers POST from this host. The query fixes the captured surface to the item's title, text and two levels of comments, each with author and absolute timestamp.\n",
      "gone": null,
      "capture": {
        "status": "held",
        "copies": 1,
        "first_observed": "2026-08-04T04:15:50Z",
        "last_observed": "2026-08-04T04:15:50Z",
        "last_checked": "2026-08-09T23:17:54Z"
      },
      "differences": []
    },
    {
      "id": "stackernews-sweep-watch",
      "title": "Coldcard Sweep Watch",
      "url": "https://stacker.news/items/1537531",
      "organisation": "Stacker News",
      "kind": "community-discussion",
      "role": "Community discussion",
      "publication_time": "2026-08-01",
      "note": "HardMoney's 'Coldcard Sweep Watch', tracking the draining address via an X post by bradytc_. Community chain-watching during the active theft window; figures quoted are the cited sources', not verified here. Captured through the site's public GraphQL API: the rendered pages crash the capture tab, and the API answers POST from this host. The query fixes the captured surface to the item's title, text and two levels of comments, each with author and absolute timestamp.\n",
      "gone": null,
      "capture": {
        "status": "held",
        "copies": 1,
        "first_observed": "2026-08-04T04:15:53Z",
        "last_observed": "2026-08-04T04:15:53Z",
        "last_checked": "2026-08-09T23:17:56Z"
      },
      "differences": []
    },
    {
      "id": "stackernews-larp-discussion",
      "title": "Can we have a serious talk about the LARP in Bitcoin",
      "url": "https://stacker.news/items/1537803",
      "organisation": "Stacker News",
      "kind": "community-discussion",
      "role": "Community discussion",
      "publication_time": "2026-08-01",
      "note": "chungkingexpress's 'Can we have a serious talk about the LARP in Bitcoin', a long criticism of how Coinkite and NVK handled and framed the incident. One of the largest discussion threads on the site; the accusations are the author's and are contested. Captured through the site's public GraphQL API: the rendered pages crash the capture tab, and the API answers POST from this host. The query fixes the captured surface to the item's title, text and two levels of comments, each with author and absolute timestamp.\n",
      "gone": null,
      "capture": {
        "status": "held",
        "copies": 2,
        "first_observed": "2026-08-04T04:15:56Z",
        "last_observed": "2026-08-04T13:39:57Z",
        "last_checked": "2026-08-09T23:17:59Z"
      },
      "differences": [
        {
          "observed_at": "2026-08-04T13:39:57Z",
          "window_start": "2026-08-04T04:15:56Z",
          "window_end": "2026-08-04T13:39:57Z",
          "status": "capture-noise",
          "summary": "Only an existing comment moved in the API response. No comment text was added, edited or removed.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 7,
          "removed_lines": 7
        }
      ]
    },
    {
      "id": "stackernews-critical-flaw-guide",
      "title": "Critical Coldcard flaw: what happened, who is affected, and what to do",
      "url": "https://stacker.news/items/1537859",
      "organisation": "Stacker News",
      "kind": "community-discussion",
      "role": "Community discussion",
      "publication_time": "2026-08-01",
      "note": "fanis linking a guide: 'Critical Coldcard flaw: what happened, who is affected, and what to do'. Link post; the value captured is the discussion. Captured through the site's public GraphQL API: the rendered pages crash the capture tab, and the API answers POST from this host. The query fixes the captured surface to the item's title, text and two levels of comments, each with author and absolute timestamp.\n",
      "gone": null,
      "capture": {
        "status": "held",
        "copies": 1,
        "first_observed": "2026-08-04T04:15:59Z",
        "last_observed": "2026-08-04T04:15:59Z",
        "last_checked": "2026-08-07T00:05:07Z"
      },
      "differences": []
    },
    {
      "id": "stackernews-galaxy-third-wave",
      "title": "Galaxy Research identifies third wave of Coldcard hacks, attacks ongoing",
      "url": "https://stacker.news/items/1537971",
      "organisation": "Stacker News",
      "kind": "community-discussion",
      "role": "Community discussion",
      "publication_time": "2026-08-01",
      "note": "Scoresby relaying Galaxy Research's identification of a third wave of drains, 207.7294 BTC, taking the estimated observed total to 1,367.05 BTC. The numbers are Galaxy's reported figures; Galaxy's own publications are registered separately. Captured through the site's public GraphQL API: the rendered pages crash the capture tab, and the API answers POST from this host. The query fixes the captured surface to the item's title, text and two levels of comments, each with author and absolute timestamp.\n",
      "gone": null,
      "capture": {
        "status": "held",
        "copies": 1,
        "first_observed": "2026-08-04T04:16:02Z",
        "last_observed": "2026-08-04T04:16:02Z",
        "last_checked": "2026-08-09T23:18:01Z"
      },
      "differences": []
    },
    {
      "id": "stackernews-random-bytes-analysis",
      "title": "When random.bytes() runs but doesn't work",
      "url": "https://stacker.news/items/1538016",
      "organisation": "Stacker News",
      "kind": "community-discussion",
      "role": "Community discussion",
      "publication_time": "2026-08-01",
      "note": "Scoresby discussing Dusty Daemon's code analysis 'When random.bytes() runs but doesn't work', on the failed attempt to override the RNG in C. Technical discussion of the root cause; the analysis belongs to its author. Captured through the site's public GraphQL API: the rendered pages crash the capture tab, and the API answers POST from this host. The query fixes the captured surface to the item's title, text and two levels of comments, each with author and absolute timestamp.\n",
      "gone": null,
      "capture": {
        "status": "held",
        "copies": 1,
        "first_observed": "2026-08-04T04:16:05Z",
        "last_observed": "2026-08-04T04:16:05Z",
        "last_checked": "2026-08-07T00:05:09Z"
      },
      "differences": []
    },
    {
      "id": "stackernews-psa-advice",
      "title": "PSA: Advice Regarding the Coldcard Bug - Exploit - Hack - Theft",
      "url": "https://stacker.news/items/1538049",
      "organisation": "Stacker News",
      "kind": "community-discussion",
      "role": "Community discussion",
      "publication_time": "2026-08-01",
      "note": "BITC0IN's PSA with owner advice, including the Mk3-without-passphrase case. Community guidance from the response window; specific claims are the author's and partly contested in replies. Captured through the site's public GraphQL API: the rendered pages crash the capture tab, and the API answers POST from this host. The query fixes the captured surface to the item's title, text and two levels of comments, each with author and absolute timestamp.\n",
      "gone": null,
      "capture": {
        "status": "held",
        "copies": 1,
        "first_observed": "2026-08-04T04:16:08Z",
        "last_observed": "2026-08-04T04:16:08Z",
        "last_checked": "2026-08-07T00:05:12Z"
      },
      "differences": []
    },
    {
      "id": "stackernews-bitkey-setup-experience",
      "title": "Because if the ColdCard fiasco I just tried setting up a BitKey with a screen",
      "url": "https://stacker.news/items/1538187",
      "organisation": "Stacker News",
      "kind": "community-discussion",
      "role": "Community discussion",
      "publication_time": "2026-08-02",
      "note": "realBitcoinDog describing setting up a BitKey because of the incident and disliking the multisig custody trade-offs. A migration-experience account; the product criticism is the author's and this project does not endorse destinations. Captured through the site's public GraphQL API: the rendered pages crash the capture tab, and the API answers POST from this host. The query fixes the captured surface to the item's title, text and two levels of comments, each with author and absolute timestamp.\n",
      "gone": null,
      "capture": {
        "status": "held",
        "copies": 1,
        "first_observed": "2026-08-04T04:16:15Z",
        "last_observed": "2026-08-04T04:16:15Z",
        "last_checked": "2026-08-07T00:05:15Z"
      },
      "differences": []
    },
    {
      "id": "stackernews-unbroadcast-failsafe-rfc",
      "title": "Request for comment:  Unbroadcast Bitcoin transactions as failsafe",
      "url": "https://stacker.news/items/1538230",
      "organisation": "Stacker News",
      "kind": "community-discussion",
      "role": "Community discussion",
      "publication_time": "2026-08-02",
      "note": "chungkingexpress requesting comment on unbroadcast transactions as a failsafe, prompted by owners who were away from their seeds or devices during the emergency. A design discussion arising directly from the incident's rescue window. Captured through the site's public GraphQL API: the rendered pages crash the capture tab, and the API answers POST from this host. The query fixes the captured surface to the item's title, text and two levels of comments, each with author and absolute timestamp.\n",
      "gone": null,
      "capture": {
        "status": "held",
        "copies": 1,
        "first_observed": "2026-08-04T04:16:18Z",
        "last_observed": "2026-08-04T04:16:18Z",
        "last_checked": "2026-08-07T00:05:18Z"
      },
      "differences": []
    },
    {
      "id": "stackernews-zerohedge-pickup",
      "title": "Zero Hedge Picks Up Cold Card Exploit",
      "url": "https://stacker.news/items/1538470",
      "organisation": "Stacker News",
      "kind": "community-discussion",
      "role": "Community discussion",
      "publication_time": "2026-08-02",
      "note": "billytheked noting Zero Hedge's coverage, among the first mainstream financial press pickups, quoting its third-wave loss figure. Part of the media-spread record; the figures are the outlets' reported numbers. Captured through the site's public GraphQL API: the rendered pages crash the capture tab, and the API answers POST from this host. The query fixes the captured surface to the item's title, text and two levels of comments, each with author and absolute timestamp.\n",
      "gone": null,
      "capture": {
        "status": "held",
        "copies": 1,
        "first_observed": "2026-08-04T04:16:21Z",
        "last_observed": "2026-08-04T04:16:21Z",
        "last_checked": "2026-08-07T00:05:20Z"
      },
      "differences": []
    },
    {
      "id": "stackernews-hot-takes-thread",
      "title": "Hot takes on the COLDCARD happenings",
      "url": "https://stacker.news/items/1538536",
      "organisation": "Stacker News",
      "kind": "community-discussion",
      "role": "Community discussion",
      "publication_time": "2026-08-02",
      "note": "desertdave collecting hot takes on the incident. Link-and-comment thread held as a sample of community sentiment. Captured through the site's public GraphQL API: the rendered pages crash the capture tab, and the API answers POST from this host. The query fixes the captured surface to the item's title, text and two levels of comments, each with author and absolute timestamp.\n",
      "gone": null,
      "capture": {
        "status": "held",
        "copies": 1,
        "first_observed": "2026-08-04T04:16:24Z",
        "last_observed": "2026-08-04T04:16:24Z",
        "last_checked": "2026-08-07T00:05:23Z"
      },
      "differences": []
    },
    {
      "id": "stackernews-lopp-bricking-reports",
      "title": "Lopp: Reports of coldcard firmware updates bricking devices",
      "url": "https://stacker.news/items/1538594",
      "organisation": "Stacker News",
      "kind": "community-discussion",
      "role": "Community discussion",
      "publication_time": "2026-08-02",
      "note": "Lobotomite relaying Lopp's report of COLDCARD firmware updates bricking devices during the emergency update push. The bricking reports are secondhand here; they matter to the record because update risk shaped owner decisions in the rescue window. Captured through the site's public GraphQL API: the rendered pages crash the capture tab, and the API answers POST from this host. The query fixes the captured surface to the item's title, text and two levels of comments, each with author and absolute timestamp.\n",
      "gone": null,
      "capture": {
        "status": "held",
        "copies": 1,
        "first_observed": "2026-08-04T04:16:28Z",
        "last_observed": "2026-08-04T04:16:28Z",
        "last_checked": "2026-08-09T23:18:04Z"
      },
      "differences": []
    },
    {
      "id": "stackernews-opreturn-laundering-offer",
      "title": "COLDCARD Hacker receives money laundering offer via OP_RETURN message",
      "url": "https://stacker.news/items/1538619",
      "organisation": "Stacker News",
      "kind": "community-discussion",
      "role": "Community discussion",
      "publication_time": "2026-08-02",
      "note": "hyperfree reporting an OP_RETURN message offering money laundering to the drainer. Part of the record of on-chain messages to the operator; the message's authenticity is not established. Captured through the site's public GraphQL API: the rendered pages crash the capture tab, and the API answers POST from this host. The query fixes the captured surface to the item's title, text and two levels of comments, each with author and absolute timestamp.\n",
      "gone": null,
      "capture": {
        "status": "held",
        "copies": 1,
        "first_observed": "2026-08-04T04:16:31Z",
        "last_observed": "2026-08-04T04:16:31Z",
        "last_checked": "2026-08-07T00:05:26Z"
      },
      "differences": []
    },
    {
      "id": "stackernews-39k-btc-moved",
      "title": "39.6K BTC transferred on July 31st after the coldcard hack",
      "url": "https://stacker.news/items/1538630",
      "organisation": "Stacker News",
      "kind": "community-discussion",
      "role": "Community discussion",
      "publication_time": "2026-08-02",
      "note": "0xbitcoiner quoting a comparison that 39.6K BTC moved on 31 July, the most in a day since the FTX collapse, attributed to the incident's sweep traffic. Reported chain statistic; the underlying account is the quoted source's. Captured through the site's public GraphQL API: the rendered pages crash the capture tab, and the API answers POST from this host. The query fixes the captured surface to the item's title, text and two levels of comments, each with author and absolute timestamp.\n",
      "gone": null,
      "capture": {
        "status": "held",
        "copies": 1,
        "first_observed": "2026-08-04T04:16:33Z",
        "last_observed": "2026-08-04T04:16:33Z",
        "last_checked": "2026-08-07T00:05:28Z"
      },
      "differences": []
    },
    {
      "id": "stackernews-foundation-phishing-warning",
      "title": "Foundation Phishing Warning",
      "url": "https://stacker.news/items/1538671",
      "organisation": "Stacker News",
      "kind": "community-discussion",
      "role": "Community discussion",
      "publication_time": "2026-08-02",
      "note": "siggy47 warning about Foundation-themed phishing during the incident. Part of the scam-wave record: lookalike warnings and phishing attempts proliferated while owners were frightened. Captured through the site's public GraphQL API: the rendered pages crash the capture tab, and the API answers POST from this host. The query fixes the captured surface to the item's title, text and two levels of comments, each with author and absolute timestamp.\n",
      "gone": null,
      "capture": {
        "status": "held",
        "copies": 1,
        "first_observed": "2026-08-04T04:16:36Z",
        "last_observed": "2026-08-04T04:16:36Z",
        "last_checked": "2026-08-07T00:05:31Z"
      },
      "differences": []
    },
    {
      "id": "stackernews-attack-over-question",
      "title": "At what point can this attack be considered over?",
      "url": "https://stacker.news/items/1538677",
      "organisation": "Stacker News",
      "kind": "community-discussion",
      "role": "Community discussion",
      "publication_time": "2026-08-02",
      "note": "theonceler asking at what point the attack can be considered over: when remaining affected addresses have either moved or been drained. Frames the endgame question the chain monitors' numbers bear on. Captured through the site's public GraphQL API: the rendered pages crash the capture tab, and the API answers POST from this host. The query fixes the captured surface to the item's title, text and two levels of comments, each with author and absolute timestamp.\n",
      "gone": null,
      "capture": {
        "status": "held",
        "copies": 1,
        "first_observed": "2026-08-04T04:16:39Z",
        "last_observed": "2026-08-04T04:16:39Z",
        "last_checked": "2026-08-07T00:05:34Z"
      },
      "differences": []
    },
    {
      "id": "stackernews-nvk-opensats-departure",
      "title": "NVK steps down from OpenSats board",
      "url": "https://stacker.news/items/1538698",
      "organisation": "Stacker News",
      "kind": "community-discussion",
      "role": "Community discussion",
      "publication_time": "2026-08-02",
      "note": "justin_shocknet reporting that NVK stepped down from the OpenSats board. The OpenSats statement is registered as opensats-nvk-board-departure; this source holds the Stacker News discussion of the governance fallout. Captured through the site's public GraphQL API: the rendered pages crash the capture tab, and the API answers POST from this host. The query fixes the captured surface to the item's title, text and two levels of comments, each with author and absolute timestamp.\n",
      "gone": null,
      "capture": {
        "status": "held",
        "copies": 1,
        "first_observed": "2026-08-04T04:16:42Z",
        "last_observed": "2026-08-04T04:16:42Z",
        "last_checked": "2026-08-09T23:18:07Z"
      },
      "differences": []
    },
    {
      "id": "stackernews-aantonop-2020-clip",
      "title": "Aantonop from 2020 nails trust, seed generation and system complexity",
      "url": "https://stacker.news/items/1538724",
      "organisation": "Stacker News",
      "kind": "community-discussion",
      "role": "Community discussion",
      "publication_time": "2026-08-02",
      "note": "sime resurfacing a 2020 aantonop talk on trust, seed generation and system complexity as prescient for this incident. Discussion of where trust sits in self custody. Captured through the site's public GraphQL API: the rendered pages crash the capture tab, and the API answers POST from this host. The query fixes the captured surface to the item's title, text and two levels of comments, each with author and absolute timestamp.\n",
      "gone": null,
      "capture": {
        "status": "held",
        "copies": 1,
        "first_observed": "2026-08-04T04:16:45Z",
        "last_observed": "2026-08-04T04:16:45Z",
        "last_checked": "2026-08-07T00:05:37Z"
      },
      "differences": []
    },
    {
      "id": "stackernews-glm-ai-finds-vuln",
      "title": "GLM-5.2 was able to easily find the ColdCard vulnerability",
      "url": "https://stacker.news/items/1538828",
      "organisation": "Stacker News",
      "kind": "community-discussion",
      "role": "Community discussion",
      "publication_time": "2026-08-03",
      "note": "gmd reporting that GLM-5.2 found the vulnerability easily, following a similar demonstration with Claude Code linked via Reddit. Part of the record of AI tools independently locating the defect, which bears on how findable the bug was. The demonstrations are the reporters'. Captured through the site's public GraphQL API: the rendered pages crash the capture tab, and the API answers POST from this host. The query fixes the captured surface to the item's title, text and two levels of comments, each with author and absolute timestamp.\n",
      "gone": null,
      "capture": {
        "status": "held",
        "copies": 1,
        "first_observed": "2026-08-04T04:16:48Z",
        "last_observed": "2026-08-04T04:16:48Z",
        "last_checked": "2026-08-09T23:18:09Z"
      },
      "differences": []
    },
    {
      "id": "stackernews-slipstream-permissionless",
      "title": "MARA Slipstream now available as a permissionless public good",
      "url": "https://stacker.news/items/1539033",
      "organisation": "Stacker News",
      "kind": "community-discussion",
      "role": "Community discussion",
      "publication_time": "2026-08-03",
      "note": "supratic relaying that MARA Slipstream opened as a permissionless public good with no client code requirement, relevant to getting rescue transactions mined. The Slipstream materials are registered separately (mara-slipstream-portal, mara-slipstream-permissionless); this source holds the community discussion, including fee-safety cautions. Captured through the site's public GraphQL API: the rendered pages crash the capture tab, and the API answers POST from this host. The query fixes the captured surface to the item's title, text and two levels of comments, each with author and absolute timestamp.\n",
      "gone": null,
      "capture": {
        "status": "held",
        "copies": 1,
        "first_observed": "2026-08-04T04:16:51Z",
        "last_observed": "2026-08-04T04:16:51Z",
        "last_checked": "2026-08-09T23:18:12Z"
      },
      "differences": []
    },
    {
      "id": "stackernews-blacklist-clean-coins",
      "title": "Coldcard exploit: Can Blockchain analysis mistakenly blacklist our “Clean”coins?",
      "url": "https://stacker.news/items/1539067",
      "organisation": "Stacker News",
      "kind": "community-discussion",
      "role": "Community discussion",
      "publication_time": "2026-08-03",
      "note": "FlorFina asking whether blockchain analysis could mistakenly blacklist clean coins after the exploit. Part of the record of feared long-term fallout for unaffected owners. Captured through the site's public GraphQL API: the rendered pages crash the capture tab, and the API answers POST from this host. The query fixes the captured surface to the item's title, text and two levels of comments, each with author and absolute timestamp.\n",
      "gone": null,
      "capture": {
        "status": "held",
        "copies": 1,
        "first_observed": "2026-08-04T04:16:54Z",
        "last_observed": "2026-08-04T04:16:54Z",
        "last_checked": "2026-08-07T00:05:39Z"
      },
      "differences": []
    },
    {
      "id": "stackernews-robhamilton-scanning",
      "title": "Rob Hamilton spends $10k scanning Bitcoin projects, finds multiple vulns",
      "url": "https://stacker.news/items/1539074",
      "organisation": "Stacker News",
      "kind": "community-discussion",
      "role": "Community discussion",
      "publication_time": "2026-08-03",
      "note": "Scoresby on Rob Hamilton spending $10k scanning Bitcoin projects and finding multiple vulnerabilities, with the poster noting Hamilton's AnchorWatch markets a related service. The disclosure of that conflict in the thread itself is part of the record. Captured through the site's public GraphQL API: the rendered pages crash the capture tab, and the API answers POST from this host. The query fixes the captured surface to the item's title, text and two levels of comments, each with author and absolute timestamp.\n",
      "gone": null,
      "capture": {
        "status": "held",
        "copies": 2,
        "first_observed": "2026-08-04T04:16:57Z",
        "last_observed": "2026-08-04T20:12:18Z",
        "last_checked": "2026-08-09T23:18:14Z"
      },
      "differences": [
        {
          "observed_at": "2026-08-04T20:12:18Z",
          "window_start": "2026-08-04T04:16:57Z",
          "window_end": "2026-08-04T20:12:18Z",
          "status": "capture-noise",
          "summary": "The GraphQL response reordered an existing comment without changing its text.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 7,
          "removed_lines": 7
        }
      ]
    },
    {
      "id": "stackernews-dear-podcasters",
      "title": "Dear podcasters & influencers",
      "url": "https://stacker.news/items/1539078",
      "organisation": "Stacker News",
      "kind": "community-discussion",
      "role": "Community discussion",
      "publication_time": "2026-08-03",
      "note": "raw_avocado's 'Dear podcasters & influencers', absolving recommenders who had pointed audiences at COLDCARD. Part of the recommender-responsibility debate; opinion, attributed to the author. Captured through the site's public GraphQL API: the rendered pages crash the capture tab, and the API answers POST from this host. The query fixes the captured surface to the item's title, text and two levels of comments, each with author and absolute timestamp.\n",
      "gone": null,
      "capture": {
        "status": "held",
        "copies": 4,
        "first_observed": "2026-08-04T04:17:00Z",
        "last_observed": "2026-08-04T12:41:32Z",
        "last_checked": "2026-08-07T00:05:42Z"
      },
      "differences": [
        {
          "observed_at": "2026-08-04T12:41:32Z",
          "window_start": "2026-08-04T12:12:28Z",
          "window_end": "2026-08-04T12:41:32Z",
          "status": "capture-noise",
          "summary": "Only comment ordering changed again: BlokchainB's comment moved above DarthCoin's image comment. No comment text was added, edited or removed.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 7,
          "removed_lines": 7
        },
        {
          "observed_at": "2026-08-04T12:12:28Z",
          "window_start": "2026-08-04T10:12:01Z",
          "window_end": "2026-08-04T12:12:28Z",
          "status": "capture-noise",
          "summary": "Only comment ordering changed in the API response: BlokchainB's comment moved above itsrealfake's. No comment text was added, edited or removed; this is ranking-order churn.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 7,
          "removed_lines": 7
        },
        {
          "observed_at": "2026-08-04T10:12:01Z",
          "window_start": "2026-08-04T04:17:00Z",
          "window_end": "2026-08-04T10:12:01Z",
          "status": "capture-noise",
          "summary": "Only comment ordering changed in the API response: siggy47's comment moved from below 028559d218's to above it. No comment text was added, edited or removed; this is ranking-order churn.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 7,
          "removed_lines": 7
        }
      ]
    },
    {
      "id": "stackernews-personal-responsibility",
      "title": "ColdCard and Personal Responsibility",
      "url": "https://stacker.news/items/1539218",
      "organisation": "Stacker News",
      "kind": "community-discussion",
      "role": "Community discussion",
      "publication_time": "2026-08-03",
      "note": "kepford's 'ColdCard and Personal Responsibility', on DYOR and trust in confident people. Part of the responsibility-framing debate the site's dice and passphrase pages must not prejudge. Captured through the site's public GraphQL API: the rendered pages crash the capture tab, and the API answers POST from this host. The query fixes the captured surface to the item's title, text and two levels of comments, each with author and absolute timestamp.\n",
      "gone": null,
      "capture": {
        "status": "held",
        "copies": 4,
        "first_observed": "2026-08-04T04:17:03Z",
        "last_observed": "2026-08-04T22:55:10Z",
        "last_checked": "2026-08-07T00:05:45Z"
      },
      "differences": [
        {
          "observed_at": "2026-08-04T22:55:10Z",
          "window_start": "2026-08-04T14:22:02Z",
          "window_end": "2026-08-04T22:55:10Z",
          "status": "capture-noise",
          "summary": "Only the order of existing comments changed; their text and timestamps were unchanged.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 7,
          "removed_lines": 7
        },
        {
          "observed_at": "2026-08-04T14:22:02Z",
          "window_start": "2026-08-04T10:41:01Z",
          "window_end": "2026-08-04T14:22:02Z",
          "status": "capture-noise",
          "summary": "Only an existing comment moved in the API response. No comment text was added, edited or removed.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 7,
          "removed_lines": 7
        },
        {
          "observed_at": "2026-08-04T10:41:01Z",
          "window_start": "2026-08-04T04:17:03Z",
          "window_end": "2026-08-04T10:41:01Z",
          "status": "source-content",
          "summary": "One new comment was posted: CruncherDefi asking how a seed can be screwed up even with dice rolls.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 7,
          "removed_lines": 0
        }
      ]
    },
    {
      "id": "stackernews-btt-512",
      "title": "Bitcoin Tech Talk #512: ColdCard RNG, Nudge Unit, Steel, Power, Scammy Produdcts",
      "url": "https://stacker.news/items/1539267",
      "organisation": "Stacker News",
      "kind": "community-discussion",
      "role": "Community discussion",
      "publication_time": "2026-08-03",
      "note": "jimmysong linking Bitcoin Tech Talk #512, which covers the COLDCARD RNG among other topics. Link post; the newsletter is the primary, this source captures any discussion. Captured through the site's public GraphQL API: the rendered pages crash the capture tab, and the API answers POST from this host. The query fixes the captured surface to the item's title, text and two levels of comments, each with author and absolute timestamp.\n",
      "gone": null,
      "capture": {
        "status": "held",
        "copies": 1,
        "first_observed": "2026-08-04T04:17:06Z",
        "last_observed": "2026-08-04T04:17:06Z",
        "last_checked": "2026-08-07T00:05:47Z"
      },
      "differences": []
    },
    {
      "id": "stackernews-boltz-zeuslsp-shutdown",
      "title": "Boltz and ZeusLSP temporarily shut down swap services",
      "url": "https://stacker.news/items/1539276",
      "organisation": "Stacker News",
      "kind": "community-discussion",
      "role": "Community discussion",
      "publication_time": "2026-08-03",
      "note": "justin_shocknet reporting Boltz and ZeusLSP temporarily shutting down swap services, with screenshots and a Zeus X post. Incident fallout on Lightning swap infrastructure; one of the largest response threads. Captured through the site's public GraphQL API: the rendered pages crash the capture tab, and the API answers POST from this host. The query fixes the captured surface to the item's title, text and two levels of comments, each with author and absolute timestamp.\n",
      "gone": null,
      "capture": {
        "status": "held",
        "copies": 6,
        "first_observed": "2026-08-04T04:17:09Z",
        "last_observed": "2026-08-05T20:56:30Z",
        "last_checked": "2026-08-09T23:18:17Z"
      },
      "differences": [
        {
          "observed_at": "2026-08-05T20:56:30Z",
          "window_start": "2026-08-05T07:53:27Z",
          "window_end": "2026-08-05T20:56:30Z",
          "status": "capture-noise",
          "summary": "The GraphQL response changed only the placement of a comment's closing JSON structure. The displayed comment text did not change.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 7,
          "removed_lines": 7
        },
        {
          "observed_at": "2026-08-05T07:53:27Z",
          "window_start": "2026-08-04T22:43:19Z",
          "window_end": "2026-08-05T07:53:27Z",
          "status": "capture-noise",
          "summary": "The same Stacker News comment record was reordered in the GraphQL response. No comment text or other captured source content changed.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 7,
          "removed_lines": 7
        },
        {
          "observed_at": "2026-08-04T22:43:19Z",
          "window_start": "2026-08-04T13:40:18Z",
          "window_end": "2026-08-04T22:43:19Z",
          "status": "capture-noise",
          "summary": "The GraphQL response reordered existing comments without changing their text.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 7,
          "removed_lines": 7
        },
        {
          "observed_at": "2026-08-04T13:40:18Z",
          "window_start": "2026-08-04T07:10:19Z",
          "window_end": "2026-08-04T13:40:18Z",
          "status": "capture-noise",
          "summary": "Only comment ordering in the API response changed. No comment text was added, edited or removed.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 13,
          "removed_lines": 13
        },
        {
          "observed_at": "2026-08-04T07:10:19Z",
          "window_start": "2026-08-04T04:17:09Z",
          "window_end": "2026-08-04T07:10:19Z",
          "status": "capture-noise",
          "summary": "Only comment ordering changed in the API response: DarthCoin's comment moved from the top of the list to below Scoresby's. No comment text was added, edited or removed; this is ranking-order churn.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 7,
          "removed_lines": 7
        }
      ]
    },
    {
      "id": "stackernews-last-week-in-bitcoin",
      "title": "The COLDCARD Incident — Last Week in Bitcoin (Jul 27 - Aug 02)",
      "url": "https://stacker.news/items/1539442",
      "organisation": "Stacker News",
      "kind": "community-discussion",
      "role": "Community discussion",
      "publication_time": "2026-08-03",
      "note": "tuma linking 'The COLDCARD Incident, Last Week in Bitcoin (Jul 27 - Aug 02)'. Link post to a weekly roundup; held for the discussion and as a pointer to secondary coverage. Captured through the site's public GraphQL API: the rendered pages crash the capture tab, and the API answers POST from this host. The query fixes the captured surface to the item's title, text and two levels of comments, each with author and absolute timestamp.\n",
      "gone": null,
      "capture": {
        "status": "held",
        "copies": 1,
        "first_observed": "2026-08-04T04:17:12Z",
        "last_observed": "2026-08-04T04:17:12Z",
        "last_checked": "2026-08-07T00:05:50Z"
      },
      "differences": []
    },
    {
      "id": "stackernews-everything-you-need-to-know",
      "title": "Everything You Need to Know About the COLDCARD Hack",
      "url": "https://stacker.news/items/1539443",
      "organisation": "Stacker News",
      "kind": "community-discussion",
      "role": "Community discussion",
      "publication_time": "2026-08-03",
      "note": "hasherstacker linking 'Everything You Need to Know About the COLDCARD Hack'. Link post to secondary coverage; held for the discussion. Captured through the site's public GraphQL API: the rendered pages crash the capture tab, and the API answers POST from this host. The query fixes the captured surface to the item's title, text and two levels of comments, each with author and absolute timestamp.\n",
      "gone": null,
      "capture": {
        "status": "held",
        "copies": 1,
        "first_observed": "2026-08-04T04:17:15Z",
        "last_observed": "2026-08-04T04:17:15Z",
        "last_checked": "2026-08-07T00:05:53Z"
      },
      "differences": []
    },
    {
      "id": "stackernews-bpi-explainer",
      "title": "Bitcoin Policy institute Coldcard bug explainer",
      "url": "https://stacker.news/items/1539573",
      "organisation": "Stacker News",
      "kind": "community-discussion",
      "role": "Community discussion",
      "publication_time": "2026-08-03",
      "note": "HardMoney linking the Bitcoin Policy Institute's explainer of the bug. Link post; the explainer is the primary and may warrant its own registration, this source captures the Stacker News discussion. Captured through the site's public GraphQL API: the rendered pages crash the capture tab, and the API answers POST from this host. The query fixes the captured surface to the item's title, text and two levels of comments, each with author and absolute timestamp.\n",
      "gone": null,
      "capture": {
        "status": "held",
        "copies": 1,
        "first_observed": "2026-08-04T04:17:18Z",
        "last_observed": "2026-08-04T04:17:18Z",
        "last_checked": "2026-08-07T00:05:55Z"
      },
      "differences": []
    },
    {
      "id": "stackernews-peerswap-disable",
      "title": "Maintainer of peerswap advises temporarily disabling peerswap...",
      "url": "https://stacker.news/items/1539582",
      "organisation": "Stacker News",
      "kind": "community-discussion",
      "role": "Community discussion",
      "publication_time": "2026-08-03",
      "note": "anon relaying the peerswap maintainer's advice to disable peerswap temporarily while the project is audited by AI. Incident-adjacent fallout on adjacent software, driven by the AI-audit wave the incident accelerated. Captured through the site's public GraphQL API: the rendered pages crash the capture tab, and the API answers POST from this host. The query fixes the captured surface to the item's title, text and two levels of comments, each with author and absolute timestamp.\n",
      "gone": null,
      "capture": {
        "status": "held",
        "copies": 2,
        "first_observed": "2026-08-04T04:17:21Z",
        "last_observed": "2026-08-04T10:12:17Z",
        "last_checked": "2026-08-07T00:05:58Z"
      },
      "differences": [
        {
          "observed_at": "2026-08-04T10:12:17Z",
          "window_start": "2026-08-04T04:17:21Z",
          "window_end": "2026-08-04T10:12:17Z",
          "status": "source-content",
          "summary": "One new comment was posted: DarthCoin ('LOL').",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 7,
          "removed_lines": 0
        }
      ]
    },
    {
      "id": "stackernews-troll-1367btc",
      "title": "How do I privately spend 1367 BTC given to me by NVK's friends?",
      "url": "https://stacker.news/items/1539600",
      "organisation": "Stacker News",
      "kind": "community-discussion",
      "role": "Community discussion",
      "publication_time": "2026-08-03",
      "note": "An anonymous satirical post asking how to privately spend 1367 BTC 'given to me by NVK's friends'. Held as a sample of community sentiment and gallows humour toward Coinkite; it makes no factual claim this project relies on. Captured through the site's public GraphQL API: the rendered pages crash the capture tab, and the API answers POST from this host. The query fixes the captured surface to the item's title, text and two levels of comments, each with author and absolute timestamp.\n",
      "gone": null,
      "capture": {
        "status": "held",
        "copies": 6,
        "first_observed": "2026-08-04T04:17:25Z",
        "last_observed": "2026-08-06T10:12:03Z",
        "last_checked": "2026-08-07T00:06:01Z"
      },
      "differences": [
        {
          "observed_at": "2026-08-06T10:12:03Z",
          "window_start": "2026-08-04T19:23:13Z",
          "window_end": "2026-08-06T10:12:03Z",
          "status": "capture-noise",
          "summary": "Comment ordering churn only: teemupleb's \"Birthday present 27 days late!\" comment moved to the top of the list with unchanged text.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 7,
          "removed_lines": 7
        },
        {
          "observed_at": "2026-08-04T19:23:13Z",
          "window_start": "2026-08-04T12:41:52Z",
          "window_end": "2026-08-04T19:23:13Z",
          "status": "capture-noise",
          "summary": "The GraphQL response reordered an existing comment without changing its text.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 7,
          "removed_lines": 7
        },
        {
          "observed_at": "2026-08-04T12:41:52Z",
          "window_start": "2026-08-04T11:41:37Z",
          "window_end": "2026-08-04T12:41:52Z",
          "status": "capture-noise",
          "summary": "Only comment ordering changed: grayruby's 'cowboy credits' comment moved from below wackster's to just under Scoresby's. No comment text was added, edited or removed.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 7,
          "removed_lines": 7
        },
        {
          "observed_at": "2026-08-04T11:41:37Z",
          "window_start": "2026-08-04T10:12:20Z",
          "window_end": "2026-08-04T11:41:37Z",
          "status": "source-content",
          "summary": "One new comment was posted: teemupleb ('Birthday present 27 days late!'). Existing comments by anon, grayruby and magnolia_mayhem were repositioned by ranking.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 20,
          "removed_lines": 13
        },
        {
          "observed_at": "2026-08-04T10:12:20Z",
          "window_start": "2026-08-04T04:17:25Z",
          "window_end": "2026-08-04T10:12:20Z",
          "status": "source-content",
          "summary": "One new comment was posted: kilianbuhn ('Coinjoins Obviously'). Existing comments by billytheked, Scoresby and wackster were repositioned by ranking.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 24,
          "removed_lines": 17
        }
      ]
    },
    {
      "id": "stackernews-dice-attack-vectors",
      "title": "What are the attack vectors of rolling 100 dice?",
      "url": "https://stacker.news/items/1539720",
      "organisation": "Stacker News",
      "kind": "community-discussion",
      "role": "Community discussion",
      "publication_time": "2026-08-04",
      "note": "anon asking how 100 dice rolls could be attacked or botched, assuming verified seed phrases. Directly relevant to the dice-mitigation guidance the site carries. Captured through the site's public GraphQL API: the rendered pages crash the capture tab, and the API answers POST from this host. The query fixes the captured surface to the item's title, text and two levels of comments, each with author and absolute timestamp.\n",
      "gone": null,
      "capture": {
        "status": "held",
        "copies": 4,
        "first_observed": "2026-08-04T04:17:29Z",
        "last_observed": "2026-08-04T18:22:51Z",
        "last_checked": "2026-08-07T00:06:03Z"
      },
      "differences": [
        {
          "observed_at": "2026-08-04T18:22:51Z",
          "window_start": "2026-08-04T17:53:05Z",
          "window_end": "2026-08-04T18:22:51Z",
          "status": "source-content",
          "summary": "The Stacker News thread gained new comments about dice-based seed generation and its risks.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 10,
          "removed_lines": 3
        },
        {
          "observed_at": "2026-08-04T17:53:05Z",
          "window_start": "2026-08-04T10:12:23Z",
          "window_end": "2026-08-04T17:53:05Z",
          "status": "source-content",
          "summary": "The Stacker News thread gained new comments about dice-based seed generation and its risks.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 7,
          "removed_lines": 0
        },
        {
          "observed_at": "2026-08-04T10:12:23Z",
          "window_start": "2026-08-04T04:17:29Z",
          "window_end": "2026-08-04T10:12:23Z",
          "status": "source-content",
          "summary": "Three new comments were posted on dice-roll verification: OT (cross-checking a coin-flip seed against Blue Wallet and iancoleman.io), anon (wipe the verification PC and check the derived private key), and SwapMarket (linking arman.theparman dice guide with offline Tails). 000w2's existing comment was repositioned by ranking.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 24,
          "removed_lines": 3
        }
      ]
    },
    {
      "id": "stoltmann-claimant-page",
      "title": "Coldcard Wallet Bitcoin Theft: Legal Options for Victims",
      "url": "https://stoltmannlaw.com/coldcard-wallet-bitcoin-theft-claims/",
      "organisation": "Stoltmann Law",
      "kind": "reporting",
      "role": "Reporting",
      "publication_time": "2026-07-31",
      "note": "Law firm claimant-intake page soliciting COLDCARD incident victims as\npotential claimants; self-labels as legal advertising. Surfaced during the\n4 Aug 2026 claim-sweep recheck (Internet Archive snapshot of 3 Aug 2026); it\nis the law firm's claimant page the scams page previously recorded as\nreported but uncaptured. Client solicitation after a mass loss event is\nordinary legal marketing, not itself a scam; held for provenance of the\nreport, not endorsed. Browser capture: the site answers plain scripted\nfetches with a challenge page.\n",
      "gone": null,
      "capture": {
        "status": "held",
        "copies": 1,
        "first_observed": "2026-08-04T04:19:15Z",
        "last_observed": "2026-08-04T04:19:15Z",
        "last_checked": "2026-08-15T12:56:09Z"
      },
      "differences": []
    },
    {
      "id": "ncfacanada-self-custody-commentary",
      "title": "What The Coldcard Flaw Reveals About Bitcoin Self Custody",
      "url": "https://ncfacanada.org/coldcard-firmware-flaw-bitcoin-self-custody/",
      "organisation": "NCFA Canada",
      "kind": "reporting",
      "role": "Reporting",
      "publication_time": "2026-08-03",
      "note": "Commentary from the National Crowdfunding and Fintech Association of Canada,\nthe first Canadian industry-body view held here. Registered for the Canadian\nvantage rather than for new evidence: Coinkite is Toronto based, and the\nincident's legal dimension runs through Ontario statutes and a proposed\nCanadian suit.\n\nSecondary throughout. Its loss figures (more than 1,000 BTC from 1,196 wallets\nin 41 minutes, two suspected later waves, an estimated total near US$89\nmillion) are attributed to Galaxy Research, which is separately held here, and\nthe piece carries its own caveat that not every wallet in those totals is\nconfirmed to have been created with the affected firmware. Its argument, that\nself custody removes the custodian but not the vendor layer beneath it, is the\nauthor's position and is not adopted by this archive.\n\nIt also carries a compiled company profile naming Rodolfo Novak and Peter D.\nGray as Coinkite's founders. That is public company record and is held as\nsuch. It must not be read as bearing on the separate and unverified claim\nabout who wrote the pseudonymous libngu commits.\n\nBrowser capture with scrolling: the site answers plain scripted fetches with a\nchallenge page, and the article body does not hydrate until the page is\nscrolled. Its robots.txt disallows only /wp-admin/, so this path is permitted.\n",
      "gone": null,
      "capture": {
        "status": "held",
        "copies": 28,
        "first_observed": "2026-08-05T03:56:50Z",
        "last_observed": "2026-08-15T12:56:19Z",
        "last_checked": "2026-08-15T12:56:19Z"
      },
      "differences": [
        {
          "observed_at": "2026-08-15T12:56:19Z",
          "window_start": "2026-08-15T06:27:36Z",
          "window_end": "2026-08-15T12:56:19Z",
          "status": "capture-noise",
          "summary": "Only rotating sidebar article links and page-hit counters changed; the commentary text was unchanged.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 6,
          "removed_lines": 6
        },
        {
          "observed_at": "2026-08-15T06:27:36Z",
          "window_start": "2026-08-14T23:51:22Z",
          "window_end": "2026-08-15T06:27:36Z",
          "status": "capture-noise",
          "summary": "Only rotating sidebar story links and page hit counters changed; the commentary text was unchanged.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 6,
          "removed_lines": 6
        },
        {
          "observed_at": "2026-08-14T23:51:22Z",
          "window_start": "2026-08-14T10:00:18Z",
          "window_end": "2026-08-14T23:51:22Z",
          "status": "capture-noise",
          "summary": "Only rotating sidebar article links, category hit counters and page-hit counters changed; the commentary text was unchanged.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 26,
          "removed_lines": 26
        },
        {
          "observed_at": "2026-08-14T10:00:18Z",
          "window_start": "2026-08-14T03:27:40Z",
          "window_end": "2026-08-14T10:00:18Z",
          "status": "capture-noise",
          "summary": "Only sidebar category counters, page-hit counters, and rotating related/recent post rails changed; the article body was unchanged.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 17,
          "removed_lines": 17
        },
        {
          "observed_at": "2026-08-14T03:27:40Z",
          "window_start": "2026-08-13T20:59:11Z",
          "window_end": "2026-08-14T03:27:40Z",
          "status": "capture-noise",
          "summary": "Only site chrome changed: sidebar article links and category hit counters rotated, with no change to the commentary text.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 21,
          "removed_lines": 21
        },
        {
          "observed_at": "2026-08-13T20:59:11Z",
          "window_start": "2026-08-13T14:30:09Z",
          "window_end": "2026-08-13T20:59:11Z",
          "status": "capture-noise",
          "summary": "Only site chrome changed: sidebar article links and category hit counters rotated, with no change to the commentary text.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 17,
          "removed_lines": 17
        },
        {
          "observed_at": "2026-08-13T14:30:09Z",
          "window_start": "2026-08-13T07:57:37Z",
          "window_end": "2026-08-13T14:30:09Z",
          "status": "capture-noise",
          "summary": "Only rotating related-content headlines and live category hit counters changed; the article body was unchanged.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 30,
          "removed_lines": 30
        },
        {
          "observed_at": "2026-08-13T07:57:37Z",
          "window_start": "2026-08-13T01:27:36Z",
          "window_end": "2026-08-13T07:57:37Z",
          "status": "capture-noise",
          "summary": "Only rotating sidebar article links and three page-hit counters changed; the commentary text was unchanged.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 6,
          "removed_lines": 6
        },
        {
          "observed_at": "2026-08-13T01:27:36Z",
          "window_start": "2026-08-12T18:27:49Z",
          "window_end": "2026-08-13T01:27:36Z",
          "status": "capture-noise",
          "summary": "Only rotating related-post cards and article hit counters changed; the commentary text was unchanged.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 6,
          "removed_lines": 6
        },
        {
          "observed_at": "2026-08-12T18:27:49Z",
          "window_start": "2026-08-12T11:57:48Z",
          "window_end": "2026-08-12T18:27:49Z",
          "status": "capture-noise",
          "summary": "Only category post counts, page-hit counters and rotating related-post rails changed; the commentary text was unchanged.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 21,
          "removed_lines": 21
        },
        {
          "observed_at": "2026-08-12T11:57:48Z",
          "window_start": "2026-08-12T05:11:18Z",
          "window_end": "2026-08-12T11:57:48Z",
          "status": "capture-noise",
          "summary": "Only rotating sidebar article links and live page-hit counters changed; the commentary text was unchanged.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 6,
          "removed_lines": 6
        },
        {
          "observed_at": "2026-08-12T05:11:18Z",
          "window_start": "2026-08-09T18:48:04Z",
          "window_end": "2026-08-12T05:11:18Z",
          "status": "capture-noise",
          "summary": "Only rotating sidebar story cards, category counts and page-hit counters changed; the article text was unchanged.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 35,
          "removed_lines": 35
        },
        {
          "observed_at": "2026-08-09T18:48:04Z",
          "window_start": "2026-08-09T12:02:31Z",
          "window_end": "2026-08-09T18:48:04Z",
          "status": "capture-noise",
          "summary": "Only rotating recommendation cards and No. of Hits counters in the sidebar changed; the commentary body was unchanged.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 5,
          "removed_lines": 5
        },
        {
          "observed_at": "2026-08-09T12:02:31Z",
          "window_start": "2026-08-09T05:30:41Z",
          "window_end": "2026-08-09T12:02:31Z",
          "status": "capture-noise",
          "summary": "Only the rotating related-content cards below the article and the page hit counters changed; the article text was unchanged.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 6,
          "removed_lines": 6
        },
        {
          "observed_at": "2026-08-09T05:30:41Z",
          "window_start": "2026-08-08T23:00:05Z",
          "window_end": "2026-08-09T05:30:41Z",
          "status": "capture-noise",
          "summary": "Only rotating related-story cards and page hit counters changed; the Coldcard commentary text was unchanged.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 6,
          "removed_lines": 6
        },
        {
          "observed_at": "2026-08-08T23:00:05Z",
          "window_start": "2026-08-08T16:27:37Z",
          "window_end": "2026-08-08T23:00:05Z",
          "status": "capture-noise",
          "summary": "Only rotating sidebar headline lists and page-view hit counters changed.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 6,
          "removed_lines": 6
        },
        {
          "observed_at": "2026-08-08T16:27:37Z",
          "window_start": "2026-08-08T09:56:35Z",
          "window_end": "2026-08-08T16:27:37Z",
          "status": "capture-noise",
          "summary": "Only rotating Related Posts cards, Recent Posts items and page hit counters changed; the Coldcard commentary text was unchanged.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 6,
          "removed_lines": 6
        },
        {
          "observed_at": "2026-08-08T09:56:35Z",
          "window_start": "2026-08-08T03:26:45Z",
          "window_end": "2026-08-08T09:56:35Z",
          "status": "capture-noise",
          "summary": "Only rotating related-article cards and page hit counters changed; the article text was unchanged.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 6,
          "removed_lines": 6
        },
        {
          "observed_at": "2026-08-08T03:26:45Z",
          "window_start": "2026-08-07T20:53:22Z",
          "window_end": "2026-08-08T03:26:45Z",
          "status": "capture-noise",
          "summary": "Only the site's related-posts rail and three unrelated article hit counters changed. The commentary body, including the secondhand Galaxy Research figures, is unchanged.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 6,
          "removed_lines": 6
        },
        {
          "observed_at": "2026-08-07T20:53:22Z",
          "window_start": "2026-08-07T14:24:27Z",
          "window_end": "2026-08-07T20:53:22Z",
          "status": "capture-noise",
          "summary": "Only sidebar related-content cards, category counters and hit counters changed; the article text was unchanged.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 30,
          "removed_lines": 30
        },
        {
          "observed_at": "2026-08-07T14:24:27Z",
          "window_start": "2026-08-06T16:40:44Z",
          "window_end": "2026-08-07T14:24:27Z",
          "status": "capture-noise",
          "summary": "Site chrome only: the Related Posts and Recent Posts cards rotated to newer articles, and category post counts plus page hit counters ticked up. The self-custody commentary article itself is unchanged.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 27,
          "removed_lines": 27
        },
        {
          "observed_at": "2026-08-06T16:40:44Z",
          "window_start": "2026-08-06T10:12:19Z",
          "window_end": "2026-08-06T16:40:44Z",
          "status": "capture-noise",
          "summary": "Rotating Related Posts cards and live hit counters changed again; the article body is unchanged.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 6,
          "removed_lines": 6
        },
        {
          "observed_at": "2026-08-06T10:12:19Z",
          "window_start": "2026-08-06T03:38:33Z",
          "window_end": "2026-08-06T10:12:19Z",
          "status": "capture-noise",
          "summary": "Rotating Related Posts cards and live hit counters changed; the article body is unchanged.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 6,
          "removed_lines": 6
        },
        {
          "observed_at": "2026-08-06T03:38:33Z",
          "window_start": "2026-08-05T21:09:15Z",
          "window_end": "2026-08-06T03:38:33Z",
          "status": "capture-noise",
          "summary": "Only unrelated linked-story cards and live hit counters changed; the commentary article text was unchanged.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 6,
          "removed_lines": 6
        },
        {
          "observed_at": "2026-08-05T21:09:15Z",
          "window_start": "2026-08-05T14:33:51Z",
          "window_end": "2026-08-05T21:09:15Z",
          "status": "capture-noise",
          "summary": "Rotating related-post cards, category counts and page hit counters changed. The Coldcard commentary itself did not change.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 23,
          "removed_lines": 23
        },
        {
          "observed_at": "2026-08-05T14:33:51Z",
          "window_start": "2026-08-05T08:04:41Z",
          "window_end": "2026-08-05T14:33:51Z",
          "status": "capture-noise",
          "summary": "Only rotating related-article cards and hit counters changed. The Coldcard commentary itself did not change.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 5,
          "removed_lines": 5
        },
        {
          "observed_at": "2026-08-05T08:04:41Z",
          "window_start": "2026-08-05T03:56:50Z",
          "window_end": "2026-08-05T08:04:41Z",
          "status": "capture-noise",
          "summary": "Only rotating sidebar links and live hit counters changed. The article text did not change.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 5,
          "removed_lines": 5
        }
      ]
    },
    {
      "id": "stackernews-dice-roll-computer-test",
      "title": "I wanted to test a coldcard's dice-roll generation against my computer's",
      "url": "https://stacker.news/items/1537388",
      "organisation": "Stacker News",
      "kind": "community-discussion",
      "role": "Community discussion",
      "publication_time": "2026-07-31",
      "note": "itsrealfake describing a personal test of a COLDCARD's dice-roll seed generation against the computer's randomness, posted the day after disclosure with the aside \"DYOR, and all that.\" The body carries no results and the thread has no comments so far; its value is documenting an owner independently checking device entropy in the incident's wake, by the same author as stackernews-rng-analysis-by-device, stackernews-dice-roll-sound and stackernews-entropy-technical-deep-dive. Any implied claims about dice-roll safety are the author's, not verified here. Captured through the site's public GraphQL API: the rendered pages crash the capture tab, and the API answers POST from this host. The query fixes the captured surface to the item's title, text and two levels of comments, each with author and absolute timestamp.\n",
      "gone": null,
      "capture": {
        "status": "held",
        "copies": 1,
        "first_observed": "2026-08-04T04:54:27Z",
        "last_observed": "2026-08-04T04:54:27Z",
        "last_checked": "2026-08-07T00:07:23Z"
      },
      "differences": []
    },
    {
      "id": "reddit-fixed-firmware-available",
      "title": "r/coldcard: relay of the 31 Jul 2026 fixed-firmware notice",
      "url": "https://www.reddit.com/r/coldcard/comments/1vboa9s/coldcard_update_fixed_firmware_now_available/",
      "organisation": "reddit",
      "kind": "community-discussion",
      "role": "Community discussion",
      "publication_time": null,
      "note": null,
      "gone": null,
      "capture": {
        "status": "held",
        "copies": 1,
        "first_observed": "2026-08-04T08:23:36Z",
        "last_observed": "2026-08-04T08:23:36Z",
        "last_checked": "2026-08-11T03:48:47Z"
      },
      "differences": []
    },
    {
      "id": "reddit-self-custody-last-straw",
      "title": "r/coldcard: owner renouncing self-custody after the incident",
      "url": "https://www.reddit.com/r/coldcard/comments/1vem5go/selfcustody_this_is_the_last_straw/",
      "organisation": "reddit",
      "kind": "community-discussion",
      "role": "Community discussion",
      "publication_time": null,
      "note": null,
      "gone": null,
      "capture": {
        "status": "held",
        "copies": 10,
        "first_observed": "2026-08-04T08:23:40Z",
        "last_observed": "2026-08-08T21:28:51Z",
        "last_checked": "2026-08-11T03:49:51Z"
      },
      "differences": [
        {
          "observed_at": "2026-08-08T21:28:51Z",
          "window_start": "2026-08-07T19:25:06Z",
          "window_end": "2026-08-08T21:28:51Z",
          "status": "source-content",
          "summary": "A participant comment renouncing self-custody for an IBIT/Schwab position was removed from the thread.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 0,
          "removed_lines": 10
        },
        {
          "observed_at": "2026-08-07T19:25:06Z",
          "window_start": "2026-08-07T12:52:27Z",
          "window_end": "2026-08-07T19:25:06Z",
          "status": "source-content",
          "summary": "The thread gained a comment arguing that ETF custody with beneficiary designation is preferable to self-custody for large sums.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 8,
          "removed_lines": 0
        },
        {
          "observed_at": "2026-08-07T12:52:27Z",
          "window_start": "2026-08-07T06:13:13Z",
          "window_end": "2026-08-07T12:52:27Z",
          "status": "source-content",
          "summary": "New comment from SnooCookies6165 considering spreading holdings across Coinbase, Schwab and Fidelity.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 8,
          "removed_lines": 0
        },
        {
          "observed_at": "2026-08-07T06:13:13Z",
          "window_start": "2026-08-06T16:29:22Z",
          "window_end": "2026-08-07T06:13:13Z",
          "status": "source-content",
          "summary": "New comment from NathanDrake-Blackops (in Italian) saying they moved from Ledger to Tangem and find it a good product.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 8,
          "removed_lines": 0
        },
        {
          "observed_at": "2026-08-06T16:29:22Z",
          "window_start": "2026-08-06T09:57:01Z",
          "window_end": "2026-08-06T16:29:22Z",
          "status": "source-content",
          "summary": "New comment from nyr00nyg asking what Coinbase uses to custody its own coins.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 8,
          "removed_lines": 0
        },
        {
          "observed_at": "2026-08-06T09:57:01Z",
          "window_start": "2026-08-04T18:10:46Z",
          "window_end": "2026-08-06T09:57:01Z",
          "status": "source-content",
          "summary": "New top-level comment from Necessary_Floor_7081 asking for reassurance that Mk3 seeds generated on firmware 3.9 are safe while waiting for a replacement wallet.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 15,
          "removed_lines": 0
        },
        {
          "observed_at": "2026-08-04T18:10:46Z",
          "window_start": "2026-08-04T16:42:37Z",
          "window_end": "2026-08-04T18:10:46Z",
          "status": "source-content",
          "summary": "The Reddit thread gained 1 new comment.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 16,
          "removed_lines": 0
        },
        {
          "observed_at": "2026-08-04T16:42:37Z",
          "window_start": "2026-08-04T13:40:26Z",
          "window_end": "2026-08-04T16:42:37Z",
          "status": "source-content",
          "summary": "1 new Reddit comment was posted, by Scissorhat, recounting reported exchange-account losses and reimbursement.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 14,
          "removed_lines": 0
        },
        {
          "observed_at": "2026-08-04T13:40:26Z",
          "window_start": "2026-08-04T08:23:40Z",
          "window_end": "2026-08-04T13:40:26Z",
          "status": "source-content",
          "summary": "4 new Reddit comments were posted, including snek-jazz,AcomaPueblo,corporate-citizen.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 48,
          "removed_lines": 0
        }
      ]
    },
    {
      "id": "reddit-price-mockery",
      "title": "r/coldcard: mockery of COLDCARD pricing after the incident",
      "url": "https://www.reddit.com/r/coldcard/comments/1veguk8/these_should_be_on_sale_for_20_whos_gonna_buy/",
      "organisation": "reddit",
      "kind": "community-discussion",
      "role": "Community discussion",
      "publication_time": null,
      "note": null,
      "gone": null,
      "capture": {
        "status": "held",
        "copies": 8,
        "first_observed": "2026-08-04T08:23:44Z",
        "last_observed": "2026-08-06T16:41:04Z",
        "last_checked": "2026-08-07T07:25:28Z"
      },
      "differences": [
        {
          "observed_at": "2026-08-06T16:41:04Z",
          "window_start": "2026-08-06T10:12:39Z",
          "window_end": "2026-08-06T16:41:04Z",
          "status": "source-content",
          "summary": "Reddit served 2 additional comment record(s); the diff preserves their text and any edits to existing records.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 20,
          "removed_lines": 0
        },
        {
          "observed_at": "2026-08-06T10:12:39Z",
          "window_start": "2026-08-06T03:39:10Z",
          "window_end": "2026-08-06T10:12:39Z",
          "status": "source-content",
          "summary": "Reddit served 2 additional comment record(s); the diff preserves their text and any edits to existing records.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 16,
          "removed_lines": 0
        },
        {
          "observed_at": "2026-08-06T03:39:10Z",
          "window_start": "2026-08-04T15:54:53Z",
          "window_end": "2026-08-06T03:39:10Z",
          "status": "source-content",
          "summary": "Reddit served 1 additional comment record(s); the diff preserves their text and any edits to existing records.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 8,
          "removed_lines": 0
        },
        {
          "observed_at": "2026-08-04T15:54:53Z",
          "window_start": "2026-08-04T15:22:26Z",
          "window_end": "2026-08-04T15:54:53Z",
          "status": "source-content",
          "summary": "1 new Reddit reply was posted, by cilicia3k3, responding to the reported device-access problem.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 8,
          "removed_lines": 0
        },
        {
          "observed_at": "2026-08-04T15:22:26Z",
          "window_start": "2026-08-04T14:52:06Z",
          "window_end": "2026-08-04T15:22:26Z",
          "status": "source-content",
          "summary": "1 new Reddit comment was posted, by ZICRON_ULTRA, describing difficulty moving funds after forgetting a device PIN and wallet-passphrase pairings.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 50,
          "removed_lines": 0
        },
        {
          "observed_at": "2026-08-04T14:52:06Z",
          "window_start": "2026-08-04T13:13:12Z",
          "window_end": "2026-08-04T14:52:06Z",
          "status": "source-content",
          "summary": "1 new Reddit comment was posted, by MysteriousAlpaco, suggesting reuse of device parts.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 8,
          "removed_lines": 0
        },
        {
          "observed_at": "2026-08-04T13:13:12Z",
          "window_start": "2026-08-04T08:23:44Z",
          "window_end": "2026-08-04T13:13:12Z",
          "status": "source-content",
          "summary": "1 new Reddit comment was posted, including cilicia3k3.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 8,
          "removed_lines": 0
        }
      ]
    },
    {
      "id": "reddit-dice-wallets-at-risk",
      "title": "r/coldcard: whether 100% dice-generated Mk4 wallets are at risk",
      "url": "https://www.reddit.com/r/coldcard/comments/1veixnw/coldcard_mk4_are_wallets_generated_with_100_dice/",
      "organisation": "reddit",
      "kind": "community-discussion",
      "role": "Community discussion",
      "publication_time": null,
      "note": null,
      "gone": null,
      "capture": {
        "status": "held",
        "copies": 8,
        "first_observed": "2026-08-04T08:23:47Z",
        "last_observed": "2026-08-08T01:55:34Z",
        "last_checked": "2026-08-11T03:50:54Z"
      },
      "differences": [
        {
          "observed_at": "2026-08-08T01:55:34Z",
          "window_start": "2026-08-07T12:52:32Z",
          "window_end": "2026-08-08T01:55:34Z",
          "status": "source-content",
          "summary": "The Reddit thread gained new participant comments about production test harnesses and moving to multi-sig.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 16,
          "removed_lines": 0
        },
        {
          "observed_at": "2026-08-07T12:52:32Z",
          "window_start": "2026-08-05T14:21:53Z",
          "window_end": "2026-08-07T12:52:32Z",
          "status": "source-content",
          "summary": "One new comment from Makunouchiipp0 warning readers not to trust their memory when doing dice rolls.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 8,
          "removed_lines": 0
        },
        {
          "observed_at": "2026-08-05T14:21:53Z",
          "window_start": "2026-08-04T17:11:05Z",
          "window_end": "2026-08-05T14:21:53Z",
          "status": "source-content",
          "summary": "Reddit served an additional comment asking whether there is a particular dice-roll method or guide to use when generating a wallet.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 8,
          "removed_lines": 0
        },
        {
          "observed_at": "2026-08-04T17:11:05Z",
          "window_start": "2026-08-04T16:42:42Z",
          "window_end": "2026-08-04T17:11:05Z",
          "status": "source-content",
          "summary": "The Reddit thread gained 2 new comments.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 20,
          "removed_lines": 0
        },
        {
          "observed_at": "2026-08-04T16:42:42Z",
          "window_start": "2026-08-04T15:11:24Z",
          "window_end": "2026-08-04T16:42:42Z",
          "status": "source-content",
          "summary": "2 new Reddit comments were posted, by Scissorhat and paulm95.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 18,
          "removed_lines": 0
        },
        {
          "observed_at": "2026-08-04T15:11:24Z",
          "window_start": "2026-08-04T13:40:31Z",
          "window_end": "2026-08-04T15:11:24Z",
          "status": "source-content",
          "summary": "4 new Reddit comments were posted, including didnt_hodl and _gianlucag_, discussing RNG certification and generating a seed elsewhere.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 39,
          "removed_lines": 0
        },
        {
          "observed_at": "2026-08-04T13:40:31Z",
          "window_start": "2026-08-04T08:23:47Z",
          "window_end": "2026-08-04T13:40:31Z",
          "status": "source-content",
          "summary": "1 new Reddit comment was posted, including WillemKadijk.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 8,
          "removed_lines": 0
        }
      ]
    },
    {
      "id": "reddit-q-repurpose",
      "title": "r/coldcard: repurposing the COLDCARD Q after the incident",
      "url": "https://www.reddit.com/r/coldcard/comments/1vex8hl/what_to_do_with_the_q_still_seems_like_a_cool/",
      "organisation": "reddit",
      "kind": "community-discussion",
      "role": "Community discussion",
      "publication_time": null,
      "note": null,
      "gone": null,
      "capture": {
        "status": "held",
        "copies": 15,
        "first_observed": "2026-08-04T08:23:52Z",
        "last_observed": "2026-08-05T21:09:39Z",
        "last_checked": "2026-08-07T07:26:37Z"
      },
      "differences": [
        {
          "observed_at": "2026-08-05T21:09:39Z",
          "window_start": "2026-08-05T14:34:19Z",
          "window_end": "2026-08-05T21:09:39Z",
          "status": "source-content",
          "summary": "Reddit served 2 additional comment record(s) and 1 previously held comment record(s) omitted; the diff preserves their text and any edits to existing records.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 16,
          "removed_lines": 8
        },
        {
          "observed_at": "2026-08-05T14:34:19Z",
          "window_start": "2026-08-05T08:05:07Z",
          "window_end": "2026-08-05T14:34:19Z",
          "status": "source-content",
          "summary": "Reddit served 2 additional comment record(s); the diff preserves their text and any edits to existing records.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 23,
          "removed_lines": 0
        },
        {
          "observed_at": "2026-08-05T08:05:07Z",
          "window_start": "2026-08-05T01:54:52Z",
          "window_end": "2026-08-05T08:05:07Z",
          "status": "source-content",
          "summary": "Reddit served 2 additional comment record(s); the diff preserves their text and any edits to existing records.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 16,
          "removed_lines": 0
        },
        {
          "observed_at": "2026-08-05T01:54:52Z",
          "window_start": "2026-08-04T22:55:52Z",
          "window_end": "2026-08-05T01:54:52Z",
          "status": "source-content",
          "summary": "The Reddit thread gained a reply suggesting an owner could avoid the issue by only receiving funds at the address.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 8,
          "removed_lines": 0
        },
        {
          "observed_at": "2026-08-04T22:55:52Z",
          "window_start": "2026-08-04T21:24:31Z",
          "window_end": "2026-08-04T22:55:52Z",
          "status": "source-content",
          "summary": "The Reddit thread gained a comment noting that repurposing a device does not create a safe key.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 8,
          "removed_lines": 0
        },
        {
          "observed_at": "2026-08-04T21:24:31Z",
          "window_start": "2026-08-04T19:54:12Z",
          "window_end": "2026-08-04T21:24:31Z",
          "status": "source-content",
          "summary": "The Reddit thread gained 1 new comment arguing that external entropy would still permit safe use for signing.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 12,
          "removed_lines": 0
        },
        {
          "observed_at": "2026-08-04T19:54:12Z",
          "window_start": "2026-08-04T17:53:25Z",
          "window_end": "2026-08-04T19:54:12Z",
          "status": "source-content",
          "summary": "The Reddit thread gained 1 new comment.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 8,
          "removed_lines": 0
        },
        {
          "observed_at": "2026-08-04T17:53:25Z",
          "window_start": "2026-08-04T16:55:06Z",
          "window_end": "2026-08-04T17:53:25Z",
          "status": "source-content",
          "summary": "The Reddit thread gained 2 new comments.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 16,
          "removed_lines": 0
        },
        {
          "observed_at": "2026-08-04T16:55:06Z",
          "window_start": "2026-08-04T15:22:31Z",
          "window_end": "2026-08-04T16:55:06Z",
          "status": "source-content",
          "summary": "The Reddit thread gained 1 new comment.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 8,
          "removed_lines": 0
        },
        {
          "observed_at": "2026-08-04T15:22:31Z",
          "window_start": "2026-08-04T12:42:15Z",
          "window_end": "2026-08-04T15:22:31Z",
          "status": "source-content",
          "summary": "1 new Reddit comment was posted, by Thin_Needleworker795, joking about repurposing the device.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 8,
          "removed_lines": 0
        },
        {
          "observed_at": "2026-08-04T12:42:15Z",
          "window_start": "2026-08-04T12:13:10Z",
          "window_end": "2026-08-04T12:42:15Z",
          "status": "source-content",
          "summary": "One new comment was posted: F1shB0wl816, still using their Mk4 and seeing no reason to drop it.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 8,
          "removed_lines": 0
        },
        {
          "observed_at": "2026-08-04T12:13:10Z",
          "window_start": "2026-08-04T10:41:40Z",
          "window_end": "2026-08-04T12:13:10Z",
          "status": "source-content",
          "summary": "One new comment was posted: newMoneyStyle joking about playing Pokemon Red on a COLDCARD Q.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 8,
          "removed_lines": 0
        },
        {
          "observed_at": "2026-08-04T10:41:40Z",
          "window_start": "2026-08-04T10:12:55Z",
          "window_end": "2026-08-04T10:41:40Z",
          "status": "source-content",
          "summary": "One new comment was posted: Intelligent_Map_246, saying the Q is one of few devices that can create a dice-roll seed directly airgapped and that signed transactions should be fine.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 8,
          "removed_lines": 0
        },
        {
          "observed_at": "2026-08-04T10:12:55Z",
          "window_start": "2026-08-04T08:23:52Z",
          "window_end": "2026-08-04T10:12:55Z",
          "status": "source-content",
          "summary": "One new top-level comment was posted: GreemBeam p1m2n7n, saying they will likely keep using the device once the code gets more scrutiny and that a strong passphrase alone is relatively decent.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 10,
          "removed_lines": 0
        }
      ]
    },
    {
      "id": "reddit-am-i-affected-dice",
      "title": "r/coldcard: owner exposure self-assessment (dice seed, dice passphrase)",
      "url": "https://www.reddit.com/r/coldcard/comments/1vewq6y/am_i_affected/",
      "organisation": "reddit",
      "kind": "community-discussion",
      "role": "Community discussion",
      "publication_time": null,
      "note": null,
      "gone": null,
      "capture": {
        "status": "held",
        "copies": 9,
        "first_observed": "2026-08-04T08:24:09Z",
        "last_observed": "2026-08-07T12:52:37Z",
        "last_checked": "2026-08-11T03:51:57Z"
      },
      "differences": [
        {
          "observed_at": "2026-08-07T12:52:37Z",
          "window_start": "2026-08-06T16:29:32Z",
          "window_end": "2026-08-07T12:52:37Z",
          "status": "source-content",
          "summary": "The poster Individual_Gate9375 deleted their account content: the original post body and two of their own comments (describing their dice-only seed setup and their January 2021 conclusion they were unaffected) now show [deleted].",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 2,
          "removed_lines": 22
        },
        {
          "observed_at": "2026-08-06T16:29:32Z",
          "window_start": "2026-08-05T07:53:45Z",
          "window_end": "2026-08-06T16:29:32Z",
          "status": "source-content",
          "summary": "One new comment by Javanaut018 suggests the poster can probably just update firmware and keep using the device.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 8,
          "removed_lines": 0
        },
        {
          "observed_at": "2026-08-05T07:53:45Z",
          "window_start": "2026-08-04T22:43:38Z",
          "window_end": "2026-08-05T07:53:45Z",
          "status": "source-content",
          "summary": "The thread gained a discussion distinguishing added dice rolls from a dice-only seed, with the original poster saying they used the latter and created their seed before the reported affected firmware window.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 21,
          "removed_lines": 0
        },
        {
          "observed_at": "2026-08-04T22:43:38Z",
          "window_start": "2026-08-04T21:42:39Z",
          "window_end": "2026-08-04T22:43:38Z",
          "status": "source-content",
          "summary": "The Reddit thread gained 1 new comment distinguishing dice input from other possible device vulnerabilities.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 8,
          "removed_lines": 0
        },
        {
          "observed_at": "2026-08-04T21:42:39Z",
          "window_start": "2026-08-04T19:42:31Z",
          "window_end": "2026-08-04T21:42:39Z",
          "status": "source-content",
          "summary": "The Reddit thread gained 1 new comment about seed generation before the affected firmware release.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 8,
          "removed_lines": 0
        },
        {
          "observed_at": "2026-08-04T19:42:31Z",
          "window_start": "2026-08-04T16:42:50Z",
          "window_end": "2026-08-04T19:42:31Z",
          "status": "source-content",
          "summary": "The Reddit thread gained 1 new comment.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 8,
          "removed_lines": 0
        },
        {
          "observed_at": "2026-08-04T16:42:50Z",
          "window_start": "2026-08-04T13:40:36Z",
          "window_end": "2026-08-04T16:42:50Z",
          "status": "source-content",
          "summary": "2 new Reddit comments were posted, including an offer to help using a 16-digit invoice ID.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 16,
          "removed_lines": 0
        },
        {
          "observed_at": "2026-08-04T13:40:36Z",
          "window_start": "2026-08-04T08:24:09Z",
          "window_end": "2026-08-04T13:40:36Z",
          "status": "source-content",
          "summary": "5 new Reddit comments were posted, including Silent_Ad_9963,JunketTurbulent2114,grraarr.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 48,
          "removed_lines": 0
        }
      ]
    },
    {
      "id": "reddit-bricked-mid-transfer",
      "title": "r/coldcard: device reported bricked mid-transfer during migration",
      "url": "https://www.reddit.com/r/coldcard/comments/1veg5t9/device_bricked_while_transferring/",
      "organisation": "reddit",
      "kind": "community-discussion",
      "role": "Community discussion",
      "publication_time": null,
      "note": null,
      "gone": null,
      "capture": {
        "status": "held",
        "copies": 7,
        "first_observed": "2026-08-04T08:25:15Z",
        "last_observed": "2026-08-05T14:34:24Z",
        "last_checked": "2026-08-07T07:27:46Z"
      },
      "differences": [
        {
          "observed_at": "2026-08-05T14:34:24Z",
          "window_start": "2026-08-04T23:31:36Z",
          "window_end": "2026-08-05T14:34:24Z",
          "status": "source-content",
          "summary": "Reddit served 2 additional comment record(s); the diff preserves their text and any edits to existing records.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 18,
          "removed_lines": 0
        },
        {
          "observed_at": "2026-08-04T23:31:36Z",
          "window_start": "2026-08-04T22:25:05Z",
          "window_end": "2026-08-04T23:31:36Z",
          "status": "source-content",
          "summary": "The Reddit thread gained new participant comments.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 10,
          "removed_lines": 0
        },
        {
          "observed_at": "2026-08-04T22:25:05Z",
          "window_start": "2026-08-04T13:52:12Z",
          "window_end": "2026-08-04T22:25:05Z",
          "status": "source-content",
          "summary": "The Reddit thread gained 1 new comment alleging recurring device-bricking problems.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 8,
          "removed_lines": 0
        },
        {
          "observed_at": "2026-08-04T13:52:12Z",
          "window_start": "2026-08-04T13:13:22Z",
          "window_end": "2026-08-04T13:52:12Z",
          "status": "source-content",
          "summary": "1 new Reddit comment was posted, including xirvin.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 13,
          "removed_lines": 0
        },
        {
          "observed_at": "2026-08-04T13:13:22Z",
          "window_start": "2026-08-04T12:42:20Z",
          "window_end": "2026-08-04T13:13:22Z",
          "status": "source-content",
          "summary": "1 new Reddit comment was posted, including newMoneyStyle.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 8,
          "removed_lines": 0
        },
        {
          "observed_at": "2026-08-04T12:42:20Z",
          "window_start": "2026-08-04T08:25:15Z",
          "window_end": "2026-08-04T12:42:20Z",
          "status": "source-content",
          "summary": "Two new comments were posted by Soft-Spring9843: disputing that the bricking report is separate from the RNG bug, and saying Casa does not allow transferring a seed to Sparrow.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 16,
          "removed_lines": 0
        }
      ]
    },
    {
      "id": "reddit-do-not-dispose-device",
      "title": "r/coldcard: advice not to dispose of affected devices",
      "url": "https://www.reddit.com/r/coldcard/comments/1ve8hve/do_not_dispose_of_affected_device/",
      "organisation": "reddit",
      "kind": "community-discussion",
      "role": "Community discussion",
      "publication_time": null,
      "note": null,
      "gone": null,
      "capture": {
        "status": "held",
        "copies": 7,
        "first_observed": "2026-08-04T08:24:16Z",
        "last_observed": "2026-08-08T21:29:06Z",
        "last_checked": "2026-08-11T03:53:00Z"
      },
      "differences": [
        {
          "observed_at": "2026-08-08T21:29:06Z",
          "window_start": "2026-08-08T14:59:06Z",
          "window_end": "2026-08-08T21:29:06Z",
          "status": "source-content",
          "summary": "The thread gained a new comment about the legal standing of non-Canadian victims relative to Canadian nationals.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 8,
          "removed_lines": 0
        },
        {
          "observed_at": "2026-08-08T14:59:06Z",
          "window_start": "2026-08-06T09:57:16Z",
          "window_end": "2026-08-08T14:59:06Z",
          "status": "source-content",
          "summary": "The thread gained a new comment saying that transaction history will make funds easy to verify.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 8,
          "removed_lines": 0
        },
        {
          "observed_at": "2026-08-06T09:57:16Z",
          "window_start": "2026-08-06T03:26:02Z",
          "window_end": "2026-08-06T09:57:16Z",
          "status": "source-content",
          "summary": "A comment by DonTheHolder accusing another user of lying about funds being safe was removed from the thread.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 0,
          "removed_lines": 12
        },
        {
          "observed_at": "2026-08-06T03:26:02Z",
          "window_start": "2026-08-05T20:56:55Z",
          "window_end": "2026-08-06T03:26:02Z",
          "status": "source-content",
          "summary": "Reddit added a comment asserting that money can be clawed back.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 8,
          "removed_lines": 0
        },
        {
          "observed_at": "2026-08-05T20:56:55Z",
          "window_start": "2026-08-04T13:40:41Z",
          "window_end": "2026-08-05T20:56:55Z",
          "status": "source-content",
          "summary": "Reddit added a comment comparing the device-preservation issue with the Celsius case.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 8,
          "removed_lines": 0
        },
        {
          "observed_at": "2026-08-04T13:40:41Z",
          "window_start": "2026-08-04T08:24:16Z",
          "window_end": "2026-08-04T13:40:41Z",
          "status": "source-content",
          "summary": "1 new Reddit comment was posted, including kawfeeman68.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 8,
          "removed_lines": 0
        }
      ]
    },
    {
      "id": "reddit-ceo-resign-calls",
      "title": "r/coldcard: calls for the Coinkite CEO to resign",
      "url": "https://www.reddit.com/r/coldcard/comments/1vdvs4w/coinkite_ceo_rodolfo_novak_needs_to_resign/",
      "organisation": "reddit",
      "kind": "community-discussion",
      "role": "Community discussion",
      "publication_time": null,
      "note": null,
      "gone": null,
      "capture": {
        "status": "held",
        "copies": 3,
        "first_observed": "2026-08-04T08:24:19Z",
        "last_observed": "2026-08-08T01:55:49Z",
        "last_checked": "2026-08-11T03:54:03Z"
      },
      "differences": [
        {
          "observed_at": "2026-08-08T01:55:49Z",
          "window_start": "2026-08-04T23:16:36Z",
          "window_end": "2026-08-08T01:55:49Z",
          "status": "source-content",
          "summary": "The Reddit thread gained a new participant comment stating a 3 BTC loss.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 8,
          "removed_lines": 0
        },
        {
          "observed_at": "2026-08-04T23:16:36Z",
          "window_start": "2026-08-04T08:24:19Z",
          "window_end": "2026-08-04T23:16:36Z",
          "status": "source-content",
          "summary": "The Reddit thread gained new participant comments.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 8,
          "removed_lines": 0
        }
      ]
    },
    {
      "id": "reddit-phishing-advisory-email",
      "title": "r/coldcard: phishing security-advisory email from a lookalike domain",
      "url": "https://www.reddit.com/r/coldcard/comments/1vefd28/got_a_security_advisory_email_from/",
      "organisation": "reddit",
      "kind": "community-discussion",
      "role": "Community discussion",
      "publication_time": null,
      "note": null,
      "gone": null,
      "capture": {
        "status": "held",
        "copies": 1,
        "first_observed": "2026-08-04T08:25:19Z",
        "last_observed": "2026-08-04T08:25:19Z",
        "last_checked": "2026-08-07T07:28:54Z"
      },
      "differences": []
    },
    {
      "id": "reddit-codebase-practices-critique",
      "title": "r/coldcard: critique of the COLDCARD codebase and development practices",
      "url": "https://www.reddit.com/r/coldcard/comments/1vdrbxo/if_your_coldcard_isnt_in_the_trash_already_read/",
      "organisation": "reddit",
      "kind": "community-discussion",
      "role": "Community discussion",
      "publication_time": null,
      "note": null,
      "gone": null,
      "capture": {
        "status": "held",
        "copies": 2,
        "first_observed": "2026-08-04T13:40:52Z",
        "last_observed": "2026-08-04T15:11:44Z",
        "last_checked": "2026-08-11T13:05:18Z"
      },
      "differences": [
        {
          "observed_at": "2026-08-04T15:11:44Z",
          "window_start": "2026-08-04T13:40:52Z",
          "window_end": "2026-08-04T15:11:44Z",
          "status": "source-content",
          "summary": "1 new Reddit comment was posted, by MysteriousAlpaco, criticizing the codebase and testing practices.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 8,
          "removed_lines": 0
        }
      ]
    },
    {
      "id": "reddit-vendor-counterfactual",
      "title": "r/coldcard: what Coinkite could have done had it found the flaw first",
      "url": "https://www.reddit.com/r/coldcard/comments/1vduxyg/what_could_coinkite_have_done_if_they_discovered/",
      "organisation": "reddit",
      "kind": "community-discussion",
      "role": "Community discussion",
      "publication_time": null,
      "note": null,
      "gone": null,
      "capture": {
        "status": "held",
        "copies": 6,
        "first_observed": "2026-08-04T08:36:54Z",
        "last_observed": "2026-08-08T01:55:59Z",
        "last_checked": "2026-08-11T03:56:09Z"
      },
      "differences": [
        {
          "observed_at": "2026-08-08T01:55:59Z",
          "window_start": "2026-08-07T06:13:42Z",
          "window_end": "2026-08-08T01:55:59Z",
          "status": "source-content",
          "summary": "The Reddit thread gained a new participant comment proposing whitehat self-sweep or closed-source migration as vendor options.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 12,
          "removed_lines": 0
        },
        {
          "observed_at": "2026-08-07T06:13:42Z",
          "window_start": "2026-08-06T16:29:55Z",
          "window_end": "2026-08-07T06:13:42Z",
          "status": "source-content",
          "summary": "New comment says the author no longer excludes the retirement attack scenario.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 8,
          "removed_lines": 0
        },
        {
          "observed_at": "2026-08-06T16:29:55Z",
          "window_start": "2026-08-04T19:11:37Z",
          "window_end": "2026-08-06T16:29:55Z",
          "status": "source-content",
          "summary": "One comment was edited (typo fix in the dice-roll weakness explanation) and a new comment argues it is game over once a seed-generation entropy weakness is whispered about.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 10,
          "removed_lines": 2
        },
        {
          "observed_at": "2026-08-04T19:11:37Z",
          "window_start": "2026-08-04T13:40:57Z",
          "window_end": "2026-08-04T19:11:37Z",
          "status": "source-content",
          "summary": "The Reddit thread gained 1 new comment.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 8,
          "removed_lines": 0
        },
        {
          "observed_at": "2026-08-04T13:40:57Z",
          "window_start": "2026-08-04T08:36:54Z",
          "window_end": "2026-08-04T13:40:57Z",
          "status": "source-content",
          "summary": "1 new Reddit comment was posted, including iloverunning11.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 8,
          "removed_lines": 0
        }
      ]
    },
    {
      "id": "reddit-weak-passphrase-multisig-warning",
      "title": "r/coldcard: warning to weak-passphrase and 2-of-3 multisig users",
      "url": "https://www.reddit.com/r/coldcard/comments/1vdw84n/if_you_used_a_weak_passphrase_or_if_you_used_23/",
      "organisation": "reddit",
      "kind": "community-discussion",
      "role": "Community discussion",
      "publication_time": null,
      "note": null,
      "gone": null,
      "capture": {
        "status": "held",
        "copies": 1,
        "first_observed": "2026-08-04T08:36:59Z",
        "last_observed": "2026-08-04T08:36:59Z",
        "last_checked": "2026-08-11T03:57:13Z"
      },
      "differences": []
    },
    {
      "id": "reddit-saved-my-stack-thanks",
      "title": "r/coldcard: owner crediting the subreddit with saving their coins",
      "url": "https://www.reddit.com/r/coldcard/comments/1vdnbk3/big_ups_to_this_sub_you_all_saved_my_stack/",
      "organisation": "reddit",
      "kind": "community-discussion",
      "role": "Community discussion",
      "publication_time": null,
      "note": null,
      "gone": null,
      "capture": {
        "status": "held",
        "copies": 3,
        "first_observed": "2026-08-04T08:37:06Z",
        "last_observed": "2026-08-06T16:41:23Z",
        "last_checked": "2026-08-07T07:30:03Z"
      },
      "differences": [
        {
          "observed_at": "2026-08-06T16:41:23Z",
          "window_start": "2026-08-04T22:56:08Z",
          "window_end": "2026-08-06T16:41:23Z",
          "status": "source-content",
          "summary": "Reddit served 1 additional comment record(s); the diff preserves their text and any edits to existing records.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 8,
          "removed_lines": 0
        },
        {
          "observed_at": "2026-08-04T22:56:08Z",
          "window_start": "2026-08-04T08:37:06Z",
          "window_end": "2026-08-04T22:56:08Z",
          "status": "source-content",
          "summary": "The Reddit thread gained a thank-you from a participant who cancelled two pending COLDCARD orders.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 8,
          "removed_lines": 0
        }
      ]
    },
    {
      "id": "reddit-device-useful-if-company-closes",
      "title": "r/coldcard: whether the devices stay useful if Coinkite closes",
      "url": "https://www.reddit.com/r/coldcard/comments/1ve3vnu/is_coldcard_still_useful_if_the_company_closes/",
      "organisation": "reddit",
      "kind": "community-discussion",
      "role": "Community discussion",
      "publication_time": null,
      "note": null,
      "gone": null,
      "capture": {
        "status": "held",
        "copies": 5,
        "first_observed": "2026-08-04T08:37:12Z",
        "last_observed": "2026-08-08T14:59:29Z",
        "last_checked": "2026-08-11T03:58:16Z"
      },
      "differences": [
        {
          "observed_at": "2026-08-08T14:59:29Z",
          "window_start": "2026-08-06T09:57:40Z",
          "window_end": "2026-08-08T14:59:29Z",
          "status": "source-content",
          "summary": "The thread gained two new comments: one offering to buy the poster's Q and pay shipping in bitcoin, and the reply declining and saying the device will be kept as memorabilia.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 16,
          "removed_lines": 0
        },
        {
          "observed_at": "2026-08-06T09:57:40Z",
          "window_start": "2026-08-04T14:41:02Z",
          "window_end": "2026-08-06T09:57:40Z",
          "status": "source-content",
          "summary": "One new comment: user AntZealousideal3728 reports they updated the firmware and moved funds to a new wallet without issue.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 8,
          "removed_lines": 0
        },
        {
          "observed_at": "2026-08-04T14:41:02Z",
          "window_start": "2026-08-04T13:41:07Z",
          "window_end": "2026-08-04T14:41:02Z",
          "status": "source-content",
          "summary": "1 new Reddit comment was posted, including KitchenTop1820.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 8,
          "removed_lines": 0
        },
        {
          "observed_at": "2026-08-04T13:41:07Z",
          "window_start": "2026-08-04T08:37:12Z",
          "window_end": "2026-08-04T13:41:07Z",
          "status": "source-content",
          "summary": "1 new Reddit comment was posted, including RedReadRedemption.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 8,
          "removed_lines": 0
        }
      ]
    },
    {
      "id": "reddit-shipments-halted-relay",
      "title": "r/coldcard: relay of the shipments-halted announcement",
      "url": "https://www.reddit.com/r/coldcard/comments/1vdpnza/they_halted_shipments_of_coldcards_and_destroyed/",
      "organisation": "reddit",
      "kind": "community-discussion",
      "role": "Community discussion",
      "publication_time": null,
      "note": null,
      "gone": null,
      "capture": {
        "status": "held",
        "copies": 10,
        "first_observed": "2026-08-04T08:37:17Z",
        "last_observed": "2026-08-09T23:19:10Z",
        "last_checked": "2026-08-11T03:59:19Z"
      },
      "differences": [
        {
          "observed_at": "2026-08-09T23:19:10Z",
          "window_start": "2026-08-08T14:59:34Z",
          "window_end": "2026-08-09T23:19:10Z",
          "status": "source-content",
          "summary": "The thread gained a comment blaming nvk for not giving the incident enough attention.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 8,
          "removed_lines": 0
        },
        {
          "observed_at": "2026-08-08T14:59:34Z",
          "window_start": "2026-08-07T06:13:56Z",
          "window_end": "2026-08-08T14:59:34Z",
          "status": "source-content",
          "summary": "The thread gained several new comments, including one calling the halt 'rats deserting a sinking ship', an exchange asking whether another poster is defending CoinKite, and a cost-based explanation for destroying compromised stock.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 42,
          "removed_lines": 0
        },
        {
          "observed_at": "2026-08-07T06:13:56Z",
          "window_start": "2026-08-06T16:30:11Z",
          "window_end": "2026-08-07T06:13:56Z",
          "status": "source-content",
          "summary": "Two new comments: Knowledge775 wants a refund over destroyed inventory, and AntZealousideal3728 says the post should be taken down because affected devices, not remaining inventory, were destroyed and their cancelled order still arrived.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 16,
          "removed_lines": 0
        },
        {
          "observed_at": "2026-08-06T16:30:11Z",
          "window_start": "2026-08-06T09:57:45Z",
          "window_end": "2026-08-06T16:30:11Z",
          "status": "source-content",
          "summary": "Two new comments: a laughing reaction from Luiz4823, and Clean_Earth1587 calling Coldcard junk and recommending Trezor.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 16,
          "removed_lines": 0
        },
        {
          "observed_at": "2026-08-06T09:57:45Z",
          "window_start": "2026-08-05T20:57:24Z",
          "window_end": "2026-08-06T09:57:45Z",
          "status": "source-content",
          "summary": "New comment from AntZealousideal3728 saying they were lucky to have cancelled their order before it shipped.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 8,
          "removed_lines": 0
        },
        {
          "observed_at": "2026-08-05T20:57:24Z",
          "window_start": "2026-08-05T07:54:19Z",
          "window_end": "2026-08-05T20:57:24Z",
          "status": "source-content",
          "summary": "A commenter edited a refund request, removing the order reference while keeping the request for all pending orders to be refunded.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 3,
          "removed_lines": 3
        },
        {
          "observed_at": "2026-08-05T07:54:19Z",
          "window_start": "2026-08-04T20:13:21Z",
          "window_end": "2026-08-05T07:54:19Z",
          "status": "source-content",
          "summary": "The thread gained a reply questioning how migration assistance could help people whose coins were already gone.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 10,
          "removed_lines": 0
        },
        {
          "observed_at": "2026-08-04T20:13:21Z",
          "window_start": "2026-08-04T16:43:28Z",
          "window_end": "2026-08-04T20:13:21Z",
          "status": "source-content",
          "summary": "The Reddit thread gained 1 new comment.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 8,
          "removed_lines": 0
        },
        {
          "observed_at": "2026-08-04T16:43:28Z",
          "window_start": "2026-08-04T08:37:17Z",
          "window_end": "2026-08-04T16:43:28Z",
          "status": "source-content",
          "summary": "An existing Reddit comment no longer appeared in the captured thread.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 0,
          "removed_lines": 8
        }
      ]
    },
    {
      "id": "reddit-still-using-coldcard",
      "title": "r/coldcard: poll on continued COLDCARD use after the incident",
      "url": "https://www.reddit.com/r/coldcard/comments/1vdnfov/still_using_coldcard/",
      "organisation": "reddit",
      "kind": "community-discussion",
      "role": "Community discussion",
      "publication_time": null,
      "note": null,
      "gone": null,
      "capture": {
        "status": "held",
        "copies": 5,
        "first_observed": "2026-08-04T08:37:23Z",
        "last_observed": "2026-08-07T06:14:01Z",
        "last_checked": "2026-08-11T04:00:22Z"
      },
      "differences": [
        {
          "observed_at": "2026-08-07T06:14:01Z",
          "window_start": "2026-08-06T03:26:38Z",
          "window_end": "2026-08-07T06:14:01Z",
          "status": "source-content",
          "summary": "Three new comments: two from shoebertdoubert (mocking the OP's reluctance to switch and calling a reply insane cope) and a profanity-laced reaction from FeedSeparate.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 26,
          "removed_lines": 0
        },
        {
          "observed_at": "2026-08-06T03:26:38Z",
          "window_start": "2026-08-05T14:22:40Z",
          "window_end": "2026-08-06T03:26:38Z",
          "status": "source-content",
          "summary": "Reddit added a commenter saying they would not use their COLDCARD devices again.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 8,
          "removed_lines": 0
        },
        {
          "observed_at": "2026-08-05T14:22:40Z",
          "window_start": "2026-08-05T07:54:24Z",
          "window_end": "2026-08-05T14:22:40Z",
          "status": "source-content",
          "summary": "Reddit served an additional comment suggesting methods for selecting passphrase words randomly and making strength claims about six, eight and twelve-word passphrases.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 14,
          "removed_lines": 0
        },
        {
          "observed_at": "2026-08-05T07:54:24Z",
          "window_start": "2026-08-04T08:37:23Z",
          "window_end": "2026-08-05T07:54:24Z",
          "status": "source-content",
          "summary": "The poll thread gained comments advocating a non-word passphrase and saying 300 dice rolls kept funds safe, while retaining the device only as a signing tool.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 16,
          "removed_lines": 0
        }
      ]
    },
    {
      "id": "reddit-dice-consensus-nontechnical",
      "title": "r/coldcard: dice-roll seed generation for non-technical owners",
      "url": "https://www.reddit.com/r/coldcard/comments/1vdu01y/so_whats_the_consensus_now_with_regular_folks_non/",
      "organisation": "reddit",
      "kind": "community-discussion",
      "role": "Community discussion",
      "publication_time": null,
      "note": null,
      "gone": null,
      "capture": {
        "status": "held",
        "copies": 2,
        "first_observed": "2026-08-04T08:37:29Z",
        "last_observed": "2026-08-05T08:05:25Z",
        "last_checked": "2026-08-07T07:31:12Z"
      },
      "differences": [
        {
          "observed_at": "2026-08-05T08:05:25Z",
          "window_start": "2026-08-04T08:37:29Z",
          "window_end": "2026-08-05T08:05:25Z",
          "status": "source-content",
          "summary": "Fields within an existing Reddit post or comment changed; the diff preserves the exact served text.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 2,
          "removed_lines": 2
        }
      ]
    },
    {
      "id": "reddit-mk4-dice-seed-safety",
      "title": "r/coldcard: safety of Mk4 dice-generated seeds, and alternatives",
      "url": "https://www.reddit.com/r/coldcard/comments/1vdge71/is_it_safe_to_use_mk4_for_creation_of_seed_using/",
      "organisation": "reddit",
      "kind": "community-discussion",
      "role": "Community discussion",
      "publication_time": null,
      "note": null,
      "gone": null,
      "capture": {
        "status": "held",
        "copies": 2,
        "first_observed": "2026-08-04T08:37:34Z",
        "last_observed": "2026-08-07T06:14:06Z",
        "last_checked": "2026-08-11T04:01:25Z"
      },
      "differences": [
        {
          "observed_at": "2026-08-07T06:14:06Z",
          "window_start": "2026-08-04T08:37:34Z",
          "window_end": "2026-08-07T06:14:06Z",
          "status": "source-content",
          "summary": "Two comments by Warrior_witha_Garden disappeared: one body replaced with [removed] and account shown as [deleted], the other dropped from the listing. The removed text had claimed all Coldcards are unsafe and urged moving to Seed Signer or Tails and Electrum.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 2,
          "removed_lines": 10
        }
      ]
    },
    {
      "id": "reddit-discount-mockery",
      "title": "r/coldcard: mockery expecting fire-sale pricing",
      "url": "https://www.reddit.com/r/coldcard/comments/1vdslbj/when_will_the_deep_discounts_be_available/",
      "organisation": "reddit",
      "kind": "community-discussion",
      "role": "Community discussion",
      "publication_time": null,
      "note": null,
      "gone": null,
      "capture": {
        "status": "held",
        "copies": 2,
        "first_observed": "2026-08-04T08:37:40Z",
        "last_observed": "2026-08-06T10:13:07Z",
        "last_checked": "2026-08-07T07:32:21Z"
      },
      "differences": [
        {
          "observed_at": "2026-08-06T10:13:07Z",
          "window_start": "2026-08-04T08:37:40Z",
          "window_end": "2026-08-06T10:13:07Z",
          "status": "source-content",
          "summary": "Reddit served 1 previously held comment record(s) omitted; the diff preserves their text and any edits to existing records.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 0,
          "removed_lines": 9
        }
      ]
    },
    {
      "id": "reddit-multisig-migration-plan",
      "title": "r/coldcard: worked example of a mixed-vendor multisig migration",
      "url": "https://www.reddit.com/r/coldcard/comments/1vdqypo/good_personal_coldcard_solution/",
      "organisation": "reddit",
      "kind": "community-discussion",
      "role": "Community discussion",
      "publication_time": null,
      "note": null,
      "gone": null,
      "capture": {
        "status": "held",
        "copies": 1,
        "first_observed": "2026-08-04T08:37:46Z",
        "last_observed": "2026-08-04T08:37:46Z",
        "last_checked": "2026-08-07T07:33:29Z"
      },
      "differences": []
    },
    {
      "id": "reddit-coinkite-next-steps",
      "title": "r/coldcard: speculation on Coinkite's next steps",
      "url": "https://www.reddit.com/r/coldcard/comments/1vd5f5h/coinkite_next_steps/",
      "organisation": "reddit",
      "kind": "community-discussion",
      "role": "Community discussion",
      "publication_time": null,
      "note": null,
      "gone": null,
      "capture": {
        "status": "held",
        "copies": 6,
        "first_observed": "2026-08-04T08:37:51Z",
        "last_observed": "2026-08-09T04:02:18Z",
        "last_checked": "2026-08-11T04:02:28Z"
      },
      "differences": [
        {
          "observed_at": "2026-08-09T04:02:18Z",
          "window_start": "2026-08-08T21:29:52Z",
          "window_end": "2026-08-09T04:02:18Z",
          "status": "source-content",
          "summary": "One short dismissive comment was removed from the thread.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 0,
          "removed_lines": 8
        },
        {
          "observed_at": "2026-08-08T21:29:52Z",
          "window_start": "2026-08-08T14:59:50Z",
          "window_end": "2026-08-08T21:29:52Z",
          "status": "source-content",
          "summary": "The thread gained a new comment arguing the previous analogy was unnecessary and the point stood on its own.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 8,
          "removed_lines": 0
        },
        {
          "observed_at": "2026-08-08T14:59:50Z",
          "window_start": "2026-08-07T19:26:10Z",
          "window_end": "2026-08-08T14:59:50Z",
          "status": "source-content",
          "summary": "An existing comment's author and body were deleted and replaced with [deleted] markers, and the thread gained two new comments, one calling the deleted comment the top comment and another comparing the safety claim to a restaurant where the food is safe only if you do not eat there.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 20,
          "removed_lines": 2
        },
        {
          "observed_at": "2026-08-07T19:26:10Z",
          "window_start": "2026-08-04T15:12:18Z",
          "window_end": "2026-08-07T19:26:10Z",
          "status": "source-content",
          "summary": "The thread gained a short dismissive reply.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 8,
          "removed_lines": 0
        },
        {
          "observed_at": "2026-08-04T15:12:18Z",
          "window_start": "2026-08-04T08:37:51Z",
          "window_end": "2026-08-04T15:12:18Z",
          "status": "source-content",
          "summary": "3 new Reddit comments were posted, all by Solid_Wolverine1639, discussing punishment, seedless wallets and audits.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 24,
          "removed_lines": 0
        }
      ]
    },
    {
      "id": "reddit-still-use-the-cc",
      "title": "r/coldcard: owners weighing continued use of the device",
      "url": "https://www.reddit.com/r/coldcard/comments/1vdhmw4/still_use_the_cc/",
      "organisation": "reddit",
      "kind": "community-discussion",
      "role": "Community discussion",
      "publication_time": null,
      "note": null,
      "gone": null,
      "capture": {
        "status": "held",
        "copies": 3,
        "first_observed": "2026-08-04T08:37:58Z",
        "last_observed": "2026-08-05T14:22:56Z",
        "last_checked": "2026-08-11T04:03:31Z"
      },
      "differences": [
        {
          "observed_at": "2026-08-05T14:22:56Z",
          "window_start": "2026-08-04T13:41:33Z",
          "window_end": "2026-08-05T14:22:56Z",
          "status": "source-content",
          "summary": "Reddit served an additional comment asking for a recommendation.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 8,
          "removed_lines": 0
        },
        {
          "observed_at": "2026-08-04T13:41:33Z",
          "window_start": "2026-08-04T08:37:58Z",
          "window_end": "2026-08-04T13:41:33Z",
          "status": "source-content",
          "summary": "1 new Reddit comment was posted, including Intelligent_Map_246.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 8,
          "removed_lines": 0
        }
      ]
    },
    {
      "id": "reddit-new-firmware-safety",
      "title": "r/coldcard: whether the fixed firmware can be trusted",
      "url": "https://www.reddit.com/r/coldcard/comments/1vdoxxf/is_the_new_firmware_safe/",
      "organisation": "reddit",
      "kind": "community-discussion",
      "role": "Community discussion",
      "publication_time": null,
      "note": null,
      "gone": null,
      "capture": {
        "status": "held",
        "copies": 2,
        "first_observed": "2026-08-04T08:38:04Z",
        "last_observed": "2026-08-05T00:14:25Z",
        "last_checked": "2026-08-11T04:04:34Z"
      },
      "differences": [
        {
          "observed_at": "2026-08-05T00:14:25Z",
          "window_start": "2026-08-04T08:38:04Z",
          "window_end": "2026-08-05T00:14:25Z",
          "status": "source-content",
          "summary": "The Reddit thread gained comments about unanswered questions and trust in signing hardware.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 18,
          "removed_lines": 0
        }
      ]
    },
    {
      "id": "reddit-mk4-bricked-hotfix",
      "title": "r/coldcard: report of a Mk4 bricked by the emergency firmware hotfix",
      "url": "https://www.reddit.com/r/coldcard/comments/1vct6m2/psa_coldcard_mk4_bricked_by_the_new_emergency/",
      "organisation": "reddit",
      "kind": "community-discussion",
      "role": "Community discussion",
      "publication_time": null,
      "note": null,
      "gone": null,
      "capture": {
        "status": "held",
        "copies": 14,
        "first_observed": "2026-08-04T08:45:58Z",
        "last_observed": "2026-08-09T16:49:17Z",
        "last_checked": "2026-08-11T04:05:37Z"
      },
      "differences": [
        {
          "observed_at": "2026-08-09T16:49:17Z",
          "window_start": "2026-08-09T10:32:19Z",
          "window_end": "2026-08-09T16:49:17Z",
          "status": "source-content",
          "summary": "Two new comments were added: one argues the hotfix bricking is triggered by the hardware RNG randomizing keyboard scan order on each press, and the poster confirms this is unintended and links the pull requests containing the fix.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 18,
          "removed_lines": 0
        },
        {
          "observed_at": "2026-08-09T10:32:19Z",
          "window_start": "2026-08-09T04:02:33Z",
          "window_end": "2026-08-09T10:32:19Z",
          "status": "source-content",
          "summary": "The thread gained two comments: one arguing third-party developers might not notice the TRNG failure, and another by the original poster explaining that keyboard-press randomization using the hardware RNG can soft-brick the device.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 24,
          "removed_lines": 0
        },
        {
          "observed_at": "2026-08-09T04:02:33Z",
          "window_start": "2026-08-08T21:30:08Z",
          "window_end": "2026-08-09T04:02:33Z",
          "status": "source-content",
          "summary": "A new comment links to Damien George's MicroPython postmortem and attributes the bricking to a LibNgU macro check error.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 10,
          "removed_lines": 0
        },
        {
          "observed_at": "2026-08-08T21:30:08Z",
          "window_start": "2026-08-07T12:53:41Z",
          "window_end": "2026-08-08T21:30:08Z",
          "status": "source-content",
          "summary": "The thread gained a new comment reporting an auto-blocked post about firmware bricking and asking what actions passphrase users should avoid.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 12,
          "removed_lines": 0
        },
        {
          "observed_at": "2026-08-07T12:53:41Z",
          "window_start": "2026-08-07T06:14:25Z",
          "window_end": "2026-08-07T12:53:41Z",
          "status": "source-content",
          "summary": "Three new comments: lucapocchio confirming the bricking bug can still occur until a fix ships in a version like 5.6.1, zatsnotmyname saying the workaround works, and nicolbolas10 asking whether others are staying on Coldcard or moving funds.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 24,
          "removed_lines": 0
        },
        {
          "observed_at": "2026-08-07T06:14:25Z",
          "window_start": "2026-08-06T09:58:15Z",
          "window_end": "2026-08-07T06:14:25Z",
          "status": "source-content",
          "summary": "New comment by nicolbolas10 reporting a first-hand recurrence: an Mk4 on firmware 5.6.0 bricked after six days, then recovered after 30 minutes, asking whether the bug can still happen.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 8,
          "removed_lines": 0
        },
        {
          "observed_at": "2026-08-06T09:58:15Z",
          "window_start": "2026-08-06T03:27:04Z",
          "window_end": "2026-08-06T09:58:15Z",
          "status": "source-content",
          "summary": "Three comments by DonTheHolder disappeared: one body replaced with [removed] and the account shown as [deleted], two others dropped from the listing entirely. The removed text had argued for leaving hardware wallets for CEX or ETF custody.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 2,
          "removed_lines": 26
        },
        {
          "observed_at": "2026-08-06T03:27:04Z",
          "window_start": "2026-08-05T20:57:56Z",
          "window_end": "2026-08-06T03:27:04Z",
          "status": "source-content",
          "summary": "Reddit added a comment attributing the reported hotfix failure to absent regression testing.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 8,
          "removed_lines": 0
        },
        {
          "observed_at": "2026-08-05T20:57:56Z",
          "window_start": "2026-08-05T14:23:07Z",
          "window_end": "2026-08-05T20:57:56Z",
          "status": "source-content",
          "summary": "Reddit added comments debating COLDCARD's source-verifiable licence, how the RNG defect might have been found, and moving funds generated with dice entropy.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 88,
          "removed_lines": 0
        },
        {
          "observed_at": "2026-08-05T14:23:07Z",
          "window_start": "2026-08-04T20:43:29Z",
          "window_end": "2026-08-05T14:23:07Z",
          "status": "source-content",
          "summary": "Reddit served an additional comment asking for clarification of the thread's claim that the device is not open source.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 8,
          "removed_lines": 0
        },
        {
          "observed_at": "2026-08-04T20:43:29Z",
          "window_start": "2026-08-04T20:13:56Z",
          "window_end": "2026-08-04T20:43:29Z",
          "status": "source-content",
          "summary": "The Reddit post was updated with the poster’s later device-recovery account and linked official report.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 69,
          "removed_lines": 5
        },
        {
          "observed_at": "2026-08-04T20:13:56Z",
          "window_start": "2026-08-04T13:41:42Z",
          "window_end": "2026-08-04T20:13:56Z",
          "status": "source-content",
          "summary": "The Reddit post was updated with the poster’s later device-recovery account and linked official report.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 10,
          "removed_lines": 1
        },
        {
          "observed_at": "2026-08-04T13:41:42Z",
          "window_start": "2026-08-04T08:45:58Z",
          "window_end": "2026-08-04T13:41:42Z",
          "status": "source-content",
          "summary": "3 new Reddit comments were posted, including Christianlutz89,lucapocchio,PopCham.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 28,
          "removed_lines": 0
        }
      ]
    },
    {
      "id": "reddit-ccq-multisig-safety",
      "title": "r/coldcard: whether a COLDCARD Q remains safe in a multisig setup",
      "url": "https://www.reddit.com/r/coldcard/comments/1vdlxgc/so_you_think_is_still_safe_to_use_the_ccq_for_a/",
      "organisation": "reddit",
      "kind": "community-discussion",
      "role": "Community discussion",
      "publication_time": null,
      "note": null,
      "gone": null,
      "capture": {
        "status": "held",
        "copies": 2,
        "first_observed": "2026-08-04T08:46:02Z",
        "last_observed": "2026-08-05T14:34:53Z",
        "last_checked": "2026-08-07T07:34:38Z"
      },
      "differences": [
        {
          "observed_at": "2026-08-05T14:34:53Z",
          "window_start": "2026-08-04T08:46:02Z",
          "window_end": "2026-08-05T14:34:53Z",
          "status": "source-content",
          "summary": "Reddit served 1 additional comment record(s); the diff preserves their text and any edits to existing records.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 8,
          "removed_lines": 0
        }
      ]
    },
    {
      "id": "reddit-coinkite-solvency-class-action",
      "title": "r/coldcard: Coinkite solvency and class-action speculation",
      "url": "https://www.reddit.com/r/coldcard/comments/1vcs0o4/anyone_who_thinks_coinkite_will_remain_solvent/",
      "organisation": "reddit",
      "kind": "community-discussion",
      "role": "Community discussion",
      "publication_time": null,
      "note": null,
      "gone": null,
      "capture": {
        "status": "held",
        "copies": 6,
        "first_observed": "2026-08-04T08:46:05Z",
        "last_observed": "2026-08-08T15:00:10Z",
        "last_checked": "2026-08-11T04:06:46Z"
      },
      "differences": [
        {
          "observed_at": "2026-08-08T15:00:10Z",
          "window_start": "2026-08-06T09:58:21Z",
          "window_end": "2026-08-08T15:00:10Z",
          "status": "source-content",
          "summary": "The thread gained two new comments: one asking whether the poster inspected the open-source COLDCARD code or is just repeating what others say, and a reply explaining that the commenter uses their own air-gapped Python scripts instead of hardware wallets.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 22,
          "removed_lines": 0
        },
        {
          "observed_at": "2026-08-06T09:58:21Z",
          "window_start": "2026-08-05T20:58:02Z",
          "window_end": "2026-08-06T09:58:21Z",
          "status": "source-content",
          "summary": "New comment by Outrageous-Lab-2138: \"Amazing that a single line of code caused all this.\"",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 8,
          "removed_lines": 0
        },
        {
          "observed_at": "2026-08-05T20:58:02Z",
          "window_start": "2026-08-05T07:54:54Z",
          "window_end": "2026-08-05T20:58:02Z",
          "status": "source-content",
          "summary": "Reddit added a comment characterising the discussion as another example of C-suite hubris.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 8,
          "removed_lines": 0
        },
        {
          "observed_at": "2026-08-05T07:54:54Z",
          "window_start": "2026-08-04T13:41:47Z",
          "window_end": "2026-08-05T07:54:54Z",
          "status": "source-content",
          "summary": "The thread gained a reply speculating that the incident was deliberate.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 8,
          "removed_lines": 0
        },
        {
          "observed_at": "2026-08-04T13:41:47Z",
          "window_start": "2026-08-04T08:46:05Z",
          "window_end": "2026-08-04T13:41:47Z",
          "status": "source-content",
          "summary": "1 new Reddit comment was posted, including magma_lakes.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 10,
          "removed_lines": 0
        }
      ]
    },
    {
      "id": "reddit-nfc-press-dice-seed",
      "title": "r/coldcard: accidental NFC button press during dice-only seed generation",
      "url": "https://www.reddit.com/r/coldcard/comments/1vdbi6e/accidental_nfc_button_press_during_diceonly_seed/",
      "organisation": "reddit",
      "kind": "community-discussion",
      "role": "Community discussion",
      "publication_time": null,
      "note": null,
      "gone": null,
      "capture": {
        "status": "held",
        "copies": 1,
        "first_observed": "2026-08-04T08:46:09Z",
        "last_observed": "2026-08-04T08:46:09Z",
        "last_checked": "2026-08-07T07:35:47Z"
      },
      "differences": []
    },
    {
      "id": "reddit-coinkite-done-for",
      "title": "r/coldcard: argument that Coinkite will not survive the incident",
      "url": "https://www.reddit.com/r/coldcard/comments/1vcfugv/coinkite_is_done_for_here_is_why/",
      "organisation": "reddit",
      "kind": "community-discussion",
      "role": "Community discussion",
      "publication_time": null,
      "note": null,
      "gone": null,
      "capture": {
        "status": "held",
        "copies": 6,
        "first_observed": "2026-08-04T08:46:12Z",
        "last_observed": "2026-08-08T01:56:53Z",
        "last_checked": "2026-08-11T04:07:49Z"
      },
      "differences": [
        {
          "observed_at": "2026-08-08T01:56:53Z",
          "window_start": "2026-08-06T03:27:15Z",
          "window_end": "2026-08-08T01:56:53Z",
          "status": "source-content",
          "summary": "The Reddit thread gained a new participant comment arguing that open-source security review failed to catch the vulnerability.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 8,
          "removed_lines": 0
        },
        {
          "observed_at": "2026-08-06T03:27:15Z",
          "window_start": "2026-08-05T20:58:07Z",
          "window_end": "2026-08-06T03:27:15Z",
          "status": "source-content",
          "summary": "Reddit added comments alleging that Coinkite personnel were responsible and should face prison, including an unsupported allegation about its CFO.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 16,
          "removed_lines": 0
        },
        {
          "observed_at": "2026-08-05T20:58:07Z",
          "window_start": "2026-08-04T15:42:37Z",
          "window_end": "2026-08-05T20:58:07Z",
          "status": "source-content",
          "summary": "Reddit added comments about a Bitcoin price prediction and using dice rolls to test deterministic seed generation.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 34,
          "removed_lines": 0
        },
        {
          "observed_at": "2026-08-04T15:42:37Z",
          "window_start": "2026-08-04T13:41:53Z",
          "window_end": "2026-08-04T15:42:37Z",
          "status": "source-content",
          "summary": "An existing Reddit comment was replaced by the platform's deleted-user and deleted-comment placeholders.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 2,
          "removed_lines": 2
        },
        {
          "observed_at": "2026-08-04T13:41:53Z",
          "window_start": "2026-08-04T08:46:12Z",
          "window_end": "2026-08-04T13:41:53Z",
          "status": "source-content",
          "summary": "1 new Reddit comment was posted, including davidcwilliams.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 8,
          "removed_lines": 0
        }
      ]
    },
    {
      "id": "reddit-key-teleport-dice-claim",
      "title": "r/coldcard: claim that key teleport exposes even dice-generated seeds",
      "url": "https://www.reddit.com/r/coldcard/comments/1vcwf2y/yasmarang/",
      "organisation": "reddit",
      "kind": "community-discussion",
      "role": "Community discussion",
      "publication_time": null,
      "note": null,
      "gone": null,
      "capture": {
        "status": "held",
        "copies": 1,
        "first_observed": "2026-08-04T08:46:17Z",
        "last_observed": "2026-08-04T08:46:17Z",
        "last_checked": "2026-08-07T07:36:56Z"
      },
      "differences": []
    },
    {
      "id": "reddit-firmware-audit-history",
      "title": "r/coldcard: who audited the firmware over the last five years",
      "url": "https://www.reddit.com/r/coldcard/comments/1vchr6s/who_has_audited_those_firmwares_for_the_last_5/",
      "organisation": "reddit",
      "kind": "community-discussion",
      "role": "Community discussion",
      "publication_time": null,
      "note": null,
      "gone": null,
      "capture": {
        "status": "held",
        "copies": 6,
        "first_observed": "2026-08-04T08:46:20Z",
        "last_observed": "2026-08-05T07:55:04Z",
        "last_checked": "2026-08-11T04:08:52Z"
      },
      "differences": [
        {
          "observed_at": "2026-08-05T07:55:04Z",
          "window_start": "2026-08-05T01:44:52Z",
          "window_end": "2026-08-05T07:55:04Z",
          "status": "source-content",
          "summary": "The thread gained a reply attributing the alleged review gap to COLDCARD's source-verifiable licensing model, lack of bounties and Rodolfo Novak, which are the commenter's own assertions.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 14,
          "removed_lines": 0
        },
        {
          "observed_at": "2026-08-05T01:44:52Z",
          "window_start": "2026-08-04T23:44:31Z",
          "window_end": "2026-08-05T01:44:52Z",
          "status": "source-content",
          "summary": "The Reddit thread gained a reply questioning how many people reviewed the source code and criticizing the absence of bug bounties.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 8,
          "removed_lines": 0
        },
        {
          "observed_at": "2026-08-04T23:44:31Z",
          "window_start": "2026-08-04T18:43:39Z",
          "window_end": "2026-08-04T23:44:31Z",
          "status": "source-content",
          "summary": "The Reddit thread gained new participant comments.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 0,
          "removed_lines": 8
        },
        {
          "observed_at": "2026-08-04T18:43:39Z",
          "window_start": "2026-08-04T13:41:59Z",
          "window_end": "2026-08-04T18:43:39Z",
          "status": "source-content",
          "summary": "The Reddit thread gained 1 new comment.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 8,
          "removed_lines": 0
        },
        {
          "observed_at": "2026-08-04T13:41:59Z",
          "window_start": "2026-08-04T08:46:20Z",
          "window_end": "2026-08-04T13:41:59Z",
          "status": "source-content",
          "summary": "1 new Reddit comment was posted, including Makunouchiipp0.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 8,
          "removed_lines": 0
        }
      ]
    },
    {
      "id": "reddit-pre-window-passphrase-safety",
      "title": "r/coldcard: whether pre-window seeds with a passphrase are safe",
      "url": "https://www.reddit.com/r/coldcard/comments/1vct25y/seeds_created_before_the_march_2021_and_using_a/",
      "organisation": "reddit",
      "kind": "community-discussion",
      "role": "Community discussion",
      "publication_time": null,
      "note": null,
      "gone": null,
      "capture": {
        "status": "held",
        "copies": 1,
        "first_observed": "2026-08-04T08:46:23Z",
        "last_observed": "2026-08-04T08:46:23Z",
        "last_checked": "2026-08-11T04:09:55Z"
      },
      "differences": []
    },
    {
      "id": "reddit-cake-wallet-precedent",
      "title": "r/coldcard: Cake Wallet 2020/2021 entropy flaw cited as precedent",
      "url": "https://www.reddit.com/r/coldcard/comments/1vcsqxw/the_coldcard_situation_is_nothing_new_cake_wallet/",
      "organisation": "reddit",
      "kind": "community-discussion",
      "role": "Community discussion",
      "publication_time": null,
      "note": null,
      "gone": null,
      "capture": {
        "status": "held",
        "copies": 1,
        "first_observed": "2026-08-04T08:50:52Z",
        "last_observed": "2026-08-04T08:50:52Z",
        "last_checked": "2026-08-07T07:38:04Z"
      },
      "differences": []
    },
    {
      "id": "reddit-1-6m-cad-drained",
      "title": "r/coldcard: first-hand report of a 1.6M CAD drain",
      "url": "https://www.reddit.com/r/coldcard/comments/1vc9kxd/16m_cad_drained/",
      "organisation": "reddit",
      "kind": "community-discussion",
      "role": "Community discussion",
      "publication_time": null,
      "note": null,
      "gone": null,
      "capture": {
        "status": "held",
        "copies": 2,
        "first_observed": "2026-08-04T08:46:30Z",
        "last_observed": "2026-08-04T13:42:09Z",
        "last_checked": "2026-08-11T04:10:58Z"
      },
      "differences": [
        {
          "observed_at": "2026-08-04T13:42:09Z",
          "window_start": "2026-08-04T08:46:30Z",
          "window_end": "2026-08-04T13:42:09Z",
          "status": "source-content",
          "summary": "3 new Reddit comments were posted, including Mission-Disaster-447,SpendHefty6066.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 24,
          "removed_lines": 0
        }
      ]
    },
    {
      "id": "reddit-passphrase-save-mk3",
      "title": "r/coldcard: whether a 25th word passphrase protects Mk3 users",
      "url": "https://www.reddit.com/r/coldcard/comments/1vcpdux/will_having_a_25th_word_passphrase_save_mk3_users/",
      "organisation": "reddit",
      "kind": "community-discussion",
      "role": "Community discussion",
      "publication_time": null,
      "note": null,
      "gone": null,
      "capture": {
        "status": "held",
        "copies": 1,
        "first_observed": "2026-08-04T08:46:34Z",
        "last_observed": "2026-08-04T08:46:34Z",
        "last_checked": "2026-08-11T04:12:01Z"
      },
      "differences": []
    },
    {
      "id": "reddit-user-entropy-options",
      "title": "r/coldcard: call for more user-entropy options in COLDCARD",
      "url": "https://www.reddit.com/r/coldcard/comments/1vcr9uo/time_for_cold_card_to_implement_more_user_entropy/",
      "organisation": "reddit",
      "kind": "community-discussion",
      "role": "Community discussion",
      "publication_time": null,
      "note": null,
      "gone": null,
      "capture": {
        "status": "held",
        "copies": 3,
        "first_observed": "2026-08-04T09:01:07Z",
        "last_observed": "2026-08-07T12:54:17Z",
        "last_checked": "2026-08-11T04:13:04Z"
      },
      "differences": [
        {
          "observed_at": "2026-08-07T12:54:17Z",
          "window_start": "2026-08-04T13:42:18Z",
          "window_end": "2026-08-07T12:54:17Z",
          "status": "source-content",
          "summary": "New comment reports that a user-entropy option is already in progress, linking Coldcard firmware GitHub pull request 707.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 10,
          "removed_lines": 0
        },
        {
          "observed_at": "2026-08-04T13:42:18Z",
          "window_start": "2026-08-04T09:01:07Z",
          "window_end": "2026-08-04T13:42:18Z",
          "status": "source-content",
          "summary": "2 new Reddit comments were posted, including Interesting-Gear-992,CornFly2014.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 18,
          "removed_lines": 0
        }
      ]
    },
    {
      "id": "reddit-wallet-drained-mk3",
      "title": "r/coldcard: first-hand report of an Mk3 wallet drained mid-migration",
      "url": "https://www.reddit.com/r/coldcard/comments/1vbzvf1/wallet_drained/",
      "organisation": "reddit",
      "kind": "community-discussion",
      "role": "Community discussion",
      "publication_time": null,
      "note": null,
      "gone": null,
      "capture": {
        "status": "held",
        "copies": 3,
        "first_observed": "2026-08-04T09:01:11Z",
        "last_observed": "2026-08-05T14:23:49Z",
        "last_checked": "2026-08-11T04:14:07Z"
      },
      "differences": [
        {
          "observed_at": "2026-08-05T14:23:49Z",
          "window_start": "2026-08-04T13:42:24Z",
          "window_end": "2026-08-05T14:23:49Z",
          "status": "source-content",
          "summary": "Reddit served an additional comment criticising COLDCARD users and recommending a different hardware-wallet brand.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 8,
          "removed_lines": 0
        },
        {
          "observed_at": "2026-08-04T13:42:24Z",
          "window_start": "2026-08-04T09:01:11Z",
          "window_end": "2026-08-04T13:42:24Z",
          "status": "source-content",
          "summary": "1 new Reddit comment was posted, including na3than.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 8,
          "removed_lines": 0
        }
      ]
    },
    {
      "id": "reddit-still-trust-coinkite",
      "title": "r/coldcard: whether owners still trust Coinkite",
      "url": "https://www.reddit.com/r/coldcard/comments/1vc9jqu/do_you_guys_still_trust_coinkite/",
      "organisation": "reddit",
      "kind": "community-discussion",
      "role": "Community discussion",
      "publication_time": null,
      "note": null,
      "gone": null,
      "capture": {
        "status": "held",
        "copies": 5,
        "first_observed": "2026-08-04T09:01:16Z",
        "last_observed": "2026-08-07T19:27:10Z",
        "last_checked": "2026-08-11T04:15:10Z"
      },
      "differences": [
        {
          "observed_at": "2026-08-07T19:27:10Z",
          "window_start": "2026-08-07T06:15:10Z",
          "window_end": "2026-08-07T19:27:10Z",
          "status": "source-content",
          "summary": "The thread gained two comments from the same participant arguing that trusting Coinkite after the incident would be irrational.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 18,
          "removed_lines": 0
        },
        {
          "observed_at": "2026-08-07T06:15:10Z",
          "window_start": "2026-08-06T16:31:26Z",
          "window_end": "2026-08-07T06:15:10Z",
          "status": "source-content",
          "summary": "New comment from Outrageous-Lab-2138 attributing the incident to a one-line error, #ifndef vs #if 0, costing hundreds of millions.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 12,
          "removed_lines": 0
        },
        {
          "observed_at": "2026-08-06T16:31:26Z",
          "window_start": "2026-08-05T07:55:33Z",
          "window_end": "2026-08-06T16:31:26Z",
          "status": "source-content",
          "summary": "Flowa-Powa edited their comment, correcting \"broken usb reader\" to \"broken SD card reader\" and trimming trailing whitespace.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 4,
          "removed_lines": 4
        },
        {
          "observed_at": "2026-08-05T07:55:33Z",
          "window_start": "2026-08-04T09:01:16Z",
          "window_end": "2026-08-05T07:55:33Z",
          "status": "source-content",
          "summary": "The thread gained a personal account alleging loss of a Coinkite exchange balance in 2016 and citing historical terms, followed by the author's distrust of the company and self-custody.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 34,
          "removed_lines": 0
        }
      ]
    },
    {
      "id": "reddit-safe-after-reseed",
      "title": "r/coldcard: whether a dice-rolled reseed on updated firmware is safe",
      "url": "https://www.reddit.com/r/coldcard/comments/1vc9la8/are_we_safe_after_updating_firmware_and/",
      "organisation": "reddit",
      "kind": "community-discussion",
      "role": "Community discussion",
      "publication_time": null,
      "note": null,
      "gone": null,
      "capture": {
        "status": "held",
        "copies": 3,
        "first_observed": "2026-08-04T09:01:20Z",
        "last_observed": "2026-08-07T19:27:16Z",
        "last_checked": "2026-08-11T04:16:14Z"
      },
      "differences": [
        {
          "observed_at": "2026-08-07T19:27:16Z",
          "window_start": "2026-08-04T14:42:32Z",
          "window_end": "2026-08-07T19:27:16Z",
          "status": "source-content",
          "summary": "The thread gained a comment suggesting a repurposed COLDCARD could be used as a seed generator or password manager instead of being discarded.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 8,
          "removed_lines": 0
        },
        {
          "observed_at": "2026-08-04T14:42:32Z",
          "window_start": "2026-08-04T09:01:20Z",
          "window_end": "2026-08-04T14:42:32Z",
          "status": "source-content",
          "summary": "7 new Reddit comments were posted, including Solid_Wolverine1639.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 64,
          "removed_lines": 0
        }
      ]
    },
    {
      "id": "reddit-coldcard-just-drained-rug",
      "title": "r/coldcard: venting thread accusing Coinkite of rugging its users",
      "url": "https://www.reddit.com/r/coldcard/comments/1vcai63/coldcard_just_drained_you_guys/",
      "organisation": "reddit",
      "kind": "community-discussion",
      "role": "Community discussion",
      "publication_time": null,
      "note": null,
      "gone": null,
      "capture": {
        "status": "held",
        "copies": 6,
        "first_observed": "2026-08-04T09:01:24Z",
        "last_observed": "2026-08-06T10:13:34Z",
        "last_checked": "2026-08-07T07:39:13Z"
      },
      "differences": [
        {
          "observed_at": "2026-08-06T10:13:34Z",
          "window_start": "2026-08-05T08:05:58Z",
          "window_end": "2026-08-06T10:13:34Z",
          "status": "source-content",
          "summary": "Reddit served 1 previously held comment record(s) omitted; the diff preserves their text and any edits to existing records.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 0,
          "removed_lines": 8
        },
        {
          "observed_at": "2026-08-05T08:05:58Z",
          "window_start": "2026-08-05T01:55:44Z",
          "window_end": "2026-08-05T08:05:58Z",
          "status": "source-content",
          "summary": "Reddit served 1 additional comment record(s); the diff preserves their text and any edits to existing records.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 8,
          "removed_lines": 0
        },
        {
          "observed_at": "2026-08-05T01:55:44Z",
          "window_start": "2026-08-04T22:56:49Z",
          "window_end": "2026-08-05T01:55:44Z",
          "status": "source-content",
          "summary": "The Reddit thread gained a reply expressing doubt about an earlier claim.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 8,
          "removed_lines": 0
        },
        {
          "observed_at": "2026-08-04T22:56:49Z",
          "window_start": "2026-08-04T15:56:09Z",
          "window_end": "2026-08-04T22:56:49Z",
          "status": "source-content",
          "summary": "The Reddit thread gained new participant comments.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 8,
          "removed_lines": 0
        },
        {
          "observed_at": "2026-08-04T15:56:09Z",
          "window_start": "2026-08-04T09:01:24Z",
          "window_end": "2026-08-04T15:56:09Z",
          "status": "source-content",
          "summary": "1 new Reddit comment was posted, by Highheat_10.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 8,
          "removed_lines": 0
        }
      ]
    },
    {
      "id": "reddit-device-repurpose",
      "title": "r/coldcard: repurposing COLDCARD hardware after the incident",
      "url": "https://www.reddit.com/r/coldcard/comments/1vckh2n/device_repurpose/",
      "organisation": "reddit",
      "kind": "community-discussion",
      "role": "Community discussion",
      "publication_time": null,
      "note": null,
      "gone": null,
      "capture": {
        "status": "held",
        "copies": 2,
        "first_observed": "2026-08-04T09:01:28Z",
        "last_observed": "2026-08-04T22:26:00Z",
        "last_checked": "2026-08-07T07:40:22Z"
      },
      "differences": [
        {
          "observed_at": "2026-08-04T22:26:00Z",
          "window_start": "2026-08-04T09:01:28Z",
          "window_end": "2026-08-04T22:26:00Z",
          "status": "source-content",
          "summary": "The Reddit thread gained 2 new comments about retaining the device for transaction signing.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 16,
          "removed_lines": 0
        }
      ]
    },
    {
      "id": "reddit-dice-rolls-trust",
      "title": "r/coldcard: whether the device can be trusted to honour dice rolls",
      "url": "https://www.reddit.com/r/coldcard/comments/1vc55eb/trust_issues/",
      "organisation": "reddit",
      "kind": "community-discussion",
      "role": "Community discussion",
      "publication_time": null,
      "note": null,
      "gone": null,
      "capture": {
        "status": "held",
        "copies": 3,
        "first_observed": "2026-08-04T09:01:31Z",
        "last_observed": "2026-08-04T21:14:45Z",
        "last_checked": "2026-08-11T04:17:17Z"
      },
      "differences": [
        {
          "observed_at": "2026-08-04T21:14:45Z",
          "window_start": "2026-08-04T20:14:57Z",
          "window_end": "2026-08-04T21:14:45Z",
          "status": "source-content",
          "summary": "The Reddit thread gained 1 new comment.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 8,
          "removed_lines": 0
        },
        {
          "observed_at": "2026-08-04T20:14:57Z",
          "window_start": "2026-08-04T09:01:31Z",
          "window_end": "2026-08-04T20:14:57Z",
          "status": "source-content",
          "summary": "The Reddit thread gained 1 new comment.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 10,
          "removed_lines": 0
        }
      ]
    },
    {
      "id": "reddit-untouched-mk3-migration",
      "title": "r/coldcard: owner of an untouched five-year-old Mk3 seeking migration guidance",
      "url": "https://www.reddit.com/r/coldcard/comments/1vbyb2s/i_havent_touch_my_cc_mk3_in_5_years_help_please/",
      "organisation": "reddit",
      "kind": "community-discussion",
      "role": "Community discussion",
      "publication_time": null,
      "note": null,
      "gone": null,
      "capture": {
        "status": "held",
        "copies": 1,
        "first_observed": "2026-08-04T09:01:35Z",
        "last_observed": "2026-08-04T09:01:35Z",
        "last_checked": "2026-08-07T07:41:31Z"
      },
      "differences": []
    },
    {
      "id": "reddit-seed-generation-check",
      "title": "r/coldcard: how to tell whether a seed came from the faulty RNG",
      "url": "https://www.reddit.com/r/coldcard/comments/1vc3sqk/is_there_a_way_to_know_if_your_seed_phrase_was/",
      "organisation": "reddit",
      "kind": "community-discussion",
      "role": "Community discussion",
      "publication_time": null,
      "note": null,
      "gone": null,
      "capture": {
        "status": "held",
        "copies": 1,
        "first_observed": "2026-08-04T09:01:39Z",
        "last_observed": "2026-08-04T09:01:39Z",
        "last_checked": "2026-08-11T04:18:20Z"
      },
      "differences": []
    },
    {
      "id": "reddit-mk4-added-rolls-safety",
      "title": "r/coldcard: whether an Mk4 5.1.2 seed with 100 added rolls is safe",
      "url": "https://www.reddit.com/r/coldcard/comments/1vbvade/mk4_512_seed_safe_with_100_added_rolls/",
      "organisation": "reddit",
      "kind": "community-discussion",
      "role": "Community discussion",
      "publication_time": null,
      "note": null,
      "gone": null,
      "capture": {
        "status": "held",
        "copies": 1,
        "first_observed": "2026-08-06T03:59:31Z",
        "last_observed": "2026-08-06T03:59:31Z",
        "last_checked": "2026-08-12T23:56:04Z"
      },
      "differences": []
    },
    {
      "id": "reddit-where-to-transfer",
      "title": "r/coldcard: where to move bitcoin after the exploit",
      "url": "https://www.reddit.com/r/coldcard/comments/1vbmuet/now_that_coldcard_is_exploitable_where_to/",
      "organisation": "reddit",
      "kind": "community-discussion",
      "role": "Community discussion",
      "publication_time": null,
      "note": null,
      "gone": null,
      "capture": {
        "status": "held",
        "copies": 2,
        "first_observed": "2026-08-04T09:01:45Z",
        "last_observed": "2026-08-06T09:59:24Z",
        "last_checked": "2026-08-11T04:20:26Z"
      },
      "differences": [
        {
          "observed_at": "2026-08-06T09:59:24Z",
          "window_start": "2026-08-04T09:01:45Z",
          "window_end": "2026-08-06T09:59:24Z",
          "status": "source-content",
          "summary": "Two comments by DonTheHolder were removed: one advising moving to a CEX or ETF now shows [removed] with author [deleted], and a one-word reply (\"Lies.\") was deleted.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 2,
          "removed_lines": 16
        }
      ]
    },
    {
      "id": "reddit-mk3-advisory-relay",
      "title": "r/coldcard: Crypto-Guide relaying the Mk3 security advisory",
      "url": "https://www.reddit.com/r/coldcard/comments/1vb9doi/mk3_security_advisory/",
      "organisation": "reddit",
      "kind": "community-discussion",
      "role": "Community discussion",
      "publication_time": null,
      "note": null,
      "gone": null,
      "capture": {
        "status": "held",
        "copies": 3,
        "first_observed": "2026-08-04T09:01:49Z",
        "last_observed": "2026-08-06T16:31:55Z",
        "last_checked": "2026-08-11T04:21:29Z"
      },
      "differences": [
        {
          "observed_at": "2026-08-06T16:31:55Z",
          "window_start": "2026-08-05T20:59:11Z",
          "window_end": "2026-08-06T16:31:55Z",
          "status": "source-content",
          "summary": "Two new comments: nyr00nyg saying they are doing fine with a Ledger Nano, and a reply from Crypto-Guide endorsing Ledger.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 16,
          "removed_lines": 0
        },
        {
          "observed_at": "2026-08-05T20:59:11Z",
          "window_start": "2026-08-04T09:01:49Z",
          "window_end": "2026-08-05T20:59:11Z",
          "status": "source-content",
          "summary": "Reddit no longer served one earlier question about Tails and Electrum, and a separate comment's author and body now appear deleted.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 2,
          "removed_lines": 10
        }
      ]
    },
    {
      "id": "reddit-38m-theft-link",
      "title": "r/coldcard: press link tying the Mk3 seed flaw to a $38M theft",
      "url": "https://www.reddit.com/r/coldcard/comments/1vbfugt/coinkite_warns_coldcard_mk3_seed_flaw_may_be_tied/",
      "organisation": "reddit",
      "kind": "community-discussion",
      "role": "Community discussion",
      "publication_time": null,
      "note": null,
      "gone": null,
      "capture": {
        "status": "held",
        "copies": 1,
        "first_observed": "2026-08-04T09:01:53Z",
        "last_observed": "2026-08-04T09:01:53Z",
        "last_checked": "2026-08-07T07:42:39Z"
      },
      "differences": []
    },
    {
      "id": "reddit-ai-code-review-suggestion",
      "title": "r/coldcard: suggestion that Coinkite AI-review code before shipping",
      "url": "https://www.reddit.com/r/coldcard/comments/1vbtwhb/a_thought_for_the_future/",
      "organisation": "reddit",
      "kind": "community-discussion",
      "role": "Community discussion",
      "publication_time": null,
      "note": null,
      "gone": null,
      "capture": {
        "status": "held",
        "copies": 1,
        "first_observed": "2026-08-04T09:12:04Z",
        "last_observed": "2026-08-04T09:12:04Z",
        "last_checked": "2026-08-07T07:43:48Z"
      },
      "differences": []
    },
    {
      "id": "reddit-ccq-dice-passphrase-risk",
      "title": "r/coldcard: whether dice, TRNG and passphrase on last year's Q firmware is enough",
      "url": "https://www.reddit.com/r/coldcard/comments/1vbnbxn/ccq_risk/",
      "organisation": "reddit",
      "kind": "community-discussion",
      "role": "Community discussion",
      "publication_time": null,
      "note": null,
      "gone": null,
      "capture": {
        "status": "held",
        "copies": 3,
        "first_observed": "2026-08-04T09:12:23Z",
        "last_observed": "2026-08-07T12:55:00Z",
        "last_checked": "2026-08-11T04:22:32Z"
      },
      "differences": [
        {
          "observed_at": "2026-08-07T12:55:00Z",
          "window_start": "2026-08-07T06:15:44Z",
          "window_end": "2026-08-07T12:55:00Z",
          "status": "source-content",
          "summary": "New reply by NiagaraBTC rejecting the imperfection-as-entropy idea: \"that's not how it works\".",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 9,
          "removed_lines": 0
        },
        {
          "observed_at": "2026-08-07T06:15:44Z",
          "window_start": "2026-08-04T09:12:23Z",
          "window_end": "2026-08-07T06:15:44Z",
          "status": "source-content",
          "summary": "New comment by Geekdratic asking whether imperfection itself could bring a form of entropy.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 8,
          "removed_lines": 0
        }
      ]
    },
    {
      "id": "reddit-mk4-trng-dice-passphrase",
      "title": "r/coldcard: Mk4 seed from TRNG plus added dice rolls and a passphrase",
      "url": "https://www.reddit.com/r/coldcard/comments/1vbhuef/mk4_trng_added_dice_rolls_passphrase/",
      "organisation": "reddit",
      "kind": "community-discussion",
      "role": "Community discussion",
      "publication_time": null,
      "note": null,
      "gone": null,
      "capture": {
        "status": "held",
        "copies": 1,
        "first_observed": "2026-08-04T09:12:37Z",
        "last_observed": "2026-08-04T09:12:37Z",
        "last_checked": "2026-08-11T04:23:35Z"
      },
      "differences": []
    },
    {
      "id": "reddit-letter-data-breach-question",
      "title": "r/coldcard: recipient of the June scam letter asking whether Coinkite had a data breach",
      "url": "https://www.reddit.com/r/coldcard/comments/1udt4zh/received_a_letter_today_from_coinkite_data_breach/",
      "organisation": "reddit",
      "kind": "community-discussion",
      "role": "Community discussion",
      "publication_time": null,
      "note": null,
      "gone": null,
      "capture": {
        "status": "held",
        "copies": 1,
        "first_observed": "2026-08-04T09:18:50Z",
        "last_observed": "2026-08-04T09:18:50Z",
        "last_checked": "2026-08-11T04:24:38Z"
      },
      "differences": []
    },
    {
      "id": "reddit-security-advisory-relay",
      "title": "r/Bitcoin: relay of the COLDCARD security advisory",
      "url": "https://www.reddit.com/r/Bitcoin/comments/1vb8taw/security_advisory_for_coldcard_hardware_wallet/",
      "organisation": "reddit",
      "kind": "community-discussion",
      "role": "Community discussion",
      "publication_time": null,
      "note": null,
      "gone": null,
      "capture": {
        "status": "held",
        "copies": 3,
        "first_observed": "2026-08-04T09:25:25Z",
        "last_observed": "2026-08-09T16:50:53Z",
        "last_checked": "2026-08-11T04:25:42Z"
      },
      "differences": [
        {
          "observed_at": "2026-08-09T16:50:53Z",
          "window_start": "2026-08-05T01:46:14Z",
          "window_end": "2026-08-09T16:50:53Z",
          "status": "source-content",
          "summary": "A comment comparing Trezor entropy sources to COLDCARD was removed by Reddit, with the author shown as [deleted] and the body as [removed].",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 2,
          "removed_lines": 10
        },
        {
          "observed_at": "2026-08-05T01:46:14Z",
          "window_start": "2026-08-04T09:25:25Z",
          "window_end": "2026-08-05T01:46:14Z",
          "status": "source-content",
          "summary": "The Reddit thread gained a request for guidance on generating a seed with dice or coins, including calculating the final checksum word.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 10,
          "removed_lines": 0
        }
      ]
    },
    {
      "id": "reddit-0-7-btc-drained",
      "title": "r/Bitcoin: first-hand account of a 0.7 BTC drain",
      "url": "https://www.reddit.com/r/Bitcoin/comments/1vewzn4/fuck_coldcard_holy_shit/",
      "organisation": "reddit",
      "kind": "community-discussion",
      "role": "Community discussion",
      "publication_time": null,
      "note": null,
      "gone": null,
      "capture": {
        "status": "held",
        "copies": 31,
        "first_observed": "2026-08-04T09:25:31Z",
        "last_observed": "2026-08-09T04:04:13Z",
        "last_checked": "2026-08-11T04:26:45Z"
      },
      "differences": [
        {
          "observed_at": "2026-08-09T04:04:13Z",
          "window_start": "2026-08-06T16:32:22Z",
          "window_end": "2026-08-09T04:04:13Z",
          "status": "source-content",
          "summary": "A comment was edited to add a note about Coldcard being closed-source since 2021, and a new ethnic-slur comment appeared.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 11,
          "removed_lines": 1
        },
        {
          "observed_at": "2026-08-06T16:32:22Z",
          "window_start": "2026-08-06T09:59:55Z",
          "window_end": "2026-08-06T16:32:22Z",
          "status": "source-content",
          "summary": "One new top-level comment from Agreeable_Bullfrog_7: \"I am so sorry.\"",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 8,
          "removed_lines": 0
        },
        {
          "observed_at": "2026-08-06T09:59:55Z",
          "window_start": "2026-08-06T03:28:46Z",
          "window_end": "2026-08-06T09:59:55Z",
          "status": "source-content",
          "summary": "Two new comments: one says the victim was older and desperate and not the only one, another speculates someone inside the company could have quietly kept the issue secret to profit from it.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 18,
          "removed_lines": 0
        },
        {
          "observed_at": "2026-08-06T03:28:46Z",
          "window_start": "2026-08-05T20:59:36Z",
          "window_end": "2026-08-06T03:28:46Z",
          "status": "source-content",
          "summary": "Reddit added comments debating AI-assisted auditing, vendor liability, alternative wallets and alleged recovery-service scams.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 136,
          "removed_lines": 0
        },
        {
          "observed_at": "2026-08-05T20:59:36Z",
          "window_start": "2026-08-05T14:24:50Z",
          "window_end": "2026-08-05T20:59:36Z",
          "status": "source-content",
          "summary": "Reddit added comments about long-term cryptocurrency risk, the wallet screenshot's label, incident awareness and the trade-offs between self-custody and custodians.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 46,
          "removed_lines": 0
        },
        {
          "observed_at": "2026-08-05T14:24:50Z",
          "window_start": "2026-08-05T07:56:27Z",
          "window_end": "2026-08-05T14:24:50Z",
          "status": "source-content",
          "summary": "One comment's author and text were replaced by a deleted-account placeholder. The thread also gained comments about compensation expectations and reduced trust in hardware wallets and recurring bitcoin purchases.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 18,
          "removed_lines": 10
        },
        {
          "observed_at": "2026-08-05T07:56:27Z",
          "window_start": "2026-08-05T01:46:20Z",
          "window_end": "2026-08-05T07:56:27Z",
          "status": "source-content",
          "summary": "The thread gained dismissive exchanges about bitcoin and a reply arguing that custody-related holding periods are preferable to losing everything in an incident.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 28,
          "removed_lines": 0
        },
        {
          "observed_at": "2026-08-05T01:46:20Z",
          "window_start": "2026-08-05T01:16:14Z",
          "window_end": "2026-08-05T01:46:20Z",
          "status": "source-content",
          "summary": "The thread gained a clarification that the victim used the app only to check whether funds were stolen, plus replies expressing sympathy, assigning responsibility to Coinkite, and recommending a passphrase.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 24,
          "removed_lines": 0
        },
        {
          "observed_at": "2026-08-05T01:16:14Z",
          "window_start": "2026-08-05T00:46:11Z",
          "window_end": "2026-08-05T01:16:14Z",
          "status": "source-content",
          "summary": "The Reddit thread gained two comments, including a question about what signs transactions and a remark on self-custody.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 16,
          "removed_lines": 0
        },
        {
          "observed_at": "2026-08-05T00:46:11Z",
          "window_start": "2026-08-04T23:45:55Z",
          "window_end": "2026-08-05T00:46:11Z",
          "status": "source-content",
          "summary": "The Reddit thread gained a new reply saying \"lol\".",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 8,
          "removed_lines": 0
        },
        {
          "observed_at": "2026-08-04T23:45:55Z",
          "window_start": "2026-08-04T22:46:31Z",
          "window_end": "2026-08-04T23:45:55Z",
          "status": "source-content",
          "summary": "The Reddit thread gained new participant comments.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 34,
          "removed_lines": 10
        },
        {
          "observed_at": "2026-08-04T22:46:31Z",
          "window_start": "2026-08-04T22:15:46Z",
          "window_end": "2026-08-04T22:46:31Z",
          "status": "source-content",
          "summary": "The Reddit thread gained new participant comments.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 8,
          "removed_lines": 0
        },
        {
          "observed_at": "2026-08-04T22:15:46Z",
          "window_start": "2026-08-04T21:45:24Z",
          "window_end": "2026-08-04T22:15:46Z",
          "status": "source-content",
          "summary": "The Reddit thread gained 2 new comments.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 28,
          "removed_lines": 0
        },
        {
          "observed_at": "2026-08-04T21:45:24Z",
          "window_start": "2026-08-04T21:15:32Z",
          "window_end": "2026-08-04T21:45:24Z",
          "status": "source-content",
          "summary": "The Reddit thread gained 4 new comments.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 33,
          "removed_lines": 0
        },
        {
          "observed_at": "2026-08-04T21:15:32Z",
          "window_start": "2026-08-04T20:45:15Z",
          "window_end": "2026-08-04T21:15:32Z",
          "status": "source-content",
          "summary": "The Reddit thread gained 4 new comments.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 34,
          "removed_lines": 0
        },
        {
          "observed_at": "2026-08-04T20:45:15Z",
          "window_start": "2026-08-04T20:15:41Z",
          "window_end": "2026-08-04T20:45:15Z",
          "status": "source-content",
          "summary": "The Reddit thread gained 1 new comment.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 8,
          "removed_lines": 0
        },
        {
          "observed_at": "2026-08-04T20:15:41Z",
          "window_start": "2026-08-04T19:45:17Z",
          "window_end": "2026-08-04T20:15:41Z",
          "status": "source-content",
          "summary": "The Reddit thread gained 3 new comments.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 25,
          "removed_lines": 0
        },
        {
          "observed_at": "2026-08-04T19:45:17Z",
          "window_start": "2026-08-04T19:14:10Z",
          "window_end": "2026-08-04T19:45:17Z",
          "status": "source-content",
          "summary": "The Reddit thread gained 2 new comments.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 18,
          "removed_lines": 0
        },
        {
          "observed_at": "2026-08-04T19:14:10Z",
          "window_start": "2026-08-04T18:45:03Z",
          "window_end": "2026-08-04T19:14:10Z",
          "status": "source-content",
          "summary": "The Reddit thread gained 1 new comment.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 8,
          "removed_lines": 0
        },
        {
          "observed_at": "2026-08-04T18:45:03Z",
          "window_start": "2026-08-04T18:13:57Z",
          "window_end": "2026-08-04T18:45:03Z",
          "status": "source-content",
          "summary": "The Reddit thread gained 1 new comment.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 8,
          "removed_lines": 0
        },
        {
          "observed_at": "2026-08-04T18:13:57Z",
          "window_start": "2026-08-04T17:44:35Z",
          "window_end": "2026-08-04T18:13:57Z",
          "status": "source-content",
          "summary": "The Reddit thread gained 1 new comment.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 8,
          "removed_lines": 0
        },
        {
          "observed_at": "2026-08-04T17:44:35Z",
          "window_start": "2026-08-04T17:14:18Z",
          "window_end": "2026-08-04T17:44:35Z",
          "status": "source-content",
          "summary": "The Reddit thread gained 4 new comments.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 32,
          "removed_lines": 0
        },
        {
          "observed_at": "2026-08-04T17:14:18Z",
          "window_start": "2026-08-04T16:46:06Z",
          "window_end": "2026-08-04T17:14:18Z",
          "status": "source-content",
          "summary": "The Reddit thread gained 3 new comments.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 24,
          "removed_lines": 0
        },
        {
          "observed_at": "2026-08-04T16:46:06Z",
          "window_start": "2026-08-04T16:15:29Z",
          "window_end": "2026-08-04T16:46:06Z",
          "status": "source-content",
          "summary": "The Reddit thread gained 5 new comments.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 40,
          "removed_lines": 0
        },
        {
          "observed_at": "2026-08-04T16:15:29Z",
          "window_start": "2026-08-04T15:44:35Z",
          "window_end": "2026-08-04T16:15:29Z",
          "status": "source-content",
          "summary": "9 new Reddit comments were posted, including H3adshotfox77 and Fil3toFishy69.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 80,
          "removed_lines": 0
        },
        {
          "observed_at": "2026-08-04T15:44:35Z",
          "window_start": "2026-08-04T15:14:13Z",
          "window_end": "2026-08-04T15:44:35Z",
          "status": "source-content",
          "summary": "1 new Reddit comment was posted, by fllannell, warning about secondary scams posing as white-hat recovery help.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 8,
          "removed_lines": 0
        },
        {
          "observed_at": "2026-08-04T15:14:13Z",
          "window_start": "2026-08-04T14:43:23Z",
          "window_end": "2026-08-04T15:14:13Z",
          "status": "source-content",
          "summary": "4 new Reddit comments were posted, including IInsulince, Punterios and terobau.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 36,
          "removed_lines": 0
        },
        {
          "observed_at": "2026-08-04T14:43:23Z",
          "window_start": "2026-08-04T14:14:16Z",
          "window_end": "2026-08-04T14:43:23Z",
          "status": "source-content",
          "summary": "2 new Reddit comments were posted, including wetokebitcoins,rmtdispatcher.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 16,
          "removed_lines": 0
        },
        {
          "observed_at": "2026-08-04T14:14:16Z",
          "window_start": "2026-08-04T13:43:25Z",
          "window_end": "2026-08-04T14:14:16Z",
          "status": "source-content",
          "summary": "4 new Reddit comments were posted, including cozmicraven,KELVALL,ILurkReddi.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 34,
          "removed_lines": 0
        },
        {
          "observed_at": "2026-08-04T13:43:25Z",
          "window_start": "2026-08-04T09:25:31Z",
          "window_end": "2026-08-04T13:43:25Z",
          "status": "source-content",
          "summary": "42 new Reddit comments were posted, including keypusher,Background_Pause34,iloverunning11.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 373,
          "removed_lines": 2
        }
      ]
    },
    {
      "id": "reddit-white-hat-drains-relay",
      "title": "r/Bitcoin: report that white-hat drains of unpatched COLDCARDs are underway",
      "url": "https://www.reddit.com/r/Bitcoin/comments/1veo0yh/white_hats_are_emptying_weak_keys_generated_by/",
      "organisation": "reddit",
      "kind": "community-discussion",
      "role": "Community discussion",
      "publication_time": null,
      "note": null,
      "gone": null,
      "capture": {
        "status": "held",
        "copies": 11,
        "first_observed": "2026-08-04T09:25:38Z",
        "last_observed": "2026-08-09T23:21:28Z",
        "last_checked": "2026-08-11T04:27:48Z"
      },
      "differences": [
        {
          "observed_at": "2026-08-09T23:21:28Z",
          "window_start": "2026-08-06T16:32:29Z",
          "window_end": "2026-08-09T23:21:28Z",
          "status": "source-content",
          "summary": "The thread gained a skeptical comment casting doubt on the white-hat drain claim.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 8,
          "removed_lines": 0
        },
        {
          "observed_at": "2026-08-06T16:32:29Z",
          "window_start": "2026-08-05T20:59:43Z",
          "window_end": "2026-08-06T16:32:29Z",
          "status": "source-content",
          "summary": "Four comments by IllllIIlIllIllllIlll were deleted (author now [deleted], bodies [deleted]) and a new comment says only rumors, nothing concrete, have been seen about the white hat.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 20,
          "removed_lines": 22
        },
        {
          "observed_at": "2026-08-05T20:59:43Z",
          "window_start": "2026-08-05T07:56:34Z",
          "window_end": "2026-08-05T20:59:43Z",
          "status": "source-content",
          "summary": "Reddit added a comment suggesting exchange withdrawal histories across derived addresses as evidence of wallet ownership.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 10,
          "removed_lines": 0
        },
        {
          "observed_at": "2026-08-05T07:56:34Z",
          "window_start": "2026-08-04T23:46:03Z",
          "window_end": "2026-08-05T07:56:34Z",
          "status": "source-content",
          "summary": "The thread gained a reply saying the cited transactions are publicly visible on-chain.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 8,
          "removed_lines": 0
        },
        {
          "observed_at": "2026-08-04T23:46:03Z",
          "window_start": "2026-08-04T22:46:38Z",
          "window_end": "2026-08-04T23:46:03Z",
          "status": "source-content",
          "summary": "The Reddit thread gained a comment disputing the white-hat characterization of the drains.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 8,
          "removed_lines": 0
        },
        {
          "observed_at": "2026-08-04T22:46:38Z",
          "window_start": "2026-08-04T19:14:18Z",
          "window_end": "2026-08-04T22:46:38Z",
          "status": "source-content",
          "summary": "The Reddit thread gained a suggestion to prove ownership through control of the funding address.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 8,
          "removed_lines": 0
        },
        {
          "observed_at": "2026-08-04T19:14:18Z",
          "window_start": "2026-08-04T14:43:30Z",
          "window_end": "2026-08-04T19:14:18Z",
          "status": "source-content",
          "summary": "The Reddit thread gained 1 new comment.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 8,
          "removed_lines": 0
        },
        {
          "observed_at": "2026-08-04T14:43:30Z",
          "window_start": "2026-08-04T14:14:23Z",
          "window_end": "2026-08-04T14:43:30Z",
          "status": "source-content",
          "summary": "1 new Reddit comment was posted, including IndependenceTop6501.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 8,
          "removed_lines": 0
        },
        {
          "observed_at": "2026-08-04T14:14:23Z",
          "window_start": "2026-08-04T13:43:32Z",
          "window_end": "2026-08-04T14:14:23Z",
          "status": "source-content",
          "summary": "3 new Reddit comments were posted, including Available-Distance81,LexxM3,Fat-Finger-8906.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 26,
          "removed_lines": 0
        },
        {
          "observed_at": "2026-08-04T13:43:32Z",
          "window_start": "2026-08-04T09:25:38Z",
          "window_end": "2026-08-04T13:43:32Z",
          "status": "source-content",
          "summary": "3 new Reddit comments were posted, including PiDigitsOfPi,MiaTaude589,Available-Distance81.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 28,
          "removed_lines": 0
        }
      ]
    },
    {
      "id": "reddit-5-13-btc-loss",
      "title": "r/Bitcoin: first-hand account of a 5.13 BTC loss",
      "url": "https://www.reddit.com/r/Bitcoin/comments/1vemip7/your_keys_not_your_crypto_a_330k_lesson_for_all/",
      "organisation": "reddit",
      "kind": "community-discussion",
      "role": "Community discussion",
      "publication_time": null,
      "note": null,
      "gone": null,
      "capture": {
        "status": "held",
        "copies": 18,
        "first_observed": "2026-08-04T09:25:44Z",
        "last_observed": "2026-08-09T16:51:12Z",
        "last_checked": "2026-08-11T04:28:51Z"
      },
      "differences": [
        {
          "observed_at": "2026-08-09T16:51:12Z",
          "window_start": "2026-08-09T10:34:13Z",
          "window_end": "2026-08-09T16:51:12Z",
          "status": "source-content",
          "summary": "A new comment was added arguing that cryptocurrency is never truly possessed, that owners must be right every minute while attackers need only be right once.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 14,
          "removed_lines": 0
        },
        {
          "observed_at": "2026-08-09T10:34:13Z",
          "window_start": "2026-08-09T04:04:26Z",
          "window_end": "2026-08-09T10:34:13Z",
          "status": "source-content",
          "summary": "The thread gained a one-line comment asking for a TL;DR.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 8,
          "removed_lines": 0
        },
        {
          "observed_at": "2026-08-09T04:04:26Z",
          "window_start": "2026-08-08T21:31:58Z",
          "window_end": "2026-08-09T04:04:26Z",
          "status": "source-content",
          "summary": "The thread gained two comments discussing whether white-hat recovery of stolen funds is plausible.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 16,
          "removed_lines": 0
        },
        {
          "observed_at": "2026-08-08T21:31:58Z",
          "window_start": "2026-08-08T15:02:01Z",
          "window_end": "2026-08-08T21:31:58Z",
          "status": "source-content",
          "summary": "The victim thread gained several new comments, including relief at not owning a COLDCARD, commiseration over past exchange losses, calls for Coinkite liability, and suspicion about a dormant account's return.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 54,
          "removed_lines": 0
        },
        {
          "observed_at": "2026-08-08T15:02:01Z",
          "window_start": "2026-08-08T01:58:35Z",
          "window_end": "2026-08-08T15:02:01Z",
          "status": "source-content",
          "summary": "The thread gained three new comments: one recommending an offline paper-wallet generator, another expressing sympathy and sharing a smaller loss, and a third offering to send sats via a lightning wallet.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 34,
          "removed_lines": 0
        },
        {
          "observed_at": "2026-08-08T01:58:35Z",
          "window_start": "2026-08-07T19:28:19Z",
          "window_end": "2026-08-08T01:58:35Z",
          "status": "source-content",
          "summary": "The Reddit thread gained a long comment defending the victim and blaming the fundamental code error, while a prior brief condolence comment was removed.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 32,
          "removed_lines": 8
        },
        {
          "observed_at": "2026-08-07T19:28:19Z",
          "window_start": "2026-08-06T03:28:59Z",
          "window_end": "2026-08-07T19:28:19Z",
          "status": "source-content",
          "summary": "The thread gained a comment stating that Coinkite should refund everyone who trusted the device with life savings.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 8,
          "removed_lines": 0
        },
        {
          "observed_at": "2026-08-06T03:28:59Z",
          "window_start": "2026-08-05T20:59:49Z",
          "window_end": "2026-08-06T03:28:59Z",
          "status": "source-content",
          "summary": "Reddit now marks a supportive commenter as deleted and their comment as removed.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 2,
          "removed_lines": 10
        },
        {
          "observed_at": "2026-08-05T20:59:49Z",
          "window_start": "2026-08-05T07:56:40Z",
          "window_end": "2026-08-05T20:59:49Z",
          "status": "source-content",
          "summary": "Reddit added a brief supportive comment to the reported-loss account.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 8,
          "removed_lines": 0
        },
        {
          "observed_at": "2026-08-05T07:56:40Z",
          "window_start": "2026-08-04T23:21:39Z",
          "window_end": "2026-08-05T07:56:40Z",
          "status": "source-content",
          "summary": "The thread gained a brief reply expressing sympathy for the reported loss.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 8,
          "removed_lines": 0
        },
        {
          "observed_at": "2026-08-04T23:21:39Z",
          "window_start": "2026-08-04T20:15:53Z",
          "window_end": "2026-08-04T23:21:39Z",
          "status": "source-content",
          "summary": "The Reddit thread gained new participant comments.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 18,
          "removed_lines": 0
        },
        {
          "observed_at": "2026-08-04T20:15:53Z",
          "window_start": "2026-08-04T16:46:23Z",
          "window_end": "2026-08-04T20:15:53Z",
          "status": "source-content",
          "summary": "The Reddit thread gained 1 new comment.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 8,
          "removed_lines": 0
        },
        {
          "observed_at": "2026-08-04T16:46:23Z",
          "window_start": "2026-08-04T16:15:45Z",
          "window_end": "2026-08-04T16:46:23Z",
          "status": "source-content",
          "summary": "An existing Reddit comment no longer appeared in the captured thread.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 0,
          "removed_lines": 8
        },
        {
          "observed_at": "2026-08-04T16:15:45Z",
          "window_start": "2026-08-04T15:44:56Z",
          "window_end": "2026-08-04T16:15:45Z",
          "status": "source-content",
          "summary": "1 new Reddit comment was posted, by Patched7fig, recommending conventional investments.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 8,
          "removed_lines": 0
        },
        {
          "observed_at": "2026-08-04T15:44:56Z",
          "window_start": "2026-08-04T14:14:28Z",
          "window_end": "2026-08-04T15:44:56Z",
          "status": "source-content",
          "summary": "1 new Reddit comment was posted, by Sensitive-Dish-7770, on the financial impact and perceived AI-related risk.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 10,
          "removed_lines": 0
        },
        {
          "observed_at": "2026-08-04T14:14:28Z",
          "window_start": "2026-08-04T13:43:38Z",
          "window_end": "2026-08-04T14:14:28Z",
          "status": "source-content",
          "summary": "1 new Reddit comment was posted, including KSTSHoldings.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 8,
          "removed_lines": 0
        },
        {
          "observed_at": "2026-08-04T13:43:38Z",
          "window_start": "2026-08-04T09:25:44Z",
          "window_end": "2026-08-04T13:43:38Z",
          "status": "source-content",
          "summary": "5 new Reddit comments were posted, including AirLawyer,Generationhodl,n8dahwgg.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 59,
          "removed_lines": 3
        }
      ]
    },
    {
      "id": "reddit-unused-coldcard-collectible",
      "title": "r/Bitcoin: owner of a sealed, never-used COLDCARD asking when it becomes a collectible",
      "url": "https://www.reddit.com/r/Bitcoin/comments/1vecxwh/my_unused_coldcard/",
      "organisation": "reddit",
      "kind": "community-discussion",
      "role": "Community discussion",
      "publication_time": null,
      "note": null,
      "gone": null,
      "capture": {
        "status": "held",
        "copies": 11,
        "first_observed": "2026-08-04T09:25:50Z",
        "last_observed": "2026-08-06T16:42:23Z",
        "last_checked": "2026-08-07T07:44:57Z"
      },
      "differences": [
        {
          "observed_at": "2026-08-06T16:42:23Z",
          "window_start": "2026-08-06T10:13:58Z",
          "window_end": "2026-08-06T16:42:23Z",
          "status": "source-content",
          "summary": "Reddit served 1 additional comment record(s) and 1 previously held comment record(s) omitted; the diff preserves their text and any edits to existing records.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 8,
          "removed_lines": 8
        },
        {
          "observed_at": "2026-08-06T10:13:58Z",
          "window_start": "2026-08-05T21:10:55Z",
          "window_end": "2026-08-06T10:13:58Z",
          "status": "source-content",
          "summary": "Reddit served 2 additional comment record(s); the diff preserves their text and any edits to existing records.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 16,
          "removed_lines": 0
        },
        {
          "observed_at": "2026-08-05T21:10:55Z",
          "window_start": "2026-08-05T08:06:19Z",
          "window_end": "2026-08-05T21:10:55Z",
          "status": "source-content",
          "summary": "Reddit served 2 additional comment record(s); the diff preserves their text and any edits to existing records.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 16,
          "removed_lines": 0
        },
        {
          "observed_at": "2026-08-05T08:06:19Z",
          "window_start": "2026-08-05T01:56:09Z",
          "window_end": "2026-08-05T08:06:19Z",
          "status": "source-content",
          "summary": "Reddit served 2 additional comment record(s); the diff preserves their text and any edits to existing records.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 18,
          "removed_lines": 0
        },
        {
          "observed_at": "2026-08-05T01:56:09Z",
          "window_start": "2026-08-04T17:24:34Z",
          "window_end": "2026-08-05T01:56:09Z",
          "status": "source-content",
          "summary": "A comment saying its author would stop recommending and buying COLDCARD products, while retaining an existing device and planning multisignature storage, disappeared.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 0,
          "removed_lines": 8
        },
        {
          "observed_at": "2026-08-04T17:24:34Z",
          "window_start": "2026-08-04T11:43:14Z",
          "window_end": "2026-08-04T17:24:34Z",
          "status": "source-content",
          "summary": "The Reddit thread gained 1 new comment.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 8,
          "removed_lines": 0
        },
        {
          "observed_at": "2026-08-04T11:43:14Z",
          "window_start": "2026-08-04T11:14:04Z",
          "window_end": "2026-08-04T11:43:14Z",
          "status": "source-content",
          "summary": "One new comment was posted: CapivaraMan, who had never heard of COLDCARD, visited the website and liked the style and models.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 8,
          "removed_lines": 0
        },
        {
          "observed_at": "2026-08-04T11:14:04Z",
          "window_start": "2026-08-04T10:42:56Z",
          "window_end": "2026-08-04T11:14:04Z",
          "status": "source-content",
          "summary": "One new comment was posted: ibraw ('The hint was in their slogan').",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 8,
          "removed_lines": 0
        },
        {
          "observed_at": "2026-08-04T10:42:56Z",
          "window_start": "2026-08-04T10:14:14Z",
          "window_end": "2026-08-04T10:42:56Z",
          "status": "source-content",
          "summary": "One new comment was posted: FavorableMadness, arguing the incident does not make the device worse than any other since all software ships security fixes and vulnerabilities.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 8,
          "removed_lines": 0
        },
        {
          "observed_at": "2026-08-04T10:14:14Z",
          "window_start": "2026-08-04T09:25:50Z",
          "window_end": "2026-08-04T10:14:14Z",
          "status": "source-content",
          "summary": "One new top-level comment was posted: Aeschbacher15 p1mdt3h ('Talk about dodging bullets lol').",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 8,
          "removed_lines": 0
        }
      ]
    },
    {
      "id": "reddit-hacker-address-message-board",
      "title": "r/Bitcoin: drainer's address turned into a public message board via OP_RETURN",
      "url": "https://www.reddit.com/r/Bitcoin/comments/1ved66r/bitcoin_users_are_turning_a_the_coldcard_hackers/",
      "organisation": "reddit",
      "kind": "community-discussion",
      "role": "Community discussion",
      "publication_time": null,
      "note": null,
      "gone": null,
      "capture": {
        "status": "held",
        "copies": 11,
        "first_observed": "2026-08-04T09:25:57Z",
        "last_observed": "2026-08-08T01:58:40Z",
        "last_checked": "2026-08-11T04:29:54Z"
      },
      "differences": [
        {
          "observed_at": "2026-08-08T01:58:40Z",
          "window_start": "2026-08-05T14:25:09Z",
          "window_end": "2026-08-08T01:58:40Z",
          "status": "source-content",
          "summary": "The Reddit thread gained a new participant comment.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 8,
          "removed_lines": 0
        },
        {
          "observed_at": "2026-08-05T14:25:09Z",
          "window_start": "2026-08-04T20:16:00Z",
          "window_end": "2026-08-05T14:25:09Z",
          "status": "source-content",
          "summary": "Reddit served an additional comment calling for the operator to be caught and arguing that COLDCARD should compensate victims.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 8,
          "removed_lines": 0
        },
        {
          "observed_at": "2026-08-04T20:16:00Z",
          "window_start": "2026-08-04T18:14:16Z",
          "window_end": "2026-08-04T20:16:00Z",
          "status": "source-content",
          "summary": "The Reddit thread gained 1 new comment.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 10,
          "removed_lines": 0
        },
        {
          "observed_at": "2026-08-04T18:14:16Z",
          "window_start": "2026-08-04T17:44:53Z",
          "window_end": "2026-08-04T18:14:16Z",
          "status": "source-content",
          "summary": "An existing Reddit comment was edited or removed.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 7,
          "removed_lines": 3
        },
        {
          "observed_at": "2026-08-04T17:44:53Z",
          "window_start": "2026-08-04T17:14:38Z",
          "window_end": "2026-08-04T17:44:53Z",
          "status": "source-content",
          "summary": "The Reddit thread gained 2 new comments.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 16,
          "removed_lines": 0
        },
        {
          "observed_at": "2026-08-04T17:14:38Z",
          "window_start": "2026-08-04T16:46:30Z",
          "window_end": "2026-08-04T17:14:38Z",
          "status": "source-content",
          "summary": "The Reddit thread gained 1 new comment.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 8,
          "removed_lines": 0
        },
        {
          "observed_at": "2026-08-04T16:46:30Z",
          "window_start": "2026-08-04T15:45:04Z",
          "window_end": "2026-08-04T16:46:30Z",
          "status": "source-content",
          "summary": "The Reddit thread gained 1 new comment.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 8,
          "removed_lines": 0
        },
        {
          "observed_at": "2026-08-04T15:45:04Z",
          "window_start": "2026-08-04T15:14:32Z",
          "window_end": "2026-08-04T15:45:04Z",
          "status": "source-content",
          "summary": "2 new Reddit comments were posted, including anonymousopsec1337, discussing the first sweep's affected balances.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 16,
          "removed_lines": 0
        },
        {
          "observed_at": "2026-08-04T15:14:32Z",
          "window_start": "2026-08-04T13:43:44Z",
          "window_end": "2026-08-04T15:14:32Z",
          "status": "source-content",
          "summary": "1 new Reddit comment was posted, by magniankh, speculating about a former employee.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 8,
          "removed_lines": 0
        },
        {
          "observed_at": "2026-08-04T13:43:44Z",
          "window_start": "2026-08-04T09:25:57Z",
          "window_end": "2026-08-04T13:43:44Z",
          "status": "source-content",
          "summary": "6 new Reddit comments were posted, including LornaQin,AdLeft7000,Leto33.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 49,
          "removed_lines": 0
        }
      ]
    },
    {
      "id": "reddit-self-custody-custodian-debate",
      "title": "r/Bitcoin: whether self-custody is still the right advice for non-technical holders",
      "url": "https://www.reddit.com/r/Bitcoin/comments/1ve9or3/live_view_of_older_folks_that_had_bitcoin_on/",
      "organisation": "reddit",
      "kind": "community-discussion",
      "role": "Community discussion",
      "publication_time": null,
      "note": null,
      "gone": null,
      "capture": {
        "status": "held",
        "copies": 16,
        "first_observed": "2026-08-04T09:33:55Z",
        "last_observed": "2026-08-08T08:31:13Z",
        "last_checked": "2026-08-11T04:30:57Z"
      },
      "differences": [
        {
          "observed_at": "2026-08-08T08:31:13Z",
          "window_start": "2026-08-07T06:16:29Z",
          "window_end": "2026-08-08T08:31:13Z",
          "status": "source-content",
          "summary": "The Reddit thread gained a new participant comment asking whether custody means a bank.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 8,
          "removed_lines": 0
        },
        {
          "observed_at": "2026-08-07T06:16:29Z",
          "window_start": "2026-08-06T16:32:46Z",
          "window_end": "2026-08-07T06:16:29Z",
          "status": "source-content",
          "summary": "New top-level comment by Aggravating_Shower_6 saying they moved to the Schwab ETF years ago and sleep well.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 8,
          "removed_lines": 0
        },
        {
          "observed_at": "2026-08-06T16:32:46Z",
          "window_start": "2026-08-06T10:00:20Z",
          "window_end": "2026-08-06T16:32:46Z",
          "status": "source-content",
          "summary": "A top-level comment by BackgroundStory7986 about grandpa figuring out Bitcoin before hardware wallets figured out grandpa disappeared from the listing.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 0,
          "removed_lines": 8
        },
        {
          "observed_at": "2026-08-06T10:00:20Z",
          "window_start": "2026-08-06T03:29:11Z",
          "window_end": "2026-08-06T10:00:20Z",
          "status": "source-content",
          "summary": "Two new comments: Skinny_Human saying they were a Coldcard user but have switched sides, and locotx continuing a Simpsons joke exchange.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 16,
          "removed_lines": 0
        },
        {
          "observed_at": "2026-08-06T03:29:11Z",
          "window_start": "2026-08-05T21:00:01Z",
          "window_end": "2026-08-06T03:29:11Z",
          "status": "source-content",
          "summary": "Reddit added two brief comments, one sexual joke and one explaining a Simpsons meme.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 16,
          "removed_lines": 0
        },
        {
          "observed_at": "2026-08-05T21:00:01Z",
          "window_start": "2026-08-05T07:56:52Z",
          "window_end": "2026-08-05T21:00:01Z",
          "status": "source-content",
          "summary": "Reddit added a comment referring to Sam Bankman-Fried in the debate over custody.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 8,
          "removed_lines": 0
        },
        {
          "observed_at": "2026-08-05T07:56:52Z",
          "window_start": "2026-08-05T01:16:39Z",
          "window_end": "2026-08-05T07:56:52Z",
          "status": "source-content",
          "summary": "A short comment asking how to get karma was removed from the thread.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 0,
          "removed_lines": 8
        },
        {
          "observed_at": "2026-08-05T01:16:39Z",
          "window_start": "2026-08-04T23:46:20Z",
          "window_end": "2026-08-05T01:16:39Z",
          "status": "source-content",
          "summary": "The Reddit thread gained a comment saying a busy user had preferred a custodian to self-custody.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 8,
          "removed_lines": 0
        },
        {
          "observed_at": "2026-08-04T23:46:20Z",
          "window_start": "2026-08-04T22:16:10Z",
          "window_end": "2026-08-04T23:46:20Z",
          "status": "source-content",
          "summary": "The Reddit thread gained a new participant comment.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 8,
          "removed_lines": 0
        },
        {
          "observed_at": "2026-08-04T22:16:10Z",
          "window_start": "2026-08-04T20:16:06Z",
          "window_end": "2026-08-04T22:16:10Z",
          "status": "source-content",
          "summary": "The Reddit thread gained 1 new comment.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 8,
          "removed_lines": 0
        },
        {
          "observed_at": "2026-08-04T20:16:06Z",
          "window_start": "2026-08-04T19:45:40Z",
          "window_end": "2026-08-04T20:16:06Z",
          "status": "source-content",
          "summary": "The Reddit thread gained 1 new comment.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 8,
          "removed_lines": 0
        },
        {
          "observed_at": "2026-08-04T19:45:40Z",
          "window_start": "2026-08-04T18:45:29Z",
          "window_end": "2026-08-04T19:45:40Z",
          "status": "source-content",
          "summary": "The Reddit thread gained 2 new comments.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 18,
          "removed_lines": 0
        },
        {
          "observed_at": "2026-08-04T18:45:29Z",
          "window_start": "2026-08-04T16:15:58Z",
          "window_end": "2026-08-04T18:45:29Z",
          "status": "source-content",
          "summary": "The Reddit thread gained 1 new comment.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 8,
          "removed_lines": 0
        },
        {
          "observed_at": "2026-08-04T16:15:58Z",
          "window_start": "2026-08-04T13:43:49Z",
          "window_end": "2026-08-04T16:15:58Z",
          "status": "source-content",
          "summary": "1 new Reddit comment was posted, by Billgatesisamoron, advocating use of a custom passphrase.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 8,
          "removed_lines": 0
        },
        {
          "observed_at": "2026-08-04T13:43:49Z",
          "window_start": "2026-08-04T09:33:55Z",
          "window_end": "2026-08-04T13:43:49Z",
          "status": "source-content",
          "summary": "7 new Reddit comments were posted, including anotherbrckinTH3Wall,DRAGULA85,Lavayo.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 64,
          "removed_lines": 0
        }
      ]
    },
    {
      "id": "reddit-trezor-community-audit-call",
      "title": "r/Bitcoin: call for a community audit of Trezor's open-source code",
      "url": "https://www.reddit.com/r/Bitcoin/comments/1veoo6t/as_a_community_we_should_fully_audit_trezors_open/",
      "organisation": "reddit",
      "kind": "community-discussion",
      "role": "Community discussion",
      "publication_time": null,
      "note": null,
      "gone": null,
      "capture": {
        "status": "held",
        "copies": 17,
        "first_observed": "2026-08-04T09:34:00Z",
        "last_observed": "2026-08-07T19:28:36Z",
        "last_checked": "2026-08-11T04:32:00Z"
      },
      "differences": [
        {
          "observed_at": "2026-08-07T19:28:36Z",
          "window_start": "2026-08-06T16:32:52Z",
          "window_end": "2026-08-07T19:28:36Z",
          "status": "source-content",
          "summary": "The thread gained a short off-topic reply.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 8,
          "removed_lines": 0
        },
        {
          "observed_at": "2026-08-06T16:32:52Z",
          "window_start": "2026-08-06T03:29:17Z",
          "window_end": "2026-08-06T16:32:52Z",
          "status": "source-content",
          "summary": "New comment from Ok-Mammoth552 arguing AI is better at finding exploits than securing systems because cybersecurity is inherently asymmetrical.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 8,
          "removed_lines": 0
        },
        {
          "observed_at": "2026-08-06T03:29:17Z",
          "window_start": "2026-08-05T14:25:20Z",
          "window_end": "2026-08-06T03:29:17Z",
          "status": "source-content",
          "summary": "Reddit added a request for a trusted method to turn dice or coin entropy into a BIP39 seed and passphrase.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 8,
          "removed_lines": 0
        },
        {
          "observed_at": "2026-08-05T14:25:20Z",
          "window_start": "2026-08-05T00:16:39Z",
          "window_end": "2026-08-05T14:25:20Z",
          "status": "source-content",
          "summary": "Reddit served an additional comment proposing physical randomness, such as dice, instead of device-generated seed phrases.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 14,
          "removed_lines": 0
        },
        {
          "observed_at": "2026-08-05T00:16:39Z",
          "window_start": "2026-08-04T23:46:26Z",
          "window_end": "2026-08-05T00:16:39Z",
          "status": "source-content",
          "summary": "The Reddit thread gained a reply to the preceding participant comment.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 8,
          "removed_lines": 0
        },
        {
          "observed_at": "2026-08-04T23:46:26Z",
          "window_start": "2026-08-04T23:21:56Z",
          "window_end": "2026-08-04T23:46:26Z",
          "status": "source-content",
          "summary": "The Reddit thread gained a new participant comment.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 8,
          "removed_lines": 0
        },
        {
          "observed_at": "2026-08-04T23:21:56Z",
          "window_start": "2026-08-04T20:16:12Z",
          "window_end": "2026-08-04T23:21:56Z",
          "status": "source-content",
          "summary": "The Reddit thread gained comments comparing entropy designs and debating what a community audit can accomplish.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 36,
          "removed_lines": 0
        },
        {
          "observed_at": "2026-08-04T20:16:12Z",
          "window_start": "2026-08-04T19:45:46Z",
          "window_end": "2026-08-04T20:16:12Z",
          "status": "source-content",
          "summary": "The Reddit thread gained 1 new comment.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 8,
          "removed_lines": 0
        },
        {
          "observed_at": "2026-08-04T19:45:46Z",
          "window_start": "2026-08-04T19:14:43Z",
          "window_end": "2026-08-04T19:45:46Z",
          "status": "source-content",
          "summary": "The Reddit thread gained 1 new comment.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 8,
          "removed_lines": 0
        },
        {
          "observed_at": "2026-08-04T19:14:43Z",
          "window_start": "2026-08-04T18:45:35Z",
          "window_end": "2026-08-04T19:14:43Z",
          "status": "source-content",
          "summary": "The Reddit thread gained 1 new comment.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 8,
          "removed_lines": 0
        },
        {
          "observed_at": "2026-08-04T18:45:35Z",
          "window_start": "2026-08-04T17:45:04Z",
          "window_end": "2026-08-04T18:45:35Z",
          "status": "source-content",
          "summary": "The Reddit thread gained 2 new comments.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 16,
          "removed_lines": 0
        },
        {
          "observed_at": "2026-08-04T17:45:04Z",
          "window_start": "2026-08-04T17:14:50Z",
          "window_end": "2026-08-04T17:45:04Z",
          "status": "source-content",
          "summary": "An existing Reddit comment no longer appeared in the captured thread.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 4,
          "removed_lines": 18
        },
        {
          "observed_at": "2026-08-04T17:14:50Z",
          "window_start": "2026-08-04T16:46:42Z",
          "window_end": "2026-08-04T17:14:50Z",
          "status": "source-content",
          "summary": "The Reddit thread gained 2 new comments.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 16,
          "removed_lines": 0
        },
        {
          "observed_at": "2026-08-04T16:46:42Z",
          "window_start": "2026-08-04T14:43:52Z",
          "window_end": "2026-08-04T16:46:42Z",
          "status": "source-content",
          "summary": "The Reddit thread gained 1 new comment.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 10,
          "removed_lines": 0
        },
        {
          "observed_at": "2026-08-04T14:43:52Z",
          "window_start": "2026-08-04T13:43:55Z",
          "window_end": "2026-08-04T14:43:52Z",
          "status": "source-content",
          "summary": "2 new Reddit comments were posted, including 00-SilverShot,naked_number_one.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 16,
          "removed_lines": 0
        },
        {
          "observed_at": "2026-08-04T13:43:55Z",
          "window_start": "2026-08-04T09:34:00Z",
          "window_end": "2026-08-04T13:43:55Z",
          "status": "source-content",
          "summary": "6 new Reddit comments were posted, including jungle,opossum_cz,Murky_Ad6160.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 50,
          "removed_lines": 0
        }
      ]
    },
    {
      "id": "reddit-1400-btc-hacked-report",
      "title": "r/Bitcoin: report of nearly 1,400 BTC hacked from COLDCARD wallets",
      "url": "https://www.reddit.com/r/Bitcoin/comments/1veauv2/nearly_1400_bitcoin_hacked_from_coldcard_wallets/",
      "organisation": "reddit",
      "kind": "community-discussion",
      "role": "Community discussion",
      "publication_time": null,
      "note": null,
      "gone": null,
      "capture": {
        "status": "held",
        "copies": 8,
        "first_observed": "2026-08-04T09:34:04Z",
        "last_observed": "2026-08-07T06:16:39Z",
        "last_checked": "2026-08-11T04:33:03Z"
      },
      "differences": [
        {
          "observed_at": "2026-08-07T06:16:39Z",
          "window_start": "2026-08-06T16:32:58Z",
          "window_end": "2026-08-07T06:16:39Z",
          "status": "source-content",
          "summary": "The original post was deleted: author HumbleRestaurant790 is now [deleted] and the post body shows [deleted]. The title and comments remain.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 3,
          "removed_lines": 1
        },
        {
          "observed_at": "2026-08-06T16:32:58Z",
          "window_start": "2026-08-05T14:25:26Z",
          "window_end": "2026-08-06T16:32:58Z",
          "status": "source-content",
          "summary": "Two comments by IllllIIlIllIllllIlll were deleted: one remarking it was their first time hearing of the hack, one sarcasm remark. Both now show author and body [deleted].",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 8,
          "removed_lines": 8
        },
        {
          "observed_at": "2026-08-05T14:25:26Z",
          "window_start": "2026-08-05T07:57:02Z",
          "window_end": "2026-08-05T14:25:26Z",
          "status": "source-content",
          "summary": "Several comments were removed or replaced with deleted-account placeholders, including discussion of passphrases, vendor responsibility and regulation.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 2,
          "removed_lines": 26
        },
        {
          "observed_at": "2026-08-05T07:57:02Z",
          "window_start": "2026-08-04T19:14:49Z",
          "window_end": "2026-08-05T07:57:02Z",
          "status": "source-content",
          "summary": "The thread gained a reply saying dice rolls and passphrases were not standard advice five years ago, and alleging that official setup material used a generated seed phrase.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 10,
          "removed_lines": 0
        },
        {
          "observed_at": "2026-08-04T19:14:49Z",
          "window_start": "2026-08-04T15:46:02Z",
          "window_end": "2026-08-04T19:14:49Z",
          "status": "source-content",
          "summary": "The Reddit thread gained 1 new comment.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 8,
          "removed_lines": 0
        },
        {
          "observed_at": "2026-08-04T15:46:02Z",
          "window_start": "2026-08-04T13:44:01Z",
          "window_end": "2026-08-04T15:46:02Z",
          "status": "source-content",
          "summary": "2 new Reddit comments were posted, both by NakedNick_ballin, criticizing the project's testing and design.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 16,
          "removed_lines": 0
        },
        {
          "observed_at": "2026-08-04T13:44:01Z",
          "window_start": "2026-08-04T09:34:04Z",
          "window_end": "2026-08-04T13:44:01Z",
          "status": "source-content",
          "summary": "3 new Reddit comments were posted, including calambacle,PracticalPianist6189,jmeador42.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 24,
          "removed_lines": 0
        }
      ]
    },
    {
      "id": "reddit-trezor-user-alert-email",
      "title": "r/Bitcoin: Trezor's incident-response email to its users",
      "url": "https://www.reddit.com/r/Bitcoin/comments/1vepzf1/trezor_just_woke_up_and_alerted_its_users_by_this/",
      "organisation": "reddit",
      "kind": "community-discussion",
      "role": "Community discussion",
      "publication_time": null,
      "note": null,
      "gone": null,
      "capture": {
        "status": "held",
        "copies": 10,
        "first_observed": "2026-08-04T09:34:09Z",
        "last_observed": "2026-08-09T16:51:40Z",
        "last_checked": "2026-08-11T04:34:06Z"
      },
      "differences": [
        {
          "observed_at": "2026-08-09T16:51:40Z",
          "window_start": "2026-08-07T19:28:48Z",
          "window_end": "2026-08-09T16:51:40Z",
          "status": "source-content",
          "summary": "Two comments by the same author comparing Trezor entropy redundancy to COLDCARD were removed by Reddit, with the author shown as [deleted] and the bodies as [removed].",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 4,
          "removed_lines": 12
        },
        {
          "observed_at": "2026-08-07T19:28:48Z",
          "window_start": "2026-08-07T06:16:45Z",
          "window_end": "2026-08-07T19:28:48Z",
          "status": "source-content",
          "summary": "The thread gained a sub-thread in which a commenter claims Trezor added a back door in a firmware update over a year ago and moved to Passport, and another replies that it sounds concerning but asks no further questions.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 26,
          "removed_lines": 0
        },
        {
          "observed_at": "2026-08-07T06:16:45Z",
          "window_start": "2026-08-06T16:33:04Z",
          "window_end": "2026-08-07T06:16:45Z",
          "status": "source-content",
          "summary": "Two new comments: one says Trezor posted a multi-post statement about the incident on X the day it happened, another asks an earlier commenter to elaborate.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 16,
          "removed_lines": 0
        },
        {
          "observed_at": "2026-08-06T16:33:04Z",
          "window_start": "2026-08-05T21:00:19Z",
          "window_end": "2026-08-06T16:33:04Z",
          "status": "source-content",
          "summary": "New comment from BigvalBROski advising using a passphrase or just buying the ETF.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 8,
          "removed_lines": 0
        },
        {
          "observed_at": "2026-08-05T21:00:19Z",
          "window_start": "2026-08-05T14:25:32Z",
          "window_end": "2026-08-05T21:00:19Z",
          "status": "source-content",
          "summary": "Reddit added a short comment asserting that funds are safe.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 8,
          "removed_lines": 0
        },
        {
          "observed_at": "2026-08-05T14:25:32Z",
          "window_start": "2026-08-05T07:57:09Z",
          "window_end": "2026-08-05T14:25:32Z",
          "status": "source-content",
          "summary": "Multiple comments by one participant were removed and replaced with deleted-account placeholders, withdrawing discussion of entropy sources, vendor trust and possible intent.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 6,
          "removed_lines": 26
        },
        {
          "observed_at": "2026-08-05T07:57:09Z",
          "window_start": "2026-08-04T22:16:28Z",
          "window_end": "2026-08-05T07:57:09Z",
          "status": "source-content",
          "summary": "The thread gained a reply speculating that Trezor was checking details before sending a mass email.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 8,
          "removed_lines": 0
        },
        {
          "observed_at": "2026-08-04T22:16:28Z",
          "window_start": "2026-08-04T21:46:06Z",
          "window_end": "2026-08-04T22:16:28Z",
          "status": "source-content",
          "summary": "The Reddit thread gained 1 new comment about scam Trezor emails.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 8,
          "removed_lines": 0
        },
        {
          "observed_at": "2026-08-04T21:46:06Z",
          "window_start": "2026-08-04T09:34:09Z",
          "window_end": "2026-08-04T21:46:06Z",
          "status": "source-content",
          "summary": "The Reddit thread gained 3 new comments about email records and moving to a new seed.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 24,
          "removed_lines": 0
        }
      ]
    },
    {
      "id": "reddit-attack-timing-speculation",
      "title": "r/Bitcoin: speculation on why the attacker struck when they did",
      "url": "https://www.reddit.com/r/Bitcoin/comments/1vetc6x/the_timing_of_it_all/",
      "organisation": "reddit",
      "kind": "community-discussion",
      "role": "Community discussion",
      "publication_time": null,
      "note": null,
      "gone": null,
      "capture": {
        "status": "held",
        "copies": 11,
        "first_observed": "2026-08-04T09:34:13Z",
        "last_observed": "2026-08-06T10:14:04Z",
        "last_checked": "2026-08-07T07:46:06Z"
      },
      "differences": [
        {
          "observed_at": "2026-08-06T10:14:04Z",
          "window_start": "2026-08-05T14:35:44Z",
          "window_end": "2026-08-06T10:14:04Z",
          "status": "source-content",
          "summary": "Reddit served 1 additional comment record(s); the diff preserves their text and any edits to existing records.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 14,
          "removed_lines": 0
        },
        {
          "observed_at": "2026-08-05T14:35:44Z",
          "window_start": "2026-08-05T08:06:25Z",
          "window_end": "2026-08-05T14:35:44Z",
          "status": "source-content",
          "summary": "Reddit served 2 additional comment record(s); the diff preserves their text and any edits to existing records.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 18,
          "removed_lines": 0
        },
        {
          "observed_at": "2026-08-05T08:06:25Z",
          "window_start": "2026-08-04T21:25:54Z",
          "window_end": "2026-08-05T08:06:25Z",
          "status": "source-content",
          "summary": "Reddit served 2 additional comment record(s); the diff preserves their text and any edits to existing records.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 19,
          "removed_lines": 0
        },
        {
          "observed_at": "2026-08-04T21:25:54Z",
          "window_start": "2026-08-04T15:58:33Z",
          "window_end": "2026-08-04T21:25:54Z",
          "status": "source-content",
          "summary": "The Reddit thread gained 1 new comment about the difficulty of disclosing and fixing the vulnerability.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 8,
          "removed_lines": 0
        },
        {
          "observed_at": "2026-08-04T15:58:33Z",
          "window_start": "2026-08-04T15:23:56Z",
          "window_end": "2026-08-04T15:58:33Z",
          "status": "source-content",
          "summary": "1 new Reddit comment was posted, by VeryThicknLong, speculating about a disgruntled former employee.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 8,
          "removed_lines": 0
        },
        {
          "observed_at": "2026-08-04T15:23:56Z",
          "window_start": "2026-08-04T14:24:00Z",
          "window_end": "2026-08-04T15:23:56Z",
          "status": "source-content",
          "summary": "1 new Reddit comment was posted, by corporate-citizen, linking timing speculation to recent AI advances.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 8,
          "removed_lines": 0
        },
        {
          "observed_at": "2026-08-04T14:24:00Z",
          "window_start": "2026-08-04T13:53:29Z",
          "window_end": "2026-08-04T14:24:00Z",
          "status": "source-content",
          "summary": "1 new Reddit comment was posted, including blackblastie.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 8,
          "removed_lines": 0
        },
        {
          "observed_at": "2026-08-04T13:53:29Z",
          "window_start": "2026-08-04T12:43:36Z",
          "window_end": "2026-08-04T13:53:29Z",
          "status": "source-content",
          "summary": "1 new Reddit comment was posted, including JanPB.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 8,
          "removed_lines": 0
        },
        {
          "observed_at": "2026-08-04T12:43:36Z",
          "window_start": "2026-08-04T11:14:09Z",
          "window_end": "2026-08-04T12:43:36Z",
          "status": "source-content",
          "summary": "One new comment was posted: circuit_breaker, doubting the bug was left in deliberately and saying anyone could have found it.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 8,
          "removed_lines": 0
        },
        {
          "observed_at": "2026-08-04T11:14:09Z",
          "window_start": "2026-08-04T09:34:13Z",
          "window_end": "2026-08-04T11:14:09Z",
          "status": "source-content",
          "summary": "Two new comments were posted: CiaranCarroll ('Interesting...') and anonuemus ('makes most sense').",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 16,
          "removed_lines": 0
        }
      ]
    },
    {
      "id": "reddit-ceo-anthropic-hack-challenge",
      "title": "r/Bitcoin: CEO publicly challenging Anthropic to hack a 100 BTC wallet",
      "url": "https://www.reddit.com/r/Bitcoin/comments/1vdu0rl/this_ceo_just_challenged_anthropic_to_hack_the/",
      "organisation": "reddit",
      "kind": "community-discussion",
      "role": "Community discussion",
      "publication_time": null,
      "note": null,
      "gone": null,
      "capture": {
        "status": "held",
        "copies": 25,
        "first_observed": "2026-08-04T09:34:16Z",
        "last_observed": "2026-08-06T16:42:34Z",
        "last_checked": "2026-08-07T07:47:14Z"
      },
      "differences": [
        {
          "observed_at": "2026-08-06T16:42:34Z",
          "window_start": "2026-08-06T10:14:08Z",
          "window_end": "2026-08-06T16:42:34Z",
          "status": "source-content",
          "summary": "Fields within an existing Reddit post or comment changed; the diff preserves the exact served text.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 2,
          "removed_lines": 0
        },
        {
          "observed_at": "2026-08-06T10:14:08Z",
          "window_start": "2026-08-05T21:11:06Z",
          "window_end": "2026-08-06T10:14:08Z",
          "status": "source-content",
          "summary": "Reddit served 2 additional comment record(s) and 2 previously held comment record(s) omitted; the diff preserves their text and any edits to existing records.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 16,
          "removed_lines": 16
        },
        {
          "observed_at": "2026-08-05T21:11:06Z",
          "window_start": "2026-08-05T14:35:49Z",
          "window_end": "2026-08-05T21:11:06Z",
          "status": "source-content",
          "summary": "Reddit served 1 previously held comment record(s) omitted; the diff preserves their text and any edits to existing records.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 82,
          "removed_lines": 90
        },
        {
          "observed_at": "2026-08-05T14:35:49Z",
          "window_start": "2026-08-05T08:06:30Z",
          "window_end": "2026-08-05T14:35:49Z",
          "status": "source-content",
          "summary": "Reddit served 2 previously held comment record(s) omitted; the diff preserves their text and any edits to existing records.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 0,
          "removed_lines": 16
        },
        {
          "observed_at": "2026-08-05T08:06:30Z",
          "window_start": "2026-08-04T23:32:56Z",
          "window_end": "2026-08-05T08:06:30Z",
          "status": "source-content",
          "summary": "Fields within an existing Reddit post or comment changed; the diff preserves the exact served text.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 1,
          "removed_lines": 1
        },
        {
          "observed_at": "2026-08-04T23:32:56Z",
          "window_start": "2026-08-04T22:26:29Z",
          "window_end": "2026-08-04T23:32:56Z",
          "status": "source-content",
          "summary": "The Reddit thread gained new participant comments.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 1,
          "removed_lines": 9
        },
        {
          "observed_at": "2026-08-04T22:26:29Z",
          "window_start": "2026-08-04T21:55:53Z",
          "window_end": "2026-08-04T22:26:29Z",
          "status": "source-content",
          "summary": "The Reddit thread gained 1 new comment and no longer served an earlier comment.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 9,
          "removed_lines": 9
        },
        {
          "observed_at": "2026-08-04T21:55:53Z",
          "window_start": "2026-08-04T21:25:59Z",
          "window_end": "2026-08-04T21:55:53Z",
          "status": "source-content",
          "summary": "The Reddit thread gained 1 new comment and no longer served an earlier comment.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 9,
          "removed_lines": 11
        },
        {
          "observed_at": "2026-08-04T21:25:59Z",
          "window_start": "2026-08-04T19:55:39Z",
          "window_end": "2026-08-04T21:25:59Z",
          "status": "source-content",
          "summary": "The Reddit thread gained 1 new comment and no longer served an earlier comment.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 9,
          "removed_lines": 9
        },
        {
          "observed_at": "2026-08-04T19:55:39Z",
          "window_start": "2026-08-04T18:55:59Z",
          "window_end": "2026-08-04T19:55:39Z",
          "status": "source-content",
          "summary": "The Reddit thread changed through new comments, removals, or edits.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 12,
          "removed_lines": 10
        },
        {
          "observed_at": "2026-08-04T18:55:59Z",
          "window_start": "2026-08-04T17:54:52Z",
          "window_end": "2026-08-04T18:55:59Z",
          "status": "source-content",
          "summary": "The Reddit capture added a collapsed-replies stub, indicating one additional reply is available under an existing comment.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 2,
          "removed_lines": 0
        },
        {
          "observed_at": "2026-08-04T17:54:52Z",
          "window_start": "2026-08-04T17:24:48Z",
          "window_end": "2026-08-04T17:54:52Z",
          "status": "source-content",
          "summary": "The Reddit thread gained 3 new comments while 4 existing comments no longer appeared.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 25,
          "removed_lines": 32
        },
        {
          "observed_at": "2026-08-04T17:24:48Z",
          "window_start": "2026-08-04T16:56:51Z",
          "window_end": "2026-08-04T17:24:48Z",
          "status": "source-content",
          "summary": "The Reddit thread gained 1 new comment while 1 existing comment no longer appeared.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 19,
          "removed_lines": 19
        },
        {
          "observed_at": "2026-08-04T16:56:51Z",
          "window_start": "2026-08-04T15:58:37Z",
          "window_end": "2026-08-04T16:56:51Z",
          "status": "source-content",
          "summary": "The Reddit thread gained 1 new comment while 1 existing comment no longer appeared.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 11,
          "removed_lines": 9
        },
        {
          "observed_at": "2026-08-04T15:58:37Z",
          "window_start": "2026-08-04T15:24:02Z",
          "window_end": "2026-08-04T15:58:37Z",
          "status": "source-content",
          "summary": "1 new Reddit comment was posted, by Good_Extension_9642. Collapsed-reply counts also changed.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 11,
          "removed_lines": 17
        },
        {
          "observed_at": "2026-08-04T15:24:02Z",
          "window_start": "2026-08-04T14:53:36Z",
          "window_end": "2026-08-04T15:24:02Z",
          "status": "source-content",
          "summary": "The captured reply tree gained a collapsed more-stub indicating nine additional replies under an existing comment.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 1,
          "removed_lines": 1
        },
        {
          "observed_at": "2026-08-04T14:53:36Z",
          "window_start": "2026-08-04T14:24:05Z",
          "window_end": "2026-08-04T14:53:36Z",
          "status": "source-content",
          "summary": "1 new Reddit comment was posted, by BloodSteyn, reporting that an AI model declined the proposed wallet-hack challenge. Collapsed-reply counts also changed.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 15,
          "removed_lines": 17
        },
        {
          "observed_at": "2026-08-04T14:24:05Z",
          "window_start": "2026-08-04T13:53:34Z",
          "window_end": "2026-08-04T14:24:05Z",
          "status": "source-content",
          "summary": "1 new Reddit comment was posted, including stealthnyc.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 9,
          "removed_lines": 9
        },
        {
          "observed_at": "2026-08-04T13:53:34Z",
          "window_start": "2026-08-04T13:14:43Z",
          "window_end": "2026-08-04T13:53:34Z",
          "status": "source-content",
          "summary": "1 new Reddit comment was posted, including CourageLeast4251.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 10,
          "removed_lines": 0
        },
        {
          "observed_at": "2026-08-04T13:14:43Z",
          "window_start": "2026-08-04T12:14:36Z",
          "window_end": "2026-08-04T13:14:43Z",
          "status": "source-content",
          "summary": "1 new Reddit comment was posted, including SeekNDstroy5102.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 9,
          "removed_lines": 9
        },
        {
          "observed_at": "2026-08-04T12:14:36Z",
          "window_start": "2026-08-04T11:43:25Z",
          "window_end": "2026-08-04T12:14:36Z",
          "status": "source-content",
          "summary": "One new comment was posted: DarthLiberty, saying a wallet address alone is not useful for reverse engineering the key without a quantum computer. Ok-East5755's earlier comment fell out of the expanded view into a collapsed more-stub.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 10,
          "removed_lines": 8
        },
        {
          "observed_at": "2026-08-04T11:43:25Z",
          "window_start": "2026-08-04T11:14:15Z",
          "window_end": "2026-08-04T11:43:25Z",
          "status": "source-content",
          "summary": "The collapsed-reply count under comment t1_p1dg8qn rose from 4 to 5, indicating a new reply the flattened capture did not expand. No visible comment text changed.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 1,
          "removed_lines": 1
        },
        {
          "observed_at": "2026-08-04T11:14:15Z",
          "window_start": "2026-08-04T10:14:25Z",
          "window_end": "2026-08-04T11:14:15Z",
          "status": "source-content",
          "summary": "One new comment was posted: Old-Buffalo-5151 arguing a successful AI wallet hack would crash the whole crypto market, so the bet cannot happen. Separately, tacojohn48's earlier comment fell out of the expanded view and now appears only as a collapsed more-stub.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 16,
          "removed_lines": 10
        },
        {
          "observed_at": "2026-08-04T10:14:25Z",
          "window_start": "2026-08-04T09:34:16Z",
          "window_end": "2026-08-04T10:14:25Z",
          "status": "source-content",
          "summary": "The collapsed-reply count under comment t1_p1dh7tp rose from 19 to 20, indicating a new reply the flattened capture did not expand. No visible comment text changed.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 1,
          "removed_lines": 1
        }
      ]
    },
    {
      "id": "reddit-bitcoin-org-still-recommends",
      "title": "r/Bitcoin: bitcoin.org still listing COLDCARD after the disclosure",
      "url": "https://www.reddit.com/r/Bitcoin/comments/1veine5/bitcoinorg_still_recommends_coldcard/",
      "organisation": "reddit",
      "kind": "community-discussion",
      "role": "Community discussion",
      "publication_time": null,
      "note": null,
      "gone": null,
      "capture": {
        "status": "held",
        "copies": 8,
        "first_observed": "2026-08-04T09:34:23Z",
        "last_observed": "2026-08-08T01:59:08Z",
        "last_checked": "2026-08-11T04:35:10Z"
      },
      "differences": [
        {
          "observed_at": "2026-08-08T01:59:08Z",
          "window_start": "2026-08-07T19:28:51Z",
          "window_end": "2026-08-08T01:59:08Z",
          "status": "source-content",
          "summary": "The original post body was removed and replaced with a [removed] marker.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 1,
          "removed_lines": 9
        },
        {
          "observed_at": "2026-08-07T19:28:51Z",
          "window_start": "2026-08-07T12:56:08Z",
          "window_end": "2026-08-07T19:28:51Z",
          "status": "source-content",
          "summary": "The thread gained a comment saying that a hardware wallet is really only needed for the last word of a seed.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 8,
          "removed_lines": 0
        },
        {
          "observed_at": "2026-08-07T12:56:08Z",
          "window_start": "2026-08-06T16:33:09Z",
          "window_end": "2026-08-07T12:56:08Z",
          "status": "source-content",
          "summary": "Two new comments by JumpProfessional3372: one praising the bitcoin.org paranoid guide, one explaining they trust small balances to a software wallet RNG but would dice-roll a seed for serious money.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 20,
          "removed_lines": 0
        },
        {
          "observed_at": "2026-08-06T16:33:09Z",
          "window_start": "2026-08-04T19:46:02Z",
          "window_end": "2026-08-06T16:33:09Z",
          "status": "source-content",
          "summary": "A comment by IllllIIlIllIllllIlll about buying another hardware wallet was self-deleted: author and body now read [deleted].",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 4,
          "removed_lines": 4
        },
        {
          "observed_at": "2026-08-04T19:46:02Z",
          "window_start": "2026-08-04T15:14:59Z",
          "window_end": "2026-08-04T19:46:02Z",
          "status": "source-content",
          "summary": "An existing Reddit comment was edited from “Corrupted” to “Corrupted compromised.”",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 3,
          "removed_lines": 3
        },
        {
          "observed_at": "2026-08-04T15:14:59Z",
          "window_start": "2026-08-04T13:44:12Z",
          "window_end": "2026-08-04T15:14:59Z",
          "status": "source-content",
          "summary": "1 new Reddit comment was posted, by phamtruax.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 8,
          "removed_lines": 0
        },
        {
          "observed_at": "2026-08-04T13:44:12Z",
          "window_start": "2026-08-04T09:34:23Z",
          "window_end": "2026-08-04T13:44:12Z",
          "status": "source-content",
          "summary": "2 new Reddit comments were posted, including SkidMarkShark,lolonaut.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 18,
          "removed_lines": 0
        }
      ]
    },
    {
      "id": "reddit-liability-blame-debate",
      "title": "r/Bitcoin: argument that blaming users shifts liability away from Coinkite",
      "url": "https://www.reddit.com/r/Bitcoin/comments/1vefwkc/blaming_coldcard_users_for_the_entropy/",
      "organisation": "reddit",
      "kind": "community-discussion",
      "role": "Community discussion",
      "publication_time": null,
      "note": null,
      "gone": null,
      "capture": {
        "status": "held",
        "copies": 8,
        "first_observed": "2026-08-04T09:34:28Z",
        "last_observed": "2026-08-07T06:16:56Z",
        "last_checked": "2026-08-11T04:36:13Z"
      },
      "differences": [
        {
          "observed_at": "2026-08-07T06:16:56Z",
          "window_start": "2026-08-06T03:29:39Z",
          "window_end": "2026-08-07T06:16:56Z",
          "status": "source-content",
          "summary": "New top-level comment by Weary-Discipline591, a first-hand victim account claiming Coinkite/Coldcard cost them 3 bitcoins and expressing anger at the company.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 8,
          "removed_lines": 0
        },
        {
          "observed_at": "2026-08-06T03:29:39Z",
          "window_start": "2026-08-05T14:25:43Z",
          "window_end": "2026-08-06T03:29:39Z",
          "status": "source-content",
          "summary": "Reddit now marks two comments questioning users' storage and audit practices as deleted.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 4,
          "removed_lines": 10
        },
        {
          "observed_at": "2026-08-05T14:25:43Z",
          "window_start": "2026-08-05T07:57:19Z",
          "window_end": "2026-08-05T14:25:43Z",
          "status": "source-content",
          "summary": "Reddit served an additional comment arguing that Canadian consumer protection could hold the people involved accountable despite difficulties refunding victims.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 8,
          "removed_lines": 0
        },
        {
          "observed_at": "2026-08-05T07:57:19Z",
          "window_start": "2026-08-04T22:16:39Z",
          "window_end": "2026-08-05T07:57:19Z",
          "status": "source-content",
          "summary": "The thread gained a comment describing a proposed verification process that compares a software-emulated dice-roll wallet hash with the hardware wallet result.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 12,
          "removed_lines": 0
        },
        {
          "observed_at": "2026-08-04T22:16:39Z",
          "window_start": "2026-08-04T14:44:13Z",
          "window_end": "2026-08-04T22:16:39Z",
          "status": "source-content",
          "summary": "The Reddit thread gained 2 new comments about potential liability.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 16,
          "removed_lines": 0
        },
        {
          "observed_at": "2026-08-04T14:44:13Z",
          "window_start": "2026-08-04T13:44:18Z",
          "window_end": "2026-08-04T14:44:13Z",
          "status": "source-content",
          "summary": "Several previously anonymized or deleted comments were removed or replaced with Reddit’s “[removed]” placeholder.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 5,
          "removed_lines": 45
        },
        {
          "observed_at": "2026-08-04T13:44:18Z",
          "window_start": "2026-08-04T09:34:28Z",
          "window_end": "2026-08-04T13:44:18Z",
          "status": "source-content",
          "summary": "2 new Reddit comments were posted, including SeaworthinessSad7300,SkidMarkShark.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 68,
          "removed_lines": 38
        }
      ]
    },
    {
      "id": "reddit-ledger-article-relay",
      "title": "r/Bitcoin: Ledger's article on the incident and its own security model",
      "url": "https://www.reddit.com/r/Bitcoin/comments/1vem0e3/ledger_article_on_the_coldcard_incident_and_why/",
      "organisation": "reddit",
      "kind": "community-discussion",
      "role": "Community discussion",
      "publication_time": null,
      "note": null,
      "gone": null,
      "capture": {
        "status": "held",
        "copies": 5,
        "first_observed": "2026-08-04T09:34:32Z",
        "last_observed": "2026-08-08T01:59:18Z",
        "last_checked": "2026-08-11T04:37:16Z"
      },
      "differences": [
        {
          "observed_at": "2026-08-08T01:59:18Z",
          "window_start": "2026-08-06T16:33:19Z",
          "window_end": "2026-08-08T01:59:18Z",
          "status": "source-content",
          "summary": "A participant comment was deleted and replaced with a [removed] marker.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 2,
          "removed_lines": 8
        },
        {
          "observed_at": "2026-08-06T16:33:19Z",
          "window_start": "2026-08-05T14:25:49Z",
          "window_end": "2026-08-06T16:33:19Z",
          "status": "source-content",
          "summary": "New comment by BruceLee2112 asking what the current go-to wallet is, in reply to a comment speculating about Ledger as cover.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 10,
          "removed_lines": 0
        },
        {
          "observed_at": "2026-08-05T14:25:49Z",
          "window_start": "2026-08-04T13:44:23Z",
          "window_end": "2026-08-05T14:25:49Z",
          "status": "source-content",
          "summary": "Three comments were removed, including claims about Ledger's secure element and seed export, and a statement about open-source code and backdoors.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 0,
          "removed_lines": 30
        },
        {
          "observed_at": "2026-08-04T13:44:23Z",
          "window_start": "2026-08-04T09:34:32Z",
          "window_end": "2026-08-04T13:44:23Z",
          "status": "source-content",
          "summary": "1 new Reddit comment was posted, including omsriver.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 8,
          "removed_lines": 0
        }
      ]
    },
    {
      "id": "reddit-btc-price-holding-up",
      "title": "r/Bitcoin: surprise that the bitcoin price held up through incident week",
      "url": "https://www.reddit.com/r/Bitcoin/comments/1vezvlv/btc_weirdly_holding_up/",
      "organisation": "reddit",
      "kind": "community-discussion",
      "role": "Community discussion",
      "publication_time": null,
      "note": null,
      "gone": null,
      "capture": {
        "status": "held",
        "copies": 29,
        "first_observed": "2026-08-04T09:34:35Z",
        "last_observed": "2026-08-05T21:11:15Z",
        "last_checked": "2026-08-07T07:48:23Z"
      },
      "differences": [
        {
          "observed_at": "2026-08-05T21:11:15Z",
          "window_start": "2026-08-05T08:06:38Z",
          "window_end": "2026-08-05T21:11:15Z",
          "status": "source-content",
          "summary": "Reddit served 1 additional comment record(s); the diff preserves their text and any edits to existing records.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 10,
          "removed_lines": 0
        },
        {
          "observed_at": "2026-08-05T08:06:38Z",
          "window_start": "2026-08-04T23:56:44Z",
          "window_end": "2026-08-05T08:06:38Z",
          "status": "source-content",
          "summary": "Reddit served 4 additional comment record(s) and 1 previously held comment record(s) omitted; the diff preserves their text and any edits to existing records.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 32,
          "removed_lines": 8
        },
        {
          "observed_at": "2026-08-04T23:56:44Z",
          "window_start": "2026-08-04T23:33:04Z",
          "window_end": "2026-08-04T23:56:44Z",
          "status": "source-content",
          "summary": "The Reddit thread gained new participant comments.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 8,
          "removed_lines": 0
        },
        {
          "observed_at": "2026-08-04T23:33:04Z",
          "window_start": "2026-08-04T22:57:39Z",
          "window_end": "2026-08-04T23:33:04Z",
          "status": "source-content",
          "summary": "The Reddit thread gained new participant comments.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 28,
          "removed_lines": 8
        },
        {
          "observed_at": "2026-08-04T22:57:39Z",
          "window_start": "2026-08-04T22:26:37Z",
          "window_end": "2026-08-04T22:57:39Z",
          "status": "source-content",
          "summary": "The Reddit thread gained new participant comments.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 28,
          "removed_lines": 0
        },
        {
          "observed_at": "2026-08-04T22:26:37Z",
          "window_start": "2026-08-04T21:56:04Z",
          "window_end": "2026-08-04T22:26:37Z",
          "status": "source-content",
          "summary": "The Reddit thread gained 2 new comments and no longer served an earlier comment.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 19,
          "removed_lines": 3
        },
        {
          "observed_at": "2026-08-04T21:56:04Z",
          "window_start": "2026-08-04T21:26:07Z",
          "window_end": "2026-08-04T21:56:04Z",
          "status": "source-content",
          "summary": "The Reddit thread gained 2 new comments about the incident's market impact.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 16,
          "removed_lines": 0
        },
        {
          "observed_at": "2026-08-04T21:26:07Z",
          "window_start": "2026-08-04T20:26:19Z",
          "window_end": "2026-08-04T21:26:07Z",
          "status": "source-content",
          "summary": "The Reddit thread gained 1 new comment.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 8,
          "removed_lines": 0
        },
        {
          "observed_at": "2026-08-04T20:26:19Z",
          "window_start": "2026-08-04T19:26:47Z",
          "window_end": "2026-08-04T20:26:19Z",
          "status": "source-content",
          "summary": "The Reddit thread gained 2 new comments.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 17,
          "removed_lines": 1
        },
        {
          "observed_at": "2026-08-04T19:26:47Z",
          "window_start": "2026-08-04T18:56:12Z",
          "window_end": "2026-08-04T19:26:47Z",
          "status": "source-content",
          "summary": "The Reddit thread gained 1 new comment.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 8,
          "removed_lines": 0
        },
        {
          "observed_at": "2026-08-04T18:56:12Z",
          "window_start": "2026-08-04T18:24:44Z",
          "window_end": "2026-08-04T18:56:12Z",
          "status": "source-content",
          "summary": "The Reddit thread gained 3 new comments.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 24,
          "removed_lines": 0
        },
        {
          "observed_at": "2026-08-04T18:24:44Z",
          "window_start": "2026-08-04T17:55:00Z",
          "window_end": "2026-08-04T18:24:44Z",
          "status": "source-content",
          "summary": "The Reddit thread gained 1 new comment.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 8,
          "removed_lines": 0
        },
        {
          "observed_at": "2026-08-04T17:55:00Z",
          "window_start": "2026-08-04T17:24:58Z",
          "window_end": "2026-08-04T17:55:00Z",
          "status": "source-content",
          "summary": "The Reddit thread gained 1 new comment.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 8,
          "removed_lines": 0
        },
        {
          "observed_at": "2026-08-04T17:24:58Z",
          "window_start": "2026-08-04T16:57:00Z",
          "window_end": "2026-08-04T17:24:58Z",
          "status": "source-content",
          "summary": "The Reddit thread gained 1 new comment.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 8,
          "removed_lines": 0
        },
        {
          "observed_at": "2026-08-04T16:57:00Z",
          "window_start": "2026-08-04T16:27:11Z",
          "window_end": "2026-08-04T16:57:00Z",
          "status": "source-content",
          "summary": "The Reddit thread gained 3 new comments.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 24,
          "removed_lines": 0
        },
        {
          "observed_at": "2026-08-04T16:27:11Z",
          "window_start": "2026-08-04T15:58:46Z",
          "window_end": "2026-08-04T16:27:11Z",
          "status": "source-content",
          "summary": "8 new Reddit comments were posted, including originalgainster, TheHollowed_Knight and Different_Umpire9003.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 64,
          "removed_lines": 0
        },
        {
          "observed_at": "2026-08-04T15:58:46Z",
          "window_start": "2026-08-04T15:24:11Z",
          "window_end": "2026-08-04T15:58:46Z",
          "status": "source-content",
          "summary": "9 new Reddit comments were posted, including Far-Afternoon-5121, Objective_Digit and MrMpeg.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 72,
          "removed_lines": 0
        },
        {
          "observed_at": "2026-08-04T15:24:11Z",
          "window_start": "2026-08-04T14:53:44Z",
          "window_end": "2026-08-04T15:24:11Z",
          "status": "source-content",
          "summary": "2 new Reddit comments were posted, including 2LostFlamingos, who contrasted the incident with earlier exchange failures.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 21,
          "removed_lines": 0
        },
        {
          "observed_at": "2026-08-04T14:53:44Z",
          "window_start": "2026-08-04T14:24:15Z",
          "window_end": "2026-08-04T14:53:44Z",
          "status": "source-content",
          "summary": "4 new Reddit comments were posted, including Just_Bluebird_5268, IndependenceTop6501 and mrlandlord.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 32,
          "removed_lines": 0
        },
        {
          "observed_at": "2026-08-04T14:24:15Z",
          "window_start": "2026-08-04T13:53:42Z",
          "window_end": "2026-08-04T14:24:15Z",
          "status": "source-content",
          "summary": "3 new Reddit comments were posted, including korean_kracka,lumiosengineering.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 24,
          "removed_lines": 0
        },
        {
          "observed_at": "2026-08-04T13:53:42Z",
          "window_start": "2026-08-04T13:14:51Z",
          "window_end": "2026-08-04T13:53:42Z",
          "status": "source-content",
          "summary": "8 new Reddit comments were posted, including UpstairsCheetah235,Astronaut6735,revanevan7.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 64,
          "removed_lines": 0
        },
        {
          "observed_at": "2026-08-04T13:14:51Z",
          "window_start": "2026-08-04T12:43:49Z",
          "window_end": "2026-08-04T13:14:51Z",
          "status": "source-content",
          "summary": "8 new Reddit comments were posted, including hrad95,Prestigious_Ear_8055,trademarktower.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 66,
          "removed_lines": 0
        },
        {
          "observed_at": "2026-08-04T12:43:49Z",
          "window_start": "2026-08-04T12:14:43Z",
          "window_end": "2026-08-04T12:43:49Z",
          "status": "source-content",
          "summary": "Three new comments were posted: EnvironmentalYard467 on institutional money and the CLARITY Act, Aggravating-Owl-7050 joking about free bitcoin, and Clear_Item_922 saying the COLDCARD fiasco affected only 0.1% of Bitcoin.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 24,
          "removed_lines": 0
        },
        {
          "observed_at": "2026-08-04T12:14:43Z",
          "window_start": "2026-08-04T11:43:32Z",
          "window_end": "2026-08-04T12:14:43Z",
          "status": "source-content",
          "summary": "Four new comments were posted: youcantexterminateme and DistributionOk2111 discussing the bottom and buying more, a code-breaks joke from sonicode, and DavidssonA reporting that people outside the bubble have not heard of the COLDCARD incident.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 32,
          "removed_lines": 0
        },
        {
          "observed_at": "2026-08-04T11:43:32Z",
          "window_start": "2026-08-04T11:14:22Z",
          "window_end": "2026-08-04T11:43:32Z",
          "status": "source-content",
          "summary": "Five new comments were posted, including theoretical_hipster ('Bad News for CoinKite. Bitcoin is fine.'), a Mark Karpeles joke from Particular-Fall-3194, and other_acc_banned ('I'm convinced it's the bottom').",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 40,
          "removed_lines": 0
        },
        {
          "observed_at": "2026-08-04T11:14:22Z",
          "window_start": "2026-08-04T10:43:15Z",
          "window_end": "2026-08-04T11:14:22Z",
          "status": "source-content",
          "summary": "Four new comments were posted: Efficient_Range1156 on the protocol sustaining attacks for 17 years, Acrobatic_News_4860 blaming FUD rather than sell pressure and wishing for relief toward 90k, and Forded_Fiction24 crediting macroeconomics for holding the price up.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 34,
          "removed_lines": 0
        },
        {
          "observed_at": "2026-08-04T10:43:15Z",
          "window_start": "2026-08-04T10:14:33Z",
          "window_end": "2026-08-04T10:43:15Z",
          "status": "source-content",
          "summary": "One new comment was posted: Firm-Mirror315 ('The longer we stay here the more support it builds at this level').",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 8,
          "removed_lines": 0
        },
        {
          "observed_at": "2026-08-04T10:14:33Z",
          "window_start": "2026-08-04T09:34:35Z",
          "window_end": "2026-08-04T10:14:33Z",
          "status": "source-content",
          "summary": "Three new comments were posted to the thread: broskibrokovski21 p1m93eo (replying to t1_p1l5avj), Madsen13140 p1m96ds and Disavowed_Rogue p1ma5fc (both top-level).",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 24,
          "removed_lines": 0
        }
      ]
    },
    {
      "id": "reddit-cash-out-forensics-question",
      "title": "r/Bitcoin: how the attacker could cash out hundreds of BTC",
      "url": "https://www.reddit.com/r/Bitcoin/comments/1vegndz/a_forensic_question_about_the_coldcard_attacker/",
      "organisation": "reddit",
      "kind": "community-discussion",
      "role": "Community discussion",
      "publication_time": null,
      "note": null,
      "gone": null,
      "capture": {
        "status": "held",
        "copies": 21,
        "first_observed": "2026-08-04T09:34:39Z",
        "last_observed": "2026-08-08T21:32:48Z",
        "last_checked": "2026-08-11T04:38:19Z"
      },
      "differences": [
        {
          "observed_at": "2026-08-08T21:32:48Z",
          "window_start": "2026-08-08T15:02:52Z",
          "window_end": "2026-08-08T21:32:48Z",
          "status": "source-content",
          "summary": "A short comment suggesting P2P cash-out in China was removed from the thread.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 0,
          "removed_lines": 8
        },
        {
          "observed_at": "2026-08-08T15:02:52Z",
          "window_start": "2026-08-07T06:17:03Z",
          "window_end": "2026-08-08T15:02:52Z",
          "status": "source-content",
          "summary": "The thread gained a new comment consisting of 'How do you like dem apples'.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 8,
          "removed_lines": 0
        },
        {
          "observed_at": "2026-08-07T06:17:03Z",
          "window_start": "2026-08-06T16:33:24Z",
          "window_end": "2026-08-07T06:17:03Z",
          "status": "source-content",
          "summary": "New top-level comment by Dreamer5752 saying the perpetrator was not an ordinary scammer and knows how to stay unnoticed.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 8,
          "removed_lines": 0
        },
        {
          "observed_at": "2026-08-06T16:33:24Z",
          "window_start": "2026-08-06T10:00:59Z",
          "window_end": "2026-08-06T16:33:24Z",
          "status": "source-content",
          "summary": "A comment by IllllIIlIllIllllIlll was self-deleted ([deleted]), and a new comment by OrganizationLong3812 describes mixing into privacy coins and selling for cash as the common laundering route.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 14,
          "removed_lines": 4
        },
        {
          "observed_at": "2026-08-06T10:00:59Z",
          "window_start": "2026-08-06T03:29:46Z",
          "window_end": "2026-08-06T10:00:59Z",
          "status": "source-content",
          "summary": "Two new comments: OtherwiseAlbatross14 criticising another user's reading comprehension, and a top-level comment showing \"[ Removed by Reddit ]\".",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 16,
          "removed_lines": 0
        },
        {
          "observed_at": "2026-08-06T03:29:46Z",
          "window_start": "2026-08-05T21:00:41Z",
          "window_end": "2026-08-06T03:29:46Z",
          "status": "source-content",
          "summary": "A commenter’s proposed small-scale cash-out scenario was removed from the thread.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 0,
          "removed_lines": 8
        },
        {
          "observed_at": "2026-08-05T21:00:41Z",
          "window_start": "2026-08-05T14:25:54Z",
          "window_end": "2026-08-05T21:00:41Z",
          "status": "source-content",
          "summary": "The thread gained three comments suggesting luxury-goods and gold purchases as cash-out methods, joking about cocaine, and dismissing an earlier proposal.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 24,
          "removed_lines": 0
        },
        {
          "observed_at": "2026-08-05T14:25:54Z",
          "window_start": "2026-08-05T07:57:26Z",
          "window_end": "2026-08-05T14:25:54Z",
          "status": "source-content",
          "summary": "Reddit served a short exchange noting that a proposed cash-out method would require cooperation from legitimate bitcoin holders and would be neither easy nor safe for them.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 16,
          "removed_lines": 0
        },
        {
          "observed_at": "2026-08-05T07:57:26Z",
          "window_start": "2026-08-05T00:17:08Z",
          "window_end": "2026-08-05T07:57:26Z",
          "status": "source-content",
          "summary": "The thread gained discussion of government recovery, permanent on-chain transaction records and an impractical cash-out scenario, plus a dismissive reply.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 32,
          "removed_lines": 0
        },
        {
          "observed_at": "2026-08-05T00:17:08Z",
          "window_start": "2026-08-04T23:22:29Z",
          "window_end": "2026-08-05T00:17:08Z",
          "status": "source-content",
          "summary": "The Reddit thread gained new participant comments.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 18,
          "removed_lines": 0
        },
        {
          "observed_at": "2026-08-04T23:22:29Z",
          "window_start": "2026-08-04T22:16:46Z",
          "window_end": "2026-08-04T23:22:29Z",
          "status": "source-content",
          "summary": "The Reddit thread gained new participant comments.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 15,
          "removed_lines": 0
        },
        {
          "observed_at": "2026-08-04T22:16:46Z",
          "window_start": "2026-08-04T20:46:18Z",
          "window_end": "2026-08-04T22:16:46Z",
          "status": "source-content",
          "summary": "The Reddit thread gained 2 new comments.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 28,
          "removed_lines": 0
        },
        {
          "observed_at": "2026-08-04T20:46:18Z",
          "window_start": "2026-08-04T20:16:42Z",
          "window_end": "2026-08-04T20:46:18Z",
          "status": "source-content",
          "summary": "The Reddit thread gained 1 new comment.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 10,
          "removed_lines": 0
        },
        {
          "observed_at": "2026-08-04T20:16:42Z",
          "window_start": "2026-08-04T19:46:14Z",
          "window_end": "2026-08-04T20:16:42Z",
          "status": "source-content",
          "summary": "The Reddit thread gained 1 new comment.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 8,
          "removed_lines": 0
        },
        {
          "observed_at": "2026-08-04T19:46:14Z",
          "window_start": "2026-08-04T18:15:01Z",
          "window_end": "2026-08-04T19:46:14Z",
          "status": "source-content",
          "summary": "The Reddit thread gained 1 new comment.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 12,
          "removed_lines": 0
        },
        {
          "observed_at": "2026-08-04T18:15:01Z",
          "window_start": "2026-08-04T16:16:44Z",
          "window_end": "2026-08-04T18:15:01Z",
          "status": "source-content",
          "summary": "The Reddit thread gained 2 new comments.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 16,
          "removed_lines": 0
        },
        {
          "observed_at": "2026-08-04T16:16:44Z",
          "window_start": "2026-08-04T14:44:24Z",
          "window_end": "2026-08-04T16:16:44Z",
          "status": "source-content",
          "summary": "1 new Reddit comment was posted, by 00MacDonald, discussing the Bitfinex hack and customer reimbursement.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 8,
          "removed_lines": 0
        },
        {
          "observed_at": "2026-08-04T14:44:24Z",
          "window_start": "2026-08-04T14:15:17Z",
          "window_end": "2026-08-04T14:44:24Z",
          "status": "source-content",
          "summary": "1 new Reddit comment was posted, including Secret_Operative.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 8,
          "removed_lines": 0
        },
        {
          "observed_at": "2026-08-04T14:15:17Z",
          "window_start": "2026-08-04T13:44:28Z",
          "window_end": "2026-08-04T14:15:17Z",
          "status": "source-content",
          "summary": "1 new Reddit comment was posted, including DaseR9-2.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 10,
          "removed_lines": 0
        },
        {
          "observed_at": "2026-08-04T13:44:28Z",
          "window_start": "2026-08-04T09:34:39Z",
          "window_end": "2026-08-04T13:44:28Z",
          "status": "source-content",
          "summary": "7 new Reddit comments were posted, including DelcimarMartins,upo33,DOG-ZILLA.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 56,
          "removed_lines": 0
        }
      ]
    },
    {
      "id": "reddit-fourth-wave-389-btc",
      "title": "r/Bitcoin: report of a fourth drain wave totalling 389 BTC",
      "url": "https://www.reddit.com/r/Bitcoin/comments/1ve28wl/4th_wave_reported_389_btc_hacked/",
      "organisation": "reddit",
      "kind": "community-discussion",
      "role": "Community discussion",
      "publication_time": null,
      "note": null,
      "gone": null,
      "capture": {
        "status": "held",
        "copies": 14,
        "first_observed": "2026-08-04T09:34:44Z",
        "last_observed": "2026-08-08T21:32:54Z",
        "last_checked": "2026-08-11T04:39:22Z"
      },
      "differences": [
        {
          "observed_at": "2026-08-08T21:32:54Z",
          "window_start": "2026-08-08T15:02:59Z",
          "window_end": "2026-08-08T21:32:54Z",
          "status": "source-content",
          "summary": "The thread gained a new comment about needing to trust someone when buying bitcoin unless mining it.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 10,
          "removed_lines": 0
        },
        {
          "observed_at": "2026-08-08T15:02:59Z",
          "window_start": "2026-08-08T01:59:26Z",
          "window_end": "2026-08-08T15:02:59Z",
          "status": "capture-noise",
          "summary": "The same eight-line 'That is what I was thinking' comment that the previous capture added has dropped out again, so the change is Reddit ranking or hydration churn rather than a source deletion.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 0,
          "removed_lines": 8
        },
        {
          "observed_at": "2026-08-08T01:59:26Z",
          "window_start": "2026-08-07T19:29:07Z",
          "window_end": "2026-08-08T01:59:26Z",
          "status": "source-content",
          "summary": "The Reddit thread gained a new participant comment about trusting a third-party exchange.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 8,
          "removed_lines": 0
        },
        {
          "observed_at": "2026-08-07T19:29:07Z",
          "window_start": "2026-08-07T06:17:07Z",
          "window_end": "2026-08-07T19:29:07Z",
          "status": "source-content",
          "summary": "The thread gained comments blaming an escaped AI and asserting that the drained funds were never on COLDCARD.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 16,
          "removed_lines": 0
        },
        {
          "observed_at": "2026-08-07T06:17:07Z",
          "window_start": "2026-08-06T03:29:51Z",
          "window_end": "2026-08-07T06:17:07Z",
          "status": "source-content",
          "summary": "A comment by 12ealdeal was deleted, and two new comments appeared: one praising Ellipal and Trezor, one from a user reporting a 0.17 BTC loss who says most funds were locked in a Bitcoin-backed loan.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 18,
          "removed_lines": 2
        },
        {
          "observed_at": "2026-08-06T03:29:51Z",
          "window_start": "2026-08-05T14:25:59Z",
          "window_end": "2026-08-06T03:29:51Z",
          "status": "source-content",
          "summary": "The thread gained a brief comment asking the reported activity to stop.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 8,
          "removed_lines": 0
        },
        {
          "observed_at": "2026-08-05T14:25:59Z",
          "window_start": "2026-08-05T01:47:24Z",
          "window_end": "2026-08-05T14:25:59Z",
          "status": "source-content",
          "summary": "Comments advocating distrust of other wallet vendors, closed-source concerns and strong passphrases were removed or replaced with deleted-account placeholders.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 4,
          "removed_lines": 14
        },
        {
          "observed_at": "2026-08-05T01:47:24Z",
          "window_start": "2026-08-04T23:22:35Z",
          "window_end": "2026-08-05T01:47:24Z",
          "status": "source-content",
          "summary": "A comment alleging the incident was an inside job was removed, and its author is now shown as deleted.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 2,
          "removed_lines": 2
        },
        {
          "observed_at": "2026-08-04T23:22:35Z",
          "window_start": "2026-08-04T18:46:13Z",
          "window_end": "2026-08-04T23:22:35Z",
          "status": "source-content",
          "summary": "The Reddit thread gained new participant comments.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 8,
          "removed_lines": 0
        },
        {
          "observed_at": "2026-08-04T18:46:13Z",
          "window_start": "2026-08-04T16:47:23Z",
          "window_end": "2026-08-04T18:46:13Z",
          "status": "source-content",
          "summary": "The Reddit thread gained 1 new comment.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 8,
          "removed_lines": 0
        },
        {
          "observed_at": "2026-08-04T16:47:23Z",
          "window_start": "2026-08-04T15:46:56Z",
          "window_end": "2026-08-04T16:47:23Z",
          "status": "source-content",
          "summary": "The Reddit thread gained 1 new comment.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 8,
          "removed_lines": 0
        },
        {
          "observed_at": "2026-08-04T15:46:56Z",
          "window_start": "2026-08-04T13:44:34Z",
          "window_end": "2026-08-04T15:46:56Z",
          "status": "source-content",
          "summary": "2 new Reddit comments were posted, both by Guava_Poppa, describing the emotional impact of a loss.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 16,
          "removed_lines": 0
        },
        {
          "observed_at": "2026-08-04T13:44:34Z",
          "window_start": "2026-08-04T09:34:44Z",
          "window_end": "2026-08-04T13:44:34Z",
          "status": "source-content",
          "summary": "4 new Reddit comments were posted, including Icy_Giraffe_21,Mobe-E-Duck,dj_destroyer.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 34,
          "removed_lines": 0
        }
      ]
    },
    {
      "id": "reddit-passphrase-vulnerable-question",
      "title": "r/Bitcoin: whether a passphrase protects an affected COLDCARD seed",
      "url": "https://www.reddit.com/r/Bitcoin/comments/1vdzo8p/coldcard_seed_passphrase_could_be_vulnerable_as/",
      "organisation": "reddit",
      "kind": "community-discussion",
      "role": "Community discussion",
      "publication_time": null,
      "note": null,
      "gone": null,
      "capture": {
        "status": "held",
        "copies": 10,
        "first_observed": "2026-08-04T09:34:49Z",
        "last_observed": "2026-08-09T04:05:27Z",
        "last_checked": "2026-08-11T04:40:25Z"
      },
      "differences": [
        {
          "observed_at": "2026-08-09T04:05:27Z",
          "window_start": "2026-08-08T15:03:06Z",
          "window_end": "2026-08-09T04:05:27Z",
          "status": "source-content",
          "summary": "A new comment dismissed state-actor attribution by saying the stolen amount is peanuts to major governments.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 8,
          "removed_lines": 0
        },
        {
          "observed_at": "2026-08-08T15:03:06Z",
          "window_start": "2026-08-05T21:00:53Z",
          "window_end": "2026-08-08T15:03:06Z",
          "status": "source-content",
          "summary": "The thread gained a new comment explaining that a passphrase can include spaces and special characters and that an empty passphrase is valid when the seed is used without an additional passphrase.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 8,
          "removed_lines": 0
        },
        {
          "observed_at": "2026-08-05T21:00:53Z",
          "window_start": "2026-08-05T14:26:03Z",
          "window_end": "2026-08-05T21:00:53Z",
          "status": "source-content",
          "summary": "The thread gained a comment asserting that a mixed-case passphrase with numbers and symbols can provide security comparable to or greater than a 24-word seed.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 10,
          "removed_lines": 0
        },
        {
          "observed_at": "2026-08-05T14:26:03Z",
          "window_start": "2026-08-04T18:15:16Z",
          "window_end": "2026-08-05T14:26:03Z",
          "status": "source-content",
          "summary": "A series of comments by one participant was removed or replaced with deleted-account placeholders, withdrawing opinions about passphrase strength, wallet trust and seed-generation risks.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 12,
          "removed_lines": 62
        },
        {
          "observed_at": "2026-08-04T18:15:16Z",
          "window_start": "2026-08-04T17:45:47Z",
          "window_end": "2026-08-04T18:15:16Z",
          "status": "source-content",
          "summary": "The Reddit thread gained 4 new comments.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 32,
          "removed_lines": 0
        },
        {
          "observed_at": "2026-08-04T17:45:47Z",
          "window_start": "2026-08-04T17:15:40Z",
          "window_end": "2026-08-04T17:45:47Z",
          "status": "source-content",
          "summary": "An existing Reddit comment was edited or removed.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 2,
          "removed_lines": 2
        },
        {
          "observed_at": "2026-08-04T17:15:40Z",
          "window_start": "2026-08-04T14:44:37Z",
          "window_end": "2026-08-04T17:15:40Z",
          "status": "source-content",
          "summary": "The Reddit thread gained 1 new comment.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 8,
          "removed_lines": 0
        },
        {
          "observed_at": "2026-08-04T14:44:37Z",
          "window_start": "2026-08-04T13:44:40Z",
          "window_end": "2026-08-04T14:44:37Z",
          "status": "source-content",
          "summary": "1 new Reddit comment was posted, including FigAggressive237.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 9,
          "removed_lines": 3
        },
        {
          "observed_at": "2026-08-04T13:44:40Z",
          "window_start": "2026-08-04T09:34:49Z",
          "window_end": "2026-08-04T13:44:40Z",
          "status": "source-content",
          "summary": "4 new Reddit comments were posted, including Apprehensive-Sky9723,Nur_2018,ballistua.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 38,
          "removed_lines": 12
        }
      ]
    },
    {
      "id": "reddit-hardware-wallet-comparison",
      "title": "r/Bitcoin: comparison of major hardware wallets after the entropy bug",
      "url": "https://www.reddit.com/r/Bitcoin/comments/1vehzv8/i_compared_every_major_bitcoin_hardware_wallet/",
      "organisation": "reddit",
      "kind": "community-discussion",
      "role": "Community discussion",
      "publication_time": null,
      "note": null,
      "gone": null,
      "capture": {
        "status": "held",
        "copies": 22,
        "first_observed": "2026-08-04T09:34:54Z",
        "last_observed": "2026-08-06T03:30:00Z",
        "last_checked": "2026-08-11T04:41:28Z"
      },
      "differences": [
        {
          "observed_at": "2026-08-06T03:30:00Z",
          "window_start": "2026-08-05T21:01:00Z",
          "window_end": "2026-08-06T03:30:00Z",
          "status": "source-content",
          "summary": "Two previously removed comments were restored under a named account, asking about SeedSigner and physical dice for seed generation.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 4,
          "removed_lines": 4
        },
        {
          "observed_at": "2026-08-05T21:01:00Z",
          "window_start": "2026-08-05T14:26:12Z",
          "window_end": "2026-08-05T21:01:00Z",
          "status": "source-content",
          "summary": "Two SeedSigner comments, including discussion of dice-derived entropy, were removed and replaced with deleted-account placeholders.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 4,
          "removed_lines": 4
        },
        {
          "observed_at": "2026-08-05T14:26:12Z",
          "window_start": "2026-08-05T07:57:41Z",
          "window_end": "2026-08-05T14:26:12Z",
          "status": "source-content",
          "summary": "Several comments were removed or replaced with deleted-account placeholders, including criticism of wallet alternatives, secure elements and open-source licensing; one short request for a destination was also removed.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 12,
          "removed_lines": 48
        },
        {
          "observed_at": "2026-08-05T07:57:41Z",
          "window_start": "2026-08-05T01:47:33Z",
          "window_end": "2026-08-05T07:57:41Z",
          "status": "source-content",
          "summary": "The thread gained a SeedSigner discussion, including commenters' views on camera, dice and coin inputs, roll counts and passphrases.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 38,
          "removed_lines": 0
        },
        {
          "observed_at": "2026-08-05T01:47:33Z",
          "window_start": "2026-08-05T00:47:24Z",
          "window_end": "2026-08-05T01:47:33Z",
          "status": "source-content",
          "summary": "A comment asking how a wallet was heavily restricted was deleted, and its author is now shown as deleted.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 2,
          "removed_lines": 2
        },
        {
          "observed_at": "2026-08-05T00:47:24Z",
          "window_start": "2026-08-04T23:22:48Z",
          "window_end": "2026-08-05T00:47:24Z",
          "status": "source-content",
          "summary": "The post was deleted, replacing its hardware-wallet comparison with \"[deleted]\" and marking its author deleted.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 2,
          "removed_lines": 71
        },
        {
          "observed_at": "2026-08-04T23:22:48Z",
          "window_start": "2026-08-04T22:47:47Z",
          "window_end": "2026-08-04T23:22:48Z",
          "status": "source-content",
          "summary": "The Reddit thread gained comments debating open-source verification and Ledger's security team.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 41,
          "removed_lines": 0
        },
        {
          "observed_at": "2026-08-04T22:47:47Z",
          "window_start": "2026-08-04T22:17:00Z",
          "window_end": "2026-08-04T22:47:47Z",
          "status": "source-content",
          "summary": "The Reddit thread gained a comment arguing that hardware wallets are difficult to recommend to non-technical users.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 8,
          "removed_lines": 0
        },
        {
          "observed_at": "2026-08-04T22:17:00Z",
          "window_start": "2026-08-04T21:46:40Z",
          "window_end": "2026-08-04T22:17:00Z",
          "status": "source-content",
          "summary": "The Reddit thread gained 1 new comment about public code and the incident.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 10,
          "removed_lines": 0
        },
        {
          "observed_at": "2026-08-04T21:46:40Z",
          "window_start": "2026-08-04T20:46:31Z",
          "window_end": "2026-08-04T21:46:40Z",
          "status": "source-content",
          "summary": "The Reddit thread gained 1 new comment.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 8,
          "removed_lines": 0
        },
        {
          "observed_at": "2026-08-04T20:46:31Z",
          "window_start": "2026-08-04T19:46:28Z",
          "window_end": "2026-08-04T20:46:31Z",
          "status": "source-content",
          "summary": "The Reddit thread gained 2 new comments.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 30,
          "removed_lines": 0
        },
        {
          "observed_at": "2026-08-04T19:46:28Z",
          "window_start": "2026-08-04T19:15:42Z",
          "window_end": "2026-08-04T19:46:28Z",
          "status": "source-content",
          "summary": "The Reddit thread gained 2 new comments.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 16,
          "removed_lines": 0
        },
        {
          "observed_at": "2026-08-04T19:15:42Z",
          "window_start": "2026-08-04T18:46:23Z",
          "window_end": "2026-08-04T19:15:42Z",
          "status": "source-content",
          "summary": "The Reddit thread gained 1 new comment.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 10,
          "removed_lines": 0
        },
        {
          "observed_at": "2026-08-04T18:46:23Z",
          "window_start": "2026-08-04T17:45:52Z",
          "window_end": "2026-08-04T18:46:23Z",
          "status": "source-content",
          "summary": "The Reddit thread gained 2 new comments.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 16,
          "removed_lines": 0
        },
        {
          "observed_at": "2026-08-04T17:45:52Z",
          "window_start": "2026-08-04T16:47:33Z",
          "window_end": "2026-08-04T17:45:52Z",
          "status": "source-content",
          "summary": "The Reddit thread gained 2 new comments.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 16,
          "removed_lines": 0
        },
        {
          "observed_at": "2026-08-04T16:47:33Z",
          "window_start": "2026-08-04T16:17:02Z",
          "window_end": "2026-08-04T16:47:33Z",
          "status": "source-content",
          "summary": "The Reddit thread gained 1 new comment.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 8,
          "removed_lines": 0
        },
        {
          "observed_at": "2026-08-04T16:17:02Z",
          "window_start": "2026-08-04T15:47:21Z",
          "window_end": "2026-08-04T16:17:02Z",
          "status": "source-content",
          "summary": "1 new Reddit comment was posted, by Hero_Dose, mentioning SecuX.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 8,
          "removed_lines": 0
        },
        {
          "observed_at": "2026-08-04T15:47:21Z",
          "window_start": "2026-08-04T14:44:43Z",
          "window_end": "2026-08-04T15:47:21Z",
          "status": "source-content",
          "summary": "2 new Reddit comments were posted, including a BitBox representative describing five claimed seed-entropy inputs and linking its code.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 32,
          "removed_lines": 0
        },
        {
          "observed_at": "2026-08-04T14:44:43Z",
          "window_start": "2026-08-04T14:15:31Z",
          "window_end": "2026-08-04T14:44:43Z",
          "status": "source-content",
          "summary": "1 new Reddit comment was posted, including Dextradomis.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 15,
          "removed_lines": 1
        },
        {
          "observed_at": "2026-08-04T14:15:31Z",
          "window_start": "2026-08-04T13:44:46Z",
          "window_end": "2026-08-04T14:15:31Z",
          "status": "source-content",
          "summary": "2 new Reddit comments were posted, including OldHamburger7923,disruptioncoin.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 20,
          "removed_lines": 0
        },
        {
          "observed_at": "2026-08-04T13:44:46Z",
          "window_start": "2026-08-04T09:34:54Z",
          "window_end": "2026-08-04T13:44:46Z",
          "status": "source-content",
          "summary": "46 new Reddit comments were posted, including slvbtc,pcvcolin,TheDuhbb.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 395,
          "removed_lines": 0
        }
      ]
    },
    {
      "id": "reddit-88m-hack-not-over",
      "title": "r/Bitcoin: press report warning all vulnerable wallets will eventually be drained",
      "url": "https://www.reddit.com/r/Bitcoin/comments/1ve8w11/bitcoins_88m_coldcard_hack_isnt_over_experts_warn/",
      "organisation": "reddit",
      "kind": "community-discussion",
      "role": "Community discussion",
      "publication_time": null,
      "note": null,
      "gone": null,
      "capture": {
        "status": "held",
        "copies": 2,
        "first_observed": "2026-08-04T09:34:59Z",
        "last_observed": "2026-08-04T13:44:50Z",
        "last_checked": "2026-08-11T04:42:31Z"
      },
      "differences": [
        {
          "observed_at": "2026-08-04T13:44:50Z",
          "window_start": "2026-08-04T09:34:59Z",
          "window_end": "2026-08-04T13:44:50Z",
          "status": "source-content",
          "summary": "3 new Reddit comments were posted, including CiaranCarroll,dj_destroyer.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 26,
          "removed_lines": 0
        }
      ]
    },
    {
      "id": "reddit-same-address-collision-question",
      "title": "r/Bitcoin: why affected COLDCARDs did not produce duplicate addresses",
      "url": "https://www.reddit.com/r/Bitcoin/comments/1vemf3k/how_come_multiple_same_addresses_werent_created/",
      "organisation": "reddit",
      "kind": "community-discussion",
      "role": "Community discussion",
      "publication_time": null,
      "note": null,
      "gone": null,
      "capture": {
        "status": "held",
        "copies": 5,
        "first_observed": "2026-08-04T09:43:05Z",
        "last_observed": "2026-08-05T14:26:20Z",
        "last_checked": "2026-08-11T04:43:34Z"
      },
      "differences": [
        {
          "observed_at": "2026-08-05T14:26:20Z",
          "window_start": "2026-08-04T16:17:10Z",
          "window_end": "2026-08-05T14:26:20Z",
          "status": "source-content",
          "summary": "Two comments were removed or replaced with a deleted-account placeholder, including a claim about earlier COLDCARD losses and a statement about hash collisions.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 2,
          "removed_lines": 10
        },
        {
          "observed_at": "2026-08-04T16:17:10Z",
          "window_start": "2026-08-04T15:15:38Z",
          "window_end": "2026-08-04T16:17:10Z",
          "status": "source-content",
          "summary": "1 new Reddit comment was posted, by DragonflyBoom, arguing that different 40-bit inputs cannot collide after expansion to a BIP39 seed.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 8,
          "removed_lines": 0
        },
        {
          "observed_at": "2026-08-04T15:15:38Z",
          "window_start": "2026-08-04T13:44:54Z",
          "window_end": "2026-08-04T15:15:38Z",
          "status": "source-content",
          "summary": "1 new Reddit comment was posted, by marvelish, quoting an AI-generated comparison of vulnerable-seed collision odds.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 13,
          "removed_lines": 0
        },
        {
          "observed_at": "2026-08-04T13:44:54Z",
          "window_start": "2026-08-04T09:43:05Z",
          "window_end": "2026-08-04T13:44:54Z",
          "status": "source-content",
          "summary": "2 new Reddit comments were posted, including Icy_Giraffe_21,skr_replicator.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 16,
          "removed_lines": 0
        }
      ]
    },
    {
      "id": "reddit-coinkite-email-data-retention",
      "title": "r/Bitcoin: owner reports Coinkite outreach email despite 90-day data policy",
      "url": "https://www.reddit.com/r/Bitcoin/comments/1vecnrt/coinkite_reached_out_to_me_via_email_although/",
      "organisation": "reddit",
      "kind": "community-discussion",
      "role": "Community discussion",
      "publication_time": null,
      "note": null,
      "gone": null,
      "capture": {
        "status": "held",
        "copies": 3,
        "first_observed": "2026-08-04T09:43:09Z",
        "last_observed": "2026-08-06T16:34:00Z",
        "last_checked": "2026-08-11T04:44:37Z"
      },
      "differences": [
        {
          "observed_at": "2026-08-06T16:34:00Z",
          "window_start": "2026-08-05T14:26:23Z",
          "window_end": "2026-08-06T16:34:00Z",
          "status": "source-content",
          "summary": "A comment by IllllIIlIllIllllIlll about SPF, DKIM and DMARC making spoofed emails easy to spot was self-deleted: author and body now read [deleted].",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 3,
          "removed_lines": 3
        },
        {
          "observed_at": "2026-08-05T14:26:23Z",
          "window_start": "2026-08-04T09:43:09Z",
          "window_end": "2026-08-05T14:26:23Z",
          "status": "source-content",
          "summary": "Reddit no longer served a comment comparing the need for phone-line regulation to a wild-west environment.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 0,
          "removed_lines": 8
        }
      ]
    },
    {
      "id": "reddit-bought-last-week",
      "title": "r/Bitcoin: buyer of a COLDCARD last week asking whether to throw it away",
      "url": "https://www.reddit.com/r/Bitcoin/comments/1veessi/i_got_a_coldcard_last_week_am_i_suppose_to_throw/",
      "organisation": "reddit",
      "kind": "community-discussion",
      "role": "Community discussion",
      "publication_time": null,
      "note": null,
      "gone": null,
      "capture": {
        "status": "held",
        "copies": 13,
        "first_observed": "2026-08-04T09:43:13Z",
        "last_observed": "2026-08-09T23:23:03Z",
        "last_checked": "2026-08-11T04:45:41Z"
      },
      "differences": [
        {
          "observed_at": "2026-08-09T23:23:03Z",
          "window_start": "2026-08-07T06:17:31Z",
          "window_end": "2026-08-09T23:23:03Z",
          "status": "source-content",
          "summary": "The OP added a reply denying that they are a bot.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 8,
          "removed_lines": 0
        },
        {
          "observed_at": "2026-08-07T06:17:31Z",
          "window_start": "2026-08-06T16:34:04Z",
          "window_end": "2026-08-07T06:17:31Z",
          "status": "source-content",
          "summary": "New top-level comment by Good_Extension_9642: \"I'll burn it to ashes!\"",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 8,
          "removed_lines": 0
        },
        {
          "observed_at": "2026-08-06T16:34:04Z",
          "window_start": "2026-08-06T10:01:38Z",
          "window_end": "2026-08-06T16:34:04Z",
          "status": "source-content",
          "summary": "Three new comments: NoBrosCrypto explaining dice rolls add entropy to seed generation, Bionic_Push asking why this is not default, and NoBrosCrypto replying that they do not know.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 24,
          "removed_lines": 0
        },
        {
          "observed_at": "2026-08-06T10:01:38Z",
          "window_start": "2026-08-06T03:30:22Z",
          "window_end": "2026-08-06T10:01:38Z",
          "status": "source-content",
          "summary": "A comment by DonTheHolder (\"Trash that shit bro\") no longer appears in the thread; it was deleted on the source.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 0,
          "removed_lines": 8
        },
        {
          "observed_at": "2026-08-06T03:30:22Z",
          "window_start": "2026-08-05T21:01:21Z",
          "window_end": "2026-08-06T03:30:22Z",
          "status": "source-content",
          "summary": "The thread gained advice to use the device only for signing and create a new seed phrase if the owner no longer trusts it.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 8,
          "removed_lines": 0
        },
        {
          "observed_at": "2026-08-05T21:01:21Z",
          "window_start": "2026-08-05T14:26:27Z",
          "window_end": "2026-08-05T21:01:21Z",
          "status": "source-content",
          "summary": "Reddit no longer served a comment advising a firmware update, dice-generated seed phrase and passphrase.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 0,
          "removed_lines": 8
        },
        {
          "observed_at": "2026-08-05T14:26:27Z",
          "window_start": "2026-08-04T21:46:55Z",
          "window_end": "2026-08-05T14:26:27Z",
          "status": "source-content",
          "summary": "Several comments were removed or replaced with a deleted-account placeholder, withdrawing advice to generate a seed with dice and criticism of other wallet vendors.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 4,
          "removed_lines": 26
        },
        {
          "observed_at": "2026-08-04T21:46:55Z",
          "window_start": "2026-08-04T19:46:43Z",
          "window_end": "2026-08-04T21:46:55Z",
          "status": "source-content",
          "summary": "The thread no longer served two earlier comments that duplicated nearby discussion.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 0,
          "removed_lines": 16
        },
        {
          "observed_at": "2026-08-04T19:46:43Z",
          "window_start": "2026-08-04T16:47:48Z",
          "window_end": "2026-08-04T19:46:43Z",
          "status": "source-content",
          "summary": "The Reddit thread gained 1 new comment.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 12,
          "removed_lines": 0
        },
        {
          "observed_at": "2026-08-04T16:47:48Z",
          "window_start": "2026-08-04T16:17:17Z",
          "window_end": "2026-08-04T16:47:48Z",
          "status": "source-content",
          "summary": "An existing Reddit comment was edited or removed.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 3,
          "removed_lines": 1
        },
        {
          "observed_at": "2026-08-04T16:17:17Z",
          "window_start": "2026-08-04T13:45:01Z",
          "window_end": "2026-08-04T16:17:17Z",
          "status": "source-content",
          "summary": "1 new Reddit comment was posted, by riscten, clarifying that deriving private keys from the weak pattern counts as hacking.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 8,
          "removed_lines": 0
        },
        {
          "observed_at": "2026-08-04T13:45:01Z",
          "window_start": "2026-08-04T09:43:13Z",
          "window_end": "2026-08-04T13:45:01Z",
          "status": "source-content",
          "summary": "1 new Reddit comment was posted, including DavidssonA.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 12,
          "removed_lines": 0
        }
      ]
    },
    {
      "id": "reddit-secure-btc-after-incident",
      "title": "r/Bitcoin: what to do now to secure bitcoin held on a COLDCARD",
      "url": "https://www.reddit.com/r/Bitcoin/comments/1veuo5u/cold_card_so_what_do_i_have_to_do_to_secure_my/",
      "organisation": "reddit",
      "kind": "community-discussion",
      "role": "Community discussion",
      "publication_time": null,
      "note": null,
      "gone": null,
      "capture": {
        "status": "held",
        "copies": 15,
        "first_observed": "2026-08-04T09:43:17Z",
        "last_observed": "2026-08-09T23:23:09Z",
        "last_checked": "2026-08-11T04:46:44Z"
      },
      "differences": [
        {
          "observed_at": "2026-08-09T23:23:09Z",
          "window_start": "2026-08-08T15:03:41Z",
          "window_end": "2026-08-09T23:23:09Z",
          "status": "source-content",
          "summary": "An existing comment by hero_in_time was deleted, leaving '[deleted]' as both author and body.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 2,
          "removed_lines": 2
        },
        {
          "observed_at": "2026-08-08T15:03:41Z",
          "window_start": "2026-08-06T03:30:27Z",
          "window_end": "2026-08-08T15:03:41Z",
          "status": "source-content",
          "summary": "A one-word 'Sell' comment was removed from the thread.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 0,
          "removed_lines": 8
        },
        {
          "observed_at": "2026-08-06T03:30:27Z",
          "window_start": "2026-08-05T21:01:27Z",
          "window_end": "2026-08-06T03:30:27Z",
          "status": "source-content",
          "summary": "The thread gained two terse recommendations, one to sell and one to use Bitkey.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 16,
          "removed_lines": 0
        },
        {
          "observed_at": "2026-08-05T21:01:27Z",
          "window_start": "2026-08-05T14:26:31Z",
          "window_end": "2026-08-05T21:01:27Z",
          "status": "source-content",
          "summary": "Reddit no longer served a one-word comment advising the poster to sell.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 0,
          "removed_lines": 8
        },
        {
          "observed_at": "2026-08-05T14:26:31Z",
          "window_start": "2026-08-05T07:57:59Z",
          "window_end": "2026-08-05T14:26:31Z",
          "status": "source-content",
          "summary": "Reddit served a new exchange debating whether open source, public scrutiny and lack of known compromise justify confidence in Trezor's entropy generation.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 57,
          "removed_lines": 0
        },
        {
          "observed_at": "2026-08-05T07:57:59Z",
          "window_start": "2026-08-05T01:17:47Z",
          "window_end": "2026-08-05T07:57:59Z",
          "status": "source-content",
          "summary": "One comment about the tradeoff between security and access disappeared, and the thread gained a question about keeping bitcoin on an unplugged hard drive.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 8,
          "removed_lines": 8
        },
        {
          "observed_at": "2026-08-05T01:17:47Z",
          "window_start": "2026-08-04T22:17:19Z",
          "window_end": "2026-08-05T01:17:47Z",
          "status": "source-content",
          "summary": "A Reddit comment was edited to correct punctuation in its discussion of historic fraud and the centralization of banking.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 2,
          "removed_lines": 2
        },
        {
          "observed_at": "2026-08-04T22:17:19Z",
          "window_start": "2026-08-04T19:16:03Z",
          "window_end": "2026-08-04T22:17:19Z",
          "status": "source-content",
          "summary": "The Reddit thread gained 1 new comment recommending an insured exchange.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 8,
          "removed_lines": 0
        },
        {
          "observed_at": "2026-08-04T19:16:03Z",
          "window_start": "2026-08-04T18:46:43Z",
          "window_end": "2026-08-04T19:16:03Z",
          "status": "source-content",
          "summary": "The Reddit thread gained 1 new comment.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 20,
          "removed_lines": 0
        },
        {
          "observed_at": "2026-08-04T18:46:43Z",
          "window_start": "2026-08-04T18:15:40Z",
          "window_end": "2026-08-04T18:46:43Z",
          "status": "source-content",
          "summary": "The Reddit thread changed through new comments, removals, or edits.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 73,
          "removed_lines": 3
        },
        {
          "observed_at": "2026-08-04T18:15:40Z",
          "window_start": "2026-08-04T17:46:10Z",
          "window_end": "2026-08-04T18:15:40Z",
          "status": "source-content",
          "summary": "The Reddit thread gained 1 new comment.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 9,
          "removed_lines": 0
        },
        {
          "observed_at": "2026-08-04T17:46:10Z",
          "window_start": "2026-08-04T16:47:52Z",
          "window_end": "2026-08-04T17:46:10Z",
          "status": "source-content",
          "summary": "The Reddit thread gained 1 new comment.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 14,
          "removed_lines": 0
        },
        {
          "observed_at": "2026-08-04T16:47:52Z",
          "window_start": "2026-08-04T13:45:05Z",
          "window_end": "2026-08-04T16:47:52Z",
          "status": "source-content",
          "summary": "The Reddit thread gained 1 new comment.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 8,
          "removed_lines": 0
        },
        {
          "observed_at": "2026-08-04T13:45:05Z",
          "window_start": "2026-08-04T09:43:17Z",
          "window_end": "2026-08-04T13:45:05Z",
          "status": "source-content",
          "summary": "3 new Reddit comments were posted, including One-Adhesiveness-138,CiaranCarroll,skr_replicator.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 28,
          "removed_lines": 0
        }
      ]
    },
    {
      "id": "reddit-throw-away-coldcard",
      "title": "r/Bitcoin: whether to throw away a COLDCARD",
      "url": "https://www.reddit.com/r/Bitcoin/comments/1veuene/do_i_throw_away_my_coldcard/",
      "organisation": "reddit",
      "kind": "community-discussion",
      "role": "Community discussion",
      "publication_time": null,
      "note": null,
      "gone": null,
      "capture": {
        "status": "held",
        "copies": 6,
        "first_observed": "2026-08-04T09:43:20Z",
        "last_observed": "2026-08-05T21:11:22Z",
        "last_checked": "2026-08-07T07:49:32Z"
      },
      "differences": [
        {
          "observed_at": "2026-08-05T21:11:22Z",
          "window_start": "2026-08-04T21:26:13Z",
          "window_end": "2026-08-05T21:11:22Z",
          "status": "source-content",
          "summary": "Reddit served 1 previously held comment record(s) omitted; the diff preserves their text and any edits to existing records.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 0,
          "removed_lines": 8
        },
        {
          "observed_at": "2026-08-04T21:26:13Z",
          "window_start": "2026-08-04T12:43:55Z",
          "window_end": "2026-08-04T21:26:13Z",
          "status": "source-content",
          "summary": "The Reddit thread gained 2 new comments about device replacement and seed entropy.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 16,
          "removed_lines": 0
        },
        {
          "observed_at": "2026-08-04T12:43:55Z",
          "window_start": "2026-08-04T12:14:49Z",
          "window_end": "2026-08-04T12:43:55Z",
          "status": "source-content",
          "summary": "Two new comments were posted: DoctorDownvotesDelux noting a seed generated elsewhere and imported should be fine though they probably would not, and NuggedClarp asking whether cold storage ultimately depends on a third-party company staying in business.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 16,
          "removed_lines": 0
        },
        {
          "observed_at": "2026-08-04T12:14:49Z",
          "window_start": "2026-08-04T11:14:27Z",
          "window_end": "2026-08-04T12:14:49Z",
          "status": "source-content",
          "summary": "One new comment was posted: nachtraum ('That's why I only have minimal funds at banks').",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 8,
          "removed_lines": 0
        },
        {
          "observed_at": "2026-08-04T11:14:27Z",
          "window_start": "2026-08-04T09:43:20Z",
          "window_end": "2026-08-04T11:14:27Z",
          "status": "source-content",
          "summary": "Two new comments were posted by FavorableMadness: advising to keep the patched device as it remains as good as any other, and asking whether bank tellers are highly skilled money managers.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 16,
          "removed_lines": 0
        }
      ]
    },
    {
      "id": "reddit-victim-support-psa",
      "title": "r/Bitcoin: appeal to drained owners not to do anything drastic",
      "url": "https://www.reddit.com/r/Bitcoin/comments/1vdxmk0/psa_to_anyone_who_got_their_coldcard_wallet/",
      "organisation": "reddit",
      "kind": "community-discussion",
      "role": "Community discussion",
      "publication_time": null,
      "note": null,
      "gone": null,
      "capture": {
        "status": "held",
        "copies": 4,
        "first_observed": "2026-08-04T09:43:24Z",
        "last_observed": "2026-08-08T21:33:38Z",
        "last_checked": "2026-08-11T04:47:47Z"
      },
      "differences": [
        {
          "observed_at": "2026-08-08T21:33:38Z",
          "window_start": "2026-08-04T18:46:48Z",
          "window_end": "2026-08-08T21:33:38Z",
          "status": "source-content",
          "summary": "A commenter account was deleted, replacing one comment with [deleted], and an earlier class-action comment was removed.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 2,
          "removed_lines": 10
        },
        {
          "observed_at": "2026-08-04T18:46:48Z",
          "window_start": "2026-08-04T13:45:09Z",
          "window_end": "2026-08-04T18:46:48Z",
          "status": "source-content",
          "summary": "The Reddit thread gained 3 new comments.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 24,
          "removed_lines": 0
        },
        {
          "observed_at": "2026-08-04T13:45:09Z",
          "window_start": "2026-08-04T09:43:24Z",
          "window_end": "2026-08-04T13:45:09Z",
          "status": "source-content",
          "summary": "1 new Reddit comment was posted, including LanguageStudyBuddy.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 8,
          "removed_lines": 0
        }
      ]
    },
    {
      "id": "reddit-sun-will-rise",
      "title": "r/Bitcoin: FTX-loss survivor's message to COLDCARD drain victims",
      "url": "https://www.reddit.com/r/Bitcoin/comments/1vdvtmu/psa_tomorrow_the_sun_will_rise_again/",
      "organisation": "reddit",
      "kind": "community-discussion",
      "role": "Community discussion",
      "publication_time": null,
      "note": null,
      "gone": null,
      "capture": {
        "status": "held",
        "copies": 6,
        "first_observed": "2026-08-04T09:43:27Z",
        "last_observed": "2026-08-08T02:00:02Z",
        "last_checked": "2026-08-11T04:48:50Z"
      },
      "differences": [
        {
          "observed_at": "2026-08-08T02:00:02Z",
          "window_start": "2026-08-07T19:29:45Z",
          "window_end": "2026-08-08T02:00:02Z",
          "status": "source-content",
          "summary": "The Reddit thread gained a new participant comment.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 10,
          "removed_lines": 0
        },
        {
          "observed_at": "2026-08-07T19:29:45Z",
          "window_start": "2026-08-07T06:17:42Z",
          "window_end": "2026-08-07T19:29:45Z",
          "status": "source-content",
          "summary": "The thread gained a comment hoping Bitcoin drops to five dollars per coin or to zero to equalize rich and poor holders.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 8,
          "removed_lines": 0
        },
        {
          "observed_at": "2026-08-07T06:17:42Z",
          "window_start": "2026-08-06T16:34:22Z",
          "window_end": "2026-08-07T06:17:42Z",
          "status": "source-content",
          "summary": "New comment from Greedy-Helicopter-99: \"yes but now im 68 years old\".",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 8,
          "removed_lines": 0
        },
        {
          "observed_at": "2026-08-06T16:34:22Z",
          "window_start": "2026-08-06T10:01:56Z",
          "window_end": "2026-08-06T16:34:22Z",
          "status": "source-content",
          "summary": "A comment by CraftyBrother6974 (\"Just put the fries in the bag\") was removed, and basedisciple added a comment criticising the post as loss-porn that does nothing for victims.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 8,
          "removed_lines": 8
        },
        {
          "observed_at": "2026-08-06T10:01:56Z",
          "window_start": "2026-08-04T09:43:27Z",
          "window_end": "2026-08-06T10:01:56Z",
          "status": "source-content",
          "summary": "A comment by DonTheHolder (\"2 mil?\") was removed from the thread.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 0,
          "removed_lines": 8
        }
      ]
    },
    {
      "id": "reddit-unconsolidated-drain-account",
      "title": "r/Bitcoin: victim whose drained coins sit apart from the known consolidation set",
      "url": "https://www.reddit.com/r/Bitcoin/comments/1veo132/coldcard_loss_question/",
      "organisation": "reddit",
      "kind": "community-discussion",
      "role": "Community discussion",
      "publication_time": null,
      "note": null,
      "gone": null,
      "capture": {
        "status": "held",
        "copies": 1,
        "first_observed": "2026-08-04T09:45:50Z",
        "last_observed": "2026-08-04T09:45:50Z",
        "last_checked": "2026-08-11T04:49:53Z"
      },
      "differences": []
    },
    {
      "id": "reddit-retirement-attack-resurfaced",
      "title": "r/Bitcoin: 2021 COLDCARD post joking about a 'retirement attack' resurfaced",
      "url": "https://www.reddit.com/r/Bitcoin/comments/1vf0ut0/coldcard_post_from_october_10_2021_retirement/",
      "organisation": "reddit",
      "kind": "community-discussion",
      "role": "Community discussion",
      "publication_time": null,
      "note": null,
      "gone": null,
      "capture": {
        "status": "held",
        "copies": 27,
        "first_observed": "2026-08-04T09:43:36Z",
        "last_observed": "2026-08-06T16:42:53Z",
        "last_checked": "2026-08-07T07:50:41Z"
      },
      "differences": [
        {
          "observed_at": "2026-08-06T16:42:53Z",
          "window_start": "2026-08-06T10:14:26Z",
          "window_end": "2026-08-06T16:42:53Z",
          "status": "source-content",
          "summary": "Reddit served 2 additional comment record(s); the diff preserves their text and any edits to existing records.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 20,
          "removed_lines": 0
        },
        {
          "observed_at": "2026-08-06T10:14:26Z",
          "window_start": "2026-08-06T03:41:07Z",
          "window_end": "2026-08-06T10:14:26Z",
          "status": "source-content",
          "summary": "Fields within an existing Reddit post or comment changed; the diff preserves the exact served text.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 3,
          "removed_lines": 3
        },
        {
          "observed_at": "2026-08-06T03:41:07Z",
          "window_start": "2026-08-05T14:36:08Z",
          "window_end": "2026-08-06T03:41:07Z",
          "status": "source-content",
          "summary": "Reddit served 2 additional comment record(s); the diff preserves their text and any edits to existing records.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 18,
          "removed_lines": 0
        },
        {
          "observed_at": "2026-08-05T14:36:08Z",
          "window_start": "2026-08-05T08:06:49Z",
          "window_end": "2026-08-05T14:36:08Z",
          "status": "source-content",
          "summary": "Reddit served 1 additional comment record(s); the diff preserves their text and any edits to existing records.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 8,
          "removed_lines": 0
        },
        {
          "observed_at": "2026-08-05T08:06:49Z",
          "window_start": "2026-08-05T01:56:39Z",
          "window_end": "2026-08-05T08:06:49Z",
          "status": "source-content",
          "summary": "Reddit served 6 additional comment record(s); the diff preserves their text and any edits to existing records.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 55,
          "removed_lines": 0
        },
        {
          "observed_at": "2026-08-05T01:56:39Z",
          "window_start": "2026-08-04T23:56:54Z",
          "window_end": "2026-08-05T01:56:39Z",
          "status": "source-content",
          "summary": "The Reddit thread gained one reply saying the incident improved COLDCARD and another saying a few mistaken manual inputs do not matter.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 16,
          "removed_lines": 0
        },
        {
          "observed_at": "2026-08-04T23:56:54Z",
          "window_start": "2026-08-04T23:33:15Z",
          "window_end": "2026-08-04T23:56:54Z",
          "status": "source-content",
          "summary": "The Reddit thread gained a comment raising possible bias in inexpensive dice.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 8,
          "removed_lines": 0
        },
        {
          "observed_at": "2026-08-04T23:33:15Z",
          "window_start": "2026-08-04T22:26:48Z",
          "window_end": "2026-08-04T23:33:15Z",
          "status": "source-content",
          "summary": "The Reddit thread gained comments about earlier reports of recurring drains and initial disbelief from readers.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 16,
          "removed_lines": 0
        },
        {
          "observed_at": "2026-08-04T22:26:48Z",
          "window_start": "2026-08-04T21:56:15Z",
          "window_end": "2026-08-04T22:26:48Z",
          "status": "source-content",
          "summary": "An existing Reddit comment was edited to add a preference for QRNG over dice rolls.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 3,
          "removed_lines": 2
        },
        {
          "observed_at": "2026-08-04T21:56:15Z",
          "window_start": "2026-08-04T21:26:18Z",
          "window_end": "2026-08-04T21:56:15Z",
          "status": "source-content",
          "summary": "The Reddit thread gained 2 new comments about entropy generation and dice rolls.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 20,
          "removed_lines": 0
        },
        {
          "observed_at": "2026-08-04T21:26:18Z",
          "window_start": "2026-08-04T20:56:21Z",
          "window_end": "2026-08-04T21:26:18Z",
          "status": "source-content",
          "summary": "The Reddit thread gained 2 new comments about air-gapped signing and seed migration.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 20,
          "removed_lines": 0
        },
        {
          "observed_at": "2026-08-04T20:56:21Z",
          "window_start": "2026-08-04T20:26:30Z",
          "window_end": "2026-08-04T20:56:21Z",
          "status": "source-content",
          "summary": "The Reddit thread gained 1 new comment contrasting a claimed 2^32 search with a 2^128 security target.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 12,
          "removed_lines": 0
        },
        {
          "observed_at": "2026-08-04T20:26:30Z",
          "window_start": "2026-08-04T19:55:58Z",
          "window_end": "2026-08-04T20:26:30Z",
          "status": "source-content",
          "summary": "The Reddit thread gained 2 new comments.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 18,
          "removed_lines": 0
        },
        {
          "observed_at": "2026-08-04T19:55:58Z",
          "window_start": "2026-08-04T18:24:55Z",
          "window_end": "2026-08-04T19:55:58Z",
          "status": "source-content",
          "summary": "The Reddit thread gained 2 new comments.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 19,
          "removed_lines": 0
        },
        {
          "observed_at": "2026-08-04T18:24:55Z",
          "window_start": "2026-08-04T17:55:11Z",
          "window_end": "2026-08-04T18:24:55Z",
          "status": "source-content",
          "summary": "The Reddit thread gained 2 new comments.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 19,
          "removed_lines": 3
        },
        {
          "observed_at": "2026-08-04T17:55:11Z",
          "window_start": "2026-08-04T16:57:14Z",
          "window_end": "2026-08-04T17:55:11Z",
          "status": "source-content",
          "summary": "The Reddit thread gained 1 new comment.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 8,
          "removed_lines": 0
        },
        {
          "observed_at": "2026-08-04T16:57:14Z",
          "window_start": "2026-08-04T16:27:23Z",
          "window_end": "2026-08-04T16:57:14Z",
          "status": "source-content",
          "summary": "The Reddit thread gained 1 new comment.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 12,
          "removed_lines": 0
        },
        {
          "observed_at": "2026-08-04T16:27:23Z",
          "window_start": "2026-08-04T15:24:24Z",
          "window_end": "2026-08-04T16:27:23Z",
          "status": "source-content",
          "summary": "1 new Reddit comment was posted, by youtossershad1job2do, questioning the trustless premise of crypto.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 8,
          "removed_lines": 0
        },
        {
          "observed_at": "2026-08-04T15:24:24Z",
          "window_start": "2026-08-04T14:53:54Z",
          "window_end": "2026-08-04T15:24:24Z",
          "status": "source-content",
          "summary": "1 new Reddit comment was posted, by Such_Advantage6988, noting that the error dated to 2021.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 8,
          "removed_lines": 0
        },
        {
          "observed_at": "2026-08-04T14:53:54Z",
          "window_start": "2026-08-04T13:53:52Z",
          "window_end": "2026-08-04T14:53:54Z",
          "status": "source-content",
          "summary": "4 new Reddit comments were posted, including Always_working_hardd, Unsounded and kikikza.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 34,
          "removed_lines": 0
        },
        {
          "observed_at": "2026-08-04T13:53:52Z",
          "window_start": "2026-08-04T13:15:01Z",
          "window_end": "2026-08-04T13:53:52Z",
          "status": "source-content",
          "summary": "5 new Reddit comments were posted, including 10kpizza,crypto_chik,ILurkReddi.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 40,
          "removed_lines": 0
        },
        {
          "observed_at": "2026-08-04T13:15:01Z",
          "window_start": "2026-08-04T12:44:00Z",
          "window_end": "2026-08-04T13:15:01Z",
          "status": "source-content",
          "summary": "4 new Reddit comments were posted, including bricksplus,shadowmage666,Gooner_93.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 32,
          "removed_lines": 0
        },
        {
          "observed_at": "2026-08-04T12:44:00Z",
          "window_start": "2026-08-04T12:14:54Z",
          "window_end": "2026-08-04T12:44:00Z",
          "status": "source-content",
          "summary": "Three new comments were posted: youtossershad1job2do distrusting the online randomness generator, NetimLabs judging the risk low in this case, and Lilcheeks suggesting the attacker was partly bragging about their own cleverness.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 26,
          "removed_lines": 0
        },
        {
          "observed_at": "2026-08-04T12:14:54Z",
          "window_start": "2026-08-04T11:14:32Z",
          "window_end": "2026-08-04T12:14:54Z",
          "status": "source-content",
          "summary": "Two new comments were posted: NetimLabs suggesting publicly available quantum randomness streams instead of dice rolls, and CBpegasus saying the concept is well known and expected of a security company.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 17,
          "removed_lines": 0
        },
        {
          "observed_at": "2026-08-04T11:14:32Z",
          "window_start": "2026-08-04T10:43:25Z",
          "window_end": "2026-08-04T11:14:32Z",
          "status": "source-content",
          "summary": "One new comment was posted: CiaranCarroll disputing the quoted Passport claims, arguing 99 dice rolls take 15 minutes and challenging the supporting reference on on-board RNG seeds.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 18,
          "removed_lines": 0
        },
        {
          "observed_at": "2026-08-04T10:43:25Z",
          "window_start": "2026-08-04T09:43:36Z",
          "window_end": "2026-08-04T10:43:25Z",
          "status": "source-content",
          "summary": "Three new comments were posted: CoffeeAlternative647 asking what a 'Razor' is, Blade_Runner_69 suggesting it is a typo for Trezor, and a follow-up emoji from CoffeeAlternative647.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 24,
          "removed_lines": 0
        }
      ]
    },
    {
      "id": "reddit-flag-four-addresses",
      "title": "r/Bitcoin: call to flag the drainer's four consolidation addresses",
      "url": "https://www.reddit.com/r/Bitcoin/comments/1verf1p/flag_the_4_coldcard_addresses/",
      "organisation": "reddit",
      "kind": "community-discussion",
      "role": "Community discussion",
      "publication_time": null,
      "note": null,
      "gone": null,
      "capture": {
        "status": "held",
        "copies": 5,
        "first_observed": "2026-08-04T09:43:40Z",
        "last_observed": "2026-08-04T22:57:59Z",
        "last_checked": "2026-08-07T07:51:50Z"
      },
      "differences": [
        {
          "observed_at": "2026-08-04T22:57:59Z",
          "window_start": "2026-08-04T14:53:59Z",
          "window_end": "2026-08-04T22:57:59Z",
          "status": "source-content",
          "summary": "The Reddit thread gained new participant comments.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 16,
          "removed_lines": 0
        },
        {
          "observed_at": "2026-08-04T14:53:59Z",
          "window_start": "2026-08-04T12:44:05Z",
          "window_end": "2026-08-04T14:53:59Z",
          "status": "source-content",
          "summary": "1 new Reddit comment was posted, by AltairSirioRigel, distinguishing the incident from a Bitcoin-code bug.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 8,
          "removed_lines": 0
        },
        {
          "observed_at": "2026-08-04T12:44:05Z",
          "window_start": "2026-08-04T12:14:59Z",
          "window_end": "2026-08-04T12:44:05Z",
          "status": "source-content",
          "summary": "One new comment was posted: Javanaut018 replying that the keys work to sign transactions but should not be weak.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 8,
          "removed_lines": 0
        },
        {
          "observed_at": "2026-08-04T12:14:59Z",
          "window_start": "2026-08-04T09:43:40Z",
          "window_end": "2026-08-04T12:14:59Z",
          "status": "source-content",
          "summary": "One new comment was posted: boy_tue ('So what? Still working as intended.').",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 8,
          "removed_lines": 0
        }
      ]
    },
    {
      "id": "reddit-entropy-bug-commits-review",
      "title": "r/Bitcoin: reviewing the commits that introduced the entropy bug",
      "url": "https://www.reddit.com/r/Bitcoin/comments/1vdycb4/coldcard_entropy_bug_the_commits_that_introduced/",
      "organisation": "reddit",
      "kind": "community-discussion",
      "role": "Community discussion",
      "publication_time": null,
      "note": null,
      "gone": null,
      "capture": {
        "status": "held",
        "copies": 5,
        "first_observed": "2026-08-04T09:55:08Z",
        "last_observed": "2026-08-05T14:26:46Z",
        "last_checked": "2026-08-11T04:50:56Z"
      },
      "differences": [
        {
          "observed_at": "2026-08-05T14:26:46Z",
          "window_start": "2026-08-04T19:47:01Z",
          "window_end": "2026-08-05T14:26:46Z",
          "status": "source-content",
          "summary": "Reddit no longer served a comment arguing that the commits showed shortcuts compared with the review process at the author's workplace.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 0,
          "removed_lines": 8
        },
        {
          "observed_at": "2026-08-04T19:47:01Z",
          "window_start": "2026-08-04T19:16:19Z",
          "window_end": "2026-08-04T19:47:01Z",
          "status": "source-content",
          "summary": "An existing Reddit comment changed or its author account was deleted.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 14,
          "removed_lines": 12
        },
        {
          "observed_at": "2026-08-04T19:16:19Z",
          "window_start": "2026-08-04T18:46:58Z",
          "window_end": "2026-08-04T19:16:19Z",
          "status": "source-content",
          "summary": "The Reddit thread gained 2 new comments.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 34,
          "removed_lines": 0
        },
        {
          "observed_at": "2026-08-04T18:46:58Z",
          "window_start": "2026-08-04T09:55:08Z",
          "window_end": "2026-08-04T18:46:58Z",
          "status": "source-content",
          "summary": "The Reddit thread gained 1 new comment.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 8,
          "removed_lines": 0
        }
      ]
    },
    {
      "id": "reddit-wild-west-sentiment",
      "title": "r/Bitcoin: 'people have forgotten what this space is all about'",
      "url": "https://www.reddit.com/r/Bitcoin/comments/1vedx0e/people_have_forgotten_what_this_space_is_all_about/",
      "organisation": "reddit",
      "kind": "community-discussion",
      "role": "Community discussion",
      "publication_time": null,
      "note": null,
      "gone": null,
      "capture": {
        "status": "held",
        "copies": 7,
        "first_observed": "2026-08-04T09:55:13Z",
        "last_observed": "2026-08-07T06:17:54Z",
        "last_checked": "2026-08-11T04:51:59Z"
      },
      "differences": [
        {
          "observed_at": "2026-08-07T06:17:54Z",
          "window_start": "2026-08-06T16:34:36Z",
          "window_end": "2026-08-07T06:17:54Z",
          "status": "source-content",
          "summary": "Two new comments: a sarcastic one about dice-rolling seeds in the basement, and one arguing Bitcoin will not be mainstream if it is not easy to use.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 16,
          "removed_lines": 0
        },
        {
          "observed_at": "2026-08-06T16:34:36Z",
          "window_start": "2026-08-06T10:02:12Z",
          "window_end": "2026-08-06T16:34:36Z",
          "status": "source-content",
          "summary": "Three comments were removed from the thread: one by IllllIIlIllIllllIlll now shows [deleted], and two longer comments by CraftyBrother6974 on financial literacy now show [removed] with author [deleted].",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 8,
          "removed_lines": 8
        },
        {
          "observed_at": "2026-08-06T10:02:12Z",
          "window_start": "2026-08-06T03:30:54Z",
          "window_end": "2026-08-06T10:02:12Z",
          "status": "source-content",
          "summary": "New comment disputes the claim that Bitcoin is mainstream: \"Then we have different definitions of mainstream.\"",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 8,
          "removed_lines": 0
        },
        {
          "observed_at": "2026-08-06T03:30:54Z",
          "window_start": "2026-08-05T14:26:50Z",
          "window_end": "2026-08-06T03:30:54Z",
          "status": "source-content",
          "summary": "A commenter argued that the existence of a Bitcoin ETF demonstrates mainstream adoption, while doubting further practical uses for crypto.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 10,
          "removed_lines": 0
        },
        {
          "observed_at": "2026-08-05T14:26:50Z",
          "window_start": "2026-08-04T13:45:24Z",
          "window_end": "2026-08-05T14:26:50Z",
          "status": "source-content",
          "summary": "Several comments about bank insurance and regulation were removed or replaced with deleted-account placeholders, and one short reply was removed.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 6,
          "removed_lines": 16
        },
        {
          "observed_at": "2026-08-04T13:45:24Z",
          "window_start": "2026-08-04T09:55:13Z",
          "window_end": "2026-08-04T13:45:24Z",
          "status": "source-content",
          "summary": "4 new Reddit comments were posted, including Javanaut018,tekmiester.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 34,
          "removed_lines": 0
        }
      ]
    },
    {
      "id": "reddit-safe-seed-without-hardware",
      "title": "r/Bitcoin: generating a safe seed without a hardware wallet",
      "url": "https://www.reddit.com/r/Bitcoin/comments/1vekcn5/how_to_create_a_safe_seed_without_hardware_wallet/",
      "organisation": "reddit",
      "kind": "community-discussion",
      "role": "Community discussion",
      "publication_time": null,
      "note": null,
      "gone": null,
      "capture": {
        "status": "held",
        "copies": 8,
        "first_observed": "2026-08-04T09:55:17Z",
        "last_observed": "2026-08-06T16:34:40Z",
        "last_checked": "2026-08-11T04:53:02Z"
      },
      "differences": [
        {
          "observed_at": "2026-08-06T16:34:40Z",
          "window_start": "2026-08-04T19:16:26Z",
          "window_end": "2026-08-06T16:34:40Z",
          "status": "source-content",
          "summary": "A comment by Fluid-Scientist9912 asking whether the other user still uses their Coldcard and thinks it is safe now shows as [deleted] with author [deleted].",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 2,
          "removed_lines": 2
        },
        {
          "observed_at": "2026-08-04T19:16:26Z",
          "window_start": "2026-08-04T18:47:06Z",
          "window_end": "2026-08-04T19:16:26Z",
          "status": "source-content",
          "summary": "The Reddit thread gained 1 new comment.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 8,
          "removed_lines": 0
        },
        {
          "observed_at": "2026-08-04T18:47:06Z",
          "window_start": "2026-08-04T16:48:16Z",
          "window_end": "2026-08-04T18:47:06Z",
          "status": "source-content",
          "summary": "The Reddit thread gained 2 new comments.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 16,
          "removed_lines": 0
        },
        {
          "observed_at": "2026-08-04T16:48:16Z",
          "window_start": "2026-08-04T15:48:02Z",
          "window_end": "2026-08-04T16:48:16Z",
          "status": "source-content",
          "summary": "An existing Reddit comment was edited or removed.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 9,
          "removed_lines": 9
        },
        {
          "observed_at": "2026-08-04T15:48:02Z",
          "window_start": "2026-08-04T14:16:14Z",
          "window_end": "2026-08-04T15:48:02Z",
          "status": "source-content",
          "summary": "1 new Reddit comment was posted, by Bryght7.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 8,
          "removed_lines": 0
        },
        {
          "observed_at": "2026-08-04T14:16:14Z",
          "window_start": "2026-08-04T13:45:28Z",
          "window_end": "2026-08-04T14:16:14Z",
          "status": "source-content",
          "summary": "1 new Reddit comment was posted, including doctrgiggles.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 8,
          "removed_lines": 0
        },
        {
          "observed_at": "2026-08-04T13:45:28Z",
          "window_start": "2026-08-04T09:55:17Z",
          "window_end": "2026-08-04T13:45:28Z",
          "status": "source-content",
          "summary": "10 new Reddit comments were posted, including Fluid-Scientist9912,tchjntr,JumpProfessional3372.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 106,
          "removed_lines": 0
        }
      ]
    },
    {
      "id": "reddit-where-store-bitcoin-now",
      "title": "r/Bitcoin: where to store bitcoin after the COLDCARD incident",
      "url": "https://www.reddit.com/r/Bitcoin/comments/1veyt5w/so_where_do_we_store_bitcoin_now/",
      "organisation": "reddit",
      "kind": "community-discussion",
      "role": "Community discussion",
      "publication_time": null,
      "note": null,
      "gone": null,
      "capture": {
        "status": "held",
        "copies": 20,
        "first_observed": "2026-08-04T09:55:21Z",
        "last_observed": "2026-08-09T04:06:16Z",
        "last_checked": "2026-08-11T04:54:05Z"
      },
      "differences": [
        {
          "observed_at": "2026-08-09T04:06:16Z",
          "window_start": "2026-08-07T06:18:01Z",
          "window_end": "2026-08-09T04:06:16Z",
          "status": "source-content",
          "summary": "A new comment warned that Michael Saylor could develop dementia and other custodians could die.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 8,
          "removed_lines": 0
        },
        {
          "observed_at": "2026-08-07T06:18:01Z",
          "window_start": "2026-08-06T16:34:44Z",
          "window_end": "2026-08-07T06:18:01Z",
          "status": "source-content",
          "summary": "Two comments by user 1-gill (about losing 0.22 BTC and stamping seed words in steel) were deleted from the thread.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 0,
          "removed_lines": 16
        },
        {
          "observed_at": "2026-08-06T16:34:44Z",
          "window_start": "2026-08-06T03:31:05Z",
          "window_end": "2026-08-06T16:34:44Z",
          "status": "source-content",
          "summary": "A previously captured comment (\"On the blockchain. Same as usual.\") was deleted from the thread.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 0,
          "removed_lines": 8
        },
        {
          "observed_at": "2026-08-06T03:31:05Z",
          "window_start": "2026-08-05T00:48:09Z",
          "window_end": "2026-08-06T03:31:05Z",
          "status": "source-content",
          "summary": "The original post was deleted, replacing the author name and question with Reddit’s deleted markers.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 2,
          "removed_lines": 2
        },
        {
          "observed_at": "2026-08-05T00:48:09Z",
          "window_start": "2026-08-04T23:23:51Z",
          "window_end": "2026-08-05T00:48:09Z",
          "status": "source-content",
          "summary": "The Reddit thread gained a reply saying the two situations involve the same people.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 8,
          "removed_lines": 0
        },
        {
          "observed_at": "2026-08-04T23:23:51Z",
          "window_start": "2026-08-04T22:48:33Z",
          "window_end": "2026-08-04T23:23:51Z",
          "status": "source-content",
          "summary": "The Reddit thread gained comments describing a claimed 0.22 BTC loss and steel seed backups.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 16,
          "removed_lines": 0
        },
        {
          "observed_at": "2026-08-04T22:48:33Z",
          "window_start": "2026-08-04T22:17:47Z",
          "window_end": "2026-08-04T22:48:33Z",
          "status": "source-content",
          "summary": "The Reddit thread gained a comment distinguishing the incident from mandatory public blockchain reporting.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 8,
          "removed_lines": 0
        },
        {
          "observed_at": "2026-08-04T22:17:47Z",
          "window_start": "2026-08-04T21:47:26Z",
          "window_end": "2026-08-04T22:17:47Z",
          "status": "source-content",
          "summary": "The Reddit thread gained 2 new comments, including a question about whether other wallet seed generation is affected.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 19,
          "removed_lines": 0
        },
        {
          "observed_at": "2026-08-04T21:47:26Z",
          "window_start": "2026-08-04T21:17:34Z",
          "window_end": "2026-08-04T21:47:26Z",
          "status": "source-content",
          "summary": "The Reddit thread gained 1 new comment recommending an air-gapped open-source wallet.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 8,
          "removed_lines": 0
        },
        {
          "observed_at": "2026-08-04T21:17:34Z",
          "window_start": "2026-08-04T20:47:16Z",
          "window_end": "2026-08-04T21:17:34Z",
          "status": "source-content",
          "summary": "The Reddit thread gained 1 new comment.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 8,
          "removed_lines": 0
        },
        {
          "observed_at": "2026-08-04T20:47:16Z",
          "window_start": "2026-08-04T20:17:41Z",
          "window_end": "2026-08-04T20:47:16Z",
          "status": "source-content",
          "summary": "The Reddit thread gained 2 new comments.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 16,
          "removed_lines": 0
        },
        {
          "observed_at": "2026-08-04T20:17:41Z",
          "window_start": "2026-08-04T18:47:10Z",
          "window_end": "2026-08-04T20:17:41Z",
          "status": "source-content",
          "summary": "The Reddit thread gained 2 new comments.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 16,
          "removed_lines": 0
        },
        {
          "observed_at": "2026-08-04T18:47:10Z",
          "window_start": "2026-08-04T18:16:06Z",
          "window_end": "2026-08-04T18:47:10Z",
          "status": "source-content",
          "summary": "The Reddit thread gained 1 new comment.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 10,
          "removed_lines": 2
        },
        {
          "observed_at": "2026-08-04T18:16:06Z",
          "window_start": "2026-08-04T17:46:37Z",
          "window_end": "2026-08-04T18:16:06Z",
          "status": "source-content",
          "summary": "The Reddit thread gained 1 new comment.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 10,
          "removed_lines": 0
        },
        {
          "observed_at": "2026-08-04T17:46:37Z",
          "window_start": "2026-08-04T16:48:21Z",
          "window_end": "2026-08-04T17:46:37Z",
          "status": "source-content",
          "summary": "The Reddit thread gained 1 new comment.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 8,
          "removed_lines": 0
        },
        {
          "observed_at": "2026-08-04T16:48:21Z",
          "window_start": "2026-08-04T16:17:48Z",
          "window_end": "2026-08-04T16:48:21Z",
          "status": "source-content",
          "summary": "The Reddit thread gained 2 new comments.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 16,
          "removed_lines": 0
        },
        {
          "observed_at": "2026-08-04T16:17:48Z",
          "window_start": "2026-08-04T14:16:17Z",
          "window_end": "2026-08-04T16:17:48Z",
          "status": "source-content",
          "summary": "3 new Reddit comments were posted, including a BitBox representative describing its seed entropy and recommending user dice rolls.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 28,
          "removed_lines": 0
        },
        {
          "observed_at": "2026-08-04T14:16:17Z",
          "window_start": "2026-08-04T13:45:32Z",
          "window_end": "2026-08-04T14:16:17Z",
          "status": "source-content",
          "summary": "1 new Reddit comment was posted, including swaggercatr.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 8,
          "removed_lines": 0
        },
        {
          "observed_at": "2026-08-04T13:45:32Z",
          "window_start": "2026-08-04T09:55:21Z",
          "window_end": "2026-08-04T13:45:32Z",
          "status": "source-content",
          "summary": "11 new Reddit comments were posted, including DK4E2XFpbETJrj,AAAdamKK,Btcyoda.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 93,
          "removed_lines": 0
        }
      ]
    },
    {
      "id": "reddit-70m-41-minutes-report",
      "title": "r/Bitcoin: news report of $70 million drained in 41 minutes",
      "url": "https://www.reddit.com/r/Bitcoin/comments/1vdt92h/a_coldcard_firmware_flaw_let_hackers_drain_70/",
      "organisation": "reddit",
      "kind": "community-discussion",
      "role": "Community discussion",
      "publication_time": null,
      "note": null,
      "gone": null,
      "capture": {
        "status": "held",
        "copies": 2,
        "first_observed": "2026-08-04T09:55:24Z",
        "last_observed": "2026-08-06T10:02:28Z",
        "last_checked": "2026-08-11T04:55:09Z"
      },
      "differences": [
        {
          "observed_at": "2026-08-06T10:02:28Z",
          "window_start": "2026-08-04T09:55:24Z",
          "window_end": "2026-08-06T10:02:28Z",
          "status": "source-content",
          "summary": "A comment by DonTheHolder telling victims to let professionals manage their coins was removed; author and body now show [deleted]/[removed].",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 2,
          "removed_lines": 4
        }
      ]
    },
    {
      "id": "reddit-best-way-keep-safe",
      "title": "r/Bitcoin: best way to keep bitcoin safe after the incident",
      "url": "https://www.reddit.com/r/Bitcoin/comments/1vedae9/with_the_coldcard_stuff_going_on_i_want_to_know/",
      "organisation": "reddit",
      "kind": "community-discussion",
      "role": "Community discussion",
      "publication_time": null,
      "note": null,
      "gone": null,
      "capture": {
        "status": "held",
        "copies": 7,
        "first_observed": "2026-08-04T09:55:35Z",
        "last_observed": "2026-08-05T21:02:17Z",
        "last_checked": "2026-08-11T04:56:12Z"
      },
      "differences": [
        {
          "observed_at": "2026-08-05T21:02:17Z",
          "window_start": "2026-08-05T14:27:05Z",
          "window_end": "2026-08-05T21:02:17Z",
          "status": "source-content",
          "summary": "The thread gained a brief reply saying there was no need for the item under discussion.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 8,
          "removed_lines": 0
        },
        {
          "observed_at": "2026-08-05T14:27:05Z",
          "window_start": "2026-08-05T07:58:32Z",
          "window_end": "2026-08-05T14:27:05Z",
          "status": "source-content",
          "summary": "Two comments advising readers to generate a seed with dice were replaced with deleted-account placeholders.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 4,
          "removed_lines": 6
        },
        {
          "observed_at": "2026-08-05T07:58:32Z",
          "window_start": "2026-08-04T15:16:23Z",
          "window_end": "2026-08-05T07:58:32Z",
          "status": "source-content",
          "summary": "The thread gained a brief reply criticising another participant's use of analogies.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 8,
          "removed_lines": 0
        },
        {
          "observed_at": "2026-08-04T15:16:23Z",
          "window_start": "2026-08-04T14:45:35Z",
          "window_end": "2026-08-04T15:16:23Z",
          "status": "source-content",
          "summary": "2 new Reddit comments were posted, including CiaranCarroll advocating user-supplied entropy and independent verification.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 22,
          "removed_lines": 0
        },
        {
          "observed_at": "2026-08-04T14:45:35Z",
          "window_start": "2026-08-04T13:45:39Z",
          "window_end": "2026-08-04T14:45:35Z",
          "status": "source-content",
          "summary": "1 new Reddit comment was posted, including CiaranCarroll.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 8,
          "removed_lines": 0
        },
        {
          "observed_at": "2026-08-04T13:45:39Z",
          "window_start": "2026-08-04T09:55:35Z",
          "window_end": "2026-08-04T13:45:39Z",
          "status": "source-content",
          "summary": "2 new Reddit comments were posted, including Javanaut018.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 16,
          "removed_lines": 0
        }
      ]
    },
    {
      "id": "reddit-trng-certification-question",
      "title": "r/Bitcoin: COLDCARD TRNG certification level questioned",
      "url": "https://www.reddit.com/r/Bitcoin/comments/1ven1lw/coldcard_trng_certification_level/",
      "organisation": "reddit",
      "kind": "community-discussion",
      "role": "Community discussion",
      "publication_time": null,
      "note": null,
      "gone": null,
      "capture": {
        "status": "held",
        "copies": 1,
        "first_observed": "2026-08-04T09:55:39Z",
        "last_observed": "2026-08-04T09:55:39Z",
        "last_checked": "2026-08-07T07:52:58Z"
      },
      "differences": []
    },
    {
      "id": "reddit-open-source-missed-flaw",
      "title": "r/Bitcoin: why open source did not catch the low-entropy seed generation",
      "url": "https://www.reddit.com/r/Bitcoin/comments/1ve5jyc/since_coldcard_is_opensource_why_wasnt_low/",
      "organisation": "reddit",
      "kind": "community-discussion",
      "role": "Community discussion",
      "publication_time": null,
      "note": null,
      "gone": null,
      "capture": {
        "status": "held",
        "copies": 3,
        "first_observed": "2026-08-04T09:55:42Z",
        "last_observed": "2026-08-07T06:18:12Z",
        "last_checked": "2026-08-11T04:57:15Z"
      },
      "differences": [
        {
          "observed_at": "2026-08-07T06:18:12Z",
          "window_start": "2026-08-06T16:34:56Z",
          "window_end": "2026-08-07T06:18:12Z",
          "status": "source-content",
          "summary": "New comment by Quantris linking a personal gist that converts seed generation to dice rolls, noting their earlier advice to mix in external entropy against hardware RNG weaknesses now looks prescient.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 12,
          "removed_lines": 0
        },
        {
          "observed_at": "2026-08-06T16:34:56Z",
          "window_start": "2026-08-04T09:55:42Z",
          "window_end": "2026-08-06T16:34:56Z",
          "status": "source-content",
          "summary": "A comment by IllllIIlIllIllllIlll recommending 48 dice rolls and 12 coin flips with BitBox diceware PDFs now shows as [deleted], a second comment by the same author dropped from the listing, and a new comment by aaj094 asks whether Trezor counts as fully open source.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 12,
          "removed_lines": 16
        }
      ]
    },
    {
      "id": "reddit-verify-code-on-device",
      "title": "r/Bitcoin: verifying that published source is what runs on the device",
      "url": "https://www.reddit.com/r/Bitcoin/comments/1vehj5c/if_the_code_of_a_hardware_wallet_is_truly_open/",
      "organisation": "reddit",
      "kind": "community-discussion",
      "role": "Community discussion",
      "publication_time": null,
      "note": null,
      "gone": null,
      "capture": {
        "status": "held",
        "copies": 3,
        "first_observed": "2026-08-04T09:55:46Z",
        "last_observed": "2026-08-04T17:25:26Z",
        "last_checked": "2026-08-07T07:54:07Z"
      },
      "differences": [
        {
          "observed_at": "2026-08-04T17:25:26Z",
          "window_start": "2026-08-04T16:27:41Z",
          "window_end": "2026-08-04T17:25:26Z",
          "status": "source-content",
          "summary": "The Reddit thread gained 1 new comment.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 10,
          "removed_lines": 0
        },
        {
          "observed_at": "2026-08-04T16:27:41Z",
          "window_start": "2026-08-04T09:55:46Z",
          "window_end": "2026-08-04T16:27:41Z",
          "status": "source-content",
          "summary": "1 new Reddit comment was posted, by riscten, contrasting vendor trust with a self-built Jade DIY device.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 14,
          "removed_lines": 0
        }
      ]
    },
    {
      "id": "reddit-lost-one-bitcoin-victim",
      "title": "r/Bitcoin: victim reports losing one bitcoin in the exploit",
      "url": "https://www.reddit.com/r/Bitcoin/comments/1vdjlls/i_lost_my_one_bitcoin_in_the_coldcard_exploit/",
      "organisation": "reddit",
      "kind": "community-discussion",
      "role": "Community discussion",
      "publication_time": null,
      "note": null,
      "gone": null,
      "capture": {
        "status": "held",
        "copies": 14,
        "first_observed": "2026-08-04T09:55:50Z",
        "last_observed": "2026-08-09T16:53:45Z",
        "last_checked": "2026-08-11T04:58:18Z"
      },
      "differences": [
        {
          "observed_at": "2026-08-09T16:53:45Z",
          "window_start": "2026-08-08T08:33:34Z",
          "window_end": "2026-08-09T16:53:45Z",
          "status": "source-content",
          "summary": "A short comment was removed and three new comments were added, including the poster mentioning a first Ledger wallet and asking about migration fees.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 16,
          "removed_lines": 8
        },
        {
          "observed_at": "2026-08-08T08:33:34Z",
          "window_start": "2026-08-08T02:00:51Z",
          "window_end": "2026-08-08T08:33:34Z",
          "status": "source-content",
          "summary": "The original post author and body were deleted and replaced with [deleted] markers.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 2,
          "removed_lines": 12
        },
        {
          "observed_at": "2026-08-08T02:00:51Z",
          "window_start": "2026-08-07T06:18:16Z",
          "window_end": "2026-08-08T02:00:51Z",
          "status": "source-content",
          "summary": "The Reddit thread gained a new participant comment.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 12,
          "removed_lines": 0
        },
        {
          "observed_at": "2026-08-07T06:18:16Z",
          "window_start": "2026-08-06T16:35:00Z",
          "window_end": "2026-08-07T06:18:16Z",
          "status": "source-content",
          "summary": "New top-level comment by Zestyclose_Ad2462 rebutting the ETF argument: not your ETF shares, not your coins.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 8,
          "removed_lines": 0
        },
        {
          "observed_at": "2026-08-06T16:35:00Z",
          "window_start": "2026-08-06T10:02:43Z",
          "window_end": "2026-08-06T16:35:00Z",
          "status": "source-content",
          "summary": "New top-level comment by Own_Reference2619 (rachete en 1).",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 8,
          "removed_lines": 0
        },
        {
          "observed_at": "2026-08-06T10:02:43Z",
          "window_start": "2026-08-05T21:02:29Z",
          "window_end": "2026-08-06T10:02:43Z",
          "status": "source-content",
          "summary": "Two new top-level comments: a one-word reply (Depp) and a comment arguing the incident shows why bitcoin ETFs have a use case.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 16,
          "removed_lines": 0
        },
        {
          "observed_at": "2026-08-05T21:02:29Z",
          "window_start": "2026-08-05T14:27:12Z",
          "window_end": "2026-08-05T21:02:29Z",
          "status": "source-content",
          "summary": "Two comments about dice rolls and passphrases were removed or replaced with deleted-account placeholders, while a new reply said affected users commonly skipped multisig.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 12,
          "removed_lines": 6
        },
        {
          "observed_at": "2026-08-05T14:27:12Z",
          "window_start": "2026-08-05T07:58:39Z",
          "window_end": "2026-08-05T14:27:12Z",
          "status": "source-content",
          "summary": "Two comments criticising COLDCARD and speculating about later sweeps were removed or replaced with deleted-account placeholders. The thread also gained a brief expression of sympathy.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 10,
          "removed_lines": 12
        },
        {
          "observed_at": "2026-08-05T07:58:39Z",
          "window_start": "2026-08-05T00:18:22Z",
          "window_end": "2026-08-05T07:58:39Z",
          "status": "source-content",
          "summary": "The thread gained comments arguing that non-device entropy and a passphrase can address the issue, while other replies expressed broader distrust and confusion about bitcoin safety.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 26,
          "removed_lines": 0
        },
        {
          "observed_at": "2026-08-05T00:18:22Z",
          "window_start": "2026-08-04T21:47:41Z",
          "window_end": "2026-08-05T00:18:22Z",
          "status": "source-content",
          "summary": "The Reddit thread gained a new participant comment.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 8,
          "removed_lines": 0
        },
        {
          "observed_at": "2026-08-04T21:47:41Z",
          "window_start": "2026-08-04T18:47:25Z",
          "window_end": "2026-08-04T21:47:41Z",
          "status": "source-content",
          "summary": "The Reddit thread gained 1 new comment.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 8,
          "removed_lines": 0
        },
        {
          "observed_at": "2026-08-04T18:47:25Z",
          "window_start": "2026-08-04T17:46:52Z",
          "window_end": "2026-08-04T18:47:25Z",
          "status": "source-content",
          "summary": "The Reddit thread gained 2 new comments.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 18,
          "removed_lines": 0
        },
        {
          "observed_at": "2026-08-04T17:46:52Z",
          "window_start": "2026-08-04T09:55:50Z",
          "window_end": "2026-08-04T17:46:52Z",
          "status": "source-content",
          "summary": "The Reddit thread gained 1 new comment.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 8,
          "removed_lines": 0
        }
      ]
    },
    {
      "id": "reddit-opreturn-laundering-offer",
      "title": "r/Bitcoin: money laundering offer sent to the drainer via OP_RETURN",
      "url": "https://www.reddit.com/r/Bitcoin/comments/1vdqybv/coldcard_hacker_receives_money_laundering_offer/",
      "organisation": "reddit",
      "kind": "community-discussion",
      "role": "Community discussion",
      "publication_time": null,
      "note": null,
      "gone": null,
      "capture": {
        "status": "held",
        "copies": 2,
        "first_observed": "2026-08-04T13:45:52Z",
        "last_observed": "2026-08-07T19:30:34Z",
        "last_checked": "2026-08-11T13:07:24Z"
      },
      "differences": [
        {
          "observed_at": "2026-08-07T19:30:34Z",
          "window_start": "2026-08-04T13:45:52Z",
          "window_end": "2026-08-07T19:30:34Z",
          "status": "source-content",
          "summary": "The thread gained a short sub-thread in which a commenter explains how to look up a block height in an advanced block explorer.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 32,
          "removed_lines": 0
        }
      ]
    },
    {
      "id": "reddit-self-custody-risk-doubt",
      "title": "r/Bitcoin: owner struggling to weigh self-custody risk after the attack",
      "url": "https://www.reddit.com/r/Bitcoin/comments/1veuylf/im_having_a_hard_time_grasping_the_risk_involved/",
      "organisation": "reddit",
      "kind": "community-discussion",
      "role": "Community discussion",
      "publication_time": null,
      "note": null,
      "gone": null,
      "capture": {
        "status": "held",
        "copies": 6,
        "first_observed": "2026-08-04T10:15:01Z",
        "last_observed": "2026-08-06T03:41:29Z",
        "last_checked": "2026-08-07T07:55:16Z"
      },
      "differences": [
        {
          "observed_at": "2026-08-06T03:41:29Z",
          "window_start": "2026-08-05T14:36:29Z",
          "window_end": "2026-08-06T03:41:29Z",
          "status": "source-content",
          "summary": "Reddit served 1 additional comment record(s); the diff preserves their text and any edits to existing records.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 8,
          "removed_lines": 0
        },
        {
          "observed_at": "2026-08-05T14:36:29Z",
          "window_start": "2026-08-04T18:25:14Z",
          "window_end": "2026-08-05T14:36:29Z",
          "status": "source-content",
          "summary": "Reddit served 1 additional comment record(s); the diff preserves their text and any edits to existing records.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 8,
          "removed_lines": 0
        },
        {
          "observed_at": "2026-08-04T18:25:14Z",
          "window_start": "2026-08-04T11:14:51Z",
          "window_end": "2026-08-04T18:25:14Z",
          "status": "source-content",
          "summary": "The Reddit thread gained 1 new comment.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 8,
          "removed_lines": 0
        },
        {
          "observed_at": "2026-08-04T11:14:51Z",
          "window_start": "2026-08-04T10:43:44Z",
          "window_end": "2026-08-04T11:14:51Z",
          "status": "source-content",
          "summary": "Two new comments were posted by JunketTurbulent2114: citing Mt. Gox as the opposite lesson for older users, and noting Satoshi's keys predate seed phrases and were just long private keys.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 16,
          "removed_lines": 0
        },
        {
          "observed_at": "2026-08-04T10:43:44Z",
          "window_start": "2026-08-04T10:15:01Z",
          "window_end": "2026-08-04T10:43:44Z",
          "status": "source-content",
          "summary": "One new comment was posted: Disavowed_Rogue ('Putting your BTC into Robin Hood is not safe').",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 8,
          "removed_lines": 0
        }
      ]
    },
    {
      "id": "reddit-self-custody-to-etf",
      "title": "r/Bitcoin: considering selling self-custodied BTC for a spot ETF",
      "url": "https://www.reddit.com/r/Bitcoin/comments/1ve1fai/is_anyone_considering_selling_their_own_btc_for_a/",
      "organisation": "reddit",
      "kind": "community-discussion",
      "role": "Community discussion",
      "publication_time": null,
      "note": null,
      "gone": null,
      "capture": {
        "status": "held",
        "copies": 8,
        "first_observed": "2026-08-04T13:45:55Z",
        "last_observed": "2026-08-09T10:36:23Z",
        "last_checked": "2026-08-11T13:08:27Z"
      },
      "differences": [
        {
          "observed_at": "2026-08-09T10:36:23Z",
          "window_start": "2026-08-06T10:02:55Z",
          "window_end": "2026-08-09T10:36:23Z",
          "status": "source-content",
          "summary": "The thread gained a short reply questioning the point of selling self-custodied bitcoin for a spot ETF.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 8,
          "removed_lines": 0
        },
        {
          "observed_at": "2026-08-06T10:02:55Z",
          "window_start": "2026-08-05T21:02:40Z",
          "window_end": "2026-08-06T10:02:55Z",
          "status": "source-content",
          "summary": "A comment by DonTheHolder arguing for ETFs and custodians over self-custody was removed and the author now shows as [deleted].",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 2,
          "removed_lines": 6
        },
        {
          "observed_at": "2026-08-05T21:02:40Z",
          "window_start": "2026-08-05T14:27:22Z",
          "window_end": "2026-08-05T21:02:40Z",
          "status": "source-content",
          "summary": "The thread gained a reported personal gold loss and a brief response rejecting the proposal.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 16,
          "removed_lines": 0
        },
        {
          "observed_at": "2026-08-05T14:27:22Z",
          "window_start": "2026-08-05T07:58:48Z",
          "window_end": "2026-08-05T14:27:22Z",
          "status": "source-content",
          "summary": "The thread gained two short comments, one asking why an IRA is considered a scam and another asking why.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 16,
          "removed_lines": 0
        },
        {
          "observed_at": "2026-08-05T07:58:48Z",
          "window_start": "2026-08-04T23:48:22Z",
          "window_end": "2026-08-05T07:58:48Z",
          "status": "source-content",
          "summary": "The thread gained comments advocating a taxable brokerage account and calling for a boycott of MSTR.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 16,
          "removed_lines": 0
        },
        {
          "observed_at": "2026-08-04T23:48:22Z",
          "window_start": "2026-08-04T23:24:25Z",
          "window_end": "2026-08-04T23:48:22Z",
          "status": "source-content",
          "summary": "The Reddit thread gained a comment advocating diversification across ETFs, a small cold-wallet balance and an exchange balance.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 21,
          "removed_lines": 0
        },
        {
          "observed_at": "2026-08-04T23:24:25Z",
          "window_start": "2026-08-04T13:45:55Z",
          "window_end": "2026-08-04T23:24:25Z",
          "status": "source-content",
          "summary": "The Reddit thread gained a comment arguing that universal ETF use would weaken Bitcoin's decentralization.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 10,
          "removed_lines": 0
        }
      ]
    },
    {
      "id": "reddit-nvk-awareness-critique",
      "title": "r/Bitcoin: critique of nvk's past firmware-attack awareness",
      "url": "https://www.reddit.com/r/Bitcoin/comments/1vdtah5/it_was_ai_and_superintelligence_man_i_swear/",
      "organisation": "reddit",
      "kind": "community-discussion",
      "role": "Community discussion",
      "publication_time": null,
      "note": null,
      "gone": null,
      "capture": {
        "status": "held",
        "copies": 3,
        "first_observed": "2026-08-04T10:15:05Z",
        "last_observed": "2026-08-04T18:25:18Z",
        "last_checked": "2026-08-07T07:56:25Z"
      },
      "differences": [
        {
          "observed_at": "2026-08-04T18:25:18Z",
          "window_start": "2026-08-04T17:25:38Z",
          "window_end": "2026-08-04T18:25:18Z",
          "status": "source-content",
          "summary": "The Reddit thread gained 1 new comment.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 8,
          "removed_lines": 0
        },
        {
          "observed_at": "2026-08-04T17:25:38Z",
          "window_start": "2026-08-04T10:15:05Z",
          "window_end": "2026-08-04T17:25:38Z",
          "status": "source-content",
          "summary": "The Reddit thread gained 1 new comment.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 8,
          "removed_lines": 0
        }
      ]
    },
    {
      "id": "reddit-coldtruth-opinion",
      "title": "r/Bitcoin: opinion urging owners to leave Coinkite products",
      "url": "https://www.reddit.com/r/Bitcoin/comments/1veo7gt/the_coldtruth/",
      "organisation": "reddit",
      "kind": "community-discussion",
      "role": "Community discussion",
      "publication_time": null,
      "note": null,
      "gone": null,
      "capture": {
        "status": "held",
        "copies": 2,
        "first_observed": "2026-08-04T10:15:10Z",
        "last_observed": "2026-08-05T14:36:39Z",
        "last_checked": "2026-08-07T07:57:33Z"
      },
      "differences": [
        {
          "observed_at": "2026-08-05T14:36:39Z",
          "window_start": "2026-08-04T10:15:10Z",
          "window_end": "2026-08-05T14:36:39Z",
          "status": "source-content",
          "summary": "Reddit served 1 additional comment record(s); the diff preserves their text and any edits to existing records.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 8,
          "removed_lines": 0
        }
      ]
    },
    {
      "id": "reddit-still-using-added-entropy",
      "title": "r/Bitcoin: continuing to use COLDCARD with user-supplied entropy",
      "url": "https://www.reddit.com/r/Bitcoin/comments/1veebh0/still_using_coldcard_but_with_great_entropy/",
      "organisation": "reddit",
      "kind": "community-discussion",
      "role": "Community discussion",
      "publication_time": null,
      "note": null,
      "gone": null,
      "capture": {
        "status": "held",
        "copies": 1,
        "first_observed": "2026-08-04T13:46:01Z",
        "last_observed": "2026-08-04T13:46:01Z",
        "last_checked": "2026-08-11T13:09:30Z"
      },
      "differences": []
    },
    {
      "id": "reddit-coldcard-never-again",
      "title": "r/Bitcoin: unaffected owner moving off COLDCARD anyway",
      "url": "https://www.reddit.com/r/Bitcoin/comments/1vdsqhy/coldcard_youll_never_hurt_me_again/",
      "organisation": "reddit",
      "kind": "community-discussion",
      "role": "Community discussion",
      "publication_time": null,
      "note": null,
      "gone": null,
      "capture": {
        "status": "held",
        "copies": 4,
        "first_observed": "2026-08-04T13:46:04Z",
        "last_observed": "2026-08-09T16:54:07Z",
        "last_checked": "2026-08-11T13:10:34Z"
      },
      "differences": [
        {
          "observed_at": "2026-08-09T16:54:07Z",
          "window_start": "2026-08-08T08:33:58Z",
          "window_end": "2026-08-09T16:54:07Z",
          "status": "source-content",
          "summary": "A comment comparing the incident to Bitcointalk OGs recommending 256 coin flips was removed.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 0,
          "removed_lines": 8
        },
        {
          "observed_at": "2026-08-08T08:33:58Z",
          "window_start": "2026-08-06T10:03:06Z",
          "window_end": "2026-08-08T08:33:58Z",
          "status": "source-content",
          "summary": "The Reddit thread gained a new participant comment urging the poster to preserve evidence for small claims court.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 8,
          "removed_lines": 0
        },
        {
          "observed_at": "2026-08-06T10:03:06Z",
          "window_start": "2026-08-04T13:46:04Z",
          "window_end": "2026-08-06T10:03:06Z",
          "status": "source-content",
          "summary": "A comment by DonTheHolder (\"Office Space\") no longer appears in the thread; it was deleted on the source.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 0,
          "removed_lines": 8
        }
      ]
    },
    {
      "id": "reddit-ownership-proof-idea",
      "title": "r/Bitcoin: pre-committing wallet ownership proof against future recovery",
      "url": "https://www.reddit.com/r/Bitcoin/comments/1vec9ms/prepared_ownership_proof_idea_smart_or_risky/",
      "organisation": "reddit",
      "kind": "community-discussion",
      "role": "Community discussion",
      "publication_time": null,
      "note": null,
      "gone": null,
      "capture": {
        "status": "held",
        "copies": 1,
        "first_observed": "2026-08-04T10:15:14Z",
        "last_observed": "2026-08-04T10:15:14Z",
        "last_checked": "2026-08-07T07:58:42Z"
      },
      "differences": []
    },
    {
      "id": "reddit-coinkite-refund-question",
      "title": "r/Bitcoin: whether Coinkite will refund COLDCARD purchases",
      "url": "https://www.reddit.com/r/Bitcoin/comments/1vex1o2/will_coinkite_refund_cold_card_purchase/",
      "organisation": "reddit",
      "kind": "community-discussion",
      "role": "Community discussion",
      "publication_time": null,
      "note": null,
      "gone": null,
      "capture": {
        "status": "held",
        "copies": 3,
        "first_observed": "2026-08-04T10:15:19Z",
        "last_observed": "2026-08-04T21:26:57Z",
        "last_checked": "2026-08-07T07:59:51Z"
      },
      "differences": [
        {
          "observed_at": "2026-08-04T21:26:57Z",
          "window_start": "2026-08-04T11:15:09Z",
          "window_end": "2026-08-04T21:26:57Z",
          "status": "source-content",
          "summary": "The Reddit thread gained 1 new comment.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 8,
          "removed_lines": 0
        },
        {
          "observed_at": "2026-08-04T11:15:09Z",
          "window_start": "2026-08-04T10:15:19Z",
          "window_end": "2026-08-04T11:15:09Z",
          "status": "source-content",
          "summary": "One new comment was posted: drumcraze92 clarifying the refund question is about the purchase of the COLDCARD itself, not lost bitcoin.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 8,
          "removed_lines": 0
        }
      ]
    },
    {
      "id": "reddit-future-of-bitcoin-debate",
      "title": "r/Bitcoin: whether the incident challenges the future of Bitcoin",
      "url": "https://www.reddit.com/r/Bitcoin/comments/1vdds1l/the_coldcard_case_fundamentally_challenges_the/",
      "organisation": "reddit",
      "kind": "community-discussion",
      "role": "Community discussion",
      "publication_time": null,
      "note": null,
      "gone": null,
      "capture": {
        "status": "held",
        "copies": 18,
        "first_observed": "2026-08-04T13:46:08Z",
        "last_observed": "2026-08-08T21:34:54Z",
        "last_checked": "2026-08-11T13:11:37Z"
      },
      "differences": [
        {
          "observed_at": "2026-08-08T21:34:54Z",
          "window_start": "2026-08-08T08:34:03Z",
          "window_end": "2026-08-08T21:34:54Z",
          "status": "source-content",
          "summary": "A comment linking to a Ledger wallet thread was removed and another comment was deleted by its author.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 2,
          "removed_lines": 10
        },
        {
          "observed_at": "2026-08-08T08:34:03Z",
          "window_start": "2026-08-08T02:01:20Z",
          "window_end": "2026-08-08T08:34:03Z",
          "status": "source-content",
          "summary": "The thread lost several older comments and gained new ones continuing the exchange about Coinbase custody, centralized control and Bitcoin's value proposition, while the more-stub pointers shifted to different parents.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 46,
          "removed_lines": 64
        },
        {
          "observed_at": "2026-08-08T02:01:20Z",
          "window_start": "2026-08-07T19:30:54Z",
          "window_end": "2026-08-08T02:01:20Z",
          "status": "source-content",
          "summary": "The Reddit thread gained a new participant reply and lost an older comment, while the live more-stub pointer shifted to a different parent.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 9,
          "removed_lines": 9
        },
        {
          "observed_at": "2026-08-07T19:30:54Z",
          "window_start": "2026-08-07T06:18:36Z",
          "window_end": "2026-08-07T19:30:54Z",
          "status": "source-content",
          "summary": "The thread added a NiagaraBTC reply saying the device's RNG was not turned off but was not asked to participate in seed creation, removed a Vipu2 comment about USD decline, and shifted several more-stub parent references.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 16,
          "removed_lines": 20
        },
        {
          "observed_at": "2026-08-07T06:18:36Z",
          "window_start": "2026-08-06T10:03:11Z",
          "window_end": "2026-08-07T06:18:36Z",
          "status": "source-content",
          "summary": "Two comments were deleted and two short new comments added; the collapsed-replies stub list rethreaded to match the deletions.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 19,
          "removed_lines": 17
        },
        {
          "observed_at": "2026-08-06T10:03:11Z",
          "window_start": "2026-08-05T21:02:58Z",
          "window_end": "2026-08-06T10:03:11Z",
          "status": "source-content",
          "summary": "Three comments were deleted and two added, one arguing the incident has major implications for AI-assisted code review and citing GLM 5.2 catching the flaw.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 16,
          "removed_lines": 24
        },
        {
          "observed_at": "2026-08-05T21:02:58Z",
          "window_start": "2026-08-05T14:27:33Z",
          "window_end": "2026-08-05T21:02:58Z",
          "status": "source-content",
          "summary": "Reddit no longer served a comment promoting an entropy service as a way the incident could have been prevented.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 0,
          "removed_lines": 8
        },
        {
          "observed_at": "2026-08-05T14:27:33Z",
          "window_start": "2026-08-05T07:58:59Z",
          "window_end": "2026-08-05T14:27:33Z",
          "status": "source-content",
          "summary": "Several earlier comments were removed or replaced with deleted-account placeholders. New comments discuss passphrases, the usability of multisig and the author's view that the incident exposes a broader trust problem and makes ETFs rational for average users.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 35,
          "removed_lines": 33
        },
        {
          "observed_at": "2026-08-05T07:58:59Z",
          "window_start": "2026-08-04T23:24:41Z",
          "window_end": "2026-08-05T07:58:59Z",
          "status": "source-content",
          "summary": "Two earlier comments about exchange protection and adoption disappeared, one new comment was added, and Reddit's remaining-comment placeholder moved to a different parent.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 9,
          "removed_lines": 23
        },
        {
          "observed_at": "2026-08-04T23:24:41Z",
          "window_start": "2026-08-04T22:18:22Z",
          "window_end": "2026-08-04T23:24:41Z",
          "status": "source-content",
          "summary": "The Reddit thread gained new participant comments.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 48,
          "removed_lines": 9
        },
        {
          "observed_at": "2026-08-04T22:18:22Z",
          "window_start": "2026-08-04T20:18:16Z",
          "window_end": "2026-08-04T22:18:22Z",
          "status": "source-content",
          "summary": "The thread no longer served an earlier comment.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 0,
          "removed_lines": 8
        },
        {
          "observed_at": "2026-08-04T20:18:16Z",
          "window_start": "2026-08-04T19:47:48Z",
          "window_end": "2026-08-04T20:18:16Z",
          "status": "source-content",
          "summary": "An existing Reddit comment changed or its author account was deleted.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 1,
          "removed_lines": 1
        },
        {
          "observed_at": "2026-08-04T19:47:48Z",
          "window_start": "2026-08-04T19:17:05Z",
          "window_end": "2026-08-04T19:47:48Z",
          "status": "source-content",
          "summary": "An existing Reddit comment changed or its author account was deleted.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 1,
          "removed_lines": 11
        },
        {
          "observed_at": "2026-08-04T19:17:05Z",
          "window_start": "2026-08-04T18:47:45Z",
          "window_end": "2026-08-04T19:17:05Z",
          "status": "source-content",
          "summary": "The Reddit thread changed through new comments, removals, or edits.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 19,
          "removed_lines": 16
        },
        {
          "observed_at": "2026-08-04T18:47:45Z",
          "window_start": "2026-08-04T18:16:42Z",
          "window_end": "2026-08-04T18:47:45Z",
          "status": "source-content",
          "summary": "An existing Reddit comment changed or its author account was deleted.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 0,
          "removed_lines": 16
        },
        {
          "observed_at": "2026-08-04T18:16:42Z",
          "window_start": "2026-08-04T16:18:24Z",
          "window_end": "2026-08-04T18:16:42Z",
          "status": "source-content",
          "summary": "The Reddit thread gained 2 new comments while 2 existing comments no longer appeared.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 25,
          "removed_lines": 21
        },
        {
          "observed_at": "2026-08-04T16:18:24Z",
          "window_start": "2026-08-04T13:46:08Z",
          "window_end": "2026-08-04T16:18:24Z",
          "status": "source-content",
          "summary": "The captured reply tree gained a collapsed more-stub indicating one additional reply under an existing comment.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 2,
          "removed_lines": 8
        }
      ]
    },
    {
      "id": "reddit-seed-collision-odds",
      "title": "r/Bitcoin: birthday-bound estimate of seed collisions from reduced entropy",
      "url": "https://www.reddit.com/r/Bitcoin/comments/1vdr94r/93000_coldcardgenerated_seeds_is_all_it_takes_for/",
      "organisation": "reddit",
      "kind": "community-discussion",
      "role": "Community discussion",
      "publication_time": null,
      "note": null,
      "gone": null,
      "capture": {
        "status": "held",
        "copies": 3,
        "first_observed": "2026-08-04T13:46:14Z",
        "last_observed": "2026-08-08T02:01:29Z",
        "last_checked": "2026-08-11T13:12:40Z"
      },
      "differences": [
        {
          "observed_at": "2026-08-08T02:01:29Z",
          "window_start": "2026-08-04T14:46:09Z",
          "window_end": "2026-08-08T02:01:29Z",
          "status": "source-content",
          "summary": "The Reddit thread gained a new participant comment suggesting earlier 2021-2022 thefts could have been organic seed collisions.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 8,
          "removed_lines": 0
        },
        {
          "observed_at": "2026-08-04T14:46:09Z",
          "window_start": "2026-08-04T13:46:14Z",
          "window_end": "2026-08-04T14:46:09Z",
          "status": "source-content",
          "summary": "1 new Reddit comment was posted, by CompetitionDouble420, expressing relief at having used another device.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 10,
          "removed_lines": 0
        }
      ]
    },
    {
      "id": "reddit-jade-passphrase-safety",
      "title": "r/Bitcoin: Jade owner asking if their seed is safe after the incident",
      "url": "https://www.reddit.com/r/Bitcoin/comments/1veiiif/i_have_a_jade_plus_with_a_passphrase/",
      "organisation": "reddit",
      "kind": "community-discussion",
      "role": "Community discussion",
      "publication_time": null,
      "note": null,
      "gone": null,
      "capture": {
        "status": "held",
        "copies": 4,
        "first_observed": "2026-08-04T10:15:24Z",
        "last_observed": "2026-08-05T21:12:12Z",
        "last_checked": "2026-08-07T08:01:00Z"
      },
      "differences": [
        {
          "observed_at": "2026-08-05T21:12:12Z",
          "window_start": "2026-08-05T14:36:54Z",
          "window_end": "2026-08-05T21:12:12Z",
          "status": "source-content",
          "summary": "Reddit served 2 additional comment record(s); the diff preserves their text and any edits to existing records.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 39,
          "removed_lines": 0
        },
        {
          "observed_at": "2026-08-05T14:36:54Z",
          "window_start": "2026-08-04T16:28:15Z",
          "window_end": "2026-08-05T14:36:54Z",
          "status": "source-content",
          "summary": "Reddit served 1 additional comment record(s); the diff preserves their text and any edits to existing records.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 8,
          "removed_lines": 0
        },
        {
          "observed_at": "2026-08-04T16:28:15Z",
          "window_start": "2026-08-04T10:15:24Z",
          "window_end": "2026-08-04T16:28:15Z",
          "status": "source-content",
          "summary": "1 new Reddit comment was posted, by trufin2038, arguing for a Linux air gap and Jade's stateless mode.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 21,
          "removed_lines": 0
        }
      ]
    },
    {
      "id": "reddit-engineering-negligence-post",
      "title": "r/Bitcoin: engineering-negligence analysis of the Coinkite bug",
      "url": "https://www.reddit.com/r/Bitcoin/comments/1ve97sw/basic_flaw_devastating_impact_engineering/",
      "organisation": "reddit",
      "kind": "community-discussion",
      "role": "Community discussion",
      "publication_time": null,
      "note": null,
      "gone": null,
      "capture": {
        "status": "held",
        "copies": 1,
        "first_observed": "2026-08-04T10:15:29Z",
        "last_observed": "2026-08-04T10:15:29Z",
        "last_checked": "2026-08-07T08:02:08Z"
      },
      "differences": []
    },
    {
      "id": "reddit-tribute-to-victims",
      "title": "r/Bitcoin: tribute thread for those affected by the exploit",
      "url": "https://www.reddit.com/r/Bitcoin/comments/1vewkkw/a_tribute_to_all_of_our_brothers_and_sisters/",
      "organisation": "reddit",
      "kind": "community-discussion",
      "role": "Community discussion",
      "publication_time": null,
      "note": null,
      "gone": null,
      "capture": {
        "status": "held",
        "copies": 1,
        "first_observed": "2026-08-06T03:59:20Z",
        "last_observed": "2026-08-06T03:59:20Z",
        "last_checked": "2026-08-08T23:00:22Z"
      },
      "differences": []
    },
    {
      "id": "reddit-multisig-coldcard-seeds-risk",
      "title": "r/Bitcoin: risks of multisig setups that include COLDCARD seeds",
      "url": "https://www.reddit.com/r/Bitcoin/comments/1ved6v3/risks_of_multisig_with_coldcard_seeds/",
      "organisation": "reddit",
      "kind": "community-discussion",
      "role": "Community discussion",
      "publication_time": null,
      "note": null,
      "gone": null,
      "capture": {
        "status": "held",
        "copies": 1,
        "first_observed": "2026-08-06T03:59:24Z",
        "last_observed": "2026-08-06T03:59:24Z",
        "last_checked": "2026-08-08T23:00:26Z"
      },
      "differences": []
    },
    {
      "id": "reddit-btc-declared-dead-reflection",
      "title": "r/Bitcoin: reflection on the incident among past declarations of Bitcoin's death",
      "url": "https://www.reddit.com/r/Bitcoin/comments/1vemsyq/for_all_those_times_when_btc_was_declared_dead/",
      "organisation": "reddit",
      "kind": "community-discussion",
      "role": "Community discussion",
      "publication_time": null,
      "note": null,
      "gone": null,
      "capture": {
        "status": "held",
        "copies": 1,
        "first_observed": "2026-08-06T03:59:27Z",
        "last_observed": "2026-08-06T03:59:27Z",
        "last_checked": "2026-08-08T23:00:33Z"
      },
      "differences": []
    },
    {
      "id": "reddit-coinkite-options-after-disclosure",
      "title": "r/Bitcoin: what Coinkite could have done once the vulnerability was found",
      "url": "https://www.reddit.com/r/Bitcoin/comments/1ve1r5g/is_there_anything_coinkite_could_have_done_once/",
      "organisation": "reddit",
      "kind": "community-discussion",
      "role": "Community discussion",
      "publication_time": null,
      "note": null,
      "gone": null,
      "capture": {
        "status": "held",
        "copies": 5,
        "first_observed": "2026-08-04T10:16:49Z",
        "last_observed": "2026-08-05T21:03:11Z",
        "last_checked": "2026-08-11T05:05:40Z"
      },
      "differences": [
        {
          "observed_at": "2026-08-05T21:03:11Z",
          "window_start": "2026-08-05T14:27:44Z",
          "window_end": "2026-08-05T21:03:11Z",
          "status": "source-content",
          "summary": "The thread gained a comment alleging an unaddressed RNG failure and arguing that routine randomness and integration testing should have detected it.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 10,
          "removed_lines": 0
        },
        {
          "observed_at": "2026-08-05T14:27:44Z",
          "window_start": "2026-08-04T17:47:22Z",
          "window_end": "2026-08-05T14:27:44Z",
          "status": "source-content",
          "summary": "A comment characterising the event as a wallet collision and a longer comment arguing against multisig were removed or replaced with deleted-account placeholders.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 2,
          "removed_lines": 10
        },
        {
          "observed_at": "2026-08-04T17:47:22Z",
          "window_start": "2026-08-04T17:17:22Z",
          "window_end": "2026-08-04T17:47:22Z",
          "status": "source-content",
          "summary": "An existing Reddit comment was edited or removed.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 2,
          "removed_lines": 2
        },
        {
          "observed_at": "2026-08-04T17:17:22Z",
          "window_start": "2026-08-04T10:16:49Z",
          "window_end": "2026-08-04T17:17:22Z",
          "status": "source-content",
          "summary": "The Reddit thread gained 1 new comment.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 8,
          "removed_lines": 0
        }
      ]
    },
    {
      "id": "reddit-passphrase-extra-security",
      "title": "r/Bitcoin: how much extra security a passphrase adds",
      "url": "https://www.reddit.com/r/Bitcoin/comments/1ve8xf0/how_much_extra_security_from_a_passphrase/",
      "organisation": "reddit",
      "kind": "community-discussion",
      "role": "Community discussion",
      "publication_time": null,
      "note": null,
      "gone": null,
      "capture": {
        "status": "held",
        "copies": 4,
        "first_observed": "2026-08-04T10:16:53Z",
        "last_observed": "2026-08-09T10:36:47Z",
        "last_checked": "2026-08-11T05:06:43Z"
      },
      "differences": [
        {
          "observed_at": "2026-08-09T10:36:47Z",
          "window_start": "2026-08-07T06:18:49Z",
          "window_end": "2026-08-09T10:36:47Z",
          "status": "source-content",
          "summary": "A comment linking to a diceware passphrase generator was removed from the thread.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 0,
          "removed_lines": 8
        },
        {
          "observed_at": "2026-08-07T06:18:49Z",
          "window_start": "2026-08-05T14:27:47Z",
          "window_end": "2026-08-07T06:18:49Z",
          "status": "source-content",
          "summary": "The original post body was removed ([removed]); it had asked whether passphrase entropy adds to the entropy of a 12-word seed. The comments remain.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 1,
          "removed_lines": 5
        },
        {
          "observed_at": "2026-08-05T14:27:47Z",
          "window_start": "2026-08-04T10:16:53Z",
          "window_end": "2026-08-05T14:27:47Z",
          "status": "source-content",
          "summary": "Reddit no longer served a comment speculating about how an attacker might search for passphrases after identifying a seed.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 0,
          "removed_lines": 8
        }
      ]
    },
    {
      "id": "reddit-dice-seed-generation",
      "title": "r/Bitcoin: generating seeds with physical dice after losing trust in RNGs",
      "url": "https://www.reddit.com/r/Bitcoin/comments/1vdl4h3/generating_your_own_seed_with_physical_dice_99/",
      "organisation": "reddit",
      "kind": "community-discussion",
      "role": "Community discussion",
      "publication_time": null,
      "note": null,
      "gone": null,
      "capture": {
        "status": "held",
        "copies": 5,
        "first_observed": "2026-08-04T13:46:24Z",
        "last_observed": "2026-08-08T02:01:43Z",
        "last_checked": "2026-08-11T13:13:43Z"
      },
      "differences": [
        {
          "observed_at": "2026-08-08T02:01:43Z",
          "window_start": "2026-08-06T16:35:37Z",
          "window_end": "2026-08-08T02:01:43Z",
          "status": "source-content",
          "summary": "The Reddit thread gained a new participant comment comparing the cost of dice to annual banking losses.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 8,
          "removed_lines": 0
        },
        {
          "observed_at": "2026-08-06T16:35:37Z",
          "window_start": "2026-08-05T14:27:51Z",
          "window_end": "2026-08-06T16:35:37Z",
          "status": "source-content",
          "summary": "Two comments by cleankiwii asking how to convert 99 dice rolls into seed words were deleted.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 4,
          "removed_lines": 4
        },
        {
          "observed_at": "2026-08-05T14:27:51Z",
          "window_start": "2026-08-04T21:48:18Z",
          "window_end": "2026-08-05T14:27:51Z",
          "status": "source-content",
          "summary": "The thread gained comments joking about randomly selecting seed words and cautioning that casino dice could be biased and reveal a seed-generation method.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 18,
          "removed_lines": 0
        },
        {
          "observed_at": "2026-08-04T21:48:18Z",
          "window_start": "2026-08-04T13:46:24Z",
          "window_end": "2026-08-04T21:48:18Z",
          "status": "source-content",
          "summary": "The Reddit thread gained 1 new comment proposing a dice-to-word method.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 8,
          "removed_lines": 0
        }
      ]
    },
    {
      "id": "reddit-quantum-damage-reaction",
      "title": "r/Bitcoin: incident taken as a preview of future quantum-computing FUD",
      "url": "https://www.reddit.com/r/Bitcoin/comments/1ved6wa/the_recent_incident_reminds_us_the_damage_quantum/",
      "organisation": "reddit",
      "kind": "community-discussion",
      "role": "Community discussion",
      "publication_time": null,
      "note": null,
      "gone": null,
      "capture": {
        "status": "held",
        "copies": 2,
        "first_observed": "2026-08-04T10:44:32Z",
        "last_observed": "2026-08-04T16:00:02Z",
        "last_checked": "2026-08-07T08:06:43Z"
      },
      "differences": [
        {
          "observed_at": "2026-08-04T16:00:02Z",
          "window_start": "2026-08-04T10:44:32Z",
          "window_end": "2026-08-04T16:00:02Z",
          "status": "source-content",
          "summary": "1 new Reddit comment was posted, by Thin_Needleworker795, saying quantum computers cannot break a properly generated Bitcoin seed.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 8,
          "removed_lines": 0
        }
      ]
    },
    {
      "id": "bitcointalk-bright-side-opinion",
      "title": "Beyond panic; the bright side of the Coldcard wallet incident",
      "url": "https://bitcointalk.org/index.php?topic=5590248.0",
      "organisation": "BitcoinTalk",
      "kind": "community-discussion",
      "role": "Community discussion",
      "publication_time": "2026-08-03",
      "note": "IjawMan arguing the incident has a bright side: a mass awakening to wallet hygiene, update habits, seed entropy and passphrases. Replies correct the decentralisation framing and debate passphrase strength, with one relaying btcsessions-passphrase-loss-report as evidence a weak passphrase protects nothing. An opinion and sentiment record from the Wallet software board. The views are the posters' own, not verified here.\n",
      "gone": null,
      "capture": {
        "status": "held",
        "copies": 1,
        "first_observed": "2026-08-04T10:19:04Z",
        "last_observed": "2026-08-04T10:19:04Z",
        "last_checked": "2026-08-07T08:08:12Z"
      },
      "differences": []
    },
    {
      "id": "bitcointalk-600-btc-exploit-news",
      "title": "Coldcard Wallet Bug Drains 600 BTC in Ongoing Exploit",
      "url": "https://bitcointalk.org/index.php?topic=5590051.0",
      "organisation": "BitcoinTalk",
      "kind": "community-discussion",
      "role": "Community discussion",
      "publication_time": "2026-07-31",
      "note": "Mate2237 relaying CoinDesk's 31 July coverage of the drains at roughly 600 BTC and about 38 million dollars, and asking whether custodial wallets are really safer. The one reply points to the forum's main incident thread and restates self-custody advice. An early news-relay record of how the story first circulated on the forum. The figures are attributed to the coverage it relays, not verified here.\n",
      "gone": null,
      "capture": {
        "status": "held",
        "copies": 1,
        "first_observed": "2026-08-04T10:19:08Z",
        "last_observed": "2026-08-04T10:19:08Z",
        "last_checked": "2026-08-07T08:08:14Z"
      },
      "differences": []
    },
    {
      "id": "bitcointalk-learn-from-incident",
      "title": "We can all learn one or two from this ColdCard incident",
      "url": "https://bitcointalk.org/index.php?topic=5590065.0",
      "organisation": "BitcoinTalk",
      "kind": "community-discussion",
      "role": "Community discussion",
      "publication_time": "2026-08-03",
      "note": "YellowSwap opening a lessons-learned thread on the Bitcoin Discussion board, drawing one of the longer forum discussions of the incident's takeaways for holders. A community response and sentiment record alongside bitcointalk-bright-side-opinion. The lessons and claims in the thread are the posters' own, not verified here.\n",
      "gone": null,
      "capture": {
        "status": "held",
        "copies": 9,
        "first_observed": "2026-08-04T10:19:12Z",
        "last_observed": "2026-08-08T02:01:49Z",
        "last_checked": "2026-08-09T23:24:56Z"
      },
      "differences": [
        {
          "observed_at": "2026-08-08T02:01:49Z",
          "window_start": "2026-08-07T19:31:24Z",
          "window_end": "2026-08-08T02:01:49Z",
          "status": "capture-noise",
          "summary": "Only Bitcointalk's relative quote dates rolled from Today to absolute dates.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 4,
          "removed_lines": 4
        },
        {
          "observed_at": "2026-08-07T19:31:24Z",
          "window_start": "2026-08-07T06:18:56Z",
          "window_end": "2026-08-07T19:31:24Z",
          "status": "source-content",
          "summary": "The thread gained new posts by arwin100, Supreme Donvic and Dogedegen debating airgapped computers, diversification across wallets, and cracked operating systems.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 37,
          "removed_lines": 0
        },
        {
          "observed_at": "2026-08-07T06:18:56Z",
          "window_start": "2026-08-06T23:49:58Z",
          "window_end": "2026-08-07T06:18:56Z",
          "status": "source-content",
          "summary": "Three new posts (X-ray on verification and watch-only workflows, hd49728 linking Electrum and Bitcoin Core verification guides, yhiaali3 on passphrases and distributing assets). The diff also contains SMF \"Today at\" relative-date rollover, which is presentation noise.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 37,
          "removed_lines": 4
        },
        {
          "observed_at": "2026-08-06T23:49:58Z",
          "window_start": "2026-08-06T16:35:41Z",
          "window_end": "2026-08-06T23:49:58Z",
          "status": "source-content",
          "summary": "Two new posts: Z-tight on airgapped wallets not being newbie-friendly, and I_Anime advising users to write down seed phrases and not rely on hardware wallets being 100 percent safe.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 9,
          "removed_lines": 0
        },
        {
          "observed_at": "2026-08-06T16:35:41Z",
          "window_start": "2026-08-06T10:03:39Z",
          "window_end": "2026-08-06T16:35:41Z",
          "status": "source-content",
          "summary": "One new post by bitmover arguing the risk of airgapped setups lies in the setup step itself, and that a good hardware wallet (\"not coldcard\") is theoretically free of those risks.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 15,
          "removed_lines": 0
        },
        {
          "observed_at": "2026-08-06T10:03:39Z",
          "window_start": "2026-08-06T03:32:23Z",
          "window_end": "2026-08-06T10:03:39Z",
          "status": "source-content",
          "summary": "Two new posts: Outhue on airgapped-computer setups not suiting people who do not live alone, and PostQuantumBTC saying airgapped setup is simple and hardware wallet users are specifically targeted.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 19,
          "removed_lines": 0
        },
        {
          "observed_at": "2026-08-06T03:32:23Z",
          "window_start": "2026-08-04T19:48:09Z",
          "window_end": "2026-08-06T03:32:23Z",
          "status": "source-content",
          "summary": "A participant added a discussion of using an air-gapped computer, describing its perceived benefits and setup burden.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 11,
          "removed_lines": 0
        },
        {
          "observed_at": "2026-08-04T19:48:09Z",
          "window_start": "2026-08-04T10:19:12Z",
          "window_end": "2026-08-04T19:48:09Z",
          "status": "source-content",
          "summary": "The BitcoinTalk thread gained a post arguing ordinary users cannot reasonably be expected to anticipate this attack class.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 6,
          "removed_lines": 0
        }
      ]
    },
    {
      "id": "bitcointalk-large-scale-compromise-thread",
      "title": "Large-scale Coldcard compromise (1360.23 BTC stolen so far)",
      "url": "https://bitcointalk.org/index.php?topic=5589927.0",
      "organisation": "BitcoinTalk",
      "kind": "community-discussion",
      "role": "Community discussion",
      "publication_time": "2026-08-04",
      "note": "flatfly opening the forum's main incident thread on the Bitcoin Discussion board, tallying the drains at 1360.23 BTC and still rising; other registered threads on the forum point here as the megathread. At 292 comments it is the longest-running BitcoinTalk record of community response, reported cases and sentiment as the incident developed. The figures and claims in the thread are the posters' own, not verified here.\n",
      "gone": null,
      "capture": {
        "status": "held",
        "copies": 37,
        "first_observed": "2026-08-04T10:30:19Z",
        "last_observed": "2026-08-09T23:24:58Z",
        "last_checked": "2026-08-09T23:24:58Z"
      },
      "differences": [
        {
          "observed_at": "2026-08-09T23:24:58Z",
          "window_start": "2026-08-09T16:54:41Z",
          "window_end": "2026-08-09T23:24:58Z",
          "status": "source-content",
          "summary": "The thread gained several new replies on 9 August discussing why the stolen funds have not moved, decoy and passphrase strategy, the Mk3 entropy estimate, and a moderator merge note; reply titles also updated to the 1,596 BTC figure.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 167,
          "removed_lines": 6
        },
        {
          "observed_at": "2026-08-09T16:54:41Z",
          "window_start": "2026-08-09T10:36:56Z",
          "window_end": "2026-08-09T16:54:41Z",
          "status": "source-content",
          "summary": "The megathread title updated its tally to 1596 BTC stolen, with a later figure of 1485.77 BTC also appearing, and many new posts were added debating whether the attacker might return funds, how laundering would work, and the emotional impact on victims.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 142,
          "removed_lines": 0
        },
        {
          "observed_at": "2026-08-09T10:36:56Z",
          "window_start": "2026-08-09T04:07:13Z",
          "window_end": "2026-08-09T10:36:56Z",
          "status": "source-content",
          "summary": "The megathread gained several posts discussing OP_Return suicide messages, the hacker's possible reflection, and passphrase search economics, and its title was updated to 1596 BTC stolen.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 65,
          "removed_lines": 0
        },
        {
          "observed_at": "2026-08-09T04:07:13Z",
          "window_start": "2026-08-08T21:35:16Z",
          "window_end": "2026-08-09T04:07:13Z",
          "status": "source-content",
          "summary": "The thread gained a new post about passphrase search economics and another about OP_Return suicide messages, while many relative quote timestamps were rendered as absolute dates.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 63,
          "removed_lines": 45
        },
        {
          "observed_at": "2026-08-08T21:35:16Z",
          "window_start": "2026-08-08T15:05:24Z",
          "window_end": "2026-08-08T21:35:16Z",
          "status": "source-content",
          "summary": "The thread title updated to 1,596 BTC stolen and gained several new replies discussing seed-generation methods, decoy-wallet risks, and passphrase brute-force mechanics.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 78,
          "removed_lines": 1
        },
        {
          "observed_at": "2026-08-08T15:05:24Z",
          "window_start": "2026-08-08T08:34:33Z",
          "window_end": "2026-08-08T15:05:24Z",
          "status": "source-content",
          "summary": "The opening post added Telegram and web scam links to its warning list with a second edit, and the thread gained replies debating decoy and passphrase risk, referencing an inside-job tweet, and comparing self-custody to ETFs.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 232,
          "removed_lines": 42
        },
        {
          "observed_at": "2026-08-08T08:34:33Z",
          "window_start": "2026-08-08T02:01:52Z",
          "window_end": "2026-08-08T08:34:33Z",
          "status": "source-content",
          "summary": "The thread title was updated to 1,485.77 BTC stolen and many new posts were added discussing dice entropy, passphrase strategy, ETF custody and a spam-like social-media campaign post.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 94,
          "removed_lines": 0
        },
        {
          "observed_at": "2026-08-08T02:01:52Z",
          "window_start": "2026-08-07T19:31:26Z",
          "window_end": "2026-08-08T02:01:52Z",
          "status": "source-content",
          "summary": "The thread title was updated to 1,485.77 BTC stolen and several new posts discussed the flaw, attribution, mitigation and on-chain experiments.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 70,
          "removed_lines": 10
        },
        {
          "observed_at": "2026-08-07T19:31:26Z",
          "window_start": "2026-08-07T12:58:16Z",
          "window_end": "2026-08-07T19:31:26Z",
          "status": "source-content",
          "summary": "The thread gained new posts by Pmalek and JayJuanGee on the Bitcoin Red Team findings and self-custody debates, and the reply titles now show 1,485.77 BTC stolen.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 33,
          "removed_lines": 0
        },
        {
          "observed_at": "2026-08-07T12:58:16Z",
          "window_start": "2026-08-07T06:18:59Z",
          "window_end": "2026-08-07T12:58:16Z",
          "status": "source-content",
          "summary": "About a dozen new posts, most notably Wind_FURY pasting Inverse Hanlon's long X essay arguing the incident looks like an inside job, kTimesG claiming the attack was over by Aug 2 with about 2050 compromised accounts detected, and sergiorus relaying Bloomberg's report that Coinkite declined to estimate customer losses.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 194,
          "removed_lines": 0
        },
        {
          "observed_at": "2026-08-07T06:18:59Z",
          "window_start": "2026-08-06T23:50:00Z",
          "window_end": "2026-08-07T06:18:59Z",
          "status": "source-content",
          "summary": "Three new posts (philipma1957's metal-punch passphrase recipe, Forsyth Jones on travel-time seed strategies, JayJuanGee on setup security) and a one-word typo fix by tvbcof (\"bag-fumbers\" to \"bag-fumblers\"). The diff also contains SMF \"Today at\" relative-date rollover, which is presentation noise.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 129,
          "removed_lines": 33
        },
        {
          "observed_at": "2026-08-06T23:50:00Z",
          "window_start": "2026-08-06T16:35:43Z",
          "window_end": "2026-08-06T23:50:00Z",
          "status": "source-content",
          "summary": "Six new posts: Meuserna explaining that restoring a Coldcard-generated seed on a Trezor stays vulnerable, suzanne5223 and OgNasty on bait-wallet experiments, tvbcof speculating about whale keys harvested later, bitmover on passphrase strength, and fillippone on wallet software being the weak layer.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 88,
          "removed_lines": 0
        },
        {
          "observed_at": "2026-08-06T16:35:43Z",
          "window_start": "2026-08-06T10:03:42Z",
          "window_end": "2026-08-06T16:35:43Z",
          "status": "source-content",
          "summary": "Roughly fifteen new posts: kTimesG and Cookdata on honeypot experiments with Mk3 wallets, Trezor safety questions, an \"inside job\" shower thought citing a gist about the Coinkite CTO, a Counterparty NOTSOCOLD asset, and Pmalek reporting Bitcoin Red Team's 5,000 audit findings.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 145,
          "removed_lines": 0
        },
        {
          "observed_at": "2026-08-06T10:03:42Z",
          "window_start": "2026-08-06T03:32:26Z",
          "window_end": "2026-08-06T10:03:42Z",
          "status": "source-content",
          "summary": "Six new posts (Dave1 flagging an unconfirmed suicide claim, passphrase-strength discussion, joker_josue and Danish Ali on vacationing users unaware of losses, ryzaadit on a bait-wallet sweep losing the RBF race) plus an edit to a tvbcof post rewording a sentence about sources overstating search-space metrics.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 83,
          "removed_lines": 4
        },
        {
          "observed_at": "2026-08-06T03:32:26Z",
          "window_start": "2026-08-05T21:03:31Z",
          "window_end": "2026-08-06T03:32:26Z",
          "status": "source-content",
          "summary": "The thread gained several replies about alternate wallet designs, a honeypot-monitor estimate, and whether publishing search-space details could endanger vulnerable funds. Relative quote dates also resolved to August 5 dates.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 45,
          "removed_lines": 12
        },
        {
          "observed_at": "2026-08-05T21:03:31Z",
          "window_start": "2026-08-05T14:27:58Z",
          "window_end": "2026-08-05T21:03:31Z",
          "status": "source-content",
          "summary": "The forum thread gained posts about passphrase strength, migration scams, recovery comparisons and Slipstream, and its displayed reported total reached 1485.77 BTC. It also corrected one #ifdef/#ifndef spelling error.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 204,
          "removed_lines": 1
        },
        {
          "observed_at": "2026-08-05T14:27:58Z",
          "window_start": "2026-08-05T07:59:22Z",
          "window_end": "2026-08-05T14:27:58Z",
          "status": "source-content",
          "summary": "The thread title's reported total increased from 1360.23 BTC to 1485.77 BTC. It also gained posts about reported fund movements, safe migration practices and participants' views of the incident, including two newly listed scam links.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 91,
          "removed_lines": 1
        },
        {
          "observed_at": "2026-08-05T07:59:22Z",
          "window_start": "2026-08-05T00:49:07Z",
          "window_end": "2026-08-05T07:59:22Z",
          "status": "source-content",
          "summary": "The forum thread gained several posts on passphrases, custody, recovery and alternatives, plus a link to a site said to track vulnerable honeypot wallets and a dice-roll script.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 119,
          "removed_lines": 0
        },
        {
          "observed_at": "2026-08-05T00:49:07Z",
          "window_start": "2026-08-05T00:19:05Z",
          "window_end": "2026-08-05T00:49:07Z",
          "status": "source-content",
          "summary": "The BitcoinTalk thread gained two posts, one speculating about a retirement attack and one criticizing the firmware controls and alleging earlier ignored reports.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 18,
          "removed_lines": 0
        },
        {
          "observed_at": "2026-08-05T00:19:05Z",
          "window_start": "2026-08-04T23:48:57Z",
          "window_end": "2026-08-05T00:19:05Z",
          "status": "capture-noise",
          "summary": "Only Bitcointalk's relative quote dates rolled from Today to absolute dates.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 27,
          "removed_lines": 27
        },
        {
          "observed_at": "2026-08-04T23:48:57Z",
          "window_start": "2026-08-04T22:49:32Z",
          "window_end": "2026-08-04T23:48:57Z",
          "status": "source-content",
          "summary": "The thread gained a reply about Mt. Gox, BTC-e and FTX custody failures.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 7,
          "removed_lines": 0
        },
        {
          "observed_at": "2026-08-04T22:49:32Z",
          "window_start": "2026-08-04T22:18:45Z",
          "window_end": "2026-08-04T22:49:32Z",
          "status": "source-content",
          "summary": "A participant added coldcard-audit.com to the thread's scam-site warning list and corrected a typo in that warning.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 2,
          "removed_lines": 2
        },
        {
          "observed_at": "2026-08-04T22:18:45Z",
          "window_start": "2026-08-04T21:48:24Z",
          "window_end": "2026-08-04T22:18:45Z",
          "status": "source-content",
          "summary": "The thread gained two posts, one warning of fake migration groups and one cautioning against conclusions about Coinkite's AI review without its prompts and scope.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 33,
          "removed_lines": 0
        },
        {
          "observed_at": "2026-08-04T21:48:24Z",
          "window_start": "2026-08-04T21:18:33Z",
          "window_end": "2026-08-04T21:48:24Z",
          "status": "source-content",
          "summary": "The thread gained a post criticizing Coinkite's early device-risk guidance.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 19,
          "removed_lines": 0
        },
        {
          "observed_at": "2026-08-04T21:18:33Z",
          "window_start": "2026-08-04T20:48:17Z",
          "window_end": "2026-08-04T21:18:33Z",
          "status": "source-content",
          "summary": "The thread gained a post disputing Coinkite's account of its AI-assisted code review.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 9,
          "removed_lines": 0
        },
        {
          "observed_at": "2026-08-04T20:48:17Z",
          "window_start": "2026-08-04T20:18:42Z",
          "window_end": "2026-08-04T20:48:17Z",
          "status": "source-content",
          "summary": "The thread gained a post advocating diversification, including custodial options, after the compromise.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 3,
          "removed_lines": 0
        },
        {
          "observed_at": "2026-08-04T20:18:42Z",
          "window_start": "2026-08-04T19:17:29Z",
          "window_end": "2026-08-04T20:18:42Z",
          "status": "source-content",
          "summary": "The BitcoinTalk thread gained new posts discussing whether and how users could have been warned, and broader hardware-wallet security concerns.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 20,
          "removed_lines": 0
        },
        {
          "observed_at": "2026-08-04T19:17:29Z",
          "window_start": "2026-08-04T18:48:08Z",
          "window_end": "2026-08-04T19:17:29Z",
          "status": "source-content",
          "summary": "The BitcoinTalk thread gained new posts discussing whether and how users could have been warned, and broader hardware-wallet security concerns.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 26,
          "removed_lines": 0
        },
        {
          "observed_at": "2026-08-04T18:48:08Z",
          "window_start": "2026-08-04T17:47:36Z",
          "window_end": "2026-08-04T18:48:08Z",
          "status": "source-content",
          "summary": "The BitcoinTalk thread gained new posts discussing whether and how users could have been warned, and broader hardware-wallet security concerns.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 6,
          "removed_lines": 0
        },
        {
          "observed_at": "2026-08-04T17:47:36Z",
          "window_start": "2026-08-04T17:17:37Z",
          "window_end": "2026-08-04T17:47:36Z",
          "status": "source-content",
          "summary": "The BitcoinTalk thread gained 2 new posts.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 9,
          "removed_lines": 0
        },
        {
          "observed_at": "2026-08-04T17:17:37Z",
          "window_start": "2026-08-04T16:49:24Z",
          "window_end": "2026-08-04T17:17:37Z",
          "status": "source-content",
          "summary": "The BitcoinTalk thread gained 1 new post.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 17,
          "removed_lines": 0
        },
        {
          "observed_at": "2026-08-04T16:49:24Z",
          "window_start": "2026-08-04T15:49:04Z",
          "window_end": "2026-08-04T16:49:24Z",
          "status": "source-content",
          "summary": "The BitcoinTalk thread gained 1 new post.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 11,
          "removed_lines": 0
        },
        {
          "observed_at": "2026-08-04T15:49:04Z",
          "window_start": "2026-08-04T15:17:14Z",
          "window_end": "2026-08-04T15:49:04Z",
          "status": "source-content",
          "summary": "A new forum reply said the incident had undermined trust in self-custody and other wallet companies.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 15,
          "removed_lines": 0
        },
        {
          "observed_at": "2026-08-04T15:17:14Z",
          "window_start": "2026-08-04T14:17:15Z",
          "window_end": "2026-08-04T15:17:14Z",
          "status": "source-content",
          "summary": "A new forum reply speculated about an insider and broadened the discussion to risks at other wallet vendors.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 13,
          "removed_lines": 0
        },
        {
          "observed_at": "2026-08-04T14:17:15Z",
          "window_start": "2026-08-04T13:46:31Z",
          "window_end": "2026-08-04T14:17:15Z",
          "status": "source-content",
          "summary": "Additional forum posts were added to the ongoing discussion, including further debate over the incident’s cause and wallet choices.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 12,
          "removed_lines": 0
        },
        {
          "observed_at": "2026-08-04T13:46:31Z",
          "window_start": "2026-08-04T10:30:19Z",
          "window_end": "2026-08-04T13:46:31Z",
          "status": "source-content",
          "summary": "Several new posts expanded the discussion of responsibility, passphrases, dice-generated seeds and alternative hardware wallets. Two earlier posts were no longer served in the print view.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 90,
          "removed_lines": 25
        }
      ]
    },
    {
      "id": "bitcointalk-hack-revolution-opinion",
      "title": "The coldcard hack will change Bitcoin, it's a revolution.",
      "url": "https://bitcointalk.org/index.php?topic=5590255.0",
      "organisation": "BitcoinTalk",
      "kind": "community-discussion",
      "role": "Community discussion",
      "publication_time": "2026-08-04",
      "note": "SaddamoftheWest arguing the incident is a turning point for Bitcoin and self custody, framing the reaction as an assault on self custody by latecomer influencers. Replies dispute the revolution framing, debate whether the discussion belongs in the megathread bitcointalk-large-scale-compromise-thread, and predict passphrases becoming near-mandatory practice. An opinion and sentiment record from the Bitcoin Discussion board. The views are the posters' own, not verified here.\n",
      "gone": {
        "since": "20260805T143727Z",
        "http_status": "404",
        "observed": "Captured 33 times between 4 August 2026 10:30 UTC and 5 August 08:08, then 404\nfrom 5 August 14:37. Rechecked on 6 August 2026: both the topic page and the\nprint view 404, while the five other BitcoinTalk topics this archive polls all\nanswer 200 from this host in the same pass, so it is this topic that was\nwithdrawn rather than the board refusing this collector. Whether it was deleted\nby a moderator or moved to a board that does not serve anonymously is not\nestablished here. The ten captures held span the thread's public life.\n"
      },
      "capture": {
        "status": "held",
        "copies": 10,
        "first_observed": "2026-08-04T10:30:27Z",
        "last_observed": "2026-08-05T08:08:02Z",
        "last_checked": "2026-08-05T08:08:02Z"
      },
      "differences": [
        {
          "observed_at": "2026-08-05T08:08:02Z",
          "window_start": "2026-08-05T01:28:21Z",
          "window_end": "2026-08-05T08:08:02Z",
          "status": "source-content",
          "summary": "The forum thread gained three replies: one defended Bitcoin's underlying cryptography, while two others described reduced confidence in hardware wallets and self-custody, and noted that Coinkite had not committed to compensation.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 23,
          "removed_lines": 0
        },
        {
          "observed_at": "2026-08-05T01:28:21Z",
          "window_start": "2026-08-05T00:28:06Z",
          "window_end": "2026-08-05T01:28:21Z",
          "status": "source-content",
          "summary": "The BitcoinTalk thread gained a reply saying many hardware-wallet users may still hold coins without fully understanding the technology.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 10,
          "removed_lines": 0
        },
        {
          "observed_at": "2026-08-05T00:28:06Z",
          "window_start": "2026-08-04T21:57:32Z",
          "window_end": "2026-08-05T00:28:06Z",
          "status": "capture-noise",
          "summary": "Only Bitcointalk's relative quote dates rolled from Today to absolute dates.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 6,
          "removed_lines": 6
        },
        {
          "observed_at": "2026-08-04T21:57:32Z",
          "window_start": "2026-08-04T20:57:39Z",
          "window_end": "2026-08-04T21:57:32Z",
          "status": "source-content",
          "summary": "The thread gained a reply predicting a lasting debate and possible customer compensation.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 16,
          "removed_lines": 0
        },
        {
          "observed_at": "2026-08-04T20:57:39Z",
          "window_start": "2026-08-04T18:26:09Z",
          "window_end": "2026-08-04T20:57:39Z",
          "status": "source-content",
          "summary": "The thread gained a post arguing that the incident should prompt safer wallet design and criticizing exchange custody messaging.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 13,
          "removed_lines": 3
        },
        {
          "observed_at": "2026-08-04T18:26:09Z",
          "window_start": "2026-08-04T16:58:44Z",
          "window_end": "2026-08-04T18:26:09Z",
          "status": "source-content",
          "summary": "The BitcoinTalk thread gained 1 new post.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 4,
          "removed_lines": 0
        },
        {
          "observed_at": "2026-08-04T16:58:44Z",
          "window_start": "2026-08-04T13:16:19Z",
          "window_end": "2026-08-04T16:58:44Z",
          "status": "source-content",
          "summary": "The BitcoinTalk thread gained 1 new post.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 8,
          "removed_lines": 0
        },
        {
          "observed_at": "2026-08-04T13:16:19Z",
          "window_start": "2026-08-04T11:44:56Z",
          "window_end": "2026-08-04T13:16:19Z",
          "status": "source-content",
          "summary": "A new post by ultrloa argued that users choose convenience over security and called for education, while agreeing that seed phrases can be as secure as private keys.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 11,
          "removed_lines": 0
        },
        {
          "observed_at": "2026-08-04T11:44:56Z",
          "window_start": "2026-08-04T10:30:27Z",
          "window_end": "2026-08-04T11:44:56Z",
          "status": "source-content",
          "summary": "Two new posts were added to the thread: MusaMohamed arguing most holders will not change their security practice despite the attack, and pooya87 replying that the hack will not change how people store funds and that seed phrases provide the same 128 bits of security as a private key.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 15,
          "removed_lines": 0
        }
      ]
    },
    {
      "id": "bitcointalk-seed-passphrase-explainer",
      "title": "Bitcoin wallet seed phrase with an optional (extended) passphrase",
      "url": "https://bitcointalk.org/index.php?topic=5590296.0",
      "organisation": "BitcoinTalk",
      "kind": "community-discussion",
      "role": "Community discussion",
      "publication_time": "2026-08-04",
      "note": "UchihaSarada writing an incident-motivated explainer on seed entropy and optional passphrases, arguing a passphrase cannot repair a weakly generated seed. The post links coinkite-mk3-advisory and coinkite-backgrounder, quotes btcsessions-passphrase-loss-report as evidence a passphrase alone does not protect a weak Mk3 seed, and points to the megathread bitcointalk-large-scale-compromise-thread. An educational community response with no replies at registration. The technical claims are the poster's own and those of the sources it cites, not verified here.\n",
      "gone": null,
      "capture": {
        "status": "held",
        "copies": 1,
        "first_observed": "2026-08-04T10:30:33Z",
        "last_observed": "2026-08-04T10:30:33Z",
        "last_checked": "2026-08-07T00:31:16Z"
      },
      "differences": []
    },
    {
      "id": "stackernews-entropy-bug-history",
      "title": "ColdCard Entropy Bug: An Investigative History",
      "url": "https://stacker.news/items/1540008",
      "organisation": "Stacker News",
      "kind": "community-discussion",
      "role": "Community discussion",
      "publication_time": "2026-08-04",
      "note": "SimpleStacker posting an investigative history of the COLDCARD entropy bug. A substantial retrospective discussion of the vulnerability and disclosure history; the historical account and technical claims are the author's, not verified here. Captured through the site's public GraphQL API: the rendered pages crash the capture tab, and the API answers POST from this host. The query fixes the captured surface to the item's title, text and two levels of comments, each with author and absolute timestamp.\n",
      "gone": null,
      "capture": {
        "status": "held",
        "copies": 6,
        "first_observed": "2026-08-04T17:47:39Z",
        "last_observed": "2026-08-04T20:18:45Z",
        "last_checked": "2026-08-09T23:25:02Z"
      },
      "differences": [
        {
          "observed_at": "2026-08-04T20:18:45Z",
          "window_start": "2026-08-04T19:48:15Z",
          "window_end": "2026-08-04T20:18:45Z",
          "status": "source-content",
          "summary": "The Stacker News thread gained a new comment about the migration and the importance of randomness.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 7,
          "removed_lines": 0
        },
        {
          "observed_at": "2026-08-04T19:48:15Z",
          "window_start": "2026-08-04T19:17:33Z",
          "window_end": "2026-08-04T19:48:15Z",
          "status": "capture-noise",
          "summary": "The GraphQL response reordered existing comments without changing their text.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 7,
          "removed_lines": 7
        },
        {
          "observed_at": "2026-08-04T19:17:33Z",
          "window_start": "2026-08-04T18:48:12Z",
          "window_end": "2026-08-04T19:17:33Z",
          "status": "capture-noise",
          "summary": "The GraphQL response reordered existing comments without changing their text.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 7,
          "removed_lines": 7
        },
        {
          "observed_at": "2026-08-04T18:48:12Z",
          "window_start": "2026-08-04T18:17:08Z",
          "window_end": "2026-08-04T18:48:12Z",
          "status": "capture-noise",
          "summary": "The GraphQL response reordered existing comments without changing their text.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 7,
          "removed_lines": 7
        },
        {
          "observed_at": "2026-08-04T18:17:08Z",
          "window_start": "2026-08-04T17:47:39Z",
          "window_end": "2026-08-04T18:17:08Z",
          "status": "source-content",
          "summary": "The Stacker News thread gained a new comment.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 7,
          "removed_lines": 0
        }
      ]
    },
    {
      "id": "stackernews-limits-dont-trust-verify",
      "title": "Coldcard and the limits of “don't trust, verify”",
      "url": "https://stacker.news/items/1539812",
      "organisation": "Stacker News",
      "kind": "community-discussion",
      "role": "Community discussion",
      "publication_time": "2026-08-04",
      "note": "bennet examining what the incident says about the limits of the “don't trust, verify” framing. A community debate about code review, product trust and self-custody practice, alongside stackernews-personal-responsibility and stackernews-dear-podcasters. The arguments in the thread are the posters' own, not verified here. Captured through the site's public GraphQL API: the rendered pages crash the capture tab, and the API answers POST from this host. The query fixes the captured surface to the item's title, text and two levels of comments, each with author and absolute timestamp.\n",
      "gone": null,
      "capture": {
        "status": "held",
        "copies": 2,
        "first_observed": "2026-08-04T17:47:42Z",
        "last_observed": "2026-08-04T21:48:31Z",
        "last_checked": "2026-08-09T23:25:04Z"
      },
      "differences": [
        {
          "observed_at": "2026-08-04T21:48:31Z",
          "window_start": "2026-08-04T17:47:42Z",
          "window_end": "2026-08-04T21:48:31Z",
          "status": "source-content",
          "summary": "The Stacker News thread gained a new comment containing a violent threat.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 7,
          "removed_lines": 0
        }
      ]
    },
    {
      "id": "stackernews-retirement-attack-question",
      "title": "Cold Card Retirement Attack?",
      "url": "https://stacker.news/items/1540033",
      "organisation": "Stacker News",
      "kind": "community-discussion",
      "role": "Community discussion",
      "publication_time": "2026-08-04",
      "note": "UncleJim21 asking whether the incident resembles the vendor's historical “retirement attack” concept. Documents post-incident scrutiny of earlier COLDCARD material, alongside coldcard-retirement-attack-claim and reddit-retirement-attack-resurfaced. Any implication of intent is speculation by the posters, not evidence, and is not endorsed here. Captured through the site's public GraphQL API: the rendered pages crash the capture tab, and the API answers POST from this host. The query fixes the captured surface to the item's title, text and two levels of comments, each with author and absolute timestamp.\n",
      "gone": null,
      "capture": {
        "status": "held",
        "copies": 7,
        "first_observed": "2026-08-04T17:47:45Z",
        "last_observed": "2026-08-06T10:03:52Z",
        "last_checked": "2026-08-09T23:25:07Z"
      },
      "differences": [
        {
          "observed_at": "2026-08-06T10:03:52Z",
          "window_start": "2026-08-05T07:59:31Z",
          "window_end": "2026-08-06T10:03:52Z",
          "status": "capture-noise",
          "summary": "Comment ordering churn only: teemupleb's \"strategic Bitcoin reserve\" guess moved from a lower position to the top of the comment list with unchanged text.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 7,
          "removed_lines": 7
        },
        {
          "observed_at": "2026-08-05T07:59:31Z",
          "window_start": "2026-08-05T00:49:16Z",
          "window_end": "2026-08-05T07:59:31Z",
          "status": "source-content",
          "summary": "The GraphQL response reordered an existing comment and the discussion gained a new reply saying the historical material did not age well.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 14,
          "removed_lines": 7
        },
        {
          "observed_at": "2026-08-05T00:49:16Z",
          "window_start": "2026-08-04T23:49:06Z",
          "window_end": "2026-08-05T00:49:16Z",
          "status": "source-content",
          "summary": "The Stacker News thread gained a new comment saying the scale of the disaster made its author sympathize with NVK psychologically.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 14,
          "removed_lines": 7
        },
        {
          "observed_at": "2026-08-04T23:49:06Z",
          "window_start": "2026-08-04T20:48:26Z",
          "window_end": "2026-08-04T23:49:06Z",
          "status": "source-content",
          "summary": "The Stacker News thread gained a reply speculating about the on-chain consolidation pattern.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 7,
          "removed_lines": 0
        },
        {
          "observed_at": "2026-08-04T20:48:26Z",
          "window_start": "2026-08-04T19:17:38Z",
          "window_end": "2026-08-04T20:48:26Z",
          "status": "source-content",
          "summary": "The Stacker News thread gained a new comment saying its author now supports the retirement-attack theory.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 7,
          "removed_lines": 0
        },
        {
          "observed_at": "2026-08-04T19:17:38Z",
          "window_start": "2026-08-04T17:47:45Z",
          "window_end": "2026-08-04T19:17:38Z",
          "status": "source-content",
          "summary": "The Stacker News thread gained a new comment alleging an inside job.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 7,
          "removed_lines": 0
        }
      ]
    },
    {
      "id": "stackernews-matt-levine-heist",
      "title": "Bitcoins Have No Physical Form: The Coldcard Heist (Money Stuff, Matt Levine)",
      "url": "https://stacker.news/items/1539875",
      "organisation": "Stacker News",
      "kind": "community-discussion",
      "role": "Community discussion",
      "publication_time": "2026-08-04",
      "note": "denlillaapan linking Matt Levine's Money Stuff coverage of the COLDCARD heist. A link post held for the discussion and as a pointer to mainstream financial coverage; claims and characterisations belong to the newsletter. Captured through the site's public GraphQL API: the rendered pages crash the capture tab, and the API answers POST from this host. The query fixes the captured surface to the item's title, text and two levels of comments, each with author and absolute timestamp.\n",
      "gone": null,
      "capture": {
        "status": "held",
        "copies": 2,
        "first_observed": "2026-08-04T17:56:33Z",
        "last_observed": "2026-08-04T19:57:18Z",
        "last_checked": "2026-08-07T14:25:01Z"
      },
      "differences": [
        {
          "observed_at": "2026-08-04T19:57:18Z",
          "window_start": "2026-08-04T17:56:33Z",
          "window_end": "2026-08-04T19:57:18Z",
          "status": "capture-noise",
          "summary": "The GraphQL response reordered an existing comment without changing its text.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 7,
          "removed_lines": 7
        }
      ]
    },
    {
      "id": "reddit-im-out",
      "title": "r/coldcard: owner leaving COLDCARD after the incident",
      "url": "https://www.reddit.com/r/coldcard/comments/1vfbi4w/im_out/",
      "organisation": "reddit",
      "kind": "community-discussion",
      "role": "Community discussion",
      "publication_time": null,
      "note": null,
      "gone": null,
      "capture": {
        "status": "held",
        "copies": 21,
        "first_observed": "2026-08-04T17:47:48Z",
        "last_observed": "2026-08-08T21:35:27Z",
        "last_checked": "2026-08-11T13:16:42Z"
      },
      "differences": [
        {
          "observed_at": "2026-08-08T21:35:27Z",
          "window_start": "2026-08-08T15:05:35Z",
          "window_end": "2026-08-08T21:35:27Z",
          "status": "source-content",
          "summary": "The thread gained a new comment comparing leaving COLDCARD to losing a relationship.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 8,
          "removed_lines": 0
        },
        {
          "observed_at": "2026-08-08T15:05:35Z",
          "window_start": "2026-08-07T19:31:36Z",
          "window_end": "2026-08-08T15:05:35Z",
          "status": "source-content",
          "summary": "Two comments by anotherfroggyevening were replaced with [deleted] and [removed], including one linking to a thread arguing the incident was deliberate rather than incompetent.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 2,
          "removed_lines": 11
        },
        {
          "observed_at": "2026-08-07T19:31:36Z",
          "window_start": "2026-08-06T03:32:44Z",
          "window_end": "2026-08-07T19:31:36Z",
          "status": "source-content",
          "summary": "The thread gained a comment saying the poster moved funds to Coinbase and lost trust in Coinkite despite having used a passphrase and dice-generated seeds.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 10,
          "removed_lines": 0
        },
        {
          "observed_at": "2026-08-06T03:32:44Z",
          "window_start": "2026-08-05T21:03:43Z",
          "window_end": "2026-08-06T03:32:44Z",
          "status": "source-content",
          "summary": "The thread gained comments proposing limited reuse of a COLDCARD and criticizing Coinkite’s competence, including an inside-job allegation presented as the commenter’s speculation.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 40,
          "removed_lines": 0
        },
        {
          "observed_at": "2026-08-05T21:03:43Z",
          "window_start": "2026-08-05T14:28:11Z",
          "window_end": "2026-08-05T21:03:43Z",
          "status": "source-content",
          "summary": "The thread gained comments questioning Coinkite's staffing and future support, and discussing alternative hardware wallets and continued use after dice-derived seed generation.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 36,
          "removed_lines": 0
        },
        {
          "observed_at": "2026-08-05T14:28:11Z",
          "window_start": "2026-08-05T07:59:34Z",
          "window_end": "2026-08-05T14:28:11Z",
          "status": "source-content",
          "summary": "The thread gained owner accounts of leaving COLDCARD despite dice-derived seeds and passphrases, alongside replies asserting the patch is safe and questioning that assessment.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 49,
          "removed_lines": 0
        },
        {
          "observed_at": "2026-08-05T07:59:34Z",
          "window_start": "2026-08-05T01:49:29Z",
          "window_end": "2026-08-05T07:59:34Z",
          "status": "source-content",
          "summary": "The thread gained criticism of COLDCARD and discussion of alternative wallets, dice-generated entropy, passphrases and speculation about the incident.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 97,
          "removed_lines": 0
        },
        {
          "observed_at": "2026-08-05T01:49:29Z",
          "window_start": "2026-08-05T01:19:24Z",
          "window_end": "2026-08-05T01:49:29Z",
          "status": "source-content",
          "summary": "The Reddit thread gained an owner report that they moved their bitcoin off a COLDCARD and felt safer afterward.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 8,
          "removed_lines": 0
        },
        {
          "observed_at": "2026-08-05T01:19:24Z",
          "window_start": "2026-08-05T00:49:20Z",
          "window_end": "2026-08-05T01:19:24Z",
          "status": "source-content",
          "summary": "The Reddit thread gained two comments, including one rejecting an intentional-drain theory.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 18,
          "removed_lines": 0
        },
        {
          "observed_at": "2026-08-05T00:49:20Z",
          "window_start": "2026-08-05T00:19:17Z",
          "window_end": "2026-08-05T00:49:20Z",
          "status": "source-content",
          "summary": "The Reddit thread gained two replies discussing a past customer-data leak and victims of phishing scams.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 16,
          "removed_lines": 0
        },
        {
          "observed_at": "2026-08-05T00:19:17Z",
          "window_start": "2026-08-04T23:25:30Z",
          "window_end": "2026-08-05T00:19:17Z",
          "status": "source-content",
          "summary": "The Reddit thread gained comments questioning the timing of the fix and discussing dice-generated entropy.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 20,
          "removed_lines": 0
        },
        {
          "observed_at": "2026-08-04T23:25:30Z",
          "window_start": "2026-08-04T22:49:44Z",
          "window_end": "2026-08-04T23:25:30Z",
          "status": "source-content",
          "summary": "The Reddit thread gained a new participant comment.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 8,
          "removed_lines": 0
        },
        {
          "observed_at": "2026-08-04T22:49:44Z",
          "window_start": "2026-08-04T21:48:36Z",
          "window_end": "2026-08-04T22:49:44Z",
          "status": "source-content",
          "summary": "The Reddit thread gained a comment assigning responsibility for the incident to COLDCARD.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 10,
          "removed_lines": 0
        },
        {
          "observed_at": "2026-08-04T21:48:36Z",
          "window_start": "2026-08-04T21:18:45Z",
          "window_end": "2026-08-04T21:48:36Z",
          "status": "source-content",
          "summary": "The Reddit thread gained 1 new comment and no longer served an earlier comment.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 8,
          "removed_lines": 8
        },
        {
          "observed_at": "2026-08-04T21:18:45Z",
          "window_start": "2026-08-04T20:48:29Z",
          "window_end": "2026-08-04T21:18:45Z",
          "status": "source-content",
          "summary": "The Reddit thread gained 3 new comments.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 24,
          "removed_lines": 0
        },
        {
          "observed_at": "2026-08-04T20:48:29Z",
          "window_start": "2026-08-04T20:18:53Z",
          "window_end": "2026-08-04T20:48:29Z",
          "status": "source-content",
          "summary": "The Reddit thread gained 2 new comments.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 20,
          "removed_lines": 0
        },
        {
          "observed_at": "2026-08-04T20:18:53Z",
          "window_start": "2026-08-04T19:48:23Z",
          "window_end": "2026-08-04T20:18:53Z",
          "status": "source-content",
          "summary": "The Reddit thread gained 3 new comments.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 24,
          "removed_lines": 0
        },
        {
          "observed_at": "2026-08-04T19:48:23Z",
          "window_start": "2026-08-04T19:17:41Z",
          "window_end": "2026-08-04T19:48:23Z",
          "status": "source-content",
          "summary": "The Reddit thread gained 1 new comment.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 8,
          "removed_lines": 0
        },
        {
          "observed_at": "2026-08-04T19:17:41Z",
          "window_start": "2026-08-04T18:17:21Z",
          "window_end": "2026-08-04T19:17:41Z",
          "status": "source-content",
          "summary": "The Reddit thread gained 1 new comment.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 9,
          "removed_lines": 0
        },
        {
          "observed_at": "2026-08-04T18:17:21Z",
          "window_start": "2026-08-04T17:47:48Z",
          "window_end": "2026-08-04T18:17:21Z",
          "status": "source-content",
          "summary": "The Reddit thread gained 1 new comment.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 8,
          "removed_lines": 0
        }
      ]
    },
    {
      "id": "reddit-inside-job-speculation",
      "title": "r/coldcard: speculation about the bug's 2021 origin",
      "url": "https://www.reddit.com/r/coldcard/comments/1vfdmtf/inside_job_the_bug_conveniently_originated_in_2021/",
      "organisation": "reddit",
      "kind": "community-discussion",
      "role": "Community discussion",
      "publication_time": null,
      "note": null,
      "gone": null,
      "capture": {
        "status": "held",
        "copies": 9,
        "first_observed": "2026-08-04T17:56:35Z",
        "last_observed": "2026-08-07T14:25:04Z",
        "last_checked": "2026-08-07T14:25:04Z"
      },
      "differences": [
        {
          "observed_at": "2026-08-07T14:25:04Z",
          "window_start": "2026-08-06T16:44:14Z",
          "window_end": "2026-08-07T14:25:04Z",
          "status": "source-content",
          "summary": "One new comment by Charming-Designer944 laying out dice-roll entropy math: 50 rolls for 128 bits and 100 rolls for a 256-bit, 24-word seed.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 10,
          "removed_lines": 0
        },
        {
          "observed_at": "2026-08-06T16:44:14Z",
          "window_start": "2026-08-06T03:42:39Z",
          "window_end": "2026-08-06T16:44:14Z",
          "status": "source-content",
          "summary": "Reddit served 1 additional comment record(s); the diff preserves their text and any edits to existing records.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 9,
          "removed_lines": 0
        },
        {
          "observed_at": "2026-08-06T03:42:39Z",
          "window_start": "2026-08-05T21:12:54Z",
          "window_end": "2026-08-06T03:42:39Z",
          "status": "source-content",
          "summary": "Reddit served 2 additional comment record(s); the diff preserves their text and any edits to existing records.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 16,
          "removed_lines": 0
        },
        {
          "observed_at": "2026-08-05T21:12:54Z",
          "window_start": "2026-08-05T08:08:10Z",
          "window_end": "2026-08-05T21:12:54Z",
          "status": "source-content",
          "summary": "Reddit served 1 additional comment record(s); the diff preserves their text and any edits to existing records.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 8,
          "removed_lines": 0
        },
        {
          "observed_at": "2026-08-05T08:08:10Z",
          "window_start": "2026-08-05T01:58:07Z",
          "window_end": "2026-08-05T08:08:10Z",
          "status": "source-content",
          "summary": "Reddit served 11 additional comment record(s); the diff preserves their text and any edits to existing records.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 90,
          "removed_lines": 0
        },
        {
          "observed_at": "2026-08-05T01:58:07Z",
          "window_start": "2026-08-04T23:34:38Z",
          "window_end": "2026-08-05T01:58:07Z",
          "status": "source-content",
          "summary": "The Reddit thread gained an antisemitic reply asserting a Jewish conspiracy.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 8,
          "removed_lines": 0
        },
        {
          "observed_at": "2026-08-04T23:34:38Z",
          "window_start": "2026-08-04T21:27:42Z",
          "window_end": "2026-08-04T23:34:38Z",
          "status": "source-content",
          "summary": "The Reddit thread gained a comment suggesting the social-media responder might not know the codebase.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 8,
          "removed_lines": 0
        },
        {
          "observed_at": "2026-08-04T21:27:42Z",
          "window_start": "2026-08-04T17:56:35Z",
          "window_end": "2026-08-04T21:27:42Z",
          "status": "source-content",
          "summary": "The Reddit thread gained 1 new comment rejecting an inside-job theory while speculating about disclosure timing.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 20,
          "removed_lines": 0
        }
      ]
    },
    {
      "id": "reddit-coldcard-open-source-question",
      "title": "r/coldcard: whether COLDCARD is really open source",
      "url": "https://www.reddit.com/r/coldcard/comments/1vf4z1b/is_coldcard_really_open_source_or_not/",
      "organisation": "reddit",
      "kind": "community-discussion",
      "role": "Community discussion",
      "publication_time": null,
      "note": null,
      "gone": null,
      "capture": {
        "status": "held",
        "copies": 7,
        "first_observed": "2026-08-04T17:56:40Z",
        "last_observed": "2026-08-07T14:25:09Z",
        "last_checked": "2026-08-07T14:25:09Z"
      },
      "differences": [
        {
          "observed_at": "2026-08-07T14:25:09Z",
          "window_start": "2026-08-05T08:08:14Z",
          "window_end": "2026-08-07T14:25:09Z",
          "status": "source-content",
          "summary": "The post body was deleted and now reads [removed], while the title and comments remain. The prior capture preserves the original body asking whether Coldcard's code was available for inspection.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 1,
          "removed_lines": 9
        },
        {
          "observed_at": "2026-08-05T08:08:14Z",
          "window_start": "2026-08-04T23:34:43Z",
          "window_end": "2026-08-05T08:08:14Z",
          "status": "source-content",
          "summary": "Reddit served 1 additional comment record(s); the diff preserves their text and any edits to existing records.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 8,
          "removed_lines": 0
        },
        {
          "observed_at": "2026-08-04T23:34:43Z",
          "window_start": "2026-08-04T21:57:44Z",
          "window_end": "2026-08-04T23:34:43Z",
          "status": "source-content",
          "summary": "The Reddit thread gained new participant comments.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 10,
          "removed_lines": 0
        },
        {
          "observed_at": "2026-08-04T21:57:44Z",
          "window_start": "2026-08-04T20:28:05Z",
          "window_end": "2026-08-04T21:57:44Z",
          "status": "source-content",
          "summary": "The Reddit thread gained 1 new comment about open-source verification.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 10,
          "removed_lines": 0
        },
        {
          "observed_at": "2026-08-04T20:28:05Z",
          "window_start": "2026-08-04T18:26:22Z",
          "window_end": "2026-08-04T20:28:05Z",
          "status": "source-content",
          "summary": "The Reddit thread gained 1 new comment.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 18,
          "removed_lines": 0
        },
        {
          "observed_at": "2026-08-04T18:26:22Z",
          "window_start": "2026-08-04T17:56:40Z",
          "window_end": "2026-08-04T18:26:22Z",
          "status": "source-content",
          "summary": "The Reddit thread gained 1 new comment.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 8,
          "removed_lines": 0
        }
      ]
    },
    {
      "id": "reddit-multisig-only-way",
      "title": "r/coldcard: whether multisig is the only remaining option",
      "url": "https://www.reddit.com/r/coldcard/comments/1vf9oh5/so_is_multisig_the_only_way_out/",
      "organisation": "reddit",
      "kind": "community-discussion",
      "role": "Community discussion",
      "publication_time": null,
      "note": null,
      "gone": null,
      "capture": {
        "status": "held",
        "copies": 8,
        "first_observed": "2026-08-04T17:56:45Z",
        "last_observed": "2026-08-07T14:25:13Z",
        "last_checked": "2026-08-07T14:25:13Z"
      },
      "differences": [
        {
          "observed_at": "2026-08-07T14:25:13Z",
          "window_start": "2026-08-06T16:44:23Z",
          "window_end": "2026-08-07T14:25:13Z",
          "status": "source-content",
          "summary": "One new comment by ElderMight arguing the multisig push is an overreaction, warning that a 2-of-3 setup also needs all three public keys, and recommending a dice-generated key with a strong passphrase instead.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 16,
          "removed_lines": 0
        },
        {
          "observed_at": "2026-08-06T16:44:23Z",
          "window_start": "2026-08-06T10:15:59Z",
          "window_end": "2026-08-06T16:44:23Z",
          "status": "source-content",
          "summary": "Reddit served 1 additional comment record(s); the diff preserves their text and any edits to existing records.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 10,
          "removed_lines": 0
        },
        {
          "observed_at": "2026-08-06T10:15:59Z",
          "window_start": "2026-08-05T21:13:03Z",
          "window_end": "2026-08-06T10:15:59Z",
          "status": "source-content",
          "summary": "Reddit served 1 additional comment record(s); the diff preserves their text and any edits to existing records.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 8,
          "removed_lines": 0
        },
        {
          "observed_at": "2026-08-05T21:13:03Z",
          "window_start": "2026-08-05T14:37:46Z",
          "window_end": "2026-08-05T21:13:03Z",
          "status": "source-content",
          "summary": "Reddit served 1 additional comment record(s); the diff preserves their text and any edits to existing records.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 8,
          "removed_lines": 0
        },
        {
          "observed_at": "2026-08-05T14:37:46Z",
          "window_start": "2026-08-05T08:08:19Z",
          "window_end": "2026-08-05T14:37:46Z",
          "status": "source-content",
          "summary": "Reddit served 2 additional comment record(s); the diff preserves their text and any edits to existing records.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 21,
          "removed_lines": 0
        },
        {
          "observed_at": "2026-08-05T08:08:19Z",
          "window_start": "2026-08-04T20:28:11Z",
          "window_end": "2026-08-05T08:08:19Z",
          "status": "source-content",
          "summary": "Reddit served 2 additional comment record(s); the diff preserves their text and any edits to existing records.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 16,
          "removed_lines": 0
        },
        {
          "observed_at": "2026-08-04T20:28:11Z",
          "window_start": "2026-08-04T17:56:45Z",
          "window_end": "2026-08-04T20:28:11Z",
          "status": "source-content",
          "summary": "The Reddit thread gained 1 new comment.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 8,
          "removed_lines": 0
        }
      ]
    },
    {
      "id": "reddit-entropy-explainer-question",
      "title": "r/coldcard: owner asking what the entropy issue means",
      "url": "https://www.reddit.com/r/coldcard/comments/1vf4hdx/is_it_only_about_entropy_i_dont_get_it/",
      "organisation": "reddit",
      "kind": "community-discussion",
      "role": "Community discussion",
      "publication_time": null,
      "note": null,
      "gone": null,
      "capture": {
        "status": "held",
        "copies": 6,
        "first_observed": "2026-08-04T17:47:51Z",
        "last_observed": "2026-08-07T19:31:43Z",
        "last_checked": "2026-08-11T13:17:45Z"
      },
      "differences": [
        {
          "observed_at": "2026-08-07T19:31:43Z",
          "window_start": "2026-08-06T03:32:49Z",
          "window_end": "2026-08-07T19:31:43Z",
          "status": "source-content",
          "summary": "The thread gained a comment stating that COLDCARD used a pseudo-random number generator, so the seed phrases were not truly random.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 8,
          "removed_lines": 0
        },
        {
          "observed_at": "2026-08-06T03:32:49Z",
          "window_start": "2026-08-05T14:28:15Z",
          "window_end": "2026-08-06T03:32:49Z",
          "status": "source-content",
          "summary": "A commenter asked whether COLDCARD’s number-to-seed conversion is compatible with SeedSigner, Sparrow and Ian Coleman tools.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 11,
          "removed_lines": 0
        },
        {
          "observed_at": "2026-08-05T14:28:15Z",
          "window_start": "2026-08-05T07:59:37Z",
          "window_end": "2026-08-05T14:28:15Z",
          "status": "source-content",
          "summary": "A comment was edited to change its stated entropy figure for 23 randomly chosen words from 230 to 253 bits, and its illustrative reduced figure from 150 to 200 bits.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 4,
          "removed_lines": 4
        },
        {
          "observed_at": "2026-08-05T07:59:37Z",
          "window_start": "2026-08-04T23:25:35Z",
          "window_end": "2026-08-05T07:59:37Z",
          "status": "source-content",
          "summary": "The thread gained a comment estimating entropy from randomly chosen words and contrasting it with the commenter's stated estimate for the flaw.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 11,
          "removed_lines": 0
        },
        {
          "observed_at": "2026-08-04T23:25:35Z",
          "window_start": "2026-08-04T17:47:51Z",
          "window_end": "2026-08-04T23:25:35Z",
          "status": "source-content",
          "summary": "The Reddit thread gained new participant comments.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 12,
          "removed_lines": 0
        }
      ]
    },
    {
      "id": "reddit-self-custody-dagger",
      "title": "r/coldcard: incident described as a blow to self-custody",
      "url": "https://www.reddit.com/r/coldcard/comments/1vf5gj4/this_has_struck_a_dagger_through_the_heart_of/",
      "organisation": "reddit",
      "kind": "community-discussion",
      "role": "Community discussion",
      "publication_time": null,
      "note": null,
      "gone": null,
      "capture": {
        "status": "held",
        "copies": 5,
        "first_observed": "2026-08-04T17:47:55Z",
        "last_observed": "2026-08-07T06:19:19Z",
        "last_checked": "2026-08-11T13:18:48Z"
      },
      "differences": [
        {
          "observed_at": "2026-08-07T06:19:19Z",
          "window_start": "2026-08-05T21:03:56Z",
          "window_end": "2026-08-07T06:19:19Z",
          "status": "source-content",
          "summary": "The original post body was replaced with [removed], and two comments by Crypto-Moony were deleted from the thread.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 1,
          "removed_lines": 27
        },
        {
          "observed_at": "2026-08-05T21:03:56Z",
          "window_start": "2026-08-04T20:48:35Z",
          "window_end": "2026-08-05T21:03:56Z",
          "status": "source-content",
          "summary": "Three comments attributing part of the incident to user error and urging distrust of RNGs were removed and replaced with deleted-account placeholders.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 12,
          "removed_lines": 19
        },
        {
          "observed_at": "2026-08-04T20:48:35Z",
          "window_start": "2026-08-04T18:48:28Z",
          "window_end": "2026-08-04T20:48:35Z",
          "status": "source-content",
          "summary": "The Reddit thread gained 1 new comment.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 8,
          "removed_lines": 0
        },
        {
          "observed_at": "2026-08-04T18:48:28Z",
          "window_start": "2026-08-04T17:47:55Z",
          "window_end": "2026-08-04T18:48:28Z",
          "status": "source-content",
          "summary": "The Reddit thread gained 1 new comment.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 14,
          "removed_lines": 0
        }
      ]
    },
    {
      "id": "reddit-hacker-still-progressing",
      "title": "r/Bitcoin: report that the COLDCARD drainer is still progressing",
      "url": "https://www.reddit.com/r/Bitcoin/comments/1vfagz9/the_coldcard_hacker_is_still_progressing_stolen/",
      "organisation": "reddit",
      "kind": "community-discussion",
      "role": "Community discussion",
      "publication_time": null,
      "note": null,
      "gone": null,
      "capture": {
        "status": "held",
        "copies": 31,
        "first_observed": "2026-08-04T17:47:58Z",
        "last_observed": "2026-08-09T23:25:20Z",
        "last_checked": "2026-08-11T13:19:52Z"
      },
      "differences": [
        {
          "observed_at": "2026-08-09T23:25:20Z",
          "window_start": "2026-08-09T16:55:02Z",
          "window_end": "2026-08-09T23:25:20Z",
          "status": "source-content",
          "summary": "One short comment was removed and Reddit API more-stub entries for several parents were reordered.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 6,
          "removed_lines": 14
        },
        {
          "observed_at": "2026-08-09T16:55:02Z",
          "window_start": "2026-08-08T21:35:38Z",
          "window_end": "2026-08-09T16:55:02Z",
          "status": "source-content",
          "summary": "Two new comments were added: one asks why the known attacker addresses cannot simply be frozen, and another asks how stolen bitcoin can be converted to cash without being caught.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 16,
          "removed_lines": 19
        },
        {
          "observed_at": "2026-08-08T21:35:38Z",
          "window_start": "2026-08-08T15:05:45Z",
          "window_end": "2026-08-08T21:35:38Z",
          "status": "source-content",
          "summary": "The thread gained new comments about AI complacency and laziness while several older comments were deleted and live stub counts shifted.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 51,
          "removed_lines": 69
        },
        {
          "observed_at": "2026-08-08T15:05:45Z",
          "window_start": "2026-08-08T02:02:17Z",
          "window_end": "2026-08-08T15:05:45Z",
          "status": "source-content",
          "summary": "A new comment comparing early Android wallet RNG failures to hardware wallets was added, and three short existing comments were removed.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 12,
          "removed_lines": 26
        },
        {
          "observed_at": "2026-08-08T02:02:17Z",
          "window_start": "2026-08-07T19:31:53Z",
          "window_end": "2026-08-08T02:02:17Z",
          "status": "source-content",
          "summary": "A participant comment was removed from the Reddit thread.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 0,
          "removed_lines": 8
        },
        {
          "observed_at": "2026-08-07T19:31:53Z",
          "window_start": "2026-08-07T12:58:37Z",
          "window_end": "2026-08-07T19:31:53Z",
          "status": "source-content",
          "summary": "The thread added new comments including an off-topic healthcare message and a claim that institutional custody is the only safe path, removed a sub-thread about a prior warning, and adjusted more-stub parent references.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 33,
          "removed_lines": 45
        },
        {
          "observed_at": "2026-08-07T12:58:37Z",
          "window_start": "2026-08-07T06:19:23Z",
          "window_end": "2026-08-07T12:58:37Z",
          "status": "source-content",
          "summary": "Three comments were deleted and three added, one urging anyone with any COLDCARD model to move coins because the company cannot be trusted.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 26,
          "removed_lines": 24
        },
        {
          "observed_at": "2026-08-07T06:19:23Z",
          "window_start": "2026-08-06T16:36:06Z",
          "window_end": "2026-08-07T06:19:23Z",
          "status": "source-content",
          "summary": "Eleven comments were deleted and ten added, several sympathising with small retail victims whose life savings show in the screenshot and questioning whether self-custody was oversold.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 87,
          "removed_lines": 99
        },
        {
          "observed_at": "2026-08-06T16:36:06Z",
          "window_start": "2026-08-06T10:04:10Z",
          "window_end": "2026-08-06T16:36:06Z",
          "status": "source-content",
          "summary": "Five comments were deleted and four added, including a report that 4 years of savings are gone and a suggestion that AI assisted the entropy cracking.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 46,
          "removed_lines": 54
        },
        {
          "observed_at": "2026-08-06T10:04:10Z",
          "window_start": "2026-08-06T03:32:59Z",
          "window_end": "2026-08-06T10:04:10Z",
          "status": "source-content",
          "summary": "Six comments were deleted and five added, including one asking how anyone knows Coinkite is not draining the wallets itself and one discussing proof of theft in court.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 55,
          "removed_lines": 53
        },
        {
          "observed_at": "2026-08-06T03:32:59Z",
          "window_start": "2026-08-05T21:04:02Z",
          "window_end": "2026-08-06T03:32:59Z",
          "status": "source-content",
          "summary": "The thread added and removed numerous comments, including renewed discussion of fiat, wallet safety and an unverified claim that the flaw was deliberate. One account and its comment were also deleted.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 170,
          "removed_lines": 179
        },
        {
          "observed_at": "2026-08-05T21:04:02Z",
          "window_start": "2026-08-05T14:28:22Z",
          "window_end": "2026-08-05T21:04:02Z",
          "status": "source-content",
          "summary": "Numerous comments about law-enforcement recovery, terminology, passphrases and unrelated bitcoin debate were no longer served in the thread.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 257,
          "removed_lines": 326
        },
        {
          "observed_at": "2026-08-05T14:28:22Z",
          "window_start": "2026-08-05T07:59:44Z",
          "window_end": "2026-08-05T14:28:22Z",
          "status": "source-content",
          "summary": "Numerous comments about the alleged drainer, bitcoin reversibility and speculative explanations were no longer served, while some comments were replaced with deleted or removed placeholders. The thread also gained a brief expression of sympathy.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 192,
          "removed_lines": 176
        },
        {
          "observed_at": "2026-08-05T07:59:44Z",
          "window_start": "2026-08-05T01:49:40Z",
          "window_end": "2026-08-05T07:59:44Z",
          "status": "source-content",
          "summary": "Many earlier comments disappeared and the thread gained new reactions, including claims distinguishing a prior dice-input issue from the current vulnerability and speculation about the incident.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 231,
          "removed_lines": 283
        },
        {
          "observed_at": "2026-08-05T01:49:40Z",
          "window_start": "2026-08-05T01:19:35Z",
          "window_end": "2026-08-05T01:49:40Z",
          "status": "source-content",
          "summary": "Several earlier comments disappeared, two new replies were added, and an existing comment was edited to add the word \"into\" to its seed-phrase copying description. New replies included claims about further vulnerable wallets and reactions to Bitcoin self-custody.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 70,
          "removed_lines": 78
        },
        {
          "observed_at": "2026-08-05T01:19:35Z",
          "window_start": "2026-08-05T00:49:30Z",
          "window_end": "2026-08-05T01:19:35Z",
          "status": "source-content",
          "summary": "The thread gained four comments, an existing comment added a claimed Trezor warning email, and several earlier comments were deleted or removed.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 47,
          "removed_lines": 40
        },
        {
          "observed_at": "2026-08-05T00:49:30Z",
          "window_start": "2026-08-05T00:19:27Z",
          "window_end": "2026-08-05T00:49:30Z",
          "status": "source-content",
          "summary": "Several earlier comments disappeared and four new replies were added, including speculation about the attacker and extradition from Indonesia.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 35,
          "removed_lines": 46
        },
        {
          "observed_at": "2026-08-05T00:19:27Z",
          "window_start": "2026-08-04T23:49:20Z",
          "window_end": "2026-08-05T00:19:27Z",
          "status": "source-content",
          "summary": "The Reddit thread gained new participant comments.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 97,
          "removed_lines": 91
        },
        {
          "observed_at": "2026-08-04T23:49:20Z",
          "window_start": "2026-08-04T23:25:46Z",
          "window_end": "2026-08-04T23:49:20Z",
          "status": "source-content",
          "summary": "The Reddit thread gained new participant comments.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 153,
          "removed_lines": 153
        },
        {
          "observed_at": "2026-08-04T23:25:46Z",
          "window_start": "2026-08-04T22:49:55Z",
          "window_end": "2026-08-04T23:25:46Z",
          "status": "source-content",
          "summary": "The Reddit thread gained new participant comments.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 123,
          "removed_lines": 89
        },
        {
          "observed_at": "2026-08-04T22:49:55Z",
          "window_start": "2026-08-04T22:19:07Z",
          "window_end": "2026-08-04T22:49:55Z",
          "status": "source-content",
          "summary": "The Reddit thread gained new participant comments.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 147,
          "removed_lines": 103
        },
        {
          "observed_at": "2026-08-04T22:19:07Z",
          "window_start": "2026-08-04T21:48:47Z",
          "window_end": "2026-08-04T22:19:07Z",
          "status": "source-content",
          "summary": "The Reddit thread gained 18 new comments and an existing comment was edited.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 158,
          "removed_lines": 3
        },
        {
          "observed_at": "2026-08-04T21:48:47Z",
          "window_start": "2026-08-04T21:18:55Z",
          "window_end": "2026-08-04T21:48:47Z",
          "status": "source-content",
          "summary": "The Reddit thread gained 10 new comments, an existing comment was edited, and two earlier comments were no longer served.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 94,
          "removed_lines": 17
        },
        {
          "observed_at": "2026-08-04T21:18:55Z",
          "window_start": "2026-08-04T20:48:39Z",
          "window_end": "2026-08-04T21:18:55Z",
          "status": "source-content",
          "summary": "The Reddit thread gained 14 new comments.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 148,
          "removed_lines": 0
        },
        {
          "observed_at": "2026-08-04T20:48:39Z",
          "window_start": "2026-08-04T20:19:04Z",
          "window_end": "2026-08-04T20:48:39Z",
          "status": "source-content",
          "summary": "The Reddit thread gained 17 new comments.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 151,
          "removed_lines": 0
        },
        {
          "observed_at": "2026-08-04T20:19:04Z",
          "window_start": "2026-08-04T19:48:34Z",
          "window_end": "2026-08-04T20:19:04Z",
          "status": "source-content",
          "summary": "The Reddit thread gained 25 new comments.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 218,
          "removed_lines": 0
        },
        {
          "observed_at": "2026-08-04T19:48:34Z",
          "window_start": "2026-08-04T19:17:52Z",
          "window_end": "2026-08-04T19:48:34Z",
          "status": "source-content",
          "summary": "The Reddit thread gained 16 new comments.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 220,
          "removed_lines": 0
        },
        {
          "observed_at": "2026-08-04T19:17:52Z",
          "window_start": "2026-08-04T18:48:32Z",
          "window_end": "2026-08-04T19:17:52Z",
          "status": "source-content",
          "summary": "The Reddit thread gained 19 new comments.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 172,
          "removed_lines": 0
        },
        {
          "observed_at": "2026-08-04T18:48:32Z",
          "window_start": "2026-08-04T18:17:32Z",
          "window_end": "2026-08-04T18:48:32Z",
          "status": "source-content",
          "summary": "The Reddit thread changed through new comments, removals, or edits.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 134,
          "removed_lines": 6
        },
        {
          "observed_at": "2026-08-04T18:17:32Z",
          "window_start": "2026-08-04T17:47:58Z",
          "window_end": "2026-08-04T18:17:32Z",
          "status": "source-content",
          "summary": "The Reddit thread gained 27 new comments.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 232,
          "removed_lines": 3
        }
      ]
    },
    {
      "id": "reddit-not-your-keys-not-your-coins",
      "title": "r/Bitcoin: self-custody sentiment after the COLDCARD incident",
      "url": "https://www.reddit.com/r/Bitcoin/comments/1vfak2k/not_your_keys_not_your_coins/",
      "organisation": "reddit",
      "kind": "community-discussion",
      "role": "Community discussion",
      "publication_time": null,
      "note": null,
      "gone": null,
      "capture": {
        "status": "held",
        "copies": 23,
        "first_observed": "2026-08-04T17:48:03Z",
        "last_observed": "2026-08-08T21:35:44Z",
        "last_checked": "2026-08-11T13:20:55Z"
      },
      "differences": [
        {
          "observed_at": "2026-08-08T21:35:44Z",
          "window_start": "2026-08-07T06:19:29Z",
          "window_end": "2026-08-08T21:35:44Z",
          "status": "source-content",
          "summary": "A one-line bullish comment was removed from the thread.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 0,
          "removed_lines": 8
        },
        {
          "observed_at": "2026-08-07T06:19:29Z",
          "window_start": "2026-08-06T16:36:15Z",
          "window_end": "2026-08-07T06:19:29Z",
          "status": "source-content",
          "summary": "Two comments by Nick700 now show as [deleted] with author [deleted], and two new comments by puck2 appeared, one listing mainstream custodial on-ramps and one asking whether 256-bit entropy could be attacked by a superintelligent AI.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 20,
          "removed_lines": 4
        },
        {
          "observed_at": "2026-08-06T16:36:15Z",
          "window_start": "2026-08-06T03:33:07Z",
          "window_end": "2026-08-06T16:36:15Z",
          "status": "source-content",
          "summary": "Three new comments in the liability thread: BigDik6355 arguing bitcoin uniquely has no counterparty liability, Time_Jump8047 citing the DFPI settlement that Yotta falsely claimed FDIC coverage, and roconnor (edited) explaining the Evolve Bank and Synapse commingling failure behind the Yotta losses.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 34,
          "removed_lines": 0
        },
        {
          "observed_at": "2026-08-06T03:33:07Z",
          "window_start": "2026-08-05T21:04:11Z",
          "window_end": "2026-08-06T03:33:07Z",
          "status": "source-content",
          "summary": "A prior comment about Bitcoin Core was removed, and the thread gained comments questioning Bitcoin’s mass-adoption use and disputing a claim about liability.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 16,
          "removed_lines": 10
        },
        {
          "observed_at": "2026-08-05T21:04:11Z",
          "window_start": "2026-08-05T14:28:28Z",
          "window_end": "2026-08-05T21:04:11Z",
          "status": "source-content",
          "summary": "The thread gained comments about FDIC coverage, a reported fintech funds-access issue, and a recommendation for offline 2-of-3 multisig using separate devices.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 42,
          "removed_lines": 0
        },
        {
          "observed_at": "2026-08-05T14:28:28Z",
          "window_start": "2026-08-05T07:59:50Z",
          "window_end": "2026-08-05T14:28:28Z",
          "status": "source-content",
          "summary": "The thread gained a series of comments debating exchange failures, reduced entropy, the accessibility of self-custody and financial protections, including an exchange about a reported Brazilian bank case.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 122,
          "removed_lines": 0
        },
        {
          "observed_at": "2026-08-05T07:59:50Z",
          "window_start": "2026-08-05T01:49:46Z",
          "window_end": "2026-08-05T07:59:50Z",
          "status": "source-content",
          "summary": "The thread gained discussion of self-custody's usability, dice-based seed generation, brokerage and exchange custody, and confidence in bitcoin's wider purpose.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 102,
          "removed_lines": 0
        },
        {
          "observed_at": "2026-08-05T01:49:46Z",
          "window_start": "2026-08-05T00:49:36Z",
          "window_end": "2026-08-05T01:49:46Z",
          "status": "source-content",
          "summary": "The Reddit thread gained a reply advocating holding bitcoin through stocks.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 8,
          "removed_lines": 0
        },
        {
          "observed_at": "2026-08-05T00:49:36Z",
          "window_start": "2026-08-05T00:19:33Z",
          "window_end": "2026-08-05T00:49:36Z",
          "status": "source-content",
          "summary": "The Reddit thread gained a question about how to know whether a hardware wallet is compromised.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 8,
          "removed_lines": 0
        },
        {
          "observed_at": "2026-08-05T00:19:33Z",
          "window_start": "2026-08-04T23:49:26Z",
          "window_end": "2026-08-05T00:19:33Z",
          "status": "source-content",
          "summary": "The Reddit thread gained a comment about using hardware and backups in different places.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 8,
          "removed_lines": 0
        },
        {
          "observed_at": "2026-08-04T23:49:26Z",
          "window_start": "2026-08-04T23:25:54Z",
          "window_end": "2026-08-04T23:49:26Z",
          "status": "source-content",
          "summary": "The Reddit thread gained comments questioning self-custody and asking about MPC.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 39,
          "removed_lines": 7
        },
        {
          "observed_at": "2026-08-04T23:25:54Z",
          "window_start": "2026-08-04T22:50:03Z",
          "window_end": "2026-08-04T23:25:54Z",
          "status": "source-content",
          "summary": "The Reddit thread gained a new participant comment.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 8,
          "removed_lines": 0
        },
        {
          "observed_at": "2026-08-04T22:50:03Z",
          "window_start": "2026-08-04T22:19:13Z",
          "window_end": "2026-08-04T22:50:03Z",
          "status": "source-content",
          "summary": "The Reddit thread gained comments about transaction-signing risks, dice entropy and spreading holdings across storage methods.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 72,
          "removed_lines": 0
        },
        {
          "observed_at": "2026-08-04T22:19:13Z",
          "window_start": "2026-08-04T21:48:54Z",
          "window_end": "2026-08-04T22:19:13Z",
          "status": "source-content",
          "summary": "The Reddit thread gained 2 new comments.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 16,
          "removed_lines": 0
        },
        {
          "observed_at": "2026-08-04T21:48:54Z",
          "window_start": "2026-08-04T21:19:01Z",
          "window_end": "2026-08-04T21:48:54Z",
          "status": "source-content",
          "summary": "The Reddit thread gained 6 new comments.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 51,
          "removed_lines": 0
        },
        {
          "observed_at": "2026-08-04T21:19:01Z",
          "window_start": "2026-08-04T20:48:46Z",
          "window_end": "2026-08-04T21:19:01Z",
          "status": "source-content",
          "summary": "The Reddit thread gained 1 new comment.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 8,
          "removed_lines": 0
        },
        {
          "observed_at": "2026-08-04T20:48:46Z",
          "window_start": "2026-08-04T20:19:09Z",
          "window_end": "2026-08-04T20:48:46Z",
          "status": "source-content",
          "summary": "The Reddit thread gained 4 new comments.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 36,
          "removed_lines": 0
        },
        {
          "observed_at": "2026-08-04T20:19:09Z",
          "window_start": "2026-08-04T19:48:39Z",
          "window_end": "2026-08-04T20:19:09Z",
          "status": "source-content",
          "summary": "The Reddit thread gained 3 new comments.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 24,
          "removed_lines": 0
        },
        {
          "observed_at": "2026-08-04T19:48:39Z",
          "window_start": "2026-08-04T19:17:58Z",
          "window_end": "2026-08-04T19:48:39Z",
          "status": "source-content",
          "summary": "The Reddit thread changed through new comments, removals, or edits.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 65,
          "removed_lines": 3
        },
        {
          "observed_at": "2026-08-04T19:17:58Z",
          "window_start": "2026-08-04T18:48:37Z",
          "window_end": "2026-08-04T19:17:58Z",
          "status": "source-content",
          "summary": "The Reddit thread gained 7 new comments.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 60,
          "removed_lines": 0
        },
        {
          "observed_at": "2026-08-04T18:48:37Z",
          "window_start": "2026-08-04T18:17:37Z",
          "window_end": "2026-08-04T18:48:37Z",
          "status": "source-content",
          "summary": "The Reddit thread gained 4 new comments.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 34,
          "removed_lines": 0
        },
        {
          "observed_at": "2026-08-04T18:17:37Z",
          "window_start": "2026-08-04T17:48:03Z",
          "window_end": "2026-08-04T18:17:37Z",
          "status": "source-content",
          "summary": "The Reddit thread gained 13 new comments.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 123,
          "removed_lines": 0
        }
      ]
    },
    {
      "id": "mempool-research-key-exposure",
      "title": "Coldcard Key Exposure",
      "url": "https://research.mempool.space/coldcard-key-exposure/",
      "organisation": "mempool.space Research",
      "kind": "independent-analysis",
      "role": "Independent primary analysis",
      "publication_time": "2026-08-04",
      "note": "mempool.space Research's incident guide, published after the first four drain waves. It separates affected firmware and seed-generation cases, recommends migration steps and links its technical and funds-accounting claims to primary material. The risk assessments and recommendations belong to the authors; registration here does not independently verify them.\n",
      "gone": null,
      "capture": {
        "status": "held",
        "copies": 3,
        "first_observed": "2026-08-05T02:24:23Z",
        "last_observed": "2026-08-13T12:55:37Z",
        "last_checked": "2026-08-15T12:26:43Z"
      },
      "differences": [
        {
          "observed_at": "2026-08-13T12:55:37Z",
          "window_start": "2026-08-05T07:59:55Z",
          "window_end": "2026-08-13T12:55:37Z",
          "status": "source-content",
          "summary": "The guide grew from a short read to a long explainer adding a What happened section, a per-model firmware scope table, affected-key risk tables, migration route guidance and a root-cause summary.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 63,
          "removed_lines": 4
        },
        {
          "observed_at": "2026-08-05T07:59:55Z",
          "window_start": "2026-08-05T02:24:23Z",
          "window_end": "2026-08-05T07:59:55Z",
          "status": "source-content",
          "summary": "The incident guide revised its opening description and changed the date of its reported single-signature Mk4 theft example from 1 August to 4 August 2026.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 2,
          "removed_lines": 1
        }
      ]
    },
    {
      "id": "bitcoinmag-self-custody-response",
      "title": "Self Custody Is Dead. Long Live Self Custody",
      "url": "https://bitcoinmagazine.com/culture/self-custody-is-dead-long-live-self-custody",
      "organisation": "Bitcoin Magazine",
      "kind": "reporting",
      "role": "Reporting",
      "publication_time": "2026-08-04",
      "note": "Juan Galt's argument that the COLDCARD failure should lead to stronger self-custody practice rather than a return to custodians. Useful as a record of the wider confidence debate after the incident; its characterisations and prescriptions are the author's, not findings of this archive.\n",
      "gone": null,
      "capture": {
        "status": "held",
        "copies": 8,
        "first_observed": "2026-08-05T02:24:24Z",
        "last_observed": "2026-08-14T10:00:36Z",
        "last_checked": "2026-08-15T12:56:36Z"
      },
      "differences": [
        {
          "observed_at": "2026-08-14T10:00:36Z",
          "window_start": "2026-08-14T03:27:57Z",
          "window_end": "2026-08-14T10:00:36Z",
          "status": "capture-noise",
          "summary": "Only social-media link formatting in the page header and the live-price widget label formatting changed; the article body was unchanged.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 2,
          "removed_lines": 8
        },
        {
          "observed_at": "2026-08-14T03:27:57Z",
          "window_start": "2026-08-13T20:59:28Z",
          "window_end": "2026-08-14T03:27:57Z",
          "status": "capture-noise",
          "summary": "Only Bitcoin Magazine site chrome changed: related article cards rotated and section counters incremented.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 3,
          "removed_lines": 3
        },
        {
          "observed_at": "2026-08-13T20:59:28Z",
          "window_start": "2026-08-12T11:58:06Z",
          "window_end": "2026-08-13T20:59:28Z",
          "status": "capture-noise",
          "summary": "Only Bitcoin Magazine site chrome changed: social links were listed one per line, related article cards rotated, and section counters incremented.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 21,
          "removed_lines": 15
        },
        {
          "observed_at": "2026-08-12T11:58:06Z",
          "window_start": "2026-08-12T05:11:37Z",
          "window_end": "2026-08-12T11:58:06Z",
          "status": "capture-noise",
          "summary": "Only Bitcoin Magazine's rotating LATEST NEWS rail and category counters changed; the article body was unchanged.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 8,
          "removed_lines": 8
        },
        {
          "observed_at": "2026-08-12T05:11:37Z",
          "window_start": "2026-08-08T03:27:17Z",
          "window_end": "2026-08-12T05:11:37Z",
          "status": "capture-noise",
          "summary": "Only rotating related-story headlines and the site article counter changed; the article text was unchanged.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 10,
          "removed_lines": 10
        },
        {
          "observed_at": "2026-08-08T03:27:17Z",
          "window_start": "2026-08-07T20:53:53Z",
          "window_end": "2026-08-08T03:27:17Z",
          "status": "capture-noise",
          "summary": "Only the publication's own rails changed: the latest-news list reordered and the NEWS section counter moved from 1,500 to 1,499. The article body is unchanged.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 3,
          "removed_lines": 3
        },
        {
          "observed_at": "2026-08-07T20:53:53Z",
          "window_start": "2026-08-05T02:24:24Z",
          "window_end": "2026-08-07T20:53:53Z",
          "status": "capture-noise",
          "summary": "Only the homepage's rotating article list and category counters changed; the target article's own text was not in the diff.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 21,
          "removed_lines": 19
        }
      ]
    },
    {
      "id": "cktripwire-honeypot-monitor",
      "title": "CKTRIPWIRE honeypot scoreboard",
      "url": "https://cktripwire.com/",
      "organisation": "CKTRIPWIRE",
      "kind": "chain-monitor",
      "role": "Chain monitor",
      "publication_time": null,
      "note": "Live experiment funding deliberately vulnerable Mk3-v4 honeypots with different added dice-roll or passphrase entropy, then recording whether and how quickly they are swept. It exposes anonymised handles, coarse value bands and transaction links while withholding addresses for live honeypots. This is primary experimental reporting by the operator; the setup, entropy estimates and attacker attribution have not been independently reproduced by this archive.\n",
      "gone": null,
      "capture": {
        "status": "held",
        "copies": 20,
        "first_observed": "2026-08-05T02:24:25Z",
        "last_observed": "2026-08-13T01:24:15Z",
        "last_checked": "2026-08-15T14:24:21Z"
      },
      "differences": [
        {
          "observed_at": "2026-08-13T01:24:15Z",
          "window_start": "2026-08-12T12:55:08Z",
          "window_end": "2026-08-13T01:24:15Z",
          "status": "source-content",
          "summary": "Another honeypot (HP-E786) was swept and the live/swept counts flipped, while an older sweep (HP-2C6F) aged out of the event log and the table updated the status of HP-9C4F.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 12,
          "removed_lines": 12
        },
        {
          "observed_at": "2026-08-12T12:55:08Z",
          "window_start": "2026-08-12T05:07:21Z",
          "window_end": "2026-08-12T12:55:08Z",
          "status": "source-content",
          "summary": "A new sweep was recorded: HP-9C4F with low (pass) entropy was swept on 2026-08-12, raising swept to 9, lowering live to 10, and pushing the estimated frontier from about 5 bits to about 11 bits. An older HP-10ED sweep row was removed, one active honeypot changed from LIVE to SWEPT, and the displayed row order shifted.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 13,
          "removed_lines": 13
        },
        {
          "observed_at": "2026-08-12T05:07:21Z",
          "window_start": "2026-08-12T03:08:52Z",
          "window_end": "2026-08-12T05:07:21Z",
          "status": "source-content",
          "summary": "The scoreboard updated from 12 live and 7 swept honeypots to 11 live and 8 swept, recording that honeypot HP-D4A0 was swept after roughly 6 days 7 hours 36 minutes.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 7,
          "removed_lines": 7
        },
        {
          "observed_at": "2026-08-12T03:08:52Z",
          "window_start": "2026-08-08T16:55:43Z",
          "window_end": "2026-08-12T03:08:52Z",
          "status": "source-content",
          "summary": "The scoreboard lowered live honeypots from 14 to 12 and raised swept from 5 to 7, recording two new trivial sweeps (HP-88A9 and HP-D85A) and marking two previously live entries as swept after about 6 days 5 hours 59 minutes.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 12,
          "removed_lines": 12
        },
        {
          "observed_at": "2026-08-08T16:55:43Z",
          "window_start": "2026-08-08T01:23:05Z",
          "window_end": "2026-08-08T16:55:43Z",
          "status": "source-content",
          "summary": "The scoreboard updated its honeypot state: live fell from 16 to 14, swept rose from 3 to 5, two low-dice honeypots (HP-2C6F and HP-10ED) were swept, and HP-696E went from live to swept in 2d14h49m.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 23,
          "removed_lines": 23
        },
        {
          "observed_at": "2026-08-08T01:23:05Z",
          "window_start": "2026-08-08T00:22:46Z",
          "window_end": "2026-08-08T01:23:05Z",
          "status": "source-content",
          "summary": "The honeypot scoreboard changed its status label from PENDING to LIVE.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 1,
          "removed_lines": 1
        },
        {
          "observed_at": "2026-08-08T00:22:46Z",
          "window_start": "2026-08-07T20:21:23Z",
          "window_end": "2026-08-08T00:22:46Z",
          "status": "source-content",
          "summary": "The scoreboard added two newly funded honeypots, HP-E736 and HP-696E, raised the live count from 14 to 16 and the total from 17 to 19, and removed older funding and sweep rows; it also added a pending low-dice entry and a live 2-of-4 Mk4 entry on zombo.com.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 25,
          "removed_lines": 13
        },
        {
          "observed_at": "2026-08-07T20:21:23Z",
          "window_start": "2026-08-06T18:26:29Z",
          "window_end": "2026-08-07T20:21:23Z",
          "status": "source-content",
          "summary": "The scoreboard reported one additional swept honeypot (HP-5F1D) and changed HP-D4A0 from live to swept after about 1 day and 22 hours.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 7,
          "removed_lines": 7
        },
        {
          "observed_at": "2026-08-06T18:26:29Z",
          "window_start": "2026-08-06T14:25:55Z",
          "window_end": "2026-08-06T18:26:29Z",
          "status": "source-content",
          "summary": "The scoreboard header gained an rss link: the site now advertises a feed. No honeypot data changed.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 1,
          "removed_lines": 0
        },
        {
          "observed_at": "2026-08-06T14:25:55Z",
          "window_start": "2026-08-06T02:55:13Z",
          "window_end": "2026-08-06T14:25:55Z",
          "status": "source-content",
          "summary": "The operator revised the estimated GPU crack times sharply downward across every difficulty band (5 added bits from ~2 days to ~66 min, 13 bits from ~476 days to ~10 days) and dropped the tx column from recent activity. The anonymised honeypot handles were also re-randomised, so individual rows cannot be followed across captures; honeypot states (LIVE/SWEPT) are unchanged.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 52,
          "removed_lines": 58
        },
        {
          "observed_at": "2026-08-06T02:55:13Z",
          "window_start": "2026-08-06T01:54:54Z",
          "window_end": "2026-08-06T02:55:13Z",
          "status": "source-content",
          "summary": "HP-8DA1 changed from pending immediately after funding to live, with its age rendered as an elapsed duration.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 2,
          "removed_lines": 2
        },
        {
          "observed_at": "2026-08-06T01:54:54Z",
          "window_start": "2026-08-05T23:54:53Z",
          "window_end": "2026-08-06T01:54:54Z",
          "status": "source-content",
          "summary": "The operator added HP-8DA1, described as a low dice-entropy Mk3 v4 honeypot, initially marked pending. The scoreboard rose to 17 honeypots and 15 live entries.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 19,
          "removed_lines": 12
        },
        {
          "observed_at": "2026-08-05T23:54:53Z",
          "window_start": "2026-08-05T21:53:48Z",
          "window_end": "2026-08-05T23:54:53Z",
          "status": "source-content",
          "summary": "The operator added the live HP-EDAD 3-of-3 multisig honeypot, raising the scoreboard to 16 honeypots and 14 live entries.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 18,
          "removed_lines": 11
        },
        {
          "observed_at": "2026-08-05T21:53:48Z",
          "window_start": "2026-08-05T20:53:18Z",
          "window_end": "2026-08-05T21:53:48Z",
          "status": "source-content",
          "summary": "The scoreboard now shows the external Mk3 honeypots individually, with their source post and live or swept status, and changes its displayed sample from 15 to 10 entries.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 35,
          "removed_lines": 39
        },
        {
          "observed_at": "2026-08-05T20:53:18Z",
          "window_start": "2026-08-05T18:52:25Z",
          "window_end": "2026-08-05T20:53:18Z",
          "status": "source-content",
          "summary": "The scoreboard increased from 10 to 15 honeypots and from one to two sweeps. It reports five new trivial-entropy honeypots, one swept in two minutes, and a higher exposed-value total.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 63,
          "removed_lines": 28
        },
        {
          "observed_at": "2026-08-05T18:52:25Z",
          "window_start": "2026-08-05T15:51:48Z",
          "window_end": "2026-08-05T18:52:25Z",
          "status": "source-content",
          "summary": "The scoreboard updated observed sweep-duration fields for several honeypots, including entries now shown at about 88 minutes, two days and 476 days, and revised one projected cracking estimate.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 5,
          "removed_lines": 22
        },
        {
          "observed_at": "2026-08-05T15:51:48Z",
          "window_start": "2026-08-05T04:17:01Z",
          "window_end": "2026-08-05T15:51:48Z",
          "status": "source-content",
          "summary": "The scoreboard added estimated GPU cracking times for its entropy categories, ranging from seconds to very long projected durations.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 11,
          "removed_lines": 0
        },
        {
          "observed_at": "2026-08-05T04:17:01Z",
          "window_start": "2026-08-05T03:18:37Z",
          "window_end": "2026-08-05T04:17:01Z",
          "status": "source-content",
          "summary": "The scoreboard added two live Mk3 v4 honeypots, HP-C6F6 (2-of-3 multisig) and HP-F755 (extreme dice), raising its totals from eight to ten honeypots and from seven to nine live ones. Its stated exposed value rose from about 0.003 BTC to about 0.006 BTC.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 33,
          "removed_lines": 19
        },
        {
          "observed_at": "2026-08-05T03:18:37Z",
          "window_start": "2026-08-05T02:24:25Z",
          "window_end": "2026-08-05T03:18:37Z",
          "status": "source-content",
          "summary": "The operator rewrote the warning to cover wallets created without additional entropy, replaced the immediate-move wording with 'move your funds to a safe place', and expanded the timing caveat about still-live honeypots. The page also added an attribution to @jamesob.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 13,
          "removed_lines": 10
        }
      ]
    },
    {
      "id": "cktripwire-methodology",
      "title": "CKTRIPWIRE methodology",
      "url": "https://cktripwire.com/methodology",
      "organisation": "CKTRIPWIRE",
      "kind": "research",
      "role": "Primary technical research",
      "publication_time": null,
      "note": "The method behind cktripwire-honeypot-monitor, linked from the scoreboard and\nregistered separately so the experiment's stated design is held as a document\nrather than inferred from its results. It describes how the operator reproduces\nthe RNG defect in software (ngu.random.bytes() resolving to the XOR of two\nYasmarang PRNGs with no hardware entropy), how that reproduction was checked\nagainst real hardware, and how the experiment is designed: difficulty bands set\nby the entropy added on top of the attacker-known seed, a zero-entropy mainnet\ncontrol, and deliberately coarse public reporting with no addresses, exact\namounts or keys. It states that the operator retains the keys to every honeypot.\nThe page directs readers to @jamesob for background and updates.\n\nKept at tier 3 rather than the chain-monitor lane: this is static prose,\nunlike the scoreboard's live state. The reproduction, the hardware\nvalidation and the entropy estimates are the operator's own and have not been\nindependently reproduced by this archive.\n",
      "gone": null,
      "capture": {
        "status": "held",
        "copies": 1,
        "first_observed": "2026-08-05T03:02:32Z",
        "last_observed": "2026-08-05T03:02:32Z",
        "last_checked": "2026-08-15T12:56:38Z"
      },
      "differences": []
    },
    {
      "id": "blockchainunmasked-prior-warning",
      "title": "Coldcard Seed Flaw ($38M)",
      "url": "https://www.blockchainunmasked.com/post/coldcard-seed-flaw-38m",
      "organisation": "Blockchain Unmasked",
      "kind": "independent-analysis",
      "role": "Independent primary analysis",
      "publication_time": "2026-07-31",
      "note": "Blockchain Unmasked's first-hand account of investigating earlier victim reports and warning Coinkite and public agencies before the July 2026 sweep. It describes its own 2024 investigation, correspondence and hypothesis development. Those historical claims are reported testimony from the organisation and are not independently verified here.\n",
      "gone": null,
      "capture": {
        "status": "held",
        "copies": 8,
        "first_observed": "2026-08-05T02:24:27Z",
        "last_observed": "2026-08-12T04:39:38Z",
        "last_checked": "2026-08-15T12:26:46Z"
      },
      "differences": [
        {
          "observed_at": "2026-08-12T04:39:38Z",
          "window_start": "2026-08-09T10:37:31Z",
          "window_end": "2026-08-12T04:39:38Z",
          "status": "source-content",
          "summary": "The page replaced one related-post headline with another at the bottom of the article.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 1,
          "removed_lines": 1
        },
        {
          "observed_at": "2026-08-09T10:37:31Z",
          "window_start": "2026-08-08T15:05:59Z",
          "window_end": "2026-08-09T10:37:31Z",
          "status": "source-content",
          "summary": "The page changed the headline of a related article from a specific repository count to a generic public-git-history framing.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 1,
          "removed_lines": 1
        },
        {
          "observed_at": "2026-08-08T15:05:59Z",
          "window_start": "2026-08-08T08:35:08Z",
          "window_end": "2026-08-08T15:05:59Z",
          "status": "capture-noise",
          "summary": "Only the relative-age label changed from '3 days ago' to 'Jul 31' and adjacent article links appeared; the first-hand account text was unchanged.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 2,
          "removed_lines": 2
        },
        {
          "observed_at": "2026-08-08T08:35:08Z",
          "window_start": "2026-08-07T19:32:09Z",
          "window_end": "2026-08-08T08:35:08Z",
          "status": "capture-noise",
          "summary": "Only a relative date marker rolled from 'Jul 31' to '3 days ago'.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 1,
          "removed_lines": 1
        },
        {
          "observed_at": "2026-08-07T19:32:09Z",
          "window_start": "2026-08-07T12:58:50Z",
          "window_end": "2026-08-07T19:32:09Z",
          "status": "capture-noise",
          "summary": "Only the page's relative publish date changed from 3 days ago to Jul 31.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 1,
          "removed_lines": 1
        },
        {
          "observed_at": "2026-08-07T12:58:50Z",
          "window_start": "2026-08-07T06:19:37Z",
          "window_end": "2026-08-07T12:58:50Z",
          "status": "capture-noise",
          "summary": "Live relative-date counter flapping: the age label changed back from \"5 days ago\" to \"3 days ago\"; the article text itself is unchanged.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 1,
          "removed_lines": 1
        },
        {
          "observed_at": "2026-08-07T06:19:37Z",
          "window_start": "2026-08-05T02:24:27Z",
          "window_end": "2026-08-07T06:19:37Z",
          "status": "capture-noise",
          "summary": "Live relative-date counter: the article's age label changed from \"3 days ago\" to \"5 days ago\"; the article text itself is unchanged.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 1,
          "removed_lines": 1
        }
      ]
    },
    {
      "id": "therage-coldcard-hack-guide",
      "title": "Everything You Need to Know About the COLDCARD Hack",
      "url": "https://www.therage.co/everything-you-need-to-know-about-the-coldcard-hack/",
      "organisation": "The Rage",
      "kind": "reporting",
      "role": "Reporting",
      "publication_time": "2026-08-03",
      "note": "Long-form incident explainer tracing the disclosure from an earlier Reddit report through the mass sweeps, with guidance for potentially affected owners. Secondary reporting that is useful for its narrative synthesis; technical, historical and loss claims remain attributable to the article and the primary sources it cites.\n",
      "gone": null,
      "capture": {
        "status": "held",
        "copies": 2,
        "first_observed": "2026-08-05T02:24:28Z",
        "last_observed": "2026-08-07T00:33:21Z",
        "last_checked": "2026-08-15T12:56:40Z"
      },
      "differences": [
        {
          "observed_at": "2026-08-07T00:33:21Z",
          "window_start": "2026-08-05T02:24:28Z",
          "window_end": "2026-08-07T00:33:21Z",
          "status": "capture-noise",
          "summary": "Rotating sidebar chrome: the \"Latest posts\" list on the article page gained a new Rage post (\"Is Debanking The New Immigration Policy?\") and dropped an older one; the COLDCARD article itself is unchanged.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 5,
          "removed_lines": 6
        }
      ]
    },
    {
      "id": "newsbitcom-class-action-threat",
      "title": "Coinkite faces class action threat as bitcoin wallet bug costs users over 1,300 BTC",
      "url": "https://news.bitcoin.com/regulation-and-legal/coinkite-faces-class-action-threat-as-bitcoin-wallet-bug-costs-users-over-1300-btc/",
      "organisation": "Bitcoin.com News",
      "kind": "reporting",
      "role": "Reporting",
      "publication_time": "2026-08-02",
      "note": "The one held source that collects named legal opinion on Coinkite's exposure\nfrom both directions: Cris Carrascosa (ATH21) saying the company has no\nregulatory responsibility for user funds and that foreseeability would be hard\nto prove, Ana Ojeda (Blend) saying there is a credible basis to investigate\nresponsibility while no victim has an automatic right to recovery, alongside\nThomas Braziel's stated intent and a Brazilian claimant's police report. Held\nfor the legal-context page, which registers what parties say about liability\nand does not choose between them. Every opinion in it is the speaker's, is\nabout a claim nobody had filed at the check date, and none of it is advice to\na reader here.\n",
      "gone": null,
      "capture": {
        "status": "held",
        "copies": 30,
        "first_observed": "2026-08-05T03:09:05Z",
        "last_observed": "2026-08-15T12:56:42Z",
        "last_checked": "2026-08-15T12:56:42Z"
      },
      "differences": [
        {
          "observed_at": "2026-08-15T12:56:42Z",
          "window_start": "2026-08-15T06:27:59Z",
          "window_end": "2026-08-15T12:56:42Z",
          "status": "capture-noise",
          "summary": "Only rotating LATEST NEWS, MOST POPULAR and Related articles modules and their relative timestamps changed; the article text was unchanged.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 35,
          "removed_lines": 35
        },
        {
          "observed_at": "2026-08-15T06:27:59Z",
          "window_start": "2026-08-14T23:51:45Z",
          "window_end": "2026-08-15T06:27:59Z",
          "status": "capture-noise",
          "summary": "Only rotating latest-news and most-popular rails and their relative-time labels changed; the article text was unchanged.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 31,
          "removed_lines": 31
        },
        {
          "observed_at": "2026-08-14T23:51:45Z",
          "window_start": "2026-08-14T10:00:42Z",
          "window_end": "2026-08-14T23:51:45Z",
          "status": "capture-noise",
          "summary": "Only rotating 'LATEST NEWS', 'MOST POPULAR' and related-article modules and their relative timestamps changed; the legal-context article text was unchanged.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 30,
          "removed_lines": 30
        },
        {
          "observed_at": "2026-08-14T10:00:42Z",
          "window_start": "2026-08-14T03:28:06Z",
          "window_end": "2026-08-14T10:00:42Z",
          "status": "capture-noise",
          "summary": "Only rotating 'LATEST NEWS', 'MOST POPULAR' and 'Related articles' modules and one relative-time label changed; the article body was unchanged.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 26,
          "removed_lines": 26
        },
        {
          "observed_at": "2026-08-14T03:28:06Z",
          "window_start": "2026-08-13T20:59:34Z",
          "window_end": "2026-08-14T03:28:06Z",
          "status": "capture-noise",
          "summary": "Only the rotating news feed items and their relative timestamps changed; the article text was unchanged.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 22,
          "removed_lines": 22
        },
        {
          "observed_at": "2026-08-13T20:59:34Z",
          "window_start": "2026-08-13T14:30:33Z",
          "window_end": "2026-08-13T20:59:34Z",
          "status": "capture-noise",
          "summary": "Only the rotating news feed items and their relative timestamps changed; the article text was unchanged.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 23,
          "removed_lines": 23
        },
        {
          "observed_at": "2026-08-13T14:30:33Z",
          "window_start": "2026-08-13T07:57:59Z",
          "window_end": "2026-08-13T14:30:33Z",
          "status": "capture-noise",
          "summary": "Only rotating related-news headlines and their relative timestamps changed; the article body was unchanged.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 24,
          "removed_lines": 24
        },
        {
          "observed_at": "2026-08-13T07:57:59Z",
          "window_start": "2026-08-13T01:27:59Z",
          "window_end": "2026-08-13T07:57:59Z",
          "status": "capture-noise",
          "summary": "Only the rotating latest-news and most-popular modules and their relative-time labels changed; the article text was unchanged.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 27,
          "removed_lines": 27
        },
        {
          "observed_at": "2026-08-13T01:27:59Z",
          "window_start": "2026-08-12T18:28:13Z",
          "window_end": "2026-08-13T01:27:59Z",
          "status": "capture-noise",
          "summary": "Only the rotating latest-news and most-popular side modules and their relative-time labels changed; the legal-context article text was unchanged.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 22,
          "removed_lines": 22
        },
        {
          "observed_at": "2026-08-12T18:28:13Z",
          "window_start": "2026-08-12T11:58:12Z",
          "window_end": "2026-08-12T18:28:13Z",
          "status": "capture-noise",
          "summary": "Only the rotating MOST POPULAR module and related-story ages below the article changed; the article text was unchanged.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 25,
          "removed_lines": 25
        },
        {
          "observed_at": "2026-08-12T11:58:12Z",
          "window_start": "2026-08-12T05:11:46Z",
          "window_end": "2026-08-12T11:58:12Z",
          "status": "capture-noise",
          "summary": "Only the rotating LATEST NEWS sidebar and its relative timestamps changed; the article text was unchanged.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 27,
          "removed_lines": 27
        },
        {
          "observed_at": "2026-08-12T05:11:46Z",
          "window_start": "2026-08-09T18:48:27Z",
          "window_end": "2026-08-12T05:11:46Z",
          "status": "capture-noise",
          "summary": "Only rotating related-story headlines and their timestamps changed; the article text was unchanged.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 28,
          "removed_lines": 28
        },
        {
          "observed_at": "2026-08-09T18:48:27Z",
          "window_start": "2026-08-09T12:02:53Z",
          "window_end": "2026-08-09T18:48:27Z",
          "status": "capture-noise",
          "summary": "Only rotating LATEST NEWS and MOST POPULAR sidebar headlines and their timestamps changed; the article body was unchanged.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 24,
          "removed_lines": 24
        },
        {
          "observed_at": "2026-08-09T12:02:53Z",
          "window_start": "2026-08-09T05:31:04Z",
          "window_end": "2026-08-09T12:02:53Z",
          "status": "capture-noise",
          "summary": "Only the rotating latest-news headlines and their relative timestamps changed; the article text was unchanged.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 24,
          "removed_lines": 24
        },
        {
          "observed_at": "2026-08-09T05:31:04Z",
          "window_start": "2026-08-08T23:00:43Z",
          "window_end": "2026-08-09T05:31:04Z",
          "status": "capture-noise",
          "summary": "Only the surrounding latest-news, most-popular, and related-articles rails and their timestamps changed; the article text was unchanged.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 25,
          "removed_lines": 25
        },
        {
          "observed_at": "2026-08-08T23:00:43Z",
          "window_start": "2026-08-08T16:28:16Z",
          "window_end": "2026-08-08T23:00:43Z",
          "status": "capture-noise",
          "summary": "Only rotating latest-news and most-popular modules and their relative-time labels changed.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 33,
          "removed_lines": 33
        },
        {
          "observed_at": "2026-08-08T16:28:16Z",
          "window_start": "2026-08-08T09:57:51Z",
          "window_end": "2026-08-08T16:28:16Z",
          "status": "capture-noise",
          "summary": "Only the duplicated LATEST NEWS sidebar and Most Popular rails, together with their relative timestamps, changed; the class-action article text was unchanged.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 28,
          "removed_lines": 28
        },
        {
          "observed_at": "2026-08-08T09:57:51Z",
          "window_start": "2026-08-08T03:27:22Z",
          "window_end": "2026-08-08T09:57:51Z",
          "status": "capture-noise",
          "summary": "Only the rotating LATEST NEWS sidebar headlines and their relative timestamps changed; the article text was unchanged.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 21,
          "removed_lines": 21
        },
        {
          "observed_at": "2026-08-08T03:27:22Z",
          "window_start": "2026-08-07T20:53:59Z",
          "window_end": "2026-08-08T03:27:22Z",
          "status": "capture-noise",
          "summary": "Only the latest-news rails and their relative timestamps changed. The article body carrying the claimant-organising quotes is unchanged.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 21,
          "removed_lines": 21
        },
        {
          "observed_at": "2026-08-07T20:53:59Z",
          "window_start": "2026-08-07T14:25:24Z",
          "window_end": "2026-08-07T20:53:59Z",
          "status": "capture-noise",
          "summary": "Only the site's latest-news and most-popular rails and their relative timestamps changed. The article body carrying the claimant-organising quotes is unchanged.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 24,
          "removed_lines": 24
        },
        {
          "observed_at": "2026-08-07T14:25:24Z",
          "window_start": "2026-08-07T08:13:38Z",
          "window_end": "2026-08-07T14:25:24Z",
          "status": "capture-noise",
          "summary": "Sidebar churn only: the Latest News, Most Popular and Latest Podcasts modules rotated to newer items and relative timestamps rolled over. The class-action article itself is unchanged.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 30,
          "removed_lines": 30
        },
        {
          "observed_at": "2026-08-07T08:13:38Z",
          "window_start": "2026-08-07T00:33:23Z",
          "window_end": "2026-08-07T08:13:38Z",
          "status": "capture-noise",
          "summary": "LATEST NEWS sidebar rotated (new lead headline is incident-related: \"Coldcard Hacker Resumes Moving Stolen 30 BTC to New Wallet\") and timestamps ticked over; the article body itself is unchanged.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 20,
          "removed_lines": 20
        },
        {
          "observed_at": "2026-08-07T00:33:23Z",
          "window_start": "2026-08-06T16:44:34Z",
          "window_end": "2026-08-07T00:33:23Z",
          "status": "capture-noise",
          "summary": "LATEST NEWS and MOST POPULAR sidebar headlines rotated and relative timestamps ticked over; the article itself is unchanged.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 20,
          "removed_lines": 20
        },
        {
          "observed_at": "2026-08-06T16:44:34Z",
          "window_start": "2026-08-06T10:16:10Z",
          "window_end": "2026-08-06T16:44:34Z",
          "status": "capture-noise",
          "summary": "LATEST NEWS and MOST POPULAR sidebar headlines rotated and relative timestamps ticked over; the article itself is unchanged.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 29,
          "removed_lines": 29
        },
        {
          "observed_at": "2026-08-06T10:16:10Z",
          "window_start": "2026-08-06T03:43:01Z",
          "window_end": "2026-08-06T10:16:10Z",
          "status": "capture-noise",
          "summary": "LATEST NEWS and MOST POPULAR sidebar modules rotated headlines and relative timestamps ticked over; the article itself is unchanged.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 29,
          "removed_lines": 29
        },
        {
          "observed_at": "2026-08-06T03:43:01Z",
          "window_start": "2026-08-05T21:13:14Z",
          "window_end": "2026-08-06T03:43:01Z",
          "status": "capture-noise",
          "summary": "Only rotating most-popular and latest-news rails, together with their relative-time labels, changed; the legal-context article text was unchanged.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 28,
          "removed_lines": 28
        },
        {
          "observed_at": "2026-08-05T21:13:14Z",
          "window_start": "2026-08-05T14:37:59Z",
          "window_end": "2026-08-05T21:13:14Z",
          "status": "capture-noise",
          "summary": "The page refreshed its latest-news and popular-story widgets, including relative timestamps. The legal reporting did not change.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 34,
          "removed_lines": 34
        },
        {
          "observed_at": "2026-08-05T14:37:59Z",
          "window_start": "2026-08-05T08:08:29Z",
          "window_end": "2026-08-05T14:37:59Z",
          "status": "capture-noise",
          "summary": "Only the page's duplicated Latest News feed and relative publication times changed. The class-action article and its attributed legal opinions did not change.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 30,
          "removed_lines": 30
        },
        {
          "observed_at": "2026-08-05T08:08:29Z",
          "window_start": "2026-08-05T03:09:05Z",
          "window_end": "2026-08-05T08:08:29Z",
          "status": "capture-noise",
          "summary": "Only rotating Latest News and Most Popular cards, their timestamps and related links changed. The legal-context article text did not change.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 32,
          "removed_lines": 32
        }
      ]
    },
    {
      "id": "reddit-coldcard-misinformation-warning",
      "title": "r/Bitcoin: warning about misinformation around COLDCARD",
      "url": "https://www.reddit.com/r/Bitcoin/comments/1vf5ohi/a_warning_about_misinformation_about_coldcard/",
      "organisation": "reddit",
      "kind": "community-discussion",
      "role": "Community discussion",
      "publication_time": null,
      "note": null,
      "gone": null,
      "capture": {
        "status": "held",
        "copies": 4,
        "first_observed": "2026-08-05T21:04:26Z",
        "last_observed": "2026-08-08T15:06:01Z",
        "last_checked": "2026-08-11T21:13:36Z"
      },
      "differences": [
        {
          "observed_at": "2026-08-08T15:06:01Z",
          "window_start": "2026-08-07T12:58:54Z",
          "window_end": "2026-08-08T15:06:01Z",
          "status": "source-content",
          "summary": "A comment accusing dice-roll users of laziness was deleted and now shows [deleted].",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 2,
          "removed_lines": 2
        },
        {
          "observed_at": "2026-08-07T12:58:54Z",
          "window_start": "2026-08-06T16:36:24Z",
          "window_end": "2026-08-07T12:58:54Z",
          "status": "source-content",
          "summary": "New reply by ukieninger telling the previous commenter they are completely missing the point.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 8,
          "removed_lines": 0
        },
        {
          "observed_at": "2026-08-06T16:36:24Z",
          "window_start": "2026-08-05T21:04:26Z",
          "window_end": "2026-08-06T16:36:24Z",
          "status": "source-content",
          "summary": "New comment by evgeniy_pp mocking users who chose 24 words and dice but stopped rolling halfway.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 8,
          "removed_lines": 0
        }
      ]
    },
    {
      "id": "delving-self-custody-best-practices",
      "title": "Towards New Self-Custody Best Practices",
      "url": "https://delvingbitcoin.org/t/towards-new-self-custody-best-practices/2768",
      "organisation": "Delving Bitcoin",
      "kind": "community-discussion",
      "role": "Community discussion",
      "publication_time": "2026-08-04",
      "note": "seed-cat drafting self-custody best practices in direct response to the incident, arguing the technical community failed to standardise practices that balance complexity and security: 2-of-2 multisig, multi-vendor signing extended to shared cryptographic code, and user-generated verifiable entropy. The first Delving Bitcoin thread found engaging with the incident (registered 5 August 2026); the prescriptions are the author's own, not endorsed or verified here. Captured through the topic's RSS feed, which carries each post's full markdown, author and fixed timestamp without the rendered page's live counters.\n",
      "gone": null,
      "capture": {
        "status": "held",
        "copies": 2,
        "first_observed": "2026-08-06T00:02:38Z",
        "last_observed": "2026-08-07T19:32:16Z",
        "last_checked": "2026-08-12T23:56:15Z"
      },
      "differences": [
        {
          "observed_at": "2026-08-07T19:32:16Z",
          "window_start": "2026-08-06T00:02:38Z",
          "window_end": "2026-08-07T19:32:16Z",
          "status": "source-content",
          "summary": "The RSS feed gained replies from seed-cat and optout covering multisig choices, user-provided entropy, manual seed generation and checksum correction.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 32,
          "removed_lines": 1
        }
      ]
    },
    {
      "id": "reddit-incident-conclusions",
      "title": "r/Bitcoin: conclusions drawn from the COLDCARD incident",
      "url": "https://www.reddit.com/r/Bitcoin/comments/1vf3u3z/cc_incident_conclusions/",
      "organisation": "reddit",
      "kind": "community-discussion",
      "role": "Community discussion",
      "publication_time": null,
      "note": null,
      "gone": null,
      "capture": {
        "status": "held",
        "copies": 1,
        "first_observed": "2026-08-06T05:08:14Z",
        "last_observed": "2026-08-06T05:08:14Z",
        "last_checked": "2026-08-12T23:56:18Z"
      },
      "differences": []
    },
    {
      "id": "bitcointalk-entropy-warning-design",
      "title": "Should wallets warn users about low-quality entropy during SEED generation?",
      "url": "https://bitcointalk.org/index.php?topic=5590329.0",
      "organisation": "BitcoinTalk",
      "kind": "community-discussion",
      "role": "Community discussion",
      "publication_time": "2026-08-04",
      "note": "satscraper opening a discussion of whether wallet software should warn users about low-quality entropy while generating a seed. A distinct prospective design question raised in the COLDCARD incident's aftermath, rather than another owner exposure self-assessment. The proposed warnings and technical claims in the thread are the posters' own, not verified here.\n",
      "gone": null,
      "capture": {
        "status": "held",
        "copies": 5,
        "first_observed": "2026-08-06T05:08:18Z",
        "last_observed": "2026-08-12T04:39:51Z",
        "last_checked": "2026-08-12T23:56:22Z"
      },
      "differences": [
        {
          "observed_at": "2026-08-12T04:39:51Z",
          "window_start": "2026-08-09T23:25:46Z",
          "window_end": "2026-08-12T04:39:51Z",
          "status": "capture-noise",
          "summary": "Only a quoted post's relative date rolled from 'Today' to the absolute date 'August 09, 2026'; no new discussion text appeared.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 1,
          "removed_lines": 1
        },
        {
          "observed_at": "2026-08-09T23:25:46Z",
          "window_start": "2026-08-09T10:37:43Z",
          "window_end": "2026-08-09T23:25:46Z",
          "status": "source-content",
          "summary": "The thread gained a reply arguing that a properly implemented TRNG or CSPRNG should signal failure internally rather than relying on user-facing entropy-quality warnings.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 13,
          "removed_lines": 0
        },
        {
          "observed_at": "2026-08-09T10:37:43Z",
          "window_start": "2026-08-09T04:07:59Z",
          "window_end": "2026-08-09T10:37:43Z",
          "status": "source-content",
          "summary": "The thread gained posts noting WalletScrutiny added Coldcard Mk4 warnings only after the hack, benchmarking NIST entropy-assessment runtimes, and debating developer responsibility for entropy warnings.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 34,
          "removed_lines": 0
        },
        {
          "observed_at": "2026-08-09T04:07:59Z",
          "window_start": "2026-08-06T05:08:18Z",
          "window_end": "2026-08-09T04:07:59Z",
          "status": "source-content",
          "summary": "The thread gained posts benchmarking NIST entropy-assessment runtimes and arguing that wallet developers who ignore weak entropy are unlikely to add warnings.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 24,
          "removed_lines": 0
        }
      ]
    },
    {
      "id": "stackernews-coinkite-investigation-record",
      "title": "Adding to the Public Record on Our Ongoing Investigation - Coldcard",
      "url": "https://stacker.news/items/1540370",
      "organisation": "Stacker News",
      "kind": "community-discussion",
      "role": "Community discussion",
      "publication_time": "2026-08-04",
      "note": "Scoresby linking Coinkite's official 4 August investigation statement, separately held as coldcardwallet-2084731768632991801. The link post's eight-comment discussion records community reception of that statement; the vendor's claims remain attributed to Coinkite and are not independently verified here. Captured through the site's public GraphQL API: the rendered pages crash the capture tab, and the API answers POST from this host. The query fixes the captured surface to the item's title, text and two levels of comments, each with author and absolute timestamp.\n",
      "gone": null,
      "capture": {
        "status": "held",
        "copies": 1,
        "first_observed": "2026-08-06T05:08:19Z",
        "last_observed": "2026-08-06T05:08:19Z",
        "last_checked": "2026-08-08T23:00:45Z"
      },
      "differences": []
    },
    {
      "id": "reddit-cto-code-link",
      "title": "r/Bitcoin: discussion linking Peter Gray to code behind the reported COLDCARD exploit",
      "url": "https://www.reddit.com/r/Bitcoin/comments/1vfpadi/coinkite_cto_peter_gray_linked_to_the_code_behind/",
      "organisation": "reddit",
      "kind": "community-discussion",
      "role": "Community discussion",
      "publication_time": null,
      "note": null,
      "gone": null,
      "capture": {
        "status": "held",
        "copies": 6,
        "first_observed": "2026-08-06T05:08:21Z",
        "last_observed": "2026-08-08T02:02:50Z",
        "last_checked": "2026-08-12T23:56:25Z"
      },
      "differences": [
        {
          "observed_at": "2026-08-08T02:02:50Z",
          "window_start": "2026-08-07T19:32:26Z",
          "window_end": "2026-08-08T02:02:50Z",
          "status": "source-content",
          "summary": "The Reddit thread gained a new participant comment about the reported code attribution.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 10,
          "removed_lines": 0
        },
        {
          "observed_at": "2026-08-07T19:32:26Z",
          "window_start": "2026-08-07T06:19:54Z",
          "window_end": "2026-08-07T19:32:26Z",
          "status": "source-content",
          "summary": "An abusive comment directed at Peter Gray was removed.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 0,
          "removed_lines": 8
        },
        {
          "observed_at": "2026-08-07T06:19:54Z",
          "window_start": "2026-08-06T16:36:36Z",
          "window_end": "2026-08-07T06:19:54Z",
          "status": "source-content",
          "summary": "A comment by 12ealdeal predicting the fallout would get much worse was deleted, and two new comments appeared: a joke exchange about stanley_fatmax's username.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 20,
          "removed_lines": 4
        },
        {
          "observed_at": "2026-08-06T16:36:36Z",
          "window_start": "2026-08-06T10:08:01Z",
          "window_end": "2026-08-06T16:36:36Z",
          "status": "source-content",
          "summary": "A comment by neurone214 questioning the cryptographic-proof claim was self-deleted ([deleted]), and a new comment by scrandlle argues stolen BTC is hard to cash out because real exchanges blacklist wallets.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 16,
          "removed_lines": 5
        },
        {
          "observed_at": "2026-08-06T10:08:01Z",
          "window_start": "2026-08-06T05:08:21Z",
          "window_end": "2026-08-06T10:08:01Z",
          "status": "source-content",
          "summary": "New comment by immersive-matthew debating Canadian politics (Carney, fossil fuel investment), an off-topic aside in the thread.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 8,
          "removed_lines": 0
        }
      ]
    },
    {
      "id": "reddit-hardware-wallet-entropy-audit-call",
      "title": "r/Bitcoin: call for third-party audits of hardware-wallet entropy generation",
      "url": "https://www.reddit.com/r/Bitcoin/comments/1vfwlgj/all_hardware_wallet_manufacturers_need_to_release/",
      "organisation": "reddit",
      "kind": "community-discussion",
      "role": "Community discussion",
      "publication_time": null,
      "note": null,
      "gone": null,
      "capture": {
        "status": "held",
        "copies": 2,
        "first_observed": "2026-08-06T05:08:25Z",
        "last_observed": "2026-08-06T10:08:07Z",
        "last_checked": "2026-08-12T23:56:31Z"
      },
      "differences": [
        {
          "observed_at": "2026-08-06T10:08:07Z",
          "window_start": "2026-08-06T05:08:25Z",
          "window_end": "2026-08-06T10:08:07Z",
          "status": "source-content",
          "summary": "One new comment noting entropy audits would be needed with every firmware release, which vendors will not do.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 8,
          "removed_lines": 0
        }
      ]
    },
    {
      "id": "stackernews-nvk-deleted-posts",
      "title": "nvk deleting tweets as we speak. Backup and screenshoot interactions with him!",
      "url": "https://stacker.news/items/1540885",
      "organisation": "Stacker News",
      "kind": "community-discussion",
      "role": "Community discussion",
      "publication_time": "2026-08-05",
      "note": "raw_avocado asking readers to preserve NVK's public interactions amid a reported deletion of posts, with an eight-comment discussion. A record of the community's preservation response during the incident, not confirmation that any particular post was deleted or of what it said. Captured through the site's public GraphQL API: the rendered pages crash the capture tab, and the API answers POST from this host. The query fixes the captured surface to the item's title, text and two levels of comments, each with author and absolute timestamp.\n",
      "gone": null,
      "capture": {
        "status": "held",
        "copies": 2,
        "first_observed": "2026-08-06T05:08:29Z",
        "last_observed": "2026-08-06T23:56:09Z",
        "last_checked": "2026-08-12T23:56:36Z"
      },
      "differences": [
        {
          "observed_at": "2026-08-06T23:56:09Z",
          "window_start": "2026-08-06T05:08:29Z",
          "window_end": "2026-08-06T23:56:09Z",
          "status": "source-content",
          "summary": "New comment by rblb speculates that bulk-deleting tweets is what a smart bad-faith actor would do to quietly remove a few specific ones, calling it the worst possible look.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 7,
          "removed_lines": 0
        }
      ]
    },
    {
      "id": "reddit-soft-brick-5-6-0",
      "title": "r/coldcard: update for users affected by the 5.6.0 soft brick",
      "url": "https://www.reddit.com/r/coldcard/comments/1vg6um3/update_for_everyone_affected_from_the_soft_brick/",
      "organisation": "reddit",
      "kind": "community-discussion",
      "role": "Community discussion",
      "publication_time": null,
      "note": null,
      "gone": null,
      "capture": {
        "status": "held",
        "copies": 2,
        "first_observed": "2026-08-06T05:08:31Z",
        "last_observed": "2026-08-07T06:20:05Z",
        "last_checked": "2026-08-12T23:56:38Z"
      },
      "differences": [
        {
          "observed_at": "2026-08-07T06:20:05Z",
          "window_start": "2026-08-06T05:08:31Z",
          "window_end": "2026-08-07T06:20:05Z",
          "status": "source-content",
          "summary": "New comment from WBDubya advising taking a sledgehammer to anything from Coldcard.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 8,
          "removed_lines": 0
        }
      ]
    },
    {
      "id": "reddit-entropy-warning-october-2023",
      "title": "r/coldcard: claimed COLDCARD entropy warning from October 2023",
      "url": "https://www.reddit.com/r/coldcard/comments/1vg95g7/coldcard_entropy_warning_in_october_2023/",
      "organisation": "reddit",
      "kind": "community-discussion",
      "role": "Community discussion",
      "publication_time": null,
      "note": null,
      "gone": null,
      "capture": {
        "status": "held",
        "copies": 2,
        "first_observed": "2026-08-06T05:08:34Z",
        "last_observed": "2026-08-07T06:20:09Z",
        "last_checked": "2026-08-12T23:56:43Z"
      },
      "differences": [
        {
          "observed_at": "2026-08-07T06:20:09Z",
          "window_start": "2026-08-06T05:08:34Z",
          "window_end": "2026-08-07T06:20:09Z",
          "status": "source-content",
          "summary": "The post body, which linked a 2023 CryptoGuide video about an insecure COLDCARD Mk4 dice-seed warning, was removed and now reads [removed].",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 1,
          "removed_lines": 17
        }
      ]
    },
    {
      "id": "reddit-64-btc-mixing-discussion",
      "title": "r/Bitcoin: discussion of a reported 64 BTC mixing move",
      "url": "https://www.reddit.com/r/Bitcoin/comments/1vg1rlc/coldcard_thief_starts_mixing_64_btc/",
      "organisation": "reddit",
      "kind": "community-discussion",
      "role": "Community discussion",
      "publication_time": null,
      "note": null,
      "gone": null,
      "capture": {
        "status": "held",
        "copies": 13,
        "first_observed": "2026-08-06T05:08:38Z",
        "last_observed": "2026-08-12T23:56:47Z",
        "last_checked": "2026-08-12T23:56:47Z"
      },
      "differences": [
        {
          "observed_at": "2026-08-12T23:56:47Z",
          "window_start": "2026-08-12T10:58:10Z",
          "window_end": "2026-08-12T23:56:47Z",
          "status": "source-content",
          "summary": "Two comments by Rabid_Mexican were removed: the author changed to [deleted] and the bodies changed to [removed], one of which had been edited after posting.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 4,
          "removed_lines": 6
        },
        {
          "observed_at": "2026-08-12T10:58:10Z",
          "window_start": "2026-08-12T04:40:16Z",
          "window_end": "2026-08-12T10:58:10Z",
          "status": "source-content",
          "summary": "The comment author changed from jkc7 to [deleted] and the comment body was replaced with [deleted].",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 2,
          "removed_lines": 4
        },
        {
          "observed_at": "2026-08-12T04:40:16Z",
          "window_start": "2026-08-09T04:08:18Z",
          "window_end": "2026-08-12T04:40:16Z",
          "status": "source-content",
          "summary": "The thread gained a comment asking whether blockchain tracing by agencies can follow mixed funds, or whether a one-to-two-year mix followed by slow cash-out is straightforward.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 8,
          "removed_lines": 0
        },
        {
          "observed_at": "2026-08-09T04:08:18Z",
          "window_start": "2026-08-08T21:36:22Z",
          "window_end": "2026-08-09T04:08:18Z",
          "status": "source-content",
          "summary": "A new one-word comment labeled the reported 64 BTC move as laundering.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 8,
          "removed_lines": 0
        },
        {
          "observed_at": "2026-08-08T21:36:22Z",
          "window_start": "2026-08-08T08:35:39Z",
          "window_end": "2026-08-08T21:36:22Z",
          "status": "source-content",
          "summary": "A commenter account was deleted, one comment was replaced with [removed], and two comments about cashing out and wealth transfer were removed.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 2,
          "removed_lines": 20
        },
        {
          "observed_at": "2026-08-08T08:35:39Z",
          "window_start": "2026-08-08T02:03:12Z",
          "window_end": "2026-08-08T08:35:39Z",
          "status": "source-content",
          "summary": "Several participant comments were deleted and replaced with [deleted] markers, and a new comment about the thief's grail was added.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 12,
          "removed_lines": 12
        },
        {
          "observed_at": "2026-08-08T02:03:12Z",
          "window_start": "2026-08-07T19:32:52Z",
          "window_end": "2026-08-08T02:03:12Z",
          "status": "source-content",
          "summary": "The Reddit thread gained two new participant comments, one about non-custodial transactions and one brief topical reply.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 16,
          "removed_lines": 0
        },
        {
          "observed_at": "2026-08-07T19:32:52Z",
          "window_start": "2026-08-07T12:59:22Z",
          "window_end": "2026-08-07T19:32:52Z",
          "status": "source-content",
          "summary": "The thread gained comments on the reported $3.8 million figure, the privacy of banks versus Bitcoin, and the relative use of dollars in crime.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 40,
          "removed_lines": 0
        },
        {
          "observed_at": "2026-08-07T12:59:22Z",
          "window_start": "2026-08-07T06:20:14Z",
          "window_end": "2026-08-07T12:59:22Z",
          "status": "source-content",
          "summary": "One new comment by PsyOmega about animals sweating, an off-topic reply in the thread.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 10,
          "removed_lines": 0
        },
        {
          "observed_at": "2026-08-07T06:20:14Z",
          "window_start": "2026-08-06T16:36:54Z",
          "window_end": "2026-08-07T06:20:14Z",
          "status": "source-content",
          "summary": "Nine new comments (including one suggesting the attacker held keys for a long time and moved funds before the fork) and the earlier Taco Bell insult comment by Money-Addition8501 disappeared.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 72,
          "removed_lines": 10
        },
        {
          "observed_at": "2026-08-06T16:36:54Z",
          "window_start": "2026-08-06T10:08:24Z",
          "window_end": "2026-08-06T16:36:54Z",
          "status": "source-content",
          "summary": "Twelve new comments (mixer mechanics explained with a vbucks analogy, speculation about how North Korea could spend the coins) and one earlier comment by BackgroundStory7986 was removed by moderators.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 113,
          "removed_lines": 2
        },
        {
          "observed_at": "2026-08-06T10:08:24Z",
          "window_start": "2026-08-06T05:08:38Z",
          "window_end": "2026-08-06T10:08:24Z",
          "status": "source-content",
          "summary": "Eight new comments, including debate over whether mixing counts as money laundering under the FATF definition and a scenario where a Coldcard insider exploits the bug and silences whale victims.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 70,
          "removed_lines": 0
        }
      ]
    },
    {
      "id": "reddit-dice-coleman-guidance-critique",
      "title": "r/Bitcoin: critique of COLDCARD dice-seed guidance against Ian Coleman's converter",
      "url": "https://www.reddit.com/r/Bitcoin/comments/1vg0lxz/did_some_checking_on_seed_generation_by_dice_on/",
      "organisation": "reddit",
      "kind": "community-discussion",
      "role": "Community discussion",
      "publication_time": null,
      "note": null,
      "gone": null,
      "capture": {
        "status": "held",
        "copies": 2,
        "first_observed": "2026-08-06T05:08:44Z",
        "last_observed": "2026-08-06T16:36:59Z",
        "last_checked": "2026-08-12T23:56:54Z"
      },
      "differences": [
        {
          "observed_at": "2026-08-06T16:36:59Z",
          "window_start": "2026-08-06T05:08:44Z",
          "window_end": "2026-08-06T16:36:59Z",
          "status": "source-content",
          "summary": "Two new comments from orbag arguing Ian Coleman's tool yields only 2 bits of entropy per dice roll, so a 24-word seed needs at least 160 rolls.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 16,
          "removed_lines": 0
        }
      ]
    },
    {
      "id": "reddit-attacker-versus-owner-attribution",
      "title": "r/Bitcoin: how to distinguish attacker drains from owners moving their own coins",
      "url": "https://www.reddit.com/r/Bitcoin/comments/1vg7lwa/how_do_we_know_it_was_an_attacker_and_not_the/",
      "organisation": "reddit",
      "kind": "community-discussion",
      "role": "Community discussion",
      "publication_time": null,
      "note": null,
      "gone": null,
      "capture": {
        "status": "held",
        "copies": 2,
        "first_observed": "2026-08-06T05:08:48Z",
        "last_observed": "2026-08-06T16:37:03Z",
        "last_checked": "2026-08-12T23:56:59Z"
      },
      "differences": [
        {
          "observed_at": "2026-08-06T16:37:03Z",
          "window_start": "2026-08-06T05:08:48Z",
          "window_end": "2026-08-06T16:37:03Z",
          "status": "source-content",
          "summary": "New comment by Lopsided_Parfait7127 hoping the attacker secured the coins with proper entropy and a passphrase.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 8,
          "removed_lines": 0
        }
      ]
    },
    {
      "id": "reddit-mcu-uid-seed-correction",
      "title": "r/Bitcoin: correction disputing a claim that the MCU UID is part of the seed",
      "url": "https://www.reddit.com/r/Bitcoin/comments/1vg0nop/coldcard_mcu_uid_is_not_part_of_the_seed_stop/",
      "organisation": "reddit",
      "kind": "community-discussion",
      "role": "Community discussion",
      "publication_time": null,
      "note": null,
      "gone": null,
      "capture": {
        "status": "held",
        "copies": 2,
        "first_observed": "2026-08-06T05:08:52Z",
        "last_observed": "2026-08-06T10:16:16Z",
        "last_checked": "2026-08-08T23:00:48Z"
      },
      "differences": [
        {
          "observed_at": "2026-08-06T10:16:16Z",
          "window_start": "2026-08-06T05:08:52Z",
          "window_end": "2026-08-06T10:16:16Z",
          "status": "source-content",
          "summary": "Reddit served 1 additional comment record(s); the diff preserves their text and any edits to existing records.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 8,
          "removed_lines": 0
        }
      ]
    },
    {
      "id": "stackernews-ctv-vaults",
      "title": "How CTV Covenant Enabled Vaults Could Have Protected Cold Card Victims",
      "url": "https://stacker.news/items/1541227",
      "organisation": "Stacker News",
      "kind": "community-discussion",
      "role": "Community discussion",
      "publication_time": "2026-08-05",
      "note": "nerd2ninja arguing that a CTV-enabled vault could have given an owner time to claw funds back after a drain, and contrasting that proposed design with multi-vendor multisig and dice-generated entropy. A distinct technical mitigation argument about how the incident might have unfolded under a future covenant, rather than a claim about the vulnerable firmware. The proposed wallet behaviour and risk assessments are the author's, not verified here. Captured through the site's public GraphQL API: the rendered pages crash the capture tab, and the API answers POST from this host. The query fixes the captured surface to the item's title, text and two levels of comments, each with author and absolute timestamp.\n",
      "gone": null,
      "capture": {
        "status": "held",
        "copies": 2,
        "first_observed": "2026-08-06T10:08:36Z",
        "last_observed": "2026-08-06T16:37:06Z",
        "last_checked": "2026-08-12T23:57:03Z"
      },
      "differences": [
        {
          "observed_at": "2026-08-06T16:37:06Z",
          "window_start": "2026-08-06T10:08:36Z",
          "window_end": "2026-08-06T16:37:06Z",
          "status": "source-content",
          "summary": "New comment added to the CTV vaults thread: a thinking-face emoji from user 4883b4c1a4.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 7,
          "removed_lines": 0
        }
      ]
    },
    {
      "id": "stackernews-rbf-rescue-experiment",
      "title": "Defending funds on ColdCard with RBF transactions",
      "url": "https://stacker.news/items/1541190",
      "organisation": "Stacker News",
      "kind": "community-discussion",
      "role": "Community discussion",
      "publication_time": "2026-08-05",
      "note": "ignaciob relaying an alleged Pathfinder COLDCARD Mk3 test in which WatchGuard detected a sweep and raced it with a pre-signed replace-by-fee transaction, naming a transaction and fee amounts. This is a distinct mitigation experiment and public discussion of an adversarial fee race during the rescue window. The experiment, its outcome and the claim that the later attacker transaction continued the race are the thread's and linked post's claims, not verified here. Captured through the site's public GraphQL API: the rendered pages crash the capture tab, and the API answers POST from this host. The query fixes the captured surface to the item's title, text and two levels of comments, each with author and absolute timestamp.\n",
      "gone": null,
      "capture": {
        "status": "held",
        "copies": 1,
        "first_observed": "2026-08-06T10:08:39Z",
        "last_observed": "2026-08-06T10:08:39Z",
        "last_checked": "2026-08-12T23:57:06Z"
      },
      "differences": []
    },
    {
      "id": "reddit-dice-rollers-response",
      "title": "r/coldcard: dice-roll users on staying with COLDCARD after the incident",
      "url": "https://www.reddit.com/r/coldcard/comments/1vghhka/coldcard_dice_rollers/",
      "organisation": "reddit",
      "kind": "community-discussion",
      "role": "Community discussion",
      "publication_time": null,
      "note": null,
      "gone": null,
      "capture": {
        "status": "held",
        "copies": 7,
        "first_observed": "2026-08-06T05:25:09Z",
        "last_observed": "2026-08-12T04:40:38Z",
        "last_checked": "2026-08-12T23:57:09Z"
      },
      "differences": [
        {
          "observed_at": "2026-08-12T04:40:38Z",
          "window_start": "2026-08-09T23:26:22Z",
          "window_end": "2026-08-12T04:40:38Z",
          "status": "source-content",
          "summary": "One earlier comment asking how to watch for this type of attack was removed, and a new hostile exchange mocked users who continue using COLDCARD.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 24,
          "removed_lines": 8
        },
        {
          "observed_at": "2026-08-09T23:26:22Z",
          "window_start": "2026-08-08T15:06:47Z",
          "window_end": "2026-08-09T23:26:22Z",
          "status": "source-content",
          "summary": "The thread gained a comment from a 100-roll dice user reporting they are unaffected but concerned about Coinkite surviving the crisis.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 8,
          "removed_lines": 0
        },
        {
          "observed_at": "2026-08-08T15:06:47Z",
          "window_start": "2026-08-07T06:20:36Z",
          "window_end": "2026-08-08T15:06:47Z",
          "status": "source-content",
          "summary": "A new reply was added stating that a BIP-39 passphrase is not optional.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 8,
          "removed_lines": 0
        },
        {
          "observed_at": "2026-08-07T06:20:36Z",
          "window_start": "2026-08-06T16:37:12Z",
          "window_end": "2026-08-07T06:20:36Z",
          "status": "source-content",
          "summary": "Eight new comments, including one user's account of rolling 200 dice with a passphrase and then pulling everything back to an exchange because trust was lost, moving toward multi-vendor multisig.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 66,
          "removed_lines": 0
        },
        {
          "observed_at": "2026-08-06T16:37:12Z",
          "window_start": "2026-08-06T10:08:42Z",
          "window_end": "2026-08-06T16:37:12Z",
          "status": "source-content",
          "summary": "Fourteen new comments: more stay-or-leave reports (one user weighing custody with Bitcoin Suisse), plus criticism of COLDCARD's source-available license, its ngu crypto library, and the risk of nonce-reuse-style signing bugs.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 127,
          "removed_lines": 0
        },
        {
          "observed_at": "2026-08-06T10:08:42Z",
          "window_start": "2026-08-06T05:25:09Z",
          "window_end": "2026-08-06T10:08:42Z",
          "status": "source-content",
          "summary": "Eight new comments in the stay-or-leave thread: several users report rolling 100+ dice, reseeding and staying with COLDCARD, while others dispute whether the firmware was ever really audited.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 66,
          "removed_lines": 0
        }
      ]
    },
    {
      "id": "reddit-switck-identity-claims",
      "title": "r/Bitcoin: claims about the switck identity and COLDCARD code review",
      "url": "https://www.reddit.com/r/Bitcoin/comments/1vgto2m/the_weirdest_part_of_the_coldcard_mess_was_peter/",
      "organisation": "reddit",
      "kind": "community-discussion",
      "role": "Community discussion",
      "publication_time": null,
      "note": null,
      "gone": null,
      "capture": {
        "status": "held",
        "copies": 5,
        "first_observed": "2026-08-06T05:25:17Z",
        "last_observed": "2026-08-07T12:59:45Z",
        "last_checked": "2026-08-12T23:57:14Z"
      },
      "differences": [
        {
          "observed_at": "2026-08-07T12:59:45Z",
          "window_start": "2026-08-07T06:20:42Z",
          "window_end": "2026-08-07T12:59:45Z",
          "status": "source-content",
          "summary": "New comment from jarsgars: \"Straight to jail\".",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 8,
          "removed_lines": 0
        },
        {
          "observed_at": "2026-08-07T06:20:42Z",
          "window_start": "2026-08-06T16:37:16Z",
          "window_end": "2026-08-07T06:20:42Z",
          "status": "source-content",
          "summary": "Several new comments, including nullc saying they had assumed switck was Peter Gray's other account and discussing the missed chance to put the question to Coinkite, plus more tripwire-theory discussion and a white-rabbit-tattoo tweet observation.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 67,
          "removed_lines": 0
        },
        {
          "observed_at": "2026-08-06T16:37:16Z",
          "window_start": "2026-08-06T10:08:46Z",
          "window_end": "2026-08-06T16:37:16Z",
          "status": "source-content",
          "summary": "The post body was edited to drop the \"u/\" prefixes before switck and DocHex, and three new comments appeared (Sociapaths remark, Rollo Tomassi, incompetence/malice spectrum).",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 26,
          "removed_lines": 2
        },
        {
          "observed_at": "2026-08-06T10:08:46Z",
          "window_start": "2026-08-06T05:25:17Z",
          "window_end": "2026-08-06T10:08:46Z",
          "status": "source-content",
          "summary": "Large batch of new comments, including achow101's detailed git-forensics analysis arguing the libngu commit's author, committer and GPG-signer timestamps suggest Switck and Peter Gray are the same person, plus tripwire and intelligence-agency speculation.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 256,
          "removed_lines": 0
        }
      ]
    },
    {
      "id": "reddit-nvk-ai-audit-podcast",
      "title": "r/Bitcoin: podcast transcript cited in criticism of nvk's AI-audit response",
      "url": "https://www.reddit.com/r/Bitcoin/comments/1vgj17y/coldcard_ceo_rodolfo_novak_confessing_2_moths_ago/",
      "organisation": "reddit",
      "kind": "community-discussion",
      "role": "Community discussion",
      "publication_time": null,
      "note": null,
      "gone": null,
      "capture": {
        "status": "held",
        "copies": 3,
        "first_observed": "2026-08-06T05:25:26Z",
        "last_observed": "2026-08-07T19:33:26Z",
        "last_checked": "2026-08-12T23:57:20Z"
      },
      "differences": [
        {
          "observed_at": "2026-08-07T19:33:26Z",
          "window_start": "2026-08-06T16:37:19Z",
          "window_end": "2026-08-07T19:33:26Z",
          "status": "source-content",
          "summary": "The post gained a separator line and a link to a WalletScrutiny GitLab work item.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 3,
          "removed_lines": 0
        },
        {
          "observed_at": "2026-08-06T16:37:19Z",
          "window_start": "2026-08-06T05:25:26Z",
          "window_end": "2026-08-06T16:37:19Z",
          "status": "source-content",
          "summary": "bobivy1234 edited their comment to add at the time to the claim about LLM audit tools flagging benign issues, and three new comments appeared, including first-hand reactions calling the developer criminally negligent and bobivy1234 replying that the podcast conversation proves little.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 27,
          "removed_lines": 3
        }
      ]
    },
    {
      "id": "afilini-seed-rng-migration-report",
      "title": "One Commit, Two Random Sources: how COLDCARD's seed generation was moved off the hardware RNG",
      "url": "https://gist.github.com/afilini/b7d13bd2d7deaf8f23d30213a801e3c5",
      "organisation": "afilini",
      "kind": "independent-analysis",
      "role": "Independent primary analysis",
      "publication_time": "2026-08-05",
      "note": "Commit-level reading of b18723dd (1 March 2021), the libngu integration, which\nthe report says moved only seed.py and random.py from the ckcc.rng hardware API\nto ngu.random while backups and file erasure stayed on the hardware path. Its\nconclusion is that this was a selective rather than blanket migration that then\nstood for five years. Primary work rather than reporting on it: the report\nstates the git commands and line-by-line diffs it rests on, so a reader can\nre-run them. The report discloses AI assistance in its own text. The selective\nmigration reading and its inferences are the author's, not verified here, and\nthe report does not assert intent. Its subject matter overlaps\ndylanleclair1-switck-key-attribution and reddit-switck-identity-claims, which\npreserve a separate identity claim about the same code. The gist had four\nrevisions within two hours of creation, so it is watched rather than treated as\na one-shot capture.\n",
      "gone": null,
      "capture": {
        "status": "held",
        "copies": 2,
        "first_observed": "2026-08-06T05:58:11Z",
        "last_observed": "2026-08-12T04:40:51Z",
        "last_checked": "2026-08-12T23:57:25Z"
      },
      "differences": [
        {
          "observed_at": "2026-08-12T04:40:51Z",
          "window_start": "2026-08-06T05:58:11Z",
          "window_end": "2026-08-12T04:40:51Z",
          "status": "capture-noise",
          "summary": "Only the gist's relative update label and star counter changed; no body text was added or removed.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 5,
          "removed_lines": 3
        }
      ]
    },
    {
      "id": "dylanleclair1-switck-key-attribution",
      "title": "switck/libngu: one key, two names",
      "url": "https://gist.github.com/dylanleclair1/67d160af313be59851b88d1a81f0d762",
      "organisation": "dylanleclair1",
      "kind": "independent-analysis",
      "role": "Independent primary analysis",
      "publication_time": "2026-08-05",
      "note": "Attribution argument that the pseudonymous GitHub account switck and Peter D.\nGray of Coinkite are one person, resting on a 2020 public exchange read through\nthe GitHub API and on local GPG verification said to show 58 Switck-authored\ncommits carrying valid signatures from Gray's personal key. It then traces\ncommit f19de05, which introduced the STM32 random-number code with the\ndefective guard, to COLDCARD's seed generation. The gist ships a verify.sh so\nthe signature checks can be re-run independently, which is why it is registered\nas primary work rather than as commentary. Its own text declines to state\nintent and calls the guard error an ordinary C mistake. The identity\nattribution, the elimination of alternative explanations and every inference\ndrawn from the commit history are the author's claims, not verified here, and\nregistration is not endorsement of them. This gist is the underlying artefact\nfor the allegation preserved at reddit-switck-identity-claims. The publishing\naccount is recorded as published; this archive does not assert who is behind\nit. Six revisions within 80 minutes of creation, so it is watched.\n",
      "gone": null,
      "capture": {
        "status": "held",
        "copies": 1,
        "first_observed": "2026-08-06T05:58:13Z",
        "last_observed": "2026-08-06T05:58:13Z",
        "last_checked": "2026-08-12T23:57:28Z"
      },
      "differences": []
    },
    {
      "id": "bitcoinmag-red-team-390-repos",
      "title": "Bitcoin Red Team finds 85 critical flaws across 390 open-source repos",
      "url": "https://bitcoinmagazine.com/business/bitcoin-red-team-finds-85-critical-flaws-across-390-open-source-repos-after-coldcard-exploit",
      "organisation": "Bitcoin Magazine",
      "kind": "reporting",
      "role": "Reporting",
      "publication_time": "2026-08-05",
      "note": "Secondary reporting on the post-incident Bitcoin Red Team effort led by Calle\nand Rob Hamilton, carrying a later and larger set of figures than the archive's\nearlier Red Team captures: 390 repositories, 4,962 findings, 85 critical and\n635 high severity, 27.5 hours of auditing, a 171,599-line harness and more than\nUS$40,000 of compute funded by OpenSats, against the roughly 150 repositories\nand US$20,000 Rob Hamilton stated in his 4 Aug status update. The underlying findings are not public\nand are stated as being held for responsible disclosure, so none of the counts\ncan be rechecked from this capture. The figures are attributed to Calle's own\nupdate, whose primary post is captured at callebtc-2085024458012586286.\n",
      "gone": null,
      "capture": {
        "status": "held",
        "copies": 4,
        "first_observed": "2026-08-06T05:58:14Z",
        "last_observed": "2026-08-12T11:58:14Z",
        "last_checked": "2026-08-13T01:28:01Z"
      },
      "differences": [
        {
          "observed_at": "2026-08-12T11:58:14Z",
          "window_start": "2026-08-12T05:11:50Z",
          "window_end": "2026-08-12T11:58:14Z",
          "status": "capture-noise",
          "summary": "Only Bitcoin Magazine's rotating LATEST NEWS rail and category counters changed; the article body was unchanged.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 8,
          "removed_lines": 8
        },
        {
          "observed_at": "2026-08-12T05:11:50Z",
          "window_start": "2026-08-07T20:54:09Z",
          "window_end": "2026-08-12T05:11:50Z",
          "status": "capture-noise",
          "summary": "Only rotating related-story headlines and their timestamps changed; the article text was unchanged.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 10,
          "removed_lines": 10
        },
        {
          "observed_at": "2026-08-07T20:54:09Z",
          "window_start": "2026-08-06T05:58:14Z",
          "window_end": "2026-08-07T20:54:09Z",
          "status": "capture-noise",
          "summary": "Only the publication's own rails changed: a next-article link appeared and the related-articles, latest-news and section-counter blocks rotated. Juan Galt's article body, including the Red Team figures the record cites, is unchanged.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 21,
          "removed_lines": 19
        }
      ]
    },
    {
      "id": "bitcoinmag-closed-source-era",
      "title": "The end of the closed-source era is at hand: obscurity was never security",
      "url": "https://bitcoinmagazine.com/technical/the-end-of-the-closed-source-era-is-at-hand-obscurity-was-never-security",
      "organisation": "Bitcoin Magazine",
      "kind": "analysis",
      "role": "Secondary analysis",
      "publication_time": "2026-08-06",
      "note": "Colin Crossman's 6 August op-ed arguing that machine-readable code ends\nsecurity through obscurity: Coinkite's move from a free-software licence to\nsource-available terms changed the economics of finding the bug, not its\nreadability. States the theft had reached 4,585 addresses and nearly\n$90 million and was ongoing at the time of writing; the figures are the\nauthor's, not reproduced here.\n",
      "gone": null,
      "capture": {
        "status": "held",
        "copies": 6,
        "first_observed": "2026-08-07T13:31:39Z",
        "last_observed": "2026-08-14T03:28:08Z",
        "last_checked": "2026-08-15T12:56:44Z"
      },
      "differences": [
        {
          "observed_at": "2026-08-14T03:28:08Z",
          "window_start": "2026-08-13T20:59:37Z",
          "window_end": "2026-08-14T03:28:08Z",
          "status": "capture-noise",
          "summary": "Only Bitcoin Magazine site chrome changed: social links were listed one per line, related article cards rotated, and section counters incremented.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 6,
          "removed_lines": 13
        },
        {
          "observed_at": "2026-08-13T20:59:37Z",
          "window_start": "2026-08-12T11:58:16Z",
          "window_end": "2026-08-13T20:59:37Z",
          "status": "capture-noise",
          "summary": "Only Bitcoin Magazine site chrome changed: social links were listed one per line, related article cards rotated, and section counters incremented.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 23,
          "removed_lines": 16
        },
        {
          "observed_at": "2026-08-12T11:58:16Z",
          "window_start": "2026-08-12T05:11:54Z",
          "window_end": "2026-08-12T11:58:16Z",
          "status": "capture-noise",
          "summary": "Only Bitcoin Magazine's rotating LATEST NEWS rail and category counters changed; the article body was unchanged.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 7,
          "removed_lines": 7
        },
        {
          "observed_at": "2026-08-12T05:11:54Z",
          "window_start": "2026-08-07T20:54:11Z",
          "window_end": "2026-08-12T05:11:54Z",
          "status": "capture-noise",
          "summary": "Only rotating related-story headlines and their timestamps changed; the article text was unchanged.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 10,
          "removed_lines": 10
        },
        {
          "observed_at": "2026-08-07T20:54:11Z",
          "window_start": "2026-08-07T13:31:39Z",
          "window_end": "2026-08-07T20:54:11Z",
          "status": "capture-noise",
          "summary": "Only the publication's own rails changed: the related-articles list, the latest-news list and the per-section article counters. Colin Crossman's article body is unchanged.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 13,
          "removed_lines": 13
        }
      ]
    },
    {
      "id": "reddit-auto-dca-drained-addresses",
      "title": "r/Bitcoin: automatic DCA buys still flowing to compromised COLDCARD addresses",
      "url": "https://www.reddit.com/r/Bitcoin/comments/1vgrt1m/are_people_still_dcaing_to_their_hacked_cold/",
      "organisation": "reddit",
      "kind": "community-discussion",
      "role": "Community discussion",
      "publication_time": null,
      "note": null,
      "gone": null,
      "capture": {
        "status": "held",
        "copies": 1,
        "first_observed": "2026-08-07T10:05:25Z",
        "last_observed": "2026-08-07T10:05:25Z",
        "last_checked": "2026-08-14T08:27:11Z"
      },
      "differences": []
    },
    {
      "id": "reddit-duosig-versus-passphrase",
      "title": "r/Bitcoin: 2-of-2 multisig versus single-sig with a passphrase",
      "url": "https://www.reddit.com/r/Bitcoin/comments/1vgizkf/with_all_the_talk_about_passphrases_doesnt_a_22/",
      "organisation": "reddit",
      "kind": "community-discussion",
      "role": "Community discussion",
      "publication_time": null,
      "note": null,
      "gone": null,
      "capture": {
        "status": "held",
        "copies": 1,
        "first_observed": "2026-08-07T10:05:29Z",
        "last_observed": "2026-08-07T10:05:29Z",
        "last_checked": "2026-08-14T08:27:15Z"
      },
      "differences": []
    },
    {
      "id": "reddit-dream-signer-design",
      "title": "r/Bitcoin: a post-incident wishlist for a hardware signer design",
      "url": "https://www.reddit.com/r/Bitcoin/comments/1vgfiw0/my_dream_hardware_wallet/",
      "organisation": "reddit",
      "kind": "community-discussion",
      "role": "Community discussion",
      "publication_time": null,
      "note": null,
      "gone": null,
      "capture": {
        "status": "held",
        "copies": 1,
        "first_observed": "2026-08-07T10:05:32Z",
        "last_observed": "2026-08-07T10:05:32Z",
        "last_checked": "2026-08-14T08:27:20Z"
      },
      "differences": []
    },
    {
      "id": "bitcointalk-device-entropy-trust",
      "title": "Possible all Bitcoin Hardware Wallets be hacked due to 'Trust in Device Entropy?",
      "url": "https://bitcointalk.org/index.php?topic=5590481.0",
      "organisation": "BitcoinTalk",
      "kind": "community-discussion",
      "role": "Community discussion",
      "publication_time": "2026-08-06",
      "note": "dim_mak5 asking how holders can verify, rather than trust, the entropy of any hardware wallet, framing the COLDCARD hack as proof of the problem and ranging into quantum, AI and confiscation speculation. Replies point to user-generated seeds and to the registered bitcointalk-entropy-warning-design discussion. An entropy-verifiability debate the incident triggered on the Bitcoin Discussion board. The claims and speculation are the posters' own, not verified here.\n",
      "gone": null,
      "capture": {
        "status": "held",
        "copies": 4,
        "first_observed": "2026-08-07T10:05:36Z",
        "last_observed": "2026-08-09T04:09:01Z",
        "last_checked": "2026-08-14T08:27:25Z"
      },
      "differences": [
        {
          "observed_at": "2026-08-09T04:09:01Z",
          "window_start": "2026-08-08T08:36:24Z",
          "window_end": "2026-08-09T04:09:01Z",
          "status": "source-content",
          "summary": "A new post argued that entropy hardware should be isolated from firmware updates because buggy software can compromise even high-grade randomness generators.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 3,
          "removed_lines": 0
        },
        {
          "observed_at": "2026-08-08T08:36:24Z",
          "window_start": "2026-08-08T02:04:10Z",
          "window_end": "2026-08-08T08:36:24Z",
          "status": "source-content",
          "summary": "The thread gained a new post quoting Coinkite's entropy technical backgrounder about the MicroPython software PRNG fallback.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 7,
          "removed_lines": 0
        },
        {
          "observed_at": "2026-08-08T02:04:10Z",
          "window_start": "2026-08-07T10:05:36Z",
          "window_end": "2026-08-08T02:04:10Z",
          "status": "source-content",
          "summary": "The thread gained new posts arguing hardware wallets mislead customers by using software entropy and speculating about Wall Street-backed wallets, plus a reply defending hybrid software approaches.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 21,
          "removed_lines": 1
        }
      ]
    },
    {
      "id": "stackernews-fireship-coverage",
      "title": "Fireship covered the coldcard hack 🤣",
      "url": "https://stacker.news/items/1541274",
      "organisation": "Stacker News",
      "kind": "community-discussion",
      "role": "Community discussion",
      "publication_time": "2026-08-06",
      "note": "justin_shocknet linking Fireship's video coverage of the COLDCARD incident, which is not separately registered or captured here. A link post held as minor colour marking the incident's arrival in mainstream tech-media commentary. Captured through the site's public GraphQL API: the rendered pages crash the capture tab, and the API answers POST from this host. The query fixes the captured surface to the item's title, text and two levels of comments, each with author and absolute timestamp.\n",
      "gone": null,
      "capture": {
        "status": "held",
        "copies": 1,
        "first_observed": "2026-08-07T10:05:36Z",
        "last_observed": "2026-08-07T10:05:36Z",
        "last_checked": "2026-08-09T18:48:33Z"
      },
      "differences": []
    },
    {
      "id": "bitcointalk-dice-bias-entropy",
      "title": "dice or not dice",
      "url": "https://bitcointalk.org/index.php?topic=5590528.0",
      "organisation": "BitcoinTalk",
      "kind": "community-discussion",
      "role": "Community discussion",
      "publication_time": "2026-08-06",
      "note": "babo relaying a Telegram debate over casino-grade dice for seed generation, citing what another user describes as a 1971 Harvard study of 219 commercial dice that found bias worth at most about one bit of entropy on a 24-word seed. Replies argue the dice response to the COLDCARD issue is overblown and that physical coercion dwarfs entropy bias. The forum's dice-paranoia record, carrying a specific checkable claim that is the posters' own and not verified here.\n",
      "gone": null,
      "capture": {
        "status": "held",
        "copies": 3,
        "first_observed": "2026-08-07T10:05:38Z",
        "last_observed": "2026-08-08T02:04:12Z",
        "last_checked": "2026-08-14T08:27:27Z"
      },
      "differences": [
        {
          "observed_at": "2026-08-08T02:04:12Z",
          "window_start": "2026-08-07T13:00:12Z",
          "window_end": "2026-08-08T02:04:12Z",
          "status": "capture-noise",
          "summary": "Only Bitcointalk's relative quote date rolled from Today to an absolute date.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 1,
          "removed_lines": 1
        },
        {
          "observed_at": "2026-08-07T13:00:12Z",
          "window_start": "2026-08-07T10:05:38Z",
          "window_end": "2026-08-07T13:00:12Z",
          "status": "source-content",
          "summary": "New post by Satofan44 arguing that a good passphrase is the practical best setup for most users and that paranoid advanced setups are only warranted for hobbyists or very high values.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 15,
          "removed_lines": 0
        }
      ]
    },
    {
      "id": "stackernews-dice-worksheet",
      "title": "Generating seed phrase from dice - an easy, understandable method",
      "url": "https://stacker.news/items/1541955",
      "organisation": "Stacker News",
      "kind": "community-discussion",
      "role": "Community discussion",
      "publication_time": "2026-08-07",
      "note": "BitcoinHandsOn2 publishing a printable dice-to-seed-phrase worksheet, explicitly motivated by lost trust in hardware-wallet entropy after the incident, and asking for feedback on its logic. A small community-built artefact of the dice response, alongside reddit-dice-entropy-pi-tool and the registered dice-guidance threads. The worksheet's correctness is the author's claim, not verified here. Captured through the site's public GraphQL API: the rendered pages crash the capture tab, and the API answers POST from this host. The query fixes the captured surface to the item's title, text and two levels of comments, each with author and absolute timestamp.\n",
      "gone": null,
      "capture": {
        "status": "held",
        "copies": 3,
        "first_observed": "2026-08-07T10:24:53Z",
        "last_observed": "2026-08-08T16:28:32Z",
        "last_checked": "2026-08-09T18:48:35Z"
      },
      "differences": [
        {
          "observed_at": "2026-08-08T16:28:32Z",
          "window_start": "2026-08-07T14:25:40Z",
          "window_end": "2026-08-08T16:28:32Z",
          "status": "source-content",
          "summary": "The thread gained a reply from quickscan explaining that the final BIP-39 word contains additional entropy bits plus checksum, with a suggested worksheet revision and a link to the canonical BIP-39 table.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 7,
          "removed_lines": 0
        },
        {
          "observed_at": "2026-08-07T14:25:40Z",
          "window_start": "2026-08-07T10:24:53Z",
          "window_end": "2026-08-07T14:25:40Z",
          "status": "source-content",
          "summary": "Two new comments: javier calling the Coldcard failure an inside job rather than something the user did wrong, and Hypno praising the worksheet's entropy method while noting BitBox's lookup-table alternative. Existing comments were reordered by the API response.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 14,
          "removed_lines": 7
        }
      ]
    },
    {
      "id": "stackernews-2023-hww-paranoia",
      "title": "extreme paranoia with hardware wallets",
      "url": "https://stacker.news/items/294620",
      "organisation": "Stacker News",
      "kind": "community-discussion",
      "role": "Community discussion",
      "publication_time": "2023-10-25",
      "note": "lloyddunne in October 2023, praising the COLDCARD yet naming seed-generation trust as the thing that kept them up at night, and proposing normalised offline seed generation with dice and independent checksum verification. A contemporaneous pre-incident record that the concern behind the July 2026 incident was already being discussed, alongside reddit-entropy-warning-october-2023. Captured through the site's public GraphQL API: the rendered pages crash the capture tab, and the API answers POST from this host. The query fixes the captured surface to the item's title, text and two levels of comments, each with author and absolute timestamp.\n",
      "gone": null,
      "capture": {
        "status": "held",
        "copies": 3,
        "first_observed": "2026-08-07T10:24:54Z",
        "last_observed": "2026-08-08T16:28:35Z",
        "last_checked": "2026-08-09T18:48:38Z"
      },
      "differences": [
        {
          "observed_at": "2026-08-08T16:28:35Z",
          "window_start": "2026-08-07T20:54:18Z",
          "window_end": "2026-08-08T16:28:35Z",
          "status": "capture-noise",
          "summary": "Only the order of existing comments changed in the API response; no comment text was added, edited or removed.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 7,
          "removed_lines": 7
        },
        {
          "observed_at": "2026-08-07T20:54:18Z",
          "window_start": "2026-08-07T10:24:54Z",
          "window_end": "2026-08-07T20:54:18Z",
          "status": "capture-noise",
          "summary": "Only comment ordering changed in the API response: CruncherDefi's 7 August comment on verifying dice rolls against reproducible on-device code moved from below BitcoinHandsOn2's worksheet comment to the top of the list. No comment text was added, edited or removed; this is ranking-order churn.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 7,
          "removed_lines": 7
        }
      ]
    },
    {
      "id": "bitcointalk-etf-inflows-hack-link",
      "title": "Bitcoin ETF Inflows Surge Following $130M Coldcard Hack",
      "url": "https://bitcointalk.org/index.php?topic=5590588.0",
      "organisation": "BitcoinTalk",
      "kind": "community-discussion",
      "role": "Community discussion",
      "publication_time": "2026-08-06",
      "note": "Oshosondy relaying a Bitcoin Magazine report that US spot bitcoin ETFs took in a claimed $626 million of fresh cash after the hack, citing Farside Investors, and asking whether fear of self-custody drove it. Replies mostly reject the causal framing as clickbait and correlation, pointing to institutional allocation and macro factors. The forum's record of the market-impact narrative and the community pushback, alongside reddit-self-custody-to-etf. The inflow figure and its attribution are the article's and posters' claims, not verified here.\n",
      "gone": null,
      "capture": {
        "status": "held",
        "copies": 4,
        "first_observed": "2026-08-07T10:24:56Z",
        "last_observed": "2026-08-08T02:04:14Z",
        "last_checked": "2026-08-14T08:27:29Z"
      },
      "differences": [
        {
          "observed_at": "2026-08-08T02:04:14Z",
          "window_start": "2026-08-07T19:33:56Z",
          "window_end": "2026-08-08T02:04:14Z",
          "status": "capture-noise",
          "summary": "Only Bitcointalk's relative quote dates rolled from Today to absolute dates.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 3,
          "removed_lines": 3
        },
        {
          "observed_at": "2026-08-07T19:33:56Z",
          "window_start": "2026-08-07T13:00:14Z",
          "window_end": "2026-08-07T19:33:56Z",
          "status": "source-content",
          "summary": "The thread gained new replies disputing the ETF inflow causality and defending Bloomberg's reporting.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 9,
          "removed_lines": 0
        },
        {
          "observed_at": "2026-08-07T13:00:14Z",
          "window_start": "2026-08-07T10:24:56Z",
          "window_end": "2026-08-07T13:00:14Z",
          "status": "source-content",
          "summary": "Three new posts: Dr.Bitcoin_Strange quoting Bloomberg's Eric Balchunas and CZ on ETF inflows versus self-custody, plus Odohu and GeorgeJohn debating whether the Coldcard hack actually moved the bitcoin price.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 17,
          "removed_lines": 0
        }
      ]
    },
    {
      "id": "reddit-ccq-stuck-splash-support",
      "title": "r/coldcard: CC Q stuck on splash screen during update attempt, support ticket unanswered",
      "url": "https://www.reddit.com/r/coldcard/comments/1vhbhy0/cc_q_wont_boot_ip/",
      "organisation": "reddit",
      "kind": "community-discussion",
      "role": "Community discussion",
      "publication_time": null,
      "note": null,
      "gone": null,
      "capture": {
        "status": "held",
        "copies": 4,
        "first_observed": "2026-08-07T10:24:57Z",
        "last_observed": "2026-08-09T04:09:07Z",
        "last_checked": "2026-08-14T08:27:31Z"
      },
      "differences": [
        {
          "observed_at": "2026-08-09T04:09:07Z",
          "window_start": "2026-08-07T19:33:58Z",
          "window_end": "2026-08-09T04:09:07Z",
          "status": "source-content",
          "summary": "A new comment mocked the COLDCARD Q's appearance by comparing it to a 2009 Blackberry.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 8,
          "removed_lines": 0
        },
        {
          "observed_at": "2026-08-07T19:33:58Z",
          "window_start": "2026-08-07T13:00:16Z",
          "window_end": "2026-08-07T19:33:58Z",
          "status": "source-content",
          "summary": "The thread gained new comments about preparing an offline MacBook Air for recovery and repurposing the device as an offline seed generator.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 16,
          "removed_lines": 0
        },
        {
          "observed_at": "2026-08-07T13:00:16Z",
          "window_start": "2026-08-07T10:24:57Z",
          "window_end": "2026-08-07T13:00:16Z",
          "status": "source-content",
          "summary": "New comment by 7ivor explaining coin-flip entropy mapped to the word list, and that hardware wallets are not required to generate an offline seed.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 10,
          "removed_lines": 0
        }
      ]
    },
    {
      "id": "reddit-cancelled-order-shipped",
      "title": "r/coldcard: cancelled order refunded but the devices arrived anyway",
      "url": "https://www.reddit.com/r/coldcard/comments/1vhbex7/cancelled_order_but_recieved_anyway/",
      "organisation": "reddit",
      "kind": "community-discussion",
      "role": "Community discussion",
      "publication_time": null,
      "note": null,
      "gone": null,
      "capture": {
        "status": "held",
        "copies": 3,
        "first_observed": "2026-08-07T10:25:00Z",
        "last_observed": "2026-08-09T18:48:41Z",
        "last_checked": "2026-08-10T02:11:27Z"
      },
      "differences": [
        {
          "observed_at": "2026-08-09T18:48:41Z",
          "window_start": "2026-08-07T14:25:45Z",
          "window_end": "2026-08-09T18:48:41Z",
          "status": "source-content",
          "summary": "Reddit served 1 additional comment record(s); the diff preserves their text and any edits to existing records.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 13,
          "removed_lines": 0
        },
        {
          "observed_at": "2026-08-07T14:25:45Z",
          "window_start": "2026-08-07T10:25:00Z",
          "window_end": "2026-08-07T14:25:45Z",
          "status": "source-content",
          "summary": "One new comment by Personal-Time-9993 asking whether the shipped cancelled order included stickers and no shitcoins.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 8,
          "removed_lines": 0
        }
      ]
    },
    {
      "id": "reddit-dice-entropy-pi-tool",
      "title": "r/coldcard: a dice-to-BIP39 tool for Pi Zero built after the entropy incident",
      "url": "https://www.reddit.com/r/coldcard/comments/1vgvt2j/got_paranoid_after_the_coldcard_entropy_thing/",
      "organisation": "reddit",
      "kind": "community-discussion",
      "role": "Community discussion",
      "publication_time": null,
      "note": null,
      "gone": null,
      "capture": {
        "status": "held",
        "copies": 1,
        "first_observed": "2026-08-07T10:25:04Z",
        "last_observed": "2026-08-07T10:25:04Z",
        "last_checked": "2026-08-14T08:27:36Z"
      },
      "differences": []
    },
    {
      "id": "reddit-attacker-execution-critique",
      "title": "r/Bitcoin: why the COLDCARD attacker's execution drew suspicion",
      "url": "https://www.reddit.com/r/Bitcoin/comments/1vh47pj/why_were_coldcard_hackers_so_stupid/",
      "organisation": "reddit",
      "kind": "community-discussion",
      "role": "Community discussion",
      "publication_time": null,
      "note": null,
      "gone": null,
      "capture": {
        "status": "held",
        "copies": 11,
        "first_observed": "2026-08-07T10:25:07Z",
        "last_observed": "2026-08-12T17:29:41Z",
        "last_checked": "2026-08-14T08:27:41Z"
      },
      "differences": [
        {
          "observed_at": "2026-08-12T17:29:41Z",
          "window_start": "2026-08-12T04:41:32Z",
          "window_end": "2026-08-12T17:29:41Z",
          "status": "source-content",
          "summary": "The Reddit thread gained a new reply from unstopablex15 saying the stolen coins will go through several mixers.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 8,
          "removed_lines": 0
        },
        {
          "observed_at": "2026-08-12T04:41:32Z",
          "window_start": "2026-08-09T23:27:01Z",
          "window_end": "2026-08-12T04:41:32Z",
          "status": "source-content",
          "summary": "The thread gained comments comparing the bug to an early Android wallet RNG flaw and arguing that the thieves' operational mistakes suggest a non-state actor.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 25,
          "removed_lines": 0
        },
        {
          "observed_at": "2026-08-09T23:27:01Z",
          "window_start": "2026-08-09T16:56:52Z",
          "window_end": "2026-08-09T23:27:01Z",
          "status": "source-content",
          "summary": "The thread gained an off-topic comment.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 8,
          "removed_lines": 0
        },
        {
          "observed_at": "2026-08-09T16:56:52Z",
          "window_start": "2026-08-08T21:37:20Z",
          "window_end": "2026-08-09T16:56:52Z",
          "status": "source-content",
          "summary": "A comment arguing that stolen funds could not be safely spent was removed by Reddit, and two new comments were added: one about building a white hat agent and another alleging an inside job by the CEO.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 18,
          "removed_lines": 4
        },
        {
          "observed_at": "2026-08-08T21:37:20Z",
          "window_start": "2026-08-08T15:07:25Z",
          "window_end": "2026-08-08T21:37:20Z",
          "status": "source-content",
          "summary": "A comment's author and body were replaced with [deleted], removing the original text from the thread.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 4,
          "removed_lines": 2
        },
        {
          "observed_at": "2026-08-08T15:07:25Z",
          "window_start": "2026-08-08T08:36:36Z",
          "window_end": "2026-08-08T15:07:25Z",
          "status": "source-content",
          "summary": "A comment speculating about an inside job was removed, and a new reply was added claiming AI-secured code will reduce future hacks.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 9,
          "removed_lines": 9
        },
        {
          "observed_at": "2026-08-08T08:36:36Z",
          "window_start": "2026-08-08T02:04:25Z",
          "window_end": "2026-08-08T08:36:36Z",
          "status": "source-content",
          "summary": "One participant comment was deleted and replaced with a [deleted] marker, while several new comments were added including one asking about a Kraken hack and the original poster replying 'Relevance?'.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 33,
          "removed_lines": 1
        },
        {
          "observed_at": "2026-08-08T02:04:25Z",
          "window_start": "2026-08-07T19:34:08Z",
          "window_end": "2026-08-08T02:04:25Z",
          "status": "source-content",
          "summary": "The Reddit thread gained several new participant comments debating proof of ownership, criticizing armchair analysis and asking about the attacker's node setup.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 41,
          "removed_lines": 0
        },
        {
          "observed_at": "2026-08-07T19:34:08Z",
          "window_start": "2026-08-07T13:00:26Z",
          "window_end": "2026-08-07T19:34:08Z",
          "status": "source-content",
          "summary": "The thread gained new comments debating whether the bug was deliberately implemented, the relationship between private and public keys, and whether mixing could hide stolen coins.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 71,
          "removed_lines": 11
        },
        {
          "observed_at": "2026-08-07T13:00:26Z",
          "window_start": "2026-08-07T10:25:07Z",
          "window_end": "2026-08-07T13:00:26Z",
          "status": "source-content",
          "summary": "One comment by Independent_Wear5840 (questioning the point of the post) was removed, and one new comment by bfr_ says prompt engineering is no longer a role companies want.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 8,
          "removed_lines": 10
        }
      ]
    },
    {
      "id": "reddit-mk3-seed-entropy-worse",
      "title": "r/Bitcoin: claim that Mk3 PRNG seed entropy is nearer 23 bits than 32",
      "url": "https://www.reddit.com/r/Bitcoin/comments/1vh0lm7/coldcard_entropy_even_worse_than_feared/",
      "organisation": "reddit",
      "kind": "community-discussion",
      "role": "Community discussion",
      "publication_time": "2026-08-06",
      "note": null,
      "gone": null,
      "capture": {
        "status": "held",
        "copies": 10,
        "first_observed": "2026-08-07T10:44:57Z",
        "last_observed": "2026-08-13T19:27:49Z",
        "last_checked": "2026-08-14T08:27:47Z"
      },
      "differences": [
        {
          "observed_at": "2026-08-13T19:27:49Z",
          "window_start": "2026-08-13T12:56:20Z",
          "window_end": "2026-08-13T19:27:49Z",
          "status": "source-content",
          "summary": "A comment by 1n5aN1aC describing dice-roll verification with a simple Python script was removed from the thread.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 0,
          "removed_lines": 12
        },
        {
          "observed_at": "2026-08-13T12:56:20Z",
          "window_start": "2026-08-12T04:41:39Z",
          "window_end": "2026-08-13T12:56:20Z",
          "status": "source-content",
          "summary": "The thread gained a new comment by brando2131 stating that multisig equals multiple factors.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 8,
          "removed_lines": 0
        },
        {
          "observed_at": "2026-08-12T04:41:39Z",
          "window_start": "2026-08-09T23:27:06Z",
          "window_end": "2026-08-12T04:41:39Z",
          "status": "source-content",
          "summary": "Several comments were deleted or redacted as [deleted] and [removed], and a short reply reading 'mk3' was added.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 16,
          "removed_lines": 24
        },
        {
          "observed_at": "2026-08-09T23:27:06Z",
          "window_start": "2026-08-09T16:56:57Z",
          "window_end": "2026-08-09T23:27:06Z",
          "status": "source-content",
          "summary": "The thread gained a reply asking whether the entropy estimate applies to Mk3 or to newer models.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 8,
          "removed_lines": 0
        },
        {
          "observed_at": "2026-08-09T16:56:57Z",
          "window_start": "2026-08-08T15:07:31Z",
          "window_end": "2026-08-09T16:56:57Z",
          "status": "source-content",
          "summary": "A comment about moderator removals was deleted and a new short comment was added stating that fewer people will understand the technical discussion.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 8,
          "removed_lines": 8
        },
        {
          "observed_at": "2026-08-08T15:07:31Z",
          "window_start": "2026-08-08T08:36:41Z",
          "window_end": "2026-08-08T15:07:31Z",
          "status": "source-content",
          "summary": "A new reply was added noting that passphrases and dice entropy were once dismissed as paranoid, and that entering a passphrase on a Mk3 is cumbersome.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 8,
          "removed_lines": 0
        },
        {
          "observed_at": "2026-08-08T08:36:41Z",
          "window_start": "2026-08-08T02:04:32Z",
          "window_end": "2026-08-08T08:36:41Z",
          "status": "source-content",
          "summary": "The Reddit thread gained a new participant comment asking whether a new address is sufficient rather than a new wallet.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 8,
          "removed_lines": 0
        },
        {
          "observed_at": "2026-08-08T02:04:32Z",
          "window_start": "2026-08-07T19:34:15Z",
          "window_end": "2026-08-08T02:04:32Z",
          "status": "source-content",
          "summary": "The Reddit thread gained a new participant reply.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 8,
          "removed_lines": 0
        },
        {
          "observed_at": "2026-08-07T19:34:15Z",
          "window_start": "2026-08-07T10:44:57Z",
          "window_end": "2026-08-07T19:34:15Z",
          "status": "source-content",
          "summary": "One comment's author changed to [deleted] and a new reply explained that adding entropy sources can only increase or preserve entropy.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 14,
          "removed_lines": 2
        }
      ]
    },
    {
      "id": "reddit-casino-dice-myths",
      "title": "r/Bitcoin: casino worker debunking dice-seed tutorial folklore",
      "url": "https://www.reddit.com/r/Bitcoin/comments/1vh0tzo/dont_do_that/",
      "organisation": "reddit",
      "kind": "community-discussion",
      "role": "Community discussion",
      "publication_time": null,
      "note": null,
      "gone": null,
      "capture": {
        "status": "held",
        "copies": 6,
        "first_observed": "2026-08-07T10:45:02Z",
        "last_observed": "2026-08-09T16:57:06Z",
        "last_checked": "2026-08-14T08:27:53Z"
      },
      "differences": [
        {
          "observed_at": "2026-08-09T16:57:06Z",
          "window_start": "2026-08-08T08:36:45Z",
          "window_end": "2026-08-09T16:57:06Z",
          "status": "source-content",
          "summary": "A new comment was added arguing that dice are a poor entropy source for computers because a die has only six values, which introduces predictability.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 9,
          "removed_lines": 0
        },
        {
          "observed_at": "2026-08-08T08:36:45Z",
          "window_start": "2026-08-08T02:04:38Z",
          "window_end": "2026-08-08T08:36:45Z",
          "status": "source-content",
          "summary": "The Reddit thread gained a new participant comment asking what is wrong with /dev/random.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 8,
          "removed_lines": 0
        },
        {
          "observed_at": "2026-08-08T02:04:38Z",
          "window_start": "2026-08-07T19:34:20Z",
          "window_end": "2026-08-08T02:04:38Z",
          "status": "source-content",
          "summary": "The Reddit thread gained three new participant comments about dice entropy and tutorial folklore.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 24,
          "removed_lines": 0
        },
        {
          "observed_at": "2026-08-07T19:34:20Z",
          "window_start": "2026-08-07T13:00:41Z",
          "window_end": "2026-08-07T19:34:20Z",
          "status": "source-content",
          "summary": "The thread gained new comments on dice bias, the difficulty of exploiting physical imperfections, and the difference between dice entropy and the COLDCARD PRNG's limited search space.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 38,
          "removed_lines": 0
        },
        {
          "observed_at": "2026-08-07T13:00:41Z",
          "window_start": "2026-08-07T10:45:02Z",
          "window_end": "2026-08-07T13:00:41Z",
          "status": "source-content",
          "summary": "New comment by 10kpizza: \"You think you're very funny\".",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 8,
          "removed_lines": 0
        }
      ]
    },
    {
      "id": "reddit-dice-entropy-explainer",
      "title": "r/Bitcoin: entropy math for dice-generated seeds after the hack",
      "url": "https://www.reddit.com/r/Bitcoin/comments/1vh3b1s/entropy_of_dice_rolls/",
      "organisation": "reddit",
      "kind": "community-discussion",
      "role": "Community discussion",
      "publication_time": null,
      "note": null,
      "gone": null,
      "capture": {
        "status": "held",
        "copies": 7,
        "first_observed": "2026-08-07T10:45:07Z",
        "last_observed": "2026-08-12T04:41:50Z",
        "last_checked": "2026-08-14T08:27:59Z"
      },
      "differences": [
        {
          "observed_at": "2026-08-12T04:41:50Z",
          "window_start": "2026-08-08T21:37:34Z",
          "window_end": "2026-08-12T04:41:50Z",
          "status": "source-content",
          "summary": "The thread gained a long explanation of addresses versus public keys, private-key search costs and quantum computing, followed by a thank-you reply.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 20,
          "removed_lines": 0
        },
        {
          "observed_at": "2026-08-08T21:37:34Z",
          "window_start": "2026-08-08T08:36:49Z",
          "window_end": "2026-08-08T21:37:34Z",
          "status": "source-content",
          "summary": "The thread gained a new comment asking when a public key is exposed during funding versus spending.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 14,
          "removed_lines": 0
        },
        {
          "observed_at": "2026-08-08T08:36:49Z",
          "window_start": "2026-08-08T02:04:44Z",
          "window_end": "2026-08-08T08:36:49Z",
          "status": "source-content",
          "summary": "The Reddit thread gained two new participant comments debating whether minor dice-bias entropy reductions are practically exploitable.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 18,
          "removed_lines": 0
        },
        {
          "observed_at": "2026-08-08T02:04:44Z",
          "window_start": "2026-08-07T19:34:26Z",
          "window_end": "2026-08-08T02:04:44Z",
          "status": "source-content",
          "summary": "The Reddit thread gained a new participant comment distinguishing self-imposed dice-ordering constraints from attacker-known calculation-space reductions.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 10,
          "removed_lines": 0
        },
        {
          "observed_at": "2026-08-07T19:34:26Z",
          "window_start": "2026-08-07T13:00:47Z",
          "window_end": "2026-08-07T19:34:26Z",
          "status": "source-content",
          "summary": "The thread gained new comments, mostly tangential, including a grammar correction and remarks about card shuffling and AI assistance.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 34,
          "removed_lines": 0
        },
        {
          "observed_at": "2026-08-07T13:00:47Z",
          "window_start": "2026-08-07T10:45:07Z",
          "window_end": "2026-08-07T13:00:47Z",
          "status": "source-content",
          "summary": "Two new comments from brtastic: advice to read multiple dice in a fixed order to avoid bias, and a warning that letting AI write the seed-generation script can backfire.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 18,
          "removed_lines": 0
        }
      ]
    },
    {
      "id": "reddit-new-wallet-after-hack",
      "title": "r/Bitcoin: victim's post-hack multisig rebuild with a dice-generated seed",
      "url": "https://www.reddit.com/r/Bitcoin/comments/1vgw23z/new_wallet_after_coldcard_hack/",
      "organisation": "reddit",
      "kind": "community-discussion",
      "role": "Community discussion",
      "publication_time": null,
      "note": null,
      "gone": null,
      "capture": {
        "status": "held",
        "copies": 1,
        "first_observed": "2026-08-07T10:54:32Z",
        "last_observed": "2026-08-07T10:54:32Z",
        "last_checked": "2026-08-14T08:28:03Z"
      },
      "differences": []
    },
    {
      "id": "reddit-vendor-checklist",
      "title": "r/Bitcoin: a community checklist of minimum cold-storage vendor requirements",
      "url": "https://www.reddit.com/r/Bitcoin/comments/1vh6bq9/cold_storage_vendor_checklist_where_to_go_next/",
      "organisation": "reddit",
      "kind": "community-discussion",
      "role": "Community discussion",
      "publication_time": null,
      "note": null,
      "gone": null,
      "capture": {
        "status": "held",
        "copies": 2,
        "first_observed": "2026-08-07T10:54:37Z",
        "last_observed": "2026-08-09T05:31:23Z",
        "last_checked": "2026-08-10T02:12:36Z"
      },
      "differences": [
        {
          "observed_at": "2026-08-09T05:31:23Z",
          "window_start": "2026-08-07T10:54:37Z",
          "window_end": "2026-08-09T05:31:23Z",
          "status": "source-content",
          "summary": "Fields within an existing Reddit post or comment changed; the diff preserves the exact served text.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 2,
          "removed_lines": 2
        }
      ]
    },
    {
      "id": "reddit-not-an-ai-hack",
      "title": "r/Bitcoin: argument that the COLDCARD vulnerability was not found by AI",
      "url": "https://www.reddit.com/r/Bitcoin/comments/1vh60ct/its_not_an_ai_hack/",
      "organisation": "reddit",
      "kind": "community-discussion",
      "role": "Community discussion",
      "publication_time": null,
      "note": null,
      "gone": null,
      "capture": {
        "status": "held",
        "copies": 1,
        "first_observed": "2026-08-07T10:54:41Z",
        "last_observed": "2026-08-07T10:54:41Z",
        "last_checked": "2026-08-14T08:28:08Z"
      },
      "differences": []
    },
    {
      "id": "casa-rise-of-machines",
      "title": "The rise of the machines",
      "url": "https://blog.casa.io/the-rise-of-the-machines/",
      "organisation": "Casa",
      "kind": "analysis",
      "role": "Secondary analysis",
      "publication_time": "2026-08-06",
      "note": "Jameson Lopp's 6 August essay for Casa, and two things at once: a restatement\nof the incident for a general reader, and Casa's account of its own security\npractice. It argues that the economics of finding a vulnerability have inverted\nnow that a frontier model can read a large codebase cheaply, that a\npoint-in-time audit is \"a photograph, not a film\", and that the defect survived\nreview because it sat in build glue rather than in the cryptographic library\neveryone scrutinised. It then describes what Casa says it does: regular\nfull-scope external penetration tests, targeted audits before launch,\nevent-driven re-engagement, and an AI penetration-testing harness run against\nits own code. Casa is a custody provider with a commercial interest in the\ncomparison it draws, and its account of its own internal practice is not\nobservable from this archive. Its statement that researchers believe the\nvulnerability was most likely found by a frontier model is an attribution the\nrecord holds as contested; see the AI discovery material.\n",
      "gone": null,
      "capture": {
        "status": "held",
        "copies": 3,
        "first_observed": "2026-08-07T11:09:07Z",
        "last_observed": "2026-08-12T04:42:19Z",
        "last_checked": "2026-08-15T12:26:49Z"
      },
      "differences": [
        {
          "observed_at": "2026-08-12T04:42:19Z",
          "window_start": "2026-08-09T16:57:29Z",
          "window_end": "2026-08-12T04:42:19Z",
          "status": "capture-noise",
          "summary": "Only the article's relative age label and the adjacent newer-post navigation link changed.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 3,
          "removed_lines": 1
        },
        {
          "observed_at": "2026-08-09T16:57:29Z",
          "window_start": "2026-08-07T11:09:07Z",
          "window_end": "2026-08-09T16:57:29Z",
          "status": "capture-noise",
          "summary": "Only the relative timestamp on the Casa article rolled. The article body was unchanged.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 1,
          "removed_lines": 1
        }
      ]
    },
    {
      "id": "opensats-code-red",
      "title": "Code RED: priority support for red teaming",
      "url": "https://opensats.org/blog/code-red-supporting-first-responders",
      "organisation": "OpenSats",
      "kind": "org-statement",
      "role": "Organisation statement",
      "publication_time": "2026-08-06",
      "note": "OpenSats' own 6 August announcement, by Gigi and the organisation, that red\nteam applications will be prioritised for the foreseeable future, with a\ndedicated path at opensats.org/red and reimbursement of past LLM token costs.\nHeld as a funder changing what it pays for in response to the incident, which\nis a distinct kind of response from a statement about it: the same nonprofit is\nnamed in the held Red Team posts as covering their compute bill. OpenSats is a\nbitcoin funding nonprofit and NVK stepped down from its board on 2 August\n(opensats-nvk-board-departure); the post itself draws no connection. What is\ndisbursed under the policy is not observable from this archive.\n",
      "gone": null,
      "capture": {
        "status": "held",
        "copies": 2,
        "first_observed": "2026-08-07T11:34:59Z",
        "last_observed": "2026-08-08T15:07:51Z",
        "last_checked": "2026-08-15T12:26:50Z"
      },
      "differences": [
        {
          "observed_at": "2026-08-08T15:07:51Z",
          "window_start": "2026-08-07T11:34:59Z",
          "window_end": "2026-08-08T15:07:51Z",
          "status": "capture-noise",
          "summary": "Only the 'Next Post' navigation link and adjacent post title appeared below the announcement; the announcement text was unchanged.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 2,
          "removed_lines": 0
        }
      ]
    },
    {
      "id": "sparrow-pr-2047",
      "title": "Sparrow Wallet PR #2047: warn on COLDCARD device selection",
      "url": "https://github.com/sparrowwallet/sparrow/pull/2047",
      "organisation": "Sparrow",
      "kind": "repo-pr",
      "role": "Repository pull request",
      "publication_time": "2026-08-06",
      "note": "A third-party proposal in Sparrow Wallet to show an advisory warning when a\nuser selects a COLDCARD in the device flow, opened 6 Aug 2026 by nrobi144 and\napproved by skwp the same day. Held because wallet software warning its own\nusers is a distinct strand of the response from vendor advisories and upstream\nlibrary fixes: it puts the notice where a person is about to use the device.\nDetection keys on the exact COLDCARD wallet model, so subclassing importers do\nnot trigger it. The author states the change was drafted with LLM assistance\nand that he could not run a full local build.\n",
      "gone": null,
      "capture": {
        "status": "held",
        "copies": 3,
        "first_observed": "2026-08-07T11:35:13Z",
        "last_observed": "2026-08-14T08:28:16Z",
        "last_checked": "2026-08-15T12:26:52Z"
      },
      "differences": [
        {
          "observed_at": "2026-08-14T08:28:16Z",
          "window_start": "2026-08-12T04:42:28Z",
          "window_end": "2026-08-14T08:28:16Z",
          "status": "capture-noise",
          "summary": "Only GitHub header chrome changed. The 'Sign in' and 'Appearance settings' labels split onto separate lines, and the search prompt changed from 'Type / to search' to 'Search/'. The pull request content was unchanged.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 5,
          "removed_lines": 3
        },
        {
          "observed_at": "2026-08-12T04:42:28Z",
          "window_start": "2026-08-07T11:35:13Z",
          "window_end": "2026-08-12T04:42:28Z",
          "status": "source-content",
          "summary": "The pull request gained a follow-up comment clarifying which COLDCARD selection surfaces show the warning, and another comment proposing a load-time acknowledgment or MOTD feature.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 28,
          "removed_lines": 0
        }
      ]
    },
    {
      "id": "stackernews-trezor-cto-coldcard-hack",
      "title": "Trezor's CTO on the Cold Card Hack: Randomness, Trust, and What Comes Next",
      "url": "https://stacker.news/items/1542511",
      "organisation": "Stacker News",
      "kind": "community-discussion",
      "role": "Community discussion",
      "publication_time": "2026-08-07",
      "note": "efrat interviewing Trezor CTO Tomáš Sušánka days after the Coldcard hack, covering entropy, Trezor's RNG design, open-source review limits, and multisig. A vendor competitor's perspective on the incident and what comes next, alongside trezor-coldcard-not-affected. The claims are the speakers' own, not verified here. Captured through the site's public GraphQL API: the rendered pages crash the capture tab, and the API answers POST from this host. The query fixes the captured surface to the item's title, text and two levels of comments, each with author and absolute timestamp.\n",
      "gone": null,
      "capture": {
        "status": "held",
        "copies": 1,
        "first_observed": "2026-08-07T17:01:05Z",
        "last_observed": "2026-08-07T17:01:05Z",
        "last_checked": "2026-08-14T08:28:19Z"
      },
      "differences": []
    },
    {
      "id": "stackernews-exchange-loss-comparison",
      "title": "Bitcoin data lost on exchanges vs. Coldcard incident",
      "url": "https://stacker.news/items/1542179",
      "organisation": "Stacker News",
      "kind": "community-discussion",
      "role": "Community discussion",
      "publication_time": "2026-08-07",
      "note": "mkmloom comparing BTC lost through exchange failures and insolvencies against the Coldcard incident, claiming Coldcard accounted for 0.081% of the amount and arguing for diversification and self-custody. A community reframing of the incident's scale; the figures and comparison method are the poster's own, not verified here. Captured through the site's public GraphQL API: the rendered pages crash the capture tab, and the API answers POST from this host. The query fixes the captured surface to the item's title, text and two levels of comments, each with author and absolute timestamp.\n",
      "gone": null,
      "capture": {
        "status": "held",
        "copies": 2,
        "first_observed": "2026-08-07T17:01:07Z",
        "last_observed": "2026-08-07T19:34:49Z",
        "last_checked": "2026-08-14T08:28:21Z"
      },
      "differences": [
        {
          "observed_at": "2026-08-07T19:34:49Z",
          "window_start": "2026-08-07T17:01:07Z",
          "window_end": "2026-08-07T19:34:49Z",
          "status": "capture-noise",
          "summary": "Only the order of existing comments changed; their text and timestamps were unchanged.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 7,
          "removed_lines": 7
        }
      ]
    },
    {
      "id": "stackernews-coldcard-correction-fallback",
      "title": "Coldcard issues \"extremely important correction\"",
      "url": "https://stacker.news/items/1542079",
      "organisation": "Stacker News",
      "kind": "community-discussion",
      "role": "Community discussion",
      "publication_time": "2026-08-07",
      "note": "Scoresby relaying and critiquing Coinkite's public correction to Jack Mallers, in which the vendor says the weak PRNG was not an intentional fallback but inherited behaviour from MicroPython that became active because of a link-time error. Preserves a key moment in the vendor-response narrative; the quoted correction is Coinkite's statement and Scoresby's framing is the poster's own. Captured through the site's public GraphQL API: the rendered pages crash the capture tab, and the API answers POST from this host. The query fixes the captured surface to the item's title, text and two levels of comments, each with author and absolute timestamp.\n",
      "gone": null,
      "capture": {
        "status": "held",
        "copies": 1,
        "first_observed": "2026-08-07T17:01:08Z",
        "last_observed": "2026-08-07T17:01:08Z",
        "last_checked": "2026-08-14T08:28:24Z"
      },
      "differences": []
    },
    {
      "id": "reddit-fake-trezor-google-ad",
      "title": "r/Bitcoin: Trezor user loses life savings to a fake Google-sponsored Trezor website",
      "url": "https://www.reddit.com/r/Bitcoin/comments/1vi2jv0/trezor_user_loses_life_savings_by_entering_their/",
      "organisation": "reddit",
      "kind": "community-discussion",
      "role": "Community discussion",
      "publication_time": null,
      "note": null,
      "gone": null,
      "capture": {
        "status": "held",
        "copies": 10,
        "first_observed": "2026-08-07T17:01:10Z",
        "last_observed": "2026-08-12T04:42:53Z",
        "last_checked": "2026-08-14T08:28:26Z"
      },
      "differences": [
        {
          "observed_at": "2026-08-12T04:42:53Z",
          "window_start": "2026-08-09T23:27:38Z",
          "window_end": "2026-08-12T04:42:53Z",
          "status": "source-content",
          "summary": "The thread gained comments about trusting Coinbase, buying a new hardware wallet, search-engine phishing, and a reported 160k loss.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 40,
          "removed_lines": 10
        },
        {
          "observed_at": "2026-08-09T23:27:38Z",
          "window_start": "2026-08-09T10:40:26Z",
          "window_end": "2026-08-09T23:27:38Z",
          "status": "source-content",
          "summary": "The thread gained comments about scams targeting Bitcoin users, a seed-typing rule for cold-wallet beginners, and platform liability for scam advertising.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 28,
          "removed_lines": 0
        },
        {
          "observed_at": "2026-08-09T10:40:26Z",
          "window_start": "2026-08-09T04:10:34Z",
          "window_end": "2026-08-09T10:40:26Z",
          "status": "source-content",
          "summary": "One existing comment was deleted and the thread gained three new comments about sponsored-link scams, near-misses, and reactions.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 28,
          "removed_lines": 4
        },
        {
          "observed_at": "2026-08-09T04:10:34Z",
          "window_start": "2026-08-08T21:37:58Z",
          "window_end": "2026-08-09T04:10:34Z",
          "status": "source-content",
          "summary": "The thread gained several new comments about scam ads on YouTube and Bing, hardware wallet loss, and why victims enter seeds into websites.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 64,
          "removed_lines": 0
        },
        {
          "observed_at": "2026-08-08T21:37:58Z",
          "window_start": "2026-08-08T15:08:03Z",
          "window_end": "2026-08-08T21:37:58Z",
          "status": "source-content",
          "summary": "The thread gained several new participant comments and lost one empty or removed comment record.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 50,
          "removed_lines": 8
        },
        {
          "observed_at": "2026-08-08T15:08:03Z",
          "window_start": "2026-08-08T08:37:13Z",
          "window_end": "2026-08-08T15:08:03Z",
          "status": "source-content",
          "summary": "A comment about Google's ability to detect malicious ad changes was removed, and new replies were added about PGP verification, Google's ad complicity, and Trezor's X response.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 78,
          "removed_lines": 10
        },
        {
          "observed_at": "2026-08-08T08:37:13Z",
          "window_start": "2026-08-08T02:05:11Z",
          "window_end": "2026-08-08T08:37:13Z",
          "status": "source-content",
          "summary": "The original post was edited to add a possessive apostrophe in 'google's', and the thread gained several new participant comments about phishing, scams and hardware wallet recovery.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 81,
          "removed_lines": 3
        },
        {
          "observed_at": "2026-08-08T02:05:11Z",
          "window_start": "2026-08-07T19:34:54Z",
          "window_end": "2026-08-08T02:05:11Z",
          "status": "source-content",
          "summary": "Two comments in an off-topic exchange were self-deleted, author and body now reading [deleted] and [removed], and a third reply to one of them is no longer served. The prior capture preserves all three.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 501,
          "removed_lines": 40
        },
        {
          "observed_at": "2026-08-07T19:34:54Z",
          "window_start": "2026-08-07T17:01:10Z",
          "window_end": "2026-08-07T19:34:54Z",
          "status": "source-content",
          "summary": "The thread gained new comments about Google-sponsored scam ads, a reported scam-wallet address, and whether self-custody users were reckless, alongside author deletions of earlier comments.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 401,
          "removed_lines": 4
        }
      ]
    },
    {
      "id": "reddit-dice-bias-1200-rolls",
      "title": "r/Bitcoin: 1200 dice rolls testing bias in ordinary board-game dice",
      "url": "https://www.reddit.com/r/Bitcoin/comments/1vi20y9/i_did_1200_dice_rolls_to_check_for_bias_in/",
      "organisation": "reddit",
      "kind": "community-discussion",
      "role": "Community discussion",
      "publication_time": null,
      "note": null,
      "gone": null,
      "capture": {
        "status": "held",
        "copies": 11,
        "first_observed": "2026-08-07T17:01:15Z",
        "last_observed": "2026-08-12T17:30:34Z",
        "last_checked": "2026-08-14T08:28:32Z"
      },
      "differences": [
        {
          "observed_at": "2026-08-12T17:30:34Z",
          "window_start": "2026-08-12T11:00:20Z",
          "window_end": "2026-08-12T17:30:34Z",
          "status": "source-content",
          "summary": "A comment from a since-deleted account was removed; it had argued that theoretical predictability is information and therefore decreases entropy.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 0,
          "removed_lines": 9
        },
        {
          "observed_at": "2026-08-12T11:00:20Z",
          "window_start": "2026-08-12T04:43:02Z",
          "window_end": "2026-08-12T11:00:20Z",
          "status": "source-content",
          "summary": "Two comments by OddBritishMan on dice technique and seed generation were removed, and another comment author changed to [deleted].",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 1,
          "removed_lines": 21
        },
        {
          "observed_at": "2026-08-12T04:43:02Z",
          "window_start": "2026-08-09T23:27:42Z",
          "window_end": "2026-08-12T04:43:02Z",
          "status": "source-content",
          "summary": "The thread gained a reply discussing why casino dice are rolled openly and noting that even a significant bias would cost little entropy.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 12,
          "removed_lines": 0
        },
        {
          "observed_at": "2026-08-09T23:27:42Z",
          "window_start": "2026-08-09T04:10:40Z",
          "window_end": "2026-08-09T23:27:42Z",
          "status": "source-content",
          "summary": "The author edited the post to clarify they do not support Coldcard and to defend dice rolls as a practical source of entropy.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 16,
          "removed_lines": 1
        },
        {
          "observed_at": "2026-08-09T04:10:40Z",
          "window_start": "2026-08-08T21:38:03Z",
          "window_end": "2026-08-09T04:10:40Z",
          "status": "source-content",
          "summary": "A new comment questioned why ordinary board-game dice would suffice against determined attackers when casinos pay a premium for controlled dice.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 8,
          "removed_lines": 0
        },
        {
          "observed_at": "2026-08-08T21:38:03Z",
          "window_start": "2026-08-08T15:08:08Z",
          "window_end": "2026-08-08T21:38:03Z",
          "status": "source-content",
          "summary": "The thread gained new comments arguing that ordinary dice bias has little effect on seed entropy and that SHA-256 hashing destroys patterns.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 58,
          "removed_lines": 0
        },
        {
          "observed_at": "2026-08-08T15:08:08Z",
          "window_start": "2026-08-08T08:37:18Z",
          "window_end": "2026-08-08T15:08:08Z",
          "status": "source-content",
          "summary": "The thread gained new replies discussing whether bias decreases entropy, the role of cup-shaking in mixing dice, and the resilience of a 24-word seed to biased coin flips.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 25,
          "removed_lines": 0
        },
        {
          "observed_at": "2026-08-08T08:37:18Z",
          "window_start": "2026-08-08T02:05:17Z",
          "window_end": "2026-08-08T08:37:18Z",
          "status": "source-content",
          "summary": "The Reddit thread gained several new participant comments about sample size, the Ian Coleman tool, /dev/random, dice-rolling technique and multisig as mitigation.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 79,
          "removed_lines": 0
        },
        {
          "observed_at": "2026-08-08T02:05:17Z",
          "window_start": "2026-08-07T19:35:00Z",
          "window_end": "2026-08-08T02:05:17Z",
          "status": "source-content",
          "summary": "The thread gained a substantial run of new comments on how to turn dice into entropy, including maidalit proposing that discarding rolls of 1 and 6 yields two binary digits per roll, with a self-edit correcting an earlier claim of four and noting the third of rolls discarded, and stanley_fatmax offering thrown toothpicks as an alternative source. The arithmetic is the posters' own and is not checked here.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 137,
          "removed_lines": 2
        },
        {
          "observed_at": "2026-08-07T19:35:00Z",
          "window_start": "2026-08-07T17:01:15Z",
          "window_end": "2026-08-07T19:35:00Z",
          "status": "source-content",
          "summary": "The original poster edited their method note and the thread gained new comments about dice bias, entropy requirements, and whether bias is exploitable without knowing the dice used.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 186,
          "removed_lines": 3
        }
      ]
    },
    {
      "id": "reddit-multisig-passphrase-debate",
      "title": "r/Bitcoin: multisig versus single-sig with passphrase after the Coldcard issue",
      "url": "https://www.reddit.com/r/Bitcoin/comments/1vhv4j0/following_the_coldcard_issue_still_debating/",
      "organisation": "reddit",
      "kind": "community-discussion",
      "role": "Community discussion",
      "publication_time": null,
      "note": null,
      "gone": null,
      "capture": {
        "status": "held",
        "copies": 1,
        "first_observed": "2026-08-08T05:02:37Z",
        "last_observed": "2026-08-08T05:02:37Z",
        "last_checked": "2026-08-14T23:43:52Z"
      },
      "differences": []
    },
    {
      "id": "reddit-dice-seed-mistakes",
      "title": "r/Bitcoin: common mistakes when generating a 24-word BIP39 seed with dice",
      "url": "https://www.reddit.com/r/Bitcoin/comments/1vhu1e7/how_easy_is_it_to_make_a_serious_mistake_when/",
      "organisation": "reddit",
      "kind": "community-discussion",
      "role": "Community discussion",
      "publication_time": null,
      "note": null,
      "gone": null,
      "capture": {
        "status": "held",
        "copies": 3,
        "first_observed": "2026-08-08T05:02:42Z",
        "last_observed": "2026-08-09T04:10:50Z",
        "last_checked": "2026-08-14T23:43:57Z"
      },
      "differences": [
        {
          "observed_at": "2026-08-09T04:10:50Z",
          "window_start": "2026-08-08T15:08:16Z",
          "window_end": "2026-08-09T04:10:50Z",
          "status": "source-content",
          "summary": "The thread gained a single emoji reaction comment.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 8,
          "removed_lines": 0
        },
        {
          "observed_at": "2026-08-08T15:08:16Z",
          "window_start": "2026-08-08T05:02:42Z",
          "window_end": "2026-08-08T15:08:16Z",
          "status": "source-content",
          "summary": "The thread gained a short joke exchange about the temperature scale used during seed generation.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 18,
          "removed_lines": 0
        }
      ]
    },
    {
      "id": "reddit-audit-cold-wallets-ai",
      "title": "r/Bitcoin: auditing cold-wallet code with AI instead of relying on dice entropy",
      "url": "https://www.reddit.com/r/Bitcoin/comments/1vhsp5a/audit_of_cold_wallets/",
      "organisation": "reddit",
      "kind": "community-discussion",
      "role": "Community discussion",
      "publication_time": null,
      "note": null,
      "gone": null,
      "capture": {
        "status": "held",
        "copies": 2,
        "first_observed": "2026-08-08T05:02:46Z",
        "last_observed": "2026-08-12T04:43:18Z",
        "last_checked": "2026-08-14T23:44:01Z"
      },
      "differences": [
        {
          "observed_at": "2026-08-12T04:43:18Z",
          "window_start": "2026-08-08T05:02:46Z",
          "window_end": "2026-08-12T04:43:18Z",
          "status": "source-content",
          "summary": "The thread gained a comment describing COLDCARD firmware reproducible builds and another comment suggesting wallets with two independent randomness sources.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 20,
          "removed_lines": 0
        }
      ]
    },
    {
      "id": "reddit-passphrase-entropy-ten-char",
      "title": "r/Bitcoin: whether a 10-character passphrase is enough after the Coldcard incident",
      "url": "https://www.reddit.com/r/Bitcoin/comments/1vhux2b/is_my_understanding_of_the_security_of_a_25th/",
      "organisation": "reddit",
      "kind": "community-discussion",
      "role": "Community discussion",
      "publication_time": null,
      "note": null,
      "gone": null,
      "capture": {
        "status": "held",
        "copies": 2,
        "first_observed": "2026-08-08T05:02:50Z",
        "last_observed": "2026-08-09T18:48:51Z",
        "last_checked": "2026-08-10T21:20:14Z"
      },
      "differences": [
        {
          "observed_at": "2026-08-09T18:48:51Z",
          "window_start": "2026-08-08T05:02:50Z",
          "window_end": "2026-08-09T18:48:51Z",
          "status": "source-content",
          "summary": "Reddit served 2 additional comment record(s); the diff preserves their text and any edits to existing records.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 18,
          "removed_lines": 0
        }
      ]
    },
    {
      "id": "reddit-mix-entropy-methods",
      "title": "r/Bitcoin: generating a seed by mixing multiple entropy methods",
      "url": "https://www.reddit.com/r/Bitcoin/comments/1vi0rka/generating_a_seed_phrase_by_mixing_entropy_methods/",
      "organisation": "reddit",
      "kind": "community-discussion",
      "role": "Community discussion",
      "publication_time": null,
      "note": null,
      "gone": null,
      "capture": {
        "status": "held",
        "copies": 2,
        "first_observed": "2026-08-08T05:02:53Z",
        "last_observed": "2026-08-09T00:29:06Z",
        "last_checked": "2026-08-10T21:21:17Z"
      },
      "differences": [
        {
          "observed_at": "2026-08-09T00:29:06Z",
          "window_start": "2026-08-08T05:02:53Z",
          "window_end": "2026-08-09T00:29:06Z",
          "status": "source-content",
          "summary": "Reddit served 1 previously held comment record(s) omitted; the diff preserves their text and any edits to existing records.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 0,
          "removed_lines": 8
        }
      ]
    },
    {
      "id": "reddit-fidelity-custody-debate",
      "title": "r/Bitcoin: considering Fidelity crypto custody after the Coldcard incident",
      "url": "https://www.reddit.com/r/Bitcoin/comments/1viix1b/fidelity_crypo_account_custodial_convince_me/",
      "organisation": "reddit",
      "kind": "community-discussion",
      "role": "Community discussion",
      "publication_time": null,
      "note": null,
      "gone": null,
      "capture": {
        "status": "held",
        "copies": 7,
        "first_observed": "2026-08-08T05:02:57Z",
        "last_observed": "2026-08-12T04:43:25Z",
        "last_checked": "2026-08-14T23:44:06Z"
      },
      "differences": [
        {
          "observed_at": "2026-08-12T04:43:25Z",
          "window_start": "2026-08-09T23:27:56Z",
          "window_end": "2026-08-12T04:43:25Z",
          "status": "source-content",
          "summary": "Two earlier comments were redacted as [deleted] or [removed], and a new participant added replies about Fidelity, seed generation, SeedSigner and wallet backups.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 52,
          "removed_lines": 4
        },
        {
          "observed_at": "2026-08-09T23:27:56Z",
          "window_start": "2026-08-09T04:11:00Z",
          "window_end": "2026-08-09T23:27:56Z",
          "status": "source-content",
          "summary": "The thread gained a comment arguing that Fidelity custody gives the institution control over the bitcoin.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 8,
          "removed_lines": 0
        },
        {
          "observed_at": "2026-08-09T04:11:00Z",
          "window_start": "2026-08-08T21:38:17Z",
          "window_end": "2026-08-09T04:11:00Z",
          "status": "source-content",
          "summary": "The thread gained several new replies discussing Fidelity crypto custody, inheritance, and whether a user-supplied seed still makes a Coldcard usable.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 62,
          "removed_lines": 0
        },
        {
          "observed_at": "2026-08-08T21:38:17Z",
          "window_start": "2026-08-08T15:08:22Z",
          "window_end": "2026-08-08T21:38:17Z",
          "status": "source-content",
          "summary": "The thread gained new comments discussing Fidelity Crypto, self-custody suitability and a report that the author moved one third of their holdings to Fidelity.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 76,
          "removed_lines": 0
        },
        {
          "observed_at": "2026-08-08T15:08:22Z",
          "window_start": "2026-08-08T08:37:33Z",
          "window_end": "2026-08-08T15:08:22Z",
          "status": "source-content",
          "summary": "The thread gained new replies debating hardware-wallet vulnerability, Fidelity's custody promise and delayed-withdrawal protections, and whether bitcoin transfers are available.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 76,
          "removed_lines": 0
        },
        {
          "observed_at": "2026-08-08T08:37:33Z",
          "window_start": "2026-08-08T05:02:57Z",
          "window_end": "2026-08-08T08:37:33Z",
          "status": "source-content",
          "summary": "The Reddit thread gained new comments discussing Fidelity crypto custody, Onramp multisig, withdrawal limits, insurance claims and hardware-wallet reliability.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 76,
          "removed_lines": 0
        }
      ]
    },
    {
      "id": "coindesk-70m-no-device-touch",
      "title": "How bitcoin cold wallets lost $70 million in an attack that never touched the devices",
      "url": "https://www.coindesk.com/tech/2026/08/01/how-bitcoin-cold-wallets-lost-usd70-million-in-an-attack-that-never-touched-the-devices",
      "organisation": "CoinDesk",
      "kind": "reporting",
      "role": "Reporting",
      "publication_time": "2026-08-01",
      "note": "CoinDesk's 1 August report on the COLDCARD entropy incident, cited by the\ncoldcard-hack-tracker community monitor. Held as a dated press account of the\ndrain and the devices-not-touched framing. The figures and attribution are the\noutlet's own, not verified here.\n",
      "gone": null,
      "capture": {
        "status": "held",
        "copies": 18,
        "first_observed": "2026-08-08T18:28:48Z",
        "last_observed": "2026-08-15T12:26:55Z",
        "last_checked": "2026-08-15T12:26:55Z"
      },
      "differences": [
        {
          "observed_at": "2026-08-15T12:26:55Z",
          "window_start": "2026-08-15T05:56:16Z",
          "window_end": "2026-08-15T12:26:55Z",
          "status": "capture-noise",
          "summary": "Only the article's relative-time labels and the live cryptocurrency ticker values in the site navigation changed.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 11,
          "removed_lines": 12
        },
        {
          "observed_at": "2026-08-15T05:56:16Z",
          "window_start": "2026-08-14T23:44:12Z",
          "window_end": "2026-08-15T05:56:16Z",
          "status": "capture-noise",
          "summary": "Only rotating related-content cards, live cryptocurrency ticker values and relative-time labels changed; the incident article text was unchanged.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 23,
          "removed_lines": 22
        },
        {
          "observed_at": "2026-08-14T23:44:12Z",
          "window_start": "2026-08-14T08:28:57Z",
          "window_end": "2026-08-14T23:44:12Z",
          "status": "capture-noise",
          "summary": "Only rotating related-news headlines and live market-ticker values changed; the incident article text was unchanged.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 23,
          "removed_lines": 23
        },
        {
          "observed_at": "2026-08-14T08:28:57Z",
          "window_start": "2026-08-14T01:57:59Z",
          "window_end": "2026-08-14T08:28:57Z",
          "status": "capture-noise",
          "summary": "Only relative-time labels, live cryptocurrency ticker values, and rotating related-content headlines changed. The article body was unchanged.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 21,
          "removed_lines": 21
        },
        {
          "observed_at": "2026-08-14T01:57:59Z",
          "window_start": "2026-08-13T19:29:05Z",
          "window_end": "2026-08-14T01:57:59Z",
          "status": "capture-noise",
          "summary": "Only the rotating Latest Crypto News headlines and the live cryptocurrency ticker footer changed; the article text was unchanged.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 24,
          "removed_lines": 24
        },
        {
          "observed_at": "2026-08-13T19:29:05Z",
          "window_start": "2026-08-13T12:57:32Z",
          "window_end": "2026-08-13T19:29:05Z",
          "status": "capture-noise",
          "summary": "Only the rotating related-content headline list and live cryptocurrency ticker values in the site chrome changed; the article text was unchanged.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 30,
          "removed_lines": 30
        },
        {
          "observed_at": "2026-08-13T12:57:32Z",
          "window_start": "2026-08-13T06:28:32Z",
          "window_end": "2026-08-13T12:57:32Z",
          "status": "capture-noise",
          "summary": "Only rotating related-story headlines, live cryptocurrency ticker values and relative-time labels in the site chrome changed; the article body was unchanged.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 25,
          "removed_lines": 25
        },
        {
          "observed_at": "2026-08-13T06:28:32Z",
          "window_start": "2026-08-12T23:59:17Z",
          "window_end": "2026-08-13T06:28:32Z",
          "status": "capture-noise",
          "summary": "Only the rotating Latest Crypto News headlines, their relative timestamps and live cryptocurrency ticker values changed; the article text was unchanged.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 24,
          "removed_lines": 24
        },
        {
          "observed_at": "2026-08-12T23:59:17Z",
          "window_start": "2026-08-12T17:31:01Z",
          "window_end": "2026-08-12T23:59:17Z",
          "status": "capture-noise",
          "summary": "Only the rotating Latest Crypto News headlines, their relative ages, and the live cryptocurrency ticker footer changed; the incident article text was unchanged.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 26,
          "removed_lines": 26
        },
        {
          "observed_at": "2026-08-12T17:31:01Z",
          "window_start": "2026-08-12T11:00:44Z",
          "window_end": "2026-08-12T17:31:01Z",
          "status": "capture-noise",
          "summary": "Only rotating related-story cards, live cryptocurrency ticker values and relative-time labels changed; the article text was unchanged.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 21,
          "removed_lines": 21
        },
        {
          "observed_at": "2026-08-12T11:00:44Z",
          "window_start": "2026-08-12T04:43:37Z",
          "window_end": "2026-08-12T11:00:44Z",
          "status": "capture-noise",
          "summary": "Only relative timestamps, rotating related-story headlines, and the live crypto price ticker changed; the article text was unchanged.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 27,
          "removed_lines": 27
        },
        {
          "observed_at": "2026-08-12T04:43:37Z",
          "window_start": "2026-08-09T23:28:00Z",
          "window_end": "2026-08-12T04:43:37Z",
          "status": "capture-noise",
          "summary": "Only relative-time labels, rotating related-story headlines and live cryptocurrency ticker values changed.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 27,
          "removed_lines": 25
        },
        {
          "observed_at": "2026-08-09T23:28:00Z",
          "window_start": "2026-08-09T16:59:05Z",
          "window_end": "2026-08-09T23:28:00Z",
          "status": "capture-noise",
          "summary": "Only the rotating latest-news list and live market-ticker values changed; the article text was unchanged.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 18,
          "removed_lines": 18
        },
        {
          "observed_at": "2026-08-09T16:59:05Z",
          "window_start": "2026-08-09T10:40:58Z",
          "window_end": "2026-08-09T16:59:05Z",
          "status": "capture-noise",
          "summary": "Only rotating related-news headlines, relative timestamps, and live cryptocurrency ticker values changed. The article body was unchanged.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 18,
          "removed_lines": 18
        },
        {
          "observed_at": "2026-08-09T10:40:58Z",
          "window_start": "2026-08-09T04:11:05Z",
          "window_end": "2026-08-09T10:40:58Z",
          "status": "capture-noise",
          "summary": "Only relative timestamps, live cryptocurrency ticker values, and rotating related-story cards changed; the article text was unchanged.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 21,
          "removed_lines": 21
        },
        {
          "observed_at": "2026-08-09T04:11:05Z",
          "window_start": "2026-08-08T21:38:20Z",
          "window_end": "2026-08-09T04:11:05Z",
          "status": "capture-noise",
          "summary": "Only relative timestamps and live cryptocurrency ticker values in the page chrome changed; the article text was unchanged.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 10,
          "removed_lines": 10
        },
        {
          "observed_at": "2026-08-08T21:38:20Z",
          "window_start": "2026-08-08T18:28:48Z",
          "window_end": "2026-08-08T21:38:20Z",
          "status": "capture-noise",
          "summary": "Only rotating related-story ages, live market tickers and site navigation chrome changed.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 21,
          "removed_lines": 21
        }
      ]
    },
    {
      "id": "chainabuse-e568bed8",
      "title": "Chainabuse victim report e568bed8",
      "url": "https://chainabuse.com/report/e568bed8-62f8-46b8-aae6-4d271c8d63e0",
      "organisation": "Chainabuse",
      "kind": "primary-data",
      "role": "Source",
      "publication_time": "2026-08-05",
      "note": "First-hand victim report cited by the coldcard-hack-tracker community monitor as wave evidence. Registered under the operator's 8 August decision that author-published first-hand victim material is registerable. The claims are the reporter's own and are not verified here.",
      "gone": null,
      "capture": {
        "status": "held",
        "copies": 1,
        "first_observed": "2026-08-08T18:39:59Z",
        "last_observed": "2026-08-08T18:39:59Z",
        "last_checked": "2026-08-08T18:39:59Z"
      },
      "differences": []
    },
    {
      "id": "chainabuse-d4c95fab",
      "title": "Chainabuse victim report d4c95fab",
      "url": "https://chainabuse.com/report/d4c95fab-ed8e-4749-ae81-9d42bfdab1cb",
      "organisation": "Chainabuse",
      "kind": "primary-data",
      "role": "Source",
      "publication_time": "2026-08-05",
      "note": "First-hand victim report cited by the coldcard-hack-tracker community monitor as wave evidence. Registered under the operator's 8 August decision that author-published first-hand victim material is registerable. The claims are the reporter's own and are not verified here.",
      "gone": null,
      "capture": {
        "status": "held",
        "copies": 1,
        "first_observed": "2026-08-08T18:40:28Z",
        "last_observed": "2026-08-08T18:40:28Z",
        "last_checked": "2026-08-08T18:40:28Z"
      },
      "differences": []
    },
    {
      "id": "chainabuse-0f8d1d1c",
      "title": "Chainabuse victim report 0f8d1d1c",
      "url": "https://chainabuse.com/report/0f8d1d1c-556b-40e6-a819-c91c153497aa",
      "organisation": "Chainabuse",
      "kind": "primary-data",
      "role": "Source",
      "publication_time": "2026-08-05",
      "note": "First-hand victim report cited by the coldcard-hack-tracker community monitor as wave evidence. Registered under the operator's 8 August decision that author-published first-hand victim material is registerable. The claims are the reporter's own and are not verified here.",
      "gone": null,
      "capture": {
        "status": "held",
        "copies": 1,
        "first_observed": "2026-08-08T18:40:39Z",
        "last_observed": "2026-08-08T18:40:39Z",
        "last_checked": "2026-08-08T18:40:39Z"
      },
      "differences": []
    },
    {
      "id": "chainabuse-2727f906",
      "title": "Chainabuse victim report 2727f906",
      "url": "https://chainabuse.com/report/2727f906-bf8f-4540-92e4-ad4fd5b59cbf",
      "organisation": "Chainabuse",
      "kind": "primary-data",
      "role": "Source",
      "publication_time": "2026-08-05",
      "note": "First-hand victim report cited by the coldcard-hack-tracker community monitor as wave evidence. Registered under the operator's 8 August decision that author-published first-hand victim material is registerable. The claims are the reporter's own and are not verified here.",
      "gone": null,
      "capture": {
        "status": "held",
        "copies": 1,
        "first_observed": "2026-08-08T18:40:49Z",
        "last_observed": "2026-08-08T18:40:49Z",
        "last_checked": "2026-08-08T18:40:49Z"
      },
      "differences": []
    },
    {
      "id": "chainabuse-6e9fa34a",
      "title": "Chainabuse victim report 6e9fa34a",
      "url": "https://chainabuse.com/report/6e9fa34a-6128-4b9b-9ef9-8cc4159b1935",
      "organisation": "Chainabuse",
      "kind": "primary-data",
      "role": "Source",
      "publication_time": "2026-08-05",
      "note": "First-hand victim report cited by the coldcard-hack-tracker community monitor as wave evidence. Registered under the operator's 8 August decision that author-published first-hand victim material is registerable. The claims are the reporter's own and are not verified here.",
      "gone": null,
      "capture": {
        "status": "held",
        "copies": 1,
        "first_observed": "2026-08-08T18:41:01Z",
        "last_observed": "2026-08-08T18:41:01Z",
        "last_checked": "2026-08-08T18:41:01Z"
      },
      "differences": []
    },
    {
      "id": "chainabuse-61e7b80a",
      "title": "Chainabuse victim report 61e7b80a",
      "url": "https://chainabuse.com/report/61e7b80a-4ec6-42b4-a8b4-4cab1a29c9ac",
      "organisation": "Chainabuse",
      "kind": "primary-data",
      "role": "Source",
      "publication_time": "2026-08-05",
      "note": "First-hand victim report cited by the coldcard-hack-tracker community monitor as wave evidence. Registered under the operator's 8 August decision that author-published first-hand victim material is registerable. The claims are the reporter's own and are not verified here.",
      "gone": null,
      "capture": {
        "status": "held",
        "copies": 1,
        "first_observed": "2026-08-08T18:41:11Z",
        "last_observed": "2026-08-08T18:41:11Z",
        "last_checked": "2026-08-08T18:41:11Z"
      },
      "differences": []
    },
    {
      "id": "chainabuse-6e9ac9f1",
      "title": "Chainabuse victim report 6e9ac9f1",
      "url": "https://chainabuse.com/report/6e9ac9f1-61e5-49c5-947c-062afc70b73b",
      "organisation": "Chainabuse",
      "kind": "primary-data",
      "role": "Source",
      "publication_time": "2026-08-05",
      "note": "First-hand victim report cited by the coldcard-hack-tracker community monitor as wave evidence. Registered under the operator's 8 August decision that author-published first-hand victim material is registerable. The claims are the reporter's own and are not verified here.",
      "gone": null,
      "capture": {
        "status": "held",
        "copies": 1,
        "first_observed": "2026-08-08T18:41:21Z",
        "last_observed": "2026-08-08T18:41:21Z",
        "last_checked": "2026-08-08T18:41:21Z"
      },
      "differences": []
    },
    {
      "id": "reddit-dice-rolls-saved-seedsigner",
      "title": "r/Bitcoin: dice rolls saved a stack, now moving to SeedSigner",
      "url": "https://www.reddit.com/r/Bitcoin/comments/1vie1vy/dice_rolls_saved_me_but/",
      "organisation": "reddit",
      "kind": "community-discussion",
      "role": "Community discussion",
      "publication_time": null,
      "note": null,
      "gone": null,
      "capture": {
        "status": "held",
        "copies": 7,
        "first_observed": "2026-08-08T18:29:13Z",
        "last_observed": "2026-08-14T23:44:15Z",
        "last_checked": "2026-08-15T12:26:57Z"
      },
      "differences": [
        {
          "observed_at": "2026-08-14T23:44:15Z",
          "window_start": "2026-08-12T04:43:48Z",
          "window_end": "2026-08-14T23:44:15Z",
          "status": "source-content",
          "summary": "The thread gained a reply advising against reusing part of the old seed as a new passphrase, recommending an independently generated strong passphrase, SeedQR handling, and recovery verification before funding.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 11,
          "removed_lines": 0
        },
        {
          "observed_at": "2026-08-12T04:43:48Z",
          "window_start": "2026-08-09T23:28:03Z",
          "window_end": "2026-08-12T04:43:48Z",
          "status": "source-content",
          "summary": "The original post was edited to correct 'seize' to 'cease', and the thread gained comments about multisig practice, testnet setup, and alternatives to casino dice for generating entropy.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 85,
          "removed_lines": 3
        },
        {
          "observed_at": "2026-08-09T23:28:03Z",
          "window_start": "2026-08-09T10:41:01Z",
          "window_end": "2026-08-09T23:28:03Z",
          "status": "source-content",
          "summary": "The thread gained a reply arguing that relying on a single network device is nonsensical and that the user wants something tested against all possibilities.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 8,
          "removed_lines": 0
        },
        {
          "observed_at": "2026-08-09T10:41:01Z",
          "window_start": "2026-08-09T04:11:07Z",
          "window_end": "2026-08-09T10:41:01Z",
          "status": "source-content",
          "summary": "A new reply notes that Coldcard would have been trusted just over a week ago.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 8,
          "removed_lines": 0
        },
        {
          "observed_at": "2026-08-09T04:11:07Z",
          "window_start": "2026-08-08T21:38:23Z",
          "window_end": "2026-08-09T04:11:07Z",
          "status": "source-content",
          "summary": "A new reply argues multisig is preferable to a passphrase for recovery, physical-coercion resistance, and inheritance planning.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 19,
          "removed_lines": 0
        },
        {
          "observed_at": "2026-08-08T21:38:23Z",
          "window_start": "2026-08-08T18:29:13Z",
          "window_end": "2026-08-08T21:38:23Z",
          "status": "source-content",
          "summary": "The thread gained new comments from users who used dice-generated seeds and were planning SeedSigner or multisig setups.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 16,
          "removed_lines": 0
        }
      ]
    },
    {
      "id": "bloomberg-crypto-sleuths",
      "title": "Bloomberg Crypto: Bitcoin Sleuths Are Going Sleepless After Coldcard Wallet Hack",
      "url": "https://www.bloomberg.com/news/newsletters/2026-08-06/bitcoin-sleuths-are-going-sleepless-after-coldcard-wallet-hack",
      "organisation": "Bloomberg",
      "kind": "reporting",
      "role": "Reporting",
      "publication_time": "2026-08-06",
      "note": "Ben Weiss's Bloomberg Crypto newsletter on the incident-response effort: Alex Thorn and Galaxy, Robert Hamilton and AnchorWatch, and the wider volunteer researcher community. Paywalled; the free portion is held and the four screenshots attached to @intangiblecoins' 6 Aug post (intangiblecoins-2085506256656023720) carry further passages.",
      "gone": null,
      "capture": {
        "status": "held",
        "copies": 1,
        "first_observed": "2026-08-09T01:24:13Z",
        "last_observed": "2026-08-09T01:24:13Z",
        "last_checked": "2026-08-09T01:24:13Z"
      },
      "differences": []
    },
    {
      "id": "lukechilds-anzen-trilemma",
      "title": "Anzen and the self-custody trilemma",
      "url": "https://lu.ke/self-custody-trilemma",
      "organisation": "Luke Childs",
      "kind": "analysis",
      "role": "Secondary analysis",
      "publication_time": "2026-08-09",
      "note": "Luke Childs publishes a writeup on Anzen, a wallet design presented as a response\nto Bitcoin's self-custody trilemma in the wake of the COLDCARD incident. Held as\na dated product launch and design argument from the author. The claims about the\ndesign and its properties are the author's own and are not verified here.\n",
      "gone": null,
      "capture": {
        "status": "held",
        "copies": 1,
        "first_observed": "2026-08-09T02:05:09Z",
        "last_observed": "2026-08-09T02:05:09Z",
        "last_checked": "2026-08-15T12:56:46Z"
      },
      "differences": []
    },
    {
      "id": "citadel21-paranoid-wallet",
      "title": "The Paranoid Wallet",
      "url": "https://www.citadel21.com/the-paranoid-wallet",
      "organisation": "Citadel21",
      "kind": "analysis",
      "role": "Secondary analysis",
      "publication_time": "2026-08-09",
      "note": "Citadel21 publishes an article titled The Paranoid Wallet, discussing wallet\ndesign in the context of the COLDCARD entropy incident. Held as a dated\ncommentary on post-incident wallet architecture and trust assumptions. The\narguments are the publisher's own and are not verified here.\n",
      "gone": null,
      "capture": {
        "status": "held",
        "copies": 1,
        "first_observed": "2026-08-09T02:05:09Z",
        "last_observed": "2026-08-09T02:05:09Z",
        "last_checked": "2026-08-15T12:56:49Z"
      },
      "differences": []
    },
    {
      "id": "orangesurf-coldcard-key-exposure",
      "title": "Coldcard key exposure",
      "url": "https://orange.surf/coldcard-key-exposure/",
      "organisation": "Orange Surf",
      "kind": "independent-analysis",
      "role": "Independent primary analysis",
      "publication_time": "2026-08-09",
      "note": "Orange Surf publishes a technical analysis of the COLDCARD key exposure,\ndocumenting the author's understanding of the vulnerability and its implications.\nHeld as a dated independent technical account. The analysis is the author's own\nand is not verified here.\n",
      "gone": null,
      "capture": {
        "status": "held",
        "copies": 1,
        "first_observed": "2026-08-09T02:05:11Z",
        "last_observed": "2026-08-09T02:05:11Z",
        "last_checked": "2026-08-15T12:56:51Z"
      },
      "differences": []
    },
    {
      "id": "reddit-safely-store-btc-without-hww",
      "title": "r/Bitcoin: safely storing BTC without a hardware wallet",
      "url": "https://www.reddit.com/r/Bitcoin/comments/1vil2qs/safely_store_btc_wo_hww/",
      "organisation": "reddit",
      "kind": "community-discussion",
      "role": "Community discussion",
      "publication_time": null,
      "note": null,
      "gone": null,
      "capture": {
        "status": "held",
        "copies": 3,
        "first_observed": "2026-08-09T02:05:14Z",
        "last_observed": "2026-08-13T12:57:40Z",
        "last_checked": "2026-08-15T12:27:03Z"
      },
      "differences": [
        {
          "observed_at": "2026-08-13T12:57:40Z",
          "window_start": "2026-08-09T10:41:06Z",
          "window_end": "2026-08-13T12:57:40Z",
          "status": "source-content",
          "summary": "One comment was deleted: its author changed from MiguelLancaster to [deleted] and its body was replaced with [deleted].",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 4,
          "removed_lines": 10
        },
        {
          "observed_at": "2026-08-09T10:41:06Z",
          "window_start": "2026-08-09T02:05:14Z",
          "window_end": "2026-08-09T10:41:06Z",
          "status": "source-content",
          "summary": "One comment was deleted, leaving only a [deleted] stub.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 2,
          "removed_lines": 8
        }
      ]
    },
    {
      "id": "reddit-jade-plus-setup-suspect",
      "title": "r/Bitcoin: Blockstream Jade Plus setup workflow suspect",
      "url": "https://www.reddit.com/r/Bitcoin/comments/1viknfe/blockstream_jade_plus_setup_workflow_suspect/",
      "organisation": "reddit",
      "kind": "community-discussion",
      "role": "Community discussion",
      "publication_time": null,
      "note": null,
      "gone": null,
      "capture": {
        "status": "held",
        "copies": 2,
        "first_observed": "2026-08-09T02:05:17Z",
        "last_observed": "2026-08-12T04:44:33Z",
        "last_checked": "2026-08-15T12:27:08Z"
      },
      "differences": [
        {
          "observed_at": "2026-08-12T04:44:33Z",
          "window_start": "2026-08-09T02:05:17Z",
          "window_end": "2026-08-12T04:44:33Z",
          "status": "source-content",
          "summary": "The thread gained a comment saying a Blockstream Jade update can be done via USB stick and explaining a preference not to update air-gapped setups unless a serious vulnerability demands it.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 10,
          "removed_lines": 0
        }
      ]
    },
    {
      "id": "reddit-coldcard-mk4-ux-flaw-continued",
      "title": "r/Bitcoin: Coldcard Mk4 UX flaw continued",
      "url": "https://www.reddit.com/r/Bitcoin/comments/1viixzj/coldcard_mk4_ux_flaw_continued/",
      "organisation": "reddit",
      "kind": "community-discussion",
      "role": "Community discussion",
      "publication_time": null,
      "note": null,
      "gone": null,
      "capture": {
        "status": "held",
        "copies": 3,
        "first_observed": "2026-08-09T06:41:48Z",
        "last_observed": "2026-08-09T18:49:08Z",
        "last_checked": "2026-08-11T22:50:10Z"
      },
      "differences": [
        {
          "observed_at": "2026-08-09T18:49:08Z",
          "window_start": "2026-08-09T12:03:36Z",
          "window_end": "2026-08-09T18:49:08Z",
          "status": "source-content",
          "summary": "Reddit served 1 additional comment record(s); the diff preserves their text and any edits to existing records.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 8,
          "removed_lines": 0
        },
        {
          "observed_at": "2026-08-09T12:03:36Z",
          "window_start": "2026-08-09T06:41:48Z",
          "window_end": "2026-08-09T12:03:36Z",
          "status": "source-content",
          "summary": "Reddit served 1 additional comment record(s); the diff preserves their text and any edits to existing records.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 8,
          "removed_lines": 0
        }
      ]
    },
    {
      "id": "reddit-llm-tracing-attackers",
      "title": "r/Bitcoin: LLM tracing for coldcard attackers",
      "url": "https://www.reddit.com/r/Bitcoin/comments/1vi6ify/llm_tracing_for_coldcard_attackers/",
      "organisation": "reddit",
      "kind": "community-discussion",
      "role": "Community discussion",
      "publication_time": null,
      "note": null,
      "gone": null,
      "capture": {
        "status": "held",
        "copies": 2,
        "first_observed": "2026-08-09T02:05:30Z",
        "last_observed": "2026-08-09T23:28:13Z",
        "last_checked": "2026-08-15T12:27:13Z"
      },
      "differences": [
        {
          "observed_at": "2026-08-09T23:28:13Z",
          "window_start": "2026-08-09T02:05:30Z",
          "window_end": "2026-08-09T23:28:13Z",
          "status": "source-content",
          "summary": "The thread gained a reply distinguishing exploiting a vulnerability from researching one, arguing the evidence does not prove attacker identity.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 10,
          "removed_lines": 0
        }
      ]
    },
    {
      "id": "reddit-coldcard-q-signing-device-only",
      "title": "r/Bitcoin: risks of using a Coldcard Q as a signing device only",
      "url": "https://www.reddit.com/r/Bitcoin/comments/1vi6fhi/realistically_are_there_any_risks_to_using_a/",
      "organisation": "reddit",
      "kind": "community-discussion",
      "role": "Community discussion",
      "publication_time": null,
      "note": null,
      "gone": null,
      "capture": {
        "status": "held",
        "copies": 1,
        "first_observed": "2026-08-09T02:05:35Z",
        "last_observed": "2026-08-09T02:05:35Z",
        "last_checked": "2026-08-15T12:27:17Z"
      },
      "differences": []
    },
    {
      "id": "reddit-roll-own-crypto-library",
      "title": "r/Bitcoin: proposal to implement a custom elliptic-curve library after the Coldcard exploit",
      "url": "https://www.reddit.com/r/Bitcoin/comments/1vi7boc/anyone_else_planning_on_implementing_their_own/",
      "organisation": "reddit",
      "kind": "community-discussion",
      "role": "Community discussion",
      "publication_time": null,
      "note": null,
      "gone": null,
      "capture": {
        "status": "held",
        "copies": 1,
        "first_observed": "2026-08-09T05:02:22Z",
        "last_observed": "2026-08-09T05:02:22Z",
        "last_checked": "2026-08-11T22:51:14Z"
      },
      "differences": []
    },
    {
      "id": "reddit-attacker-praise-heist",
      "title": "r/coldcard: poster praising the planning and execution of the drain",
      "url": "https://www.reddit.com/r/coldcard/comments/1vizpea/you_have_to_admit/",
      "organisation": "reddit",
      "kind": "community-discussion",
      "role": "Community discussion",
      "publication_time": null,
      "note": null,
      "gone": null,
      "capture": {
        "status": "held",
        "copies": 3,
        "first_observed": "2026-08-09T06:41:13Z",
        "last_observed": "2026-08-09T18:49:18Z",
        "last_checked": "2026-08-11T22:52:17Z"
      },
      "differences": [
        {
          "observed_at": "2026-08-09T18:49:18Z",
          "window_start": "2026-08-09T12:03:46Z",
          "window_end": "2026-08-09T18:49:18Z",
          "status": "source-content",
          "summary": "Reddit served 1 additional comment record(s); the diff preserves their text and any edits to existing records.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 8,
          "removed_lines": 0
        },
        {
          "observed_at": "2026-08-09T12:03:46Z",
          "window_start": "2026-08-09T06:41:13Z",
          "window_end": "2026-08-09T12:03:46Z",
          "status": "source-content",
          "summary": "Reddit served 1 additional comment record(s); the diff preserves their text and any edits to existing records.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 8,
          "removed_lines": 0
        }
      ]
    },
    {
      "id": "bitcointalk-audio-entropy-wallet",
      "title": "Audio-based entropy wallet",
      "url": "https://bitcointalk.org/index.php?topic=5590622.0",
      "organisation": "BitcoinTalk",
      "kind": "community-discussion",
      "role": "Community discussion",
      "publication_time": "2026-08-07",
      "note": "barrysty1e proposing an audio-based entropy wallet after recent hardware-wallet entropy flaws, with discussion of microphone preprocessing, frame-selection determinism, entropy measurement and mixing independent sources. A community-driven mitigation proposal in the incident's wake. The technical claims are the posters' own and are not verified here.\n",
      "gone": null,
      "capture": {
        "status": "held",
        "copies": 4,
        "first_observed": "2026-08-09T05:02:29Z",
        "last_observed": "2026-08-12T04:45:13Z",
        "last_checked": "2026-08-15T12:27:22Z"
      },
      "differences": [
        {
          "observed_at": "2026-08-12T04:45:13Z",
          "window_start": "2026-08-09T17:00:08Z",
          "window_end": "2026-08-12T04:45:13Z",
          "status": "capture-noise",
          "summary": "Only Bitcointalk's relative quote dates rolled from Today to absolute dates.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 1,
          "removed_lines": 1
        },
        {
          "observed_at": "2026-08-09T17:00:08Z",
          "window_start": "2026-08-09T10:41:26Z",
          "window_end": "2026-08-09T17:00:08Z",
          "status": "source-content",
          "summary": "Several new posts were added discussing microphone preprocessing, AI-generated voice as an attack vector, whether frame selection is deterministic, and using audio entropy as an additional source rather than replacing a CSPRNG.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 62,
          "removed_lines": 0
        },
        {
          "observed_at": "2026-08-09T10:41:26Z",
          "window_start": "2026-08-09T05:02:29Z",
          "window_end": "2026-08-09T10:41:26Z",
          "status": "source-content",
          "summary": "The thread gained posts arguing audio-based entropy is not a new idea, raising privacy concerns about microphone leakage, and questioning microphone noise defects.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 22,
          "removed_lines": 0
        }
      ]
    },
    {
      "id": "coindesk-third-wave-89m",
      "title": "Bitcoin cold wallet attack spreads to 4,500 addresses as losses near $89 million",
      "url": "https://www.coindesk.com/tech/2026/08/02/bitcoin-cold-wallet-attack-spreads-to-4-500-addresses-as-losses-near-usd89-million",
      "organisation": "CoinDesk",
      "kind": "reporting",
      "role": "Reporting",
      "publication_time": "2026-08-02",
      "note": "CoinDesk's third-wave follow-up records the changing address and loss estimates\non 2 August and distinguishes transaction patterns across waves. Held as a\ndated reporting state in the evolving funds-attribution record. The figures,\nwave groupings and causation account are the publisher's and are not verified\nby registration here.\n",
      "gone": null,
      "capture": {
        "status": "held",
        "copies": 9,
        "first_observed": "2026-08-02T01:19:19Z",
        "last_observed": "2026-08-09T12:19:04Z",
        "last_checked": "2026-08-15T12:27:24Z"
      },
      "differences": [
        {
          "observed_at": "2026-08-09T12:19:04Z",
          "window_start": "2026-08-07T04:22:44Z",
          "window_end": "2026-08-09T12:19:04Z",
          "status": "capture-noise",
          "summary": "Only the page locale for share controls flipped back to English, relative timestamps rolled, the language selector expanded, and live cryptocurrency ticker values changed. The article body was unchanged.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": true,
          "added_lines": 35,
          "removed_lines": 35
        },
        {
          "observed_at": "2026-08-07T04:22:44Z",
          "window_start": "2026-08-05T23:14:58Z",
          "window_end": "2026-08-07T04:22:44Z",
          "status": "capture-noise",
          "summary": "Only the page locale for share controls and relative timestamps flipped to Indonesian, while rotating related-story cards and live cryptocurrency ticker values changed. The article body was unchanged.",
          "inherited_from_wayback": true,
          "baseline_inherited_from_wayback": true,
          "added_lines": 28,
          "removed_lines": 31
        },
        {
          "observed_at": "2026-08-05T23:14:58Z",
          "window_start": "2026-08-03T11:17:31Z",
          "window_end": "2026-08-05T23:14:58Z",
          "status": "capture-noise",
          "summary": "Only rotating related-story cards, their relative timestamps and live cryptocurrency ticker values changed. The article body was unchanged.",
          "inherited_from_wayback": true,
          "baseline_inherited_from_wayback": true,
          "added_lines": 24,
          "removed_lines": 24
        },
        {
          "observed_at": "2026-08-03T11:17:31Z",
          "window_start": "2026-08-03T06:48:09Z",
          "window_end": "2026-08-03T11:17:31Z",
          "status": "capture-noise",
          "summary": "Only rotating related-story cards, their relative timestamps, live cryptocurrency ticker values and page locale for timestamps changed. The article body was unchanged.",
          "inherited_from_wayback": true,
          "baseline_inherited_from_wayback": true,
          "added_lines": 28,
          "removed_lines": 28
        },
        {
          "observed_at": "2026-08-03T06:48:09Z",
          "window_start": "2026-08-03T02:31:09Z",
          "window_end": "2026-08-03T06:48:09Z",
          "status": "capture-noise",
          "summary": "Only rotating related-story cards, their relative timestamps and live cryptocurrency ticker values changed. The article body was unchanged.",
          "inherited_from_wayback": true,
          "baseline_inherited_from_wayback": true,
          "added_lines": 21,
          "removed_lines": 21
        },
        {
          "observed_at": "2026-08-03T02:31:09Z",
          "window_start": "2026-08-02T15:24:50Z",
          "window_end": "2026-08-03T02:31:09Z",
          "status": "capture-noise",
          "summary": "Only rotating related-story cards, their relative timestamps and live cryptocurrency ticker values changed. The article body was unchanged.",
          "inherited_from_wayback": true,
          "baseline_inherited_from_wayback": true,
          "added_lines": 20,
          "removed_lines": 20
        },
        {
          "observed_at": "2026-08-02T15:24:50Z",
          "window_start": "2026-08-02T14:03:09Z",
          "window_end": "2026-08-02T15:24:50Z",
          "status": "capture-noise",
          "summary": "Only relative story timestamps and live cryptocurrency ticker values changed. The article body was unchanged.",
          "inherited_from_wayback": true,
          "baseline_inherited_from_wayback": true,
          "added_lines": 7,
          "removed_lines": 7
        },
        {
          "observed_at": "2026-08-02T14:03:09Z",
          "window_start": "2026-08-02T01:19:19Z",
          "window_end": "2026-08-02T14:03:09Z",
          "status": "capture-noise",
          "summary": "Only rotating related-story cards, their relative timestamps and live cryptocurrency ticker values changed. The article body was unchanged.",
          "inherited_from_wayback": true,
          "baseline_inherited_from_wayback": true,
          "added_lines": 22,
          "removed_lines": 22
        }
      ]
    },
    {
      "id": "ledger-primary-incident-article",
      "title": "The COLDCARD incident",
      "url": "https://www.ledger.com/blog-coldcard-incident",
      "organisation": "Ledger",
      "kind": "vendor-response",
      "role": "Vendor response",
      "publication_time": "2026-08-02",
      "note": "Ledger chief technology officer Charles Guillemet's primary incident article,\ncovering Ledger's account of the mechanism, entropy, certification, source\navailability and AI-assisted exploitation. Held directly rather than through\nthe Reddit relay that first led to it. Ledger is a competing wallet vendor and\nthe technical and comparative claims are its own.\n",
      "gone": null,
      "capture": {
        "status": "held",
        "copies": 5,
        "first_observed": "2026-08-03T12:38:57Z",
        "last_observed": "2026-08-14T08:29:30Z",
        "last_checked": "2026-08-15T12:27:27Z"
      },
      "differences": [
        {
          "observed_at": "2026-08-14T08:29:30Z",
          "window_start": "2026-08-12T04:45:26Z",
          "window_end": "2026-08-14T08:29:30Z",
          "status": "capture-noise",
          "summary": "Only Ledger product-promotion banners and the top navigation chrome changed. The incident article body was unchanged.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 3,
          "removed_lines": 3
        },
        {
          "observed_at": "2026-08-12T04:45:26Z",
          "window_start": "2026-08-09T12:20:06Z",
          "window_end": "2026-08-12T04:45:26Z",
          "status": "capture-noise",
          "summary": "Only the page's language-selector menu changed, adding Simplified Chinese and Arabic entries and reordering the list.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 105,
          "removed_lines": 81
        },
        {
          "observed_at": "2026-08-09T12:20:06Z",
          "window_start": "2026-08-04T15:39:45Z",
          "window_end": "2026-08-09T12:20:06Z",
          "status": "capture-noise",
          "summary": "Only Ledger product-promotion banners and the language-selector chrome changed. The incident article body was unchanged.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": true,
          "added_lines": 133,
          "removed_lines": 31
        },
        {
          "observed_at": "2026-08-04T15:39:45Z",
          "window_start": "2026-08-03T12:38:57Z",
          "window_end": "2026-08-04T15:39:45Z",
          "status": "capture-noise",
          "summary": "Only the top promotional banner text for Ledger products changed. The article body was unchanged.",
          "inherited_from_wayback": true,
          "baseline_inherited_from_wayback": true,
          "added_lines": 3,
          "removed_lines": 2
        }
      ]
    },
    {
      "id": "ledger-open-source-security-position",
      "title": "Open source is not a security property",
      "url": "https://www.ledger.com/blog-open-source-not-security-property",
      "organisation": "Ledger",
      "kind": "vendor-response",
      "role": "Vendor response",
      "publication_time": "2026-08-06",
      "note": "Charles Guillemet's follow-up position on open source and security, published\nin the incident's aftermath and promoted by Ledger's already registered social\npost. Held as the direct article behind that response. Its comparisons and\nclaims about Ledger's security model are the competing vendor's own.\n",
      "gone": null,
      "capture": {
        "status": "held",
        "copies": 2,
        "first_observed": "2026-08-09T12:20:07Z",
        "last_observed": "2026-08-14T01:58:34Z",
        "last_checked": "2026-08-15T12:27:29Z"
      },
      "differences": [
        {
          "observed_at": "2026-08-14T01:58:34Z",
          "window_start": "2026-08-09T12:20:07Z",
          "window_end": "2026-08-14T01:58:34Z",
          "status": "capture-noise",
          "summary": "Only the More articles promotional carousel changed, swapping one Ledger product entry for another; the position text was unchanged.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 3,
          "removed_lines": 3
        }
      ]
    },
    {
      "id": "ledger-incident-faq",
      "title": "FAQs related to the COLDCARD incident, July 2026",
      "url": "https://support.ledger.com/article/FAQs-Related-to-the-Coldcard-Incident-July-2026",
      "organisation": "Ledger",
      "kind": "vendor-response",
      "role": "Vendor response",
      "publication_time": "2026-08-07",
      "note": "Ledger's official incident FAQ, linked from its stickied community-moderator\nstatement. Held as a primary competing-vendor response and as the direct\nsupport document behind the moderator post. Security and product claims in it\nare Ledger's own and are not endorsed by registration.\n",
      "gone": null,
      "capture": {
        "status": "held",
        "copies": 1,
        "first_observed": "2026-08-09T12:30:56Z",
        "last_observed": "2026-08-09T12:30:56Z",
        "last_checked": "2026-08-15T12:27:30Z"
      },
      "differences": []
    },
    {
      "id": "thehackernews-incident-synthesis",
      "title": "COLDCARD hardware wallet flaw linked to bitcoin theft",
      "url": "https://thehackernews.com/2026/08/coldcard-hardware-wallet-flaw-linked-to.html",
      "organisation": "The Hacker News",
      "kind": "reporting",
      "role": "Reporting",
      "publication_time": "2026-08-01",
      "note": "A dated security-news synthesis that separately attributes Coinkite, Block and\ntheft-accounting claims rather than combining them into one archive-authored\naccount. Held for that source separation and its contemporaneous chronology;\nthe technical and attribution claims remain those of the named publishers.\n",
      "gone": null,
      "capture": {
        "status": "held",
        "copies": 3,
        "first_observed": "2026-08-09T12:33:07Z",
        "last_observed": "2026-08-12T17:31:50Z",
        "last_checked": "2026-08-15T12:27:40Z"
      },
      "differences": [
        {
          "observed_at": "2026-08-12T17:31:50Z",
          "window_start": "2026-08-12T04:45:50Z",
          "window_end": "2026-08-12T17:31:50Z",
          "status": "capture-noise",
          "summary": "Only rotating promotional banners and security-news headline cards changed; the incident article text was unchanged.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 10,
          "removed_lines": 10
        },
        {
          "observed_at": "2026-08-12T04:45:50Z",
          "window_start": "2026-08-09T12:33:07Z",
          "window_end": "2026-08-12T04:45:50Z",
          "status": "capture-noise",
          "summary": "Only the surrounding security-news headline feed and article-card list changed; the incident article text was unchanged.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 31,
          "removed_lines": 29
        }
      ]
    },
    {
      "id": "bleepingcomputer-88m-report",
      "title": "Coldcard wallet RNG flaw likely linked to $88 million bitcoin theft",
      "url": "https://www.bleepingcomputer.com/news/security/coldcard-wallet-rng-flaw-likely-linked-to-88-million-bitcoin-theft/",
      "organisation": "BleepingComputer",
      "kind": "reporting",
      "role": "Reporting",
      "publication_time": "2026-08-02",
      "note": "BleepingComputer's 2 August security report on the generator flaw and the\nthen-current theft attribution. Held as distinct mainstream security reporting\nfrom the first weekend of the incident. Its total, causation and technical\nframing are attributed to the outlet and its cited sources.\n",
      "gone": null,
      "capture": {
        "status": "held",
        "copies": 12,
        "first_observed": "2026-08-02T21:22:20Z",
        "last_observed": "2026-08-12T11:01:34Z",
        "last_checked": "2026-08-15T12:27:42Z"
      },
      "differences": [
        {
          "observed_at": "2026-08-12T11:01:34Z",
          "window_start": "2026-08-09T12:33:08Z",
          "window_end": "2026-08-12T11:01:34Z",
          "status": "capture-noise",
          "summary": "Only the embedded promotional banner rotated from one vendor offer to another; the article text was unchanged.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 4,
          "removed_lines": 4
        },
        {
          "observed_at": "2026-08-09T12:33:08Z",
          "window_start": "2026-08-06T21:38:15Z",
          "window_end": "2026-08-09T12:33:08Z",
          "status": "capture-noise",
          "summary": "Only rotating latest-news headlines and advertisement blocks changed. The article body was unchanged.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": true,
          "added_lines": 11,
          "removed_lines": 11
        },
        {
          "observed_at": "2026-08-06T21:38:15Z",
          "window_start": "2026-08-05T04:13:17Z",
          "window_end": "2026-08-06T21:38:15Z",
          "status": "capture-noise",
          "summary": "Only rotating latest-news headlines and advertisement blocks on the homepage and article rail changed. The article body was unchanged.",
          "inherited_from_wayback": true,
          "baseline_inherited_from_wayback": true,
          "added_lines": 15,
          "removed_lines": 13
        },
        {
          "observed_at": "2026-08-05T04:13:17Z",
          "window_start": "2026-08-04T17:51:37Z",
          "window_end": "2026-08-05T04:13:17Z",
          "status": "capture-noise",
          "summary": "Only rotating latest-news headlines and advertisement blocks changed. The article body was unchanged.",
          "inherited_from_wayback": true,
          "baseline_inherited_from_wayback": true,
          "added_lines": 10,
          "removed_lines": 10
        },
        {
          "observed_at": "2026-08-04T17:51:37Z",
          "window_start": "2026-08-04T11:28:46Z",
          "window_end": "2026-08-04T17:51:37Z",
          "status": "capture-noise",
          "summary": "Only rotating latest-news headlines and advertisement blocks changed. The article body was unchanged.",
          "inherited_from_wayback": true,
          "baseline_inherited_from_wayback": true,
          "added_lines": 5,
          "removed_lines": 5
        },
        {
          "observed_at": "2026-08-04T11:28:46Z",
          "window_start": "2026-08-03T11:19:20Z",
          "window_end": "2026-08-04T11:28:46Z",
          "status": "capture-noise",
          "summary": "Only rotating latest-news headlines, advertisement blocks and adjacent navigation chrome changed. The article body was unchanged.",
          "inherited_from_wayback": true,
          "baseline_inherited_from_wayback": true,
          "added_lines": 10,
          "removed_lines": 10
        },
        {
          "observed_at": "2026-08-03T11:19:20Z",
          "window_start": "2026-08-03T11:04:09Z",
          "window_end": "2026-08-03T11:19:20Z",
          "status": "capture-noise",
          "summary": "Only rotating advertisement blocks changed. The article body was unchanged.",
          "inherited_from_wayback": true,
          "baseline_inherited_from_wayback": true,
          "added_lines": 3,
          "removed_lines": 3
        },
        {
          "observed_at": "2026-08-03T11:04:09Z",
          "window_start": "2026-08-03T08:16:58Z",
          "window_end": "2026-08-03T11:04:09Z",
          "status": "capture-noise",
          "summary": "Only the order of rotating advertisement lines changed. The article body was unchanged.",
          "inherited_from_wayback": true,
          "baseline_inherited_from_wayback": true,
          "added_lines": 2,
          "removed_lines": 2
        },
        {
          "observed_at": "2026-08-03T08:16:58Z",
          "window_start": "2026-08-03T03:05:02Z",
          "window_end": "2026-08-03T08:16:58Z",
          "status": "capture-noise",
          "summary": "Only rotating latest-news headlines and advertisement blocks changed. The article body was unchanged.",
          "inherited_from_wayback": true,
          "baseline_inherited_from_wayback": true,
          "added_lines": 6,
          "removed_lines": 6
        },
        {
          "observed_at": "2026-08-03T03:05:02Z",
          "window_start": "2026-08-03T02:26:43Z",
          "window_end": "2026-08-03T03:05:02Z",
          "status": "capture-noise",
          "summary": "Only rotating advertisement blocks changed. The article body was unchanged.",
          "inherited_from_wayback": true,
          "baseline_inherited_from_wayback": true,
          "added_lines": 3,
          "removed_lines": 3
        },
        {
          "observed_at": "2026-08-03T02:26:43Z",
          "window_start": "2026-08-02T21:22:20Z",
          "window_end": "2026-08-03T02:26:43Z",
          "status": "capture-noise",
          "summary": "Only rotating latest-news headlines, advertisement blocks and adjacent navigation chrome changed. The article body was unchanged.",
          "inherited_from_wayback": true,
          "baseline_inherited_from_wayback": true,
          "added_lines": 9,
          "removed_lines": 8
        }
      ]
    },
    {
      "id": "web3isgoinggreat-incident-entry",
      "title": "COLDCARD hardware wallet flaw",
      "url": "https://www.web3isgoinggreat.com/single/coldcard-hardware-wallet-flaw",
      "organisation": "Web3 is Going Just Great",
      "kind": "reporting",
      "role": "Reporting",
      "publication_time": null,
      "note": "A stable incident-database entry with independent framing and outbound archive\nlinks. Held as a compact secondary chronology and discovery aid, not as a\nsubstitute for the primary publications it cites. Its summary and loss figure\nare the publisher's own.\n",
      "gone": null,
      "capture": {
        "status": "held",
        "copies": 2,
        "first_observed": "2026-08-04T02:49:22Z",
        "last_observed": "2026-08-09T12:33:10Z",
        "last_checked": "2026-08-15T12:56:55Z"
      },
      "differences": [
        {
          "observed_at": "2026-08-09T12:33:10Z",
          "window_start": "2026-08-04T02:49:22Z",
          "window_end": "2026-08-09T12:33:10Z",
          "status": "source-content",
          "summary": "The entry raised its loss figure from more than 1,367 BTC (about $89 million) to more than 2,000 BTC (about $130 million), restated the body as at least 2,055 BTC (about $130 million), added Galaxy Research's estimate of 15 unique attacker groups, and added a link to the Galaxy Research tweet thread.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": true,
          "added_lines": 4,
          "removed_lines": 3
        }
      ]
    },
    {
      "id": "reddit-ledger-early-risk-discussion",
      "title": "r/ledgerwallet: Coldcard wallets drained due to poor entropy",
      "url": "https://www.reddit.com/r/ledgerwallet/comments/1vbddgv/coldcard_wallets_drained_due_to_poor_entropy_how/",
      "organisation": "reddit",
      "kind": "community-discussion",
      "role": "Community discussion",
      "publication_time": null,
      "note": null,
      "gone": null,
      "capture": {
        "status": "held",
        "copies": 1,
        "first_observed": "2026-08-09T12:19:37Z",
        "last_observed": "2026-08-09T12:19:37Z",
        "last_checked": "2026-08-15T12:27:45Z"
      },
      "differences": []
    },
    {
      "id": "reddit-trezor-official-response",
      "title": "r/TREZOR: official response to the Coldcard event",
      "url": "https://www.reddit.com/r/TREZOR/comments/1vbjtlo/trezor_users_your_funds_are_safe_cc_related_event/",
      "organisation": "reddit",
      "kind": "community-discussion",
      "role": "Community discussion",
      "publication_time": null,
      "note": null,
      "gone": null,
      "capture": {
        "status": "held",
        "copies": 2,
        "first_observed": "2026-08-09T12:19:42Z",
        "last_observed": "2026-08-15T05:57:14Z",
        "last_checked": "2026-08-15T12:27:51Z"
      },
      "differences": [
        {
          "observed_at": "2026-08-15T05:57:14Z",
          "window_start": "2026-08-09T12:19:42Z",
          "window_end": "2026-08-15T05:57:14Z",
          "status": "source-content",
          "summary": "The thread gained a new reply from MaxWildman warning that Trezor users' physical safety could be at risk from the ShipMonk PII breach.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 10,
          "removed_lines": 0
        }
      ]
    },
    {
      "id": "reddit-bitcoin-early-explanation",
      "title": "r/Bitcoin: about the recent Coldcard attack",
      "url": "https://www.reddit.com/r/Bitcoin/comments/1vbnvzn/about_the_recent_coldcard_attack/",
      "organisation": "reddit",
      "kind": "community-discussion",
      "role": "Community discussion",
      "publication_time": null,
      "note": null,
      "gone": null,
      "capture": {
        "status": "held",
        "copies": 1,
        "first_observed": "2026-08-09T12:19:48Z",
        "last_observed": "2026-08-09T12:19:48Z",
        "last_checked": "2026-08-15T12:27:57Z"
      },
      "differences": []
    },
    {
      "id": "reddit-ledger-official-incident-statement",
      "title": "r/ledgerwallet: the Coldcard incident and Ledger seed generation",
      "url": "https://www.reddit.com/r/ledgerwallet/comments/1vi0ut3/the_coldcard_incident_how_ledger_wallet_seed/",
      "organisation": "reddit",
      "kind": "vendor-response",
      "role": "Vendor response",
      "publication_time": null,
      "note": null,
      "gone": null,
      "capture": {
        "status": "held",
        "copies": 5,
        "first_observed": "2026-08-09T12:19:52Z",
        "last_observed": "2026-08-12T17:32:15Z",
        "last_checked": "2026-08-15T12:28:02Z"
      },
      "differences": [
        {
          "observed_at": "2026-08-12T17:32:15Z",
          "window_start": "2026-08-12T04:46:30Z",
          "window_end": "2026-08-12T17:32:15Z",
          "status": "source-content",
          "summary": "The official statement thread gained a new reply from KIG45 saying the new chip is physically impenetrable even for the government.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 8,
          "removed_lines": 0
        },
        {
          "observed_at": "2026-08-12T04:46:30Z",
          "window_start": "2026-08-09T23:28:54Z",
          "window_end": "2026-08-12T04:46:30Z",
          "status": "source-content",
          "summary": "The official statement thread gained new participant comments about passphrase entry and PRNG verification.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 28,
          "removed_lines": 0
        },
        {
          "observed_at": "2026-08-09T23:28:54Z",
          "window_start": "2026-08-09T17:00:48Z",
          "window_end": "2026-08-09T23:28:54Z",
          "status": "source-content",
          "summary": "btchip added a reply about passphrase length trade-offs: long against recovery-phrase exposure, short when used only as a duress PIN.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 10,
          "removed_lines": 0
        },
        {
          "observed_at": "2026-08-09T17:00:48Z",
          "window_start": "2026-08-09T12:19:52Z",
          "window_end": "2026-08-09T17:00:48Z",
          "status": "source-content",
          "summary": "The stickied Ledger statement thread gained two new replies: btchip said a BIP-39 passphrase can be as simple as 'ac1' or 'ac2' and can be tied to a PIN as a duress code, and _speedoflight_ questioned whether such short passphrases are strong enough if the recovery phrase is exposed.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 16,
          "removed_lines": 0
        }
      ]
    },
    {
      "id": "reddit-ledger-source-availability-debate",
      "title": "r/ledgerwallet: source availability and vendor trust after Coldcard",
      "url": "https://www.reddit.com/r/ledgerwallet/comments/1vc81y1/3_years_ago_ledger_was_deemed_the_worst_wallet/",
      "organisation": "reddit",
      "kind": "community-discussion",
      "role": "Community discussion",
      "publication_time": null,
      "note": null,
      "gone": null,
      "capture": {
        "status": "held",
        "copies": 1,
        "first_observed": "2026-08-09T12:19:56Z",
        "last_observed": "2026-08-09T12:19:56Z",
        "last_checked": "2026-08-15T12:28:07Z"
      },
      "differences": []
    },
    {
      "id": "reddit-cryptocurrency-incident-explanation",
      "title": "r/CryptoCurrency: what people misunderstood about the Coldcard incident",
      "url": "https://www.reddit.com/r/CryptoCurrency/comments/1vd4f2e/it_seems_people_did_not_understand_what_happened/",
      "organisation": "reddit",
      "kind": "community-discussion",
      "role": "Community discussion",
      "publication_time": null,
      "note": null,
      "gone": null,
      "capture": {
        "status": "held",
        "copies": 2,
        "first_observed": "2026-08-09T12:20:00Z",
        "last_observed": "2026-08-12T05:12:15Z",
        "last_checked": "2026-08-15T12:56:57Z"
      },
      "differences": [
        {
          "observed_at": "2026-08-12T05:12:15Z",
          "window_start": "2026-08-09T12:20:00Z",
          "window_end": "2026-08-12T05:12:15Z",
          "status": "source-content",
          "summary": "Reddit served 2 additional comment record(s); the diff preserves their text and any edits to existing records.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 16,
          "removed_lines": 0
        }
      ]
    },
    {
      "id": "stackernews-btcpay-setup-after-hack",
      "title": "How to Set Up BTCPay Server Better After the Hack?",
      "url": "https://stacker.news/items/1543355",
      "organisation": "Stacker News",
      "kind": "community-discussion",
      "role": "Community discussion",
      "publication_time": "2026-08-08",
      "note": "Natalia posting a merchant-oriented BTCPay Server setup guide framed around improving security after recent hacks, comparing xpub deposit workflows, Lightning receive options and third-party plugins. Incident-contextual guidance for merchants; the setup advice and product claims are the poster's own, not verified here. Captured through the site's public GraphQL API: the rendered pages crash the capture tab, and the API answers POST from this host. The query fixes the captured surface to the item's title, text and two levels of comments, each with author and absolute timestamp.\n",
      "gone": null,
      "capture": {
        "status": "held",
        "copies": 1,
        "first_observed": "2026-08-09T05:02:30Z",
        "last_observed": "2026-08-09T05:02:30Z",
        "last_checked": "2026-08-09T18:49:31Z"
      },
      "differences": []
    },
    {
      "id": "bitcointalk-short-term-self-custody-impact",
      "title": "Short-term impact of the Coldcard incident on Self-Custody",
      "url": "https://bitcointalk.org/index.php?topic=5590691.0",
      "organisation": "BitcoinTalk",
      "kind": "community-discussion",
      "role": "Community discussion",
      "publication_time": "2026-08-08",
      "note": "Abiky asking how the COLDCARD incident will affect the self-custodial industry,\nwhether users will abandon hardware wallets for CEXs or ETFs, and how long the\ntrust damage will last. Replies debate whether centralised custody is a rational\nresponse and whether the impact is short-lived. A BitcoinTalk community sentiment\nand response record. The views and figures are the posters' own, not verified here.\n",
      "gone": null,
      "capture": {
        "status": "held",
        "copies": 2,
        "first_observed": "2026-08-09T23:29:01Z",
        "last_observed": "2026-08-12T04:46:52Z",
        "last_checked": "2026-08-15T12:28:13Z"
      },
      "differences": [
        {
          "observed_at": "2026-08-12T04:46:52Z",
          "window_start": "2026-08-09T23:29:01Z",
          "window_end": "2026-08-12T04:46:52Z",
          "status": "source-content",
          "summary": "The thread gained multiple replies debating whether users will move to CEXs or ETFs, how long the trust damage will last, and the merits of self custody.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 148,
          "removed_lines": 4
        }
      ]
    },
    {
      "id": "reddit-coinkite-social-media-messaging",
      "title": "r/coldcard: critique of Coinkite's incident-week social media messaging",
      "url": "https://www.reddit.com/r/coldcard/comments/1vjbjrr/what_is_up_with_coldcardcoinkites_messaging_on/",
      "organisation": "reddit",
      "kind": "community-discussion",
      "role": "Community discussion",
      "publication_time": null,
      "note": null,
      "gone": null,
      "capture": {
        "status": "held",
        "copies": 1,
        "first_observed": "2026-08-12T04:46:55Z",
        "last_observed": "2026-08-12T04:46:55Z",
        "last_checked": "2026-08-15T12:28:15Z"
      },
      "differences": []
    },
    {
      "id": "reddit-creator-patent-application",
      "title": "r/coldcard: patent application from the bug's creator",
      "url": "https://www.reddit.com/r/coldcard/comments/1viduvp/wonder_what_more_could_be_hidden/",
      "organisation": "reddit",
      "kind": "community-discussion",
      "role": "Community discussion",
      "publication_time": null,
      "note": null,
      "gone": null,
      "capture": {
        "status": "not-yet-held",
        "copies": 0,
        "first_observed": null,
        "last_observed": null,
        "last_checked": "2026-08-15T12:28:21Z"
      },
      "differences": []
    },
    {
      "id": "reddit-bitcoin-not-broken-explainer",
      "title": "r/Bitcoin: 'Bitcoin wasn't broken; the random key generation was' explainer",
      "url": "https://www.reddit.com/r/Bitcoin/comments/1vjf9jw/bitcoin_wasnt_broken_the_random_key_generation/",
      "organisation": "reddit",
      "kind": "community-discussion",
      "role": "Community discussion",
      "publication_time": null,
      "note": null,
      "gone": null,
      "capture": {
        "status": "held",
        "copies": 3,
        "first_observed": "2026-08-12T04:47:22Z",
        "last_observed": "2026-08-14T23:45:42Z",
        "last_checked": "2026-08-15T12:28:25Z"
      },
      "differences": [
        {
          "observed_at": "2026-08-14T23:45:42Z",
          "window_start": "2026-08-13T19:30:39Z",
          "window_end": "2026-08-14T23:45:42Z",
          "status": "source-content",
          "summary": "The thread gained a comment stating the reduced key search space is far larger than three billion.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 8,
          "removed_lines": 0
        },
        {
          "observed_at": "2026-08-13T19:30:39Z",
          "window_start": "2026-08-12T04:47:22Z",
          "window_end": "2026-08-13T19:30:39Z",
          "status": "source-content",
          "summary": "A comment by TheRivieraKid22 urging readers to learn about bank deposit insurance and avoid winging it was removed from the thread.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 0,
          "removed_lines": 12
        }
      ]
    },
    {
      "id": "reddit-coldcard-future-design-philosophy",
      "title": "r/Bitcoin: future of ColdCard hardware and firmware design",
      "url": "https://www.reddit.com/r/Bitcoin/comments/1vjfyzv/the_future_of_coldcard_hardware_and_firmware/",
      "organisation": "reddit",
      "kind": "community-discussion",
      "role": "Community discussion",
      "publication_time": null,
      "note": null,
      "gone": null,
      "capture": {
        "status": "held",
        "copies": 3,
        "first_observed": "2026-08-12T04:47:34Z",
        "last_observed": "2026-08-13T19:30:44Z",
        "last_checked": "2026-08-15T12:28:30Z"
      },
      "differences": [
        {
          "observed_at": "2026-08-13T19:30:44Z",
          "window_start": "2026-08-13T12:59:08Z",
          "window_end": "2026-08-13T19:30:44Z",
          "status": "source-content",
          "summary": "A comment by Individual_Gate9375 argued that ColdCard firmware cannot be forked because devices reject unsigned updates and the license would expose forkers to lawsuits.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 0,
          "removed_lines": 10
        },
        {
          "observed_at": "2026-08-13T12:59:08Z",
          "window_start": "2026-08-12T04:47:34Z",
          "window_end": "2026-08-13T12:59:08Z",
          "status": "source-content",
          "summary": "One comment was deleted (author changed from MiguelLancaster to [deleted], body replaced with [deleted]), and a child reply by the same author was removed.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 4,
          "removed_lines": 18
        }
      ]
    },
    {
      "id": "reddit-multi-source-fail-closed-entropy",
      "title": "r/Bitcoin: the case for multi-source, fail-closed entropy after the COLDCARD incident",
      "url": "https://www.reddit.com/r/Bitcoin/comments/1vjn3u5/coldcard_users_lost_1367_btc_89m_because_a_2021/",
      "organisation": "reddit",
      "kind": "community-discussion",
      "role": "Community discussion",
      "publication_time": null,
      "note": null,
      "gone": null,
      "capture": {
        "status": "held",
        "copies": 2,
        "first_observed": "2026-08-12T04:47:58Z",
        "last_observed": "2026-08-14T08:30:42Z",
        "last_checked": "2026-08-15T12:28:35Z"
      },
      "differences": [
        {
          "observed_at": "2026-08-14T08:30:42Z",
          "window_start": "2026-08-12T04:47:58Z",
          "window_end": "2026-08-14T08:30:42Z",
          "status": "source-content",
          "summary": "The Reddit thread gained a new top-level comment by sporastefy arguing that silent entropy degradation is the actual defect and that reproducible builds are the only way to close the gap between published source and shipped firmware.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 28,
          "removed_lines": 0
        }
      ]
    },
    {
      "id": "reddit-firmware-bricking-reports",
      "title": "r/Bitcoin: reports of Coldcard devices bricked by the latest firmware",
      "url": "https://www.reddit.com/r/Bitcoin/comments/1vjg4z3/many_coldcard_users_report_having_their_devices/",
      "organisation": "reddit",
      "kind": "community-discussion",
      "role": "Community discussion",
      "publication_time": null,
      "note": null,
      "gone": null,
      "capture": {
        "status": "held",
        "copies": 1,
        "first_observed": "2026-08-15T11:29:23Z",
        "last_observed": "2026-08-15T11:29:23Z",
        "last_checked": "2026-08-15T12:28:40Z"
      },
      "differences": []
    },
    {
      "id": "reddit-bip85-passphrase-entropy-mix",
      "title": "r/Bitcoin: mixing human and hardware entropy with a one-time passphrase and BIP85",
      "url": "https://www.reddit.com/r/Bitcoin/comments/1vizful/you_can_mix_human_entropy_with_hardware_wallet/",
      "organisation": "reddit",
      "kind": "community-discussion",
      "role": "Community discussion",
      "publication_time": null,
      "note": null,
      "gone": null,
      "capture": {
        "status": "held",
        "copies": 1,
        "first_observed": "2026-08-12T04:48:15Z",
        "last_observed": "2026-08-12T04:48:15Z",
        "last_checked": "2026-08-15T12:28:44Z"
      },
      "differences": []
    },
    {
      "id": "reddit-multisig-coldcard-bitbox-setup",
      "title": "r/Bitcoin: possible failures of a Coldcard and BitBox multisig setup",
      "url": "https://www.reddit.com/r/Bitcoin/comments/1vj3xxb/what_are_the_possible_failures_of_this_multisig/",
      "organisation": "reddit",
      "kind": "community-discussion",
      "role": "Community discussion",
      "publication_time": null,
      "note": null,
      "gone": null,
      "capture": {
        "status": "held",
        "copies": 1,
        "first_observed": "2026-08-12T04:48:35Z",
        "last_observed": "2026-08-12T04:48:35Z",
        "last_checked": "2026-08-15T12:28:49Z"
      },
      "differences": []
    },
    {
      "id": "reddit-dice-adoption-critique",
      "title": "r/Bitcoin: critique of dice-roll seed generation as impractical for mass adoption",
      "url": "https://www.reddit.com/r/Bitcoin/comments/1vj4lq4/grown_men_rolling_dice/",
      "organisation": "reddit",
      "kind": "community-discussion",
      "role": "Community discussion",
      "publication_time": null,
      "note": null,
      "gone": null,
      "capture": {
        "status": "held",
        "copies": 2,
        "first_observed": "2026-08-12T04:49:30Z",
        "last_observed": "2026-08-13T12:59:32Z",
        "last_checked": "2026-08-15T12:28:54Z"
      },
      "differences": [
        {
          "observed_at": "2026-08-13T12:59:32Z",
          "window_start": "2026-08-12T04:49:30Z",
          "window_end": "2026-08-13T12:59:32Z",
          "status": "source-content",
          "summary": "The thread gained a new comment by MiguelLancaster arguing that bitcoin is stored on the blockchain rather than on a physical device.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 0,
          "removed_lines": 8
        }
      ]
    },
    {
      "id": "reddit-nvk-scammer-regulation-call",
      "title": "r/Bitcoin: call for hardware-wallet vendor accountability and certification after the incident",
      "url": "https://www.reddit.com/r/Bitcoin/comments/1vji2nz/rodolfo_novak_coldcard_scammer_i_will_take_it/",
      "organisation": "reddit",
      "kind": "community-discussion",
      "role": "Community discussion",
      "publication_time": null,
      "note": null,
      "gone": null,
      "capture": {
        "status": "held",
        "copies": 2,
        "first_observed": "2026-08-12T17:33:12Z",
        "last_observed": "2026-08-14T23:46:18Z",
        "last_checked": "2026-08-15T12:28:59Z"
      },
      "differences": [
        {
          "observed_at": "2026-08-14T23:46:18Z",
          "window_start": "2026-08-12T17:33:12Z",
          "window_end": "2026-08-14T23:46:18Z",
          "status": "source-content",
          "summary": "A participant comment from cleankiwii was deleted, leaving only a [deleted] author marker and body.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 2,
          "removed_lines": 2
        }
      ]
    },
    {
      "id": "stackernews-technical-autopsy-entropy-failure",
      "title": "Coldcard: the technical autopsy of an entropy failure",
      "url": "https://stacker.news/items/1546011",
      "organisation": "Stacker News",
      "kind": "community-discussion",
      "role": "Community discussion",
      "publication_time": "2026-08-11",
      "note": "k00b relaying a detailed postmortem that claims the Mk3 and Mk4 candidate spaces\nare smaller than previously reported, estimates sweep costs and collision\nprobabilities, and compares device-class vulnerability. The numerical claims are\nthe author's and are reported here without endorsement; the thread is a\nsignificant technical counterpoint to earlier published estimates. Captured\nthrough the site's public GraphQL API: the rendered pages crash the capture tab,\nand the API answers POST from this host. The query fixes the captured surface to\nthe item's title, text and two levels of comments, each with author and absolute\ntimestamp.\n",
      "gone": null,
      "capture": {
        "status": "held",
        "copies": 1,
        "first_observed": "2026-08-12T17:33:17Z",
        "last_observed": "2026-08-12T17:33:17Z",
        "last_checked": "2026-08-15T12:29:04Z"
      },
      "differences": []
    },
    {
      "id": "reddit-steel-plates-wasted",
      "title": "r/coldcard: first-hand report of wasted Coinkite steel plates after the forced migration",
      "url": "https://www.reddit.com/r/coldcard/comments/1vkqgos/steel_plates_100_waste/",
      "organisation": "reddit",
      "kind": "community-discussion",
      "role": "Community discussion",
      "publication_time": null,
      "note": null,
      "gone": null,
      "capture": {
        "status": "held",
        "copies": 3,
        "first_observed": "2026-08-12T17:33:20Z",
        "last_observed": "2026-08-15T12:29:07Z",
        "last_checked": "2026-08-15T12:29:07Z"
      },
      "differences": [
        {
          "observed_at": "2026-08-15T12:29:07Z",
          "window_start": "2026-08-13T19:31:22Z",
          "window_end": "2026-08-15T12:29:07Z",
          "status": "source-content",
          "summary": "The Reddit thread gained a reply from Oxymorix saying 'You should have rolled your own.'",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 8,
          "removed_lines": 0
        },
        {
          "observed_at": "2026-08-13T19:31:22Z",
          "window_start": "2026-08-12T17:33:20Z",
          "window_end": "2026-08-13T19:31:22Z",
          "status": "source-content",
          "summary": "Several comments were deleted or marked [deleted] and new replies were added debating seed backup security and suggesting reusable steel plates.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 48,
          "removed_lines": 4
        }
      ]
    },
    {
      "id": "reddit-randomness-collision-question",
      "title": "r/coldcard: asking whether another wallet could randomly produce an affected Coldcard key",
      "url": "https://www.reddit.com/r/coldcard/comments/1vlbpxf/randomness_in_bitcoin_and_other_wallets/",
      "organisation": "reddit",
      "kind": "community-discussion",
      "role": "Community discussion",
      "publication_time": null,
      "note": null,
      "gone": null,
      "capture": {
        "status": "held",
        "copies": 2,
        "first_observed": "2026-08-12T17:33:25Z",
        "last_observed": "2026-08-14T23:46:30Z",
        "last_checked": "2026-08-15T12:29:13Z"
      },
      "differences": [
        {
          "observed_at": "2026-08-14T23:46:30Z",
          "window_start": "2026-08-12T17:33:25Z",
          "window_end": "2026-08-14T23:46:30Z",
          "status": "source-content",
          "summary": "The thread gained two new replies: phoebeethical asked whether a passphrase can produce the same master password as a different seed, and logan-807128 confirmed the wording and explained that a passphrase effectively acts as an additional seed word.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 22,
          "removed_lines": 0
        }
      ]
    },
    {
      "id": "reddit-steelplate-refund-demand",
      "title": "r/coldcard: demand for steel-plate refund or replacement from Coinkite",
      "url": "https://www.reddit.com/r/coldcard/comments/1vl6asz/steelplate_refundreplacement/",
      "organisation": "reddit",
      "kind": "community-discussion",
      "role": "Community discussion",
      "publication_time": null,
      "note": null,
      "gone": null,
      "capture": {
        "status": "held",
        "copies": 2,
        "first_observed": "2026-08-12T17:33:30Z",
        "last_observed": "2026-08-13T06:30:50Z",
        "last_checked": "2026-08-15T12:29:17Z"
      },
      "differences": [
        {
          "observed_at": "2026-08-13T06:30:50Z",
          "window_start": "2026-08-12T17:33:30Z",
          "window_end": "2026-08-13T06:30:50Z",
          "status": "source-content",
          "summary": "The thread gained three new replies: grraarr told the poster self-custody may not be for them, grraarr mocked the suggested precaution as overkill, and stargate425 retorted that grraarr did not understand English.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 24,
          "removed_lines": 0
        }
      ]
    },
    {
      "id": "reddit-mk4-reverse-engineering-question",
      "title": "r/coldcard: questions about Mk4 RNG reverse-engineering and a linked research collection",
      "url": "https://www.reddit.com/r/coldcard/comments/1vkogy3/coldcard_mk4_rng_weakness_full_reverse/",
      "organisation": "reddit",
      "kind": "community-discussion",
      "role": "Community discussion",
      "publication_time": null,
      "note": null,
      "gone": null,
      "capture": {
        "status": "held",
        "copies": 1,
        "first_observed": "2026-08-12T18:28:37Z",
        "last_observed": "2026-08-12T18:28:37Z",
        "last_checked": "2026-08-15T12:57:03Z"
      },
      "differences": []
    },
    {
      "id": "reddit-gold-standard-banner",
      "title": "r/coldcard: questioning the subreddit's 'Gold Standard in Bitcoin Security' banner after the incident",
      "url": "https://www.reddit.com/r/coldcard/comments/1vk5f4p/coldcard_the_gold_standard_in_bitcoin_security/",
      "organisation": "reddit",
      "kind": "community-discussion",
      "role": "Community discussion",
      "publication_time": null,
      "note": null,
      "gone": null,
      "capture": {
        "status": "held",
        "copies": 2,
        "first_observed": "2026-08-12T17:33:35Z",
        "last_observed": "2026-08-13T00:01:41Z",
        "last_checked": "2026-08-15T12:29:22Z"
      },
      "differences": [
        {
          "observed_at": "2026-08-13T00:01:41Z",
          "window_start": "2026-08-12T17:33:35Z",
          "window_end": "2026-08-13T00:01:41Z",
          "status": "source-content",
          "summary": "The Reddit thread gained a new reply from zinornia saying 'GoneCard'.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 8,
          "removed_lines": 0
        }
      ]
    },
    {
      "id": "reddit-stolen-funds-recovery-hope",
      "title": "r/coldcard: first-hand victim asking whether stolen funds can be recovered",
      "url": "https://www.reddit.com/r/coldcard/comments/1vk6ylb/any_hope_for_stolen_funds/",
      "organisation": "reddit",
      "kind": "victim-account",
      "role": "First-hand account",
      "publication_time": null,
      "note": null,
      "gone": null,
      "capture": {
        "status": "held",
        "copies": 4,
        "first_observed": "2026-08-12T17:33:39Z",
        "last_observed": "2026-08-13T19:31:41Z",
        "last_checked": "2026-08-15T12:29:26Z"
      },
      "differences": [
        {
          "observed_at": "2026-08-13T19:31:41Z",
          "window_start": "2026-08-13T06:31:00Z",
          "window_end": "2026-08-13T19:31:41Z",
          "status": "source-content",
          "summary": "A comment by Vagelen_Von was added suggesting the victim's lawyer should investigate an inside job scenario.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 8,
          "removed_lines": 0
        },
        {
          "observed_at": "2026-08-13T06:31:00Z",
          "window_start": "2026-08-13T00:01:46Z",
          "window_end": "2026-08-13T06:31:00Z",
          "status": "source-content",
          "summary": "The thread gained a new reply from grraarr citing a recent federal seizure of stolen BTC and the Bisq reimbursement fund as reasons not to rule out recovery.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 8,
          "removed_lines": 0
        },
        {
          "observed_at": "2026-08-13T00:01:46Z",
          "window_start": "2026-08-12T17:33:39Z",
          "window_end": "2026-08-13T00:01:46Z",
          "status": "source-content",
          "summary": "The Reddit thread gained a new reply from ArachnidSalty8496 reporting a 20k loss and not knowing what to do.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 8,
          "removed_lines": 0
        }
      ]
    },
    {
      "id": "reddit-coinomi-rng-approach",
      "title": "r/coldcard: Coinomi explains its RNG approach after the Coldcard incident",
      "url": "https://www.reddit.com/r/coldcard/comments/1vke7kg/how_we_handle_rng_at_coinomi/",
      "organisation": "reddit",
      "kind": "community-discussion",
      "role": "Community discussion",
      "publication_time": null,
      "note": null,
      "gone": null,
      "capture": {
        "status": "held",
        "copies": 1,
        "first_observed": "2026-08-12T17:33:44Z",
        "last_observed": "2026-08-12T17:33:44Z",
        "last_checked": "2026-08-15T12:29:32Z"
      },
      "differences": []
    },
    {
      "id": "reddit-coinkite-inventory-destruction-question",
      "title": "r/Bitcoin: why Coinkite destroyed affected inventory",
      "url": "https://www.reddit.com/r/Bitcoin/comments/1vld3rt/why_did_coinkite_destroy_its_inventory/",
      "organisation": "reddit",
      "kind": "community-discussion",
      "role": "Community discussion",
      "publication_time": null,
      "note": null,
      "gone": null,
      "capture": {
        "status": "held",
        "copies": 4,
        "first_observed": "2026-08-13T01:56:23Z",
        "last_observed": "2026-08-14T23:46:55Z",
        "last_checked": "2026-08-15T12:29:36Z"
      },
      "differences": [
        {
          "observed_at": "2026-08-14T23:46:55Z",
          "window_start": "2026-08-13T13:00:14Z",
          "window_end": "2026-08-14T23:46:55Z",
          "status": "source-content",
          "summary": "Two existing comments were removed or marked [deleted] (one by striata and one by Save_JR), and a new comment by Levitdon argued that unflashed affected devices are the only remaining hardware evidence.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 12,
          "removed_lines": 12
        },
        {
          "observed_at": "2026-08-13T13:00:14Z",
          "window_start": "2026-08-13T06:31:09Z",
          "window_end": "2026-08-13T13:00:14Z",
          "status": "source-content",
          "summary": "The thread gained two new comments: one by snek-jazz linking wider vulnerability discovery to AI-assisted auditing, and a short agreement from Oxymorix.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 26,
          "removed_lines": 0
        },
        {
          "observed_at": "2026-08-13T06:31:09Z",
          "window_start": "2026-08-13T01:56:23Z",
          "window_end": "2026-08-13T06:31:09Z",
          "status": "source-content",
          "summary": "The thread gained two new replies: Mr_Ander5on argued that most users cannot audit code and that Coinkite's failure to do so is gross negligence, and AnthonyBTC simply answered yes.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 20,
          "removed_lines": 0
        }
      ]
    },
    {
      "id": "reddit-07-btc-loss-leadership-blame",
      "title": "r/Bitcoin: first-hand 0.7 BTC drain and blame toward Coinkite leadership",
      "url": "https://www.reddit.com/r/Bitcoin/comments/1vkywj4/if_rodolfo_novak_spent_1100th_of_the_time_he/",
      "organisation": "reddit",
      "kind": "victim-account",
      "role": "First-hand account",
      "publication_time": null,
      "note": null,
      "gone": null,
      "capture": {
        "status": "held",
        "copies": 1,
        "first_observed": "2026-08-13T01:56:28Z",
        "last_observed": "2026-08-13T01:56:28Z",
        "last_checked": "2026-08-15T12:29:43Z"
      },
      "differences": []
    },
    {
      "id": "reddit-nvk-proxy-marketing-claim",
      "title": "r/Bitcoin: allegation that Rodolfo Novak marketed COLDCARD through a proxy site",
      "url": "https://www.reddit.com/r/Bitcoin/comments/1vl4nly/for_many_years_rodolfo_novak_coldcard_ceo/",
      "organisation": "reddit",
      "kind": "community-discussion",
      "role": "Community discussion",
      "publication_time": null,
      "note": null,
      "gone": null,
      "capture": {
        "status": "held",
        "copies": 2,
        "first_observed": "2026-08-13T01:56:32Z",
        "last_observed": "2026-08-14T23:47:05Z",
        "last_checked": "2026-08-15T12:29:48Z"
      },
      "differences": [
        {
          "observed_at": "2026-08-14T23:47:05Z",
          "window_start": "2026-08-13T01:56:32Z",
          "window_end": "2026-08-14T23:47:05Z",
          "status": "source-content",
          "summary": "The poster added an update stating that the website now returns 404 and that Rodolfo Novak appears to be removing the deceptive endorsement.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 3,
          "removed_lines": 0
        }
      ]
    },
    {
      "id": "reddit-dice-entropy-simulator",
      "title": "r/Bitcoin: interactive simulator mapping dice rolls to a BIP39 seed",
      "url": "https://www.reddit.com/r/Bitcoin/comments/1vl4ku3/interactive_simulator_how_dice_rolls_become_a/",
      "organisation": "reddit",
      "kind": "community-discussion",
      "role": "Community discussion",
      "publication_time": null,
      "note": null,
      "gone": null,
      "capture": {
        "status": "held",
        "copies": 1,
        "first_observed": "2026-08-13T10:43:08Z",
        "last_observed": "2026-08-13T10:43:08Z",
        "last_checked": "2026-08-15T12:57:08Z"
      },
      "differences": []
    },
    {
      "id": "reddit-novak-deceptive-marketing",
      "title": "r/Bitcoin: allegation that Rodolfo Novak promoted COLDCARD through undeclared security guide sites",
      "url": "https://www.reddit.com/r/Bitcoin/comments/1vk6iiu/more_on_the_coldcard_fraud_deceptive_practice_of/",
      "organisation": "reddit",
      "kind": "community-discussion",
      "role": "Community discussion",
      "publication_time": null,
      "note": null,
      "gone": null,
      "capture": {
        "status": "held",
        "copies": 2,
        "first_observed": "2026-08-13T02:11:16Z",
        "last_observed": "2026-08-13T19:32:06Z",
        "last_checked": "2026-08-15T12:29:53Z"
      },
      "differences": [
        {
          "observed_at": "2026-08-13T19:32:06Z",
          "window_start": "2026-08-13T02:11:16Z",
          "window_end": "2026-08-13T19:32:06Z",
          "status": "source-content",
          "summary": "New comments by KnowledgeOk473 and Thin_Needleworker795 were added debating whether an always-offline old laptop can substitute for a hardware wallet.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 32,
          "removed_lines": 0
        }
      ]
    },
    {
      "id": "reddit-seed-backup-test-first-hand",
      "title": "r/Bitcoin: first-hand account of catching a bad seed backup before adding passphrase or multisig",
      "url": "https://www.reddit.com/r/Bitcoin/comments/1vk1akj/actually_test_your_seed_backup_before_adding/",
      "organisation": "reddit",
      "kind": "community-discussion",
      "role": "Community discussion",
      "publication_time": null,
      "note": null,
      "gone": null,
      "capture": {
        "status": "held",
        "copies": 1,
        "first_observed": "2026-08-13T02:11:20Z",
        "last_observed": "2026-08-13T02:11:20Z",
        "last_checked": "2026-08-15T12:29:58Z"
      },
      "differences": []
    },
    {
      "id": "reddit-coldcard-q-self-rolled-signing",
      "title": "r/Bitcoin: using a Coldcard Q with a self-rolled dice seed as a pure signing device",
      "url": "https://www.reddit.com/r/Bitcoin/comments/1vkgatv/coldcard_q_security_with_selfrolled_seed_as_pure/",
      "organisation": "reddit",
      "kind": "community-discussion",
      "role": "Community discussion",
      "publication_time": null,
      "note": null,
      "gone": null,
      "capture": {
        "status": "held",
        "copies": 1,
        "first_observed": "2026-08-13T13:33:42Z",
        "last_observed": "2026-08-13T13:33:42Z",
        "last_checked": "2026-08-15T12:30:02Z"
      },
      "differences": []
    },
    {
      "id": "reddit-coinkite-silence-unprofessional",
      "title": "r/coldcard: complaint about Coinkite support silence and lack of public statement",
      "url": "https://www.reddit.com/r/coldcard/comments/1vm708g/unprofessional/",
      "organisation": "reddit",
      "kind": "community-discussion",
      "role": "Community discussion",
      "publication_time": null,
      "note": null,
      "gone": null,
      "capture": {
        "status": "held",
        "copies": 3,
        "first_observed": "2026-08-13T13:33:46Z",
        "last_observed": "2026-08-15T12:30:07Z",
        "last_checked": "2026-08-15T12:30:07Z"
      },
      "differences": [
        {
          "observed_at": "2026-08-15T12:30:07Z",
          "window_start": "2026-08-13T19:32:20Z",
          "window_end": "2026-08-15T12:30:07Z",
          "status": "source-content",
          "summary": "A reply by Mission-Disaster-447 was added, noting that Coinkite has created a security-status website and published blog posts and that individual support responses are not expected.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 10,
          "removed_lines": 0
        },
        {
          "observed_at": "2026-08-13T19:32:20Z",
          "window_start": "2026-08-13T13:33:46Z",
          "window_end": "2026-08-13T19:32:20Z",
          "status": "source-content",
          "summary": "New comments were added reporting an unanswered ARCA refund request, speculating about lawsuit avoidance, and offering to buy a bricked Q device.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 24,
          "removed_lines": 0
        }
      ]
    },
    {
      "id": "reddit-forrest-video-coldcard",
      "title": "r/Bitcoin: Forrest video from nine months ago that may have helped Coldcard users",
      "url": "https://www.reddit.com/r/Bitcoin/comments/1vm15sk/9_months_ago_a_video_from_forrest_couldve/",
      "organisation": "reddit",
      "kind": "community-discussion",
      "role": "Community discussion",
      "publication_time": null,
      "note": null,
      "gone": null,
      "capture": {
        "status": "held",
        "copies": 5,
        "first_observed": "2026-08-13T13:33:50Z",
        "last_observed": "2026-08-14T23:52:15Z",
        "last_checked": "2026-08-15T12:57:12Z"
      },
      "differences": [
        {
          "observed_at": "2026-08-14T23:52:15Z",
          "window_start": "2026-08-14T10:01:12Z",
          "window_end": "2026-08-14T23:52:15Z",
          "status": "source-content",
          "summary": "Reddit served 4 additional comment record(s); the diff preserves their text and any edits to existing records.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 41,
          "removed_lines": 0
        },
        {
          "observed_at": "2026-08-14T10:01:12Z",
          "window_start": "2026-08-14T03:28:34Z",
          "window_end": "2026-08-14T10:01:12Z",
          "status": "source-content",
          "summary": "Reddit served 7 additional comment record(s); the diff preserves their text and any edits to existing records.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 72,
          "removed_lines": 0
        },
        {
          "observed_at": "2026-08-14T03:28:34Z",
          "window_start": "2026-08-13T21:00:08Z",
          "window_end": "2026-08-14T03:28:34Z",
          "status": "source-content",
          "summary": "Reddit served 1 additional comment record(s); the diff preserves their text and any edits to existing records.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 14,
          "removed_lines": 0
        },
        {
          "observed_at": "2026-08-13T21:00:08Z",
          "window_start": "2026-08-13T13:33:50Z",
          "window_end": "2026-08-13T21:00:08Z",
          "status": "source-content",
          "summary": "Reddit served 1 additional comment record(s); the diff preserves their text and any edits to existing records.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 8,
          "removed_lines": 0
        }
      ]
    },
    {
      "id": "reddit-unplug-blockclock",
      "title": "r/Bitcoin: whether to unplug a Coinkite BlockClock after the incident",
      "url": "https://www.reddit.com/r/Bitcoin/comments/1vm1gve/unplug_the_blockclock/",
      "organisation": "reddit",
      "kind": "community-discussion",
      "role": "Community discussion",
      "publication_time": null,
      "note": null,
      "gone": null,
      "capture": {
        "status": "held",
        "copies": 1,
        "first_observed": "2026-08-13T13:33:54Z",
        "last_observed": "2026-08-13T13:33:54Z",
        "last_checked": "2026-08-15T12:57:18Z"
      },
      "differences": []
    },
    {
      "id": "reddit-case-against-passphrases",
      "title": "r/Bitcoin: the case against using passphrases",
      "url": "https://www.reddit.com/r/Bitcoin/comments/1vm56ou/the_case_against_passphrases/",
      "organisation": "reddit",
      "kind": "community-discussion",
      "role": "Community discussion",
      "publication_time": null,
      "note": null,
      "gone": null,
      "capture": {
        "status": "held",
        "copies": 2,
        "first_observed": "2026-08-13T13:33:57Z",
        "last_observed": "2026-08-13T19:32:25Z",
        "last_checked": "2026-08-15T12:30:12Z"
      },
      "differences": [
        {
          "observed_at": "2026-08-13T19:32:25Z",
          "window_start": "2026-08-13T13:33:57Z",
          "window_end": "2026-08-13T19:32:25Z",
          "status": "source-content",
          "summary": "A comment by SmokeAndSkate agreeing with the original post was removed from the thread.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 0,
          "removed_lines": 8
        }
      ]
    },
    {
      "id": "stackernews-mara-9k-bitcoin-rescued",
      "title": "9K Bitcoin rescued out of Coldcard multisigs | MARA Foundation",
      "url": "https://stacker.news/items/1546608",
      "organisation": "Stacker News",
      "kind": "community-discussion",
      "role": "Community discussion",
      "publication_time": "2026-08-12",
      "note": "hasherstacker links to a MARA Foundation announcement that 9,000 bitcoin were rescued from Coldcard multisig setups. Held as a link-post record of a claimed large-scale rescue operation during the incident response. The rescue claim is the poster's own and is not independently verified here. Captured through the site's public GraphQL API: the rendered pages crash the capture tab, and the API answers POST from this host. The query fixes the captured surface to the item's title, text and two levels of comments, each with author and absolute timestamp.\n",
      "gone": null,
      "capture": {
        "status": "held",
        "copies": 1,
        "first_observed": "2026-08-13T13:42:43Z",
        "last_observed": "2026-08-13T13:42:43Z",
        "last_checked": "2026-08-15T12:57:22Z"
      },
      "differences": []
    },
    {
      "id": "reddit-coldcard-not-doom-hardware-wallets",
      "title": "r/Bitcoin: the Coldcard hack does not mean hardware wallets are doomed",
      "url": "https://www.reddit.com/r/Bitcoin/comments/1vmi5bq/the_coldcards_hack_doesnt_mean_hardware_wallets/",
      "organisation": "reddit",
      "kind": "community-discussion",
      "role": "Community discussion",
      "publication_time": null,
      "note": null,
      "gone": null,
      "capture": {
        "status": "held",
        "copies": 2,
        "first_observed": "2026-08-13T13:42:45Z",
        "last_observed": "2026-08-13T19:32:30Z",
        "last_checked": "2026-08-15T12:30:17Z"
      },
      "differences": [
        {
          "observed_at": "2026-08-13T19:32:30Z",
          "window_start": "2026-08-13T13:42:45Z",
          "window_end": "2026-08-13T19:32:30Z",
          "status": "source-content",
          "summary": "A comment by certifr1ed was added stating they are still sticking to open source wallets.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 8,
          "removed_lines": 0
        }
      ]
    },
    {
      "id": "stackernews-tracing-attacker-steps-praveen",
      "title": "Tracing the Attacker's Steps Through 1,082 BTC Coldcard Drain - Praveen Perera",
      "url": "https://stacker.news/items/1547780",
      "organisation": "Stacker News",
      "kind": "community-discussion",
      "role": "Community discussion",
      "publication_time": "2026-08-14",
      "note": "Scoresby links Praveen Perera's analysis of the 1,082 BTC Coldcard drain, focusing on 153 swept addresses that researchers have not been able to reconstruct seeds for. Perera describes a search effort covering 104 billion candidate seeds and 5.60 trillion address checks, and argues a missed derivation path is unlikely. Held as a dated technical follow-up on the attacker methodology and the remaining reconstruction gap. The claims and calculations are Perera's own and are not independently verified here.\n",
      "gone": null,
      "capture": {
        "status": "held",
        "copies": 1,
        "first_observed": "2026-08-14T23:47:40Z",
        "last_observed": "2026-08-14T23:47:40Z",
        "last_checked": "2026-08-15T12:30:21Z"
      },
      "differences": []
    },
    {
      "id": "reddit-glacier-protocol-20-call",
      "title": "r/Bitcoin: call for a Glacier Protocol 2.0 self-custody standard",
      "url": "https://www.reddit.com/r/Bitcoin/comments/1vnu1eb/we_need_a_glacier_protocol_20_for_bitcoin/",
      "organisation": "reddit",
      "kind": "community-discussion",
      "role": "Community discussion",
      "publication_time": null,
      "note": null,
      "gone": null,
      "capture": {
        "status": "held",
        "copies": 2,
        "first_observed": "2026-08-14T23:47:43Z",
        "last_observed": "2026-08-15T05:59:45Z",
        "last_checked": "2026-08-15T12:30:24Z"
      },
      "differences": [
        {
          "observed_at": "2026-08-15T05:59:45Z",
          "window_start": "2026-08-14T23:47:43Z",
          "window_end": "2026-08-15T05:59:45Z",
          "status": "source-content",
          "summary": "The thread gained replies proposing a BLIP-based official Bitcoin announcement page and agreeing that Bitcoin needs curated news.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 28,
          "removed_lines": 0
        }
      ]
    },
    {
      "id": "reddit-trezor-breach-coldcard-ptsd",
      "title": "r/Bitcoin: Trezor ShipMonk breach explained for people still reacting to the COLDCARD hack",
      "url": "https://www.reddit.com/r/Bitcoin/comments/1vnkt5d/trezor_breach_explained_for_anyone_still_in/",
      "organisation": "reddit",
      "kind": "community-discussion",
      "role": "Community discussion",
      "publication_time": null,
      "note": null,
      "gone": null,
      "capture": {
        "status": "held",
        "copies": 2,
        "first_observed": "2026-08-14T23:47:48Z",
        "last_observed": "2026-08-15T05:59:50Z",
        "last_checked": "2026-08-15T12:30:29Z"
      },
      "differences": [
        {
          "observed_at": "2026-08-15T05:59:50Z",
          "window_start": "2026-08-14T23:47:48Z",
          "window_end": "2026-08-15T05:59:50Z",
          "status": "source-content",
          "summary": "The thread gained a new reply warning that leaked Trezor customer information will likely be used for phishing attempts.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 8,
          "removed_lines": 0
        }
      ]
    },
    {
      "id": "stackernews-rolling-dice-fresh-entropy",
      "title": "Rolling Dice to Generate Fresh Entropy on Coldcard Devices",
      "url": "https://stacker.news/items/1547505",
      "organisation": "Stacker News",
      "kind": "community-discussion",
      "role": "Community discussion",
      "publication_time": "2026-08-13",
      "note": "Nittany asks whether rolling dice to provide user entropy produces safe seeds on COLDCARD Mk4, Mk5 and Q devices in the wake of the ongoing incident. The thread documents an owner's effort to keep using an existing signer by supplying external entropy rather than trusting its RNG. Held as a dated mitigation question and community response to the vulnerability. The claims and assumptions are the poster's own and are not verified here. Captured through the site's public GraphQL API: the rendered pages crash the capture tab, and the API answers POST from this host. The query fixes the captured surface to the item's title, text and two levels of comments, each with author and absolute timestamp.\n",
      "gone": null,
      "capture": {
        "status": "held",
        "copies": 1,
        "first_observed": "2026-08-15T01:52:25Z",
        "last_observed": "2026-08-15T01:52:25Z",
        "last_checked": "2026-08-15T12:30:35Z"
      },
      "differences": []
    },
    {
      "id": "reddit-coldcards-next-exploit",
      "title": "r/Bitcoin: claim that destroying hardware stock points to a possible second exploit",
      "url": "https://www.reddit.com/r/Bitcoin/comments/1vn78qh/coldcards_next_exploit/",
      "organisation": "reddit",
      "kind": "community-discussion",
      "role": "Community discussion",
      "publication_time": null,
      "note": null,
      "gone": null,
      "capture": {
        "status": "held",
        "copies": 3,
        "first_observed": "2026-08-15T01:52:27Z",
        "last_observed": "2026-08-15T12:30:38Z",
        "last_checked": "2026-08-15T12:30:38Z"
      },
      "differences": [
        {
          "observed_at": "2026-08-15T12:30:38Z",
          "window_start": "2026-08-15T05:59:57Z",
          "window_end": "2026-08-15T12:30:38Z",
          "status": "source-content",
          "summary": "A reply by Oxymorix was added arguing that destroying affected inventory is more practical than reflashing because returning devices to factory-first-boot state may not be feasible.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 12,
          "removed_lines": 0
        },
        {
          "observed_at": "2026-08-15T05:59:57Z",
          "window_start": "2026-08-15T01:52:27Z",
          "window_end": "2026-08-15T05:59:57Z",
          "status": "source-content",
          "summary": "The thread gained an exchange of short replies between grraarr and ItsAlwaysThemBooBoo disputing the original hardware-bug speculation.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 40,
          "removed_lines": 0
        }
      ]
    },
    {
      "id": "stackernews-losses-climb-112m-state-investigation",
      "title": "Losses Climb to $112m: State of Coldcard Investigation - Alex Thorn",
      "url": "https://stacker.news/items/1548121",
      "organisation": "Stacker News",
      "kind": "community-discussion",
      "role": "Community discussion",
      "publication_time": "2026-08-14",
      "note": "Scoresby relays Galaxy Research's 14 August update on the Coldcard investigation: 190 victim contacts, 1,778.84 BTC ($112.7m) stolen from more than 8,600 addresses, and a possible total of 2,417.35 BTC ($153m) if unconfirmed Wave 4 thefts are included. The thread also notes that most stolen funds have remained unmoved, some movement through Coinjoin and peelchains, elevated small-exchange inflows after the incident, and BlackRock lowering the IBIT in-kind creation minimum. Held as a dated update to Galaxy's loss accounting. The figures are Galaxy's and are not independently verified here.\n",
      "gone": null,
      "capture": {
        "status": "held",
        "copies": 2,
        "first_observed": "2026-08-15T01:58:31Z",
        "last_observed": "2026-08-15T06:00:02Z",
        "last_checked": "2026-08-15T12:30:44Z"
      },
      "differences": [
        {
          "observed_at": "2026-08-15T06:00:02Z",
          "window_start": "2026-08-15T01:58:31Z",
          "window_end": "2026-08-15T06:00:02Z",
          "status": "capture-noise",
          "summary": "Only the display order of two existing comments swapped; their text and timestamps were unchanged.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 6,
          "removed_lines": 6
        }
      ]
    },
    {
      "id": "reddit-novak-deletes-bitcoinsecurity-guide",
      "title": "r/Bitcoin: Rodolfo Novak deletes bitcoinsecurity.guide after claims of deceptive endorsement",
      "url": "https://www.reddit.com/r/Bitcoin/comments/1vohwh6/rodolfo_novak_coldcard_ceo_deletes_his/",
      "organisation": "reddit",
      "kind": "community-discussion",
      "role": "Community discussion",
      "publication_time": null,
      "note": null,
      "gone": null,
      "capture": {
        "status": "held",
        "copies": 3,
        "first_observed": "2026-08-15T01:58:33Z",
        "last_observed": "2026-08-15T12:30:47Z",
        "last_checked": "2026-08-15T12:30:47Z"
      },
      "differences": [
        {
          "observed_at": "2026-08-15T12:30:47Z",
          "window_start": "2026-08-15T06:00:05Z",
          "window_end": "2026-08-15T12:30:47Z",
          "status": "source-content",
          "summary": "A reply by No-Contribution23 was added claiming that COLDCARD is not open source and that bitcoinsecurity.guide displayed a misleading green checkmark.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 8,
          "removed_lines": 0
        },
        {
          "observed_at": "2026-08-15T06:00:05Z",
          "window_start": "2026-08-15T01:58:33Z",
          "window_end": "2026-08-15T06:00:05Z",
          "status": "source-content",
          "summary": "The thread gained replies criticizing the deletion of bitcoinsecurity.guide and noting that the Wayback Machine preserves the removed guide.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 16,
          "removed_lines": 0
        }
      ]
    },
    {
      "id": "reddit-plot-thickens-coldcard-hack",
      "title": "r/Bitcoin: no researcher has reproduced a seed for 153 source addresses containing 132.95 BTC",
      "url": "https://www.reddit.com/r/Bitcoin/comments/1vobf3s/plot_thickens_with_coldcard_hack_no_researcher_i/",
      "organisation": "reddit",
      "kind": "community-discussion",
      "role": "Community discussion",
      "publication_time": null,
      "note": null,
      "gone": null,
      "capture": {
        "status": "held",
        "copies": 3,
        "first_observed": "2026-08-15T01:58:37Z",
        "last_observed": "2026-08-15T12:30:52Z",
        "last_checked": "2026-08-15T12:30:52Z"
      },
      "differences": [
        {
          "observed_at": "2026-08-15T12:30:52Z",
          "window_start": "2026-08-15T06:00:10Z",
          "window_end": "2026-08-15T12:30:52Z",
          "status": "source-content",
          "summary": "A reply by Ok-Courage-5115 was added comparing the unresolved seed-reconstruction gap to a leak where one interesting document is highlighted among many.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 8,
          "removed_lines": 0
        },
        {
          "observed_at": "2026-08-15T06:00:10Z",
          "window_start": "2026-08-15T01:58:37Z",
          "window_end": "2026-08-15T06:00:10Z",
          "status": "source-content",
          "summary": "Several comments from FTP_FTP_ were deleted or redacted to [deleted], and the thread gained new replies from data_diver and lobhater about the unresolved seed reconstruction and internal dismissal claims.",
          "inherited_from_wayback": false,
          "baseline_inherited_from_wayback": false,
          "added_lines": 22,
          "removed_lines": 19
        }
      ]
    },
    {
      "id": "reddit-cold-storage-human-factor",
      "title": "r/Bitcoin: how much safer is cold storage once you factor in the person using it?",
      "url": "https://www.reddit.com/r/Bitcoin/comments/1vo86t2/how_much_safer_is_cold_storage_really_once_you/",
      "organisation": "reddit",
      "kind": "community-discussion",
      "role": "Community discussion",
      "publication_time": null,
      "note": null,
      "gone": null,
      "capture": {
        "status": "held",
        "copies": 1,
        "first_observed": "2026-08-15T01:58:41Z",
        "last_observed": "2026-08-15T01:58:41Z",
        "last_checked": "2026-08-15T12:30:57Z"
      },
      "differences": []
    },
    {
      "id": "reddit-returning-coldcard-device",
      "title": "r/Bitcoin: returning the COLDCARD device and asking for a refund",
      "url": "https://www.reddit.com/r/Bitcoin/comments/1vounpq/returning_the_coldcard_device_back/",
      "organisation": "reddit",
      "kind": "community-discussion",
      "role": "Community discussion",
      "publication_time": "2026-08-15",
      "note": null,
      "gone": null,
      "capture": {
        "status": "held",
        "copies": 1,
        "first_observed": "2026-08-15T13:48:09Z",
        "last_observed": "2026-08-15T13:48:09Z",
        "last_checked": "2026-08-15T14:27:28Z"
      },
      "differences": []
    }
  ],
  "social_posts": [
    {
      "id": "nvk-apology",
      "title": "Full accountability statement",
      "url": "https://x.com/nvk/status/2083216713693151552",
      "author": "nvk",
      "platform": "x",
      "organisation": "Coinkite",
      "posted": "2026-07-31T15:42:23Z",
      "role": "social-statement",
      "why_registered": "Vendor apology, hotfix summary, postmortem commitment and support offered to affected users.",
      "relation": {
        "kind": "single-post",
        "head_id": null
      },
      "capture": {
        "status": "held",
        "artefact_count": 18,
        "conversation_copies": 0,
        "conversation_posts": 0,
        "conversation_replies": 0,
        "conversation_gaps": []
      }
    },
    {
      "id": "trustwallet-wasm-update",
      "title": "Browser-extension WASM vulnerability thread",
      "url": "https://x.com/TrustWallet/status/1649699428733947906",
      "author": "TrustWallet",
      "platform": "x",
      "organisation": "Trust Wallet",
      "posted": "2023-04-22T08:59:28Z",
      "role": "historical-precedent",
      "why_registered": "Trust Wallet's primary incident thread states the affected browser-extension creation window, that the issue was fixed, and that affected users should follow its remediation guidance. The held capture covered the first post of the ten-post thread until 7 Aug 2026, when the conversation was added to the curated thread tier.",
      "relation": {
        "kind": "conversation-head",
        "head_id": null
      },
      "capture": {
        "status": "held",
        "artefact_count": 58,
        "conversation_copies": 5,
        "conversation_posts": 49,
        "conversation_replies": 39,
        "conversation_gaps": []
      }
    },
    {
      "id": "llfourn-model",
      "title": "Initial attack-cost model",
      "url": "https://x.com/LLFOURN/status/2082990000896147942",
      "author": "LLFOURN",
      "platform": "x",
      "organisation": null,
      "posted": "2026-07-31T00:41:30Z",
      "role": "social-statement",
      "why_registered": "LLFOURN's stated attack-cost model: approximately 2^40.3 for Mk3 and 2^72.3 for Mk4-class devices under its listed UID, timing and interaction assumptions.",
      "relation": {
        "kind": "single-post",
        "head_id": null
      },
      "capture": {
        "status": "held",
        "artefact_count": 18,
        "conversation_copies": 0,
        "conversation_posts": 0,
        "conversation_replies": 0,
        "conversation_gaps": []
      }
    },
    {
      "id": "llfourn-followup",
      "title": "Attack-cost follow-up",
      "url": "https://x.com/LLFOURN/status/2083296357662765399",
      "author": "LLFOURN",
      "platform": "x",
      "organisation": null,
      "posted": "2026-07-31T20:58:52Z",
      "role": "social-statement",
      "why_registered": "LLFOURN's follow-up lowering the Mk4-class estimate by 10 to 14 bits, giving approximately 2^58.3 to 2^62.3 under the revised assumptions.",
      "relation": {
        "kind": "single-post",
        "head_id": null
      },
      "capture": {
        "status": "held",
        "artefact_count": 3,
        "conversation_copies": 0,
        "conversation_posts": 0,
        "conversation_replies": 0,
        "conversation_gaps": []
      }
    },
    {
      "id": "kloaec-multisig",
      "title": "Multisig threshold warning",
      "url": "https://x.com/KLoaec/status/2083301216050700780",
      "author": "KLoaec",
      "platform": "x",
      "organisation": null,
      "posted": "2026-07-31T21:18:10Z",
      "role": "social-statement",
      "why_registered": "Dated guidance on configurations where affected COLDCARD keys meet a multisig or miniscript threshold, with qualified Taproot and private-submission advice.",
      "relation": {
        "kind": "single-post",
        "head_id": null
      },
      "capture": {
        "status": "held",
        "artefact_count": 3,
        "conversation_copies": 0,
        "conversation_posts": 0,
        "conversation_replies": 0,
        "conversation_gaps": []
      }
    },
    {
      "id": "clay-attribution",
      "title": "Operator attribution report",
      "url": "https://x.com/clay_garrett/status/2083247006139503065",
      "author": "clay_garrett",
      "platform": "x",
      "organisation": "Block",
      "posted": "2026-07-31T17:42:45Z",
      "role": "social-statement",
      "why_registered": "Block's report that the operator used a paid blockchain-services account; the complete thread says the provider's logs matched the workflow and that Block saw no evidence of knowing participation.",
      "relation": {
        "kind": "conversation-head",
        "head_id": null
      },
      "capture": {
        "status": "held",
        "artefact_count": 186,
        "conversation_copies": 25,
        "conversation_posts": 169,
        "conversation_replies": 166,
        "conversation_gaps": []
      }
    },
    {
      "id": "clay-earlier-waves-thread",
      "title": "Earlier-wave accounting thread",
      "url": "https://x.com/clay_garrett/status/2082980439367487724",
      "author": "clay_garrett",
      "platform": "x",
      "organisation": "Block",
      "posted": "2026-07-31T00:03:31Z",
      "role": "on-chain-analysis",
      "why_registered": "Block's seven-post preliminary accounting thread for the reported 695 earlier transactions, including the two block-level counts, amounts, scan method and explicit warning that the common-incident attribution was not confirmed.",
      "relation": {
        "kind": "single-post",
        "head_id": null
      },
      "capture": {
        "status": "held",
        "artefact_count": 3,
        "conversation_copies": 0,
        "conversation_posts": 0,
        "conversation_replies": 0,
        "conversation_gaps": []
      }
    },
    {
      "id": "unchained-guidance",
      "title": "Unchained client guidance",
      "url": "https://x.com/unchained/status/2083036112449163618",
      "author": "unchained",
      "platform": "x",
      "organisation": "Unchained",
      "posted": "2026-07-31T03:44:44Z",
      "role": "social-statement",
      "why_registered": "Unchained's client guidance to rotate COLDCARD-generated keys, with specific treatment of one versus two affected keys in a 2-of-3 vault.",
      "relation": {
        "kind": "single-post",
        "head_id": null
      },
      "capture": {
        "status": "held",
        "artefact_count": 3,
        "conversation_copies": 0,
        "conversation_posts": 0,
        "conversation_replies": 0,
        "conversation_gaps": []
      }
    },
    {
      "id": "otaliptus-technical",
      "title": "Tentative Mk4 entropy model",
      "url": "https://x.com/otaliptus/status/2083365327740543404",
      "author": "otaliptus",
      "platform": "x",
      "organisation": null,
      "posted": "2026-08-01T01:32:55Z",
      "role": "independent-analysis",
      "why_registered": "A deliberately tentative independent Mk4 model. Assuming a remote attacker does\nnot know the UID, otaliptus estimates about 20 to 21 bits from the wafer-coordinate\nword, narrows practical SysTick positions, and isolates the unresolved RTC term.\nThe post reports roughly 52 to 63 bits if Mk4 RTC behaviour is problematic and\nroughly 75 to 88 bits if it is not. The author labels this brainstorming and lists\nassumptions that may be wrong, so it is preserved as reported analysis rather than\na measured bound.\n",
      "relation": {
        "kind": "single-post",
        "head_id": null
      },
      "capture": {
        "status": "held",
        "artefact_count": 3,
        "conversation_copies": 0,
        "conversation_posts": 0,
        "conversation_replies": 0,
        "conversation_gaps": []
      }
    },
    {
      "id": "benowhere-multisig-race",
      "title": "Multisig migration race",
      "url": "https://x.com/BEN0WHERE/status/2083351351980109950",
      "author": "BEN0WHERE",
      "platform": "x",
      "organisation": null,
      "posted": "2026-08-01T00:37Z",
      "role": "migration-guidance",
      "why_registered": "Part of the Slipstream advice chain. Reply to \"why do multisig holders need\nSlipstream?\", explaining the mechanism: a thief holding some keys of a multisig\nmay still lack the wallet setup data, but the owner's own broadcast reveals\nenough of it to let the thief build a competing transaction; private miner\nsubmission avoids that race. Author's profile: Product Lead at Bitkey (Block's\nwallet), which bears on the conflict disclosure already on the Slipstream page.\n",
      "relation": {
        "kind": "single-post",
        "head_id": null
      },
      "capture": {
        "status": "held",
        "artefact_count": 3,
        "conversation_copies": 0,
        "conversation_posts": 0,
        "conversation_replies": 0,
        "conversation_gaps": []
      }
    },
    {
      "id": "glxyresearch-flow-map",
      "title": "Galaxy flow-of-funds map",
      "url": "https://x.com/glxyresearch/status/2083181683067506899",
      "author": "glxyresearch",
      "platform": "x",
      "organisation": "Galaxy Research",
      "posted": "2026-07-31T13:23:11Z",
      "role": "social-statement",
      "why_registered": "Galaxy's own flow-of-funds post, the primary source behind the 1,082.65 BTC /\n1,196-address figure quoted by The Block. Adds what the reporting dropped: the\n30.0 sat/vB hardcoded fee signature with no change outputs, the BIP-84/49/44\nderivation mix, blocks 960,183-960,191, and the four consolidation addresses\nwith per-address balances (562.02 + 398.48 + 89.62 + 32.45 BTC).\nThe first rendered screenshot was taken before the attached chart hydrated. The\ntimestamped 07:49:51 UTC recapture includes the complete post and flow map.\n",
      "relation": {
        "kind": "single-post",
        "head_id": null
      },
      "capture": {
        "status": "held",
        "artefact_count": 20,
        "conversation_copies": 0,
        "conversation_posts": 0,
        "conversation_replies": 0,
        "conversation_gaps": []
      }
    },
    {
      "id": "kevinkelbie-later-wave",
      "title": "Later 45.9 BTC wave",
      "url": "https://x.com/KevinKelbie/status/2083368025864990857",
      "author": "KevinKelbie",
      "platform": "x",
      "organisation": null,
      "posted": "2026-08-01T01:43:39Z",
      "role": "on-chain-analysis",
      "why_registered": "Reports a later 31 July cluster of 1,216 transactions and 45.9 BTC, outside\nBlock's published scan window. The post says seven of Block's eight markers\nmatch while replace-by-fee behaviour differs. Captured as a reported lead, not\ntreated as verified until the underlying transaction set is independently\nchecked.\n",
      "relation": {
        "kind": "single-post",
        "head_id": null
      },
      "capture": {
        "status": "held",
        "artefact_count": 3,
        "conversation_copies": 0,
        "conversation_posts": 0,
        "conversation_replies": 0,
        "conversation_gaps": []
      }
    },
    {
      "id": "robhamilton-preliminary-sweep",
      "title": "Preliminary sweep accounting",
      "url": "https://x.com/Rob1Ham/status/2082896614218203616",
      "author": "Rob1Ham",
      "platform": "x",
      "organisation": "AnchorWatch",
      "posted": "2026-07-30T18:30:25Z",
      "role": "on-chain-analysis",
      "why_registered": "Primary source for Hamilton's preliminary accounting: 1,324 UTXOs, 500\ntransactions, a three-block window, 594.48 BTC, and a later 562 BTC\nconsolidation. The post itself says the activity occurred over 15 minutes and\nlabels the analysis preliminary.\n",
      "relation": {
        "kind": "single-post",
        "head_id": null
      },
      "capture": {
        "status": "held",
        "artefact_count": 3,
        "conversation_copies": 0,
        "conversation_posts": 0,
        "conversation_replies": 0,
        "conversation_gaps": []
      }
    },
    {
      "id": "llfourn-2083312169316499663",
      "title": "Pessimistic Mk4 scenario",
      "url": "https://x.com/LLFOURN/status/2083312169316499663",
      "author": "LLFOURN",
      "platform": "x",
      "organisation": null,
      "posted": "2026-07-31T22:01:41Z",
      "role": "independent-analysis",
      "why_registered": "Reports a pessimistic Mk4 scenario of 32 bits of work per target if the UID is\nknown and the button-press count and clock behaviour are more predictable. This\nis an attributed attack model, not a measurement of shipped devices.\n",
      "relation": {
        "kind": "single-post",
        "head_id": null
      },
      "capture": {
        "status": "held",
        "artefact_count": 8,
        "conversation_copies": 0,
        "conversation_posts": 0,
        "conversation_replies": 0,
        "conversation_gaps": []
      }
    },
    {
      "id": "llfourn-2083375420721025313",
      "title": "Time-stamped migration risk",
      "url": "https://x.com/LLFOURN/status/2083375420721025313",
      "author": "LLFOURN",
      "platform": "x",
      "organisation": null,
      "posted": "2026-08-01T02:13:02Z",
      "role": "migration-guidance",
      "why_registered": "A time-stamped risk assessment rather than a durable guarantee: LLFOURN reports\nlittle immediate risk in moving Mk4 multisig on 1 Aug, warns that could change\nwithin days, and describes Unchained's one-size process as sensible for a KYC\nprovider that knows its customer base.\n",
      "relation": {
        "kind": "single-post",
        "head_id": null
      },
      "capture": {
        "status": "held",
        "artefact_count": 8,
        "conversation_copies": 0,
        "conversation_posts": 0,
        "conversation_replies": 0,
        "conversation_gaps": []
      }
    },
    {
      "id": "llfourn-2083298061250666721",
      "title": "Correction to multisig guidance",
      "url": "https://x.com/LLFOURN/status/2083298061250666721",
      "author": "LLFOURN",
      "platform": "x",
      "organisation": null,
      "posted": "2026-07-31T21:05:38Z",
      "role": "migration-guidance",
      "why_registered": "An explicit correction of LLFOURN's earlier multisig guidance: Mk4, Mk5 and Q\nsetups in which affected devices meet the signing threshold, without a mitigating\nfactor such as dice rolls, need to move.\n",
      "relation": {
        "kind": "single-post",
        "head_id": null
      },
      "capture": {
        "status": "held",
        "artefact_count": 6,
        "conversation_copies": 0,
        "conversation_posts": 0,
        "conversation_replies": 0,
        "conversation_gaps": []
      }
    },
    {
      "id": "darosior-emergency-guidance",
      "title": "Emergency migration guidance",
      "url": "https://x.com/darosior/status/2083228876558290979",
      "author": "darosior",
      "platform": "x",
      "organisation": null,
      "posted": "2026-07-31T16:30:43Z",
      "role": "migration-guidance",
      "why_registered": "Antoine Poinsot's high-urgency public warning covering Mk3, Mk4, Mk5 and Q,\nwith a 50-roll pure-dice exception. The scope and urgency are attributed\nguidance; the post does not itself provide evidence that every named model was\nalready being drained.\n",
      "relation": {
        "kind": "single-post",
        "head_id": null
      },
      "capture": {
        "status": "held",
        "artefact_count": 18,
        "conversation_copies": 0,
        "conversation_posts": 0,
        "conversation_replies": 0,
        "conversation_gaps": []
      }
    },
    {
      "id": "instagibbs-reproduction",
      "title": "Independent hardware reproduction",
      "url": "https://x.com/theinstagibbs/status/2082958675975553224",
      "author": "theinstagibbs",
      "platform": "x",
      "organisation": null,
      "posted": "2026-07-30T22:37:02Z",
      "role": "independent-reproduction",
      "why_registered": "Gregory Sanders's concise public result from an independent hardware\nreproduction: Mk2/Mk3 confirmed, with Mk4 explicitly left uncertain. The owned\ndevice inputs and unpublished scripts limit what this establishes about a blind\nremote search.\n",
      "relation": {
        "kind": "single-post",
        "head_id": null
      },
      "capture": {
        "status": "held",
        "artefact_count": 18,
        "conversation_copies": 0,
        "conversation_posts": 0,
        "conversation_replies": 0,
        "conversation_gaps": []
      }
    },
    {
      "id": "kloaec-early-hypothesis",
      "title": "Early low-entropy hypothesis",
      "url": "https://x.com/KLoaec/status/2082926304995762209",
      "author": "KLoaec",
      "platform": "x",
      "organisation": null,
      "posted": "2026-07-30T20:28:24Z",
      "role": "early-analysis",
      "why_registered": "Kevin Loaec's early low-entropy hypothesis, based on BIP84-only scanning,\nlimited derivation depth and partial sweeps. The post labels the account a\ncurrent hypothesis; its claim that the operator used AI remains unverified.\n",
      "relation": {
        "kind": "single-post",
        "head_id": null
      },
      "capture": {
        "status": "held",
        "artefact_count": 3,
        "conversation_copies": 0,
        "conversation_posts": 0,
        "conversation_replies": 0,
        "conversation_gaps": []
      }
    },
    {
      "id": "dhruvbansal-ai-response",
      "title": "Layered security response",
      "url": "https://x.com/dhruvbansal/status/2083262201717244369",
      "author": "dhruvbansal",
      "platform": "x",
      "organisation": null,
      "posted": "2026-07-31T18:43:08Z",
      "role": "ai-response",
      "why_registered": "Dhruv Bansal's broader security response, arguing for layered protections,\nredundancy and human involvement as Bitcoin, AI and computer security overlap.\nIts reference to an attacker using an LLM is commentary, not new attribution\nevidence.\n",
      "relation": {
        "kind": "single-post",
        "head_id": null
      },
      "capture": {
        "status": "held",
        "artefact_count": 3,
        "conversation_copies": 0,
        "conversation_posts": 0,
        "conversation_replies": 0,
        "conversation_gaps": []
      }
    },
    {
      "id": "praveenperera-independent-confirmation",
      "title": "Independent key-recovery confirmation",
      "url": "https://x.com/PraveenPerera/status/2082976249371115811",
      "author": "PraveenPerera",
      "platform": "x",
      "organisation": null,
      "posted": "2026-07-30T23:46:52Z",
      "role": "independent-reproduction",
      "why_registered": "Praveen Perera's first public report that an independent scan recovered two\nprivate keys belonging to the known stolen-address set. The result is preserved\nas reported because the reproduction code and candidate data are not published.\n",
      "relation": {
        "kind": "single-post",
        "head_id": null
      },
      "capture": {
        "status": "held",
        "artefact_count": 3,
        "conversation_copies": 0,
        "conversation_posts": 0,
        "conversation_replies": 0,
        "conversation_gaps": []
      }
    },
    {
      "id": "praveenperera-reproduction-cost",
      "title": "Reported reproduction cost",
      "url": "https://x.com/PraveenPerera/status/2082995029467942947",
      "author": "PraveenPerera",
      "platform": "x",
      "organisation": null,
      "posted": "2026-07-31T01:01:29Z",
      "role": "independent-reproduction",
      "why_registered": "Adds scope and cost to Perera's earlier report: index-zero addresses against a\nknown stolen set, two recovered keys associated with about 34 BTC, roughly five\nminutes and less than US$5 of GPU time. The post also gives urgent dice and\npassphrase advice, which remains an attributed recommendation.\n",
      "relation": {
        "kind": "single-post",
        "head_id": null
      },
      "capture": {
        "status": "held",
        "artefact_count": 3,
        "conversation_copies": 0,
        "conversation_posts": 0,
        "conversation_replies": 0,
        "conversation_gaps": []
      }
    },
    {
      "id": "robhamilton-multisig-psa",
      "title": "Multisig migration PSA",
      "url": "https://x.com/Rob1Ham/status/2083215573928853532",
      "author": "Rob1Ham",
      "platform": "x",
      "organisation": null,
      "posted": "2026-07-31T15:37:51Z",
      "role": "migration-guidance",
      "why_registered": "Origin of the public multisig migration warning and Slipstream recommendation.\nHamilton describes the first-broadcast race for wallets whose affected COLDCARD\nkeys alone meet the threshold. The service recommendation is attributed, not\nindependently guaranteed.\n",
      "relation": {
        "kind": "single-post",
        "head_id": null
      },
      "capture": {
        "status": "held",
        "artefact_count": 3,
        "conversation_copies": 0,
        "conversation_posts": 0,
        "conversation_replies": 0,
        "conversation_gaps": []
      }
    },
    {
      "id": "petertodd-slipstream-guidance",
      "title": "Slipstream endorsement and caveat",
      "url": "https://x.com/peterktodd/status/2083219725094453649",
      "author": "peterktodd",
      "platform": "x",
      "organisation": null,
      "posted": "2026-07-31T15:54:21Z",
      "role": "migration-guidance",
      "why_registered": "Peter Todd expands Hamilton's multisig scenario, endorses private miner\nsubmission, and adds the caveat that an already revealed script does not gain\nthe same protection. The recommendation and service assumptions remain\nattributed.\n",
      "relation": {
        "kind": "single-post",
        "head_id": null
      },
      "capture": {
        "status": "held",
        "artefact_count": 3,
        "conversation_copies": 0,
        "conversation_posts": 0,
        "conversation_replies": 0,
        "conversation_gaps": []
      }
    },
    {
      "id": "portlandhodl-slipstream-access",
      "title": "Slipstream access-code offer",
      "url": "https://x.com/PortlandHODL/status/2083236118175322577",
      "author": "PortlandHODL",
      "platform": "x",
      "organisation": null,
      "posted": "2026-07-31T16:59:29Z",
      "role": "service-access",
      "why_registered": "PortlandHODL publicly offered Slipstream access codes by direct message during\nthe incident. This records the access channel and its authentication risk; it\ndoes not establish service confidentiality or confirmation guarantees.\n",
      "relation": {
        "kind": "single-post",
        "head_id": null
      },
      "capture": {
        "status": "held",
        "artefact_count": 3,
        "conversation_copies": 0,
        "conversation_posts": 0,
        "conversation_replies": 0,
        "conversation_gaps": []
      }
    },
    {
      "id": "coldcard-expanded-scope",
      "title": "Urgent expanded-scope update",
      "url": "https://x.com/COLDCARDwallet/status/2083155034762621425",
      "author": "COLDCARDwallet",
      "platform": "x",
      "organisation": "Coinkite",
      "posted": "2026-07-31T11:37:18Z",
      "role": "vendor-update",
      "why_registered": "Official COLDCARD update expanding the affected scope beyond the initial Mk3 advisory and directing users to model-specific remediation.\n",
      "relation": {
        "kind": "single-post",
        "head_id": null
      },
      "capture": {
        "status": "held",
        "artefact_count": 3,
        "conversation_copies": 0,
        "conversation_posts": 0,
        "conversation_replies": 0,
        "conversation_gaps": []
      }
    },
    {
      "id": "coldcard-mk3-hotfix-update",
      "title": "Mk3 v4.2.0 availability update",
      "url": "https://x.com/COLDCARDwallet/status/2083186689246208474",
      "author": "COLDCARDwallet",
      "platform": "x",
      "organisation": "Coinkite",
      "posted": "2026-07-31T13:43:05Z",
      "role": "vendor-update",
      "why_registered": "Official COLDCARD announcement of the Mk3 v4.2.0 hotfix, useful for bounding the public remediation timeline.\n",
      "relation": {
        "kind": "single-post",
        "head_id": null
      },
      "capture": {
        "status": "held",
        "artefact_count": 3,
        "conversation_copies": 0,
        "conversation_posts": 0,
        "conversation_replies": 0,
        "conversation_gaps": []
      }
    },
    {
      "id": "coldcard-edge-hotfix-update",
      "title": "Edge hotfix availability update",
      "url": "https://x.com/COLDCARDwallet/status/2083234896676356587",
      "author": "COLDCARDwallet",
      "platform": "x",
      "organisation": "Coinkite",
      "posted": "2026-07-31T16:54:38Z",
      "role": "vendor-update",
      "why_registered": "Official COLDCARD announcement naming the Edge hotfix releases 6.6.0X and 6.6.0QX.\n",
      "relation": {
        "kind": "single-post",
        "head_id": null
      },
      "capture": {
        "status": "held",
        "artefact_count": 3,
        "conversation_copies": 0,
        "conversation_posts": 0,
        "conversation_replies": 0,
        "conversation_gaps": []
      }
    },
    {
      "id": "instagibbs-reproduction-followup",
      "title": "Mk3 on-device proof timing",
      "url": "https://x.com/theinstagibbs/status/2083188153318256742",
      "author": "theinstagibbs",
      "platform": "x",
      "organisation": null,
      "posted": "2026-07-31T13:48:54Z",
      "role": "independent-reproduction",
      "why_registered": "Gregory Sanders states the elapsed time from deciding to investigate to an on-device Mk3 proof, while leaving method and brute-force runtime unstated.\n",
      "relation": {
        "kind": "single-post",
        "head_id": null
      },
      "capture": {
        "status": "held",
        "artefact_count": 3,
        "conversation_copies": 0,
        "conversation_posts": 0,
        "conversation_replies": 0,
        "conversation_gaps": []
      }
    },
    {
      "id": "benma-bip85-warning",
      "title": "Benma: BIP85 downstream-wallet warning",
      "url": "https://x.com/_benma_/status/2083375721687511366",
      "author": "_benma_",
      "platform": "x",
      "organisation": null,
      "posted": "2026-08-01T02:14:13Z",
      "role": "downstream-wallet-scope",
      "why_registered": "Independent warning that BIP85 child wallets inherit exposure from an affected COLDCARD master seed and require separate migration consideration.\n",
      "relation": {
        "kind": "single-post",
        "head_id": null
      },
      "capture": {
        "status": "held",
        "artefact_count": 3,
        "conversation_copies": 0,
        "conversation_posts": 0,
        "conversation_replies": 0,
        "conversation_gaps": []
      }
    },
    {
      "id": "kloaec-bip85-warning",
      "title": "Kevin Loaec: BIP85 downstream-wallet warning",
      "url": "https://x.com/KLoaec/status/2083138461452693772",
      "author": "KLoaec",
      "platform": "x",
      "organisation": null,
      "posted": "2026-07-31T10:31:26Z",
      "role": "downstream-wallet-scope",
      "why_registered": "Kevin Loaec warns that BIP85-derived wallets from an affected COLDCARD master seed fall within the migration scope.\n",
      "relation": {
        "kind": "single-post",
        "head_id": null
      },
      "capture": {
        "status": "held",
        "artefact_count": 17,
        "conversation_copies": 0,
        "conversation_posts": 0,
        "conversation_replies": 0,
        "conversation_gaps": []
      }
    },
    {
      "id": "portlandhodl-slipstream-outcome",
      "title": "Reported Slipstream migration outcome",
      "url": "https://x.com/PortlandHODL/status/2083391943799865486",
      "author": "PortlandHODL",
      "platform": "x",
      "organisation": null,
      "posted": "2026-08-01T03:18:41Z",
      "role": "reported-migration-outcome",
      "why_registered": "PortlandHODL reports a specific amount moved through Slipstream for a 2-of-3 multisig case; the result is retained as attributed and unverified.\n",
      "relation": {
        "kind": "single-post",
        "head_id": null
      },
      "capture": {
        "status": "held",
        "artefact_count": 18,
        "conversation_copies": 0,
        "conversation_posts": 0,
        "conversation_replies": 0,
        "conversation_gaps": []
      }
    },
    {
      "id": "guillemet-multisig-relay-analysis",
      "title": "Multisig relay and script-disclosure analysis",
      "url": "https://x.com/P3b7_/status/2083301695606648977",
      "author": "P3b7_",
      "platform": "x",
      "organisation": "Ledger",
      "posted": "2026-07-31T21:20:04Z",
      "role": "independent-technical-analysis",
      "why_registered": "Charles Guillemet explains how script visibility changes a threshold-wallet migration race and recommends private transaction submission; Ledger affiliation requires disclosure.\n",
      "relation": {
        "kind": "single-post",
        "head_id": null
      },
      "capture": {
        "status": "held",
        "artefact_count": 3,
        "conversation_copies": 0,
        "conversation_posts": 0,
        "conversation_replies": 0,
        "conversation_gaps": []
      }
    },
    {
      "id": "ledger-not-affected-response",
      "title": "Ledger not-affected response",
      "url": "https://x.com/Ledger/status/2083225280441721264",
      "author": "Ledger",
      "platform": "x",
      "organisation": "Ledger",
      "posted": "2026-07-31T16:16:25Z",
      "role": "vendor-response",
      "why_registered": "Ledger states that its devices are not affected and describes the architecture and entropy source it says distinguish them.\n",
      "relation": {
        "kind": "single-post",
        "head_id": null
      },
      "capture": {
        "status": "held",
        "artefact_count": 3,
        "conversation_copies": 0,
        "conversation_posts": 0,
        "conversation_replies": 0,
        "conversation_gaps": []
      }
    },
    {
      "id": "casa-incident-guidance",
      "title": "Casa multisig response",
      "url": "https://x.com/CasaHODL/status/2083222263617200589",
      "author": "CasaHODL",
      "platform": "x",
      "organisation": "Casa",
      "posted": "2026-07-31T16:04:26Z",
      "role": "custody-provider-guidance",
      "why_registered": "Casa publishes incident-specific guidance for customers using COLDCARD keys in Casa vault policies.\n",
      "relation": {
        "kind": "single-post",
        "head_id": null
      },
      "capture": {
        "status": "held",
        "artefact_count": 3,
        "conversation_copies": 0,
        "conversation_posts": 0,
        "conversation_replies": 0,
        "conversation_gaps": []
      }
    },
    {
      "id": "nneuman-casa-migration-video",
      "title": "Casa migration video and risk claim",
      "url": "https://x.com/Nneuman/status/2083256427649388797",
      "author": "Nneuman",
      "platform": "x",
      "organisation": "Casa",
      "posted": "2026-07-31T18:20:12Z",
      "role": "custody-provider-guidance",
      "why_registered": "Casa CEO Nick Neuman publishes migration guidance and a threshold-risk claim\nwhose applicability depends on the stated wallet policy and key-provenance\nassumptions.\n",
      "relation": {
        "kind": "single-post",
        "head_id": null
      },
      "capture": {
        "status": "held",
        "artefact_count": 17,
        "conversation_copies": 0,
        "conversation_posts": 0,
        "conversation_replies": 0,
        "conversation_gaps": []
      }
    },
    {
      "id": "dhruvbansal-ai-response-part1",
      "title": "Layered-security response, part 1",
      "url": "https://x.com/dhruvbansal/status/2083262198382801261",
      "author": "dhruvbansal",
      "platform": "x",
      "organisation": null,
      "posted": "2026-07-31T18:43:07Z",
      "role": "ai-security-response",
      "why_registered": "First post in Dhruv Bansal thread, preserving the setup and argument that precede the already registered concluding post.\n",
      "relation": {
        "kind": "single-post",
        "head_id": null
      },
      "capture": {
        "status": "held",
        "artefact_count": 3,
        "conversation_copies": 0,
        "conversation_posts": 0,
        "conversation_replies": 0,
        "conversation_gaps": []
      }
    },
    {
      "id": "dhruvbansal-ai-response-part2",
      "title": "Layered-security response, part 2",
      "url": "https://x.com/dhruvbansal/status/2083262200152821835",
      "author": "dhruvbansal",
      "platform": "x",
      "organisation": null,
      "posted": "2026-07-31T18:43:08Z",
      "role": "ai-security-response",
      "why_registered": "Second post in Dhruv Bansal thread, preserving the middle argument that precedes the already registered concluding post.\n",
      "relation": {
        "kind": "single-post",
        "head_id": null
      },
      "capture": {
        "status": "held",
        "artefact_count": 3,
        "conversation_copies": 0,
        "conversation_posts": 0,
        "conversation_replies": 0,
        "conversation_gaps": []
      }
    },
    {
      "id": "zherbert-opendime-entropy-test",
      "title": "OPENDIME entropy-incorporation test",
      "url": "https://x.com/zherbert/status/2083399238445056082",
      "author": "zherbert",
      "platform": "x",
      "organisation": "Foundation Devices",
      "posted": "2026-08-01T03:47:40Z",
      "role": "product-scope-test",
      "why_registered": "Foundation Devices co-founder and CEO Zach Herbert reports a physical OPENDIME\nentropy test and provides device-specific evidence bearing on the not-affected\nclaim. Foundation sells competing hardware-wallet products, so that affiliation\nis relevant to the report's provenance.\n",
      "relation": {
        "kind": "single-post",
        "head_id": null
      },
      "capture": {
        "status": "held",
        "artefact_count": 3,
        "conversation_copies": 0,
        "conversation_posts": 0,
        "conversation_replies": 0,
        "conversation_gaps": []
      }
    },
    {
      "id": "robhamilton-opendime-tapsigner-scope",
      "title": "OPENDIME and TAPSIGNER scope response",
      "url": "https://x.com/Rob1Ham/status/2083403595995611223",
      "author": "Rob1Ham",
      "platform": "x",
      "organisation": null,
      "posted": "2026-08-01T04:04:59Z",
      "role": "independent-product-scope",
      "why_registered": "Rob Hamilton responds to the OPENDIME test, distinguishes its observed entropy incorporation from the harder-to-verify closed-source TAPSIGNER claim.\n",
      "relation": {
        "kind": "single-post",
        "head_id": null
      },
      "capture": {
        "status": "held",
        "artefact_count": 3,
        "conversation_copies": 0,
        "conversation_posts": 0,
        "conversation_replies": 0,
        "conversation_gaps": []
      }
    },
    {
      "id": "jamesob-dice-roll-guidance",
      "title": "99-roll migration guidance",
      "url": "https://x.com/jamesob/status/2083195361313656949",
      "author": "jamesob",
      "platform": "x",
      "organisation": null,
      "posted": "2026-07-31T14:17:32Z",
      "role": "incident-response-guidance",
      "why_registered": "James O'Beirne recommends migration for affected COLDCARD seeds generated with\nfewer than 99 dice rolls, documenting stricter public guidance than the vendor's\n50-roll threshold.\n",
      "relation": {
        "kind": "single-post",
        "head_id": null
      },
      "capture": {
        "status": "held",
        "artefact_count": 3,
        "conversation_copies": 0,
        "conversation_posts": 0,
        "conversation_replies": 0,
        "conversation_gaps": []
      }
    },
    {
      "id": "alwaysaimbig-multisig-webinar-question",
      "title": "Reader post with attached multisig webinar slide",
      "url": "https://x.com/alwaysaimbig/status/2083373191389425765",
      "author": "alwaysaimbig",
      "platform": "x",
      "organisation": null,
      "posted": "2026-08-01T02:04:10Z",
      "role": "community-question",
      "why_registered": "Zach's post includes a slide headed \"An Unchained vault with 2\nColdcard-generated keys: Group A\" and describes it as webinar guidance. The\npost, complete attached image and attachment transcript are held. The archive\nhas not independently authenticated the slide's authorship, webinar context or\nthe complete presentation. The unversioned PNG and text capture are preserved\nas an incomplete first attempt; the timestamped PNG, JPG attachment and text\ncapture supersede them for reading the post and slide.\n",
      "relation": {
        "kind": "single-post",
        "head_id": null
      },
      "capture": {
        "status": "held",
        "artefact_count": 17,
        "conversation_copies": 0,
        "conversation_posts": 0,
        "conversation_replies": 0,
        "conversation_gaps": []
      }
    },
    {
      "id": "coldcard-urgent-migration-appeal",
      "title": "COLDCARD Urgent Migration Appeal",
      "url": "https://x.com/COLDCARDwallet/status/2083513501662765530",
      "author": "COLDCARDwallet",
      "platform": "x",
      "organisation": null,
      "posted": "2026-08-01T11:21:43Z",
      "role": "vendor-update",
      "why_registered": "Coinkite's 1 August escalation post asks users to treat migration as urgent and to spread the word to less-online owners. It quotes the vendor's 31 July urgent update, whose wording states the Mk3 affected boundary as 4.0.1+ and carves out seeds generated with at least 50 private, independent dice rolls. Both details bear directly on the affected-range boundary and the mixed-dice classification recorded elsewhere in this archive.\n",
      "relation": {
        "kind": "single-post",
        "head_id": null
      },
      "capture": {
        "status": "held",
        "artefact_count": 3,
        "conversation_copies": 0,
        "conversation_posts": 0,
        "conversation_replies": 0,
        "conversation_gaps": []
      }
    },
    {
      "id": "kloaec-mk4-class-drain-report",
      "title": "KLoaec Mk4 Class Drain Report",
      "url": "https://x.com/KLoaec/status/2083530439101239380",
      "author": "KLoaec",
      "platform": "x",
      "organisation": null,
      "posted": "2026-08-01T12:29:01Z",
      "role": "on-chain-analysis",
      "why_registered": "Kevin Loaec of Wizardsardine states on 1 August that Mk4, Mk5 and Q wallets are now being actively drained, quoting Tomer Strolight's account of an intentionally seeded Mk4 honeypot swept overnight to a named bc1q address. If corroborated on chain this is the first reported Mk4-class sweep, extending observed exploitation beyond the roughly 40-bit Mk3 space; the claim itself remains a reported third-party account.\n",
      "relation": {
        "kind": "single-post",
        "head_id": null
      },
      "capture": {
        "status": "held",
        "artefact_count": 3,
        "conversation_copies": 0,
        "conversation_posts": 0,
        "conversation_replies": 0,
        "conversation_gaps": []
      }
    },
    {
      "id": "kloaec-wizardsardine-postmortem",
      "title": "KLoaec Wizardsardine Postmortem",
      "url": "https://x.com/KLoaec/status/2083579776887922865",
      "author": "KLoaec",
      "platform": "x",
      "organisation": null,
      "posted": "2026-08-01T15:45:04Z",
      "role": "independent-analysis",
      "why_registered": "Kevin Loaec announces Wizardsardine's long-form post-mortem of the COLDCARD flaw, summarising it as worse than commonly understood because users with safe mnemonics, including dice-generated ones, still face broken features on affected devices. The linked blog post is captured separately as a web source; this post records the framing and the author's request for corrections.\n",
      "relation": {
        "kind": "single-post",
        "head_id": null
      },
      "capture": {
        "status": "held",
        "artefact_count": 3,
        "conversation_copies": 0,
        "conversation_posts": 0,
        "conversation_replies": 0,
        "conversation_gaps": []
      }
    },
    {
      "id": "kloaec-derived-feature-exposure",
      "title": "KLoaec Derived Feature Exposure",
      "url": "https://x.com/KLoaec/status/2083580367970193449",
      "author": "KLoaec",
      "platform": "x",
      "organisation": null,
      "posted": "2026-08-01T15:47:25Z",
      "role": "downstream-wallet-scope",
      "why_registered": "Kevin Loaec stresses that even users who imported a seed or generated one with dice are exposed if they used certain COLDCARD features, with an attached graphic enumerating them. This extends the incident's blast radius beyond seed generation into derived-material features and aligns with the Wizardsardine post-mortem's broken-features section; the specific feature list is the vendor-independent claim to check against source.\n",
      "relation": {
        "kind": "single-post",
        "head_id": null
      },
      "capture": {
        "status": "held",
        "artefact_count": 18,
        "conversation_copies": 0,
        "conversation_posts": 0,
        "conversation_replies": 0,
        "conversation_gaps": []
      }
    },
    {
      "id": "claygarrett-bitkey-initial-findings",
      "title": "Claygarrett Bitkey Initial Findings",
      "url": "https://x.com/clay_garrett/status/2083585966481068398",
      "author": "clay_garrett",
      "platform": "x",
      "organisation": null,
      "posted": "2026-08-01T16:09:40Z",
      "role": "vendor-response",
      "why_registered": "Block hardware lead Clay Garrett shares initial findings on a separately reported Bitkey vulnerability disclosed by 1440000bytes, stating it requires exceptional circumstances during inheritance setup, yields insufficient key material even if exploited, and that a mobile-app patch ships same day. Recorded because Block is a primary party in the COLDCARD incident record and this statement shows its concurrent security posture; the Bitkey issue itself is distinct from the COLDCARD RNG flaw.\n",
      "relation": {
        "kind": "single-post",
        "head_id": null
      },
      "capture": {
        "status": "held",
        "artefact_count": 3,
        "conversation_copies": 0,
        "conversation_posts": 0,
        "conversation_replies": 0,
        "conversation_gaps": []
      }
    },
    {
      "id": "btcpp-dettmer-analysis-announcement",
      "title": "Btcpp Dettmer Analysis Announcement",
      "url": "https://x.com/btcinsider__/status/2083592498954572145",
      "author": "btcinsider__",
      "platform": "x",
      "organisation": null,
      "posted": "2026-08-01T16:35:37Z",
      "role": "independent-analysis",
      "why_registered": "bitcoin++ Insider Edition announces Dustin Dettmer's commit-history walkthrough of how the COLDCARD entropy bug was introduced, titled 'When random.bytes() runs but doesn't work'. The linked article is captured separately as a web source; this post records the publication and its framing.\n",
      "relation": {
        "kind": "single-post",
        "head_id": null
      },
      "capture": {
        "status": "held",
        "artefact_count": 5,
        "conversation_copies": 0,
        "conversation_posts": 0,
        "conversation_replies": 0,
        "conversation_gaps": []
      }
    },
    {
      "id": "glxyresearch-third-wave-revision",
      "title": "Galaxy Research Third Wave Revision",
      "url": "https://x.com/glxyresearch/status/2083623500183421043",
      "author": "glxyresearch",
      "platform": "x",
      "organisation": null,
      "posted": "2026-08-01T18:38:48Z",
      "role": "on-chain-analysis",
      "why_registered": "Galaxy Research's 1 August revision identifying a third sweep wave of 207.7294 BTC and raising its estimated observed total to 1,367.05 BTC across 4,585 addresses, superseding the roughly 1,083 BTC figure quoted earlier in this archive. The thread also states that no coin drained in waves 1 to 3 was created before block 674,951 on 17 March 2021, which bears independently on the affected-range lower bound, and carries Galaxy's own disclaimer that the work derives solely from block data and the unspent-output set without testing whether the identified addresses were in fact generated with low entropy.\n",
      "relation": {
        "kind": "single-post",
        "head_id": null
      },
      "capture": {
        "status": "held",
        "artefact_count": 18,
        "conversation_copies": 0,
        "conversation_posts": 0,
        "conversation_replies": 0,
        "conversation_gaps": []
      }
    },
    {
      "id": "glxyresearch-methodology-disclaimer",
      "title": "Galaxy Research Methodology Disclaimer",
      "url": "https://x.com/glxyresearch/status/2083623504285421622",
      "author": "glxyresearch",
      "platform": "x",
      "organisation": null,
      "posted": "2026-08-01T18:38:49Z",
      "role": "on-chain-analysis",
      "why_registered": "Galaxy Research's own scope disclaimer for its wave analysis: the work derives solely from Bitcoin block data and the unspent-output set, and Galaxy has not used compute to test whether the addresses it identifies as possible victims were in fact generated with low entropy. This bounds every Galaxy figure quoted in this archive and is the reason those totals are recorded as attributed observations rather than established causation.\n",
      "relation": {
        "kind": "single-post",
        "head_id": null
      },
      "capture": {
        "status": "held",
        "artefact_count": 3,
        "conversation_copies": 0,
        "conversation_posts": 0,
        "conversation_replies": 0,
        "conversation_gaps": []
      }
    },
    {
      "id": "glxyresearch-firmware-block-boundary",
      "title": "Galaxy Research Firmware Block Boundary",
      "url": "https://x.com/glxyresearch/status/2083623541921001756",
      "author": "glxyresearch",
      "platform": "x",
      "organisation": null,
      "posted": "2026-08-01T18:38:58Z",
      "role": "on-chain-analysis",
      "why_registered": "Galaxy Research states that the vulnerable COLDCARD firmware shipped on 17 March 2021 around block 674,951, and that no coin identified in waves 1 to 3 was created before that block. This bears independently on the affected-range lower bound: 17 March 2021 is the v4.0.0 release date recorded here, not the 29 March 2021 v4.0.1 date that the vendor advisory uses as its stated boundary.\n",
      "relation": {
        "kind": "single-post",
        "head_id": null
      },
      "capture": {
        "status": "held",
        "artefact_count": 18,
        "conversation_copies": 0,
        "conversation_posts": 0,
        "conversation_replies": 0,
        "conversation_gaps": []
      }
    },
    {
      "id": "glxyresearch-attacker-holdings",
      "title": "Galaxy Research Attacker Holdings",
      "url": "https://x.com/glxyresearch/status/2083623527366734239",
      "author": "glxyresearch",
      "platform": "x",
      "organisation": null,
      "posted": "2026-08-01T18:38:55Z",
      "role": "on-chain-analysis",
      "why_registered": "Galaxy Research reports 1,366.3865 BTC under attacker control with all endpoint attacker addresses fully unspent on chain as of 1 August 2026. Recorded alongside the funds accounting because it is the outcome question a reader asks after the sweep totals, and because an unspent endpoint set is the condition under which any later movement becomes newsworthy.\n",
      "relation": {
        "kind": "single-post",
        "head_id": null
      },
      "capture": {
        "status": "held",
        "artefact_count": 18,
        "conversation_copies": 0,
        "conversation_posts": 0,
        "conversation_replies": 0,
        "conversation_gaps": []
      }
    },
    {
      "id": "glxyresearch-same-operator-basis",
      "title": "Galaxy Research Same Operator Basis",
      "url": "https://x.com/glxyresearch/status/2083623511126638642",
      "author": "glxyresearch",
      "platform": "x",
      "organisation": null,
      "posted": "2026-08-01T18:38:51Z",
      "role": "on-chain-analysis",
      "why_registered": "Galaxy Research states the basis for treating the sweep waves as one operator: waves 1 and 2 share funnel topology into a handful of collectors, the same P2WPKH destinations and the same mix of derivation paths, 27 hours apart, and that treating them as one operator is reasonable but rests on resemblance rather than proof. This is the attribution qualifier behind every same-operator total quoted in this archive.\n",
      "relation": {
        "kind": "single-post",
        "head_id": null
      },
      "capture": {
        "status": "held",
        "artefact_count": 18,
        "conversation_copies": 0,
        "conversation_posts": 0,
        "conversation_replies": 0,
        "conversation_gaps": []
      }
    },
    {
      "id": "lopp-scam-playbook-update",
      "title": "Lopp Scam Playbook Update",
      "url": "https://x.com/lopp/status/2083614303127547977",
      "author": "lopp",
      "platform": "x",
      "organisation": null,
      "posted": "2026-08-01T18:02:16Z",
      "role": "scam-report",
      "why_registered": "Jameson Lopp posts a screenshot of a Telegram account impersonating COLDCARD WALLET that messaged a user on 1 August, opening with rapport rather than an immediate credential request: the sender claims database records showing the recipient was an early user and asks whether they moved their funds safely. The capture also shows Telegram's own contact panel marking the account Not an official account, registered March 2026, and the blue mark identified in-app as a Premium subscriber badge rather than verification. Quoted above his 31 July warning that phishing mail posing as Coinkite security notices would follow. First-hand documentary evidence of an impersonation channel exploiting this incident's migration guidance.\n",
      "relation": {
        "kind": "single-post",
        "head_id": null
      },
      "capture": {
        "status": "held",
        "artefact_count": 19,
        "conversation_copies": 0,
        "conversation_posts": 0,
        "conversation_replies": 0,
        "conversation_gaps": []
      }
    },
    {
      "id": "lopp-phishing-prediction",
      "title": "Lopp Phishing Prediction",
      "url": "https://x.com/lopp/status/2083205974907621835",
      "author": "lopp",
      "platform": "x",
      "organisation": null,
      "posted": "2026-07-31T14:59:43Z",
      "role": "scam-report",
      "why_registered": "Jameson Lopp predicts on 31 July that phishing mail posing as Coinkite security notices will follow the disclosure and will try to get readers to type recovery words into a malicious site. Held because his 1 August impersonation screenshot quote-tweets this post: together they are a dated prediction and a dated artefact, and the pairing is what distinguishes a documented scam from an anticipated one.\n",
      "relation": {
        "kind": "single-post",
        "head_id": null
      },
      "capture": {
        "status": "held",
        "artefact_count": 3,
        "conversation_copies": 0,
        "conversation_posts": 0,
        "conversation_replies": 0,
        "conversation_gaps": []
      }
    },
    {
      "id": "coldcard-outreach-complete",
      "title": "Email outreach to all reachable customers complete",
      "url": "https://x.com/coldcardwallet/status/2083741922070352247",
      "author": "COLDCARDwallet",
      "platform": "x",
      "organisation": "Coinkite",
      "posted": "2026-08-02T02:29:22Z",
      "role": "social-statement",
      "why_registered": "Vendor statement that batched email outreach reached every address available through its store and newsletter systems, which bears on the notification timeline.",
      "relation": {
        "kind": "single-post",
        "head_id": null
      },
      "capture": {
        "status": "held",
        "artefact_count": 37,
        "conversation_copies": 0,
        "conversation_posts": 0,
        "conversation_replies": 0,
        "conversation_gaps": []
      }
    },
    {
      "id": "coldcard-pii-policy",
      "title": "Reply on outreach data handling and PII deletion",
      "url": "https://x.com/coldcardwallet/status/2083880615242260697",
      "author": "COLDCARDwallet",
      "platform": "x",
      "organisation": "Coinkite",
      "posted": "2026-08-02T11:40:29Z",
      "role": "social-statement",
      "why_registered": "Vendor statement on customer-data handling during outreach: phone numbers and PII deleted, many customers unreachable by email, and an acknowledgement that an earlier post could have been worded better.",
      "relation": {
        "kind": "single-post",
        "head_id": null
      },
      "capture": {
        "status": "held",
        "artefact_count": 17,
        "conversation_copies": 0,
        "conversation_posts": 0,
        "conversation_replies": 0,
        "conversation_gaps": []
      }
    },
    {
      "id": "marius-mk2-drain-report",
      "title": "Report of a continuing sweep including a Mk2 device",
      "url": "https://x.com/mariusoffchain/status/2083814011859030252",
      "author": "mariusoffchain",
      "platform": "x",
      "organisation": null,
      "posted": "2026-08-02T07:15:50Z",
      "role": "social-statement",
      "why_registered": "Reported claim that sweeps were continuing on 2 August, including a Mk2 device, with a named consolidation address aggregating about 64 BTC across roughly 890 inputs. Bears on the ongoing-drain timeline and on model scope if verified.",
      "relation": {
        "kind": "single-post",
        "head_id": null
      },
      "capture": {
        "status": "held",
        "artefact_count": 17,
        "conversation_copies": 0,
        "conversation_posts": 0,
        "conversation_replies": 0,
        "conversation_gaps": []
      }
    },
    {
      "id": "thorn-thorchain-peel",
      "title": "Victim funds peeled over THORChain to a casino",
      "url": "https://x.com/intangiblecoins/status/2083792644048597326",
      "author": "intangiblecoins",
      "platform": "x",
      "organisation": "Galaxy",
      "posted": "2026-08-02T05:50:55Z",
      "role": "social-statement",
      "why_registered": "Reported fund-flow development beyond the consolidation cluster: part of one victim's BTC bridged to ETH via THORChain and deposited at a gambling site, with outreach emails sent by the victim and a researcher.",
      "relation": {
        "kind": "single-post",
        "head_id": null
      },
      "capture": {
        "status": "held",
        "artefact_count": 2,
        "conversation_copies": 0,
        "conversation_posts": 0,
        "conversation_replies": 0,
        "conversation_gaps": []
      }
    },
    {
      "id": "gegelsmr4-licensing-history",
      "title": "Commentary on COLDCARD licensing history and review",
      "url": "https://x.com/gegelsmr4/status/2083716607977967622",
      "author": "gegelsmr4",
      "platform": "x",
      "organisation": null,
      "posted": "2026-08-02T00:48:47Z",
      "role": "commentary",
      "why_registered": "Community account linking the firmware's Trezor-derived origins and the post-Passport Commons Clause relicensing to the outside-review question. Attributed commentary, not primary analysis.",
      "relation": {
        "kind": "single-post",
        "head_id": null
      },
      "capture": {
        "status": "held",
        "artefact_count": 2,
        "conversation_copies": 0,
        "conversation_posts": 0,
        "conversation_replies": 0,
        "conversation_gaps": []
      }
    },
    {
      "id": "pledditor-remaining-stock",
      "title": "Claim that affected stock remains on sale with an added disclosure",
      "url": "https://x.com/Pledditor/status/2083915097559253044",
      "author": "Pledditor",
      "platform": "x",
      "organisation": null,
      "posted": "2026-08-02T13:57:31Z",
      "role": "commentary",
      "why_registered": "Reported claim that Coinkite added a disclosure to its store stating remaining devices carry the affected firmware, rather than halting sales. Bears on the vendor-response record and, if the store text changed, on the source-revision record. The store page itself is not yet a tracked source.",
      "relation": {
        "kind": "single-post",
        "head_id": null
      },
      "capture": {
        "status": "held",
        "artefact_count": 14,
        "conversation_copies": 0,
        "conversation_posts": 0,
        "conversation_replies": 0,
        "conversation_gaps": []
      }
    },
    {
      "id": "rot13maxi-ifndef-explanation",
      "title": "The guard is a definedness check, not a truth check",
      "url": "https://x.com/rot13maxi/status/2083870550347157787",
      "author": "rot13maxi",
      "platform": "x",
      "organisation": null,
      "posted": "2026-08-02T11:00:30Z",
      "role": "independent-technical-analysis",
      "why_registered": "Quotes the guard itself and states the mechanism in one line: the ifndef tests whether the macro is defined rather than whether it is true, so the error never fired and readers believed the hardware generator was enabled. Independently corroborates the same correction Greg Maxwell published on Hacker News, and bears on how the explainer describes the guard.",
      "relation": {
        "kind": "single-post",
        "head_id": null
      },
      "capture": {
        "status": "held",
        "artefact_count": 8,
        "conversation_copies": 0,
        "conversation_posts": 0,
        "conversation_replies": 0,
        "conversation_gaps": []
      }
    },
    {
      "id": "utxoclub-prior-ai-prompt",
      "title": "Claim of an AI prompt naming weak RNG seven weeks before disclosure",
      "url": "https://x.com/utxoclub/status/2083837995300618625",
      "author": "utxoclub",
      "platform": "x",
      "organisation": null,
      "posted": "2026-08-02T08:51:08Z",
      "role": "ai-discovery-claim",
      "why_registered": "Claims a large language model was pointed at the COLDCARD firmware roughly seven weeks before disclosure with a prompt whose second item was weak RNG source. Bears on the AI-discovery question, with the distinction the page must preserve: naming weak randomness as a category to look for is not the same as identifying this specific defect, and the post is a claim about the poster's own prior work rather than a published finding.",
      "relation": {
        "kind": "single-post",
        "head_id": null
      },
      "capture": {
        "status": "held",
        "artefact_count": 14,
        "conversation_copies": 0,
        "conversation_posts": 0,
        "conversation_replies": 0,
        "conversation_gaps": []
      }
    },
    {
      "id": "odell-victim-support-account",
      "title": "First-hand account of assisting affected owners",
      "url": "https://x.com/ODELLXYZ/status/2083919877090463856",
      "author": "ODELLXYZ",
      "platform": "x",
      "organisation": null,
      "posted": "2026-08-02T14:16:30Z",
      "role": "social-statement",
      "why_registered": "A widely followed Bitcoin educator describing two days spent helping owners move funds, and revising his own prior recommendation of the device. Community-response material rather than technical evidence, held because the response of trusted intermediaries is part of what happened to owners.",
      "relation": {
        "kind": "single-post",
        "head_id": null
      },
      "capture": {
        "status": "held",
        "artefact_count": 4,
        "conversation_copies": 0,
        "conversation_posts": 0,
        "conversation_replies": 0,
        "conversation_gaps": []
      }
    },
    {
      "id": "percoco-coldcard-article",
      "title": "Percoco post linking a longer piece on the incident",
      "url": "https://x.com/c7five/status/2083884290442469678",
      "author": "c7five",
      "platform": "x",
      "organisation": "Kraken",
      "posted": "2026-08-02T11:55:06Z",
      "role": "reporting",
      "why_registered": "Post consists of a link to an X-hosted long-form article (x.com/i/article/2083882294855512064) by Kraken's chief security officer. Registered so the capture holds whatever the linked piece says; the article itself is not separately fetchable through the scripted path.",
      "relation": {
        "kind": "single-post",
        "head_id": null
      },
      "capture": {
        "status": "held",
        "artefact_count": 14,
        "conversation_copies": 0,
        "conversation_posts": 0,
        "conversation_replies": 0,
        "conversation_gaps": []
      }
    },
    {
      "id": "robhamilton-where-to-move",
      "title": "Answer to the most common question: where to move funds",
      "url": "https://x.com/Rob1Ham/status/2083936334511538368",
      "author": "Rob1Ham",
      "platform": "x",
      "organisation": "AnchorWatch",
      "posted": "2026-08-02T15:21:54Z",
      "role": "social-statement",
      "why_registered": "Addresses the question owners are actually asking, naming alternatives the author would use. Held with the conflict already disclosed elsewhere on this site: Hamilton is at AnchorWatch and originated the Slipstream recommendation, so his guidance is attributed rather than adopted.",
      "relation": {
        "kind": "single-post",
        "head_id": null
      },
      "capture": {
        "status": "held",
        "artefact_count": 4,
        "conversation_copies": 0,
        "conversation_posts": 0,
        "conversation_replies": 0,
        "conversation_gaps": []
      }
    },
    {
      "id": "hodlbits-donation-objection",
      "title": "Objection to a victim-donation drive routed through a hashrate scheme",
      "url": "https://x.com/HodlBits/status/2083886349594021912",
      "author": "HodlBits",
      "platform": "x",
      "organisation": null,
      "posted": "2026-08-02T12:03:17Z",
      "role": "commentary",
      "why_registered": "States an objection, in strong terms, to a fundraising effort presented as being for victims and routed through a hashrate-renting arrangement. Held as attributed community criticism of the post-incident fundraising, not as a finding about who organised what or where funds went; neither is established here.",
      "relation": {
        "kind": "single-post",
        "head_id": null
      },
      "capture": {
        "status": "held",
        "artefact_count": 13,
        "conversation_copies": 0,
        "conversation_posts": 0,
        "conversation_replies": 0,
        "conversation_gaps": []
      }
    },
    {
      "id": "lopp-entropy-remark",
      "title": "Short remark on entropy during the incident",
      "url": "https://x.com/lopp/status/2083893075785531504",
      "author": "lopp",
      "platform": "x",
      "organisation": "Casa",
      "posted": "2026-08-02T12:30:00Z",
      "role": "commentary",
      "why_registered": "Brief remark, quoting other material, from a widely followed security commentator during the aftermath. Held for the response record; the substance sits in what it quotes.",
      "relation": {
        "kind": "single-post",
        "head_id": null
      },
      "capture": {
        "status": "held",
        "artefact_count": 15,
        "conversation_copies": 0,
        "conversation_posts": 0,
        "conversation_replies": 0,
        "conversation_gaps": []
      }
    },
    {
      "id": "kloaec-dice-not-your-fault",
      "title": "Owners who did not roll dice did nothing wrong",
      "url": "https://x.com/KLoaec/status/2083900851081388340",
      "author": "KLoaec",
      "platform": "x",
      "organisation": "Wizardsardine",
      "posted": "2026-08-02T13:00:54Z",
      "role": "independent-technical-analysis",
      "why_registered": "Addresses owners blaming themselves for not adding dice or a passphrase: device entropy is normally expected to be better than human-generated entropy, so declining to roll dice was reasonable, and the failure is that the device did not do the job it was bought for. Bears directly on the framing of the dice and passphrase pages, which must not imply owners were negligent.",
      "relation": {
        "kind": "single-post",
        "head_id": null
      },
      "capture": {
        "status": "held",
        "artefact_count": 4,
        "conversation_copies": 0,
        "conversation_posts": 0,
        "conversation_replies": 0,
        "conversation_gaps": []
      }
    },
    {
      "id": "nunchuk-advisory-update",
      "title": "Nunchuk advisory update and multisig guidance",
      "url": "https://x.com/nunchuk_io/status/2083034519183966214",
      "author": "nunchuk_io",
      "platform": "x",
      "organisation": "Nunchuk",
      "posted": "2026-07-31T03:38:24Z",
      "role": "custody-provider-guidance",
      "why_registered": "Nunchuk's public guidance thread following Block's analysis: treats any\non-device Coldcard seed since 2021 as suspect pending Coinkite's full report,\nand refines its multisig guidance to distinguish one compromised key from a\nquorum composed entirely of affected Coldcard seeds. Nunchuk is also reported\nto have emailed subscribers before posting publicly; the email itself is not\nin this archive.\n",
      "relation": {
        "kind": "single-post",
        "head_id": null
      },
      "capture": {
        "status": "held",
        "artefact_count": 2,
        "conversation_copies": 0,
        "conversation_posts": 0,
        "conversation_replies": 0,
        "conversation_gaps": []
      }
    },
    {
      "id": "csbastiat-nunchuk-criticism",
      "title": "Criticism of Nunchuk platform-key disclosure timing",
      "url": "https://x.com/CSBastiat/status/2083242346020323447",
      "author": "CSBastiat",
      "platform": "x",
      "organisation": null,
      "posted": "2026-07-31T17:24:14Z",
      "role": "commentary",
      "why_registered": "States, in strong terms, that Nunchuk should have disclosed sooner that its\nplatform keys were generated with Coldcards, arguing every Nunchuk multisig\nuser unknowingly held an extra Coldcard-generated key. Held as attributed\ncommunity criticism of a provider's disclosure timing. The attached image\n(archived as an attachment, never displayed) is a crop of a Nunchuk statement\nheaded \"How this affects Nunchuk platform keys\": some platform keys were\ngenerated with a Coldcard Mk4, custom derivation logic means the seeds are\nnot used directly, and Nunchuk assumes an attacker's lookup table would\neventually include the derived keys. Which channel the crop came from (the\nsubscriber email or a notice page) is unconfirmed.\n",
      "relation": {
        "kind": "single-post",
        "head_id": null
      },
      "capture": {
        "status": "held",
        "artefact_count": 11,
        "conversation_copies": 0,
        "conversation_posts": 0,
        "conversation_replies": 0,
        "conversation_gaps": []
      }
    },
    {
      "id": "mallers-coldcard-alert",
      "title": "Strike CEO severity alert",
      "url": "https://x.com/jackmallers/status/2083224256976953706",
      "author": "jackmallers",
      "platform": "x",
      "organisation": "Strike",
      "posted": "2026-07-31T16:12:21Z",
      "role": "incident-response-guidance",
      "why_registered": "Strike's CEO calls this one of the most serious wallet security incidents\nBitcoin has seen and urges affected users to act and to contact others who\nuse the device. A severity characterisation from an exchange CEO, held as\nattributed commentary with reach, not as analysis. Element screenshot refused\ntwice on 3 Aug 2026 (the attached video did not hydrate); the video itself\nwas captured via gallery-dl (local only, video files are gitignored).\nScreenshot retry pending; joins the withheld set until it succeeds.\n",
      "relation": {
        "kind": "single-post",
        "head_id": null
      },
      "capture": {
        "status": "held",
        "artefact_count": 11,
        "conversation_copies": 0,
        "conversation_posts": 0,
        "conversation_replies": 0,
        "conversation_gaps": []
      }
    },
    {
      "id": "strike-temporary-custody-offer",
      "title": "Strike as interim venue during migrations",
      "url": "https://x.com/jackmallers/status/2083589549666496790",
      "author": "jackmallers",
      "platform": "x",
      "organisation": "Strike",
      "posted": "2026-08-01T16:23:54Z",
      "role": "service-access",
      "why_registered": "Reports that many users are moving bitcoin to Strike while rebuilding cold\nstorage and offers the exchange as an interim venue, with help offered to\nnon-customers too. Registered as a provider positioning itself as a\nmigration destination; the inflow claim is the company's own and is not\nverified here.\n",
      "relation": {
        "kind": "single-post",
        "head_id": null
      },
      "capture": {
        "status": "held",
        "artefact_count": 2,
        "conversation_copies": 0,
        "conversation_posts": 0,
        "conversation_replies": 0,
        "conversation_gaps": []
      }
    },
    {
      "id": "opensats-nvk-board-departure",
      "title": "NVK OpenSats board departure",
      "url": "https://x.com/opensats/status/2084017521376866402",
      "author": "OpenSats",
      "platform": "x",
      "organisation": "OpenSats",
      "posted": "2026-08-02T20:44:30Z",
      "role": "incident-fallout",
      "why_registered": "OpenSats' statement that NVK is stepping down from its board effective immediately, with an eight-person board continuing until a replacement is made. No reason is stated in the post.",
      "relation": {
        "kind": "single-post",
        "head_id": null
      },
      "capture": {
        "status": "held",
        "artefact_count": 2,
        "conversation_copies": 0,
        "conversation_posts": 0,
        "conversation_replies": 0,
        "conversation_gaps": []
      }
    },
    {
      "id": "benowhere-bitkey-entropy-answer",
      "title": "Bitkey entropy long-form answer",
      "url": "https://x.com/BEN0WHERE/status/2084027233656860920",
      "author": "BEN0WHERE",
      "platform": "x",
      "organisation": null,
      "posted": "2026-08-02T21:23:06Z",
      "role": "downstream-wallet-scope",
      "why_registered": "Long-form answer to whether Bitkey has enough entropy, written from the Bitkey team's perspective: three keys generated in separate environments, with the stated OS RNG, EFR32MG24 Secure Vault TRNG and server-module sources named per key.",
      "relation": {
        "kind": "single-post",
        "head_id": null
      },
      "capture": {
        "status": "held",
        "artefact_count": 2,
        "conversation_copies": 0,
        "conversation_posts": 0,
        "conversation_replies": 0,
        "conversation_gaps": []
      }
    },
    {
      "id": "coldcard-update-sunday",
      "title": "Vendor Sunday update",
      "url": "https://x.com/coldcardwallet/status/2084051697148498394",
      "author": "COLDCARDwallet",
      "platform": "x",
      "organisation": "Coinkite",
      "posted": "2026-08-02T23:00:19Z",
      "role": "vendor-update",
      "why_registered": "Coinkite's 'Update, Sunday' statement: acknowledges permanent damage and hard questions about the company, describes direct customer outreach and migration help since Friday, thanks unpaid community helpers, and commits to continued work with the wider self-custody community.",
      "relation": {
        "kind": "single-post",
        "head_id": null
      },
      "capture": {
        "status": "held",
        "artefact_count": 8,
        "conversation_copies": 0,
        "conversation_posts": 0,
        "conversation_replies": 0,
        "conversation_gaps": []
      }
    },
    {
      "id": "korraflow-duel-freeze-exception",
      "title": "Duel one-time freeze exception",
      "url": "https://x.com/korraflow/status/2083812755409191373",
      "author": "korraflow",
      "platform": "x",
      "organisation": null,
      "posted": "2026-08-02T07:10:50Z",
      "role": "funds-recovery",
      "why_registered": "Duel's reply to the report of a ~30 BTC victim's funds peeled over THORChain: it will not freeze balances on third-party claims as policy, but offers a one-time exception if the victim signs a message from a drained address, signs an affidavit and shows the evidence trail to Duel.",
      "relation": {
        "kind": "single-post",
        "head_id": null
      },
      "capture": {
        "status": "held",
        "artefact_count": 2,
        "conversation_copies": 0,
        "conversation_posts": 0,
        "conversation_replies": 0,
        "conversation_gaps": []
      }
    },
    {
      "id": "intangiblecoins-wave4-announcement",
      "title": "Original wave-4 announcement",
      "url": "https://x.com/intangiblecoins/status/2084079706320646300",
      "author": "intangiblecoins",
      "platform": "x",
      "organisation": null,
      "posted": "2026-08-03T00:51:36Z",
      "role": "on-chain-analysis",
      "why_registered": "Opening post of the original wave-4 thread: reports a live pattern-matched sweep across blocks 960,778 to 960,792, states 218 transactions, 462 victim addresses, 216 fresh destinations and 388.92748828 BTC, and labels the attribution likely rather than confirmed.",
      "relation": {
        "kind": "single-post",
        "head_id": null
      },
      "capture": {
        "status": "held",
        "artefact_count": 2,
        "conversation_copies": 0,
        "conversation_posts": 0,
        "conversation_replies": 0,
        "conversation_gaps": []
      }
    },
    {
      "id": "intangiblecoins-wave4-confirmed-list",
      "title": "Original wave-4 confirmed-address list",
      "url": "https://x.com/intangiblecoins/status/2084079707855651180",
      "author": "intangiblecoins",
      "platform": "x",
      "organisation": null,
      "posted": "2026-08-03T00:51:37Z",
      "role": "on-chain-analysis",
      "why_registered": "Second post of the original wave-4 thread, linking the Pastebin of victim and destination addresses for transactions already confirmed in blocks. The linked list is registered separately as intangiblecoins-wave4-confirmed-pastebin.",
      "relation": {
        "kind": "single-post",
        "head_id": null
      },
      "capture": {
        "status": "held",
        "artefact_count": 4,
        "conversation_copies": 0,
        "conversation_posts": 0,
        "conversation_replies": 0,
        "conversation_gaps": []
      }
    },
    {
      "id": "intangiblecoins-wave4-pending-list",
      "title": "Original wave-4 pending-transaction warning",
      "url": "https://x.com/intangiblecoins/status/2084082791717699885",
      "author": "intangiblecoins",
      "platform": "x",
      "organisation": null,
      "posted": "2026-08-03T01:03:52Z",
      "role": "on-chain-analysis",
      "why_registered": "Third post of the original wave-4 thread, reporting further transactions pending in the mempool with replace-by-fee enabled and linking the second Pastebin. The linked list is registered separately as intangiblecoins-wave4-pending-pastebin.",
      "relation": {
        "kind": "single-post",
        "head_id": null
      },
      "capture": {
        "status": "held",
        "artefact_count": 4,
        "conversation_copies": 0,
        "conversation_posts": 0,
        "conversation_replies": 0,
        "conversation_gaps": []
      }
    },
    {
      "id": "intangiblecoins-wave4-address-correction",
      "title": "Wave-4 destination-list correction",
      "url": "https://x.com/intangiblecoins/status/2084091366720655844",
      "author": "intangiblecoins",
      "platform": "x",
      "organisation": null,
      "posted": "2026-08-03T01:37:57Z",
      "role": "on-chain-analysis",
      "why_registered": "Correction to the author's circulated wave-4 destination list: six of 216 addresses had years of history before block 960,183 (30 July 2026) and are removed as unlikely attacker addresses; the rest stand, 206 of them freshly created to receive the sweeps.",
      "relation": {
        "kind": "single-post",
        "head_id": null
      },
      "capture": {
        "status": "held",
        "artefact_count": 2,
        "conversation_copies": 0,
        "conversation_posts": 0,
        "conversation_replies": 0,
        "conversation_gaps": []
      }
    },
    {
      "id": "intangiblecoins-wave4-multisig-correction",
      "title": "Wave-4 multisig correction and unconfirmed status",
      "url": "https://x.com/intangiblecoins/status/2084117621864046698",
      "author": "intangiblecoins",
      "platform": "x",
      "organisation": null,
      "posted": "2026-08-03T03:22:16Z",
      "role": "on-chain-analysis",
      "why_registered": "Second wave-4 correction, credited to Nunchuk: the circulated set erroneously\ncontained multisig addresses, while waves 1-3 contain none. States wave 4 as\ncirculated at 857 addresses / 486.11 BTC, an 89-address / 20.58 BTC multisig\ndiscount, and a surviving core of 709 addresses / 448.73 BTC, and stresses that\nwave 4 rests on pattern matching with no direct victim confirmation yet.\n",
      "relation": {
        "kind": "single-post",
        "head_id": null
      },
      "capture": {
        "status": "held",
        "artefact_count": 2,
        "conversation_copies": 0,
        "conversation_posts": 0,
        "conversation_replies": 0,
        "conversation_gaps": []
      }
    },
    {
      "id": "bitcoindevs-explainer-thread",
      "title": "Illustrated incident explainer thread",
      "url": "https://x.com/Bitcoin_Devs/status/2083912081255153897",
      "author": "Bitcoin_Devs",
      "platform": "x",
      "organisation": null,
      "posted": "2026-08-02T13:45:32Z",
      "role": "reporting",
      "why_registered": "An illustrated thread explaining the entropy attack simply; held as a record of how the incident was being explained to a general audience. Only the first post was held until 7 Aug 2026, when the conversation was added to the curated thread tier.",
      "relation": {
        "kind": "conversation-head",
        "head_id": null
      },
      "capture": {
        "status": "held",
        "artefact_count": 52,
        "conversation_copies": 8,
        "conversation_posts": 30,
        "conversation_replies": 27,
        "conversation_gaps": []
      }
    },
    {
      "id": "colourorange-nunchuk-platform-key",
      "title": "Nunchuk platform-key exposure question",
      "url": "https://x.com/_colourorange/status/2084098343421239395",
      "author": "_colourorange",
      "platform": "x",
      "organisation": null,
      "posted": "2026-08-03T02:05:40Z",
      "role": "community-question",
      "why_registered": "Notes Nunchuk's disclosure that the platform key in its 2-of-4 collaborative custody was generated with a COLDCARD Mk4 using a custom derivation path, and asks whether sweeps of such setups are beginning.",
      "relation": {
        "kind": "single-post",
        "head_id": null
      },
      "capture": {
        "status": "held",
        "artefact_count": 8,
        "conversation_copies": 0,
        "conversation_posts": 0,
        "conversation_replies": 0,
        "conversation_gaps": []
      }
    },
    {
      "id": "llfourn-prompt-reproduction-thread",
      "title": "Audit-prompt reproduction thread",
      "url": "https://x.com/LLFOURN/status/2084079829545370034",
      "author": "LLFOURN",
      "platform": "x",
      "organisation": null,
      "posted": "2026-08-03T00:52:06Z",
      "role": "ai-security-response",
      "why_registered": "Start of LLFOURN's thread testing what was missing from the pre-incident audit prompt; reports the same prompt failing on Opus 5 at xhigh reasoning effort. The per-model results posted in the thread are held as individual captures (llfourn-repro-gpt56-pass, llfourn-repro-glm52-fail, llfourn-repro-kimi-k3-success, llfourn-repro-qwen3-fail, llfourn-repro-gemini-flash-fail, llfourn-repro-exact-prompt, ozdeadman-kimi27-pass). One further reply (status 2084467388607783406) no longer rendered at capture time and is not held.\n",
      "relation": {
        "kind": "single-post",
        "head_id": null
      },
      "capture": {
        "status": "held",
        "artefact_count": 10,
        "conversation_copies": 0,
        "conversation_posts": 0,
        "conversation_replies": 0,
        "conversation_gaps": []
      }
    },
    {
      "id": "zachxbt-declines-tracing",
      "title": "ZachXBT declines to trace",
      "url": "https://x.com/zachxbt/status/2084045834099057018",
      "author": "zachxbt",
      "platform": "x",
      "organisation": null,
      "posted": "2026-08-02T22:37:01Z",
      "role": "commentary",
      "why_registered": "ZachXBT states he has no plans to monitor or trace the incident, citing where his donor support comes from. Held as part of the record of who is and is not investigating.",
      "relation": {
        "kind": "single-post",
        "head_id": null
      },
      "capture": {
        "status": "held",
        "artefact_count": 2,
        "conversation_copies": 0,
        "conversation_posts": 0,
        "conversation_replies": 0,
        "conversation_gaps": []
      }
    },
    {
      "id": "bitcoinnews-bricking-warning",
      "title": "Firmware-upgrade bricking reports",
      "url": "https://x.com/bitcoinnewscom/status/2083963013988540656",
      "author": "bitcoinnewscom",
      "platform": "x",
      "organisation": "Bitcoin News",
      "posted": "2026-08-02T17:07:55Z",
      "role": "reporting",
      "why_registered": "Report that users say the new firmware upgrade is bricking some devices, advising funds be moved off before upgrading. Secondhand: no device count or first-hand report is cited in the post.",
      "relation": {
        "kind": "single-post",
        "head_id": null
      },
      "capture": {
        "status": "held",
        "artefact_count": 2,
        "conversation_copies": 0,
        "conversation_posts": 0,
        "conversation_replies": 0,
        "conversation_gaps": []
      }
    },
    {
      "id": "lopp-migrate-before-upgrade",
      "title": "Migrate before upgrading guidance",
      "url": "https://x.com/lopp/status/2083958797354127631",
      "author": "lopp",
      "platform": "x",
      "organisation": null,
      "posted": "2026-08-02T16:51:10Z",
      "role": "migration-guidance",
      "why_registered": "Lopp's guidance to move funds off a weakly generated seed before upgrading device firmware, citing reports of a non-zero chance the upgrade bricks the device.",
      "relation": {
        "kind": "single-post",
        "head_id": null
      },
      "capture": {
        "status": "held",
        "artefact_count": 2,
        "conversation_copies": 0,
        "conversation_posts": 0,
        "conversation_replies": 0,
        "conversation_gaps": []
      }
    },
    {
      "id": "glxyresearch-victim-outreach-update",
      "title": "Investigation status and victim outreach",
      "url": "https://x.com/glxyresearch/status/2083967080911470640",
      "author": "glxyresearch",
      "platform": "x",
      "organisation": "Galaxy Research",
      "posted": "2026-08-02T17:24:04Z",
      "role": "on-chain-analysis",
      "why_registered": "Galaxy's status update: the wave-1 pattern came from Block engineers while\nwaves 2 and 3 were identified through victims coming forward. Asks victims to\nshare addresses and TXIDs with @intangiblecoins without personal identifying\ninformation, says findings are shared with US authorities, SEAL, exchanges and\ncyber investigators, and promises a substantive update.\n",
      "relation": {
        "kind": "single-post",
        "head_id": null
      },
      "capture": {
        "status": "held",
        "artefact_count": 2,
        "conversation_copies": 0,
        "conversation_posts": 0,
        "conversation_replies": 0,
        "conversation_gaps": []
      }
    },
    {
      "id": "tshodl-two-coldcard-guidance",
      "title": "Two-COLDCARD multisig guidance",
      "url": "https://x.com/ts_hodl/status/2083717301828808941",
      "author": "ts_hodl",
      "platform": "x",
      "organisation": null,
      "posted": "2026-08-02T00:51:33Z",
      "role": "migration-guidance",
      "why_registered": "States that multisigs whose keys are two COLDCARDs are safe at rest if the wallet configuration is also secure, but vulnerable to RBF sniping in the mempool, and recommends rotating keys using direct-to-miner submission via Slipstream.",
      "relation": {
        "kind": "single-post",
        "head_id": null
      },
      "capture": {
        "status": "held",
        "artefact_count": 2,
        "conversation_copies": 0,
        "conversation_posts": 0,
        "conversation_replies": 0,
        "conversation_gaps": []
      }
    },
    {
      "id": "tftc-shipments-halted",
      "title": "Shipments halted and inventory destroyed report",
      "url": "https://x.com/tftc21/status/2084013342671392930",
      "author": "tftc21",
      "platform": "x",
      "organisation": "TFTC",
      "posted": "2026-08-02T20:27:54Z",
      "role": "reporting",
      "why_registered": "TFTC's report that Coinkite halted shipments and destroyed remaining inventory carrying affected firmware, and contacted in-transit customers with migration steps. Posted after the vendor's own statement of the same facts.",
      "relation": {
        "kind": "single-post",
        "head_id": null
      },
      "capture": {
        "status": "held",
        "artefact_count": 8,
        "conversation_copies": 0,
        "conversation_posts": 0,
        "conversation_replies": 0,
        "conversation_gaps": []
      }
    },
    {
      "id": "btctherapist-prior-drain-report",
      "title": "Claimed four-year-old drain report",
      "url": "https://x.com/thebtctherapist/status/2083916626051715528",
      "author": "thebtctherapist",
      "platform": "x",
      "organisation": null,
      "posted": "2026-08-02T14:03:35Z",
      "role": "prior-warning-claim",
      "why_registered": "Claims that four years earlier someone reported a COLDCARD drained after seed generation without dice rolls and was then blocked by the vendor account, crediting @Zenul_Abidin. The underlying report is shown only as an attached screenshot; not verified here.",
      "relation": {
        "kind": "single-post",
        "head_id": null
      },
      "capture": {
        "status": "held",
        "artefact_count": 8,
        "conversation_copies": 0,
        "conversation_posts": 0,
        "conversation_replies": 0,
        "conversation_gaps": []
      }
    },
    {
      "id": "notgrubles-license-fork-question",
      "title": "Firmware forking licence question",
      "url": "https://x.com/notgrubles/status/2083960173077365012",
      "author": "notgrubles",
      "platform": "x",
      "organisation": null,
      "posted": "2026-08-02T16:56:38Z",
      "role": "community-question",
      "why_registered": "Asks whether Coinkite's licence would legally prevent forking the firmware to provide longer-term support if the company went out of business.",
      "relation": {
        "kind": "single-post",
        "head_id": null
      },
      "capture": {
        "status": "held",
        "artefact_count": 2,
        "conversation_copies": 0,
        "conversation_posts": 0,
        "conversation_replies": 0,
        "conversation_gaps": []
      }
    },
    {
      "id": "claygarrett-bitkey-entropy-design",
      "title": "Bitkey entropy-diversification explanation",
      "url": "https://x.com/clay_garrett/status/2083425375015579865",
      "author": "clay_garrett",
      "platform": "x",
      "organisation": "Block",
      "posted": "2026-08-01T05:31:32Z",
      "role": "downstream-wallet-scope",
      "why_registered": "The Bitkey lead's long reply, conflict disclosed in the post, on why 2-of-3 keys generated in three environments (phone, hardware, server) mean a single-environment entropy bug cannot alone threaten funds.",
      "relation": {
        "kind": "single-post",
        "head_id": null
      },
      "capture": {
        "status": "held",
        "artefact_count": 2,
        "conversation_copies": 0,
        "conversation_posts": 0,
        "conversation_replies": 0,
        "conversation_gaps": []
      }
    },
    {
      "id": "coldcard-shipments-halted",
      "title": "Shipments halted and inventory destroyed",
      "url": "https://x.com/coldcardwallet/status/2083977229084578060",
      "author": "COLDCARDwallet",
      "platform": "x",
      "organisation": "Coinkite",
      "posted": "2026-08-02T18:04:24Z",
      "role": "vendor-update",
      "why_registered": "Coinkite states shipments were halted when the vulnerability was confirmed and remaining units with affected firmware destroyed; already-shipped customers were emailed the advisory and migration steps; SATSCARD, OPENDIME and TAPSIGNER are stated to use different codebases and be unaffected.",
      "relation": {
        "kind": "single-post",
        "head_id": null
      },
      "capture": {
        "status": "held",
        "artefact_count": 2,
        "conversation_copies": 0,
        "conversation_posts": 0,
        "conversation_replies": 0,
        "conversation_gaps": []
      }
    },
    {
      "id": "martybent-endorsement-apology",
      "title": "Endorsement apology",
      "url": "https://x.com/martybent/status/2083962185131102553",
      "author": "martybent",
      "platform": "x",
      "organisation": null,
      "posted": "2026-08-02T17:04:37Z",
      "role": "commentary",
      "why_registered": "Marty Bent apologises to anyone who bought a COLDCARD on his endorsement and describes spending the weekend helping people move funds to safety.",
      "relation": {
        "kind": "single-post",
        "head_id": null
      },
      "capture": {
        "status": "held",
        "artefact_count": 2,
        "conversation_copies": 0,
        "conversation_posts": 0,
        "conversation_replies": 0,
        "conversation_gaps": []
      }
    },
    {
      "id": "bitcoinnews-opreturn-laundering-pitch",
      "title": "OP_RETURN laundering solicitation report",
      "url": "https://x.com/bitcoinnewscom/status/2083983567751667930",
      "author": "bitcoinnewscom",
      "platform": "x",
      "organisation": "Bitcoin News",
      "posted": "2026-08-02T18:29:35Z",
      "role": "reporting",
      "why_registered": "Reports a dust transaction to the attacker's largest consolidation address (562 BTC) carrying an OP_RETURN advertising laundering for a 10% cut; notes the embedded Telegram handle is withheld, authenticity is unproven, and the stolen coins had not moved: an approach to the attacker, not attacker activity.",
      "relation": {
        "kind": "single-post",
        "head_id": null
      },
      "capture": {
        "status": "held",
        "artefact_count": 8,
        "conversation_copies": 0,
        "conversation_posts": 0,
        "conversation_replies": 0,
        "conversation_gaps": []
      }
    },
    {
      "id": "vladcostea-disclosure-history",
      "title": "Prior disclosure-handling thread",
      "url": "https://x.com/vladcostea/status/2083286735220552077",
      "author": "vladcostea",
      "platform": "x",
      "organisation": null,
      "posted": "2026-07-31T20:20:37Z",
      "role": "commentary",
      "why_registered": "Thread asserting a pattern in Coinkite's handling of past disclosures, including the 2019 researcher disclosure rewarded with merchandise and a claim that a later researcher disclosed to other vendors but not Coinkite. The characterisations are the author's; not verified here.",
      "relation": {
        "kind": "single-post",
        "head_id": null
      },
      "capture": {
        "status": "held",
        "artefact_count": 12,
        "conversation_copies": 0,
        "conversation_posts": 0,
        "conversation_replies": 0,
        "conversation_gaps": []
      }
    },
    {
      "id": "robhamilton-bip39-reevaluation",
      "title": "Seed-standard reevaluation remark",
      "url": "https://x.com/Rob1Ham/status/2084010317504536944",
      "author": "Rob1Ham",
      "platform": "x",
      "organisation": "AnchorWatch",
      "posted": "2026-08-02T20:15:53Z",
      "role": "commentary",
      "why_registered": "Hamilton's view that the incident will prompt a ground-up reevaluation of seed-phrase-era key handling in the coming weeks and months, while keys remain user-held.",
      "relation": {
        "kind": "single-post",
        "head_id": null
      },
      "capture": {
        "status": "held",
        "artefact_count": 8,
        "conversation_copies": 0,
        "conversation_posts": 0,
        "conversation_replies": 0,
        "conversation_gaps": []
      }
    },
    {
      "id": "mitchellaskew-collision-arithmetic",
      "title": "93,000-seed collision arithmetic",
      "url": "https://x.com/mitchellaskew/status/2084002368748696026",
      "author": "mitchellaskew",
      "platform": "x",
      "organisation": null,
      "posted": "2026-08-02T19:44:18Z",
      "role": "independent-analysis",
      "why_registered": "Birthday-bound arithmetic: at 32 bits of effective entropy about 93,000 generated seeds give a 50% chance of a duplicate wallet, contrasted with the 2^256 space of a properly generated 24-word seed.",
      "relation": {
        "kind": "single-post",
        "head_id": null
      },
      "capture": {
        "status": "held",
        "artefact_count": 8,
        "conversation_copies": 0,
        "conversation_posts": 0,
        "conversation_replies": 0,
        "conversation_gaps": []
      }
    },
    {
      "id": "satochip-data-retention-question",
      "title": "Customer-data retention question",
      "url": "https://x.com/satochip/status/2083805915384332600",
      "author": "satochip",
      "platform": "x",
      "organisation": "Satochip",
      "posted": "2026-08-02T06:43:40Z",
      "role": "community-question",
      "why_registered": "A competing vendor asks how customers received store emails if Coinkite deleted customer data after 90 days, requesting a plain explanation.",
      "relation": {
        "kind": "single-post",
        "head_id": null
      },
      "capture": {
        "status": "held",
        "artefact_count": 8,
        "conversation_copies": 0,
        "conversation_posts": 0,
        "conversation_replies": 0,
        "conversation_gaps": []
      }
    },
    {
      "id": "jstefanop-collision-program",
      "title": "Collision-search demonstration program",
      "url": "https://x.com/JStefanop1/status/2083406002704015859",
      "author": "JStefanop1",
      "platform": "x",
      "organisation": null,
      "posted": "2026-08-01T04:14:33Z",
      "role": "independent-reproduction",
      "why_registered": "Reports a program under the 40-bit effective-state model showing a duplicate wallet on average every ~1.3 million seed generations, and a collision found in 4.7 seconds on an M1 Max at roughly 268,000 evaluated states per second; the attached screenshot shows the confirmed duplicate-seed run.",
      "relation": {
        "kind": "single-post",
        "head_id": null
      },
      "capture": {
        "status": "held",
        "artefact_count": 8,
        "conversation_copies": 0,
        "conversation_posts": 0,
        "conversation_replies": 0,
        "conversation_gaps": []
      }
    },
    {
      "id": "kevinkelbie-tracker-update",
      "title": "Tracker update: 1,367 BTC across 4,620 addresses",
      "url": "https://x.com/KevinKelbie/status/2083987258210660683",
      "author": "KevinKelbie",
      "platform": "x",
      "organisation": null,
      "posted": "2026-08-02T18:44:15Z",
      "role": "on-chain-analysis",
      "why_registered": "Announces a major tracker update: 1,367 BTC tracked across 4,620 drained addresses, coins followed from victim to current position, a timeline from the 2021 bug to the July 2026 sweeps, and a searchable ledger at coldcard-hack.up.railway.app.",
      "relation": {
        "kind": "single-post",
        "head_id": null
      },
      "capture": {
        "status": "held",
        "artefact_count": 11,
        "conversation_copies": 0,
        "conversation_posts": 0,
        "conversation_replies": 0,
        "conversation_gaps": []
      }
    },
    {
      "id": "jamesob-passphrase-verification",
      "title": "Passphrase-integration verification",
      "url": "https://x.com/jamesob/status/2083520730432413923",
      "author": "jamesob",
      "platform": "x",
      "organisation": null,
      "posted": "2026-08-01T11:50:26Z",
      "role": "independent-analysis",
      "why_registered": "Reports an LLM-assisted verification across coldcard/firmware tags concluding BIP-39 passphrase integration is sound, with the caution that a passphrase must be long and unwieldy to be cryptographically relevant.",
      "relation": {
        "kind": "single-post",
        "head_id": null
      },
      "capture": {
        "status": "held",
        "artefact_count": 8,
        "conversation_copies": 0,
        "conversation_posts": 0,
        "conversation_replies": 0,
        "conversation_gaps": []
      }
    },
    {
      "id": "mutatrum-repo-process",
      "title": "Firmware repository process observation",
      "url": "https://x.com/mutatrum/status/2083831529768108317",
      "author": "mutatrum",
      "platform": "x",
      "organisation": null,
      "posted": "2026-08-02T08:25:27Z",
      "role": "commentary",
      "why_registered": "Observation that most coldcard/firmware changes land directly on master or merge without review comments, questioning what the open repository provides in that state.",
      "relation": {
        "kind": "single-post",
        "head_id": null
      },
      "capture": {
        "status": "held",
        "artefact_count": 20,
        "conversation_copies": 0,
        "conversation_posts": 0,
        "conversation_replies": 0,
        "conversation_gaps": []
      }
    },
    {
      "id": "llfourn-prior-prompt-analysis",
      "title": "Prior audit-prompt failure analysis",
      "url": "https://x.com/LLFOURN/status/2083869145318531122",
      "author": "LLFOURN",
      "platform": "x",
      "organisation": null,
      "posted": "2026-08-02T10:54:55Z",
      "role": "ai-security-response",
      "why_registered": "LLFOURN's reading of the 17 June pre-incident audit prompt by @utxoclub: it failed to surface the defect, which he attributes to the model tier available to that account at the time and to the firmware's submodule structure. The characterisations are the author's own.",
      "relation": {
        "kind": "single-post",
        "head_id": null
      },
      "capture": {
        "status": "held",
        "artefact_count": 2,
        "conversation_copies": 0,
        "conversation_posts": 0,
        "conversation_replies": 0,
        "conversation_gaps": []
      }
    },
    {
      "id": "coldcard-disclaimer-clarification",
      "title": "Store disclaimer clarification",
      "url": "https://x.com/coldcardwallet/status/2084004277089964369",
      "author": "COLDCARDwallet",
      "platform": "x",
      "organisation": "Coinkite",
      "posted": "2026-08-02T19:51:53Z",
      "role": "vendor-response",
      "why_registered": "Coinkite confirms the store disclaimer exists so previous buyers are aware of the incident, answering a question about whether it implied anything further.",
      "relation": {
        "kind": "single-post",
        "head_id": null
      },
      "capture": {
        "status": "held",
        "artefact_count": 2,
        "conversation_copies": 0,
        "conversation_posts": 0,
        "conversation_replies": 0,
        "conversation_gaps": []
      }
    },
    {
      "id": "btcsessions-passphrase-loss-report",
      "title": "First reported Mk3 passphrase-wallet loss",
      "url": "https://x.com/btcsessions/status/2084024733511921691",
      "author": "btcsessions",
      "platform": "x",
      "organisation": null,
      "posted": "2026-08-02T21:13:10Z",
      "role": "victim-report",
      "why_registered": "Reports a first confirmed loss from a Mk3 protected by a two-word passphrase, drained around 2pm 2 August Australia time. If accurate it extends observed drains to weak-passphrase wallets; the post cites no transaction or address.",
      "relation": {
        "kind": "single-post",
        "head_id": null
      },
      "capture": {
        "status": "held",
        "artefact_count": 2,
        "conversation_copies": 0,
        "conversation_posts": 0,
        "conversation_replies": 0,
        "conversation_gaps": []
      }
    },
    {
      "id": "rawavocado-privacy-impact",
      "title": "Privacy blast-radius argument",
      "url": "https://x.com/raw_avocado/status/2083946596543168758",
      "author": "raw_avocado",
      "platform": "x",
      "organisation": null,
      "posted": "2026-08-02T16:02:41Z",
      "role": "commentary",
      "why_registered": "Argues the recoverable seed population is also a privacy failure: anyone deriving a compromised seed gains that wallet's full history, enabling UTXO linkage and deanonymisation even for users who already moved funds.",
      "relation": {
        "kind": "single-post",
        "head_id": null
      },
      "capture": {
        "status": "held",
        "artefact_count": 2,
        "conversation_copies": 0,
        "conversation_posts": 0,
        "conversation_replies": 0,
        "conversation_gaps": []
      }
    },
    {
      "id": "robhamilton-mk4-confirmation-question",
      "title": "Mk4-class confirmation question",
      "url": "https://x.com/Rob1Ham/status/2083822646714614167",
      "author": "Rob1Ham",
      "platform": "x",
      "organisation": "AnchorWatch",
      "posted": "2026-08-02T07:50:09Z",
      "role": "community-question",
      "why_registered": "Asks whether any Mk4, Mk5 or Q compromise has been confirmed, noting multiple claims later retracted, and asks how much collective grinding effort is being applied to the larger keyspace.",
      "relation": {
        "kind": "single-post",
        "head_id": null
      },
      "capture": {
        "status": "held",
        "artefact_count": 2,
        "conversation_copies": 0,
        "conversation_posts": 0,
        "conversation_replies": 0,
        "conversation_gaps": []
      }
    },
    {
      "id": "profedustream-mapping-export",
      "title": "On-chain mapping JSON export",
      "url": "https://x.com/profedustream/status/2084021570872160545",
      "author": "profedustream",
      "platform": "x",
      "organisation": null,
      "posted": "2026-08-02T21:00:36Z",
      "role": "on-chain-analysis",
      "why_registered": "Publishes a JSON export of a multi-day on-chain mapping and a two-actor working\nhypothesis: a scripted first wave whose consolidations remain untouched, a\nnoisier erratic pattern with movements reaching clusters linked to Chivo\nWallet, Binance, ChangeNOW and a CoinJoin service, and further script-like\nwaves that also remain unmoved.\n",
      "relation": {
        "kind": "single-post",
        "head_id": null
      },
      "capture": {
        "status": "held",
        "artefact_count": 20,
        "conversation_copies": 0,
        "conversation_posts": 0,
        "conversation_replies": 0,
        "conversation_gaps": []
      }
    },
    {
      "id": "skot9000-population-collisions",
      "title": "Population collision arithmetic",
      "url": "https://x.com/skot9000/status/2084025399839748101",
      "author": "skot9000",
      "platform": "x",
      "organisation": null,
      "posted": "2026-08-02T21:15:49Z",
      "role": "independent-analysis",
      "why_registered": "Birthday arithmetic at 32 bits of effective entropy: about 77,000 total generated seeds give a 50% chance that two are identical, and 200,000 give about 99%.",
      "relation": {
        "kind": "single-post",
        "head_id": null
      },
      "capture": {
        "status": "held",
        "artefact_count": 2,
        "conversation_copies": 0,
        "conversation_posts": 0,
        "conversation_replies": 0,
        "conversation_gaps": []
      }
    },
    {
      "id": "kevinkelbie-gpu-farm-question",
      "title": "Attacker GPU-farm sizing question",
      "url": "https://x.com/KevinKelbie/status/2083800007157678414",
      "author": "KevinKelbie",
      "platform": "x",
      "organisation": null,
      "posted": "2026-08-02T06:20:11Z",
      "role": "community-question",
      "why_registered": "Asks whether the size of the attacker's GPU farm could be calculated from observed behaviour; the attached context is preserved in the capture.",
      "relation": {
        "kind": "single-post",
        "head_id": null
      },
      "capture": {
        "status": "held",
        "artefact_count": 8,
        "conversation_copies": 0,
        "conversation_posts": 0,
        "conversation_replies": 0,
        "conversation_gaps": []
      }
    },
    {
      "id": "pledditor-owner-outreach",
      "title": "Individual owner-outreach effort",
      "url": "https://x.com/Pledditor/status/2083750879434252506",
      "author": "Pledditor",
      "platform": "x",
      "organisation": null,
      "posted": "2026-08-02T03:04:58Z",
      "role": "commentary",
      "why_registered": "Describes searching X for 2021-25 posts mentioning COLDCARD purchases and replying to each with an exploit alert, accepting a possible shadow ban as the cost of reaching owners.",
      "relation": {
        "kind": "single-post",
        "head_id": null
      },
      "capture": {
        "status": "held",
        "artefact_count": 2,
        "conversation_copies": 0,
        "conversation_posts": 0,
        "conversation_replies": 0,
        "conversation_gaps": []
      }
    },
    {
      "id": "mara-slipstream-permissionless",
      "title": "Slipstream permissionless announcement",
      "url": "https://x.com/MARAFoundation_/status/2084176346402730479",
      "author": "MARAFoundation_",
      "platform": "x",
      "organisation": "MARA Foundation",
      "posted": "2026-08-03T07:15:37Z",
      "role": "service-access",
      "why_registered": "Announces Slipstream is now a permissionless public good with no client code requirement, warns users to be conservative with fees so transactions do not get stuck in the Slipstream mempool if competitive rates spike, and says MARA is not charging additional service fees for the foreseeable future.\n",
      "relation": {
        "kind": "single-post",
        "head_id": null
      },
      "capture": {
        "status": "held",
        "artefact_count": 2,
        "conversation_copies": 0,
        "conversation_posts": 0,
        "conversation_replies": 0,
        "conversation_gaps": []
      }
    },
    {
      "id": "nunchuk-slipstream-migration-guide",
      "title": "Slipstream multisig migration guide",
      "url": "https://x.com/nunchuk_io/status/2084163891043688858",
      "author": "nunchuk_io",
      "platform": "x",
      "organisation": "Nunchuk",
      "posted": "2026-08-03T06:26:08Z",
      "role": "migration-guidance",
      "why_registered": "Gives multisig migration guidance over Slipstream: migrate now if the affected Coldcard-generated keys alone meet the signing threshold, soon otherwise. Announces an upcoming paid-subscriber update that routes assisted-multisig transactions through Slipstream automatically, documents a manual raw-hex submission path for everyone else, and notes the method trusts the MARA pool operators.\n",
      "relation": {
        "kind": "single-post",
        "head_id": null
      },
      "capture": {
        "status": "held",
        "artefact_count": 2,
        "conversation_copies": 0,
        "conversation_posts": 0,
        "conversation_replies": 0,
        "conversation_gaps": []
      }
    },
    {
      "id": "nunchuk-inheritance-key-options",
      "title": "Inheritance-key hardware expansion",
      "url": "https://x.com/nunchuk_io/status/2084132206323372215",
      "author": "nunchuk_io",
      "platform": "x",
      "organisation": "Nunchuk",
      "posted": "2026-08-03T04:20:13Z",
      "role": "vendor-update",
      "why_registered": "Responds to affected users by expanding inheritance-key options for its off-chain timelock protocol beyond Tapsigner and Coldcard: says the Jade and Foundation teams confirmed they are adding on-device encryption support, notes Jade, Ledger and soon BitBox02 already work for the on-chain timelock protocol, and says Ledger and BitBox have been contacted about device encryption.\n",
      "relation": {
        "kind": "single-post",
        "head_id": null
      },
      "capture": {
        "status": "held",
        "artefact_count": 2,
        "conversation_copies": 0,
        "conversation_posts": 0,
        "conversation_replies": 0,
        "conversation_gaps": []
      }
    },
    {
      "id": "livera-retail-hardware-bridge",
      "title": "Retail hardware bridge migration",
      "url": "https://x.com/stephanlivera/status/2084130246052528508",
      "author": "stephanlivera",
      "platform": "x",
      "organisation": null,
      "posted": "2026-08-03T04:12:26Z",
      "role": "migration-guidance",
      "why_registered": "Emergency migration path for owners in a pinch: move coins to a reputable phone wallet as a strictly temporary bridge, walk into a physical tech retailer and buy a genuine hardware wallet, verify the device, migrate the coins, then take time to set up proper multisig or decide on custody.\n",
      "relation": {
        "kind": "single-post",
        "head_id": null
      },
      "capture": {
        "status": "held",
        "artefact_count": 2,
        "conversation_copies": 0,
        "conversation_posts": 0,
        "conversation_replies": 0,
        "conversation_gaps": []
      }
    },
    {
      "id": "skysupersonic-attacker-open-letter",
      "title": "Open letter to the attackers",
      "url": "https://x.com/skysupersonic/status/2083912951027634204",
      "author": "skysupersonic",
      "platform": "x",
      "organisation": null,
      "posted": "2026-08-02T13:48:59Z",
      "role": "commentary",
      "why_registered": "Open letter to the attackers claiming they have collectively gathered around 1,500 bitcoin, arguing the stack is among the most blacklisted in history and nearly impossible to cash out, and proposing they negotiate with CoinKite to return the funds in exchange for a five percent audit fee.\n",
      "relation": {
        "kind": "single-post",
        "head_id": null
      },
      "capture": {
        "status": "held",
        "artefact_count": 2,
        "conversation_copies": 0,
        "conversation_posts": 0,
        "conversation_replies": 0,
        "conversation_gaps": []
      }
    },
    {
      "id": "heavilyarmedc-pbkdf2-weakness",
      "title": "BIP39 PBKDF2 weakness explainer",
      "url": "https://x.com/heavilyarmedc/status/2084101978716504155",
      "author": "heavilyarmedc",
      "platform": "x",
      "organisation": null,
      "posted": "2026-08-03T02:20:07Z",
      "role": "independent-technical-analysis",
      "why_registered": "Explains, citing Greg Maxwell, why BIP 39 seed derivation via PBKDF2-HMAC-SHA512 with 2048 iterations gives little protection when input entropy is poor: the KDF is compute-bound rather than memory-hard and highly parallelizable on GPUs, ASICs or FPGAs, so weak-entropy seeds are cheap to grind.\n",
      "relation": {
        "kind": "single-post",
        "head_id": null
      },
      "capture": {
        "status": "held",
        "artefact_count": 5,
        "conversation_copies": 0,
        "conversation_posts": 0,
        "conversation_replies": 0,
        "conversation_gaps": []
      }
    },
    {
      "id": "panhodl-2021-telegram-warning",
      "title": "Claimed 2021 Telegram warning",
      "url": "https://x.com/PanHodl/status/2084117965717323961",
      "author": "PanHodl",
      "platform": "x",
      "organisation": null,
      "posted": "2026-08-03T03:23:38Z",
      "role": "prior-warning-claim",
      "why_registered": "Claims that a Telegram group flagged the Coldcard random function back in 2021 and that the warning was ignored; posted in reply to Zach Herbert recounting the incorrect Christmas Eve 2023 Passport entropy claim, with an attached screenshot as the only supporting material.\n",
      "relation": {
        "kind": "single-post",
        "head_id": null
      },
      "capture": {
        "status": "held",
        "artefact_count": 5,
        "conversation_copies": 0,
        "conversation_posts": 0,
        "conversation_replies": 0,
        "conversation_gaps": []
      }
    },
    {
      "id": "kevinkelbie-tracker-move",
      "title": "Tracker moves to coldcard.rip",
      "url": "https://x.com/KevinKelbie/status/2084188150927184351",
      "author": "KevinKelbie",
      "platform": "x",
      "organisation": null,
      "posted": "2026-08-03T08:02:32Z",
      "role": "on-chain-analysis",
      "why_registered": "Announces the on-chain tracker is moving from coldcard-hack.up.railway.app to the dedicated domain coldcard.rip, with an attached video; the tracker was announced on 2 August as tracking 1,367 BTC across 4,620 drained addresses.\n",
      "relation": {
        "kind": "single-post",
        "head_id": null
      },
      "capture": {
        "status": "held",
        "artefact_count": 2,
        "conversation_copies": 0,
        "conversation_posts": 0,
        "conversation_replies": 0,
        "conversation_gaps": []
      }
    },
    {
      "id": "studentofthings-prior-discovery-claim",
      "title": "Claimed unreported prior discovery",
      "url": "https://x.com/studentofthings/status/2084007449267188163",
      "author": "studentofthings",
      "platform": "x",
      "organisation": null,
      "posted": "2026-08-02T20:04:29Z",
      "role": "prior-warning-claim",
      "why_registered": "Claims to have found the COLDCARD RNG bug 11 months before the July 2026 incident and to have withheld it because Coinkite did not acknowledge an earlier report. A first-hand claim with an attached screenshot; not independently verified.\n",
      "relation": {
        "kind": "single-post",
        "head_id": null
      },
      "capture": {
        "status": "held",
        "artefact_count": 5,
        "conversation_copies": 0,
        "conversation_posts": 0,
        "conversation_replies": 0,
        "conversation_gaps": []
      }
    },
    {
      "id": "joecarlasare-fake-post-warning",
      "title": "Fake-post warning",
      "url": "https://x.com/JoeCarlasare/status/2084428579408880009",
      "author": "JoeCarlasare",
      "platform": "x",
      "organisation": null,
      "posted": "2026-08-03T23:57:54Z",
      "role": "scam-report",
      "why_registered": "Calls out a post preying on holder fears during the incident as fake and asks readers to share the warning; the attached image shows the post being called out.\n",
      "relation": {
        "kind": "single-post",
        "head_id": null
      },
      "capture": {
        "status": "held",
        "artefact_count": 5,
        "conversation_copies": 0,
        "conversation_posts": 0,
        "conversation_replies": 0,
        "conversation_gaps": []
      }
    },
    {
      "id": "rob1ham-dice-roll-endorsement",
      "title": "Dice-roll verification endorsement",
      "url": "https://x.com/Rob1Ham/status/2084430349984055307",
      "author": "Rob1Ham",
      "platform": "x",
      "organisation": "AnchorWatch",
      "posted": "2026-08-04T00:04:56Z",
      "role": "commentary",
      "why_registered": "Points to PortlandHODL's dice-roll verification report as adding to the work of jamesob and BlockEng, arguing it shows dice-roll entropy is applied when using a COLDCARD; frames skepticism of the wider system as warranted given the RNG failure.\n",
      "relation": {
        "kind": "single-post",
        "head_id": null
      },
      "capture": {
        "status": "held",
        "artefact_count": 2,
        "conversation_copies": 0,
        "conversation_posts": 0,
        "conversation_replies": 0,
        "conversation_gaps": []
      }
    },
    {
      "id": "portlandhodl-dice-roll-verification",
      "title": "Dice-roll seed path verification report",
      "url": "https://x.com/PortlandHODL/status/2084428567077900563",
      "author": "PortlandHODL",
      "platform": "x",
      "organisation": null,
      "posted": "2026-08-03T23:57:51Z",
      "role": "independent-analysis",
      "why_registered": "Primary verification of the COLDCARD dice-roll seed path across multiple firmware versions; reports the implementation is correct and can generate up to 256 bits of entropy with 100 dice rolls. The held capture is the announcement post, with the full report linked from it.\n",
      "relation": {
        "kind": "single-post",
        "head_id": null
      },
      "capture": {
        "status": "held",
        "artefact_count": 2,
        "conversation_copies": 0,
        "conversation_posts": 0,
        "conversation_replies": 0,
        "conversation_gaps": []
      }
    },
    {
      "id": "unchained-client-migrations",
      "title": "Client vault migrations report",
      "url": "https://x.com/unchained/status/2084441306051252293",
      "author": "unchained",
      "platform": "x",
      "organisation": "Unchained",
      "posted": "2026-08-04T00:48:29Z",
      "role": "reported-migration-outcome",
      "why_registered": "Reports that Unchained clients transferred thousands of BTC from vaults with compromised COLDCARD keys to new vaults with new keys in the days after disclosure. Provider-reported aggregate figure.\n",
      "relation": {
        "kind": "single-post",
        "head_id": null
      },
      "capture": {
        "status": "held",
        "artefact_count": 11,
        "conversation_copies": 0,
        "conversation_posts": 0,
        "conversation_replies": 0,
        "conversation_gaps": []
      }
    },
    {
      "id": "kloaec-slipstream-psbt-tool",
      "title": "PSBT-to-Slipstream conversion tool",
      "url": "https://x.com/KLoaec/status/2084440671503499609",
      "author": "KLoaec",
      "platform": "x",
      "organisation": null,
      "posted": "2026-08-04T00:45:57Z",
      "role": "migration-guidance",
      "why_registered": "Announces a tool that converts most PSBT formats into raw transactions acceptable to MARA Slipstream, aimed at wallets where an attacker can only act once a transaction is broadcast, such as a 2-of-3 with two COLDCARDs. Part of the Slipstream advice chain; the author built the tool.\n",
      "relation": {
        "kind": "single-post",
        "head_id": null
      },
      "capture": {
        "status": "held",
        "artefact_count": 2,
        "conversation_copies": 0,
        "conversation_posts": 0,
        "conversation_replies": 0,
        "conversation_gaps": []
      }
    },
    {
      "id": "anchorwatch-awareness-notice",
      "title": "Off-platform awareness notice",
      "url": "https://x.com/AnchorWatch/status/2084406949924520344",
      "author": "AnchorWatch",
      "platform": "x",
      "organisation": "AnchorWatch",
      "posted": "2026-08-03T22:31:57Z",
      "role": "incident-response-guidance",
      "why_registered": "Provides a notice for reposting on Instagram, Facebook or TikTok, warning that time is running out to move funds and that many holders have not heard about the COLDCARD vulnerability.\n",
      "relation": {
        "kind": "single-post",
        "head_id": null
      },
      "capture": {
        "status": "held",
        "artefact_count": 5,
        "conversation_copies": 0,
        "conversation_posts": 0,
        "conversation_replies": 0,
        "conversation_gaps": []
      }
    },
    {
      "id": "lopp-missed-bug-context",
      "title": "Why the bug escaped review",
      "url": "https://x.com/lopp/status/2084241215852068992",
      "author": "lopp",
      "platform": "x",
      "organisation": null,
      "posted": "2026-08-03T11:33:23Z",
      "role": "commentary",
      "why_registered": "Argues the defect was non-obvious because it sat in the build system rather than the main code, notes that Ledger DonJon's repeated reviews missed it, that most LLMs miss it without full submodule context, and that critical vulnerabilities have survived over a decade in widely used code such as SSL, SSH and Linux.\n",
      "relation": {
        "kind": "single-post",
        "head_id": null
      },
      "capture": {
        "status": "held",
        "artefact_count": 2,
        "conversation_copies": 0,
        "conversation_posts": 0,
        "conversation_replies": 0,
        "conversation_gaps": []
      }
    },
    {
      "id": "darosior-whitehat-sweep-warning",
      "title": "Whitehat sweep warning",
      "url": "https://x.com/darosior/status/2084272746612019439",
      "author": "darosior",
      "platform": "x",
      "organisation": null,
      "posted": "2026-08-03T13:38:41Z",
      "role": "incident-response-guidance",
      "why_registered": "Warns that a widespread whitehat sweep of vulnerable funds would be actively harmful and makes things worse, while acknowledging the proposal comes from a good place.\n",
      "relation": {
        "kind": "single-post",
        "head_id": null
      },
      "capture": {
        "status": "held",
        "artefact_count": 2,
        "conversation_copies": 0,
        "conversation_posts": 0,
        "conversation_replies": 0,
        "conversation_gaps": []
      }
    },
    {
      "id": "bullbitcoin-boltz-suspension",
      "title": "Boltz suspension advisory for BULL users",
      "url": "https://x.com/francispouliot_/status/2084375359521456471",
      "author": "francispouliot_",
      "platform": "x",
      "organisation": "Bull Bitcoin",
      "posted": "2026-08-03T20:26:26Z",
      "role": "service-access",
      "why_registered": "Advises BULL users that Boltz has suspended its services and that work on solutions is in progress, with a personal comment from the author in the replies.\n",
      "relation": {
        "kind": "single-post",
        "head_id": null
      },
      "capture": {
        "status": "held",
        "artefact_count": 2,
        "conversation_copies": 0,
        "conversation_posts": 0,
        "conversation_replies": 0,
        "conversation_gaps": []
      }
    },
    {
      "id": "laurentmt-prior-claim-reaction",
      "title": "Reaction to prior-discovery claim",
      "url": "https://x.com/LaurentMT/status/2084281873841164319",
      "author": "LaurentMT",
      "platform": "x",
      "organisation": null,
      "posted": "2026-08-03T14:14:57Z",
      "role": "commentary",
      "why_registered": "Reacts to the claimed prior discovery of the RNG bug: \"It's devastating if it's not a hoax.\" Shares the claim's attached image.\n",
      "relation": {
        "kind": "single-post",
        "head_id": null
      },
      "capture": {
        "status": "held",
        "artefact_count": 2,
        "conversation_copies": 0,
        "conversation_posts": 0,
        "conversation_replies": 0,
        "conversation_gaps": []
      }
    },
    {
      "id": "laurentmt-vuln109-sources",
      "title": "VULN-109 description and code reference",
      "url": "https://x.com/LaurentMT/status/2084434979912663547",
      "author": "LaurentMT",
      "platform": "x",
      "organisation": null,
      "posted": "2026-08-04T00:23:20Z",
      "role": "prior-warning-claim",
      "why_registered": "Posts the VULN-109 description from the karma-x.io article behind the prior-discovery claim together with the referenced ae.c code line, in reply to Fully Noded's developer; presented as the sources for the claim that this bug class was flagged before the incident.\n",
      "relation": {
        "kind": "single-post",
        "head_id": null
      },
      "capture": {
        "status": "held",
        "artefact_count": 7,
        "conversation_copies": 0,
        "conversation_posts": 0,
        "conversation_replies": 0,
        "conversation_gaps": []
      }
    },
    {
      "id": "thebitcoinlayer-aftermath-letter",
      "title": "Bitcoiners, Where Do We Go From Here?",
      "url": "https://x.com/TheBitcoinLayer/status/2084476338392694947",
      "author": "TheBitcoinLayer",
      "platform": "x",
      "organisation": "The Bitcoin Layer",
      "posted": "2026-08-04T03:07:41Z",
      "role": "commentary",
      "why_registered": "Long-form opinion letter on the incident: the author's own custody reaction (moving some balance toward custodians), an assignment of ultimate responsibility to NVK, and open questions on self custody after the disclosure. Discloses past Foundation and Blockstream sponsorships and anchors its account of Coinkite conduct on Zach Herbert's first-hand thread. Opinion, attributed as such.\n",
      "relation": {
        "kind": "single-post",
        "head_id": null
      },
      "capture": {
        "status": "held",
        "artefact_count": 7,
        "conversation_copies": 0,
        "conversation_posts": 0,
        "conversation_replies": 0,
        "conversation_gaps": []
      }
    },
    {
      "id": "gladstein-reflections-thread",
      "title": "Initial reflections on the Coldcard catastrophe",
      "url": "https://x.com/gladstein/status/2084355296747810923",
      "author": "gladstein",
      "platform": "x",
      "organisation": "HRF",
      "posted": "2026-08-03T19:06:42Z",
      "role": "commentary",
      "why_registered": "Thirteen-point reflections thread from a prominent recommender: acknowledges trusting and recommending COLDCARD more than was warranted, apologises for HRF handing out devices at events, defends the bitcoin-only self-custody approach against what he calls scammer and ETF-promoter lecturing, and points to multi-vendor multisig and collaborative custody (Casa, Liana, AnchorWatch, Unchained named approvingly). First-hand accountability, opinion throughout.\n",
      "relation": {
        "kind": "single-post",
        "head_id": null
      },
      "capture": {
        "status": "held",
        "artefact_count": 2,
        "conversation_copies": 0,
        "conversation_posts": 0,
        "conversation_replies": 0,
        "conversation_gaps": []
      }
    },
    {
      "id": "zherbert-nvk-conduct-record",
      "title": "Don't trust NVK, verify",
      "url": "https://x.com/zherbert/status/2084269925632217297",
      "author": "zherbert",
      "platform": "x",
      "organisation": "Foundation Devices",
      "posted": "2026-08-03T13:27:28Z",
      "role": "commentary",
      "why_registered": "Long-form first-hand account by Foundation's CEO of NVK's years of public attacks on Foundation, SeedSigner, WalletScrutiny and independent researchers; the GPLv3 to Commons Clause license change; the BTClock trademark takedown; and a point-by-point correction of claims made about those projects. The author leads a direct competitor and says so inside the piece; The Bitcoin Layer's aftermath letter defers to this thread for its account of Coinkite conduct.\n",
      "relation": {
        "kind": "single-post",
        "head_id": null
      },
      "capture": {
        "status": "held",
        "artefact_count": 5,
        "conversation_copies": 0,
        "conversation_posts": 0,
        "conversation_replies": 0,
        "conversation_gaps": []
      }
    },
    {
      "id": "btcperception-conversation-share",
      "title": "Hardware wallet conversation share around the exploit",
      "url": "https://x.com/BTCPerception/status/2084298157274312923",
      "author": "BTCPerception",
      "platform": "x",
      "organisation": null,
      "posted": "2026-08-03T15:19:39Z",
      "role": "reporting",
      "why_registered": "Conversation-share metrics from the Perception tracker: COLDCARD held 24% of hardware-wallet discussion in the twelve months before the exploit, level with Ledger, and 79% in the four days after, 2.4 times its entire prior year's mentions. The account's own measurements, share of conversation rather than market share.\n",
      "relation": {
        "kind": "single-post",
        "head_id": null
      },
      "capture": {
        "status": "held",
        "artefact_count": 5,
        "conversation_copies": 0,
        "conversation_posts": 0,
        "conversation_replies": 0,
        "conversation_gaps": []
      }
    },
    {
      "id": "praveenperera-lowentropy-db-proposal",
      "title": "Low-entropy wallet database proposal",
      "url": "https://x.com/PraveenPerera/status/2084463358724448293",
      "author": "PraveenPerera",
      "platform": "x",
      "organisation": null,
      "posted": "2026-08-04T02:16:06Z",
      "role": "community-question",
      "why_registered": "Proposes a community-funded database of xpub hashes from grindable low-entropy wallets (roughly 2^52 for a hypothesised $1M), which software and watch-only wallets would check at import and refuse on a match, with the hash-only design intended to avoid privacy leaks. Posted as an open question, asking to be told if the idea is dumb.\n",
      "relation": {
        "kind": "single-post",
        "head_id": null
      },
      "capture": {
        "status": "held",
        "artefact_count": 2,
        "conversation_copies": 0,
        "conversation_posts": 0,
        "conversation_replies": 0,
        "conversation_gaps": []
      }
    },
    {
      "id": "bitpaine-river-dice-officer",
      "title": "River's Chief Dice Officer joke",
      "url": "https://x.com/BitPaine/status/2084313682130165958",
      "author": "BitPaine",
      "platform": "x",
      "organisation": null,
      "posted": "2026-08-03T16:21:21Z",
      "role": "commentary",
      "why_registered": "Praises River's speed in riffing on the incident: the attached image is River's satirical \"We're Hiring: Chief Dice Officer\" posting extolling dice-mediated entropy over TRNGs. Company-response humour rather than guidance, held as part of the public reaction record.\n",
      "relation": {
        "kind": "single-post",
        "head_id": null
      },
      "capture": {
        "status": "held",
        "artefact_count": 5,
        "conversation_copies": 0,
        "conversation_posts": 0,
        "conversation_replies": 0,
        "conversation_gaps": []
      }
    },
    {
      "id": "zenulabidin-drain-report-screenshot",
      "title": "Zenulabidin Drain Report Screenshot",
      "url": "https://x.com/Zenul_Abidin/status/2083756420843839872",
      "author": "Zenul_Abidin",
      "platform": "x",
      "organisation": null,
      "posted": "2026-08-02T03:26:59Z",
      "role": "prior-warning-claim",
      "why_registered": "Circulated the screenshot of Economy-Cash6726s years-old r/ledgerwallet drain report after the vulnerability became public; the circulation btctherapist-prior-drain-report credits. The underlying Reddit comment is registered separately as reddit-ledgerwallet-drain-comment.\n",
      "relation": {
        "kind": "single-post",
        "head_id": null
      },
      "capture": {
        "status": "held",
        "artefact_count": 7,
        "conversation_copies": 0,
        "conversation_posts": 0,
        "conversation_replies": 0,
        "conversation_gaps": []
      }
    },
    {
      "id": "llfourn-repro-gpt56-pass",
      "title": "Reproduction: gpt-5.6-sol passes",
      "url": "https://x.com/LLFOURN/status/2084081148930695658",
      "author": "LLFOURN",
      "platform": "x",
      "organisation": null,
      "posted": "2026-08-03T00:57:20Z",
      "role": "ai-security-response",
      "why_registered": "First result in the audit-prompt reproduction thread: gpt-5.6-sol at max effort passes with the same prompt that failed pre-incident.",
      "relation": {
        "kind": "single-post",
        "head_id": null
      },
      "capture": {
        "status": "held",
        "artefact_count": 5,
        "conversation_copies": 0,
        "conversation_posts": 0,
        "conversation_replies": 0,
        "conversation_gaps": []
      }
    },
    {
      "id": "llfourn-repro-glm52-fail",
      "title": "Reproduction: glm 5.2 fails",
      "url": "https://x.com/LLFOURN/status/2084090595329687626",
      "author": "LLFOURN",
      "platform": "x",
      "organisation": null,
      "posted": "2026-08-03T01:34:53Z",
      "role": "ai-security-response",
      "why_registered": "Thread result: glm 5.2 fails the same audit prompt.",
      "relation": {
        "kind": "single-post",
        "head_id": null
      },
      "capture": {
        "status": "held",
        "artefact_count": 5,
        "conversation_copies": 0,
        "conversation_posts": 0,
        "conversation_replies": 0,
        "conversation_gaps": []
      }
    },
    {
      "id": "llfourn-repro-exact-prompt",
      "title": "The exact audit prompt tested",
      "url": "https://x.com/LLFOURN/status/2084109013508366763",
      "author": "LLFOURN",
      "platform": "x",
      "organisation": null,
      "posted": "2026-08-03T02:48:04Z",
      "role": "ai-security-response",
      "why_registered": "The verbatim audit prompt used across the reproduction thread, posted in reply to Ryan Dale; the context every pass/fail result in the thread refers to.",
      "relation": {
        "kind": "single-post",
        "head_id": null
      },
      "capture": {
        "status": "held",
        "artefact_count": 2,
        "conversation_copies": 0,
        "conversation_posts": 0,
        "conversation_replies": 0,
        "conversation_gaps": []
      }
    },
    {
      "id": "llfourn-repro-kimi-k3-success",
      "title": "Reproduction: Kimi k3 succeeds",
      "url": "https://x.com/LLFOURN/status/2084399174880260188",
      "author": "LLFOURN",
      "platform": "x",
      "organisation": null,
      "posted": "2026-08-03T22:01:04Z",
      "role": "ai-security-response",
      "why_registered": "Thread result: Kimi k3 succeeds with the same audit prompt.",
      "relation": {
        "kind": "single-post",
        "head_id": null
      },
      "capture": {
        "status": "held",
        "artefact_count": 2,
        "conversation_copies": 0,
        "conversation_posts": 0,
        "conversation_replies": 0,
        "conversation_gaps": []
      }
    },
    {
      "id": "llfourn-repro-qwen3-fail",
      "title": "Reproduction: Qwen3-coder-next fails",
      "url": "https://x.com/LLFOURN/status/2084400470215582102",
      "author": "LLFOURN",
      "platform": "x",
      "organisation": null,
      "posted": "2026-08-03T22:06:13Z",
      "role": "ai-security-response",
      "why_registered": "Thread result: Qwen3-coder-next fails the same audit prompt, even after being shown the problem.",
      "relation": {
        "kind": "single-post",
        "head_id": null
      },
      "capture": {
        "status": "held",
        "artefact_count": 5,
        "conversation_copies": 0,
        "conversation_posts": 0,
        "conversation_replies": 0,
        "conversation_gaps": []
      }
    },
    {
      "id": "llfourn-repro-gemini-flash-fail",
      "title": "Reproduction: gemini 3.6 flash fails",
      "url": "https://x.com/LLFOURN/status/2084451396544545213",
      "author": "LLFOURN",
      "platform": "x",
      "organisation": null,
      "posted": "2026-08-04T01:28:34Z",
      "role": "ai-security-response",
      "why_registered": "Thread result: gemini 3.6 flash at high effort fails the same audit prompt.",
      "relation": {
        "kind": "single-post",
        "head_id": null
      },
      "capture": {
        "status": "held",
        "artefact_count": 5,
        "conversation_copies": 0,
        "conversation_posts": 0,
        "conversation_replies": 0,
        "conversation_gaps": []
      }
    },
    {
      "id": "ozdeadman-kimi27-pass",
      "title": "Reproduction: Kimi 2.7 Coding passes",
      "url": "https://x.com/ozdeadman/status/2084462907044286703",
      "author": "ozdeadman",
      "platform": "x",
      "organisation": null,
      "posted": "2026-08-04T02:14:19Z",
      "role": "ai-security-response",
      "why_registered": "Third-party result posted into the reproduction thread: Kimi 2.7 Coding passes the same audit prompt.",
      "relation": {
        "kind": "single-post",
        "head_id": null
      },
      "capture": {
        "status": "held",
        "artefact_count": 5,
        "conversation_copies": 0,
        "conversation_posts": 0,
        "conversation_replies": 0,
        "conversation_gaps": []
      }
    },
    {
      "id": "bitcoinrothbard-trezor-phishing",
      "title": "Fake Trezor CEO email",
      "url": "https://x.com/BitcoinRothbard/status/2084483674964177079",
      "author": "BitcoinRothbard",
      "platform": "x",
      "organisation": null,
      "posted": "2026-08-04T03:36:50Z",
      "role": "scam-report",
      "why_registered": "Shows a phishing email impersonating Trezor's CEO that leverages the COLDCARD exploit to push a \"latest version in our web suite\" link, and quote-shows americanhodl8's alert about the fake COLDCARD Desktop app. Part of the same panic-driven phishing wave.\n",
      "relation": {
        "kind": "single-post",
        "head_id": null
      },
      "capture": {
        "status": "held",
        "artefact_count": 5,
        "conversation_copies": 0,
        "conversation_posts": 0,
        "conversation_replies": 0,
        "conversation_gaps": []
      }
    },
    {
      "id": "americanhodl-desktop-app-phishing",
      "title": "Fake COLDCARD Desktop app phishing alert",
      "url": "https://x.com/americanhodl8/status/2084480562501484975",
      "author": "americanhodl8",
      "platform": "x",
      "organisation": null,
      "posted": "2026-08-04T03:24:28Z",
      "role": "scam-report",
      "why_registered": "Warns of a phishing email urging download of a fake \"Coldcard Desktop App MK3 4.2.0\", stressing that no COLDCARD desktop app exists; the attached screenshots show the lure and its download button.\n",
      "relation": {
        "kind": "single-post",
        "head_id": null
      },
      "capture": {
        "status": "held",
        "artefact_count": 11,
        "conversation_copies": 0,
        "conversation_posts": 0,
        "conversation_replies": 0,
        "conversation_gaps": []
      }
    },
    {
      "id": "bitcoinnews-whitehat-drains",
      "title": "White hat drains of COLDCARD wallets begin",
      "url": "https://x.com/BitcoinNewsCom/status/2084273394229362780",
      "author": "BitcoinNewsCom",
      "platform": "x",
      "organisation": "Bitcoin News",
      "posted": "2026-08-03T13:41:15Z",
      "role": "reporting",
      "why_registered": "Reports, citing @coinjoined, that white-hat drains of exploitable COLDCARD wallets are underway, and advises owners not to destroy their devices because any recovery claim may depend on proving ownership with the device and KYC records. A reported claim, not independently confirmed; contrast darosior-whitehat-sweep-warning.\n",
      "relation": {
        "kind": "single-post",
        "head_id": null
      },
      "capture": {
        "status": "held",
        "artefact_count": 2,
        "conversation_copies": 0,
        "conversation_posts": 0,
        "conversation_replies": 0,
        "conversation_gaps": []
      }
    },
    {
      "id": "lookonchain-galaxy-2055-btc",
      "title": "Relayed Galaxy estimate: 2,055 BTC",
      "url": "https://x.com/lookonchain/status/2084465607932854717",
      "author": "lookonchain",
      "platform": "x",
      "organisation": null,
      "posted": "2026-08-04T02:25:03Z",
      "role": "reporting",
      "why_registered": "Relays Galaxy Research's updated estimate that losses may have reached 2,055 BTC (about $130M) across more than 7,700 victim addresses. The figures are Galaxy's, amplified by an analytics account with a large following.\n",
      "relation": {
        "kind": "single-post",
        "head_id": null
      },
      "capture": {
        "status": "held",
        "artefact_count": 5,
        "conversation_copies": 0,
        "conversation_posts": 0,
        "conversation_replies": 0,
        "conversation_gaps": []
      }
    },
    {
      "id": "laurentmt-open-hardware-contrast",
      "title": "Open-hardware contrast",
      "url": "https://x.com/laurentmt/status/2084265335893504311",
      "author": "LaurentMT",
      "platform": "x",
      "organisation": null,
      "posted": "2026-08-03T13:09:14Z",
      "role": "commentary",
      "why_registered": "\"Somewhere along the way, something went wrong\", linking a Bitcoin Magazine piece from Coinkite's open-hardware era, when it published everything needed to build your own COLDCARD, with attached images. Commentary on how far the project moved from that posture.\n",
      "relation": {
        "kind": "single-post",
        "head_id": null
      },
      "capture": {
        "status": "held",
        "artefact_count": 7,
        "conversation_copies": 0,
        "conversation_posts": 0,
        "conversation_replies": 0,
        "conversation_gaps": []
      }
    },
    {
      "id": "christophera-rng-review-history",
      "title": "1994 lesson: randomness fails reviews",
      "url": "https://x.com/christophera/status/2084299750757777597",
      "author": "christophera",
      "platform": "x",
      "organisation": "Blockchain Commons",
      "posted": "2026-08-03T15:25:59Z",
      "role": "historical-precedent",
      "why_registered": "First-hand historical note: in 1994, when Verisign would not issue a certificate without a basic security review, over half of the secure servers his company reviewed failed on randomness problems. His standing lesson: randomness is easy to get wrong and always needs multiple reviewers.\n",
      "relation": {
        "kind": "single-post",
        "head_id": null
      },
      "capture": {
        "status": "held",
        "artefact_count": 2,
        "conversation_copies": 0,
        "conversation_posts": 0,
        "conversation_replies": 0,
        "conversation_gaps": []
      }
    },
    {
      "id": "basedlayer-influencers-vs-engineers",
      "title": "Influencers over engineers",
      "url": "https://x.com/basedlayer/status/2084247812645011711",
      "author": "basedlayer",
      "platform": "x",
      "organisation": null,
      "posted": "2026-08-03T11:59:36Z",
      "role": "commentary",
      "why_registered": "Argues the most exposed holders were those listening to influencers rather than engineers, and that NVK antagonising engineers years earlier did not help a white hat find the bug before black hats did.\n",
      "relation": {
        "kind": "single-post",
        "head_id": null
      },
      "capture": {
        "status": "held",
        "artefact_count": 9,
        "conversation_copies": 0,
        "conversation_posts": 0,
        "conversation_replies": 0,
        "conversation_gaps": []
      }
    },
    {
      "id": "proofomoney-educator-victim-17btc",
      "title": "Educator's 17.39 BTC loss, anonymised",
      "url": "https://x.com/proofofmoney/status/2084386594484879773",
      "author": "ProofOfMoney",
      "platform": "x",
      "organisation": null,
      "posted": "2026-08-03T21:11:04Z",
      "role": "victim-report",
      "why_registered": "Second-hand victim account, posted with the victim's permission and without naming him: a long-time Bitcoin educator lost 17.39 BTC from a single-sig COLDCARD key, said to make him the fifth-largest victim so far; most of his holdings are in multisig. The author notes the identifying detail is withheld deliberately.\n",
      "relation": {
        "kind": "single-post",
        "head_id": null
      },
      "capture": {
        "status": "held",
        "artefact_count": 5,
        "conversation_copies": 0,
        "conversation_posts": 0,
        "conversation_replies": 0,
        "conversation_gaps": []
      }
    },
    {
      "id": "onramp-custody-guidance",
      "title": "Emergency advice and multi-institution custody pitch",
      "url": "https://x.com/mtanguma/status/2084280474168401981",
      "author": "mtanguma",
      "platform": "x",
      "organisation": "Onramp Bitcoin",
      "posted": "2026-08-03T14:09:23Z",
      "role": "custody-provider-guidance",
      "why_registered": "Practical migration advice (move now, an exchange is a fine place to stand while the building is on fire) followed by a pitch for Onramp's multi-institution custody, 2-of-3 native multisig across independent regulated institutions. The author is an Onramp principal promoting his own custody product, which the post itself acknowledges; the cited figures (1,367 BTC, 4,585 addresses, three waves) match the community tracker numbers of that day.\n",
      "relation": {
        "kind": "single-post",
        "head_id": null
      },
      "capture": {
        "status": "held",
        "artefact_count": 5,
        "conversation_copies": 0,
        "conversation_posts": 0,
        "conversation_replies": 0,
        "conversation_gaps": []
      }
    },
    {
      "id": "robinlinus-uid-whitehat-question",
      "title": "UID request to aid white hats",
      "url": "https://x.com/robin_linus/status/2084101249306337469",
      "author": "robin_linus",
      "platform": "x",
      "organisation": null,
      "posted": "2026-08-03T02:17:13Z",
      "role": "community-question",
      "why_registered": "Asks Coinkite publicly whether it has UID information that could help white hats search the vulnerable key space faster than attackers. Part of the white-hat sweep discussion: darosior-whitehat-sweep-warning argues the sweep would be harmful, bitcoinnews-whitehat-drains reports drains underway.\n",
      "relation": {
        "kind": "single-post",
        "head_id": null
      },
      "capture": {
        "status": "held",
        "artefact_count": 2,
        "conversation_copies": 0,
        "conversation_posts": 0,
        "conversation_replies": 0,
        "conversation_gaps": []
      }
    },
    {
      "id": "bkclaims-victim-intake",
      "title": "Victim intake for legal options and recovery",
      "url": "https://x.com/Bkclaims/status/2083589981713428977",
      "author": "Bkclaims",
      "platform": "x",
      "organisation": null,
      "posted": "2026-08-01T16:25:37Z",
      "role": "funds-recovery",
      "why_registered": "Thomas Braziel (117 Partners) solicits affected users for potential legal options, including product liability and class or group litigation, plus asset recovery efforts, asking for country, purchase channel, model, loss size and contact details. A solicitation by a recovery professional with a direct business interest in sign-ups.\n",
      "relation": {
        "kind": "single-post",
        "head_id": null
      },
      "capture": {
        "status": "held",
        "artefact_count": 2,
        "conversation_copies": 0,
        "conversation_posts": 0,
        "conversation_replies": 0,
        "conversation_gaps": []
      }
    },
    {
      "id": "bkclaims-legal-strategy-update",
      "title": "Coinkite legal strategy update",
      "url": "https://x.com/Bkclaims/status/2084307749517553684",
      "author": "Bkclaims",
      "platform": "x",
      "organisation": null,
      "posted": "2026-08-03T15:57:46Z",
      "role": "funds-recovery",
      "why_registered": "Braziel's strategy update: leaning away from a class action toward a private Canadian lawsuit by 10 to 30 larger claimants, with product liability and negligence theories under review and collectability named as the larger question. Describes litigation funding expectations and points victims to the same Telegram group.\n",
      "relation": {
        "kind": "single-post",
        "head_id": null
      },
      "capture": {
        "status": "held",
        "artefact_count": 2,
        "conversation_copies": 0,
        "conversation_posts": 0,
        "conversation_replies": 0,
        "conversation_gaps": []
      }
    },
    {
      "id": "l0lal33tz-braziel-court-record",
      "title": "Warning about the victims' lawyer",
      "url": "https://x.com/L0laL33tz/status/2084371489810423846",
      "author": "L0laL33tz",
      "platform": "x",
      "organisation": null,
      "posted": "2026-08-03T20:11:03Z",
      "role": "reporting",
      "why_registered": "Warns COLDCARD victims away from Braziel, quoting a Delaware court's findings in an earlier receivership (falsified records, manufactured account statements, $1.9M restitution ordered, no criminal indictment) and linking the opinion. Contested: Braziel's own posts describe the same matter as settled with an exceptional outcome.\n",
      "relation": {
        "kind": "single-post",
        "head_id": null
      },
      "capture": {
        "status": "held",
        "artefact_count": 5,
        "conversation_copies": 0,
        "conversation_posts": 0,
        "conversation_replies": 0,
        "conversation_gaps": []
      }
    },
    {
      "id": "l0lal33tz-braziel-lying-claim",
      "title": "Claim the lawyer is misleading victims",
      "url": "https://x.com/L0laL33tz/status/2084392983290331463",
      "author": "L0laL33tz",
      "platform": "x",
      "organisation": null,
      "posted": "2026-08-03T21:36:28Z",
      "role": "reporting",
      "why_registered": "Claims Braziel is lying to COLDCARD victims when he describes the earlier matter as settled, citing court filings showing he was removed from the receivership with the court reserving further proceedings, and urges readers to warn the victims' Telegram group. Contested, attributed reporting; the underlying dispute is documented in the two bkclaims entries.\n",
      "relation": {
        "kind": "single-post",
        "head_id": null
      },
      "capture": {
        "status": "held",
        "artefact_count": 7,
        "conversation_copies": 0,
        "conversation_posts": 0,
        "conversation_replies": 0,
        "conversation_gaps": []
      }
    },
    {
      "id": "coldcard-retirement-attack-claim",
      "title": "2021: retirement attacks impossible",
      "url": "https://x.com/COLDCARDwallet/status/1447198712736985093",
      "author": "COLDCARDwallet",
      "platform": "x",
      "organisation": "Coinkite",
      "posted": "2021-10-10T13:53:55Z",
      "role": "historical-precedent",
      "why_registered": "The vendor's own 2021 marketing claim that COLDCARD makes retirement attacks impossible because users can generate their own entropy and reproduce it provably. Held as historical context: the July 2026 failure was an entropy defect in the device's own generation path, the class of attack this post claimed to defeat.\n",
      "relation": {
        "kind": "single-post",
        "head_id": null
      },
      "capture": {
        "status": "held",
        "artefact_count": 5,
        "conversation_copies": 0,
        "conversation_posts": 0,
        "conversation_replies": 0,
        "conversation_gaps": []
      }
    },
    {
      "id": "coldcard-retirement-attack-definition",
      "title": "2021: retirement attack defined",
      "url": "https://x.com/COLDCARDwallet/status/1447213375398846473",
      "author": "COLDCARDwallet",
      "platform": "x",
      "organisation": "Coinkite",
      "posted": "2021-10-10T14:52:11Z",
      "role": "historical-precedent",
      "why_registered": "The vendor's 2021 definition, in reply to a reader: a retirement attack is when project makers could have a \"bug\" in the entropy generation for later retrieval. Companion to coldcard-retirement-attack-claim.\n",
      "relation": {
        "kind": "single-post",
        "head_id": null
      },
      "capture": {
        "status": "held",
        "artefact_count": 2,
        "conversation_copies": 0,
        "conversation_posts": 0,
        "conversation_replies": 0,
        "conversation_gaps": []
      }
    },
    {
      "id": "glxy-losses-exceed-100m",
      "title": "Updated total: losses exceed $100M",
      "url": "https://x.com/glxyresearch/status/2084411904924045370",
      "author": "glxyresearch",
      "platform": "x",
      "organisation": "Galaxy Research",
      "posted": "2026-08-03T22:51:39Z",
      "role": "on-chain-analysis",
      "why_registered": "Start of Galaxy's updated accounting thread: high-confidence 1,596 BTC stolen from about 7,300 addresses across three confirmed waves plus 14 smaller incidents, with suspected but unconfirmed activity taking the total near 2,000 BTC ($130M). Succeeds the 1,082.65 BTC figure in glxyresearch-flow-map; all eight posts of the thread are held (glxy-wave-map through glxy-thread-close).\n",
      "relation": {
        "kind": "single-post",
        "head_id": null
      },
      "capture": {
        "status": "held",
        "artefact_count": 5,
        "conversation_copies": 0,
        "conversation_posts": 0,
        "conversation_replies": 0,
        "conversation_gaps": []
      }
    },
    {
      "id": "glxy-wave-map",
      "title": "Event map and Wave 4 caveat",
      "url": "https://x.com/glxyresearch/status/2084411907520311662",
      "author": "glxyresearch",
      "platform": "x",
      "organisation": "Galaxy Research",
      "posted": "2026-08-03T22:51:39Z",
      "role": "on-chain-analysis",
      "why_registered": "Thread post 2: the event graphic, every identified event positioned by start time and sized by addresses drained, with Wave 4 noted as unconfirmed by any victim but suspected real at medium-high confidence.",
      "relation": {
        "kind": "single-post",
        "head_id": null
      },
      "capture": {
        "status": "held",
        "artefact_count": 5,
        "conversation_copies": 0,
        "conversation_posts": 0,
        "conversation_replies": 0,
        "conversation_gaps": []
      }
    },
    {
      "id": "glxy-wave-attribution",
      "title": "Wave attribution method",
      "url": "https://x.com/glxyresearch/status/2084411910053618032",
      "author": "glxyresearch",
      "platform": "x",
      "organisation": "Galaxy Research",
      "posted": "2026-08-03T22:51:40Z",
      "role": "on-chain-analysis",
      "why_registered": "Thread post 3: Wave 1 first observed by Block engineers and confirmed by Galaxy on victim reports; Waves 2 and 3 discovered from victim reports; most victims appear in only one wave.",
      "relation": {
        "kind": "single-post",
        "head_id": null
      },
      "capture": {
        "status": "held",
        "artefact_count": 5,
        "conversation_copies": 0,
        "conversation_posts": 0,
        "conversation_replies": 0,
        "conversation_gaps": []
      }
    },
    {
      "id": "glxy-victim-count",
      "title": "73 victims, 14 additional footprints",
      "url": "https://x.com/glxyresearch/status/2084411912889000340",
      "author": "glxyresearch",
      "platform": "x",
      "organisation": "Galaxy Research",
      "posted": "2026-08-03T22:51:41Z",
      "role": "on-chain-analysis",
      "why_registered": "Thread post 4: 73 individual victims contacted @intangiblecoins for tracing help; victim reports identified 14 additional footprints that could be different attackers individually exploiting the known vulnerability.",
      "relation": {
        "kind": "single-post",
        "head_id": null
      },
      "capture": {
        "status": "held",
        "artefact_count": 5,
        "conversation_copies": 0,
        "conversation_posts": 0,
        "conversation_replies": 0,
        "conversation_gaps": []
      }
    },
    {
      "id": "glxy-wave4-caveat",
      "title": "Wave 4 would take the total to 2,055 BTC",
      "url": "https://x.com/glxyresearch/status/2084411915745595527",
      "author": "glxyresearch",
      "platform": "x",
      "organisation": "Galaxy Research",
      "posted": "2026-08-03T22:51:41Z",
      "role": "on-chain-analysis",
      "why_registered": "Thread post 5: including the potential Wave 4 would bring the total to 2,055 BTC ($130M), but it is kept out of the top-line numbers for lack of victim confirmation. This is the figure Lookonchain's relay presents as the headline.",
      "relation": {
        "kind": "single-post",
        "head_id": null
      },
      "capture": {
        "status": "held",
        "artefact_count": 5,
        "conversation_copies": 0,
        "conversation_posts": 0,
        "conversation_replies": 0,
        "conversation_gaps": []
      }
    },
    {
      "id": "glxy-law-enforcement-handoff",
      "title": "Addresses handed to law enforcement; 90% unmoved",
      "url": "https://x.com/glxyresearch/status/2084411918861652194",
      "author": "glxyresearch",
      "platform": "x",
      "organisation": "Galaxy Research",
      "posted": "2026-08-03T22:51:42Z",
      "role": "on-chain-analysis",
      "why_registered": "Thread post 6: confirmed attacker and victim addresses provided to US federal law enforcement, exchanges and compliance groups; 90% of stolen coins have not moved, and 100% of Waves 1 to 3 coins are unmoved.",
      "relation": {
        "kind": "single-post",
        "head_id": null
      },
      "capture": {
        "status": "held",
        "artefact_count": 2,
        "conversation_copies": 0,
        "conversation_posts": 0,
        "conversation_replies": 0,
        "conversation_gaps": []
      }
    },
    {
      "id": "glxy-attack-ongoing",
      "title": "The attack is ongoing",
      "url": "https://x.com/glxyresearch/status/2084411920254111840",
      "author": "glxyresearch",
      "platform": "x",
      "organisation": "Galaxy Research",
      "posted": "2026-08-03T22:51:42Z",
      "role": "on-chain-analysis",
      "why_registered": "Thread post 7: warns the attack is ongoing, tells unsure COLDCARD users to migrate to a custodian or fresh seed, and asks victims to DM @intangiblecoins with drained addresses and attacker TXIDs for tracing and law-enforcement reports.",
      "relation": {
        "kind": "single-post",
        "head_id": null
      },
      "capture": {
        "status": "held",
        "artefact_count": 2,
        "conversation_copies": 0,
        "conversation_posts": 0,
        "conversation_replies": 0,
        "conversation_gaps": []
      }
    },
    {
      "id": "glxy-thread-close",
      "title": "Thread close: recovery hopes",
      "url": "https://x.com/glxyresearch/status/2084411921541787792",
      "author": "glxyresearch",
      "platform": "x",
      "organisation": "Galaxy Research",
      "posted": "2026-08-03T22:51:43Z",
      "role": "on-chain-analysis",
      "why_registered": "Thread post 8: closing note that recovery hopes remain, thanking the people working behind the scenes for victims, attacker identification and codebase hardening.",
      "relation": {
        "kind": "single-post",
        "head_id": null
      },
      "capture": {
        "status": "held",
        "artefact_count": 2,
        "conversation_copies": 0,
        "conversation_posts": 0,
        "conversation_replies": 0,
        "conversation_gaps": []
      }
    },
    {
      "id": "glxyresearch-2085748513015488758",
      "title": "7 August update: $111M confirmed, 1,719 BTC, 25+ patterns",
      "url": "https://x.com/glxyresearch/status/2085748513015488758",
      "author": "glxyresearch",
      "platform": "x",
      "organisation": "Galaxy Research",
      "posted": "2026-08-07T23:59:00Z",
      "role": "on-chain-analysis",
      "why_registered": "Galaxy Research 7 August 2026 update: $111 million confirmed stolen so far, 1,719 BTC with high confidence,\n25+ separate attack patterns, 250+ victim reports to @intangiblecoins, no stolen coin created before the\n17 March 2021 affected-firmware release. This supersedes the 1,596 BTC / ~7,300 address figure in\nglxy-losses-exceed-100m and is the basis for the state-changed flags on the 8 August 2026 claim sweep.\n",
      "relation": {
        "kind": "conversation-head",
        "head_id": null
      },
      "capture": {
        "status": "held",
        "artefact_count": 22,
        "conversation_copies": 3,
        "conversation_posts": 15,
        "conversation_replies": 9,
        "conversation_gaps": []
      }
    },
    {
      "id": "kloaec-outofband-tool",
      "title": "Out-of-band Slipstream tool for Liana",
      "url": "https://x.com/KLoaec/status/2084364148855447816",
      "author": "KLoaec",
      "platform": "x",
      "organisation": null,
      "posted": "2026-08-03T19:41:53Z",
      "role": "migration-guidance",
      "why_registered": "Launches a browser-only tool (outofband.wizardsardine.com) for Liana and other Miniscript or multisig wallets to send transactions through MARA Slipstream out of band, with a bugs-and-feedback caveat. Part of the Slipstream advice chain; the author's company built the tool.\n",
      "relation": {
        "kind": "single-post",
        "head_id": null
      },
      "capture": {
        "status": "held",
        "artefact_count": 2,
        "conversation_copies": 0,
        "conversation_posts": 0,
        "conversation_replies": 0,
        "conversation_gaps": []
      }
    },
    {
      "id": "lucasdcf-opensats-seedsigner",
      "title": "Fund SeedSigner after the OpenSats vote",
      "url": "https://x.com/lucasdcf/status/2084313995238846934",
      "author": "lucasdcf",
      "platform": "x",
      "organisation": "OpenSats",
      "posted": "2026-08-03T16:22:35Z",
      "role": "commentary",
      "why_registered": "An OpenSats insider argues the board members who voted against funding SeedSigner may have had genuine security concerns, that those concerns are more reason to fund it, and proposes an open call for security reviews of major wallets as part of the incident response. Relevant to the NVK OpenSats board history recorded elsewhere in the register.\n",
      "relation": {
        "kind": "single-post",
        "head_id": null
      },
      "capture": {
        "status": "held",
        "artefact_count": 2,
        "conversation_copies": 0,
        "conversation_posts": 0,
        "conversation_replies": 0,
        "conversation_gaps": []
      }
    },
    {
      "id": "bpi-explainer-video",
      "title": "Visual explainer of the bug",
      "url": "https://x.com/bitcoinpolicy/status/2084337559346548988",
      "author": "bitcoinpolicy",
      "platform": "x",
      "organisation": "Bitcoin Policy Institute",
      "posted": "2026-08-03T17:56:13Z",
      "role": "commentary",
      "why_registered": "BPI's short video explainer of the entropy flaw (proper key space as one atom in two billion galaxies versus the affected firmware's much smaller pool), with sympathy for victims, a note that BPI team members were personally affected, and policy reflections promised. The held artefacts are the element screenshot and text; the video itself is held via gallery-dl.\n",
      "relation": {
        "kind": "single-post",
        "head_id": null
      },
      "capture": {
        "status": "held",
        "artefact_count": 8,
        "conversation_copies": 0,
        "conversation_posts": 0,
        "conversation_replies": 0,
        "conversation_gaps": []
      }
    },
    {
      "id": "guillermodiazgr-2084636247146774715",
      "title": "Guillermodiazgr 2084636247146774715",
      "url": "https://x.com/GuillermoDiazGr/status/2084636247146774715",
      "author": "GuillermoDiazGr",
      "platform": "x",
      "organisation": null,
      "posted": "2026-08-04T13:43:06Z",
      "role": "social-statement",
      "why_registered": "Proposal for a signed, opt-in registry of stolen UTXOs and wallet-side ancestry screening. A policy argument about making theft proceeds harder to spend, not evidence about this incident's operator.\n",
      "relation": {
        "kind": "single-post",
        "head_id": null
      },
      "capture": {
        "status": "held",
        "artefact_count": 2,
        "conversation_copies": 0,
        "conversation_posts": 0,
        "conversation_replies": 0,
        "conversation_gaps": []
      }
    },
    {
      "id": "coldcardwallet-2084596971268956161",
      "title": "Coldcardwallet 2084596971268956161",
      "url": "https://x.com/COLDCARDwallet/status/2084596971268956161",
      "author": "COLDCARDwallet",
      "platform": "x",
      "organisation": null,
      "posted": "2026-08-04T11:07:02Z",
      "role": "social-statement",
      "why_registered": "Official 4 August warning that the threat remained ongoing, urging affected owners to follow the model-specific advisory, generate a new seed and migrate funds, and asking readers to reach less-online owners.\n",
      "relation": {
        "kind": "single-post",
        "head_id": null
      },
      "capture": {
        "status": "held",
        "artefact_count": 2,
        "conversation_copies": 0,
        "conversation_posts": 0,
        "conversation_replies": 0,
        "conversation_gaps": []
      }
    },
    {
      "id": "bitschmidty-2084657778610581663",
      "title": "Bitschmidty 2084657778610581663",
      "url": "https://x.com/bitschmidty/status/2084657778610581663",
      "author": "bitschmidty",
      "platform": "x",
      "organisation": null,
      "posted": "2026-08-04T15:08:40Z",
      "role": "social-statement",
      "why_registered": "Credits OpenSats and ODELL with funding the post-incident Bitcoin Red Team work. A brief acknowledgement, retained as provenance for the funding claim.\n",
      "relation": {
        "kind": "single-post",
        "head_id": null
      },
      "capture": {
        "status": "held",
        "artefact_count": 2,
        "conversation_copies": 0,
        "conversation_posts": 0,
        "conversation_replies": 0,
        "conversation_gaps": []
      }
    },
    {
      "id": "rob1ham-2084750639444213823",
      "title": "Rob1ham 2084750639444213823",
      "url": "https://x.com/Rob1Ham/status/2084750639444213823",
      "author": "Rob1Ham",
      "platform": "x",
      "organisation": null,
      "posted": "2026-08-04T21:17:39Z",
      "role": "social-statement",
      "why_registered": "Rob Hamilton's urgent 4 August warning that exposed owners still had time to move funds. The all-COLDCARD wording is broader than the configuration-specific risk guidance on this site.\n",
      "relation": {
        "kind": "single-post",
        "head_id": null
      },
      "capture": {
        "status": "held",
        "artefact_count": 5,
        "conversation_copies": 0,
        "conversation_posts": 0,
        "conversation_replies": 0,
        "conversation_gaps": []
      }
    },
    {
      "id": "unchained-2084735366158787065",
      "title": "Unchained 2084735366158787065",
      "url": "https://x.com/unchained/status/2084735366158787065",
      "author": "unchained",
      "platform": "x",
      "organisation": null,
      "posted": "2026-08-04T20:16:58Z",
      "role": "social-statement",
      "why_registered": "Unchained reports helping move thousands of bitcoin through MARA Slipstream and links an explanation of the private-submission process. Scale and outcome are the provider's own report.\n",
      "relation": {
        "kind": "single-post",
        "head_id": null
      },
      "capture": {
        "status": "held",
        "artefact_count": 5,
        "conversation_copies": 0,
        "conversation_posts": 0,
        "conversation_replies": 0,
        "conversation_gaps": []
      }
    },
    {
      "id": "mandrik-2084729515297968633",
      "title": "Mandrik 2084729515297968633",
      "url": "https://x.com/Mandrik/status/2084729515297968633",
      "author": "Mandrik",
      "platform": "x",
      "organisation": null,
      "posted": "2026-08-04T19:53:43Z",
      "role": "social-statement",
      "why_registered": "Alleges a connection between a developer involved in the affected dependency and an earlier wallet RNG incident. Historical commentary that is not independently verified here.\n",
      "relation": {
        "kind": "single-post",
        "head_id": null
      },
      "capture": {
        "status": "held",
        "artefact_count": 2,
        "conversation_copies": 0,
        "conversation_posts": 0,
        "conversation_replies": 0,
        "conversation_gaps": []
      }
    },
    {
      "id": "milessuter-2084619892699897882",
      "title": "Milessuter 2084619892699897882",
      "url": "https://x.com/milessuter/status/2084619892699897882",
      "author": "milessuter",
      "platform": "x",
      "organisation": null,
      "posted": "2026-08-04T12:38:07Z",
      "role": "social-statement",
      "why_registered": "Miles Suter supports AI review of open-source code while warning that unverified public claims can create panic and false narratives. Records the responsible-disclosure debate surrounding the Red Team push.\n",
      "relation": {
        "kind": "single-post",
        "head_id": null
      },
      "capture": {
        "status": "held",
        "artefact_count": 2,
        "conversation_copies": 0,
        "conversation_posts": 0,
        "conversation_replies": 0,
        "conversation_gaps": []
      }
    },
    {
      "id": "itscoachgoodman-2084707970747613497",
      "title": "Itscoachgoodman 2084707970747613497",
      "url": "https://x.com/itscoachgoodman/status/2084707970747613497",
      "author": "itscoachgoodman",
      "platform": "x",
      "organisation": null,
      "posted": "2026-08-04T18:28:06Z",
      "role": "social-statement",
      "why_registered": "First-person account of discovering a reported US$1.6 million Bitcoin loss and describing the immediate emotional response. No transaction or address is provided, so the amount remains reported.\n",
      "relation": {
        "kind": "single-post",
        "head_id": null
      },
      "capture": {
        "status": "held",
        "artefact_count": 5,
        "conversation_copies": 0,
        "conversation_posts": 0,
        "conversation_replies": 0,
        "conversation_gaps": []
      }
    },
    {
      "id": "bradmillscan-2084647651052573031",
      "title": "Bradmillscan 2084647651052573031",
      "url": "https://x.com/bradmillscan/status/2084647651052573031",
      "author": "bradmillscan",
      "platform": "x",
      "organisation": null,
      "posted": "2026-08-04T14:28:25Z",
      "role": "social-statement",
      "why_registered": "First-person rescue account: a less-technical Mk3 owner reportedly saw an email but did not understand the urgency, then moved funds after a direct call. The post says dice may have delayed theft but the roll count was uncertain.\n",
      "relation": {
        "kind": "single-post",
        "head_id": null
      },
      "capture": {
        "status": "held",
        "artefact_count": 7,
        "conversation_copies": 0,
        "conversation_posts": 0,
        "conversation_replies": 0,
        "conversation_gaps": []
      }
    },
    {
      "id": "orangesurfbtc-2084729250997813510",
      "title": "Orangesurfbtc 2084729250997813510",
      "url": "https://x.com/OrangeSurfBTC/status/2084729250997813510",
      "author": "OrangeSurfBTC",
      "platform": "x",
      "organisation": null,
      "posted": "2026-08-04T19:52:40Z",
      "role": "social-statement",
      "why_registered": "Announcement of the mempool.space Research exposure and migration guide, separately captured as mempool-research-key-exposure.\n",
      "relation": {
        "kind": "single-post",
        "head_id": null
      },
      "capture": {
        "status": "held",
        "artefact_count": 2,
        "conversation_copies": 0,
        "conversation_posts": 0,
        "conversation_replies": 0,
        "conversation_gaps": []
      }
    },
    {
      "id": "jamesob-2084624605969350915",
      "title": "Jamesob 2084624605969350915",
      "url": "https://x.com/jamesob/status/2084624605969350915",
      "author": "jamesob",
      "platform": "x",
      "organisation": null,
      "posted": "2026-08-04T12:56:51Z",
      "role": "social-statement",
      "why_registered": "James O'Beirne's first-person account of a May 2025 firmware audit, his concern about the RNG path and libngu constants, and a report to the COLDCARD team that he says was dismissed. No contemporaneous report artefact is attached.\n",
      "relation": {
        "kind": "single-post",
        "head_id": null
      },
      "capture": {
        "status": "held",
        "artefact_count": 5,
        "conversation_copies": 0,
        "conversation_posts": 0,
        "conversation_replies": 0,
        "conversation_gaps": []
      }
    },
    {
      "id": "lunymoon13-2083957228122354112",
      "title": "Lunymoon13 2083957228122354112",
      "url": "https://x.com/lunymoon13/status/2083957228122354112",
      "author": "lunymoon13",
      "platform": "x",
      "organisation": null,
      "posted": "2026-08-02T16:44:55Z",
      "role": "social-statement",
      "why_registered": "First-person report of losing 6.06 BTC after reacting to the incident by moving funds into an impersonating Wasabi wallet from Apple's App Store. The app and loss are not independently verified here.\n",
      "relation": {
        "kind": "single-post",
        "head_id": null
      },
      "capture": {
        "status": "held",
        "artefact_count": 2,
        "conversation_copies": 0,
        "conversation_posts": 0,
        "conversation_replies": 0,
        "conversation_gaps": []
      }
    },
    {
      "id": "meditation_man-2084644147089338742",
      "title": "Meditation_man 2084644147089338742",
      "url": "https://x.com/Meditation_Man/status/2084644147089338742",
      "author": "Meditation_Man",
      "platform": "x",
      "organisation": null,
      "posted": "2026-08-04T14:14:30Z",
      "role": "social-statement",
      "why_registered": "Second-hand report of a friend losing a six-year stack from a Mk4-generated seed without dice rolls or a passphrase. No transaction, amount or device evidence is supplied.\n",
      "relation": {
        "kind": "single-post",
        "head_id": null
      },
      "capture": {
        "status": "held",
        "artefact_count": 2,
        "conversation_copies": 0,
        "conversation_posts": 0,
        "conversation_replies": 0,
        "conversation_gaps": []
      }
    },
    {
      "id": "hodlonaut-2084692918506295583",
      "title": "Hodlonaut 2084692918506295583",
      "url": "https://x.com/hodlonaut/status/2084692918506295583",
      "author": "hodlonaut",
      "platform": "x",
      "organisation": null,
      "posted": "2026-08-04T17:28:18Z",
      "role": "social-statement",
      "why_registered": "Question amplifying the claim that the pseudonymous libngu contributor was Coinkite's CTO. A request for confirmation, not evidence of the identity claim.\n",
      "relation": {
        "kind": "single-post",
        "head_id": null
      },
      "capture": {
        "status": "held",
        "artefact_count": 5,
        "conversation_copies": 0,
        "conversation_posts": 0,
        "conversation_replies": 0,
        "conversation_gaps": []
      }
    },
    {
      "id": "coldcardwallet-2084731768632991801",
      "title": "Coldcardwallet 2084731768632991801",
      "url": "https://x.com/COLDCARDwallet/status/2084731768632991801",
      "author": "COLDCARDwallet",
      "platform": "x",
      "organisation": null,
      "posted": "2026-08-04T20:02:40Z",
      "role": "social-statement",
      "why_registered": "Official 4 August investigation statement: acknowledges losses, repeats migration conditions, announces a historical-disclosures page, describes the submodule-boundary theory, and says multiple frontier-model reviews did not catch the bug.\n",
      "relation": {
        "kind": "single-post",
        "head_id": null
      },
      "capture": {
        "status": "held",
        "artefact_count": 5,
        "conversation_copies": 0,
        "conversation_posts": 0,
        "conversation_replies": 0,
        "conversation_gaps": []
      }
    },
    {
      "id": "coin_and_peace-2084637767720665120",
      "title": "Coin_and_peace 2084637767720665120",
      "url": "https://x.com/Coin_and_Peace/status/2084637767720665120",
      "author": "Coin_and_Peace",
      "platform": "x",
      "organisation": null,
      "posted": "2026-08-04T13:49:09Z",
      "role": "social-statement",
      "why_registered": "Long-form community essay claiming no direct Korean losses had been reported and attributing that outcome to local dice-roll practice and less vendor-aligned advice. The comparative claims are anecdotal and unverified.\n",
      "relation": {
        "kind": "single-post",
        "head_id": null
      },
      "capture": {
        "status": "held",
        "artefact_count": 7,
        "conversation_copies": 0,
        "conversation_posts": 0,
        "conversation_replies": 0,
        "conversation_gaps": []
      }
    },
    {
      "id": "rob1ham-2084642112482496515",
      "title": "Rob1ham 2084642112482496515",
      "url": "https://x.com/Rob1Ham/status/2084642112482496515",
      "author": "Rob1Ham",
      "platform": "x",
      "organisation": null,
      "posted": "2026-08-04T14:06:25Z",
      "role": "social-statement",
      "why_registered": "Rob Hamilton reports that four days of Red Team hardware-wallet scanning had shown no vulnerability indicating those wallets were unsafe. A time-bounded statement about reviewed reports, not a comprehensive security finding.\n",
      "relation": {
        "kind": "single-post",
        "head_id": null
      },
      "capture": {
        "status": "held",
        "artefact_count": 2,
        "conversation_copies": 0,
        "conversation_posts": 0,
        "conversation_replies": 0,
        "conversation_gaps": []
      }
    },
    {
      "id": "josephkelly-2084780878476026046",
      "title": "Josephkelly 2084780878476026046",
      "url": "https://x.com/josephkelly/status/2084780878476026046",
      "author": "josephkelly",
      "platform": "x",
      "organisation": null,
      "posted": "2026-08-04T23:17:49Z",
      "role": "social-statement",
      "why_registered": "Casa's Joseph Kelly thanks named participants in the public technical and migration response. Retained as a record of cross-organisation coordination.\n",
      "relation": {
        "kind": "single-post",
        "head_id": null
      },
      "capture": {
        "status": "held",
        "artefact_count": 2,
        "conversation_copies": 0,
        "conversation_posts": 0,
        "conversation_replies": 0,
        "conversation_gaps": []
      }
    },
    {
      "id": "casahodl-2084792466805276869",
      "title": "Casahodl 2084792466805276869",
      "url": "https://x.com/CasaHODL/status/2084792466805276869",
      "author": "CasaHODL",
      "platform": "x",
      "organisation": null,
      "posted": "2026-08-05T00:03:52Z",
      "role": "social-statement",
      "why_registered": "Casa reports helping owners assess and secure affected setups and points to a public FAQ for members and non-members. Its descriptions of losses and support activity are the company's own account.\n",
      "relation": {
        "kind": "single-post",
        "head_id": null
      },
      "capture": {
        "status": "held",
        "artefact_count": 2,
        "conversation_copies": 0,
        "conversation_posts": 0,
        "conversation_replies": 0,
        "conversation_gaps": []
      }
    },
    {
      "id": "intangiblecoins-2084729603336077327",
      "title": "Intangiblecoins 2084729603336077327",
      "url": "https://x.com/intangiblecoins/status/2084729603336077327",
      "author": "intangiblecoins",
      "platform": "x",
      "organisation": null,
      "posted": "2026-08-04T19:54:04Z",
      "role": "social-statement",
      "why_registered": "Galaxy's Alex Thorn reports a large volume of victim messages and offers a forensic report to each reporter. The post records the intake route, not a count of independently verified victims.\n",
      "relation": {
        "kind": "single-post",
        "head_id": null
      },
      "capture": {
        "status": "held",
        "artefact_count": 2,
        "conversation_copies": 0,
        "conversation_posts": 0,
        "conversation_replies": 0,
        "conversation_gaps": []
      }
    },
    {
      "id": "kloaec-2084788219212632545",
      "title": "KLoaec 2084788219212632545",
      "url": "https://x.com/KLoaec/status/2084788219212632545",
      "author": "KLoaec",
      "platform": "x",
      "organisation": null,
      "posted": "2026-08-04T23:46:59Z",
      "role": "social-statement",
      "why_registered": "Kevin Loaec reflects that early warnings were initially ignored and that checking cold storage brought victim reports into his messages. First-person account of the disclosure response.\n",
      "relation": {
        "kind": "single-post",
        "head_id": null
      },
      "capture": {
        "status": "held",
        "artefact_count": 2,
        "conversation_copies": 0,
        "conversation_posts": 0,
        "conversation_replies": 0,
        "conversation_gaps": []
      }
    },
    {
      "id": "trezor-2084552993471389722",
      "title": "Trezor 2084552993471389722",
      "url": "https://x.com/Trezor/status/2084552993471389722",
      "author": "Trezor",
      "platform": "x",
      "organisation": null,
      "posted": "2026-08-04T08:12:17Z",
      "role": "social-statement",
      "why_registered": "Official Trezor warning that phishing attempts were increasing after the disclosure, with rules never to share seed words or follow unsolicited migration instructions. It also states Trezor devices are unaffected.\n",
      "relation": {
        "kind": "single-post",
        "head_id": null
      },
      "capture": {
        "status": "held",
        "artefact_count": 2,
        "conversation_copies": 0,
        "conversation_posts": 0,
        "conversation_replies": 0,
        "conversation_gaps": []
      }
    },
    {
      "id": "avg_gary-2084784777752637683",
      "title": "Avg_gary 2084784777752637683",
      "url": "https://x.com/avg_gary/status/2084784777752637683",
      "author": "avg_gary",
      "platform": "x",
      "organisation": null,
      "posted": "2026-08-04T23:33:19Z",
      "role": "social-statement",
      "why_registered": "Speculation based on a pseudonym wordplay about the identity of the libngu contributor. Retained as evidence of the conspiracy framing, not as evidence for the claim.\n",
      "relation": {
        "kind": "single-post",
        "head_id": null
      },
      "capture": {
        "status": "held",
        "artefact_count": 5,
        "conversation_copies": 0,
        "conversation_posts": 0,
        "conversation_replies": 0,
        "conversation_gaps": []
      }
    },
    {
      "id": "rob1ham-2084770432020828310",
      "title": "Rob1ham 2084770432020828310",
      "url": "https://x.com/Rob1Ham/status/2084770432020828310",
      "author": "Rob1Ham",
      "platform": "x",
      "organisation": null,
      "posted": "2026-08-04T22:36:18Z",
      "role": "social-statement",
      "why_registered": "Rob Hamilton announces James O'Beirne's CKTRIPWIRE experiment, describing varying added-entropy honeypots intended to measure the active search frontier.\n",
      "relation": {
        "kind": "single-post",
        "head_id": null
      },
      "capture": {
        "status": "held",
        "artefact_count": 2,
        "conversation_copies": 0,
        "conversation_posts": 0,
        "conversation_replies": 0,
        "conversation_gaps": []
      }
    },
    {
      "id": "bitcoinnewscom-2084761545108804038",
      "title": "Bitcoinnewscom 2084761545108804038",
      "url": "https://x.com/BitcoinNewsCom/status/2084761545108804038",
      "author": "BitcoinNewsCom",
      "platform": "x",
      "organisation": null,
      "posted": "2026-08-04T22:01:00Z",
      "role": "social-statement",
      "why_registered": "Secondary report on Red Team claims of 150 scanned repositories, more than a dozen private disclosures and roughly US$20,000 in compute, with OpenSats funding. The underlying reports are not public.\n",
      "relation": {
        "kind": "single-post",
        "head_id": null
      },
      "capture": {
        "status": "held",
        "artefact_count": 2,
        "conversation_copies": 0,
        "conversation_posts": 0,
        "conversation_replies": 0,
        "conversation_gaps": []
      }
    },
    {
      "id": "rob1ham-2084523368783438198",
      "title": "Rob1ham 2084523368783438198",
      "url": "https://x.com/Rob1Ham/status/2084523368783438198",
      "author": "Rob1Ham",
      "platform": "x",
      "organisation": null,
      "posted": "2026-08-04T06:14:34Z",
      "role": "social-statement",
      "why_registered": "Rob Hamilton's Red Team status report: about US$20,000 spent, 150 repositories scanned, more than a dozen disclosures, critical findings and plans to publish an agent harness. Findings are not itemised publicly.\n",
      "relation": {
        "kind": "single-post",
        "head_id": null
      },
      "capture": {
        "status": "held",
        "artefact_count": 2,
        "conversation_copies": 0,
        "conversation_posts": 0,
        "conversation_replies": 0,
        "conversation_gaps": []
      }
    },
    {
      "id": "spacebull-2084744945278300652",
      "title": "Spacebull 2084744945278300652",
      "url": "https://x.com/spacebull/status/2084744945278300652",
      "author": "spacebull",
      "platform": "x",
      "organisation": null,
      "posted": "2026-08-04T20:55:02Z",
      "role": "social-statement",
      "why_registered": "First-person victim reflection describing lost COLDCARD funds as an expensive lesson and announcing a future essay. No amount or transaction is supplied.\n",
      "relation": {
        "kind": "single-post",
        "head_id": null
      },
      "capture": {
        "status": "held",
        "artefact_count": 2,
        "conversation_copies": 0,
        "conversation_posts": 0,
        "conversation_replies": 0,
        "conversation_gaps": []
      }
    },
    {
      "id": "sedited_-2084560146781323351",
      "title": "Sedited_ 2084560146781323351",
      "url": "https://x.com/sedited_/status/2084560146781323351",
      "author": "sedited_",
      "platform": "x",
      "organisation": null,
      "posted": "2026-08-04T08:40:42Z",
      "role": "social-statement",
      "why_registered": "Community advice to avoid updating any COLDCARD and move funds instead. Broader than the configuration-specific guidance and retained as a response record, not adopted here.\n",
      "relation": {
        "kind": "single-post",
        "head_id": null
      },
      "capture": {
        "status": "held",
        "artefact_count": 2,
        "conversation_copies": 0,
        "conversation_posts": 0,
        "conversation_replies": 0,
        "conversation_gaps": []
      }
    },
    {
      "id": "w_s_bitcoin-2084781904918650965",
      "title": "W_s_bitcoin 2084781904918650965",
      "url": "https://x.com/w_s_bitcoin/status/2084781904918650965",
      "author": "w_s_bitcoin",
      "platform": "x",
      "organisation": null,
      "posted": "2026-08-04T23:21:54Z",
      "role": "social-statement",
      "why_registered": "Thought experiment proposing decentralised identity and social attestations for returning hypothetical white-hat sweeps. No such recovery system or sweep is claimed to exist.\n",
      "relation": {
        "kind": "single-post",
        "head_id": null
      },
      "capture": {
        "status": "held",
        "artefact_count": 2,
        "conversation_copies": 0,
        "conversation_posts": 0,
        "conversation_replies": 0,
        "conversation_gaps": []
      }
    },
    {
      "id": "callebtc-2084561246305542617",
      "title": "Callebtc 2084561246305542617",
      "url": "https://x.com/callebtc/status/2084561246305542617",
      "author": "callebtc",
      "platform": "x",
      "organisation": null,
      "posted": "2026-08-04T08:45:05Z",
      "role": "social-statement",
      "why_registered": "Early Red Team update claiming multiple private disclosures, critical findings at a high rate and roughly US$10,000 per day in compute, with OpenSats and Kimi support. No vulnerability details are published.\n",
      "relation": {
        "kind": "single-post",
        "head_id": null
      },
      "capture": {
        "status": "held",
        "artefact_count": 2,
        "conversation_copies": 0,
        "conversation_posts": 0,
        "conversation_replies": 0,
        "conversation_gaps": []
      }
    },
    {
      "id": "coinjoined-2084767522776023158",
      "title": "Coinjoined 2084767522776023158",
      "url": "https://x.com/coinjoined/status/2084767522776023158",
      "author": "coinjoined",
      "platform": "x",
      "organisation": null,
      "posted": "2026-08-04T22:24:45Z",
      "role": "social-statement",
      "why_registered": "Community praise for Kevin Loaec's warning and for Liana, arguing that alternative custody tools may have limited losses. An opinion, not a measured saved-funds claim.\n",
      "relation": {
        "kind": "single-post",
        "head_id": null
      },
      "capture": {
        "status": "held",
        "artefact_count": 2,
        "conversation_copies": 0,
        "conversation_posts": 0,
        "conversation_replies": 0,
        "conversation_gaps": []
      }
    },
    {
      "id": "jamesob-2084603251706503369",
      "title": "Jamesob 2084603251706503369",
      "url": "https://x.com/jamesob/status/2084603251706503369",
      "author": "jamesob",
      "platform": "x",
      "organisation": null,
      "posted": "2026-08-04T11:31:59Z",
      "role": "social-statement",
      "why_registered": "Short follow-up to James O'Beirne's longer account, stating that he reported a possible active RNG misconfiguration in May 2025 and trusted the vendor's response. No contemporaneous report is attached.\n",
      "relation": {
        "kind": "single-post",
        "head_id": null
      },
      "capture": {
        "status": "held",
        "artefact_count": 5,
        "conversation_copies": 0,
        "conversation_posts": 0,
        "conversation_replies": 0,
        "conversation_gaps": []
      }
    },
    {
      "id": "coldcardwallet-2084574110445674733",
      "title": "Coldcardwallet 2084574110445674733",
      "url": "https://x.com/COLDCARDwallet/status/2084574110445674733",
      "author": "COLDCARDwallet",
      "platform": "x",
      "organisation": null,
      "posted": "2026-08-04T09:36:12Z",
      "role": "social-statement",
      "why_registered": "Brief official reply about customer-data retention: physical personal information is described as deleted while email is retained. Kept with the reply context rather than treated as a complete policy statement.\n",
      "relation": {
        "kind": "single-post",
        "head_id": null
      },
      "capture": {
        "status": "held",
        "artefact_count": 5,
        "conversation_copies": 0,
        "conversation_posts": 0,
        "conversation_replies": 0,
        "conversation_gaps": []
      }
    },
    {
      "id": "julianor-2084332016321863862",
      "title": "Julianor 2084332016321863862",
      "url": "https://x.com/julianor/status/2084332016321863862",
      "author": "julianor",
      "platform": "x",
      "organisation": null,
      "posted": "2026-08-03T17:34:12Z",
      "role": "social-statement",
      "why_registered": "Julián Ors cautions that finding an insecure RNG does not establish key exposure without reachability and release-history analysis. A useful counterweight to broad post-incident AI scanning claims.\n",
      "relation": {
        "kind": "single-post",
        "head_id": null
      },
      "capture": {
        "status": "held",
        "artefact_count": 2,
        "conversation_copies": 0,
        "conversation_posts": 0,
        "conversation_replies": 0,
        "conversation_gaps": []
      }
    },
    {
      "id": "bitcoinnewscom-2084281113359302715",
      "title": "Bitcoinnewscom 2084281113359302715",
      "url": "https://x.com/BitcoinNewsCom/status/2084281113359302715",
      "author": "BitcoinNewsCom",
      "platform": "x",
      "organisation": null,
      "posted": "2026-08-03T14:11:56Z",
      "role": "social-statement",
      "why_registered": "Secondary relay of Galaxy's third-wave estimate: 207.7294 BTC and a revised 1,367.05 BTC across 4,585 addresses. The Galaxy primary post is separately captured.\n",
      "relation": {
        "kind": "single-post",
        "head_id": null
      },
      "capture": {
        "status": "held",
        "artefact_count": 9,
        "conversation_copies": 0,
        "conversation_posts": 0,
        "conversation_replies": 0,
        "conversation_gaps": []
      }
    },
    {
      "id": "xbtoshi-2084476380452950050",
      "title": "Xbtoshi 2084476380452950050",
      "url": "https://x.com/xbtoshi/status/2084476380452950050",
      "author": "xbtoshi",
      "platform": "x",
      "organisation": null,
      "posted": "2026-08-04T03:07:51Z",
      "role": "social-statement",
      "why_registered": "Thought experiment comparing how the same weak-seed flaw might be exploited on Monero, arguing private balances and scan costs would change mass-target economics. Technical speculation, not incident evidence.\n",
      "relation": {
        "kind": "single-post",
        "head_id": null
      },
      "capture": {
        "status": "held",
        "artefact_count": 7,
        "conversation_copies": 0,
        "conversation_posts": 0,
        "conversation_replies": 0,
        "conversation_gaps": []
      }
    },
    {
      "id": "kloaec-2084755995801047336",
      "title": "KLoaec 2084755995801047336",
      "url": "https://x.com/KLoaec/status/2084755995801047336",
      "author": "KLoaec",
      "platform": "x",
      "organisation": null,
      "posted": "2026-08-04T21:38:56Z",
      "role": "social-statement",
      "why_registered": "Kevin Loaec closes his emergency-warning role five days later and announces a future first-person postmortem. Any number of people saved is not quantified.\n",
      "relation": {
        "kind": "single-post",
        "head_id": null
      },
      "capture": {
        "status": "held",
        "artefact_count": 5,
        "conversation_copies": 0,
        "conversation_posts": 0,
        "conversation_replies": 0,
        "conversation_gaps": []
      }
    },
    {
      "id": "chainalysis-2084734055858282986",
      "title": "Chainalysis 2084734055858282986",
      "url": "https://x.com/chainalysis/status/2084734055858282986",
      "author": "chainalysis",
      "platform": "x",
      "organisation": null,
      "posted": "2026-08-04T20:11:46Z",
      "role": "social-statement",
      "why_registered": "Chainalysis reports that Canadian holders account for 25 percent of losses it could geographically attribute, with Australia, the United States and Thailand also prominent. The post does not publish its dataset or method.\n",
      "relation": {
        "kind": "single-post",
        "head_id": null
      },
      "capture": {
        "status": "held",
        "artefact_count": 5,
        "conversation_copies": 0,
        "conversation_posts": 0,
        "conversation_replies": 0,
        "conversation_gaps": []
      }
    },
    {
      "id": "bitcoin_devs-2084675763542823016",
      "title": "Bitcoin_devs 2084675763542823016",
      "url": "https://x.com/Bitcoin_Devs/status/2084675763542823016",
      "author": "Bitcoin_Devs",
      "platform": "x",
      "organisation": null,
      "posted": "2026-08-04T16:20:08Z",
      "role": "social-statement",
      "why_registered": "Short educational prompt contrasting 40 bits and 256 bits of entropy. Retained as a pointer to the public-explanation wave, not a technical analysis by itself.\n",
      "relation": {
        "kind": "single-post",
        "head_id": null
      },
      "capture": {
        "status": "held",
        "artefact_count": 11,
        "conversation_copies": 0,
        "conversation_posts": 0,
        "conversation_replies": 0,
        "conversation_gaps": []
      }
    },
    {
      "id": "jamesob-2084769501661331589",
      "title": "Jamesob 2084769501661331589",
      "url": "https://x.com/jamesob/status/2084769501661331589",
      "author": "jamesob",
      "platform": "x",
      "organisation": null,
      "posted": "2026-08-04T22:32:36Z",
      "role": "social-statement",
      "why_registered": "James O'Beirne announces CKTRIPWIRE: Mk3-calibrated honeypots with stepped dice-roll and passphrase entropy. The control UTXO was reported swept within one hour; the live dashboard is separately captured.\n",
      "relation": {
        "kind": "single-post",
        "head_id": null
      },
      "capture": {
        "status": "held",
        "artefact_count": 7,
        "conversation_copies": 0,
        "conversation_posts": 0,
        "conversation_replies": 0,
        "conversation_gaps": []
      }
    },
    {
      "id": "benjustman-2084766262899752985",
      "title": "Benjustman 2084766262899752985",
      "url": "https://x.com/BenJustman/status/2084766262899752985",
      "author": "BenJustman",
      "platform": "x",
      "organisation": null,
      "posted": "2026-08-04T22:19:44Z",
      "role": "social-statement",
      "why_registered": "Background commentary listing two earlier engineering projects attributed to Peter Gray. It does not establish responsibility for the RNG defect or the identity of the pseudonymous contributor.\n",
      "relation": {
        "kind": "single-post",
        "head_id": null
      },
      "capture": {
        "status": "held",
        "artefact_count": 2,
        "conversation_copies": 0,
        "conversation_posts": 0,
        "conversation_replies": 0,
        "conversation_gaps": []
      }
    },
    {
      "id": "blockunmasked-2083210091671568874",
      "title": "Blockunmasked 2083210091671568874",
      "url": "https://x.com/blockunmasked/status/2083210091671568874",
      "author": "blockunmasked",
      "platform": "x",
      "organisation": null,
      "posted": "2026-07-31T15:16:04Z",
      "role": "social-statement",
      "why_registered": "Blockchain Unmasked says it investigated Coldcard victim reports in 2024, attributed them to weak seed entropy and reported findings to Coinkite and government agencies. The detailed article is separately captured; contemporaneous reports are not public.\n",
      "relation": {
        "kind": "single-post",
        "head_id": null
      },
      "capture": {
        "status": "held",
        "artefact_count": 2,
        "conversation_copies": 0,
        "conversation_posts": 0,
        "conversation_replies": 0,
        "conversation_gaps": []
      }
    },
    {
      "id": "cz_binance-2084531849515131231",
      "title": "Cz_binance 2084531849515131231",
      "url": "https://x.com/cz_binance/status/2084531849515131231",
      "author": "cz_binance",
      "platform": "x",
      "organisation": null,
      "posted": "2026-08-04T06:48:16Z",
      "role": "social-statement",
      "why_registered": "CZ argues that losses on the self-custody side are underreported and that custody choices have different risk profiles, while noting exchanges including Binance have covered some losses. A custody-policy opinion with an obvious commercial conflict.\n",
      "relation": {
        "kind": "single-post",
        "head_id": null
      },
      "capture": {
        "status": "held",
        "artefact_count": 2,
        "conversation_copies": 0,
        "conversation_posts": 0,
        "conversation_replies": 0,
        "conversation_gaps": []
      }
    },
    {
      "id": "intangiblecoins-2084584185528746434",
      "title": "Intangiblecoins 2084584185528746434",
      "url": "https://x.com/intangiblecoins/status/2084584185528746434",
      "author": "intangiblecoins",
      "platform": "x",
      "organisation": null,
      "posted": "2026-08-04T10:16:14Z",
      "role": "social-statement",
      "why_registered": "Galaxy's Alex Thorn reports an estimate of at least 15 distinct attackers, based on continuing victim reports and cluster labelling. The underlying address set and classification method are not published.\n",
      "relation": {
        "kind": "single-post",
        "head_id": null
      },
      "capture": {
        "status": "held",
        "artefact_count": 2,
        "conversation_copies": 0,
        "conversation_posts": 0,
        "conversation_replies": 0,
        "conversation_gaps": []
      }
    },
    {
      "id": "fonta1n3-2084591160505389296",
      "title": "Fonta1n3 2084591160505389296",
      "url": "https://x.com/fonta1n3/status/2084591160505389296",
      "author": "fonta1n3",
      "platform": "x",
      "organisation": null,
      "posted": "2026-08-04T10:43:57Z",
      "role": "social-statement",
      "why_registered": "Relays an explicitly unverified report of a poison-change multisig bug. Retained as rumour propagation, not evidence that the issue exists.\n",
      "relation": {
        "kind": "single-post",
        "head_id": null
      },
      "capture": {
        "status": "held",
        "artefact_count": 5,
        "conversation_copies": 0,
        "conversation_posts": 0,
        "conversation_replies": 0,
        "conversation_gaps": []
      }
    },
    {
      "id": "bitcoinnewscom-2084593487408722197",
      "title": "Bitcoinnewscom 2084593487408722197",
      "url": "https://x.com/BitcoinNewsCom/status/2084593487408722197",
      "author": "BitcoinNewsCom",
      "platform": "x",
      "organisation": null,
      "posted": "2026-08-04T10:53:11Z",
      "role": "social-statement",
      "why_registered": "Secondary summary combining Galaxy's reported attacker count with Red Team disclosure-rate claims. Primary posts for both claims are separately captured.\n",
      "relation": {
        "kind": "single-post",
        "head_id": null
      },
      "capture": {
        "status": "held",
        "artefact_count": 2,
        "conversation_copies": 0,
        "conversation_posts": 0,
        "conversation_replies": 0,
        "conversation_gaps": []
      }
    },
    {
      "id": "theretailbull-2083930775217488305",
      "title": "Theretailbull 2083930775217488305",
      "url": "https://x.com/theretailbull/status/2083930775217488305",
      "author": "theretailbull",
      "platform": "x",
      "organisation": null,
      "posted": "2026-08-02T14:59:49Z",
      "role": "social-statement",
      "why_registered": "First-person report of losing 2 BTC from a Mk3 while away, after being unable to reach the seed in time. The amount and circumstances are not independently corroborated.\n",
      "relation": {
        "kind": "single-post",
        "head_id": null
      },
      "capture": {
        "status": "held",
        "artefact_count": 2,
        "conversation_copies": 0,
        "conversation_posts": 0,
        "conversation_replies": 0,
        "conversation_gaps": []
      }
    },
    {
      "id": "shocknet_justin-2084315236086042751",
      "title": "Shocknet_justin 2084315236086042751",
      "url": "https://x.com/shocknet_justin/status/2084315236086042751",
      "author": "shocknet_justin",
      "platform": "x",
      "organisation": null,
      "posted": "2026-08-03T16:27:31Z",
      "role": "social-statement",
      "why_registered": "Reports an AI review finding a critical issue in an unnamed popular software wallet and says it was privately disclosed. With no project or report named, the finding cannot be independently assessed.\n",
      "relation": {
        "kind": "single-post",
        "head_id": null
      },
      "capture": {
        "status": "held",
        "artefact_count": 5,
        "conversation_copies": 0,
        "conversation_posts": 0,
        "conversation_replies": 0,
        "conversation_gaps": []
      }
    },
    {
      "id": "boomer_btc-2084397691396595798",
      "title": "Boomer_btc 2084397691396595798",
      "url": "https://x.com/boomer_btc/status/2084397691396595798",
      "author": "boomer_btc",
      "platform": "x",
      "organisation": null,
      "posted": "2026-08-03T21:55:10Z",
      "role": "social-statement",
      "why_registered": "Speculates that concern about a possible chain split influenced exploit timing, while explicitly saying no split is expected. No evidence links the timing to this hypothesis.\n",
      "relation": {
        "kind": "single-post",
        "head_id": null
      },
      "capture": {
        "status": "held",
        "artefact_count": 2,
        "conversation_copies": 0,
        "conversation_posts": 0,
        "conversation_replies": 0,
        "conversation_gaps": []
      }
    },
    {
      "id": "phil_geiger-2084277844826308614",
      "title": "Phil_geiger 2084277844826308614",
      "url": "https://x.com/phil_geiger/status/2084277844826308614",
      "author": "phil_geiger",
      "platform": "x",
      "organisation": null,
      "posted": "2026-08-03T13:58:56Z",
      "role": "social-statement",
      "why_registered": "Comparative multisig-device recommendations covering Ledger, Jade, BitBox and Trezor. Product opinion rather than incident evidence, with no comprehensive security assessment implied.\n",
      "relation": {
        "kind": "single-post",
        "head_id": null
      },
      "capture": {
        "status": "held",
        "artefact_count": 2,
        "conversation_copies": 0,
        "conversation_posts": 0,
        "conversation_replies": 0,
        "conversation_gaps": []
      }
    },
    {
      "id": "hosseeb-2084327870961508408",
      "title": "Hosseeb 2084327870961508408",
      "url": "https://x.com/hosseeb/status/2084327870961508408",
      "author": "hosseeb",
      "platform": "x",
      "organisation": null,
      "posted": "2026-08-03T17:17:44Z",
      "role": "social-statement",
      "why_registered": "Haseeb Qureshi argues security now depends on defensive AI spend and proposes a cost-of-discovery metric, estimating this bug at roughly US$2. The estimate and policy conclusion are his own.\n",
      "relation": {
        "kind": "single-post",
        "head_id": null
      },
      "capture": {
        "status": "held",
        "artefact_count": 2,
        "conversation_copies": 0,
        "conversation_posts": 0,
        "conversation_replies": 0,
        "conversation_gaps": []
      }
    },
    {
      "id": "theragetech-2084356768868495441",
      "title": "Theragetech 2084356768868495441",
      "url": "https://x.com/theragetech/status/2084356768868495441",
      "author": "theragetech",
      "platform": "x",
      "organisation": null,
      "posted": "2026-08-03T19:12:33Z",
      "role": "social-statement",
      "why_registered": "Announcement of The Rage's long-form incident guide, separately captured as therage-coldcard-hack-guide.\n",
      "relation": {
        "kind": "single-post",
        "head_id": null
      },
      "capture": {
        "status": "held",
        "artefact_count": 5,
        "conversation_copies": 0,
        "conversation_posts": 0,
        "conversation_replies": 0,
        "conversation_gaps": []
      }
    },
    {
      "id": "coindesk-2084302018076930186",
      "title": "Coindesk 2084302018076930186",
      "url": "https://x.com/coindesk/status/2084302018076930186",
      "author": "coindesk",
      "platform": "x",
      "organisation": null,
      "posted": "2026-08-03T15:35:00Z",
      "role": "social-statement",
      "why_registered": "CoinDesk video-news teaser presenting a near-US$114 million fourth-wave figure alongside unrelated news. Secondary reporting; its scope is not adopted by the funds record.\n",
      "relation": {
        "kind": "single-post",
        "head_id": null
      },
      "capture": {
        "status": "held",
        "artefact_count": 5,
        "conversation_copies": 0,
        "conversation_posts": 0,
        "conversation_replies": 0,
        "conversation_gaps": []
      }
    },
    {
      "id": "orangesurfbtc-2084409794618675555",
      "title": "Orangesurfbtc 2084409794618675555",
      "url": "https://x.com/OrangeSurfBTC/status/2084409794618675555",
      "author": "OrangeSurfBTC",
      "platform": "x",
      "organisation": null,
      "posted": "2026-08-03T22:43:16Z",
      "role": "social-statement",
      "why_registered": "OrangeSurf argues that users can test a signing device's deterministic dice workflow with public test rolls and recommends 100 or more private rolls for real use. Technical advice attributed to the author.\n",
      "relation": {
        "kind": "single-post",
        "head_id": null
      },
      "capture": {
        "status": "held",
        "artefact_count": 2,
        "conversation_copies": 0,
        "conversation_posts": 0,
        "conversation_replies": 0,
        "conversation_gaps": []
      }
    },
    {
      "id": "orangesurfbtc-2084591381364830473",
      "title": "Orangesurfbtc 2084591381364830473",
      "url": "https://x.com/OrangeSurfBTC/status/2084591381364830473",
      "author": "OrangeSurfBTC",
      "platform": "x",
      "organisation": null,
      "posted": "2026-08-04T10:44:49Z",
      "role": "social-statement",
      "why_registered": "OrangeSurf reports more than 3,650 BTC spent from multisig wallets through Slipstream, presumed to be incident migration. No transaction set or independent counterfactual is provided.\n",
      "relation": {
        "kind": "single-post",
        "head_id": null
      },
      "capture": {
        "status": "held",
        "artefact_count": 5,
        "conversation_copies": 0,
        "conversation_posts": 0,
        "conversation_replies": 0,
        "conversation_gaps": []
      }
    },
    {
      "id": "tftc21-2084312517669761426",
      "title": "Tftc21 2084312517669761426",
      "url": "https://x.com/tftc21/status/2084312517669761426",
      "author": "tftc21",
      "platform": "x",
      "organisation": null,
      "posted": "2026-08-03T16:16:43Z",
      "role": "social-statement",
      "why_registered": "Announcement of a TFTC Rabbit Hole Recap episode about the incident. Retained as a media-response pointer rather than primary evidence.\n",
      "relation": {
        "kind": "single-post",
        "head_id": null
      },
      "capture": {
        "status": "held",
        "artefact_count": 2,
        "conversation_copies": 0,
        "conversation_posts": 0,
        "conversation_replies": 0,
        "conversation_gaps": []
      }
    },
    {
      "id": "jamesob-2084620229389197453",
      "title": "Jamesob 2084620229389197453",
      "url": "https://x.com/jamesob/status/2084620229389197453",
      "author": "jamesob",
      "platform": "x",
      "organisation": null,
      "posted": "2026-08-04T12:39:27Z",
      "role": "social-statement",
      "why_registered": "James O'Beirne alleges that the pseudonymous libngu contributor may have been Coinkite CTO Peter Gray. The post supplies no conclusive identity evidence, so the attribution remains unverified.\n",
      "relation": {
        "kind": "single-post",
        "head_id": null
      },
      "capture": {
        "status": "held",
        "artefact_count": 2,
        "conversation_copies": 0,
        "conversation_posts": 0,
        "conversation_replies": 0,
        "conversation_gaps": []
      }
    },
    {
      "id": "hodldee-2084689963652669896",
      "title": "Hodldee 2084689963652669896",
      "url": "https://x.com/HodlDee/status/2084689963652669896",
      "author": "HodlDee",
      "platform": "x",
      "organisation": null,
      "posted": "2026-08-04T17:16:33Z",
      "role": "social-statement",
      "why_registered": "Public offer to help affected owners move funds. Retained as part of the volunteer-response record; inclusion is not an endorsement of private-message migration assistance.\n",
      "relation": {
        "kind": "single-post",
        "head_id": null
      },
      "capture": {
        "status": "held",
        "artefact_count": 2,
        "conversation_copies": 0,
        "conversation_posts": 0,
        "conversation_replies": 0,
        "conversation_gaps": []
      }
    },
    {
      "id": "l0lal33tz-2084733132608323868",
      "title": "L0lal33tz 2084733132608323868",
      "url": "https://x.com/L0laL33tz/status/2084733132608323868",
      "author": "L0laL33tz",
      "platform": "x",
      "organisation": null,
      "posted": "2026-08-04T20:08:05Z",
      "role": "social-statement",
      "why_registered": "L0laL33tz reports that Thomas Braziel, who offered victims help recovering coins through a lawsuit against Coinkite, had been ordered to pay former clients $1.9 million restitution, and warns victims not to hand over their claims.\n",
      "relation": {
        "kind": "single-post",
        "head_id": null
      },
      "capture": {
        "status": "held",
        "artefact_count": 7,
        "conversation_copies": 0,
        "conversation_posts": 0,
        "conversation_replies": 0,
        "conversation_gaps": []
      }
    },
    {
      "id": "kloaec-2084609292057915726",
      "title": "KLoaec 2084609292057915726",
      "url": "https://x.com/KLoaec/status/2084609292057915726",
      "author": "KLoaec",
      "platform": "x",
      "organisation": null,
      "posted": "2026-08-04T11:56:00Z",
      "role": "social-statement",
      "why_registered": "Kevin Loaec's 4 August migration checklist: single-sig without 50 or more dice rolls and all-COLDCARD multisigs move immediately; mixed multisig and miniscript setups follow the linked guide.\n",
      "relation": {
        "kind": "single-post",
        "head_id": null
      },
      "capture": {
        "status": "held",
        "artefact_count": 2,
        "conversation_copies": 0,
        "conversation_posts": 0,
        "conversation_replies": 0,
        "conversation_gaps": []
      }
    },
    {
      "id": "l0lal33tz-2084738388297716206",
      "title": "L0lal33tz 2084738388297716206",
      "url": "https://x.com/L0laL33tz/status/2084738388297716206",
      "author": "L0laL33tz",
      "platform": "x",
      "organisation": null,
      "posted": "2026-08-04T20:28:58Z",
      "role": "social-statement",
      "why_registered": "L0laL33tz points affected users to Alex Thorn's video on improving recovery chances, noting he is tracing the attack waves, coordinating with law enforcement, and taking victim addresses to produce tracing proofs.\n",
      "relation": {
        "kind": "single-post",
        "head_id": null
      },
      "capture": {
        "status": "held",
        "artefact_count": 2,
        "conversation_copies": 0,
        "conversation_posts": 0,
        "conversation_replies": 0,
        "conversation_gaps": []
      }
    },
    {
      "id": "janrothen-2084766282352861505",
      "title": "Janrothen 2084766282352861505",
      "url": "https://x.com/janrothen/status/2084766282352861505",
      "author": "janrothen",
      "platform": "x",
      "organisation": null,
      "posted": "2026-08-04T22:19:49Z",
      "role": "social-statement",
      "why_registered": "Jan Rothen reports that Coinkite's downloads page still offered the vulnerable 4.x firmware versions named in its own advisory six days after disclosure, with no warning on the files.\n",
      "relation": {
        "kind": "single-post",
        "head_id": null
      },
      "capture": {
        "status": "held",
        "artefact_count": 5,
        "conversation_copies": 0,
        "conversation_posts": 0,
        "conversation_replies": 0,
        "conversation_gaps": []
      }
    },
    {
      "id": "americanhodl8-2084788362968506750",
      "title": "Americanhodl8 2084788362968506750",
      "url": "https://x.com/americanhodl8/status/2084788362968506750",
      "author": "americanhodl8",
      "platform": "x",
      "organisation": null,
      "posted": "2026-08-04T23:47:33Z",
      "role": "social-statement",
      "why_registered": "AMERICAN HODL tags Coinkite's accounts demanding the still-listed downloads be pulled; the held screenshot is the downloads page image also documented in janrothen's post.\n",
      "relation": {
        "kind": "single-post",
        "head_id": null
      },
      "capture": {
        "status": "held",
        "artefact_count": 2,
        "conversation_copies": 0,
        "conversation_posts": 0,
        "conversation_replies": 0,
        "conversation_gaps": []
      }
    },
    {
      "id": "blockdyor-2084756541635182834",
      "title": "Blockdyor 2084756541635182834",
      "url": "https://x.com/blockdyor/status/2084756541635182834",
      "author": "blockdyor",
      "platform": "x",
      "organisation": null,
      "posted": "2026-08-04T21:41:07Z",
      "role": "social-statement",
      "why_registered": "blockdyor's 4 August demand that Coinkite remove pre-5.6.0 firmware from its downloads page, the versions carrying the entropy bug.\n",
      "relation": {
        "kind": "single-post",
        "head_id": null
      },
      "capture": {
        "status": "held",
        "artefact_count": 9,
        "conversation_copies": 0,
        "conversation_posts": 0,
        "conversation_replies": 0,
        "conversation_gaps": []
      }
    },
    {
      "id": "pavelthecoder-2084755064686551327",
      "title": "Pavelthecoder 2084755064686551327",
      "url": "https://x.com/pavelthecoder/status/2084755064686551327",
      "author": "pavelthecoder",
      "platform": "x",
      "organisation": null,
      "posted": "2026-08-04T21:35:14Z",
      "role": "social-statement",
      "why_registered": "pavelthecoder's claim that the operator was mixing stolen funds through Wasabi and that Wasabi would expose them; held as a reported claim, not an established fact.\n",
      "relation": {
        "kind": "single-post",
        "head_id": null
      },
      "capture": {
        "status": "held",
        "artefact_count": 2,
        "conversation_copies": 0,
        "conversation_posts": 0,
        "conversation_replies": 0,
        "conversation_gaps": []
      }
    },
    {
      "id": "raw_avocado-2084806989205385667",
      "title": "Raw_avocado 2084806989205385667",
      "url": "https://x.com/raw_avocado/status/2084806989205385667",
      "author": "raw_avocado",
      "platform": "x",
      "organisation": null,
      "posted": "2026-08-05T01:01:34Z",
      "role": "social-statement",
      "why_registered": "Flags an OP_RETURN message sent to one of the theft consolidation addresses; the message content is carried in the attached screenshot held by the capture.\n",
      "relation": {
        "kind": "single-post",
        "head_id": null
      },
      "capture": {
        "status": "held",
        "artefact_count": 5,
        "conversation_copies": 0,
        "conversation_posts": 0,
        "conversation_replies": 0,
        "conversation_gaps": []
      }
    },
    {
      "id": "fatmanterra-2084791442212339942",
      "title": "Fatmanterra 2084791442212339942",
      "url": "https://x.com/fatmanterra/status/2084791442212339942",
      "author": "fatmanterra",
      "platform": "x",
      "organisation": null,
      "posted": "2026-08-04T23:59:48Z",
      "role": "social-statement",
      "why_registered": "FatMan argues the broken RNG points to negligence rather than an orchestrated inside job, since a deliberate backdoor would have been kept secret rather than left publicly crackable.\n",
      "relation": {
        "kind": "single-post",
        "head_id": null
      },
      "capture": {
        "status": "held",
        "artefact_count": 2,
        "conversation_copies": 0,
        "conversation_posts": 0,
        "conversation_replies": 0,
        "conversation_gaps": []
      }
    },
    {
      "id": "stack2thefuture-2084760618322526298",
      "title": "Stack2thefuture 2084760618322526298",
      "url": "https://x.com/stack2thefuture/status/2084760618322526298",
      "author": "stack2thefuture",
      "platform": "x",
      "organisation": null,
      "posted": "2026-08-04T21:57:19Z",
      "role": "social-statement",
      "why_registered": "Notes that Coinkite's Peter Gray was a public figure in the company's early years, citing a 2013 Toronto Star article, and counsels against reading conspiracy into his later privacy.\n",
      "relation": {
        "kind": "single-post",
        "head_id": null
      },
      "capture": {
        "status": "held",
        "artefact_count": 2,
        "conversation_copies": 0,
        "conversation_posts": 0,
        "conversation_replies": 0,
        "conversation_gaps": []
      }
    },
    {
      "id": "pledditor-2084624867350004111",
      "title": "Pledditor 2084624867350004111",
      "url": "https://x.com/pledditor/status/2084624867350004111",
      "author": "pledditor",
      "platform": "x",
      "organisation": null,
      "posted": "2026-08-04T12:57:53Z",
      "role": "social-statement",
      "why_registered": "Pledditor's day-5 criticism that NVK and Doc Hex had given little to no communication since the patched firmware shipped.\n",
      "relation": {
        "kind": "single-post",
        "head_id": null
      },
      "capture": {
        "status": "held",
        "artefact_count": 2,
        "conversation_copies": 0,
        "conversation_posts": 0,
        "conversation_replies": 0,
        "conversation_gaps": []
      }
    },
    {
      "id": "coldcardwallet-2084632203019833820",
      "title": "Coldcardwallet 2084632203019833820",
      "url": "https://x.com/coldcardwallet/status/2084632203019833820",
      "author": "coldcardwallet",
      "platform": "x",
      "organisation": null,
      "posted": "2026-08-04T13:27:02Z",
      "role": "social-statement",
      "why_registered": "Coinkite's reply to the silence criticism: the team is heads down, personal opinions add no value, and the company is speaking with a single united front for accurate information.\n",
      "relation": {
        "kind": "single-post",
        "head_id": null
      },
      "capture": {
        "status": "held",
        "artefact_count": 2,
        "conversation_copies": 0,
        "conversation_posts": 0,
        "conversation_replies": 0,
        "conversation_gaps": []
      }
    },
    {
      "id": "kloaec-2082882772092211589",
      "title": "KLoaec 2082882772092211589",
      "url": "https://x.com/KLoaec/status/2082882772092211589",
      "author": "KLoaec",
      "platform": "x",
      "organisation": null,
      "posted": "2026-07-30T17:35:25Z",
      "role": "social-statement",
      "why_registered": "Kevin Loaec's 30 July request for balance reports from single-sig COLDCARD owners who generated seeds on-device; one of the first public alerts that wallets were being drained.\n",
      "relation": {
        "kind": "single-post",
        "head_id": null
      },
      "capture": {
        "status": "held",
        "artefact_count": 2,
        "conversation_copies": 0,
        "conversation_posts": 0,
        "conversation_replies": 0,
        "conversation_gaps": []
      }
    },
    {
      "id": "nvk-2082956626516967510",
      "title": "NVK 2082956626516967510",
      "url": "https://x.com/nvk/status/2082956626516967510",
      "author": "nvk",
      "platform": "x",
      "organisation": null,
      "posted": "2026-07-30T22:28:53Z",
      "role": "social-statement",
      "why_registered": "nvk's first-night statement that an earlier post was wrong and a blog was coming, made while the sweep's cause was still unknown.\n",
      "relation": {
        "kind": "single-post",
        "head_id": null
      },
      "capture": {
        "status": "held",
        "artefact_count": 2,
        "conversation_copies": 0,
        "conversation_posts": 0,
        "conversation_replies": 0,
        "conversation_gaps": []
      }
    },
    {
      "id": "jwweatherman_-1329613163973668865",
      "title": "Jwweatherman_ 1329613163973668865",
      "url": "https://x.com/JWWeatherman_/status/1329613163973668865",
      "author": "JWWeatherman_",
      "platform": "x",
      "organisation": null,
      "posted": "2020-11-20T02:30:55Z",
      "role": "social-statement",
      "why_registered": "JW Weatherman's November 2020 prediction that a hardware wallet would exit scam within five years by blaming a bug or rogue employee; registered as historical context.\n",
      "relation": {
        "kind": "single-post",
        "head_id": null
      },
      "capture": {
        "status": "held",
        "artefact_count": 2,
        "conversation_copies": 0,
        "conversation_posts": 0,
        "conversation_replies": 0,
        "conversation_gaps": []
      }
    },
    {
      "id": "nvk-1341213389549412353",
      "title": "NVK 1341213389549412353",
      "url": "https://x.com/nvk/status/1341213389549412353",
      "author": "nvk",
      "platform": "x",
      "organisation": null,
      "posted": "2020-12-22T02:46:05Z",
      "role": "social-statement",
      "why_registered": "nvk's December 2020 reply that users were likelier to lose coins through their own mistakes than a vendor attack, recommending dice; a pre-incident record of the vendor's public stance.\n",
      "relation": {
        "kind": "single-post",
        "head_id": null
      },
      "capture": {
        "status": "held",
        "artefact_count": 2,
        "conversation_copies": 0,
        "conversation_posts": 0,
        "conversation_replies": 0,
        "conversation_gaps": []
      }
    },
    {
      "id": "finnejay-1737662786941968736",
      "title": "Finnejay 1737662786941968736",
      "url": "https://x.com/FinneJay/status/1737662786941968736",
      "author": "FinneJay",
      "platform": "x",
      "organisation": null,
      "posted": "2023-12-21T02:34:27Z",
      "role": "social-statement",
      "why_registered": "A December 2023 thread promising an easy guide to generating a bitcoin private key offline; pre-incident context on manual key generation.\n",
      "relation": {
        "kind": "single-post",
        "head_id": null
      },
      "capture": {
        "status": "held",
        "artefact_count": 5,
        "conversation_copies": 0,
        "conversation_posts": 0,
        "conversation_replies": 0,
        "conversation_gaps": []
      }
    },
    {
      "id": "foundationhq-1778581463618773441",
      "title": "Foundationhq 1778581463618773441",
      "url": "https://x.com/FoundationHQ/status/1778581463618773441",
      "author": "FoundationHQ",
      "platform": "x",
      "organisation": null,
      "posted": "2024-04-12T00:30:40Z",
      "role": "social-statement",
      "why_registered": "Foundation's April 2024 explanation for not adding dice rolls to Passport, citing reported COLDCARD losses from low dice counts and noting dice do not protect against malicious firmware.\n",
      "relation": {
        "kind": "single-post",
        "head_id": null
      },
      "capture": {
        "status": "held",
        "artefact_count": 2,
        "conversation_copies": 0,
        "conversation_posts": 0,
        "conversation_replies": 0,
        "conversation_gaps": []
      }
    },
    {
      "id": "nvk-2031836293240668367",
      "title": "NVK 2031836293240668367",
      "url": "https://x.com/nvk/status/2031836293240668367",
      "author": "nvk",
      "platform": "x",
      "organisation": null,
      "posted": "2026-03-11T20:54:56Z",
      "role": "social-statement",
      "why_registered": "nvk's March 2026 reference list of crypto company data breaches that led to phishing and scam campaigns, published months before the incident.\n",
      "relation": {
        "kind": "single-post",
        "head_id": null
      },
      "capture": {
        "status": "held",
        "artefact_count": 5,
        "conversation_copies": 0,
        "conversation_posts": 0,
        "conversation_replies": 0,
        "conversation_gaps": []
      }
    },
    {
      "id": "lopp-2082912652645253204",
      "title": "Lopp 2082912652645253204",
      "url": "https://x.com/lopp/status/2082912652645253204",
      "author": "lopp",
      "platform": "x",
      "organisation": null,
      "posted": "2026-07-30T19:34:09Z",
      "role": "social-statement",
      "why_registered": "Jameson Lopp relays a victim report of a partial loss from a fully airgapped device whose seed was generated on-device without user-supplied entropy.\n",
      "relation": {
        "kind": "single-post",
        "head_id": null
      },
      "capture": {
        "status": "held",
        "artefact_count": 2,
        "conversation_copies": 0,
        "conversation_posts": 0,
        "conversation_replies": 0,
        "conversation_gaps": []
      }
    },
    {
      "id": "bitcoinnewscom-2082919505819304343",
      "title": "Bitcoinnewscom 2082919505819304343",
      "url": "https://x.com/BitcoinNewsCom/status/2082919505819304343",
      "author": "BitcoinNewsCom",
      "platform": "x",
      "organisation": null,
      "posted": "2026-07-30T20:01:23Z",
      "role": "social-statement",
      "why_registered": "Bitcoin News' first-night report of roughly 594 BTC swept from 500 single-sig addresses in 25 minutes, recording that the cause was still unknown and no COLDCARD RNG flaw was yet evidenced.\n",
      "relation": {
        "kind": "single-post",
        "head_id": null
      },
      "capture": {
        "status": "held",
        "artefact_count": 5,
        "conversation_copies": 0,
        "conversation_posts": 0,
        "conversation_replies": 0,
        "conversation_gaps": []
      }
    },
    {
      "id": "vandelaybtc-2082920858234843368",
      "title": "Vandelaybtc 2082920858234843368",
      "url": "https://x.com/VandelayBTC/status/2082920858234843368",
      "author": "VandelayBTC",
      "platform": "x",
      "organisation": null,
      "posted": "2026-07-30T20:06:46Z",
      "role": "social-statement",
      "why_registered": "Early reply speculation that the reported victim's Sparrow Wallet use could implicate the fake Sparrow apps then listed on the Apple store.\n",
      "relation": {
        "kind": "single-post",
        "head_id": null
      },
      "capture": {
        "status": "held",
        "artefact_count": 5,
        "conversation_copies": 0,
        "conversation_posts": 0,
        "conversation_replies": 0,
        "conversation_gaps": []
      }
    },
    {
      "id": "nvk-2082922407229091964",
      "title": "NVK 2082922407229091964",
      "url": "https://x.com/nvk/status/2082922407229091964",
      "author": "nvk",
      "platform": "x",
      "organisation": null,
      "posted": "2026-07-30T20:12:55Z",
      "role": "social-statement",
      "why_registered": "nvk states COLDCARD uses RFC 6979 deterministic nonces, countering early speculation that the sweeps came from a nonce-reuse flaw.\n",
      "relation": {
        "kind": "single-post",
        "head_id": null
      },
      "capture": {
        "status": "held",
        "artefact_count": 2,
        "conversation_copies": 0,
        "conversation_posts": 0,
        "conversation_replies": 0,
        "conversation_gaps": []
      }
    },
    {
      "id": "rob1ham-2082926552598147101",
      "title": "Rob1ham 2082926552598147101",
      "url": "https://x.com/Rob1Ham/status/2082926552598147101",
      "author": "Rob1Ham",
      "platform": "x",
      "organisation": null,
      "posted": "2026-07-30T20:29:23Z",
      "role": "social-statement",
      "why_registered": "Rob Hamilton's early observation that only about 5 percent of the swept funds had a previously exposed public key, countering quantum-attack speculation.\n",
      "relation": {
        "kind": "single-post",
        "head_id": null
      },
      "capture": {
        "status": "held",
        "artefact_count": 2,
        "conversation_copies": 0,
        "conversation_posts": 0,
        "conversation_replies": 0,
        "conversation_gaps": []
      }
    },
    {
      "id": "theinstagibbs-2082960055846998223",
      "title": "Theinstagibbs 2082960055846998223",
      "url": "https://x.com/theinstagibbs/status/2082960055846998223",
      "author": "theinstagibbs",
      "platform": "x",
      "organisation": null,
      "posted": "2026-07-30T22:42:31Z",
      "role": "social-statement",
      "why_registered": "instagibbs' plain statement that Mk2 and Mk3 keys on certain firmware versions are trivially stealable, adding that he made no attempt to rescue funds.\n",
      "relation": {
        "kind": "single-post",
        "head_id": null
      },
      "capture": {
        "status": "held",
        "artefact_count": 2,
        "conversation_copies": 0,
        "conversation_posts": 0,
        "conversation_replies": 0,
        "conversation_gaps": []
      }
    },
    {
      "id": "coldcardwallet-2082961993070247948",
      "title": "Coldcardwallet 2082961993070247948",
      "url": "https://x.com/COLDCARDwallet/status/2082961993070247948",
      "author": "COLDCARDwallet",
      "platform": "x",
      "organisation": null,
      "posted": "2026-07-30T22:50:13Z",
      "role": "social-statement",
      "why_registered": "Coinkite's initial advisory post: seeds generated on a Mk3 after firmware 4.0.1 may be at risk, with Mk4, Q and Mk5 stated as not affected based on early analysis.\n",
      "relation": {
        "kind": "single-post",
        "head_id": null
      },
      "capture": {
        "status": "held",
        "artefact_count": 2,
        "conversation_copies": 0,
        "conversation_posts": 0,
        "conversation_replies": 0,
        "conversation_gaps": []
      }
    },
    {
      "id": "otaliptus-2082968745710858461",
      "title": "otaliptus 2082968745710858461",
      "url": "https://x.com/otaliptus/status/2082968745710858461",
      "author": "otaliptus",
      "platform": "x",
      "organisation": null,
      "posted": "2026-07-30T23:17:03Z",
      "role": "social-statement",
      "why_registered": "otaliptus' first-hand account of the discovery: an AI model identified the bug after two prompts, the scope was confirmed with industry contacts within an hour, and affected parties were notified.\n",
      "relation": {
        "kind": "single-post",
        "head_id": null
      },
      "capture": {
        "status": "held",
        "artefact_count": 2,
        "conversation_copies": 0,
        "conversation_posts": 0,
        "conversation_replies": 0,
        "conversation_gaps": []
      }
    },
    {
      "id": "praveenperera-2082972475915157907",
      "title": "Praveenperera 2082972475915157907",
      "url": "https://x.com/PraveenPerera/status/2082972475915157907",
      "author": "PraveenPerera",
      "platform": "x",
      "organisation": null,
      "posted": "2026-07-30T23:31:52Z",
      "role": "social-statement",
      "why_registered": "Praveen Perera's independent confirmation that he could regenerate the private keys of one of the stolen addresses.\n",
      "relation": {
        "kind": "single-post",
        "head_id": null
      },
      "capture": {
        "status": "held",
        "artefact_count": 2,
        "conversation_copies": 0,
        "conversation_posts": 0,
        "conversation_replies": 0,
        "conversation_gaps": []
      }
    },
    {
      "id": "nneuman-2082977839654093290",
      "title": "Nneuman 2082977839654093290",
      "url": "https://x.com/Nneuman/status/2082977839654093290",
      "author": "Nneuman",
      "platform": "x",
      "organisation": null,
      "posted": "2026-07-30T23:53:11Z",
      "role": "social-statement",
      "why_registered": "Nick Neuman's early warning that Mk4, Q and Mk5 appeared vulnerable in a different way than Mk3, advising single-sig COLDCARD users to move funds elsewhere.\n",
      "relation": {
        "kind": "single-post",
        "head_id": null
      },
      "capture": {
        "status": "held",
        "artefact_count": 2,
        "conversation_copies": 0,
        "conversation_posts": 0,
        "conversation_replies": 0,
        "conversation_gaps": []
      }
    },
    {
      "id": "clay_garrett-2082980440525132245",
      "title": "Clay_garrett 2082980440525132245",
      "url": "https://x.com/clay_garrett/status/2082980440525132245",
      "author": "clay_garrett",
      "platform": "x",
      "organisation": null,
      "posted": "2026-07-31T00:03:31Z",
      "role": "social-statement",
      "why_registered": "Second post of Block's preliminary accounting thread: 695 earlier transactions sharing the known set's fingerprint moved another 488.10957948 BTC, which would bring the total to 1,082.58680432 BTC if confirmed.\n",
      "relation": {
        "kind": "single-post",
        "head_id": null
      },
      "capture": {
        "status": "held",
        "artefact_count": 2,
        "conversation_copies": 0,
        "conversation_posts": 0,
        "conversation_replies": 0,
        "conversation_gaps": []
      }
    },
    {
      "id": "zherbert-2082993276324319713",
      "title": "Zherbert 2082993276324319713",
      "url": "https://x.com/zherbert/status/2082993276324319713",
      "author": "zherbert",
      "platform": "x",
      "organisation": null,
      "posted": "2026-07-31T00:54:31Z",
      "role": "social-statement",
      "why_registered": "Foundation CEO Zach Herbert's timeline arguing Coinkite's 2020 to 2021 relicense is where the entropy bug entered; a competitor's account, held as reported.\n",
      "relation": {
        "kind": "single-post",
        "head_id": null
      },
      "capture": {
        "status": "held",
        "artefact_count": 2,
        "conversation_copies": 0,
        "conversation_posts": 0,
        "conversation_replies": 0,
        "conversation_gaps": []
      }
    },
    {
      "id": "max_guise-2083007814713373075",
      "title": "Max_guise 2083007814713373075",
      "url": "https://x.com/max_guise/status/2083007814713373075",
      "author": "max_guise",
      "platform": "x",
      "organisation": null,
      "posted": "2026-07-31T01:52:18Z",
      "role": "social-statement",
      "why_registered": "Fourth post of Block's disclosure thread: two vulnerabilities were found affecting COLDCARD Mk2, Mk3, Mk4, Q and Mk5 at varying levels, with detail in the linked document.\n",
      "relation": {
        "kind": "single-post",
        "head_id": null
      },
      "capture": {
        "status": "held",
        "artefact_count": 2,
        "conversation_copies": 0,
        "conversation_posts": 0,
        "conversation_replies": 0,
        "conversation_gaps": []
      }
    },
    {
      "id": "sethforprivacy-2083042831820616090",
      "title": "Sethforprivacy 2083042831820616090",
      "url": "https://x.com/sethforprivacy/status/2083042831820616090",
      "author": "sethforprivacy",
      "platform": "x",
      "organisation": null,
      "posted": "2026-07-31T04:11:26Z",
      "role": "social-statement",
      "why_registered": "Seth for Privacy says his teams had run internal AI-driven audits for months, comments that the sweep approach looked unsophisticated, and reports no critical bugs found in Cake Wallet or Cupcake.\n",
      "relation": {
        "kind": "single-post",
        "head_id": null
      },
      "capture": {
        "status": "held",
        "artefact_count": 2,
        "conversation_copies": 0,
        "conversation_posts": 0,
        "conversation_replies": 0,
        "conversation_gaps": []
      }
    },
    {
      "id": "lukedashjr-2083063324334248075",
      "title": "Lukedashjr 2083063324334248075",
      "url": "https://x.com/LukeDashjr/status/2083063324334248075",
      "author": "LukeDashjr",
      "platform": "x",
      "organisation": null,
      "posted": "2026-07-31T05:32:52Z",
      "role": "social-statement",
      "why_registered": "Luke Dashjr cautions that common dice are not cryptographically secure and recommends precision casino dice plus another entropy source for anyone mitigating with dice rolls.\n",
      "relation": {
        "kind": "single-post",
        "head_id": null
      },
      "capture": {
        "status": "held",
        "artefact_count": 2,
        "conversation_copies": 0,
        "conversation_posts": 0,
        "conversation_replies": 0,
        "conversation_gaps": []
      }
    },
    {
      "id": "kloaec-2083133361799778719",
      "title": "KLoaec 2083133361799778719",
      "url": "https://x.com/KLoaec/status/2083133361799778719",
      "author": "KLoaec",
      "platform": "x",
      "organisation": null,
      "posted": "2026-07-31T10:11:10Z",
      "role": "social-statement",
      "why_registered": "Kevin Loaec's summary ahead of his blog post: the scope is worse than thought, Mk4, Mk5 and Q will be drained, and multisig or miniscript setups where COLDCARD signatures reach threshold are at risk.\n",
      "relation": {
        "kind": "single-post",
        "head_id": null
      },
      "capture": {
        "status": "held",
        "artefact_count": 2,
        "conversation_copies": 0,
        "conversation_posts": 0,
        "conversation_replies": 0,
        "conversation_gaps": []
      }
    },
    {
      "id": "itscoachgoodman-2083244485400580349",
      "title": "Itscoachgoodman 2083244485400580349",
      "url": "https://x.com/itscoachgoodman/status/2083244485400580349",
      "author": "itscoachgoodman",
      "platform": "x",
      "organisation": null,
      "posted": "2026-07-31T17:32:44Z",
      "role": "social-statement",
      "why_registered": "Jonathan Goodman's first-hand report of losing $1.6 million in bitcoin in the 29 July drains; one of the largest named individual losses.\n",
      "relation": {
        "kind": "single-post",
        "head_id": null
      },
      "capture": {
        "status": "held",
        "artefact_count": 2,
        "conversation_copies": 0,
        "conversation_posts": 0,
        "conversation_replies": 0,
        "conversation_gaps": []
      }
    },
    {
      "id": "zherbert-2083261221726220638",
      "title": "Zherbert 2083261221726220638",
      "url": "https://x.com/zherbert/status/2083261221726220638",
      "author": "zherbert",
      "platform": "x",
      "organisation": null,
      "posted": "2026-07-31T18:39:15Z",
      "role": "social-statement",
      "why_registered": "Zach Herbert advises victims to keep their devices, since the processor's hardware ID may be needed to prove seed ownership if law enforcement recovers the coins.\n",
      "relation": {
        "kind": "single-post",
        "head_id": null
      },
      "capture": {
        "status": "held",
        "artefact_count": 2,
        "conversation_copies": 0,
        "conversation_posts": 0,
        "conversation_replies": 0,
        "conversation_gaps": []
      }
    },
    {
      "id": "bradytc_-2083331338522820667",
      "title": "Bradytc_ 2083331338522820667",
      "url": "https://x.com/bradytc_/status/2083331338522820667",
      "author": "bradytc_",
      "platform": "x",
      "organisation": null,
      "posted": "2026-07-31T23:17:52Z",
      "role": "social-statement",
      "why_registered": "Launch post for the coldcard-watch.vercel.app live dashboard of drained BTC, the community chain monitor later registered here as coldcard-watch.\n",
      "relation": {
        "kind": "single-post",
        "head_id": null
      },
      "capture": {
        "status": "held",
        "artefact_count": 2,
        "conversation_copies": 0,
        "conversation_posts": 0,
        "conversation_replies": 0,
        "conversation_gaps": []
      }
    },
    {
      "id": "janrothen-2083388740496478361",
      "title": "Janrothen 2083388740496478361",
      "url": "https://x.com/janrothen/status/2083388740496478361",
      "author": "janrothen",
      "platform": "x",
      "organisation": null,
      "posted": "2026-08-01T03:05:57Z",
      "role": "social-statement",
      "why_registered": "Jan Rothen's engineering critique that seed generation silently fell back to a non-cryptographic RNG for five years instead of failing closed, which he calls disqualifying for a security vendor.\n",
      "relation": {
        "kind": "single-post",
        "head_id": null
      },
      "capture": {
        "status": "held",
        "artefact_count": 2,
        "conversation_copies": 0,
        "conversation_posts": 0,
        "conversation_replies": 0,
        "conversation_gaps": []
      }
    },
    {
      "id": "jasonsvoboda-2083425979800973518",
      "title": "Jasonsvoboda 2083425979800973518",
      "url": "https://x.com/jasonsvoboda/status/2083425979800973518",
      "author": "jasonsvoboda",
      "platform": "x",
      "organisation": null,
      "posted": "2026-08-01T05:33:56Z",
      "role": "social-statement",
      "why_registered": "Jason Svoboda posts material generated with an AI tool; the substance sits in the two attached images held by the capture rather than in the text.\n",
      "relation": {
        "kind": "single-post",
        "head_id": null
      },
      "capture": {
        "status": "held",
        "artefact_count": 7,
        "conversation_copies": 0,
        "conversation_posts": 0,
        "conversation_replies": 0,
        "conversation_gaps": []
      }
    },
    {
      "id": "1440000bytes-2083507377643606068",
      "title": "1440000bytes 2083507377643606068",
      "url": "https://x.com/1440000bytes/status/2083507377643606068",
      "author": "1440000bytes",
      "platform": "x",
      "organisation": null,
      "posted": "2026-08-01T10:57:23Z",
      "role": "social-statement",
      "why_registered": "floppy.md reports having disclosed a critical vulnerability in Bitkey by email; part of the wider wallet-audit wave that followed the COLDCARD disclosure.\n",
      "relation": {
        "kind": "single-post",
        "head_id": null
      },
      "capture": {
        "status": "held",
        "artefact_count": 2,
        "conversation_copies": 0,
        "conversation_posts": 0,
        "conversation_replies": 0,
        "conversation_gaps": []
      }
    },
    {
      "id": "tomerstrolight-2083525927309320202",
      "title": "Tomerstrolight 2083525927309320202",
      "url": "https://x.com/TomerStrolight/status/2083525927309320202",
      "author": "TomerStrolight",
      "platform": "x",
      "organisation": null,
      "posted": "2026-08-01T12:11:05Z",
      "role": "social-statement",
      "why_registered": "Tomer Strolight reports that a small balance on an Mk4 RNG seed was swept overnight and warns that any COLDCARD RNG-generated seed is under active attack.\n",
      "relation": {
        "kind": "single-post",
        "head_id": null
      },
      "capture": {
        "status": "held",
        "artefact_count": 2,
        "conversation_copies": 0,
        "conversation_posts": 0,
        "conversation_replies": 0,
        "conversation_gaps": []
      }
    },
    {
      "id": "w_s_bitcoin-2083539953892364400",
      "title": "W_s_bitcoin 2083539953892364400",
      "url": "https://x.com/w_s_bitcoin/status/2083539953892364400",
      "author": "w_s_bitcoin",
      "platform": "x",
      "organisation": null,
      "posted": "2026-08-01T13:06:49Z",
      "role": "social-statement",
      "why_registered": "Wicked says AI tools are finding critical vulnerabilities across wallets and explains personally keeping funds in a multivendor multisig that still includes a COLDCARD, citing dice-rolled seeds and passphrases as protection.\n",
      "relation": {
        "kind": "single-post",
        "head_id": null
      },
      "capture": {
        "status": "held",
        "artefact_count": 2,
        "conversation_copies": 0,
        "conversation_posts": 0,
        "conversation_replies": 0,
        "conversation_gaps": []
      }
    },
    {
      "id": "milessuter-2083542842253656250",
      "title": "Milessuter 2083542842253656250",
      "url": "https://x.com/milessuter/status/2083542842253656250",
      "author": "milessuter",
      "platform": "x",
      "organisation": null,
      "posted": "2026-08-01T13:18:18Z",
      "role": "social-statement",
      "why_registered": "Block's Miles Suter acknowledges the Bitkey report, commits to verify, patch and publicly disclose, and gives an initial read limited to Inheritance flows requiring Block compromise or intercepted traffic.\n",
      "relation": {
        "kind": "single-post",
        "head_id": null
      },
      "capture": {
        "status": "held",
        "artefact_count": 2,
        "conversation_copies": 0,
        "conversation_posts": 0,
        "conversation_replies": 0,
        "conversation_gaps": []
      }
    },
    {
      "id": "tomerstrolight-2083578868191957292",
      "title": "Tomerstrolight 2083578868191957292",
      "url": "https://x.com/TomerStrolight/status/2083578868191957292",
      "author": "TomerStrolight",
      "platform": "x",
      "organisation": null,
      "posted": "2026-08-01T15:41:27Z",
      "role": "social-statement",
      "why_registered": "Strolight's correction: the swept key was created on an Mk3 and migrated to an Mk4, so that case does not confirm Mk4 entropy is breached.\n",
      "relation": {
        "kind": "single-post",
        "head_id": null
      },
      "capture": {
        "status": "held",
        "artefact_count": 2,
        "conversation_copies": 0,
        "conversation_posts": 0,
        "conversation_replies": 0,
        "conversation_gaps": []
      }
    },
    {
      "id": "bitcoinnewscom-2083593408182911073",
      "title": "Bitcoinnewscom 2083593408182911073",
      "url": "https://x.com/BitcoinNewsCom/status/2083593408182911073",
      "author": "BitcoinNewsCom",
      "platform": "x",
      "organisation": null,
      "posted": "2026-08-01T16:39:14Z",
      "role": "social-statement",
      "why_registered": "Bitcoin News lists COLDCARD features still exposed by the Yasmarang flaw even with a safe seed: paper wallets, device cloning, USB sessions, Secret Teleport, co-signing keys, password generator and HSM mode.\n",
      "relation": {
        "kind": "single-post",
        "head_id": null
      },
      "capture": {
        "status": "held",
        "artefact_count": 2,
        "conversation_copies": 0,
        "conversation_posts": 0,
        "conversation_replies": 0,
        "conversation_gaps": []
      }
    },
    {
      "id": "bluewalletio-2083597423050461312",
      "title": "Bluewalletio 2083597423050461312",
      "url": "https://x.com/bluewalletio/status/2083597423050461312",
      "author": "bluewalletio",
      "platform": "x",
      "organisation": null,
      "posted": "2026-08-01T16:55:11Z",
      "role": "social-statement",
      "why_registered": "BlueWallet's entropy explainer: wallets use the device's cryptographically secure system RNG, users can add dice or coin-flip entropy, and shortfalls are topped up from the system RNG.\n",
      "relation": {
        "kind": "single-post",
        "head_id": null
      },
      "capture": {
        "status": "held",
        "artefact_count": 5,
        "conversation_copies": 0,
        "conversation_posts": 0,
        "conversation_replies": 0,
        "conversation_gaps": []
      }
    },
    {
      "id": "northernh0dl-2083633778572787862",
      "title": "Northernh0dl 2083633778572787862",
      "url": "https://x.com/northernH0DL/status/2083633778572787862",
      "author": "northernH0DL",
      "platform": "x",
      "organisation": null,
      "posted": "2026-08-01T19:19:39Z",
      "role": "social-statement",
      "why_registered": "First-hand report of a COLDCARD left on an RNG error screen and unusable after the hotfix firmware release, advising others not to update.\n",
      "relation": {
        "kind": "single-post",
        "head_id": null
      },
      "capture": {
        "status": "held",
        "artefact_count": 5,
        "conversation_copies": 0,
        "conversation_posts": 0,
        "conversation_replies": 0,
        "conversation_gaps": []
      }
    },
    {
      "id": "bitcoinmagazine-2083634238104940884",
      "title": "Bitcoinmagazine 2083634238104940884",
      "url": "https://x.com/BitcoinMagazine/status/2083634238104940884",
      "author": "BitcoinMagazine",
      "platform": "x",
      "organisation": null,
      "posted": "2026-08-01T19:21:29Z",
      "role": "social-statement",
      "why_registered": "Bitcoin Magazine reports a third wave of thefts of 207.7294 BTC, putting the running figure at 1,367.05 BTC from 4,585 addresses according to Galaxy Research.\n",
      "relation": {
        "kind": "single-post",
        "head_id": null
      },
      "capture": {
        "status": "held",
        "artefact_count": 5,
        "conversation_copies": 0,
        "conversation_posts": 0,
        "conversation_replies": 0,
        "conversation_gaps": []
      }
    },
    {
      "id": "bitcoinnewscom-2083715303087673392",
      "title": "Bitcoinnewscom 2083715303087673392",
      "url": "https://x.com/BitcoinNewsCom/status/2083715303087673392",
      "author": "BitcoinNewsCom",
      "platform": "x",
      "organisation": null,
      "posted": "2026-08-02T00:43:36Z",
      "role": "social-statement",
      "why_registered": "Bitcoin News reports ddustin's analysis that a compiler conflict led a developer to disable the hardware RNG by setting MICROPY_HW_ENABLE_RNG to 0, silently falling back to the Yasmarang software RNG.\n",
      "relation": {
        "kind": "single-post",
        "head_id": null
      },
      "capture": {
        "status": "held",
        "artefact_count": 5,
        "conversation_copies": 0,
        "conversation_posts": 0,
        "conversation_replies": 0,
        "conversation_gaps": []
      }
    },
    {
      "id": "jjcmoreno-2083768184176324737",
      "title": "Jjcmoreno 2083768184176324737",
      "url": "https://x.com/jjcmoreno/status/2083768184176324737",
      "author": "jjcmoreno",
      "platform": "x",
      "organisation": null,
      "posted": "2026-08-02T04:13:44Z",
      "role": "social-statement",
      "why_registered": "Julio Moreno's observation that sub-1 BTC transfers on 31 July were the largest since the FTX collapse, suggesting holders moved funds en masse after the disclosure.\n",
      "relation": {
        "kind": "single-post",
        "head_id": null
      },
      "capture": {
        "status": "held",
        "artefact_count": 5,
        "conversation_copies": 0,
        "conversation_posts": 0,
        "conversation_replies": 0,
        "conversation_gaps": []
      }
    },
    {
      "id": "intangiblecoins-2083883830499303933",
      "title": "Intangiblecoins 2083883830499303933",
      "url": "https://x.com/intangiblecoins/status/2083883830499303933",
      "author": "intangiblecoins",
      "platform": "x",
      "organisation": null,
      "posted": "2026-08-02T11:53:16Z",
      "role": "social-statement",
      "why_registered": "Alex Thorn reports a nearly 30 BTC victim had 17 BTC peeled through THORChain into a casino, which identified the depositor after the funds had left, and warns smaller copycat operators are attacking remaining seeds.\n",
      "relation": {
        "kind": "single-post",
        "head_id": null
      },
      "capture": {
        "status": "held",
        "artefact_count": 2,
        "conversation_copies": 0,
        "conversation_posts": 0,
        "conversation_replies": 0,
        "conversation_gaps": []
      }
    },
    {
      "id": "hodlonaut-2083885515229573203",
      "title": "Hodlonaut 2083885515229573203",
      "url": "https://x.com/hodlonaut/status/2083885515229573203",
      "author": "hodlonaut",
      "platform": "x",
      "organisation": null,
      "posted": "2026-08-02T11:59:58Z",
      "role": "social-statement",
      "why_registered": "hodlonaut notes the commits that introduced the low-entropy bug changed around 2,500 lines of the most security-critical code, with commit messages reading 'runs' and 'x'.\n",
      "relation": {
        "kind": "single-post",
        "head_id": null
      },
      "capture": {
        "status": "held",
        "artefact_count": 5,
        "conversation_copies": 0,
        "conversation_posts": 0,
        "conversation_replies": 0,
        "conversation_gaps": []
      }
    },
    {
      "id": "grok-2083899371330916755",
      "title": "Grok 2083899371330916755",
      "url": "https://x.com/grok/status/2083899371330916755",
      "author": "grok",
      "platform": "x",
      "organisation": null,
      "posted": "2026-08-02T12:55:01Z",
      "role": "social-statement",
      "why_registered": "Grok's generated answer attributing the 'runs' commit and libNgU integration to Coinkite CTO Peter D. Gray; held as a record of what the chatbot answered, not as verified attribution.\n",
      "relation": {
        "kind": "single-post",
        "head_id": null
      },
      "capture": {
        "status": "held",
        "artefact_count": 2,
        "conversation_copies": 0,
        "conversation_posts": 0,
        "conversation_replies": 0,
        "conversation_gaps": []
      }
    },
    {
      "id": "kuptokosmos-2083916236002336780",
      "title": "Kuptokosmos 2083916236002336780",
      "url": "https://x.com/KuptoKosmos/status/2083916236002336780",
      "author": "KuptoKosmos",
      "platform": "x",
      "organisation": null,
      "posted": "2026-08-02T14:02:02Z",
      "role": "social-statement",
      "why_registered": "Kruptos' illustrated thread tying the bug's introduction to Coinkite's March 2021 relicense commit, describing the hardware RNG bypass and the drop to roughly 40 bits of entropy on Mk3.\n",
      "relation": {
        "kind": "single-post",
        "head_id": null
      },
      "capture": {
        "status": "held",
        "artefact_count": 5,
        "conversation_copies": 0,
        "conversation_posts": 0,
        "conversation_replies": 0,
        "conversation_gaps": []
      }
    },
    {
      "id": "stevesimple-2083971557861269828",
      "title": "Stevesimple 2083971557861269828",
      "url": "https://x.com/SteveSimple/status/2083971557861269828",
      "author": "SteveSimple",
      "platform": "x",
      "organisation": null,
      "posted": "2026-08-02T17:41:52Z",
      "role": "social-statement",
      "why_registered": "Steve Simple links a 2021 article he describes as a blueprint matching the incident; registered as an example of the speculation in circulation, not endorsed.\n",
      "relation": {
        "kind": "single-post",
        "head_id": null
      },
      "capture": {
        "status": "held",
        "artefact_count": 5,
        "conversation_copies": 0,
        "conversation_posts": 0,
        "conversation_replies": 0,
        "conversation_gaps": []
      }
    },
    {
      "id": "btcsessions-2084036568990294527",
      "title": "Btcsessions 2084036568990294527",
      "url": "https://x.com/BTCsessions/status/2084036568990294527",
      "author": "BTCsessions",
      "platform": "x",
      "organisation": null,
      "posted": "2026-08-02T22:00:12Z",
      "role": "social-statement",
      "why_registered": "BTC Sessions adds that the drained Mk3 wallet's passphrase was two ordinary words, warning that attackers had moved from low-entropy seeds to also brute-forcing weak passphrases.\n",
      "relation": {
        "kind": "single-post",
        "head_id": null
      },
      "capture": {
        "status": "held",
        "artefact_count": 2,
        "conversation_copies": 0,
        "conversation_posts": 0,
        "conversation_replies": 0,
        "conversation_gaps": []
      }
    },
    {
      "id": "willywoo-2084113176681968063",
      "title": "Willywoo 2084113176681968063",
      "url": "https://x.com/willywoo/status/2084113176681968063",
      "author": "willywoo",
      "platform": "x",
      "organisation": null,
      "posted": "2026-08-03T03:04:36Z",
      "role": "social-statement",
      "why_registered": "Willy Woo's estimate of a 20 to 40 percent chance of partial recovery by authorities over a multi-year timeframe, pointing victims to Samson's recovery notes.\n",
      "relation": {
        "kind": "single-post",
        "head_id": null
      },
      "capture": {
        "status": "held",
        "artefact_count": 2,
        "conversation_copies": 0,
        "conversation_posts": 0,
        "conversation_replies": 0,
        "conversation_gaps": []
      }
    },
    {
      "id": "rob1ham-2084140242915782743",
      "title": "Rob1ham 2084140242915782743",
      "url": "https://x.com/Rob1Ham/status/2084140242915782743",
      "author": "Rob1Ham",
      "platform": "x",
      "organisation": null,
      "posted": "2026-08-03T04:52:10Z",
      "role": "social-statement",
      "why_registered": "Rob Hamilton reports spending over $10,000 scanning more than 100 Bitcoin ecosystem libraries with Kimi K3, says his team found multiple serious vulnerabilities, and calls for repositories to scan.\n",
      "relation": {
        "kind": "single-post",
        "head_id": null
      },
      "capture": {
        "status": "held",
        "artefact_count": 2,
        "conversation_copies": 0,
        "conversation_posts": 0,
        "conversation_replies": 0,
        "conversation_gaps": []
      }
    },
    {
      "id": "hodlonaut-2084217381165940812",
      "title": "Hodlonaut 2084217381165940812",
      "url": "https://x.com/hodlonaut/status/2084217381165940812",
      "author": "hodlonaut",
      "platform": "x",
      "organisation": null,
      "posted": "2026-08-03T09:58:41Z",
      "role": "social-statement",
      "why_registered": "hodlonaut speculates that a COLDCARD firmware job vacancy posted three weeks before the attack could be connected, noting the bug would likely have been found once the role was filled.\n",
      "relation": {
        "kind": "single-post",
        "head_id": null
      },
      "capture": {
        "status": "held",
        "artefact_count": 7,
        "conversation_copies": 0,
        "conversation_posts": 0,
        "conversation_replies": 0,
        "conversation_gaps": []
      }
    },
    {
      "id": "bitcoinnewscom-2084264904370847761",
      "title": "Bitcoinnewscom 2084264904370847761",
      "url": "https://x.com/BitcoinNewsCom/status/2084264904370847761",
      "author": "BitcoinNewsCom",
      "platform": "x",
      "organisation": null,
      "posted": "2026-08-03T13:07:31Z",
      "role": "social-statement",
      "why_registered": "Bitcoin News reports a bug in the emergency hotfix that can leave a device stuck on a fatal error screen before the PIN prompt, blocking access to the upgrade menu.\n",
      "relation": {
        "kind": "single-post",
        "head_id": null
      },
      "capture": {
        "status": "held",
        "artefact_count": 5,
        "conversation_copies": 0,
        "conversation_posts": 0,
        "conversation_replies": 0,
        "conversation_gaps": []
      }
    },
    {
      "id": "the_smart_ape-2084265598368809390",
      "title": "The_smart_ape 2084265598368809390",
      "url": "https://x.com/the_smart_ape/status/2084265598368809390",
      "author": "the_smart_ape",
      "platform": "x",
      "organisation": null,
      "posted": "2026-08-03T13:10:17Z",
      "role": "social-statement",
      "why_registered": "A wallet-by-wallet comparison of seed randomness across Trezor, BitBox, Foundation and Keystone, prompted by the COLDCARD entropy failure.\n",
      "relation": {
        "kind": "single-post",
        "head_id": null
      },
      "capture": {
        "status": "held",
        "artefact_count": 5,
        "conversation_copies": 0,
        "conversation_posts": 0,
        "conversation_replies": 0,
        "conversation_gaps": []
      }
    },
    {
      "id": "narcelio-2084303965202657304",
      "title": "Narcelio 2084303965202657304",
      "url": "https://x.com/narcelio/status/2084303965202657304",
      "author": "narcelio",
      "platform": "x",
      "organisation": null,
      "posted": "2026-08-03T15:42:44Z",
      "role": "social-statement",
      "why_registered": "Portuguese-language reply arguing that proving ownership may technically be possible because the seed was generated from the COLDCARD's device ID; a reported claim in the reimbursement debate.\n",
      "relation": {
        "kind": "single-post",
        "head_id": null
      },
      "capture": {
        "status": "held",
        "artefact_count": 2,
        "conversation_copies": 0,
        "conversation_posts": 0,
        "conversation_replies": 0,
        "conversation_gaps": []
      }
    },
    {
      "id": "zeusln-2084316041673347138",
      "title": "Zeusln 2084316041673347138",
      "url": "https://x.com/ZeusLN/status/2084316041673347138",
      "author": "ZeusLN",
      "platform": "x",
      "organisation": null,
      "posted": "2026-08-03T16:30:43Z",
      "role": "social-statement",
      "why_registered": "ZEUS announces its swaps.zeuslsp.com instance is following suit as Lightning swap services suspend operations during the incident fallout, with updates promised.\n",
      "relation": {
        "kind": "single-post",
        "head_id": null
      },
      "capture": {
        "status": "held",
        "artefact_count": 2,
        "conversation_copies": 0,
        "conversation_posts": 0,
        "conversation_replies": 0,
        "conversation_gaps": []
      }
    },
    {
      "id": "tftc21-2084342383274283023",
      "title": "Tftc21 2084342383274283023",
      "url": "https://x.com/TFTC21/status/2084342383274283023",
      "author": "TFTC21",
      "platform": "x",
      "organisation": null,
      "posted": "2026-08-03T18:15:24Z",
      "role": "social-statement",
      "why_registered": "TFTC shares the Bitcoin Policy Institute's visual explainer of the entropy loss: a proper key is one atom across two billion galaxies, an affected COLDCARD key crackable in hours.\n",
      "relation": {
        "kind": "single-post",
        "head_id": null
      },
      "capture": {
        "status": "held",
        "artefact_count": 5,
        "conversation_copies": 0,
        "conversation_posts": 0,
        "conversation_replies": 0,
        "conversation_gaps": []
      }
    },
    {
      "id": "alexbosworth-2084379577095446624",
      "title": "Alexbosworth 2084379577095446624",
      "url": "https://x.com/alexbosworth/status/2084379577095446624",
      "author": "alexbosworth",
      "platform": "x",
      "organisation": null,
      "posted": "2026-08-03T20:43:11Z",
      "role": "social-statement",
      "why_registered": "Lightning Loop's Alex Bosworth reports elevated submarine swap traffic and possibly higher network fees during the incident period, noting liquidity adjusts as a market process.\n",
      "relation": {
        "kind": "single-post",
        "head_id": null
      },
      "capture": {
        "status": "held",
        "artefact_count": 2,
        "conversation_copies": 0,
        "conversation_posts": 0,
        "conversation_replies": 0,
        "conversation_gaps": []
      }
    },
    {
      "id": "boomer_btc-2084424317505249557",
      "title": "Boomer_btc 2084424317505249557",
      "url": "https://x.com/boomer_btc/status/2084424317505249557",
      "author": "boomer_btc",
      "platform": "x",
      "organisation": null,
      "posted": "2026-08-03T23:40:58Z",
      "role": "social-statement",
      "why_registered": "Bob Burnett's first analysis of the attack, sketching how the thief could launder the coins through a black-market miner by overpaying fees that return as clean coinbase payouts.\n",
      "relation": {
        "kind": "single-post",
        "head_id": null
      },
      "capture": {
        "status": "held",
        "artefact_count": 2,
        "conversation_copies": 0,
        "conversation_posts": 0,
        "conversation_replies": 0,
        "conversation_gaps": []
      }
    },
    {
      "id": "premai_io-2084552134444662986",
      "title": "Premai_io 2084552134444662986",
      "url": "https://x.com/premai_io/status/2084552134444662986",
      "author": "premai_io",
      "platform": "x",
      "organisation": null,
      "posted": "2026-08-04T08:08:52Z",
      "role": "social-statement",
      "why_registered": "Prem announces its prem-router gateway and sponsored Kimi-K3 credits for Bitcoin researchers and security teams, citing overwhelming demand during the incident.\n",
      "relation": {
        "kind": "single-post",
        "head_id": null
      },
      "capture": {
        "status": "held",
        "artefact_count": 5,
        "conversation_copies": 0,
        "conversation_posts": 0,
        "conversation_replies": 0,
        "conversation_gaps": []
      }
    },
    {
      "id": "chucksrq-2084628592760164385",
      "title": "Chucksrq 2084628592760164385",
      "url": "https://x.com/ChuckSRQ/status/2084628592760164385",
      "author": "ChuckSRQ",
      "platform": "x",
      "organisation": null,
      "posted": "2026-08-04T13:12:41Z",
      "role": "social-statement",
      "why_registered": "ChuckSRQ's catalog of pre-July 2026 drain reports, with the caveat that they are not all this bug: one predates the vulnerable firmware, several involved low dice entropy, and one Mk4 theft is verified on-chain.\n",
      "relation": {
        "kind": "single-post",
        "head_id": null
      },
      "capture": {
        "status": "held",
        "artefact_count": 5,
        "conversation_copies": 0,
        "conversation_posts": 0,
        "conversation_replies": 0,
        "conversation_gaps": []
      }
    },
    {
      "id": "coldcardwallet-2084632863756955661",
      "title": "Coldcardwallet 2084632863756955661",
      "url": "https://x.com/COLDCARDwallet/status/2084632863756955661",
      "author": "COLDCARDwallet",
      "platform": "x",
      "organisation": null,
      "posted": "2026-08-04T13:29:39Z",
      "role": "social-statement",
      "why_registered": "Coinkite's response to the bricking reports: the TRNG fault state is volatile, nothing is written to flash, and a full power-cycle recovers the device.\n",
      "relation": {
        "kind": "single-post",
        "head_id": null
      },
      "capture": {
        "status": "held",
        "artefact_count": 4,
        "conversation_copies": 0,
        "conversation_posts": 0,
        "conversation_replies": 0,
        "conversation_gaps": []
      }
    },
    {
      "id": "forefy-2084714317501600202",
      "title": "Forefy 2084714317501600202",
      "url": "https://x.com/forefy/status/2084714317501600202",
      "author": "forefy",
      "platform": "x",
      "organisation": null,
      "posted": "2026-08-04T18:53:20Z",
      "role": "social-statement",
      "why_registered": "forefy's case study of vibe coding a security training platform, arguing the expertise to direct the AI still matters; registered amid the AI-audit debate the incident started.\n",
      "relation": {
        "kind": "single-post",
        "head_id": null
      },
      "capture": {
        "status": "held",
        "artefact_count": 5,
        "conversation_copies": 0,
        "conversation_posts": 0,
        "conversation_replies": 0,
        "conversation_gaps": []
      }
    },
    {
      "id": "nvk-2082902502169510263",
      "title": "NVK 2082902502169510263",
      "url": "https://x.com/nvk/status/2082902502169510263",
      "author": "nvk",
      "platform": "x",
      "organisation": null,
      "posted": "2026-07-30T18:53:49Z",
      "role": "social-statement",
      "why_registered": "nvk's 30 July statement that Coinkite had received no support or security emails about the drains, only hearsay and Reddit posts; the vendor's position before its advisory.\n",
      "relation": {
        "kind": "single-post",
        "head_id": null
      },
      "capture": {
        "status": "held",
        "artefact_count": 2,
        "conversation_copies": 0,
        "conversation_posts": 0,
        "conversation_replies": 0,
        "conversation_gaps": []
      }
    },
    {
      "id": "notgrubles-2082910089824854209",
      "title": "Notgrubles 2082910089824854209",
      "url": "https://x.com/notgrubles/status/2082910089824854209",
      "author": "notgrubles",
      "platform": "x",
      "organisation": null,
      "posted": "2026-07-30T19:23:58Z",
      "role": "social-statement",
      "why_registered": "grubles' terse 30 July confirmation that the drain reports reflected a real issue, among the first public confirmations.\n",
      "relation": {
        "kind": "single-post",
        "head_id": null
      },
      "capture": {
        "status": "held",
        "artefact_count": 2,
        "conversation_copies": 0,
        "conversation_posts": 0,
        "conversation_replies": 0,
        "conversation_gaps": []
      }
    },
    {
      "id": "callebtc-2085101769500377193",
      "title": "Callebtc 2085101769500377193",
      "url": "https://x.com/callebtc/status/2085101769500377193",
      "author": "callebtc",
      "platform": "x",
      "organisation": null,
      "posted": "2026-08-05T20:32:55Z",
      "role": "ai-security-response",
      "why_registered": "calle directing offers of help to OpenSats, which he says paid the Bitcoin Red Team's AI bill, and describing donations there as converting into inference for bug hunting. Records the funding route for the post-incident review effort in the participant's own words. The characterisation of how donations are applied is his.\n",
      "relation": {
        "kind": "single-post",
        "head_id": null
      },
      "capture": {
        "status": "held",
        "artefact_count": 2,
        "conversation_copies": 0,
        "conversation_posts": 0,
        "conversation_replies": 0,
        "conversation_gaps": []
      }
    },
    {
      "id": "callebtc-2085024458012586286",
      "title": "Callebtc 2085024458012586286",
      "url": "https://x.com/callebtc/status/2085024458012586286",
      "author": "callebtc",
      "platform": "x",
      "organisation": null,
      "posted": "2026-08-05T15:25:43Z",
      "role": "ai-security-response",
      "why_registered": "calle's 5 Aug Bitcoin Red Team status post: 16 people, 27.5 hours in, 4,962 findings across 390 projects, 85 critical and 635 high severity. The primary source for the figures that bitcoinmag-red-team-390-repos reports, and a substantial escalation from the roughly 150 repositories in the archive's 2 Aug captures. The findings themselves are not public and are said to be held for disclosure, so none of the counts can be rechecked here.\n",
      "relation": {
        "kind": "single-post",
        "head_id": null
      },
      "capture": {
        "status": "held",
        "artefact_count": 5,
        "conversation_copies": 0,
        "conversation_posts": 0,
        "conversation_replies": 0,
        "conversation_gaps": []
      }
    },
    {
      "id": "jp_technology-2085031289141232016",
      "title": "Jp_technology 2085031289141232016",
      "url": "https://x.com/JP_Technology/status/2085031289141232016",
      "author": "JP_Technology",
      "platform": "x",
      "organisation": null,
      "posted": "2026-08-05T15:52:51Z",
      "role": "prior-warning-claim",
      "why_registered": "JP Technology relaying a March 2021 TFTC podcast clip and reading it as showing Coinkite knew of the defect for years, headed THEY'VE KNOWN FOR YEARS. Preserved as a widely circulated interpretation at the moment it spread, not as a finding. Two posts captured in the same batch dispute it directly on the identity of the 2021 bug: zherbert-2085070195702268321 and bitcoinnewscom-2085132208025567648, both saying it was the USB serial REPL flaw in unreleased firmware 4.0.0. The video itself is not captured by this tool; the sidecar records its poster frame.\n",
      "relation": {
        "kind": "single-post",
        "head_id": null
      },
      "capture": {
        "status": "held",
        "artefact_count": 5,
        "conversation_copies": 0,
        "conversation_posts": 0,
        "conversation_replies": 0,
        "conversation_gaps": []
      }
    },
    {
      "id": "rob1ham-2085108517262782467",
      "title": "Rob1ham 2085108517262782467",
      "url": "https://x.com/Rob1Ham/status/2085108517262782467",
      "author": "Rob1Ham",
      "platform": "x",
      "organisation": null,
      "posted": "2026-08-05T20:59:44Z",
      "role": "ai-security-response",
      "why_registered": "Rob Hamilton directing Red Team donations to OpenSats. Short, and kept as provenance for the funding claim alongside callebtc-2085101769500377193.\n",
      "relation": {
        "kind": "single-post",
        "head_id": null
      },
      "capture": {
        "status": "held",
        "artefact_count": 2,
        "conversation_copies": 0,
        "conversation_posts": 0,
        "conversation_replies": 0,
        "conversation_gaps": []
      }
    },
    {
      "id": "miketwenty1-2085130028094718097",
      "title": "Miketwenty1 2085130028094718097",
      "url": "https://x.com/miketwenty1/status/2085130028094718097",
      "author": "miketwenty1",
      "platform": "x",
      "organisation": null,
      "posted": "2026-08-05T22:25:13Z",
      "role": "commentary",
      "why_registered": "Michael Tidwell predicting that no purposeful foul play or intent will be found in relation to nvk or Coinkite staff, and calling it disturbing if the circulating conspiracy theories prove true. A dated counterweight to the insider allegations captured in the same batch, and a marker of how contested attribution of intent was on 5 August. A prediction, not evidence either way.\n",
      "relation": {
        "kind": "single-post",
        "head_id": null
      },
      "capture": {
        "status": "held",
        "artefact_count": 2,
        "conversation_copies": 0,
        "conversation_posts": 0,
        "conversation_replies": 0,
        "conversation_gaps": []
      }
    },
    {
      "id": "coldcardwallet-2085161476956840172",
      "title": "Coldcardwallet 2085161476956840172",
      "url": "https://x.com/COLDCARDwallet/status/2085161476956840172",
      "author": "COLDCARDwallet",
      "platform": "x",
      "organisation": null,
      "posted": "2026-08-06T00:30:11Z",
      "role": "vendor-update",
      "why_registered": "Coinkite's 6 Aug post telling owners to treat migration as urgent, follow the advisory for their model, upgrade, generate a new seed and move funds, and stating that the threat is still ongoing. A vendor statement of current risk a week into the incident, and one of the few captured sources in which Coinkite asks readers to spread the warning to people who are less online.\n",
      "relation": {
        "kind": "single-post",
        "head_id": null
      },
      "capture": {
        "status": "held",
        "artefact_count": 2,
        "conversation_copies": 0,
        "conversation_posts": 0,
        "conversation_replies": 0,
        "conversation_gaps": []
      }
    },
    {
      "id": "rob1ham-2085087812534116402",
      "title": "Rob1ham 2085087812534116402",
      "url": "https://x.com/Rob1Ham/status/2085087812534116402",
      "author": "Rob1Ham",
      "platform": "x",
      "organisation": null,
      "posted": "2026-08-05T19:37:28Z",
      "role": "ai-security-response",
      "why_registered": "Rob Hamilton naming libsecp256k1 the cleanest repository found in the Red Team sweep and crediting its maintainers. A negative result from the scan, which is rarely published, and useful context for the finding counts in callebtc-2085024458012586286. The assessment is his and the underlying scan output is not public.\n",
      "relation": {
        "kind": "single-post",
        "head_id": null
      },
      "capture": {
        "status": "held",
        "artefact_count": 2,
        "conversation_copies": 0,
        "conversation_posts": 0,
        "conversation_replies": 0,
        "conversation_gaps": []
      }
    },
    {
      "id": "jamesob-2085146040320073918",
      "title": "Jamesob 2085146040320073918",
      "url": "https://x.com/jamesob/status/2085146040320073918",
      "author": "jamesob",
      "platform": "x",
      "organisation": null,
      "posted": "2026-08-05T23:28:50Z",
      "role": "on-chain-analysis",
      "why_registered": "James O'Beirne describing two live cktripwire multisig honeypots: a 2-of-3 with two bad-cc keys whose pubkeys have been revealed by a spend, and a 3-of-3 where all three keys are bad-cc and no pubkey has ever been revealed. He states the experiment's logic explicitly: a sweep of the dark 3-of-3 would show attackers speculatively constructing multisig scripts from pubkeys they have never seen. Primary instrumentation of attacker capability rather than commentary on it. Whether either is swept is a future observation, and the archive records the design, not an outcome.\n",
      "relation": {
        "kind": "single-post",
        "head_id": null
      },
      "capture": {
        "status": "held",
        "artefact_count": 5,
        "conversation_copies": 0,
        "conversation_posts": 0,
        "conversation_replies": 0,
        "conversation_gaps": []
      }
    },
    {
      "id": "adam3us-2084972334180421669",
      "title": "Adam3us 2084972334180421669",
      "url": "https://x.com/adam3us/status/2084972334180421669",
      "author": "adam3us",
      "platform": "x",
      "organisation": null,
      "posted": "2026-08-05T11:58:36Z",
      "role": "migration-guidance",
      "why_registered": "Adam Back advising owners to move coins to a different hardware wallet, and separately telling anyone already swept not to destroy the device because it may weakly prove ownership to a whitehat sweeper. The device-retention point is distinct from the migration advice the archive holds elsewhere and bears on funds-recovery claims. He names Blockstream Jade first, and he is Blockstream's CEO, which is stated here because the recommendation is a product recommendation.\n",
      "relation": {
        "kind": "single-post",
        "head_id": null
      },
      "capture": {
        "status": "held",
        "artefact_count": 2,
        "conversation_copies": 0,
        "conversation_posts": 0,
        "conversation_replies": 0,
        "conversation_gaps": []
      }
    },
    {
      "id": "juansgalt-2085102236179333442",
      "title": "Juansgalt 2085102236179333442",
      "url": "https://x.com/JuanSGalt/status/2085102236179333442",
      "author": "JuanSGalt",
      "platform": "x",
      "organisation": null,
      "posted": "2026-08-05T20:34:47Z",
      "role": "reporting",
      "why_registered": "Juan Galt circulating his own Bitcoin Magazine piece on the Red Team's 390-repository figures. Kept as the author's distribution of the article registered at bitcoinmag-red-team-390-repos, not as separate analysis.\n",
      "relation": {
        "kind": "single-post",
        "head_id": null
      },
      "capture": {
        "status": "held",
        "artefact_count": 2,
        "conversation_copies": 0,
        "conversation_posts": 0,
        "conversation_replies": 0,
        "conversation_gaps": []
      }
    },
    {
      "id": "callebtc-2085024461992939882",
      "title": "Callebtc 2085024461992939882",
      "url": "https://x.com/callebtc/status/2085024461992939882",
      "author": "callebtc",
      "platform": "x",
      "organisation": null,
      "posted": "2026-08-05T15:25:44Z",
      "role": "ai-security-response",
      "why_registered": "calle's method note in the same thread: the work is still largely manual with the AI hand held, reviewers are deliberately left to use their own prompts and tools because the diversity produces different hits, and the visible spike is backfill of Rob Hamilton's earlier review dump rather than new throughput. It also names the sponsors providing funding and inference. The clearest captured statement of how the finding counts were produced, which is what makes them hard to compare with an ordinary audit. Self-reported.\n",
      "relation": {
        "kind": "single-post",
        "head_id": null
      },
      "capture": {
        "status": "held",
        "artefact_count": 5,
        "conversation_copies": 0,
        "conversation_posts": 0,
        "conversation_replies": 0,
        "conversation_gaps": []
      }
    },
    {
      "id": "w_s_bitcoin-2084991031724957808",
      "title": "W_s_bitcoin 2084991031724957808",
      "url": "https://x.com/w_s_bitcoin/status/2084991031724957808",
      "author": "w_s_bitcoin",
      "platform": "x",
      "organisation": null,
      "posted": "2026-08-05T13:12:53Z",
      "role": "commentary",
      "why_registered": "Wicked urging owners to unplug BLOCKCLOCK devices immediately and to plan to move funds even if they used dice or a passphrase, saying this is not a drill. Preserved as a dated example of how far the perceived blast radius extended on the morning of 5 August, past the advisories' stated scope. The same account walked this back the same evening in w_s_bitcoin-2085105794950029561, and both are held so the shift is legible. No captured source establishes a BLOCKCLOCK exposure path; this is the poster's own precaution, not a verified finding.\n",
      "relation": {
        "kind": "single-post",
        "head_id": null
      },
      "capture": {
        "status": "held",
        "artefact_count": 5,
        "conversation_copies": 0,
        "conversation_posts": 0,
        "conversation_replies": 0,
        "conversation_gaps": []
      }
    },
    {
      "id": "laurentmt-2085109468149277050",
      "title": "Laurentmt 2085109468149277050",
      "url": "https://x.com/LaurentMT/status/2085109468149277050",
      "author": "LaurentMT",
      "platform": "x",
      "organisation": null,
      "posted": "2026-08-05T21:03:31Z",
      "role": "commentary",
      "why_registered": "LaurentMT contrasting two screenshots under How it started / How it's going, tagged #Disgraceful and #MagicalHTTP308, on the removal or redirection of published COLDCARD endorsements. Part of the 5 August argument about retroactive editing of promotional material, continued in laurentmt-2085115785152741838, laurentmt-2085115946490814649 and laurentmt-2085109959717454248. The archive holds the screenshots as he published them and does not verify what the cited pages served at any earlier date.\n",
      "relation": {
        "kind": "single-post",
        "head_id": null
      },
      "capture": {
        "status": "held",
        "artefact_count": 7,
        "conversation_copies": 0,
        "conversation_posts": 0,
        "conversation_replies": 0,
        "conversation_gaps": []
      }
    },
    {
      "id": "bitcoinnewscom-2085132208025567648",
      "title": "Bitcoinnewscom 2085132208025567648",
      "url": "https://x.com/BitcoinNewsCom/status/2085132208025567648",
      "author": "BitcoinNewsCom",
      "platform": "x",
      "organisation": null,
      "posted": "2026-08-05T22:33:52Z",
      "role": "reporting",
      "why_registered": "Bitcoin News rebutting the claim that a 2021 Rabbit Hole Recap episode shows Coinkite knew of the RNG defect: it says the bug Odell referenced was a USB serial REPL flaw in firmware 4.0.0, which was built and tested internally but never released, with public users receiving the already-fixed 4.0.1. Directly answers jp_technology-2085031289141232016 and agrees with zherbert-2085070195702268321, who cites the version diff. Secondary reporting resting on Coinkite's own disclosure history; the archive records the disagreement rather than settling it.\n",
      "relation": {
        "kind": "single-post",
        "head_id": null
      },
      "capture": {
        "status": "held",
        "artefact_count": 4,
        "conversation_copies": 0,
        "conversation_posts": 0,
        "conversation_replies": 0,
        "conversation_gaps": []
      }
    },
    {
      "id": "francispouliot_-2084827076482200060",
      "title": "Francispouliot_ 2084827076482200060",
      "url": "https://x.com/francispouliot_/status/2084827076482200060",
      "author": "francispouliot_",
      "platform": "x",
      "organisation": null,
      "posted": "2026-08-05T02:21:23Z",
      "role": "commentary",
      "why_registered": "Francis Pouliot framing the incident and a separate privacy-wallet disclosure as the realised worst cases for two communities, and linking both to what he characterises as toxic conduct toward open-source competitors. Reflective commentary from a Bitcoin business operator, kept for how the incident was being fitted into a wider account of the culture. The linkage and the characterisation are his.\n",
      "relation": {
        "kind": "single-post",
        "head_id": null
      },
      "capture": {
        "status": "held",
        "artefact_count": 2,
        "conversation_copies": 0,
        "conversation_posts": 0,
        "conversation_replies": 0,
        "conversation_gaps": []
      }
    },
    {
      "id": "dylanleclair-2085074383773581570",
      "title": "Dylanleclair 2085074383773581570",
      "url": "https://x.com/DylanLeClair/status/2085074383773581570",
      "author": "DylanLeClair",
      "platform": "x",
      "organisation": null,
      "posted": "2026-08-05T18:44:06Z",
      "role": "independent-analysis",
      "why_registered": "Dylan LeClair publishing the gist registered at dylanleclair1-switck-key-attribution with the line that Coinkite's CTO was having a conversation with himself using a pseudonym. Held as the distribution point that carried the attribution claim to a wide audience on 5 August. The identity attribution is the gist author's claim, not verified here, and registration is not endorsement.\n",
      "relation": {
        "kind": "single-post",
        "head_id": null
      },
      "capture": {
        "status": "held",
        "artefact_count": 5,
        "conversation_copies": 0,
        "conversation_posts": 0,
        "conversation_replies": 0,
        "conversation_gaps": []
      }
    },
    {
      "id": "atlasphoenixbtc-2085078309885579573",
      "title": "Atlasphoenixbtc 2085078309885579573",
      "url": "https://x.com/AtlasPhoenixBTC/status/2085078309885579573",
      "author": "AtlasPhoenixBTC",
      "platform": "x",
      "organisation": null,
      "posted": "2026-08-05T18:59:42Z",
      "role": "victim-report",
      "why_registered": "A pseudonymous first-hand account posted a week after the drains, describing the loss of an entire stack built over 13 years and stating a belief that it was the largest single loss in the attack. The author explains the decision to post pseudonymously and addresses other victims directly. First-hand loss reports are the part of the record least likely to survive elsewhere. The size claim is the author's and no captured source corroborates the ranking; the post is a victim account, not an attribution of cause.\n",
      "relation": {
        "kind": "single-post",
        "head_id": null
      },
      "capture": {
        "status": "held",
        "artefact_count": 2,
        "conversation_copies": 0,
        "conversation_posts": 0,
        "conversation_replies": 0,
        "conversation_gaps": []
      }
    },
    {
      "id": "lokobtc-2085122363838906718",
      "title": "Lokobtc 2085122363838906718",
      "url": "https://x.com/LoKoBTC/status/2085122363838906718",
      "author": "LoKoBTC",
      "platform": "x",
      "organisation": null,
      "posted": "2026-08-05T21:54:45Z",
      "role": "commentary",
      "why_registered": "Satire. LoKo joking that the entropy bug was a distraction and the SEEDPLATE contains a microchip logging every punch and phoning home to the nearest BLOCKCLOCK. Registered because it is the clearest dated marker of the point at which the escalating-hardware-compromise theories became a joke format, and because near-identical claims were circulating sincerely at the same time, including the r/Bitcoin seed-plate thread in the intake queue. Nothing in it is a factual claim about any product.\n",
      "relation": {
        "kind": "single-post",
        "head_id": null
      },
      "capture": {
        "status": "held",
        "artefact_count": 5,
        "conversation_copies": 0,
        "conversation_posts": 0,
        "conversation_replies": 0,
        "conversation_gaps": []
      }
    },
    {
      "id": "pavolrusnak-2084645616932606300",
      "title": "Pavolrusnak 2084645616932606300",
      "url": "https://x.com/PavolRusnak/status/2084645616932606300",
      "author": "PavolRusnak",
      "platform": "x",
      "organisation": null,
      "posted": "2026-08-04T14:20:20Z",
      "role": "commentary",
      "why_registered": "Pavol Rusnak's long-form post arguing that toxic Bitcoin maximalism has failed, using the COLDCARD controversy as the occasion while explicitly setting aside his own prior conflicts with Coinkite's founder. Substantial community-reaction writing from a competing hardware wallet's co-founder, which is disclosed here because it bears on how the argument should be read. Opinion, and not a claim about the defect.\n",
      "relation": {
        "kind": "single-post",
        "head_id": null
      },
      "capture": {
        "status": "held",
        "artefact_count": 5,
        "conversation_copies": 0,
        "conversation_posts": 0,
        "conversation_replies": 0,
        "conversation_gaps": []
      }
    },
    {
      "id": "raw_avocado-2085004614093434928",
      "title": "Raw_avocado 2085004614093434928",
      "url": "https://x.com/raw_avocado/status/2085004614093434928",
      "author": "raw_avocado",
      "platform": "x",
      "organisation": null,
      "posted": "2026-08-05T14:06:52Z",
      "role": "commentary",
      "why_registered": "Alex Waltz observing that it took the loss of roughly US$130 million in savings to make criticism of Coinkite acceptable. A compact statement of the pre-incident-criticism theme that recurs across the 5 August record. The dollar figure is a rounded reference to circulating loss estimates, which differ; see /record/funds/.\n",
      "relation": {
        "kind": "single-post",
        "head_id": null
      },
      "capture": {
        "status": "held",
        "artefact_count": 2,
        "conversation_copies": 0,
        "conversation_posts": 0,
        "conversation_replies": 0,
        "conversation_gaps": []
      }
    },
    {
      "id": "coletu-2085065558333022663",
      "title": "Coletu 2085065558333022663",
      "url": "https://x.com/ColeTU/status/2085065558333022663",
      "author": "ColeTU",
      "platform": "x",
      "organisation": null,
      "posted": "2026-08-05T18:09:02Z",
      "role": "product-scope-test",
      "why_registered": "Cole funding five outputs from a COLDCARD Mk3 seed to time how long each survives, varying the derivation deliberately: seed only, seed plus a one, two and three word passphrase, and seed only at a random account number. He publishes the transaction id so the outcome can be watched by anyone. A public, reproducible probe of whether passphrase and account-number variation is being covered by the attacker, and complementary to the cktripwire honeypots. The setup is verifiable on chain; the result is a future observation and nothing is concluded here.\n",
      "relation": {
        "kind": "single-post",
        "head_id": null
      },
      "capture": {
        "status": "held",
        "artefact_count": 5,
        "conversation_copies": 0,
        "conversation_posts": 0,
        "conversation_replies": 0,
        "conversation_gaps": []
      }
    },
    {
      "id": "bitcoinoptech-2085070517527027907",
      "title": "Bitcoinoptech 2085070517527027907",
      "url": "https://x.com/bitcoinoptech/status/2085070517527027907",
      "author": "bitcoinoptech",
      "platform": "x",
      "organisation": null,
      "posted": "2026-08-05T18:28:44Z",
      "role": "reporting",
      "why_registered": "Bitcoin Optech's Newsletter #416 recap podcast, whose first action item is to move funds secured by COLDCARD-generated keys, with Rob Hamilton among the participants. Places the incident in the technical newsletter of record for Bitcoin engineering and timestamps the guidance reaching that audience. The audio is not captured by this tool.\n",
      "relation": {
        "kind": "single-post",
        "head_id": null
      },
      "capture": {
        "status": "held",
        "artefact_count": 5,
        "conversation_copies": 0,
        "conversation_posts": 0,
        "conversation_replies": 0,
        "conversation_gaps": []
      }
    },
    {
      "id": "simplybitcoin-2085123684591673520",
      "title": "Simplybitcoin 2085123684591673520",
      "url": "https://x.com/SimplyBitcoin/status/2085123684591673520",
      "author": "SimplyBitcoin",
      "platform": "x",
      "organisation": null,
      "posted": "2026-08-05T22:00:00Z",
      "role": "custody-provider-guidance",
      "why_registered": "Casa's CEO Nick Neuman arguing that the response to the incident is to eliminate single points of failure by combining providers so that no one vendor's failure takes the whole setup down. Registered as attributed published guidance rather than adopted advice. Casa sells multi-key custody, which is the arrangement being recommended, and that is stated here because the recommendation is a commercial one.\n",
      "relation": {
        "kind": "single-post",
        "head_id": null
      },
      "capture": {
        "status": "held",
        "artefact_count": 5,
        "conversation_copies": 0,
        "conversation_posts": 0,
        "conversation_replies": 0,
        "conversation_gaps": []
      }
    },
    {
      "id": "jamesob-2085096867990278512",
      "title": "Jamesob 2085096867990278512",
      "url": "https://x.com/jamesob/status/2085096867990278512",
      "author": "jamesob",
      "platform": "x",
      "organisation": null,
      "posted": "2026-08-05T20:13:27Z",
      "role": "independent-technical-analysis",
      "why_registered": "James O'Beirne reading the 2021 bug from a version diff as a USB debug mode enabled by default, posted in reply to the THEY'VE KNOWN FOR YEARS claim. An independent read that converges with zherbert-2085070195702268321 on the same conclusion from the same kind of evidence. The diff is public and the reasoning is stated, so this is recheckable in principle; the archive has not re-derived it.\n",
      "relation": {
        "kind": "single-post",
        "head_id": null
      },
      "capture": {
        "status": "held",
        "artefact_count": 5,
        "conversation_copies": 0,
        "conversation_posts": 0,
        "conversation_replies": 0,
        "conversation_gaps": []
      }
    },
    {
      "id": "jamesob-2085110343487955071",
      "title": "Jamesob 2085110343487955071",
      "url": "https://x.com/jamesob/status/2085110343487955071",
      "author": "jamesob",
      "platform": "x",
      "organisation": null,
      "posted": "2026-08-05T21:07:00Z",
      "role": "on-chain-analysis",
      "why_registered": "James O'Beirne opening cktripwire to user-submitted external honeypots. Records the point at which the tripwire measurement stopped being one researcher's own UTXOs and started accepting third-party ones, which changes what its coverage means.\n",
      "relation": {
        "kind": "single-post",
        "head_id": null
      },
      "capture": {
        "status": "held",
        "artefact_count": 5,
        "conversation_copies": 0,
        "conversation_posts": 0,
        "conversation_replies": 0,
        "conversation_gaps": []
      }
    },
    {
      "id": "jwweatherman_-1328075905604829185",
      "title": "Jwweatherman_ 1328075905604829185",
      "url": "https://x.com/JWWeatherman_/status/1328075905604829185",
      "author": "JWWeatherman_",
      "platform": "x",
      "organisation": null,
      "posted": "2020-11-15T20:42:25Z",
      "role": "historical-precedent",
      "why_registered": "A November 2020 post, five and a half years before the incident, quoting Greg Maxwell that the mitigations for hardware-wallet tampering risk are to avoid specialised hardware or to use multifactor security. Registered as pre-incident context that was resurfaced in August 2026, not as a warning about this defect: the quoted concern is supply-chain tampering, not seed generation. Its value is that the argued mitigation, multisig across vendors, is the one the incident revived.\n",
      "relation": {
        "kind": "single-post",
        "head_id": null
      },
      "capture": {
        "status": "held",
        "artefact_count": 2,
        "conversation_copies": 0,
        "conversation_posts": 0,
        "conversation_replies": 0,
        "conversation_gaps": []
      }
    },
    {
      "id": "p3b7_-2085089893328499156",
      "title": "P3b7_ 2085089893328499156",
      "url": "https://x.com/P3b7_/status/2085089893328499156",
      "author": "P3b7_",
      "platform": "x",
      "organisation": null,
      "posted": "2026-08-05T19:45:44Z",
      "role": "commentary",
      "why_registered": "Charles Guillemet arguing that open source is a distribution and inspection property rather than a security one, that COLDCARD's source availability was read as security, and that on hardware neither source review nor compilation gives integrity guarantees without attestation and tamper resistance. A substantial technical argument, and one of the sharpest published statements of the source-availability question the incident raised. Guillemet is Ledger's CTO, a direct competitor, which is stated because the post argues for the secure-element and attestation model Ledger sells.\n",
      "relation": {
        "kind": "single-post",
        "head_id": null
      },
      "capture": {
        "status": "held",
        "artefact_count": 2,
        "conversation_copies": 0,
        "conversation_posts": 0,
        "conversation_replies": 0,
        "conversation_gaps": []
      }
    },
    {
      "id": "gegelsmr4-2084983123582792032",
      "title": "Gegelsmr4 2084983123582792032",
      "url": "https://x.com/gegelsmr4/status/2084983123582792032",
      "author": "gegelsmr4",
      "platform": "x",
      "organisation": null,
      "posted": "2026-08-05T12:41:28Z",
      "role": "reporting",
      "why_registered": "Le Bunker's interview with Kevin Loaec, who raised the early alarm, covering what went wrong with the RNG, entropy generation, dice plus passphrase against multi-vendor multisig, the role of a secure element and BIP 110. Recorded in French with English auto-dubbing on YouTube. Registered for the interview's existence and scope; the video is not captured by this tool and its contents are not quoted here.\n",
      "relation": {
        "kind": "single-post",
        "head_id": null
      },
      "capture": {
        "status": "held",
        "artefact_count": 5,
        "conversation_copies": 0,
        "conversation_posts": 0,
        "conversation_replies": 0,
        "conversation_gaps": []
      }
    },
    {
      "id": "w_s_bitcoin-2085105794950029561",
      "title": "W_s_bitcoin 2085105794950029561",
      "url": "https://x.com/w_s_bitcoin/status/2085105794950029561",
      "author": "w_s_bitcoin",
      "platform": "x",
      "organisation": null,
      "posted": "2026-08-05T20:48:55Z",
      "role": "commentary",
      "why_registered": "Wicked's same-day walk-back: he says he was not in the right state of mind that morning and is no longer as paranoid, while still intending to migrate away from COLDCARD and to take his time doing it safely rather than rushing. Held as the second half of a documented change of view, the first half being w_s_bitcoin-2084991031724957808. Preserving the correction beside the alarm is the point.\n",
      "relation": {
        "kind": "single-post",
        "head_id": null
      },
      "capture": {
        "status": "held",
        "artefact_count": 2,
        "conversation_copies": 0,
        "conversation_posts": 0,
        "conversation_replies": 0,
        "conversation_gaps": []
      }
    },
    {
      "id": "inthepixels-2084969523204026382",
      "title": "Inthepixels 2084969523204026382",
      "url": "https://x.com/inthepixels/status/2084969523204026382",
      "author": "inthepixels",
      "platform": "x",
      "organisation": null,
      "posted": "2026-08-05T11:47:25Z",
      "role": "commentary",
      "why_registered": "Brian Cohen publicly asking eBay to forbid sales of COLDCARD devices on the grounds that buyers would likely be robbed. A dated example of secondary-market pressure during the incident. No captured source shows an eBay response or policy change, and the premise that a resold device robs its buyer is the poster's, not an advisory finding.\n",
      "relation": {
        "kind": "single-post",
        "head_id": null
      },
      "capture": {
        "status": "held",
        "artefact_count": 5,
        "conversation_copies": 0,
        "conversation_posts": 0,
        "conversation_replies": 0,
        "conversation_gaps": []
      }
    },
    {
      "id": "laurentmt-2085115785152741838",
      "title": "Laurentmt 2085115785152741838",
      "url": "https://x.com/LaurentMT/status/2085115785152741838",
      "author": "LaurentMT",
      "platform": "x",
      "organisation": null,
      "posted": "2026-08-05T21:28:37Z",
      "role": "commentary",
      "why_registered": "LaurentMT arguing that deleting content which promoted COLDCARD stops victims understanding how they came to their decision and pushes them to blame themselves. The clearest statement of the harm he attributes to retroactive removal, and directly relevant to why this archive preserves material that publishers later edited.\n",
      "relation": {
        "kind": "single-post",
        "head_id": null
      },
      "capture": {
        "status": "held",
        "artefact_count": 2,
        "conversation_copies": 0,
        "conversation_posts": 0,
        "conversation_replies": 0,
        "conversation_gaps": []
      }
    },
    {
      "id": "laurentmt-2085115946490814649",
      "title": "Laurentmt 2085115946490814649",
      "url": "https://x.com/LaurentMT/status/2085115946490814649",
      "author": "LaurentMT",
      "platform": "x",
      "organisation": null,
      "posted": "2026-08-05T21:29:15Z",
      "role": "commentary",
      "why_registered": "LaurentMT proposing the alternative to deletion: leave the promotional page up and add a prominent warning at the top rather than removing it. A concrete editorial remedy in the same argument, useful because it separates the objection to endorsement from the objection to erasure.\n",
      "relation": {
        "kind": "single-post",
        "head_id": null
      },
      "capture": {
        "status": "held",
        "artefact_count": 2,
        "conversation_copies": 0,
        "conversation_posts": 0,
        "conversation_replies": 0,
        "conversation_gaps": []
      }
    },
    {
      "id": "honesthodl-2084727291846750211",
      "title": "Honesthodl 2084727291846750211",
      "url": "https://x.com/honesthodl/status/2084727291846750211",
      "author": "honesthodl",
      "platform": "x",
      "organisation": null,
      "posted": "2026-08-04T19:44:53Z",
      "role": "prior-warning-claim",
      "why_registered": "Uncle Jim relaying an account he attributes to Ryan of a COLDCARD RNG problem in December 2022, more than three years before the incident became public. One of several 4 to 5 August claims of earlier private knowledge. The video is not captured by this tool. The account is second-hand, no contemporaneous artefact is attached, and it is preserved as an attributed claim. See hodldee-2084864011061866745, posted in reply with further context.\n",
      "relation": {
        "kind": "single-post",
        "head_id": null
      },
      "capture": {
        "status": "held",
        "artefact_count": 5,
        "conversation_copies": 0,
        "conversation_posts": 0,
        "conversation_replies": 0,
        "conversation_gaps": []
      }
    },
    {
      "id": "hodldee-2084864011061866745",
      "title": "Hodldee 2084864011061866745",
      "url": "https://x.com/HodlDee/status/2084864011061866745",
      "author": "HodlDee",
      "platform": "x",
      "organisation": null,
      "posted": "2026-08-05T04:48:09Z",
      "role": "prior-warning-claim",
      "why_registered": "Dee adding context to the December 2022 RNG account by sharing a direct message, noting the unusual step of publishing a DM. Held with honesthodl-2084727291846750211 because the two together are the whole of that claim's public evidence. The screenshot is the poster's own material, published by its recipient; the underlying account remains unverified here.\n",
      "relation": {
        "kind": "single-post",
        "head_id": null
      },
      "capture": {
        "status": "held",
        "artefact_count": 5,
        "conversation_copies": 0,
        "conversation_posts": 0,
        "conversation_replies": 0,
        "conversation_gaps": []
      }
    },
    {
      "id": "kevinkelbie-2085113456735248765",
      "title": "Kevin Kelbie 2085113456735248765",
      "url": "https://x.com/KevinKelbie/status/2085113456735248765",
      "author": "KevinKelbie",
      "platform": "x",
      "organisation": null,
      "posted": "2026-08-05T21:19:22Z",
      "role": "on-chain-analysis",
      "why_registered": "Kevin Kelbie asking whether a wave of sweeps sharing a 2 sat/vB fee rate across many different wallets is a new finding. A fee-rate fingerprint is a weak clustering signal on its own, which is why it is posted as a question. Related to the wave attributions in the coldcard-hack-tracker link review.\n",
      "relation": {
        "kind": "single-post",
        "head_id": null
      },
      "capture": {
        "status": "held",
        "artefact_count": 5,
        "conversation_copies": 0,
        "conversation_posts": 0,
        "conversation_replies": 0,
        "conversation_gaps": []
      }
    },
    {
      "id": "kevinkelbie-2085113459113366013",
      "title": "Kevin Kelbie 2085113459113366013",
      "url": "https://x.com/KevinKelbie/status/2085113459113366013",
      "author": "KevinKelbie",
      "platform": "x",
      "organisation": null,
      "posted": "2026-08-05T21:19:22Z",
      "role": "on-chain-analysis",
      "why_registered": "Kelbie's follow-up tagging intangiblecoins and clay_garrett in case they already hold the finding, and stating that the 2 sat/vB pattern also matches a victim report he received, so it is not resting on the heuristic alone. The corroboration matters to the strength of the claim, which is why the reply is captured with its parent. The victim report is not public and cannot be checked here.\n",
      "relation": {
        "kind": "single-post",
        "head_id": null
      },
      "capture": {
        "status": "held",
        "artefact_count": 2,
        "conversation_copies": 0,
        "conversation_posts": 0,
        "conversation_replies": 0,
        "conversation_gaps": []
      }
    },
    {
      "id": "bitschmidty-2084951183324479712",
      "title": "Bitschmidty 2084951183324479712",
      "url": "https://x.com/bitschmidty/status/2084951183324479712",
      "author": "bitschmidty",
      "platform": "x",
      "organisation": null,
      "posted": "2026-08-05T10:34:33Z",
      "role": "reporting",
      "why_registered": "Mike Schmidt's 5 August roundup linking, in one place, Kevin Loaec's alarm, Kimi-K3 capacity added for Bitcoin researchers, the LLM review efforts by calle and Rob Hamilton with OpenSats funding, Project Loupe's parallel scanning call, MARA's permissionless Slipstream access, Liana and Unchained using Slipstream, James O'Beirne's honeypots and HodlDee's migration support. Useful as a dated index of which response efforts were visible together at that hour; each linked claim is captured or assessed on its own terms elsewhere.\n",
      "relation": {
        "kind": "single-post",
        "head_id": null
      },
      "capture": {
        "status": "held",
        "artefact_count": 2,
        "conversation_copies": 0,
        "conversation_posts": 0,
        "conversation_replies": 0,
        "conversation_gaps": []
      }
    },
    {
      "id": "satsie-2084982723609768045",
      "title": "Satsie 2084982723609768045",
      "url": "https://x.com/satsie/status/2084982723609768045",
      "author": "satsie",
      "platform": "x",
      "organisation": null,
      "posted": "2026-08-05T12:39:53Z",
      "role": "scam-report",
      "why_registered": "satsie describing having starred a repository found while researching the attack, then unstarring it once it was identified as malicious, and crediting jrakibi for checking rather than trusting. A first-hand account of the near miss that jrakibi-2084947141202768295 reports, and a record of how the malicious repository spread through people researching the incident in good faith.\n",
      "relation": {
        "kind": "single-post",
        "head_id": null
      },
      "capture": {
        "status": "held",
        "artefact_count": 2,
        "conversation_copies": 0,
        "conversation_posts": 0,
        "conversation_replies": 0,
        "conversation_gaps": []
      }
    },
    {
      "id": "jrakibi-2084947141202768295",
      "title": "Jrakibi 2084947141202768295",
      "url": "https://x.com/jrakibi/status/2084947141202768295",
      "author": "jrakibi",
      "platform": "x",
      "organisation": null,
      "posted": "2026-08-05T10:18:29Z",
      "role": "scam-report",
      "why_registered": "jrakibi warning that a repository which gained many stars in 24 hours, and claims to reproduce the vulnerable COLDCARD RNG, pulls a dependency that downloads and runs an infostealer searching for seeds, private keys and passwords. A specific and actionable secondary-attack report: the bait is reproduction of this defect, so the target is exactly the people investigating it. The repository is not named or linked here. The malicious behaviour is the reporter's LLM-assisted finding and is not verified by this archive.\n",
      "relation": {
        "kind": "single-post",
        "head_id": null
      },
      "capture": {
        "status": "held",
        "artefact_count": 2,
        "conversation_copies": 0,
        "conversation_posts": 0,
        "conversation_replies": 0,
        "conversation_gaps": []
      }
    },
    {
      "id": "erikcason-2085076560617623651",
      "title": "Erikcason 2085076560617623651",
      "url": "https://x.com/Erikcason/status/2085076560617623651",
      "author": "Erikcason",
      "platform": "x",
      "organisation": null,
      "posted": "2026-08-05T18:52:45Z",
      "role": "commentary",
      "why_registered": "Erik Cason invoking Hanlon's razor, never attribute to malice what stupidity explains, at the height of the insider and state-actor speculation on 5 August. A compact marker of the counter-position; see stonychambers-2084661509913764306 for the theory it answers.\n",
      "relation": {
        "kind": "single-post",
        "head_id": null
      },
      "capture": {
        "status": "held",
        "artefact_count": 2,
        "conversation_copies": 0,
        "conversation_posts": 0,
        "conversation_replies": 0,
        "conversation_gaps": []
      }
    },
    {
      "id": "laurentmt-2085109959717454248",
      "title": "Laurentmt 2085109959717454248",
      "url": "https://x.com/LaurentMT/status/2085109959717454248",
      "author": "LaurentMT",
      "platform": "x",
      "organisation": null,
      "posted": "2026-08-05T21:05:28Z",
      "role": "commentary",
      "why_registered": "LaurentMT's line that he who controls the HTTP redirect controls the past, on the same removal-and-redirection argument. Registered as the phrasing that carried the point furthest, and as a statement of the problem this archive exists to address.\n",
      "relation": {
        "kind": "single-post",
        "head_id": null
      },
      "capture": {
        "status": "held",
        "artefact_count": 5,
        "conversation_copies": 0,
        "conversation_posts": 0,
        "conversation_replies": 0,
        "conversation_gaps": []
      }
    },
    {
      "id": "jyn_urso-2085094085795233911",
      "title": "Jyn_urso 2085094085795233911",
      "url": "https://x.com/jyn_urso/status/2085094085795233911",
      "author": "jyn_urso",
      "platform": "x",
      "organisation": null,
      "posted": "2026-08-05T20:02:23Z",
      "role": "scam-report",
      "why_registered": "Margot Paez warning of a phishing email posing as Trezor support, naming the sending address and telling readers not to click its call-to-action button. A specific dated instance of the migration-driven phishing wave: owners moving off COLDCARD are expecting mail from other vendors. The sender address is as published by the reporter.\n",
      "relation": {
        "kind": "single-post",
        "head_id": null
      },
      "capture": {
        "status": "held",
        "artefact_count": 5,
        "conversation_copies": 0,
        "conversation_posts": 0,
        "conversation_replies": 0,
        "conversation_gaps": []
      }
    },
    {
      "id": "rob1ham-2085047535807180895",
      "title": "Rob1ham 2085047535807180895",
      "url": "https://x.com/Rob1Ham/status/2085047535807180895",
      "author": "Rob1Ham",
      "platform": "x",
      "organisation": null,
      "posted": "2026-08-05T16:57:25Z",
      "role": "ai-security-response",
      "why_registered": "Rob Hamilton's 5 August status post: peer review of known issues alongside calle's coordination, credit to OpenCode for the infrastructure, and a security notice that he is no longer reachable by direct message because of scammers posing as media and as victims, with named AnchorWatch contacts instead. The impersonation warning is the substantive part and matches the wider scam pattern in this batch. He is AnchorWatch's CEO.\n",
      "relation": {
        "kind": "single-post",
        "head_id": null
      },
      "capture": {
        "status": "held",
        "artefact_count": 5,
        "conversation_copies": 0,
        "conversation_posts": 0,
        "conversation_replies": 0,
        "conversation_gaps": []
      }
    },
    {
      "id": "erikcason-2085031817162436729",
      "title": "Erikcason 2085031817162436729",
      "url": "https://x.com/Erikcason/status/2085031817162436729",
      "author": "Erikcason",
      "platform": "x",
      "organisation": null,
      "posted": "2026-08-05T15:54:57Z",
      "role": "commentary",
      "why_registered": "Erik Cason joking that Mark Karpelès should take over Coinkite. Kept as a dated marker of the gallows humour around magicaltux-2083966069124014412, which is the post it plays on, and of how the community was reaching for earlier custody failures as comparison.\n",
      "relation": {
        "kind": "single-post",
        "head_id": null
      },
      "capture": {
        "status": "held",
        "artefact_count": 2,
        "conversation_copies": 0,
        "conversation_posts": 0,
        "conversation_replies": 0,
        "conversation_gaps": []
      }
    },
    {
      "id": "magicaltux-2083966069124014412",
      "title": "Magicaltux 2083966069124014412",
      "url": "https://x.com/MagicalTux/status/2083966069124014412",
      "author": "MagicalTux",
      "platform": "x",
      "organisation": null,
      "posted": "2026-08-02T17:20:03Z",
      "role": "commentary",
      "why_registered": "Mark Karpelès saying on 2 August that he has started new firmware for the COLDCARD hardware and needs a device to test it. Registered because the former Mt. Gox operator publicly proposing to write replacement firmware became a recurring reference point in the reaction, including erikcason-2085031817162436729. No captured source shows such firmware being released, and the statement of intent is his alone.\n",
      "relation": {
        "kind": "single-post",
        "head_id": null
      },
      "capture": {
        "status": "held",
        "artefact_count": 2,
        "conversation_copies": 0,
        "conversation_posts": 0,
        "conversation_replies": 0,
        "conversation_gaps": []
      }
    },
    {
      "id": "adriancercenia-2084865984587034805",
      "title": "Adriancercenia 2084865984587034805",
      "url": "https://x.com/AdrianCercenia/status/2084865984587034805",
      "author": "AdrianCercenia",
      "platform": "x",
      "organisation": null,
      "posted": "2026-08-05T04:56:00Z",
      "role": "migration-guidance",
      "why_registered": "A.C arguing against destroying the device: that dice-only seed generation takes user-supplied entropy in a verifiable, trust-minimised way with no firmware update needed, and that the device remains a functional stateless airgapped signer when used with a temporary seed. Held as a dated, explicitly labelled unpopular position on continued use. The safety of the dice path under the affected firmware is contested across the record and is not verified here; the archive does not recommend a course of action.\n",
      "relation": {
        "kind": "single-post",
        "head_id": null
      },
      "capture": {
        "status": "held",
        "artefact_count": 5,
        "conversation_copies": 0,
        "conversation_posts": 0,
        "conversation_replies": 0,
        "conversation_gaps": []
      }
    },
    {
      "id": "janrothen-2084764544455315640",
      "title": "Janrothen 2084764544455315640",
      "url": "https://x.com/janrothen/status/2084764544455315640",
      "author": "janrothen",
      "platform": "x",
      "organisation": null,
      "posted": "2026-08-04T22:12:55Z",
      "role": "downstream-wallet-scope",
      "why_registered": "Jan Rothen announcing a move to BitBox and listing five entropy sources he says it combines: true RNG on the secure chip, true RNG on the microcontroller, a factory-burned unique value, host entropy and a hash of the device password. Registered for the competitor design claim, which is the substantive part, and because entropy-source layering is the design question the incident raised. The post ends in a purchase link and reads as promotional; the five-source description is the poster's and is not verified against BitBox firmware here.\n",
      "relation": {
        "kind": "single-post",
        "head_id": null
      },
      "capture": {
        "status": "held",
        "artefact_count": 2,
        "conversation_copies": 0,
        "conversation_posts": 0,
        "conversation_replies": 0,
        "conversation_gaps": []
      }
    },
    {
      "id": "martybent-2085008976576405971",
      "title": "Martybent 2085008976576405971",
      "url": "https://x.com/MartyBent/status/2085008976576405971",
      "author": "MartyBent",
      "platform": "x",
      "organisation": null,
      "posted": "2026-08-05T14:24:12Z",
      "role": "incident-response-guidance",
      "why_registered": "Marty Bent directing affected owners to Galaxy Research, who are tracking stolen funds and mapping the extent of the damage, and separately telling them to file a police report. One of the clearer captured statements of what an individual victim was being told to do, and relevant to the population-denominator gap: the victim set is being assembled from self-reports.\n",
      "relation": {
        "kind": "single-post",
        "head_id": null
      },
      "capture": {
        "status": "held",
        "artefact_count": 2,
        "conversation_copies": 0,
        "conversation_posts": 0,
        "conversation_replies": 0,
        "conversation_gaps": []
      }
    },
    {
      "id": "coryswan-2085077996738941204",
      "title": "Coryswan 2085077996738941204",
      "url": "https://x.com/CorySwan/status/2085077996738941204",
      "author": "CorySwan",
      "platform": "x",
      "organisation": null,
      "posted": "2026-08-05T18:58:27Z",
      "role": "commentary",
      "why_registered": "Cory Swan warning that the disruption will be used to push paper Bitcoin, to justify adding other assets, and to argue that self-custody is too risky, and urging readers not to accept that framing. A dated statement of the defensive reaction, from an employee of a company that sells both brokerage and self-custody products.\n",
      "relation": {
        "kind": "single-post",
        "head_id": null
      },
      "capture": {
        "status": "held",
        "artefact_count": 2,
        "conversation_copies": 0,
        "conversation_posts": 0,
        "conversation_replies": 0,
        "conversation_gaps": []
      }
    },
    {
      "id": "americanhodl8-2085036994305184008",
      "title": "Americanhodl8 2085036994305184008",
      "url": "https://x.com/americanhodl8/status/2085036994305184008",
      "author": "americanhodl8",
      "platform": "x",
      "organisation": null,
      "posted": "2026-08-05T16:15:32Z",
      "role": "commentary",
      "why_registered": "AMERICAN HODL's essay on the psychological aftermath: survivor's guilt, freeze states, and the observation that the people hit hardest were the careful ones who followed the guides. He frames it as a belief-system failure rather than only a bug, and discloses in the text that one line came from an AI. Substantial reaction writing on the human cost, which the technical record does not otherwise carry. Its clinical framing is the author's own and it reports conversations that are not public.\n",
      "relation": {
        "kind": "single-post",
        "head_id": null
      },
      "capture": {
        "status": "held",
        "artefact_count": 5,
        "conversation_copies": 0,
        "conversation_posts": 0,
        "conversation_replies": 0,
        "conversation_gaps": []
      }
    },
    {
      "id": "stonychambers-2084661509913764306",
      "title": "Stonychambers 2084661509913764306",
      "url": "https://x.com/stonychambers/status/2084661509913764306",
      "author": "stonychambers",
      "platform": "x",
      "organisation": null,
      "posted": "2026-08-04T15:23:29Z",
      "role": "commentary",
      "why_registered": "Bitcoin Asset Research alleging a state-backed inside job planned over years, built from questions about why the attacker consolidated into a single address, used KYC'd providers, made no attempt to cover their tracks, and about the timing. Preserved solely as dated, attributed public reaction, which is the only basis on which this archive carries inside-job and state-actor theories. Nothing here is evidence that any of it is true: no captured source supports the allegation, Block's tracing work found no evidence of participation by the provider it traced, and the archive holds miketwenty1-2085130028094718097 and erikcason-2085076560617623651 as contemporaneous rejections of exactly this reading. If the author later retracts or revises, that will be preserved beside it.\n",
      "relation": {
        "kind": "single-post",
        "head_id": null
      },
      "capture": {
        "status": "held",
        "artefact_count": 5,
        "conversation_copies": 0,
        "conversation_posts": 0,
        "conversation_replies": 0,
        "conversation_gaps": []
      }
    },
    {
      "id": "rob1ham-2084883822298997009",
      "title": "Rob1ham 2084883822298997009",
      "url": "https://x.com/Rob1Ham/status/2084883822298997009",
      "author": "Rob1Ham",
      "platform": "x",
      "organisation": null,
      "posted": "2026-08-05T06:06:53Z",
      "role": "migration-guidance",
      "why_registered": "Rob Hamilton reporting that he had just spoken to someone whose bitcoin was taken from a default Mk4, and urging owners not to wait because attackers are likely accelerating. Registered because a default Mk4 loss speaks to the scope question the advisories left open, and because of the timestamp: 06:06 UTC on 5 August. The account is second-hand and no artefact is attached.\n",
      "relation": {
        "kind": "single-post",
        "head_id": null
      },
      "capture": {
        "status": "held",
        "artefact_count": 2,
        "conversation_copies": 0,
        "conversation_posts": 0,
        "conversation_replies": 0,
        "conversation_gaps": []
      }
    },
    {
      "id": "river-2084654194913403137",
      "title": "River 2084654194913403137",
      "url": "https://x.com/River/status/2084654194913403137",
      "author": "River",
      "platform": "x",
      "organisation": null,
      "posted": "2026-08-04T14:54:25Z",
      "role": "historical-precedent",
      "why_registered": "River recalling Hal Finney's 1995 challenge to break 40-bit encryption, cracked a month later by Adam Back and three others. Registered as the historical framing that circulated during the incident, on how key-space assumptions decay. It is background rather than a claim about this defect, and the archive holds the earlier predictable-key incidents separately as the closer precedents.\n",
      "relation": {
        "kind": "single-post",
        "head_id": null
      },
      "capture": {
        "status": "held",
        "artefact_count": 5,
        "conversation_copies": 0,
        "conversation_posts": 0,
        "conversation_replies": 0,
        "conversation_gaps": []
      }
    },
    {
      "id": "lukedewolf-2084971750874288133",
      "title": "Lukedewolf 2084971750874288133",
      "url": "https://x.com/lukedewolf/status/2084971750874288133",
      "author": "lukedewolf",
      "platform": "x",
      "organisation": null,
      "posted": "2026-08-05T11:56:16Z",
      "role": "commentary",
      "why_registered": "Luke de Wolf releasing his book Defending Bitcoin free in response to the incident, and saying he had underestimated AI attack capability and had not expected a widely recommended hardware wallet to have neglected secure seed generation. The author's stated revision of his own published risk assessment is the part worth preserving. The post is also promotional, linking a store.\n",
      "relation": {
        "kind": "single-post",
        "head_id": null
      },
      "capture": {
        "status": "held",
        "artefact_count": 2,
        "conversation_copies": 0,
        "conversation_posts": 0,
        "conversation_replies": 0,
        "conversation_gaps": []
      }
    },
    {
      "id": "btctimescom-2084629110018482639",
      "title": "Btctimescom 2084629110018482639",
      "url": "https://x.com/BTCTimescom/status/2084629110018482639",
      "author": "BTCTimescom",
      "platform": "x",
      "organisation": null,
      "posted": "2026-08-04T13:14:45Z",
      "role": "reporting",
      "why_registered": "BTC Times reporting losses that may total 2,055 BTC, about US$130 million, attributed to a firmware flaw that weakened wallet seeds. A dated secondary figure from 4 August. Loss totals differ substantially between Coinkite, Block, Galaxy and the community trackers, and this archive does not choose between them; the figures and their assumptions are set out at /record/funds/.\n",
      "relation": {
        "kind": "single-post",
        "head_id": null
      },
      "capture": {
        "status": "held",
        "artefact_count": 2,
        "conversation_copies": 0,
        "conversation_posts": 0,
        "conversation_replies": 0,
        "conversation_gaps": []
      }
    },
    {
      "id": "kloaec-2084985260010271035",
      "title": "KLoaec 2084985260010271035",
      "url": "https://x.com/KLoaec/status/2084985260010271035",
      "author": "KLoaec",
      "platform": "x",
      "organisation": null,
      "posted": "2026-08-05T12:49:57Z",
      "role": "incident-response-guidance",
      "why_registered": "Kevin Loaec asking readers to stop attacking nvk and check on people at their local meetups instead, on the grounds that victims cannot get useful support from non-bitcoiners who see the loss as monopoly money, and saying it may save a life. From the person who helped raise the initial alarm. The clearest captured statement of the welfare concern during the first week. The scale figure in it is his own characterisation.\n",
      "relation": {
        "kind": "single-post",
        "head_id": null
      },
      "capture": {
        "status": "held",
        "artefact_count": 2,
        "conversation_copies": 0,
        "conversation_posts": 0,
        "conversation_replies": 0,
        "conversation_gaps": []
      }
    },
    {
      "id": "tftc21-2085073073947173269",
      "title": "Tftc21 2085073073947173269",
      "url": "https://x.com/TFTC21/status/2085073073947173269",
      "author": "TFTC21",
      "platform": "x",
      "organisation": null,
      "posted": "2026-08-05T18:38:54Z",
      "role": "prior-warning-claim",
      "why_registered": "TFTC relaying an account of a COLDCARD user who generated weak entropy at the bottom of the last bear market, unknowingly collided with another wallet, and had bitcoin stolen at a time when nobody could explain it. If accurate, this describes a loss from the same defect years before it was identified, which bears directly on when the exposure began. Second-hand, undated as to the specific event, with no transaction identifier attached; the video is not captured by this tool.\n",
      "relation": {
        "kind": "single-post",
        "head_id": null
      },
      "capture": {
        "status": "held",
        "artefact_count": 2,
        "conversation_copies": 0,
        "conversation_posts": 0,
        "conversation_replies": 0,
        "conversation_gaps": []
      }
    },
    {
      "id": "bryanjacoutot-2085016998744903941",
      "title": "Bryanjacoutot 2085016998744903941",
      "url": "https://x.com/BryanJacoutot/status/2085016998744903941",
      "author": "BryanJacoutot",
      "platform": "x",
      "organisation": null,
      "posted": "2026-08-05T14:56:04Z",
      "role": "independent-technical-analysis",
      "why_registered": "Bryan Jacoutot's argument that blaming poor user dice rolls cannot account for a pre-existing transaction at a derived address, because that requires a second party to have independently arrived at the same key, whereas a defective firmware RNG shared across devices does explain it. A clean statement of why the user-error explanation fails on the collision evidence. The reasoning is stated and can be argued on its merits; the archive has not re-derived it from a specific transaction.\n",
      "relation": {
        "kind": "single-post",
        "head_id": null
      },
      "capture": {
        "status": "held",
        "artefact_count": 2,
        "conversation_copies": 0,
        "conversation_posts": 0,
        "conversation_replies": 0,
        "conversation_gaps": []
      }
    },
    {
      "id": "gladstein-2085007129216246152",
      "title": "Gladstein 2085007129216246152",
      "url": "https://x.com/gladstein/status/2085007129216246152",
      "author": "gladstein",
      "platform": "x",
      "organisation": null,
      "posted": "2026-08-05T14:16:51Z",
      "role": "commentary",
      "why_registered": "Alex Gladstein calling it the worst thing he has seen in the space in ten years of paying attention, while noting that the wider world and the market appeared indifferent. The gap between the severity inside the community and the absence of an outside reaction is the observation worth preserving.\n",
      "relation": {
        "kind": "single-post",
        "head_id": null
      },
      "capture": {
        "status": "held",
        "artefact_count": 2,
        "conversation_copies": 0,
        "conversation_posts": 0,
        "conversation_replies": 0,
        "conversation_gaps": []
      }
    },
    {
      "id": "mandrik-2084931345088643076",
      "title": "Mandrik 2084931345088643076",
      "url": "https://x.com/Mandrik/status/2084931345088643076",
      "author": "Mandrik",
      "platform": "x",
      "organisation": null,
      "posted": "2026-08-05T09:15:43Z",
      "role": "commentary",
      "why_registered": "Mandrik's flat statement that readers had just lived through the worst event in Bitcoin's history. Registered as one dated instance of the ranking claim that circulated widely in the first week. Attribution totals differ and the number of people affected is unknown, so the archive treats the ranking as contemporaneous assessment rather than a settled fact.\n",
      "relation": {
        "kind": "single-post",
        "head_id": null
      },
      "capture": {
        "status": "held",
        "artefact_count": 2,
        "conversation_copies": 0,
        "conversation_posts": 0,
        "conversation_replies": 0,
        "conversation_gaps": []
      }
    },
    {
      "id": "afilini-2085028027499413710",
      "title": "Afilini 2085028027499413710",
      "url": "https://x.com/afilini/status/2085028027499413710",
      "author": "afilini",
      "platform": "x",
      "organisation": null,
      "posted": "2026-08-05T15:39:54Z",
      "role": "independent-technical-analysis",
      "why_registered": "Alekos Filini restating his report as a thread after judging the long form harder to follow, opening on the point that COLDCARD previously had two RNG sources, tcc from trezor-crypto and ckcc implemented in the firmware, both safe TRNG sources. The accessible entry point to the analysis registered at afilini-seed-rng-migration-report.\n",
      "relation": {
        "kind": "single-post",
        "head_id": null
      },
      "capture": {
        "status": "held",
        "artefact_count": 2,
        "conversation_copies": 0,
        "conversation_posts": 0,
        "conversation_replies": 0,
        "conversation_gaps": []
      }
    },
    {
      "id": "afilini-2085021651918332071",
      "title": "Afilini 2085021651918332071",
      "url": "https://x.com/afilini/status/2085021651918332071",
      "author": "afilini",
      "platform": "x",
      "organisation": null,
      "posted": "2026-08-05T15:14:34Z",
      "role": "independent-technical-analysis",
      "why_registered": "Alekos Filini's first post on finding that the commit introducing libngu replaced only some RNG calls with the vulnerable version. The moment the selective-migration observation was first published, ahead of the full report; the gist is registered at afilini-seed-rng-migration-report and states the git commands the claim rests on.\n",
      "relation": {
        "kind": "single-post",
        "head_id": null
      },
      "capture": {
        "status": "held",
        "artefact_count": 2,
        "conversation_copies": 0,
        "conversation_posts": 0,
        "conversation_replies": 0,
        "conversation_gaps": []
      }
    },
    {
      "id": "zeetxo-2082868212677615933",
      "title": "Zeetxo 2082868212677615933",
      "url": "https://x.com/zeetxo/status/2082868212677615933",
      "author": "zeetxo",
      "platform": "x",
      "organisation": null,
      "posted": "2026-07-30T16:37:34Z",
      "role": "early-analysis",
      "why_registered": "Zee's 30 July post noting some sort of mass attack on multiple dormant wallets, published at 16:37 UTC on the first day. One of the earliest public signals in the archive, made before any cause was known and phrased with matching uncertainty. Its significance is the timestamp: see notgrubles-2085084394352500935, which credits this post as first notice.\n",
      "relation": {
        "kind": "single-post",
        "head_id": null
      },
      "capture": {
        "status": "held",
        "artefact_count": 5,
        "conversation_copies": 0,
        "conversation_posts": 0,
        "conversation_replies": 0,
        "conversation_gaps": []
      }
    },
    {
      "id": "notgrubles-2085084394352500935",
      "title": "Notgrubles 2085084394352500935",
      "url": "https://x.com/notgrubles/status/2085084394352500935",
      "author": "notgrubles",
      "platform": "x",
      "organisation": null,
      "posted": "2026-08-05T19:23:53Z",
      "role": "early-analysis",
      "why_registered": "grubles crediting zeetxo's post as how he first learned something was happening. A week later, an attribution of first notice, which is worth preserving because the earliest observers are usually written out of an incident's account once the analysis arrives.\n",
      "relation": {
        "kind": "single-post",
        "head_id": null
      },
      "capture": {
        "status": "held",
        "artefact_count": 2,
        "conversation_copies": 0,
        "conversation_posts": 0,
        "conversation_replies": 0,
        "conversation_gaps": []
      }
    },
    {
      "id": "jamesob-2085001896192827884",
      "title": "Jamesob 2085001896192827884",
      "url": "https://x.com/jamesob/status/2085001896192827884",
      "author": "jamesob",
      "platform": "x",
      "organisation": null,
      "posted": "2026-08-05T13:56:04Z",
      "role": "prior-warning-claim",
      "why_registered": "James O'Beirne reporting a second credible account of someone warning Coinkite about bad entropy in 2021, distinct from the Telegram account he had quoted earlier and four years before his own report, and saying it is possible three independent people raised it. Directly relevant to the open question of pre-incident private warnings, on which the archive holds no primary artefact. The reports are second-hand, the sources are not named and nothing is attached; see the audit-artefact gap in BACKLOG.md.\n",
      "relation": {
        "kind": "single-post",
        "head_id": null
      },
      "capture": {
        "status": "held",
        "artefact_count": 2,
        "conversation_copies": 0,
        "conversation_posts": 0,
        "conversation_replies": 0,
        "conversation_gaps": []
      }
    },
    {
      "id": "zherbert-2085070195702268321",
      "title": "Zherbert 2085070195702268321",
      "url": "https://x.com/zherbert/status/2085070195702268321",
      "author": "zherbert",
      "platform": "x",
      "organisation": null,
      "posted": "2026-08-05T18:27:28Z",
      "role": "independent-technical-analysis",
      "why_registered": "Zach Herbert identifying the 2021 bug precisely: COLDCARD 4.0.0 initialised ckcc_vcp_enabled to true, so once USB was active a connected computer could send Control-C, drop into the MicroPython REPL and reach wallet secrets, with 4.0.1 defaulting the flag to false. He states the 4.0.0 to 4.0.1 diff makes it clear and notes Coinkite has since named it the USB serial REPL vulnerability. The most specific captured rebuttal of the THEY'VE KNOWN FOR YEARS reading, and recheckable against the public diff. Herbert is Foundation's CEO, a competing hardware wallet vendor, which is stated because the post exonerates Coinkite on this particular point.\n",
      "relation": {
        "kind": "single-post",
        "head_id": null
      },
      "capture": {
        "status": "held",
        "artefact_count": 2,
        "conversation_copies": 0,
        "conversation_posts": 0,
        "conversation_replies": 0,
        "conversation_gaps": []
      }
    },
    {
      "id": "christophera-2085114670244139135",
      "title": "Christophera 2085114670244139135",
      "url": "https://x.com/ChristopherA/status/2085114670244139135",
      "author": "ChristopherA",
      "platform": "x",
      "organisation": null,
      "posted": "2026-08-05T21:24:11Z",
      "role": "commentary",
      "why_registered": "Christopher Allen arguing that the incident hides a deeper problem, the usability and complexity of multisig and the lack of interoperability between wallets, which he says he has been pressing wallet companies on for more than seven years. Relevant because multi-vendor multisig is the mitigation most often recommended across this record, and this is the captured statement of why it has not been adopted. Opening post of a thread; only this post is captured.\n",
      "relation": {
        "kind": "single-post",
        "head_id": null
      },
      "capture": {
        "status": "held",
        "artefact_count": 2,
        "conversation_copies": 0,
        "conversation_posts": 0,
        "conversation_replies": 0,
        "conversation_gaps": []
      }
    },
    {
      "id": "thefuzzstone-2084940899767800055",
      "title": "Thefuzzstone 2084940899767800055",
      "url": "https://x.com/thefuzzstone/status/2084940899767800055",
      "author": "thefuzzstone",
      "platform": "x",
      "organisation": null,
      "posted": "2026-08-05T09:53:41Z",
      "role": "independent-analysis",
      "why_registered": "TheFuzzStone's dated timeline of the incident, running from Peter D. Gray and Rodolfo Novak's pre-Bitcoin work together in 2010 through Coinkite's founding, the 2013 creation of Gray's GPG key, the pivot to hardware and the first Mk1 shipments, and continuing into the switck identity. Registered as the most complete public chronology assembled during the first week, and as the form in which the identity claim reached a general audience. It is a compilation, dates and inferences alike are the author's, and the archive does not verify the identity attribution it carries; the underlying artefact is at dylanleclair1-switck-key-attribution.\n",
      "relation": {
        "kind": "single-post",
        "head_id": null
      },
      "capture": {
        "status": "held",
        "artefact_count": 5,
        "conversation_copies": 0,
        "conversation_posts": 0,
        "conversation_replies": 0,
        "conversation_gaps": []
      }
    },
    {
      "id": "soapminer1-2085157332518900180",
      "title": "Soapminer1 2085157332518900180",
      "url": "https://x.com/soapminer1/status/2085157332518900180",
      "author": "soapminer1",
      "platform": "x",
      "organisation": null,
      "posted": "2026-08-06T00:13:43Z",
      "role": "scam-report",
      "why_registered": "SoapMiner reporting having just been scammed and warning others, linking the impersonation account involved, whose handle is a near-miss of Rob Hamilton's. A first-hand account of the impersonation pattern Rob Hamilton warned about in rob1ham-2085047535807180895, captured from the victim's side hours later.\n",
      "relation": {
        "kind": "single-post",
        "head_id": null
      },
      "capture": {
        "status": "held",
        "artefact_count": 2,
        "conversation_copies": 0,
        "conversation_posts": 0,
        "conversation_replies": 0,
        "conversation_gaps": []
      }
    },
    {
      "id": "teddybitcoins-2084812101172748464",
      "title": "Teddybitcoins 2084812101172748464",
      "url": "https://x.com/TeddyBitcoins/status/2084812101172748464",
      "author": "TeddyBitcoins",
      "platform": "x",
      "organisation": null,
      "posted": "2026-08-05T01:21:53Z",
      "role": "commentary",
      "why_registered": "Satire posted mid-incident, claiming a Coinkite BLOCKCLOCK was found to contain a Russian military listening device precise enough to hear seed words being stamped into steel plates. It is a joke rather than a report, and is registered as one dated instance of how far distrust of the vendor's other products travelled in the first week. Neil Jacobs asked for forensic analysis of BLOCKCLOCK models as a straight question the same day, at neiljacobs-2084978259079426454; nothing captured here establishes that the second was prompted by the first.\n",
      "relation": {
        "kind": "single-post",
        "head_id": null
      },
      "capture": {
        "status": "held",
        "artefact_count": 5,
        "conversation_copies": 0,
        "conversation_posts": 0,
        "conversation_replies": 0,
        "conversation_gaps": []
      }
    },
    {
      "id": "mariusoffchain-2084892387445244196",
      "title": "Mariusoffchain 2084892387445244196",
      "url": "https://x.com/mariusoffchain/status/2084892387445244196",
      "author": "mariusoffchain",
      "platform": "x",
      "organisation": null,
      "posted": "2026-08-05T06:40:55Z",
      "role": "on-chain-analysis",
      "why_registered": "Marius OffChain's 5 August trace of one attacker beginning to mix 64 BTC: a 64 BTC input against a roughly 54 BTC output, so about 10 BTC mixed at the first hop, with the change then split into roughly 7 BTC pieces and mixed again. It names the receiving address, calls the pattern surprising and asks other on-chain analysts whether they have seen it before. tanuki42_-2084927029430870179 answers by identifying the coordinator, and bitcoinnewscom-2085117642567020750 reports the same figures that evening. Self-reported; the transactions are checkable on chain but are not reproduced here.\n",
      "relation": {
        "kind": "single-post",
        "head_id": null
      },
      "capture": {
        "status": "held",
        "artefact_count": 9,
        "conversation_copies": 0,
        "conversation_posts": 0,
        "conversation_replies": 0,
        "conversation_gaps": []
      }
    },
    {
      "id": "we_satoshis-2085034468935450918",
      "title": "We_satoshis 2085034468935450918",
      "url": "https://x.com/we_satoshis/status/2085034468935450918",
      "author": "we_satoshis",
      "platform": "x",
      "organisation": null,
      "posted": "2026-08-05T16:05:30Z",
      "role": "independent-analysis",
      "why_registered": "A first-hand honeypot result: 10,000 sats placed on a Mk3 were swept 10 seconds after the deposit, and a pre-signed replace-by-fee transaction won the race at a 9,000 sat fee before the attacker rebid at 9,100. The poster's conclusion is that such a race can continue until the balance is burned in mining fees rather than recovered by either side. The same post promotes the account's own WatchGuard hardware, which is stated here because the result and the product claim arrive together. Self-reported: the linked transaction is checkable on chain, the 10-second timing is not.\n",
      "relation": {
        "kind": "single-post",
        "head_id": null
      },
      "capture": {
        "status": "held",
        "artefact_count": 11,
        "conversation_copies": 0,
        "conversation_posts": 0,
        "conversation_replies": 0,
        "conversation_gaps": []
      }
    },
    {
      "id": "chainalysis-2085126271042830608",
      "title": "Chainalysis 2085126271042830608",
      "url": "https://x.com/chainalysis/status/2085126271042830608",
      "author": "chainalysis",
      "platform": "x",
      "organisation": null,
      "posted": "2026-08-05T22:10:17Z",
      "role": "on-chain-analysis",
      "why_registered": "Chainalysis's 5 August typology of what it describes as multiple independent attackers, separated by how each moves funds: a first wave consolidating into a wallet where 35 million dollars sits dormant, cross-chain movement into TornadoCash, movement through intermediaries onward to centralized exchanges, and movement into Wasabi Wallet. No addresses, method or denominator are published, so none of the four types can be reproduced from the post. Follows chainalysis-2084734055858282986, whose geographic estimate has the same limitation. l0lal33tz-2085154479423307782 disputes the inference the trace supports.\n",
      "relation": {
        "kind": "single-post",
        "head_id": null
      },
      "capture": {
        "status": "held",
        "artefact_count": 5,
        "conversation_copies": 0,
        "conversation_posts": 0,
        "conversation_replies": 0,
        "conversation_gaps": []
      }
    },
    {
      "id": "truthcoin-2085043734115143763",
      "title": "Truthcoin 2085043734115143763",
      "url": "https://x.com/Truthcoin/status/2085043734115143763",
      "author": "Truthcoin",
      "platform": "x",
      "organisation": null,
      "posted": "2026-08-05T16:42:19Z",
      "role": "commentary",
      "why_registered": "Paul Sztorc circulating Peter Todd's screenshot, recovered from a phone cache, of an nvk post dated 15 November 2024 that had since been deleted: \"Now imagine if this knockoff was a back door into peoples home network...\". Registered for the deleted material it carries rather than for Sztorc's one-line reaction, and kept alongside stackernews-nvk-deleted-posts. What the archive holds is a third party's picture of the post, not the post; nothing here establishes when or why it was deleted, and the post it originally quoted is already unavailable in the screenshot.\n",
      "relation": {
        "kind": "single-post",
        "head_id": null
      },
      "capture": {
        "status": "held",
        "artefact_count": 2,
        "conversation_copies": 0,
        "conversation_posts": 0,
        "conversation_replies": 0,
        "conversation_gaps": []
      }
    },
    {
      "id": "frankcorva-2084830941780836750",
      "title": "Frankcorva 2084830941780836750",
      "url": "https://x.com/frankcorva/status/2084830941780836750",
      "author": "frankcorva",
      "platform": "x",
      "organisation": null,
      "posted": "2026-08-05T02:36:45Z",
      "role": "commentary",
      "why_registered": "Frank Corva circulating, as four screenshots, a chronology of Coinkite that he attributes to an author called Laser on nostr: the 2012-2013 founding, Ten31 becoming sole external investor, the January 2021 licence change from GPL to MIT plus Commons Clause, the August 2019 creation of the switck identity, and the 1 March 2021 commit \"First pass w/ libNgU\" (b18723dd) replacing the remaining Trezor-derived code and switching seed generation from ckcc.rng_bytes() to ngu.random.bytes(). The commit is checkable against the firmware repository; the surrounding biography is the nostr author's account and that primary post is not held here.\n",
      "relation": {
        "kind": "single-post",
        "head_id": null
      },
      "capture": {
        "status": "held",
        "artefact_count": 11,
        "conversation_copies": 0,
        "conversation_posts": 0,
        "conversation_replies": 0,
        "conversation_gaps": []
      }
    },
    {
      "id": "trezor-2084975929948766645",
      "title": "Trezor 2084975929948766645",
      "url": "https://x.com/Trezor/status/2084975929948766645",
      "author": "Trezor",
      "platform": "x",
      "organisation": null,
      "posted": "2026-08-05T12:12:53Z",
      "role": "downstream-wallet-scope",
      "why_registered": "Trezor's 5 August scope statement: its devices are not affected by the COLDCARD vulnerability, followed by a twelve-post FAQ on who may need to move funds, how Trezor backups work and how to avoid related scams. The post links the fuller article registered at trezor-coldcard-not-affected. Registered as a polled thread so the whole FAQ is held rather than its first post alone. Follows trezor-2084552993471389722, which stated the same scope alongside a phishing warning.\n",
      "relation": {
        "kind": "conversation-head",
        "head_id": null
      },
      "capture": {
        "status": "held",
        "artefact_count": 94,
        "conversation_copies": 15,
        "conversation_posts": 88,
        "conversation_replies": 77,
        "conversation_gaps": []
      }
    },
    {
      "id": "gmoneypepe-2085038346557169833",
      "title": "Gmoneypepe 2085038346557169833",
      "url": "https://x.com/GMONEYPEPE/status/2085038346557169833",
      "author": "GMONEYPEPE",
      "platform": "x",
      "organisation": null,
      "posted": "2026-08-05T16:20:54Z",
      "role": "commentary",
      "why_registered": "GMONEY calling \"a smoking gun\" a 4 August exchange in which JW Weatherman states he is 100 percent certain the incident was an inside job, and NoomDynamite replies that the entropy was cut enough to make keys brute-forceable but not so far that collisions would make many users suspicious. Registered as one dated, attributed instance of the inside-job theory circulating in the first week, beside reddit-inside-job-speculation. Inclusion is not endorsement: no captured source establishes intent, and the quoted exchange carries its own counter-argument, that an inside job would have precomputed the keys rather than deriving them on the fly.\n",
      "relation": {
        "kind": "single-post",
        "head_id": null
      },
      "capture": {
        "status": "held",
        "artefact_count": 5,
        "conversation_copies": 0,
        "conversation_posts": 0,
        "conversation_replies": 0,
        "conversation_gaps": []
      }
    },
    {
      "id": "l0lal33tz-2085154479423307782",
      "title": "L0lal33tz 2085154479423307782",
      "url": "https://x.com/L0laL33tz/status/2085154479423307782",
      "author": "L0laL33tz",
      "platform": "x",
      "organisation": null,
      "posted": "2026-08-06T00:02:22Z",
      "role": "commentary",
      "why_registered": "L0la L33tz's objection to reading a chain trace as attribution: any intermediary hop may be an ordinary peer-to-peer transfer, so following the money can lead investigators to people who simply bought coins from a stranger. She adds that she doubts a thief at this scale would deposit at a centralized exchange, while hoping for victims' sake that one did. A direct methodological criticism of the typology at chainalysis-2085126271042830608, which the post quotes.\n",
      "relation": {
        "kind": "single-post",
        "head_id": null
      },
      "capture": {
        "status": "held",
        "artefact_count": 5,
        "conversation_copies": 0,
        "conversation_posts": 0,
        "conversation_replies": 0,
        "conversation_gaps": []
      }
    },
    {
      "id": "bitcoinnewscom-2085117642567020750",
      "title": "Bitcoinnewscom 2085117642567020750",
      "url": "https://x.com/BitcoinNewsCom/status/2085117642567020750",
      "author": "BitcoinNewsCom",
      "platform": "x",
      "organisation": null,
      "posted": "2026-08-05T21:36:00Z",
      "role": "reporting",
      "why_registered": "Bitcoin News's 5 August summary of two movements at once: Galaxy Research's finding that the largest known theft, given as 1,159 BTC across seven attacker addresses taken in 41 minutes, remained untouched with nothing cashed out or mixed and roughly 600 attacker addresses flagged, set against a smaller attacker's 64 BTC mixing run. Secondary throughout: Galaxy's own published totals are held at theblock-galaxy-total and stackernews-galaxy-updated-total, and the mixing trace is primary at mariusoffchain-2084892387445244196. The figures are the article's attribution of Galaxy, not this archive's arithmetic.\n",
      "relation": {
        "kind": "single-post",
        "head_id": null
      },
      "capture": {
        "status": "held",
        "artefact_count": 5,
        "conversation_copies": 0,
        "conversation_posts": 0,
        "conversation_replies": 0,
        "conversation_gaps": []
      }
    },
    {
      "id": "neiljacobs-2084978259079426454",
      "title": "Neiljacobs 2084978259079426454",
      "url": "https://x.com/NeilJacobs/status/2084978259079426454",
      "author": "NeilJacobs",
      "platform": "x",
      "organisation": null,
      "posted": "2026-08-05T12:22:08Z",
      "role": "community-question",
      "why_registered": "Neil Jacobs asking publicly for a forensic analysis of all BLOCKCLOCK models, on the basis that if one carries malware or spyware then bitcoiners need to know immediately. Registered as a dated instance of incident distrust extending from the wallet to Coinkite's other products; the same day's satire at teddybitcoins-2084812101172748464 makes the same claim as a joke. No captured source reports any BLOCKCLOCK finding, and this archive holds no such analysis.\n",
      "relation": {
        "kind": "single-post",
        "head_id": null
      },
      "capture": {
        "status": "held",
        "artefact_count": 2,
        "conversation_copies": 0,
        "conversation_posts": 0,
        "conversation_replies": 0,
        "conversation_gaps": []
      }
    },
    {
      "id": "fractalencrypt-2085199072755884349",
      "title": "Fractalencrypt 2085199072755884349",
      "url": "https://x.com/FractalEncrypt/status/2085199072755884349",
      "author": "FractalEncrypt",
      "platform": "x",
      "organisation": null,
      "posted": "2026-08-06T02:59:34Z",
      "role": "independent-reproduction",
      "why_registered": "FractalEncrypt reporting that entering 99 sixes into a SeedSigner reproduced a live wallet, so its owner had pressed one die face 99 times in December 2022 rather than rolling, with two further wallets showing the same pattern in June and October 2023. It adds that funds on the legacy derivation path were swept 14 to 17 hours later than native SegWit funds stolen the same day, 17 December. Bears on the dice-entropy strand rather than on the libngu defect, though the post does not say which device generated the seeds. Self-reported: the wallets are not identified and the result is not reproduced here.\n",
      "relation": {
        "kind": "single-post",
        "head_id": null
      },
      "capture": {
        "status": "held",
        "artefact_count": 7,
        "conversation_copies": 0,
        "conversation_posts": 0,
        "conversation_replies": 0,
        "conversation_gaps": []
      }
    },
    {
      "id": "lunymoon13-2084971945070666028",
      "title": "Lunymoon13 2084971945070666028",
      "url": "https://x.com/lunymoon13/status/2084971945070666028",
      "author": "lunymoon13",
      "platform": "x",
      "organisation": null,
      "posted": "2026-08-05T11:57:03Z",
      "role": "victim-report",
      "why_registered": "A first-person account addressed to Kevin Loaec of losing an entire stack of more than 6 BTC: hearing about the incident, panicking because the poster believed only a few dice rolls had been used, and moving funds in a hurry. The capture is the opening of the account and stops mid-narrative because it continues in the poster's own replies, which a single-post capture does not hold. Self-reported and not verified here. Related guidance is at kloaec-multisig and kloaec-dice-not-your-fault.\n",
      "relation": {
        "kind": "single-post",
        "head_id": null
      },
      "capture": {
        "status": "held",
        "artefact_count": 2,
        "conversation_copies": 0,
        "conversation_posts": 0,
        "conversation_replies": 0,
        "conversation_gaps": []
      }
    },
    {
      "id": "intcyberdigest-2085013507913687508",
      "title": "Intcyberdigest 2085013507913687508",
      "url": "https://x.com/IntCyberDigest/status/2085013507913687508",
      "author": "IntCyberDigest",
      "platform": "x",
      "organisation": null,
      "posted": "2026-08-05T14:42:12Z",
      "role": "reporting",
      "why_registered": "International Cyber Digest's 5 August summary of the coordinator dispute: stolen coins entering a CoinJoin round run on Kruw's centralised coordinator, tanuki42_'s point that the coordinator could exclude them, Kruw's reply that \"you can't prove you've been robbed. The attacker and the legitimate owner share the same entropy\", and ZachXBT's reply to Kruw quoted in full. Secondary to tanuki42_-2084927029430870179; the Kruw and ZachXBT posts are quoted inside it rather than captured here as primaries. ZachXBT's separate position on tracing this incident is at zachxbt-declines-tracing.\n",
      "relation": {
        "kind": "single-post",
        "head_id": null
      },
      "capture": {
        "status": "held",
        "artefact_count": 2,
        "conversation_copies": 0,
        "conversation_posts": 0,
        "conversation_replies": 0,
        "conversation_gaps": []
      }
    },
    {
      "id": "tonevays-2085023305744973840",
      "title": "Tonevays 2085023305744973840",
      "url": "https://x.com/ToneVays/status/2085023305744973840",
      "author": "ToneVays",
      "platform": "x",
      "organisation": null,
      "posted": "2026-08-05T15:21:08Z",
      "role": "commentary",
      "why_registered": "Tone Vays asking who would maintain COLDCARD firmware if Coinkite were to shut down, noting that at least one person had taken up the task and that the irony writes itself. Registered as a dated instance of the continuity question being asked publicly in the first week. No captured source states that Coinkite is closing, and the archive holds no such announcement.\n",
      "relation": {
        "kind": "single-post",
        "head_id": null
      },
      "capture": {
        "status": "held",
        "artefact_count": 2,
        "conversation_copies": 0,
        "conversation_posts": 0,
        "conversation_replies": 0,
        "conversation_gaps": []
      }
    },
    {
      "id": "tanuki42_-2084927029430870179",
      "title": "Tanuki42_ 2084927029430870179",
      "url": "https://x.com/tanuki42_/status/2084927029430870179",
      "author": "tanuki42_",
      "platform": "x",
      "organisation": null,
      "posted": "2026-08-05T08:58:34Z",
      "role": "on-chain-analysis",
      "why_registered": "tanuki42 identifying the mixing round in mariusoffchain-2084892387445244196 as a Wasabi Wallet CoinJoin coordinated by Kruw's entirely centralised coordinator, and arguing that the coordinator could exclude the stolen coins at any time but consistently chooses not to. The opening of the coordinator-responsibility dispute that intcyberdigest-2085013507913687508 reports that afternoon. Contested: Kruw's answer, quoted in that report, is that the theft cannot be proved because attacker and owner share the same entropy.\n",
      "relation": {
        "kind": "single-post",
        "head_id": null
      },
      "capture": {
        "status": "held",
        "artefact_count": 5,
        "conversation_copies": 0,
        "conversation_posts": 0,
        "conversation_replies": 0,
        "conversation_gaps": []
      }
    },
    {
      "id": "coldcardwallet-2085149280382181519",
      "title": "Coldcardwallet 2085149280382181519",
      "url": "https://x.com/COLDCARDwallet/status/2085149280382181519",
      "author": "COLDCARDwallet",
      "platform": "x",
      "organisation": null,
      "posted": "2026-08-05T23:41:43Z",
      "role": "vendor-response",
      "why_registered": "Coinkite's one-line reply to a poster alleging that investors knew before customers did and that the 2021 firmware bug went unaddressed for five years: \"Everything is disclosed here\", linking the page registered at coinkite-historical-disclosures. Registered for what the vendor answered with rather than as an answer to the allegation, which the reply does not address point by point.\n",
      "relation": {
        "kind": "single-post",
        "head_id": null
      },
      "capture": {
        "status": "held",
        "artefact_count": 5,
        "conversation_copies": 0,
        "conversation_posts": 0,
        "conversation_replies": 0,
        "conversation_gaps": []
      }
    },
    {
      "id": "bradytc_-2085178689944195521",
      "title": "Bradytc_ 2085178689944195521",
      "url": "https://x.com/bradytc_/status/2085178689944195521",
      "author": "bradytc_",
      "platform": "x",
      "organisation": null,
      "posted": "2026-08-06T01:38:35Z",
      "role": "on-chain-analysis",
      "why_registered": "The author of the coldcardwatch tracker, registered at coldcard-watch, stating its accounting policy: it publishes only verifiable on-chain minimums, and Galaxy Research's wider figures now sit on the chart as a separate toggleable layer rather than being folded into its own total. Directly relevant to why the published totals differ, because it is the tracker's own statement of what its number counts. This site's tracker readings are taken from held captures, never from this post.\n",
      "relation": {
        "kind": "single-post",
        "head_id": null
      },
      "capture": {
        "status": "held",
        "artefact_count": 5,
        "conversation_copies": 0,
        "conversation_posts": 0,
        "conversation_replies": 0,
        "conversation_gaps": []
      }
    },
    {
      "id": "callebtc-2085024465851674789",
      "title": "Callebtc 2085024465851674789",
      "url": "https://x.com/callebtc/status/2085024465851674789",
      "author": "callebtc",
      "platform": "x",
      "organisation": null,
      "posted": "2026-08-05T15:25:45Z",
      "role": "ai-security-response",
      "why_registered": "calle's 5 August answer to complaints about the Red Team's reporting volume: most critical reports so far were quickly verified by project owners, most critical findings are reproduced with a proof of concept in a local regtest environment before being sent, recipients are asked to use AI to verify them, and the team apologises for adding stress while arguing speed matters because others outside the team will reach the same findings anyway. The clearest captured statement of the team's reporting standard, beside the method note at callebtc-2085024461992939882 in the same thread. Self-reported.\n",
      "relation": {
        "kind": "single-post",
        "head_id": null
      },
      "capture": {
        "status": "held",
        "artefact_count": 7,
        "conversation_copies": 0,
        "conversation_posts": 0,
        "conversation_replies": 0,
        "conversation_gaps": []
      }
    },
    {
      "id": "afilini-2085269060028170742",
      "title": "Afilini 2085269060028170742",
      "url": "https://x.com/afilini/status/2085269060028170742",
      "author": "afilini",
      "platform": "x",
      "organisation": null,
      "posted": "2026-08-06T07:37:40Z",
      "role": "independent-technical-analysis",
      "why_registered": "Alekos Filini's 6 August view on what Coinkite could reasonably have done: he does not think better entropy testing would have caught this, and argues that building a proper emulator might have. From the author of the migration analysis at afilini-seed-rng-migration-report and the threads at afilini-2085028027499413710 and afilini-2085021651918332071. Registered as a polled thread so the replies, where the disagreement about what is testable plays out, are held with it.\n",
      "relation": {
        "kind": "conversation-head",
        "head_id": null
      },
      "capture": {
        "status": "held",
        "artefact_count": 32,
        "conversation_copies": 12,
        "conversation_posts": 13,
        "conversation_replies": 7,
        "conversation_gaps": []
      }
    },
    {
      "id": "slush-2085628203268252036",
      "title": "Objection to browser-based dice seed tools",
      "url": "https://x.com/slush/status/2085628203268252036",
      "author": "slush",
      "platform": "x",
      "organisation": null,
      "posted": "2026-08-07T07:24:47Z",
      "role": "social-statement",
      "why_registered": "Quote-posts the offline dice-seed tool promoted at\ndotkrueger-2085507527178092813, a single-file browser page that converts sixty\nphysical d6 rolls into a twelve-word BIP-39 phrase, and calls it an\nover-reaction, terrible advice, and a disaster in the making, on the ground that\nit asks owners to generate recovery seeds with custom vibe-coded software on a\nstandard computer. Held because it is a direct objection to one of the concrete\nmigration remedies circulating that week, and because it names the general\nrisk, ad-hoc seed-generation tools written quickly under pressure, that the\nincident itself is an instance of. Interest: the account is Marek Palatinus, a\nco-founder of SatoshiLabs, which makes the competing Trezor hardware wallet, and\nthat is stated here because the post is a criticism of advice being given to\nCOLDCARD owners looking for somewhere to go. The assessment of the tool is the\nposter's own and is not verified here.\n",
      "relation": {
        "kind": "single-post",
        "head_id": null
      },
      "capture": {
        "status": "held",
        "artefact_count": 2,
        "conversation_copies": 0,
        "conversation_posts": 0,
        "conversation_replies": 0,
        "conversation_gaps": []
      }
    },
    {
      "id": "callebtc-2085329159094489183",
      "title": "Open-weights models doing the vulnerability search",
      "url": "https://x.com/callebtc/status/2085329159094489183",
      "author": "callebtc",
      "platform": "x",
      "organisation": null,
      "posted": "2026-08-06T11:36:29Z",
      "role": "social-statement",
      "why_registered": "calle argues that not a single vulnerability in this wave was found by a US\nfrontier model, and that roughly $10k a day is instead being spent on\nopen-weights models, naming Kimi K3 and Qwen 3.8, to find vulnerabilities in\nBitcoin infrastructure. The attached screenshot shows a coding assistant\nrefusing a request during a review of a secp256k1 sample with a notice offering\nTrusted Access to security professionals, circled in red. Interest: this\nproject's watch list records calle as a Bitcoin Red Team participant, so he is\ndescribing work and spending he takes part in. The spend figure and the claim\nthat no frontier model produced a finding are the poster's own and are not\nverified here.\n",
      "relation": {
        "kind": "single-post",
        "head_id": null
      },
      "capture": {
        "status": "held",
        "artefact_count": 5,
        "conversation_copies": 0,
        "conversation_posts": 0,
        "conversation_replies": 0,
        "conversation_gaps": []
      }
    },
    {
      "id": "nneuman-2085356124622954661",
      "title": "US models versus Chinese open-weights models",
      "url": "https://x.com/Nneuman/status/2085356124622954661",
      "author": "Nneuman",
      "platform": "x",
      "organisation": null,
      "posted": "2026-08-06T13:23:38Z",
      "role": "social-statement",
      "why_registered": "Quote-posts calle's claim, held at callebtc-2085329159094489183, that not a\nsingle vulnerability in this wave was found by a US frontier model and that\nroughly $10k a day is going to open-weights models such as Kimi K3 and Qwen 3.8,\nand adds that US model makers publicise their models breaking into systems while\ndefenders of core open-source infrastructure in a trillion-dollar asset\necosystem have to rely on Chinese models. It tags a US technology-policy\nofficial, which makes it an attempt to put the incident's AI-review story in\nfront of policymakers rather than only the Bitcoin audience. Interest: the\nposter is the chief executive of Casa, a multi-key custody provider that\npublished its own incident guidance, held at casa-incident-guidance. The claim\nabout which models produced findings originates with calle and is not verified\nhere.\n",
      "relation": {
        "kind": "single-post",
        "head_id": null
      },
      "capture": {
        "status": "held",
        "artefact_count": 2,
        "conversation_copies": 0,
        "conversation_posts": 0,
        "conversation_replies": 0,
        "conversation_gaps": []
      }
    },
    {
      "id": "rob1ham-2085599751769124869",
      "title": "Encouragement to start hunting bugs unprompted",
      "url": "https://x.com/Rob1Ham/status/2085599751769124869",
      "author": "Rob1Ham",
      "platform": "x",
      "organisation": null,
      "posted": "2026-08-07T05:31:44Z",
      "role": "social-statement",
      "why_registered": "Rob Hamilton reports that someone asked whether they could join the red team,\nthat after a two-minute conversation they tried the problem themselves and made\nsubstantial progress, and that there is nothing special about it: you just hunt\nfor bugs. Held as a small dated record of how the red-team effort was recruiting\nand framing itself in its second week, alongside the status posts already in the\nregister at rob1ham-2084523368783438198 and rob1ham-2085047535807180895. It\ncontains no finding, names no project and identifies no vulnerability. Hamilton\nis AnchorWatch's chief executive, a conflict disclosed throughout this register.\nThe account of the exchange is his own.\n",
      "relation": {
        "kind": "single-post",
        "head_id": null
      },
      "capture": {
        "status": "held",
        "artefact_count": 2,
        "conversation_copies": 0,
        "conversation_posts": 0,
        "conversation_replies": 0,
        "conversation_gaps": []
      }
    },
    {
      "id": "mandrik-2085648395994087424",
      "title": "The disclosure dilemma stated as a question",
      "url": "https://x.com/Mandrik/status/2085648395994087424",
      "author": "Mandrik",
      "platform": "x",
      "organisation": null,
      "posted": "2026-08-07T08:45:01Z",
      "role": "social-statement",
      "why_registered": "Two sentences putting the responsible-disclosure argument as a practical\nproblem rather than a moral one: if the COLDCARD bug had been disclosed\nprivately first, how would anyone have told every owner to move funds\nimmediately without setting off mass panic. Held because it states, more\nneatly than most of the week's exchanges, why the usual disclosure norm is hard\nto apply to a defect in already-shipped keys, and it sits alongside the sharper\nobjections held at fractalencrypt-2085584132420043263 and the caution at\nmilessuter-2084619892699897882. It is a rhetorical question and asserts no facts\nthis record could check.\n",
      "relation": {
        "kind": "single-post",
        "head_id": null
      },
      "capture": {
        "status": "held",
        "artefact_count": 2,
        "conversation_copies": 0,
        "conversation_posts": 0,
        "conversation_replies": 0,
        "conversation_gaps": []
      }
    },
    {
      "id": "orangesurfbtc-2085676831320035381",
      "title": "Slipstream migration total, 5,681 BTC",
      "url": "https://x.com/OrangeSurfBTC/status/2085676831320035381",
      "author": "OrangeSurfBTC",
      "platform": "x",
      "organisation": null,
      "posted": "2026-08-07T10:38:01Z",
      "role": "social-statement",
      "why_registered": "The latest reading in OrangeSurf's running count of bitcoin moved out of\nmultisig wallets through Slipstream, presumed to be incident migration: at\nleast 5,681 BTC, against more than 3,650 BTC on 4 August and 5,371 BTC hours\nearlier the same night. This reading adds a breakdown by quorum, and the post\nsays the large majority of the migrated bitcoin came from 2-of-3 wallets. Two\ncharts are attached. No transaction set, methodology or counterfactual is\npublished with it, so both the total and the inference that the spends are\nincident migration remain the author's own.\n",
      "relation": {
        "kind": "single-post",
        "head_id": null
      },
      "capture": {
        "status": "held",
        "artefact_count": 5,
        "conversation_copies": 0,
        "conversation_posts": 0,
        "conversation_replies": 0,
        "conversation_gaps": []
      }
    },
    {
      "id": "callebtc-2085418268689391792",
      "title": "Red Team update at 55 hours",
      "url": "https://x.com/callebtc/status/2085418268689391792",
      "author": "callebtc",
      "platform": "x",
      "organisation": null,
      "posted": "2026-08-06T17:30:35Z",
      "role": "social-statement",
      "why_registered": "calle's next status post in the Bitcoin Red Team series: 55 hours into the\ncampaign, 24 people working, 425 projects scanned and 1,029 combined high and\ncritical findings. It continues the count held at callebtc-2085024458012586286\nfrom the previous day, which gave 16 people, 390 projects and 85 critical plus\n635 high findings, so this records both the people and project growth and the\nrate at which severe findings accumulated. A chart is attached. The findings\nthemselves are not public and are said to be held for disclosure, so none of\nthe counts can be rechecked here.\n",
      "relation": {
        "kind": "single-post",
        "head_id": null
      },
      "capture": {
        "status": "held",
        "artefact_count": 5,
        "conversation_copies": 0,
        "conversation_posts": 0,
        "conversation_replies": 0,
        "conversation_gaps": []
      }
    },
    {
      "id": "danwilcz-2085674528534048781",
      "title": "Position that the failure was error, not design",
      "url": "https://x.com/danWilcz/status/2085674528534048781",
      "author": "danWilcz",
      "platform": "x",
      "organisation": null,
      "posted": "2026-08-07T10:28:52Z",
      "role": "social-statement",
      "why_registered": "Daniel Wilczynski says he does not think the ColdCard hack was anything\nnefarious, that the vendor simply made a major mistake, and that AI has become\nmuch better at finding security vulnerabilities over the past year, which is why\nthis was exploited now. Held as a compact statement of the not-malicious reading,\nwhich this record carries alongside the insinuation material it also holds,\nincluding the resurfaced 2021 entropy joke at bramk-2084618965226074604 and the\npseudonym-attribution gist. Both the verdict and the AI-timing explanation are\nthe poster's own and are not verified here.\n",
      "relation": {
        "kind": "single-post",
        "head_id": null
      },
      "capture": {
        "status": "held",
        "artefact_count": 2,
        "conversation_copies": 0,
        "conversation_posts": 0,
        "conversation_replies": 0,
        "conversation_gaps": []
      }
    },
    {
      "id": "adelgary-2085270460724379777",
      "title": "Quote-post of the Mallers fail-closed clip",
      "url": "https://x.com/Adelgary/status/2085270460724379777",
      "author": "Adelgary",
      "platform": "x",
      "organisation": null,
      "posted": "2026-08-06T07:43:14Z",
      "role": "social-statement",
      "why_registered": "Three words of text over a 1:28 video of Jack Mallers, whose visible slides\ncontrast what happened - secure entropy unavailable, fallback activated, key\ngenerated, nothing complained - with what the slides say should have happened,\na halt and a refusal to generate. The post quote-posts JW Weatherman calling a\nweak-entropy fallback obviously malicious, and adds that Mallers cannot explain\nit either. The video itself is not held: this capture keeps the post text and\nthe poster frame only. Coinkite's own reply to Mallers disputes the \"fallback\"\nframing and is registered at coldcardwallet-2085541034243600805, so both\npositions are in the record. The characterisations of intent are the posters'\nown and are not verified here.\n",
      "relation": {
        "kind": "single-post",
        "head_id": null
      },
      "capture": {
        "status": "held",
        "artefact_count": 5,
        "conversation_copies": 0,
        "conversation_posts": 0,
        "conversation_replies": 0,
        "conversation_gaps": []
      }
    },
    {
      "id": "jwweatherman_-2084921468337463615",
      "title": "Weak-entropy fallback called deliberate",
      "url": "https://x.com/JWWeatherman_/status/2084921468337463615",
      "author": "JWWeatherman_",
      "platform": "x",
      "organisation": null,
      "posted": "2026-08-05T08:36:28Z",
      "role": "social-statement",
      "why_registered": "A standalone assertion, quoting and replying to nothing, that no competent\ndesigner would build a fallback to weak entropy, compared to an aircraft engine\nfalling back to a nuclear bomb in the wing, and concluding that the arrangement\nwas obviously malicious. It is an inference of intent against the vendor rather\nthan a technical finding, and it is one of the plainest statements of the\nmalice reading that circulated in the first week. The vendor's own contrary\naccount is held at coldcardwallet-2085541034243600805, which argues there was no\nCoinkite fallback at all and that the software generator became reachable\nthrough a link-time error; Block's disclosure, held at block-disclosure,\ndescribes the behaviour as a fallback. The archive holds the reading and the\nvendor's rebuttal side by side. The imputation of intent is the poster's own and\nis not verified here.\n",
      "relation": {
        "kind": "single-post",
        "head_id": null
      },
      "capture": {
        "status": "held",
        "artefact_count": 2,
        "conversation_copies": 0,
        "conversation_posts": 0,
        "conversation_replies": 0,
        "conversation_gaps": []
      }
    },
    {
      "id": "coldcardwallet-2085541034243600805",
      "title": "Vendor correction of the fallback framing",
      "url": "https://x.com/COLDCARDwallet/status/2085541034243600805",
      "author": "COLDCARDwallet",
      "platform": "x",
      "organisation": null,
      "posted": "2026-08-07T01:38:24Z",
      "role": "social-statement",
      "why_registered": "COLDCARD publicly correcting Jack Mallers over the description of a weak\nentropy fallback, and the clearest vendor statement held of how the defect\narose. It says Yasmarang was not Coinkite's fallback but MicroPython's built-in\ngeneral-purpose RNG, added upstream in May 2018, and that it did not enter\nColdcard's seed generation until the libNgU migration in March 2021. It argues\nthe design intent was the opposite of a software fallback: seed generation was\nto rely on the hardware TRNG alone, and setting MICROPY_HW_ENABLE_RNG=0 was\nmeant to disable the software path, but the symbol instead resolved to the\nruntime's default, so the behaviour was inherited from the platform through a\nlink-time error rather than chosen. Mallers's severity alert is held at\nmallers-coldcard-alert, and the guard and generator themselves are tracked as\nrepository sources. The statement of intent is the vendor's own account of its\nown work.\n",
      "relation": {
        "kind": "single-post",
        "head_id": null
      },
      "capture": {
        "status": "held",
        "artefact_count": 2,
        "conversation_copies": 0,
        "conversation_posts": 0,
        "conversation_replies": 0,
        "conversation_gaps": []
      }
    },
    {
      "id": "giacomozucco-2085638047719178341",
      "title": "Endorsement of the vendor's account of the commit",
      "url": "https://x.com/giacomozucco/status/2085638047719178341",
      "author": "giacomozucco",
      "platform": "x",
      "organisation": null,
      "posted": "2026-08-07T08:03:54Z",
      "role": "social-statement",
      "why_registered": "Giacomo Zucco quote-posts a COLDCARD reply reading \"Nvk didn't make that code\nchange\", calls it objectively very credible, and argues that had he made it he\nwould have behaved differently in many ways. Held because it is a named\ncommentator taking a public position in the strand about who wrote the change\nthat introduced the defect. The quoted COLDCARD reply is not registered in its\nown right; this capture holds it only as the quote card inside the post, so the\nrecord has the endorsement without the underlying statement's own page. The\ninference from behaviour is the poster's own reasoning and is not evidence about\nauthorship.\n",
      "relation": {
        "kind": "single-post",
        "head_id": null
      },
      "capture": {
        "status": "held",
        "artefact_count": 2,
        "conversation_copies": 0,
        "conversation_posts": 0,
        "conversation_replies": 0,
        "conversation_gaps": []
      }
    },
    {
      "id": "w_s_bitcoin-2085659409758163436",
      "title": "Counter-example to 'nobody rolls dice'",
      "url": "https://x.com/w_s_bitcoin/status/2085659409758163436",
      "author": "w_s_bitcoin",
      "platform": "x",
      "organisation": null,
      "posted": "2026-08-07T09:28:47Z",
      "role": "social-statement",
      "why_registered": "Wicked answers the claim that nobody is going to roll dice 100 times by pointing\nto his own two-year-old tutorial, \"Create & Verify Your Bitcoin Seed Phrase Using\nDice + Coldcard + SeedSigner\", which he says has 4.6k views on YouTube alone, and\nscreenshots two appreciative viewer comments, one of them about being able to\nverify that signing devices really use the rolled entropy. Held in the\ndice-mitigation strand, where this account's earlier alarm and same-day\nwalk-back are already preserved at w_s_bitcoin-2084991031724957808 and\nw_s_bitcoin-2085105794950029561. Interest: the post promotes the poster's own\ncontent, and the evidence offered for the claim is that content's reception. The\nview count and the selected comments are the poster's presentation of his own\nmaterial and are not verified here.\n",
      "relation": {
        "kind": "single-post",
        "head_id": null
      },
      "capture": {
        "status": "held",
        "artefact_count": 5,
        "conversation_copies": 0,
        "conversation_posts": 0,
        "conversation_replies": 0,
        "conversation_gaps": []
      }
    },
    {
      "id": "basedlayer-2085644867556852048",
      "title": "Criticism of the Bitcoin Security Consortium's response",
      "url": "https://x.com/basedlayer/status/2085644867556852048",
      "author": "basedlayer",
      "platform": "x",
      "organisation": null,
      "posted": "2026-08-07T08:31:00Z",
      "role": "social-statement",
      "why_registered": "Fernando Nikolić arguing that of the companies on the Bitcoin Security\nConsortium member list only two, Block and Galaxy, visibly stepped up after the\nColdcard exploits, and that he is not only talking about funding the Red Team\nfrom the US$15M pledged but about using any resource at all. He credits Block's\nengineering team and @intangiblecoins with seven days of sustained work, says\nthe consortium itself contributed three retweets, and calls the optics\nhorrible. It is the only held source raising the consortium's response, and it\nsupplies the pledge figure and the membership framing that the record does not\notherwise hold. The same account's earlier influencers-over-engineers post is\nregistered separately. The membership claim, the US$15M figure and the judgement\nof who did what are the poster's own and are not verified here.\n",
      "relation": {
        "kind": "single-post",
        "head_id": null
      },
      "capture": {
        "status": "held",
        "artefact_count": 2,
        "conversation_copies": 0,
        "conversation_posts": 0,
        "conversation_replies": 0,
        "conversation_gaps": []
      }
    },
    {
      "id": "lopp-2085430345080422700",
      "title": "Casa incident-response recap pointer",
      "url": "https://x.com/lopp/status/2085430345080422700",
      "author": "lopp",
      "platform": "x",
      "organisation": null,
      "posted": "2026-08-06T18:18:34Z",
      "role": "social-statement",
      "why_registered": "Jameson Lopp introduces a Casa blog post, \"The Rise of the Machines\", described\nas his recap of how Casa prepared for this problem, how it responded to the\nsecurity incident, and his thoughts on the evolving threat environment; the\nlinked article is held separately at casa-rise-of-machines. The interest is\ndirect and worth stating: Lopp is Casa's CTO, and this is a collaborative\ncustody vendor's account of its own incident response, published in the week its\ncustomers were migrating COLDCARD keys out of Casa vault policies. Held as the\npost that carried that recap to Lopp's audience and as a dated marker of when\nCasa published its account. The vendor's characterisation of its own preparation\nand response is its own and is not verified here.\n",
      "relation": {
        "kind": "single-post",
        "head_id": null
      },
      "capture": {
        "status": "held",
        "artefact_count": 2,
        "conversation_copies": 0,
        "conversation_posts": 0,
        "conversation_replies": 0,
        "conversation_gaps": []
      }
    },
    {
      "id": "jamesob-2085555839797166530",
      "title": "Rebuttal of the vendor's fallback correction",
      "url": "https://x.com/jamesob/status/2085555839797166530",
      "author": "jamesob",
      "platform": "x",
      "organisation": null,
      "posted": "2026-08-07T02:37:14Z",
      "role": "social-statement",
      "why_registered": "James O'Beirne replies to Coinkite's \"extremely important correction\" to Jack\nMallers, held at coldcardwallet-2085541034243600805, which argued there was no\nweak-entropy fallback and that Yasmarang was MicroPython's general-purpose RNG\nreached through a link-time error. O'Beirne calls that hairsplitting and\nmisdirection, says the device absolutely did fall back to weak entropy, and says\nthe Yasmarang implementation placed in libngu was weaker than MicroPython's\nbecause it used hardcoded constants, linking a pinned commit and line range in\nswitck/libngu ngu/random.c. He adds that he warned Coinkite about this issue and\nthat at least one other person did four years before him. This is a direct\nexchange between the vendor and the auditor whose disclosure history the record\nalready carries; the file he cites is itself held at libngu-random-c, so the\ncomparison can be checked against the source rather than taken on assertion. The\nwarning history and the characterisation of the correction are his own.\n",
      "relation": {
        "kind": "single-post",
        "head_id": null
      },
      "capture": {
        "status": "held",
        "artefact_count": 2,
        "conversation_copies": 0,
        "conversation_posts": 0,
        "conversation_replies": 0,
        "conversation_gaps": []
      }
    },
    {
      "id": "w_s_bitcoin-2085640428729102484",
      "title": "libngu image macro",
      "url": "https://x.com/w_s_bitcoin/status/2085640428729102484",
      "author": "w_s_bitcoin",
      "platform": "x",
      "organisation": null,
      "posted": "2026-08-07T08:13:22Z",
      "role": "social-statement",
      "why_registered": "An image macro captioned \"He's beginning to believe\": a cartoon apple, matching\nthe account's avatar, stands between a stone slab quoting \"Lost coins only make\neveryone else's coins worth slightly more. Think of it as a donation to\neveryone. - Satoshi Nakamoto\" and an open doorway labelled \"libngu\". The joke\nturns on whether to look next at libngu, the Coinkite library that appears in the\nentropy models this record holds. It makes no factual claim; its value here is as\na dated example of how the incident was being talked about within the week, not\nas evidence of anything.\n",
      "relation": {
        "kind": "single-post",
        "head_id": null
      },
      "capture": {
        "status": "held",
        "artefact_count": 5,
        "conversation_copies": 0,
        "conversation_posts": 0,
        "conversation_replies": 0,
        "conversation_gaps": []
      }
    },
    {
      "id": "milessuter-2085371820371304884",
      "title": "Recommendation of the Presidio Bitcoin session",
      "url": "https://x.com/milessuter/status/2085371820371304884",
      "author": "milessuter",
      "platform": "x",
      "organisation": null,
      "posted": "2026-08-06T14:26:00Z",
      "role": "social-statement",
      "why_registered": "Miles Suter recommending Presidio Bitcoin's Friday breakdown of the Coldcard\nsituation as the best and most timely one he saw, and praising Steve Lee\n(@moneyball). It quote-posts Lee's announcement of the PB Media Archive, a\nsearchable index of 77 Presidio Bitcoin podcast episodes and 39 of another\nseries. Held as a pointer to a same-week discussion of the incident that this\nrecord does not otherwise hold. Suter works on bitcoin at Block, which is a\nparty in this record through Bitkey and Block's engineering response, and that\naffiliation bears on the recommendation. The assessment is his.\n",
      "relation": {
        "kind": "single-post",
        "head_id": null
      },
      "capture": {
        "status": "held",
        "artefact_count": 2,
        "conversation_copies": 0,
        "conversation_posts": 0,
        "conversation_replies": 0,
        "conversation_gaps": []
      }
    },
    {
      "id": "neiljacobs-2085391351340838938",
      "title": "Meetup attendance and renewed purpose",
      "url": "https://x.com/NeilJacobs/status/2085391351340838938",
      "author": "NeilJacobs",
      "platform": "x",
      "organisation": null,
      "posted": "2026-08-06T15:43:37Z",
      "role": "social-statement",
      "why_registered": "Neil Jacobs reports attending a Bitcoin meetup in Miami where he was told\nattendance was about two to three times higher than usual, calls the COLDCARD\nincidents tragic, and argues they have reignited a sense of purpose and a\ndetermination to build better products. Held as a dated example of the\nconstructive strand of community reaction, against the anger and vendor-viability\nthreads registered around it. The attendance figure is second-hand within the\npost itself - the poster says he was told it - and neither it nor the causal link\nto the incident is verified here.\n",
      "relation": {
        "kind": "single-post",
        "head_id": null
      },
      "capture": {
        "status": "held",
        "artefact_count": 2,
        "conversation_copies": 0,
        "conversation_posts": 0,
        "conversation_replies": 0,
        "conversation_gaps": []
      }
    },
    {
      "id": "coldcardwallet-2085572285608366139",
      "title": "Vendor position on why the bug survived five years",
      "url": "https://x.com/COLDCARDwallet/status/2085572285608366139",
      "author": "COLDCARDwallet",
      "platform": "x",
      "organisation": null,
      "posted": "2026-08-07T03:42:35Z",
      "role": "social-statement",
      "why_registered": "Replying to a hostile comment, COLDCARD states its position on discoverability:\nthe bug lived in public for five years, even third-party researchers did not find\nit, and the vendor believes it took the latest LLM models to find it. Held\nbecause it is the vendor's own compact public account of why the defect went\nunnoticed, and because other material held here runs against it: Lopp's explanation that the defect sat in the build system and\nthat Ledger DonJon's repeated reviews missed it, a claim of a discovery eleven\nmonths earlier that was withheld, and a claimed drain report four years earlier.\nThe archive holds the vendor's position and those counter-claims side by side and\ndoes not resolve between them; none of them is verified here.\n",
      "relation": {
        "kind": "single-post",
        "head_id": null
      },
      "capture": {
        "status": "held",
        "artefact_count": 2,
        "conversation_copies": 0,
        "conversation_posts": 0,
        "conversation_replies": 0,
        "conversation_gaps": []
      }
    },
    {
      "id": "tftc21-2085518519945638262",
      "title": "Origin story of the Red Team scanning push",
      "url": "https://x.com/TFTC21/status/2085518519945638262",
      "author": "TFTC21",
      "platform": "x",
      "organisation": null,
      "posted": "2026-08-07T00:08:56Z",
      "role": "social-statement",
      "why_registered": "A media account's summary of how the Bitcoin Red Team began, quoting Rob\nHamilton's own account, which it also quote-posts: Kimi K3 went to open weights\non 27 July, three days before the disclosure, Hamilton began scanning Bitcoin\ninfrastructure and found most projects were not using AI for defensive security,\nand his replies to calle predate the initiative by a day. The two quoted lines\nare that for ten to thirty dollars you can likely scan most small or medium code\nbases, and that attackers will do this if they have not already, so defenders'\nsecurity posture has to change. Held as a compact dated origin account for the\nscanning effort whose figures this record holds throughout. The account and the\ncost figure are Hamilton's, relayed by the outlet, and are not verified here.\n",
      "relation": {
        "kind": "single-post",
        "head_id": null
      },
      "capture": {
        "status": "held",
        "artefact_count": 2,
        "conversation_copies": 0,
        "conversation_posts": 0,
        "conversation_replies": 0,
        "conversation_gaps": []
      }
    },
    {
      "id": "rob1ham-2085494034026598854",
      "title": "Red Team origin dates, scanning costs and disclosure advice",
      "url": "https://x.com/Rob1Ham/status/2085494034026598854",
      "author": "Rob1Ham",
      "platform": "x",
      "organisation": null,
      "posted": "2026-08-06T22:31:38Z",
      "role": "social-statement",
      "why_registered": "Rob Hamilton dates the start of the Red Team initiative by pointing at a reply\nof his to @callebtc one day earlier, notes that Kimi K3 went open weights on 27\nJuly, and says his group was already red-teaming its own infrastructure as it\nlaunched. He argues that after the Coldcard hack it became evident most software\nmaintainers were not using frontier AI tools for defensive security, puts the\ncost of scanning most small or medium codebases at $10 to $30 in credits,\ncredits @opencode for multi-model access, urges projects to add a security.md\nfile so responsible disclosure has a clean path, and asks readers to donate to\nthe @OpenSats red team fund. Two interests: Hamilton works at AnchorWatch, a\ncommercial custody provider, and the post solicits funding for the effort he\nleads. Held for the dates and cost figures, which are among the most specific\npublished about the post-incident scanning campaign; they are his own and are\nnot verified here.\n",
      "relation": {
        "kind": "single-post",
        "head_id": null
      },
      "capture": {
        "status": "held",
        "artefact_count": 2,
        "conversation_copies": 0,
        "conversation_posts": 0,
        "conversation_replies": 0,
        "conversation_gaps": []
      }
    },
    {
      "id": "dale21m-2085578950684905813",
      "title": "Support-call account of owner knowledge",
      "url": "https://x.com/Dale21M/status/2085578950684905813",
      "author": "Dale21M",
      "platform": "x",
      "organisation": null,
      "posted": "2026-08-07T04:09:04Z",
      "role": "social-statement",
      "why_registered": "Dale Warburton, whose account describes a bitcoin inheritance practice, says he\nhas taken more than a dozen calls helping people through the incident and found\nit disheartening how few understand self-custody basics, adding that he spent two\nweeks learning before buying any bitcoin. A first-hand report on what the people\nseeking help actually knew, from someone doing the helping, which is a vantage\nthe record otherwise has little of. He works in the self-custody advice field, so\nthe observation comes from a commercially interested position. The call count and\nthe characterisation of those callers are his own and cannot be checked here.\n",
      "relation": {
        "kind": "single-post",
        "head_id": null
      },
      "capture": {
        "status": "held",
        "artefact_count": 2,
        "conversation_copies": 0,
        "conversation_posts": 0,
        "conversation_replies": 0,
        "conversation_gaps": []
      }
    },
    {
      "id": "_checkonchain-2085614739720400967",
      "title": "Long-term holder supply effect measurement",
      "url": "https://x.com/_checkonchain/status/2085614739720400967",
      "author": "_checkonchain",
      "platform": "x",
      "organisation": null,
      "posted": "2026-08-07T06:31:17Z",
      "role": "social-statement",
      "why_registered": "Checkonchain reports that the incident cut Long-Term Holder supply by about\n233,000 BTC, a 1.38% fall from its recent all-time high, and asks whether the\nemergency migration of coins has skewed the on-chain metrics analysts use to\nread Bitcoin. It points to a newsletter piece by @_Checkmatey_ documenting the\nsize and scale of the change across network activity and on-chain supply\nstructure and assessing its effect on several key metrics; a chart is attached\nand the linked piece is not currently held in this archive. Held because it is\none of the few attempts in the record to measure the incident's effect on the\nwider chain rather than to count losses, and because a mass migration that resets\ncoin ages is a measurement problem for anyone reading on-chain data from this\nperiod. Checkonchain is an analytics business and the post promotes its own\nnewsletter; the figures and the method behind them are theirs and are not\nverified here.\n",
      "relation": {
        "kind": "single-post",
        "head_id": null
      },
      "capture": {
        "status": "held",
        "artefact_count": 5,
        "conversation_copies": 0,
        "conversation_posts": 0,
        "conversation_replies": 0,
        "conversation_gaps": []
      }
    },
    {
      "id": "occamicrypto-2085550568349835323",
      "title": "Dismissal of the vendor correction",
      "url": "https://x.com/OccamiCrypto/status/2085550568349835323",
      "author": "OccamiCrypto",
      "platform": "x",
      "organisation": null,
      "posted": "2026-08-07T02:16:17Z",
      "role": "social-statement",
      "why_registered": "The direct rejoinder to COLDCARD's correction, headed \"Extremely pointless\ncorrection\", quoting the vendor's line that Yasmarang was MicroPython's\nbuilt-in general-purpose RNG and answering that the provenance changes nothing\nbecause the coins were stolen either way. Held as the contrary side of the same\nexchange, beside coldcardwallet-2085541034243600805, and as a compact statement\nof the view that the distinction between inherited and chosen behaviour is a\ndistinction without a difference. The argument is the poster's own and this\nproject does not decide between the two.\n",
      "relation": {
        "kind": "single-post",
        "head_id": null
      },
      "capture": {
        "status": "held",
        "artefact_count": 2,
        "conversation_copies": 0,
        "conversation_posts": 0,
        "conversation_replies": 0,
        "conversation_gaps": []
      }
    },
    {
      "id": "w_s_bitcoin-2085462390150242408",
      "title": "Retirement attack reframed as state seizure",
      "url": "https://x.com/w_s_bitcoin/status/2085462390150242408",
      "author": "w_s_bitcoin",
      "platform": "x",
      "organisation": null,
      "posted": "2026-08-06T20:25:54Z",
      "role": "social-statement",
      "why_registered": "Argues that the real retirement attack will not come through code but by force,\nwhen governments begin seizing bitcoin held on exchanges as their fiat regimes\nfail, and that this should always have been the primary concern of anyone saving\nin self custody. It quotes and replies to nothing and engages none of the\nincident's technical facts. Its connection to the record is the term: retirement\nattack is the vendor's own marketing phrase, and COLDCARD's 2021 claim that its\ndevices made such attacks impossible is held at\ncoldcard-retirement-attack-claim. Held as a reaction that redirects that phrase\naway from the vendor rather than as evidence about the incident. The prediction\nis the poster's own and is not verified here.\n",
      "relation": {
        "kind": "single-post",
        "head_id": null
      },
      "capture": {
        "status": "held",
        "artefact_count": 2,
        "conversation_copies": 0,
        "conversation_posts": 0,
        "conversation_replies": 0,
        "conversation_gaps": []
      }
    },
    {
      "id": "francispouliot_-2085466597414883373",
      "title": "Red Team as a mindset",
      "url": "https://x.com/francispouliot_/status/2085466597414883373",
      "author": "francispouliot_",
      "platform": "x",
      "organisation": null,
      "posted": "2026-08-06T20:42:37Z",
      "role": "social-statement",
      "why_registered": "Francis Pouliot writes that bugs are being fixed left and right, that the\nBitcoin Red Team is an actual team of people but far from the only one, that\nthere are dozens and probably hundreds of Bitcoin red teams, and that Bitcoin\nRed Team is above all a mindset, ending with \"NO SURRENDER / STRONGER THAN EVER\n/ THIS OUR LAND\". Pouliot runs Bull Bitcoin, a bitcoin exchange whose own\nservices were disrupted in the same week; this record separately holds Bull\nBitcoin's advisory about Boltz suspending services. Held as a dated example of\nthe morale register the industry response took rather than for factual content.\nThe claim that dozens or hundreds of red teams exist is the poster's own and is\nnot verified here.\n",
      "relation": {
        "kind": "single-post",
        "head_id": null
      },
      "capture": {
        "status": "held",
        "artefact_count": 2,
        "conversation_copies": 0,
        "conversation_posts": 0,
        "conversation_replies": 0,
        "conversation_gaps": []
      }
    },
    {
      "id": "orangesurfbtc-2085513982043963560",
      "title": "Slipstream multisig migration update: 5,371 BTC",
      "url": "https://x.com/OrangeSurfBTC/status/2085513982043963560",
      "author": "OrangeSurfBTC",
      "platform": "x",
      "organisation": null,
      "posted": "2026-08-06T23:50:54Z",
      "role": "social-statement",
      "why_registered": "OrangeSurf reports that at least 5,371 BTC, about $345 million at the time, have\nmigrated out of multisig wallets via Slipstream, quoting his own 5 August post\nthat gave 3,890 BTC. Two mempool.space Research charts are attached, both\nplotting cumulative multisig any-M-of-N BTC output in MARA blocks since height\n860,000. The figure counts private-submission multisig migration, not losses,\nand the poster is associated with mempool.space Research, whose charts the post\ncarries. Held as one dated point in a running series this record keeps in full so\nthe migration curve can be read rather than summarised; the count, the method\nbehind it and the attribution of those flows to incident migration are the\nmonitor's own and are not verified here.\n",
      "relation": {
        "kind": "single-post",
        "head_id": null
      },
      "capture": {
        "status": "held",
        "artefact_count": 5,
        "conversation_copies": 0,
        "conversation_posts": 0,
        "conversation_replies": 0,
        "conversation_gaps": []
      }
    },
    {
      "id": "pledditor-2085497730084847834",
      "title": "Appreciation of the community response",
      "url": "https://x.com/Pledditor/status/2085497730084847834",
      "author": "Pledditor",
      "platform": "x",
      "organisation": null,
      "posted": "2026-08-06T22:46:20Z",
      "role": "social-statement",
      "why_registered": "An assessment of how bitcoin X responded to the incident, listing the strands\nthe poster credits: rapid diagnosis, specialised domain expertise, frontier AI\ntools scanning code, tracking of the stolen funds, marathon Twitter Spaces on\nbest practice, and broad message-spreading. It adds that even paid Coldcard\npromoters made alert videos, apologised and told affected users what to do, and\nargues nothing comparable follows a typical DeFi rug pull. Held as a dated\nrecord of community sentiment near the end of the first week, and because the\nstrands it names are separately captured here. The characterisations, including\nthe reference to paid promoters, are the poster's own.\n",
      "relation": {
        "kind": "single-post",
        "head_id": null
      },
      "capture": {
        "status": "held",
        "artefact_count": 2,
        "conversation_copies": 0,
        "conversation_posts": 0,
        "conversation_replies": 0,
        "conversation_gaps": []
      }
    },
    {
      "id": "callebtc-2085318442488348811",
      "title": "Red Team inference sponsorship",
      "url": "https://x.com/callebtc/status/2085318442488348811",
      "author": "callebtc",
      "platform": "x",
      "organisation": null,
      "posted": "2026-08-06T10:53:54Z",
      "role": "social-statement",
      "why_registered": "calle announces that vikrantnyc of Cake Wallet gave the Bitcoin Red Team\ncampaign an OpenRouter account carrying US$10,000 of credit, quoting his own\nearlier request for exactly that sponsorship. The primary record of who paid for\nthe campaign's model inference at this point, beside the OpenSats funding already\nheld at callebtc-2085101769500377193. Cake Wallet is a wallet vendor, so this is\na commercial party underwriting a review effort that scans peers' and\ncompetitors' code, and calle leads the campaign being funded. The amount and the\narrangement are as the poster describes them and are not confirmed here.\n",
      "relation": {
        "kind": "single-post",
        "head_id": null
      },
      "capture": {
        "status": "held",
        "artefact_count": 5,
        "conversation_copies": 0,
        "conversation_posts": 0,
        "conversation_replies": 0,
        "conversation_gaps": []
      }
    },
    {
      "id": "callebtc-2085295541353611714",
      "title": "Appeal for sponsored inference",
      "url": "https://x.com/callebtc/status/2085295541353611714",
      "author": "callebtc",
      "platform": "x",
      "organisation": null,
      "posted": "2026-08-06T09:22:54Z",
      "role": "social-statement",
      "why_registered": "An open request for someone to sponsor an OpenRouter account for the security\nreview campaign, saying the cost is high but the yield is too, and inviting\ndirect messages. It quote-posts the Bitcoin Red Team's Situation Report No. 1,\nthe same 4,962-findings-across-390-projects card reported at\ncallebtc-2085024458012586286. Held as a dated record of how the campaign's\ninference bill was being funded in public, alongside the OpenSats route at\ncallebtc-2085101769500377193 and the sponsored-credit offer at\npremai_io-2084552134444662986. Interest: calle leads the campaign and is asking\nfor support for his own effort. The cost and yield claims are his own and are\nnot verified here.\n",
      "relation": {
        "kind": "single-post",
        "head_id": null
      },
      "capture": {
        "status": "held",
        "artefact_count": 2,
        "conversation_copies": 0,
        "conversation_posts": 0,
        "conversation_replies": 0,
        "conversation_gaps": []
      }
    },
    {
      "id": "opensats-2085363706255573313",
      "title": "Code RED red-team support programme",
      "url": "https://x.com/OpenSats/status/2085363706255573313",
      "author": "OpenSats",
      "platform": "x",
      "organisation": null,
      "posted": "2026-08-06T13:53:46Z",
      "role": "social-statement",
      "why_registered": "OpenSats announces that Code RED is live: priority support for people red\nteaming Bitcoin software, including reimbursement of past LLM token costs. It is\nregistered as part of the afilini thread rather than as a standalone post, and\nit is the funder's own announcement of the programme, not a relay of it. OpenSats\nis a party elsewhere in the record - NVK's departure from its board is at\nopensats-nvk-board-departure, and bitschmidty-2084657778610581663 credits\nOpenSats with funding the post-incident Red Team work. The terms are as\nannounced; no held source shows what has actually been disbursed.\n",
      "relation": {
        "kind": "conversation-member",
        "head_id": "afilini-2085269060028170742"
      },
      "capture": {
        "status": "held",
        "artefact_count": 2,
        "conversation_copies": 0,
        "conversation_posts": 0,
        "conversation_replies": 0,
        "conversation_gaps": []
      }
    },
    {
      "id": "thebtcadviser-2085534737117143085",
      "title": "Weekly status update with a service offer",
      "url": "https://x.com/TheBTCAdviser/status/2085534737117143085",
      "author": "TheBTCAdviser",
      "platform": "x",
      "organisation": null,
      "posted": "2026-08-07T01:13:23Z",
      "role": "social-statement",
      "why_registered": "The Bitcoin Adviser's end-of-week update states that the threat remains active,\nthat multiple attackers are still targeting affected seeds, and that observed\nlosses now sit well above $100 million; it repeats that a firmware update does\nnot repair a seed generated under the affected versions and that a new seed and\ncareful migration are needed, while warning against rushing into an unfamiliar\nsetup. The second half is a commercial offer: the first three months of the\ncompany's collaborative custody service free for anyone signing up through\nAugust, with no commitment or early-termination fee, and a contact link.\nInterest: the company sells the collaborative custody service the post\nrecommends, in the same post that supplies the loss figure and threat\nassessment. Those figures and that assessment are the company's own and are not\nverified here.\n",
      "relation": {
        "kind": "single-post",
        "head_id": null
      },
      "capture": {
        "status": "held",
        "artefact_count": 5,
        "conversation_copies": 0,
        "conversation_posts": 0,
        "conversation_replies": 0,
        "conversation_gaps": []
      }
    },
    {
      "id": "btcsessions-2085612074806251668",
      "title": "Dice-roll verification procedure",
      "url": "https://x.com/BTCsessions/status/2085612074806251668",
      "author": "BTCsessions",
      "platform": "x",
      "organisation": null,
      "posted": "2026-08-07T06:20:42Z",
      "role": "social-statement",
      "why_registered": "Replying to grubles' question about whether firmware could ignore dice input,\nBTC Sessions proposes a test to run before rolling a real seed: record a set of\nrolls, enter them on the device, then check the same rolls against\niancoleman.io/bip39; if the results match, re-roll and use the offline device for\nthe seed actually kept. It is the concrete owner-side answer to\nnotgrubles-2085481084888760400, and it sits alongside the independent dice-path\ncheck at portlandhodl-dice-roll-verification. The method sends the test rolls\ninto a browser tool, and its safeguard is that those rolls are discarded and\nre-rolled afterwards. Whether the check catches every failure mode is not\nestablished by any held source; the procedure is the poster's own and is not\nverified here.\n",
      "relation": {
        "kind": "single-post",
        "head_id": null
      },
      "capture": {
        "status": "held",
        "artefact_count": 2,
        "conversation_copies": 0,
        "conversation_posts": 0,
        "conversation_replies": 0,
        "conversation_gaps": []
      }
    },
    {
      "id": "skwp-2085475419386519875",
      "title": "Swan's code-review pipeline published as a template",
      "url": "https://x.com/skwp/status/2085475419386519875",
      "author": "skwp",
      "platform": "x",
      "organisation": null,
      "posted": "2026-08-06T21:17:40Z",
      "role": "social-statement",
      "why_registered": "Yan Pritzker describes the process Swan uses for every change that reaches\nproduction, a deterministically orchestrated LLM pipeline plus GitHub lockdowns\nand rules, with a human review required afterwards, and invites other teams to\ncopy it. The attached diagram sets out the detail: five review lenses run in\nparallel with at least three required to succeed, covering architecture, semantic,\nperformance, security and quality; a change-request gate requiring a ticket link;\nsupply-chain and static analysis with extended security queries, a manifest CVE\ngate failing on high, third-party actions vendored through an internal mirror and\nnetwork egress locked at install; and a final human review in which code owners\nand the security team sign off and agent-authored changes need independent human\napproval. Held because the incident turned AI code review into a live argument,\nand this is a concrete published process rather than a position on it, usable as\na document by anyone assessing that argument. Pritzker is at Swan and the post\npromotes Swan's own engineering practice. Nothing here establishes that the\npipeline works as described or that it would have caught this defect.\n",
      "relation": {
        "kind": "single-post",
        "head_id": null
      },
      "capture": {
        "status": "held",
        "artefact_count": 7,
        "conversation_copies": 0,
        "conversation_posts": 0,
        "conversation_replies": 0,
        "conversation_gaps": []
      }
    },
    {
      "id": "walkeramerica-2085437265233473821",
      "title": "Red Team credit and the BIP110 factional split",
      "url": "https://x.com/WalkerAmerica/status/2085437265233473821",
      "author": "WalkerAmerica",
      "platform": "x",
      "organisation": null,
      "posted": "2026-08-06T18:46:04Z",
      "role": "social-statement",
      "why_registered": "Quote-posts the Bitcoin Red Team's Situation Report No. 2, 6,700 findings across\n425 projects, 1,029 high and critical and 24 contributors at 55.6 hours, and\nuses it to make a factional point: the people auditing hundreds of Bitcoin\nprojects for free are, he says, the same people BIP110 supporters have spent\nmonths calling by a list of slurs, that no BIP110 supporters are on the red\nteam, and he credits calle and Rob Hamilton by name. Held because it records how\nquickly the incident response was absorbed into the existing BIP110 dispute, and\nbecause it is one of the more widely seen posts making that connection. The\ncharacterisation of a faction and of what its members have said is the poster's\nown and is not verified here.\n",
      "relation": {
        "kind": "single-post",
        "head_id": null
      },
      "capture": {
        "status": "held",
        "artefact_count": 2,
        "conversation_copies": 0,
        "conversation_posts": 0,
        "conversation_replies": 0,
        "conversation_gaps": []
      }
    },
    {
      "id": "kevinkelbie-2085601856298930533",
      "title": "New bug hunter's first disclosure",
      "url": "https://x.com/KevinKelbie/status/2085601856298930533",
      "author": "KevinKelbie",
      "platform": "x",
      "organisation": null,
      "posted": "2026-08-07T05:40:05Z",
      "role": "social-statement",
      "why_registered": "Replying to Rob Hamilton's post about how quickly a newcomer joined the bug hunt,\nKevin Kelbie says he is hunting vulnerabilities himself after being inspired by\nthat work and disclosed one the previous day. Held as a first-hand data point on\nthe Red Team campaign's recruitment effect, seen from the recruit's side rather\nthan the organisers'. The disclosure is not identified: no project, report or\ndate is given beyond \"yesterday\", and nothing about it can be checked here. The\naccount is the poster's own.\n",
      "relation": {
        "kind": "single-post",
        "head_id": null
      },
      "capture": {
        "status": "held",
        "artefact_count": 2,
        "conversation_copies": 0,
        "conversation_posts": 0,
        "conversation_replies": 0,
        "conversation_gaps": []
      }
    },
    {
      "id": "rob1ham-2085477372938060221",
      "title": "Security policy coverage across scanned projects",
      "url": "https://x.com/Rob1Ham/status/2085477372938060221",
      "author": "Rob1Ham",
      "platform": "x",
      "organisation": null,
      "posted": "2026-08-06T21:25:26Z",
      "role": "social-statement",
      "why_registered": "Rob Hamilton urges projects that touch people's money to publish a SECURITY.md,\nquoting calle's post that outreach is the campaign's biggest bottleneck. The\nquoted card carries the measurement behind the plea, taken over 426 reviewed\nprojects: 19.5 per cent publish a SECURITY.md, 13.1 per cent expose an\nextractable security email, 28 route through GitHub advisories or a bug bounty\nwith no email, and 342 have no published policy at all. That figure for how\nreachable bitcoin projects are for disclosure is the reason to hold this rather\nthan the exhortation, and it is one of the few Red Team outputs stated as a\nproportion rather than a count of findings. Hamilton co-leads the campaign that\nproduced the numbers and the underlying dataset is not published. The figures are\nthe campaign's own and are not checked here.\n",
      "relation": {
        "kind": "single-post",
        "head_id": null
      },
      "capture": {
        "status": "held",
        "artefact_count": 2,
        "conversation_copies": 0,
        "conversation_posts": 0,
        "conversation_replies": 0,
        "conversation_gaps": []
      }
    },
    {
      "id": "callebtc-2085418280253038697",
      "title": "Disclosure-channel coverage across reviewed repos",
      "url": "https://x.com/callebtc/status/2085418280253038697",
      "author": "callebtc",
      "platform": "x",
      "organisation": null,
      "posted": "2026-08-06T17:30:37Z",
      "role": "social-statement",
      "why_registered": "A method note in the Bitcoin Red Team thread whose parent, held at\ncallebtc-2085418268689391792, reports 425 projects scanned and 1,029 high and\ncritical findings. It says the campaign's biggest bottleneck is not finding bugs\nbut reaching maintainers: of 426 reviewed projects only 19.5 percent, 83\nprojects, publish a SECURITY.md, and only 13.1 percent, 56 projects, have an\nextractable security email, with 28 routing through GitHub advisories and 408\nrepositories resolved. The attached chart is the source of those figures, and the\nask is that maintainers leave an email address in their repositories. Held\nbecause it quantifies a coordination problem the incident exposed, and because it\nbears directly on the responsible-disclosure argument recorded elsewhere in this\nregister. Interest: calle leads the campaign whose reporting volume was itself\nbeing criticised at the time. The percentages are the campaign's own measurements\nand are not verified here.\n",
      "relation": {
        "kind": "single-post",
        "head_id": null
      },
      "capture": {
        "status": "held",
        "artefact_count": 5,
        "conversation_copies": 0,
        "conversation_posts": 0,
        "conversation_replies": 0,
        "conversation_gaps": []
      }
    },
    {
      "id": "hermeslux-2085340926864503222",
      "title": "Hermeslux 2085340926864503222",
      "url": "https://x.com/HermesLux/status/2085340926864503222",
      "author": "HermesLux",
      "platform": "x",
      "organisation": null,
      "posted": "2026-08-06T12:23:15Z",
      "role": "social-statement",
      "why_registered": "Hermes Lux's one-line statement in the incident's vendor-trust debate: using a cold wallet designed by a vendor means a third party is involved. Carries one attached image, not transcribed here. A short sentiment post rather than a factual claim, kept as part of the community-response record alongside the longer self-custody debates it echoes.\n",
      "relation": {
        "kind": "single-post",
        "head_id": null
      },
      "capture": {
        "status": "held",
        "artefact_count": 2,
        "conversation_copies": 0,
        "conversation_posts": 0,
        "conversation_replies": 0,
        "conversation_gaps": []
      }
    },
    {
      "id": "raw_avocado-2085097220336972015",
      "title": "Dice-seed guide recommendation",
      "url": "https://x.com/raw_avocado/status/2085097220336972015",
      "author": "raw_avocado",
      "platform": "x",
      "organisation": null,
      "posted": "2026-08-05T20:14:51Z",
      "role": "social-statement",
      "why_registered": "Alex Waltz recommends a third-party web guide, \"How to Safely Roll Dice for Your\nBitcoin Seed\", attributed to matthewjablack and shown in the attached card as\nposted 3 August and updated 5 August 2026. He singles out the interactive piece\nthat explains why casino dice are not needed and how entropy loss scales.\nHeld as a record of what circulated as dice guidance in the days after the\nincident, and as dated provenance for the guide's existence. The guide itself is\nnot held here and neither its arithmetic nor its advice is checked by this\nproject. The recommendation is the poster's own.\n",
      "relation": {
        "kind": "single-post",
        "head_id": null
      },
      "capture": {
        "status": "held",
        "artefact_count": 5,
        "conversation_copies": 0,
        "conversation_posts": 0,
        "conversation_replies": 0,
        "conversation_gaps": []
      }
    },
    {
      "id": "coldcardwallet-2085551349962334324",
      "title": "Vendor reply on likely closure",
      "url": "https://x.com/COLDCARDwallet/status/2085551349962334324",
      "author": "COLDCARDwallet",
      "platform": "x",
      "organisation": null,
      "posted": "2026-08-07T02:19:24Z",
      "role": "social-statement",
      "why_registered": "Replying to an account telling the company it is going bankrupt, the COLDCARD\naccount answers that it is very likely they will not be around, but that this is\nno reason to stop trying to give people the best version of the firmware they\ncan. The plainest statement held from the vendor about its own survival, posted\nnine days into the incident and alongside the halted shipments already recorded\nat tftc-shipments-halted. It is a remark on the company's social account, not a\nfiling, a notice or a statement of accounts, and this project has not confirmed\nanything about Coinkite's financial position.\n",
      "relation": {
        "kind": "single-post",
        "head_id": null
      },
      "capture": {
        "status": "held",
        "artefact_count": 2,
        "conversation_copies": 0,
        "conversation_posts": 0,
        "conversation_replies": 0,
        "conversation_gaps": []
      }
    },
    {
      "id": "coldcardwallet-2085549723981672841",
      "title": "Vendor answer on further firmware fixes",
      "url": "https://x.com/COLDCARDwallet/status/2085549723981672841",
      "author": "COLDCARDwallet",
      "platform": "x",
      "organisation": null,
      "posted": "2026-08-07T02:12:56Z",
      "role": "social-statement",
      "why_registered": "Asked in a reply by @0ld_AF whether the firmware would be fixed further over the\nnext few months, COLDCARD answers that multiple pull requests are under review\nand that new versions are coming out. Two lines, but a dated vendor commitment to\ncontinued firmware work, made in a reply rather than in an advisory, which is\nwhere a good deal of the vendor's communication went in this period. Held as a\nprimary vendor artefact. No timeline, release number or scope is given.\n",
      "relation": {
        "kind": "single-post",
        "head_id": null
      },
      "capture": {
        "status": "held",
        "artefact_count": 2,
        "conversation_copies": 0,
        "conversation_posts": 0,
        "conversation_replies": 0,
        "conversation_gaps": []
      }
    },
    {
      "id": "zherbert-2085572703931511003",
      "title": "Foundation KeyOS positioning",
      "url": "https://x.com/zherbert/status/2085572703931511003",
      "author": "zherbert",
      "platform": "x",
      "organisation": null,
      "posted": "2026-08-07T03:44:15Z",
      "role": "social-statement",
      "why_registered": "Zach Herbert citing the incident as the reason Foundation Devices spent three\nyears building KeyOS, a Rust microkernel operating system for its Passport\nPrime device, which he describes as free and open source and reproducible.\nHerbert is Foundation Devices' co-founder and CEO and Passport Prime is a\ncompeting hardware wallet, so the post is vendor positioning and that\naffiliation is the interest to state; the record already holds his OPENDIME\nentropy test under the same disclosure. The product claims are the vendor's own\nand none of them is checked here.\n",
      "relation": {
        "kind": "single-post",
        "head_id": null
      },
      "capture": {
        "status": "held",
        "artefact_count": 2,
        "conversation_copies": 0,
        "conversation_posts": 0,
        "conversation_replies": 0,
        "conversation_gaps": []
      }
    },
    {
      "id": "zherbert-2085548862878466251",
      "title": "Foundation CEO on the source of wallet-industry vitriol",
      "url": "https://x.com/zherbert/status/2085548862878466251",
      "author": "zherbert",
      "platform": "x",
      "organisation": null,
      "posted": "2026-08-07T02:09:31Z",
      "role": "social-statement",
      "why_registered": "Answering a quoted line that the Bitcoin wallet industry is petty and dramatic,\nZach Herbert argues there is no industry-wide infighting and that one CEO is\nresponsible for it, naming NVK. He describes his own company's dealings with\nBlockstream, BitBox, Trezor, Bitkey, SeedSigner and Ledger as collegial and\ncompetitive, credits Ledger's security research and disclosure participation,\nand sets out a five-step pattern he says was used against competitors and\nresearchers: public attack, a defence, repetition until the claim becomes common\nknowledge, pressure on the target to stay civil, and no equivalent pressure on\nthe attacker. The post then makes further specific allegations about the same\nnamed individual's off-platform conduct, involving domain registrations,\napproaches to funders and event organisers, and coordinated pile-ons; those\nallegations are described here rather than repeated, and no held source\ncorroborates them. Interest: Herbert is co-founder and CEO of Foundation\nDevices, a direct competitor, and the post names his company; the same author's\nlonger account is at zherbert-nvk-conduct-record. The account is his own\nfirst-hand testimony and is not verified here.\n",
      "relation": {
        "kind": "single-post",
        "head_id": null
      },
      "capture": {
        "status": "held",
        "artefact_count": 2,
        "conversation_copies": 0,
        "conversation_posts": 0,
        "conversation_replies": 0,
        "conversation_gaps": []
      }
    },
    {
      "id": "notgrubles-2085481084888760400",
      "title": "Whether firmware could ignore dice entropy",
      "url": "https://x.com/notgrubles/status/2085481084888760400",
      "author": "notgrubles",
      "platform": "x",
      "organisation": null,
      "posted": "2026-08-06T21:40:11Z",
      "role": "social-statement",
      "why_registered": "grubles says he is all for rolling dice for entropy but asks what prevents a\nfirmware flaw from also ignoring the dice-roll entropy and falling back to the\nflawed RNG. It states the verifiability problem at the centre of the dice\nmitigation: the advice can be sound while the owner has no way to confirm the\ndevice followed it. The post drew BTC Sessions' verification procedure, held at\nbtcsessions-2085612074806251668, and sits against PortlandHODL's report of\nchecking the dice path across firmware versions at\nportlandhodl-dice-roll-verification. An attached video is not captured here,\nonly its poster frame. The post asks a question and does not report such\nbehaviour; nothing in it is a finding.\n",
      "relation": {
        "kind": "single-post",
        "head_id": null
      },
      "capture": {
        "status": "held",
        "artefact_count": 2,
        "conversation_copies": 0,
        "conversation_posts": 0,
        "conversation_replies": 0,
        "conversation_gaps": []
      }
    },
    {
      "id": "coldcardwallet-2085551118164132316",
      "title": "Vendor statement on the disclosure route",
      "url": "https://x.com/COLDCARDwallet/status/2085551118164132316",
      "author": "COLDCARDwallet",
      "platform": "x",
      "organisation": null,
      "posted": "2026-08-07T02:18:28Z",
      "role": "social-statement",
      "why_registered": "Coinkite's own account, replying to a poster who was arguing that the correction\nabout which generator was at fault, MicroPython's built-in general-purpose RNG\nrather than a Coinkite fallback, was pointless given the losses. The vendor\nanswers in three sentences: that it is doing all the investigation it can to get\nto the bottom of it as promised, that it is devastated, and that the hacker could\nhave done the right thing and responsibly disclosed. Primary vendor material and\none of the clearest published statements of the vendor's position on how the\ndefect became public. It is also the sentence that was immediately turned back on\nthe vendor, captured here at fractalencrypt-2085576915453157786 and\nfractalencrypt-2085687538962812943, so the register holds both the statement and\nits reception. What the investigation has found, and whether disclosure was\nattempted, are not established by this post or by any captured source.\n",
      "relation": {
        "kind": "single-post",
        "head_id": null
      },
      "capture": {
        "status": "held",
        "artefact_count": 2,
        "conversation_copies": 0,
        "conversation_posts": 0,
        "conversation_replies": 0,
        "conversation_gaps": []
      }
    },
    {
      "id": "clowncardwallet-2085407852517114131",
      "title": "Parody vendor account on unacknowledged losses",
      "url": "https://x.com/CLOWNCARDwallet/status/2085407852517114131",
      "author": "CLOWNCARDwallet",
      "platform": "x",
      "organisation": null,
      "posted": "2026-08-06T16:49:11Z",
      "role": "social-statement",
      "why_registered": "A parody account whose display name and handle imitate COLDCARD, writing in the\nvendor's voice that all hands are on deck to put out the fires \"that we started\"\nwhile still not acknowledging the funds customers lost. This is satire and not a\nCoinkite statement; the vendor's own posts are registered separately under the\ncoldcardwallet and nvk ids. It is held because the specific complaint it\nlampoons - that the vendor had apologised and shipped firmware without\nacknowledging customer losses - runs through the community record, and this is\nhow that complaint was voiced. Nothing in it is evidence of the vendor's\nposition.\n",
      "relation": {
        "kind": "single-post",
        "head_id": null
      },
      "capture": {
        "status": "held",
        "artefact_count": 2,
        "conversation_copies": 0,
        "conversation_posts": 0,
        "conversation_replies": 0,
        "conversation_gaps": []
      }
    },
    {
      "id": "skot9000-2085457282234507353",
      "title": "Open-source argument from the entropy bug",
      "url": "https://x.com/skot9000/status/2085457282234507353",
      "author": "skot9000",
      "platform": "x",
      "organisation": null,
      "posted": "2026-08-06T20:05:36Z",
      "role": "social-statement",
      "why_registered": "A two-line argument that closed source would not have prevented the theft: the\nentropy bug would still have been exploited if the firmware source were not\nviewable, but in that case \"there would be no survivors\", meaning nobody\noutside the attacker would have been placed to find the defect or warn owners.\nIt closes with \"DEMAND OPEN SOURCE\". Distinct because most of the held\ncommentary treats source availability as having helped the attacker, and this\ninverts that; the same account's collision arithmetic is held at\nskot9000-population-collisions. The counterfactual is the poster's own and is\nnot testable.\n",
      "relation": {
        "kind": "single-post",
        "head_id": null
      },
      "capture": {
        "status": "held",
        "artefact_count": 2,
        "conversation_copies": 0,
        "conversation_posts": 0,
        "conversation_replies": 0,
        "conversation_gaps": []
      }
    },
    {
      "id": "odudex-2085463543613124714",
      "title": "Responsible-disclosure appeal",
      "url": "https://x.com/odudex/status/2085463543613124714",
      "author": "odudex",
      "platform": "x",
      "organisation": null,
      "posted": "2026-08-06T20:30:29Z",
      "role": "social-statement",
      "why_registered": "odudex addresses people newly trying to find vulnerabilities in bitcoin\napplications, including those who are not experienced researchers and are not\nconfident in their findings, and tells them to learn and practise responsible\ndisclosure before taking any other action. Held as part of the reaction to the\nvolume of AI-assisted bug reports the Red Team campaign put into the ecosystem,\na strand the record already carries at milessuter-2084619892699897882 and\ncallebtc-2085024461992939882. The post is short, names no project or report, and\nmakes no factual claim about this incident. The position is the poster's own.\n",
      "relation": {
        "kind": "single-post",
        "head_id": null
      },
      "capture": {
        "status": "held",
        "artefact_count": 2,
        "conversation_copies": 0,
        "conversation_posts": 0,
        "conversation_replies": 0,
        "conversation_gaps": []
      }
    },
    {
      "id": "hodlonaut-2084988860598042655",
      "title": "Draft article on the libngu contributor",
      "url": "https://x.com/hodlonaut/status/2084988860598042655",
      "author": "hodlonaut",
      "platform": "x",
      "organisation": null,
      "posted": "2026-08-05T13:04:16Z",
      "role": "social-statement",
      "why_registered": "One line of text, \"Working on a new article\", over a screenshot of a draft\nsection headed \"Part III: switck\". The excerpt makes an identity allegation\nagainst a named Coinkite officer, holding that the pseudonymous account behind\nthe libngu library is that person, citing GPG-signature matching attributed to\na bitcoin developer, and reading an October 2020 pull request in which two\naccounts exchanged messages eight minutes apart as one person granting himself\npermission so that libngu would appear to have arrived as an outside\ncontribution. The record already holds that attribution, unverified and not\nadopted, at jamesob-2084620229389197453 and dylanleclair1-switck-key-attribution;\nthis entry preserves the form in which it was being worked into a longer\nnarrative for a general audience. Only the screenshot of the excerpt is held\nhere, not the article. The identity claim and the inference drawn from the pull\nrequest are the author's own and are not verified here.\n",
      "relation": {
        "kind": "single-post",
        "head_id": null
      },
      "capture": {
        "status": "held",
        "artefact_count": 5,
        "conversation_copies": 0,
        "conversation_posts": 0,
        "conversation_replies": 0,
        "conversation_gaps": []
      }
    },
    {
      "id": "pubkey-2085540805666549971",
      "title": "Call for donated devices for a memorial",
      "url": "https://x.com/PubKey/status/2085540805666549971",
      "author": "PubKey",
      "platform": "x",
      "organisation": null,
      "posted": "2026-08-07T01:37:30Z",
      "role": "social-statement",
      "why_registered": "PubKey asks people to donate their dead Coldcard so the bar can construct a\nmemorial, \"so we never forget this horrific event\", opening with \"We believe\nthat we will win. But we win on the shoulders of those who came before us.\"\nPubKey is a commercial bitcoin bar in New York and the request is for physical\ndevices. Held as a dated artefact of how the incident was being memorialised\nwithin about a week of disclosure. It sits against guidance held elsewhere in\nthis record that owners should not destroy or part with an affected device,\nbecause any future recovery claim may depend on proving ownership with it; the\narchive holds both and recommends neither.\n",
      "relation": {
        "kind": "single-post",
        "head_id": null
      },
      "capture": {
        "status": "held",
        "artefact_count": 2,
        "conversation_copies": 0,
        "conversation_posts": 0,
        "conversation_replies": 0,
        "conversation_gaps": []
      }
    },
    {
      "id": "bitcoinpierre-2085541313014059218",
      "title": "Objection to Python on embedded hardware",
      "url": "https://x.com/BitcoinPierre/status/2085541313014059218",
      "author": "BitcoinPierre",
      "platform": "x",
      "organisation": null,
      "posted": "2026-08-07T01:39:31Z",
      "role": "social-statement",
      "why_registered": "A one-line reply to the vendor's fallback correction, held at\ncoldcardwallet-2085541034243600805, in which COLDCARD explains that the weak\ngenerator was MicroPython's built-in general-purpose RNG rather than a Coinkite\nfallback and that it became reachable through a link-time error. Pierre\nRochard's response is that a security-critical embedded application should\nperhaps not have used Python at all. Short, but held because it is a named\nindustry figure putting the language-and-runtime choice, rather than the specific\nbuild flag, at the centre of the failure, which is a distinct position from both\nthe vendor's account and the malice reading. It is an opinion and asserts no\nfacts this record could check.\n",
      "relation": {
        "kind": "single-post",
        "head_id": null
      },
      "capture": {
        "status": "held",
        "artefact_count": 2,
        "conversation_copies": 0,
        "conversation_posts": 0,
        "conversation_replies": 0,
        "conversation_gaps": []
      }
    },
    {
      "id": "llfourn-2085275362607735277",
      "title": "Pushback on BlockClock concern",
      "url": "https://x.com/LLFOURN/status/2085275362607735277",
      "author": "LLFOURN",
      "platform": "x",
      "organisation": null,
      "posted": "2026-08-06T08:02:43Z",
      "role": "social-statement",
      "why_registered": "LLFOURN arguing that the wave of concern about BlockClock, Coinkite's other\nproduct, is misplaced: it connects to the internet because that is where\nbitcoin is, it holds the WiFi password, and it is probably about as insecure as\nany other device of its kind on a home network. The distinct point is that the\ndevice is unremarkable rather than that it is safe, and it is one of the few\nheld sources addressing whether the incident should widen to the vendor's\nnon-signing products. LLFOURN is a repeatedly captured technical voice in this\nrecord. The assessment is his and no test of the device is offered.\n",
      "relation": {
        "kind": "conversation-head",
        "head_id": null
      },
      "capture": {
        "status": "held",
        "artefact_count": 8,
        "conversation_copies": 1,
        "conversation_posts": 6,
        "conversation_replies": 4,
        "conversation_gaps": []
      }
    },
    {
      "id": "coletu-2085521804337008997",
      "title": "Shrinking anonymity set argument",
      "url": "https://x.com/ColeTU/status/2085521804337008997",
      "author": "ColeTU",
      "platform": "x",
      "organisation": null,
      "posted": "2026-08-07T00:21:59Z",
      "role": "social-statement",
      "why_registered": "Cole argues that the attack damages bitcoin privacy well beyond the people who\nlost money: anyone holding a compromised seed can see that wallet's entire\ntransaction history and address set, including for owners who already moved their\nfunds, so surveillance firms can cluster those addresses to single owners, and\neveryone else is left hiding in a smaller crowd. He puts it as hiding in a room of\n1,000 people from which 800 suddenly leave. Held because it states the\nsecond-order privacy cost compactly and independently of\nrawavocado-privacy-impact, which the archive holds making a related argument four\ndays earlier. The same account's on-chain probe is registered at\ncoletu-2085065558333022663. The reasoning is the poster's; no captured source\nmeasures the clustering effect he describes, and it is not verified here.\n",
      "relation": {
        "kind": "single-post",
        "head_id": null
      },
      "capture": {
        "status": "held",
        "artefact_count": 2,
        "conversation_copies": 0,
        "conversation_posts": 0,
        "conversation_replies": 0,
        "conversation_gaps": []
      }
    },
    {
      "id": "grassfedbitcoin-2085463112048873485",
      "title": "Objection to a repost circulating during the panic",
      "url": "https://x.com/GrassFedBitcoin/status/2085463112048873485",
      "author": "GrassFedBitcoin",
      "platform": "x",
      "organisation": null,
      "posted": "2026-08-06T20:28:46Z",
      "role": "social-statement",
      "why_registered": "The poster argues that adding false claims and noise while people are panicking\nfor real information is among the most immoral behaviour he can imagine, even\nfrom a troll, and says he finds it stunning that the account responsible is\nCoinkite's chief executive. The attached screenshot is his evidence: it shows a\nrepost, labelled as made by that account, of a third party's post claiming the\nSEEDPLATE contains a microchip that logs every punch and reports to the nearest\nBLOCKCLOCK, with a close-up image purporting to show the chip. The claim in the\nreposted item is on its face a joke and no captured source supports any such\nhardware. Held as a dated instance of the misinformation and satire problem\nduring the migration window, and because the archive already records how far the\nperceived blast radius stretched in w_s_bitcoin-2084991031724957808. This post\nmakes an allegation about the conduct of a named individual; the only support for\nit here is the poster's own screenshot, and whether the repost was made, and in\nwhat spirit, is not established by this archive.\n",
      "relation": {
        "kind": "conversation-head",
        "head_id": null
      },
      "capture": {
        "status": "held",
        "artefact_count": 33,
        "conversation_copies": 11,
        "conversation_posts": 25,
        "conversation_replies": 24,
        "conversation_gaps": []
      }
    },
    {
      "id": "skwp-2085399213563593083",
      "title": "Wallet warning pull requests across five projects",
      "url": "https://x.com/skwp/status/2085399213563593083",
      "author": "skwp",
      "platform": "x",
      "organisation": null,
      "posted": "2026-08-06T16:14:52Z",
      "role": "social-statement",
      "why_registered": "Yan Pritzker reports that he is opening pull requests on widely used wallet\nsoftware so that users see a warning about the COLDCARD disclosure inside the\napplication, and asks other maintainers to do the same, on the reasoning that\nmany owners are not on X and will not otherwise learn what happened. He links\nfive: Sparrow 2047, Liana 2242, Electrum 10805, WasabiDoc 2113 and Caravan 524.\nHeld as the primary announcement of a distinct strand of the response, putting\nthe notice in front of a person at the moment they reach for the device rather\nthan in a vendor advisory; the Sparrow change is registered separately as\nsparrow-pr-2047, which records that he approved it the same day. Pritzker is at\nSwan, a bitcoin brokerage that also sells self-custody products, which is stated\nbecause the wider argument about who benefits from the response is itself part of\nthe record. Whether each pull request was merged is not established by this post.\n",
      "relation": {
        "kind": "single-post",
        "head_id": null
      },
      "capture": {
        "status": "held",
        "artefact_count": 2,
        "conversation_copies": 0,
        "conversation_posts": 0,
        "conversation_replies": 0,
        "conversation_gaps": []
      }
    },
    {
      "id": "intangiblecoins-2085506256656023720",
      "title": "Bloomberg coverage of the incident responders",
      "url": "https://x.com/intangiblecoins/status/2085506256656023720",
      "author": "intangiblecoins",
      "platform": "x",
      "organisation": null,
      "posted": "2026-08-06T23:20:13Z",
      "role": "social-statement",
      "why_registered": "Alex Thorn notes that many bitcoiners are giving up work and family time to deal\nwith the fallout, and thanks Bloomberg for covering two of those stories,\nattaching screenshots of the article. The captured screenshots show a 6 August\n2026 piece by Ben Weiss quoting Thorn saying the victims are average everyday\npeople saving their money in bitcoin, that he has been immersed in victim reports\nand code, and that he told victims who lost all their savings and felt ashamed\nthat he would help as much as he could; Robert Hamilton of AnchorWatch describing\nsleepless nights and teaming up with other developers to use AI to find security\nvulnerabilities; and Becca Rubenfeld saying it is as if they are off at war.\nHeld as a dated marker of the incident reaching mainstream financial press and of\nwhich responders that press went to. Thorn heads research at Galaxy, whose\nflow-of-funds accounting the archive holds at glxyresearch-flow-map, and Hamilton\nis AnchorWatch's chief executive, both interests recorded elsewhere in the\nregister. The article's contents are Bloomberg's reporting and the quotations are\nits subjects' own; nothing in it is verified here, and the article itself is not\nheld by this archive.\n",
      "relation": {
        "kind": "single-post",
        "head_id": null
      },
      "capture": {
        "status": "held",
        "artefact_count": 11,
        "conversation_copies": 0,
        "conversation_posts": 0,
        "conversation_replies": 0,
        "conversation_gaps": []
      }
    },
    {
      "id": "casahodl-2085516292904432051",
      "title": "Casa multisig workshop promotion",
      "url": "https://x.com/CasaHODL/status/2085516292904432051",
      "author": "CasaHODL",
      "platform": "x",
      "organisation": null,
      "posted": "2026-08-07T00:00:05Z",
      "role": "social-statement",
      "why_registered": "Casa promoting a free live multisig workshop on the Monday after the incident,\nexplicitly addressed to people reconsidering how they hold bitcoin because of\nit: moving from one key to multiple keys across different hardware vendors,\nwhat that protects against, the tradeoffs, and a live Q&A. Casa is a commercial\nmulti-key custody provider and this is marketing for its own product, which is\nthe interest to state. Held as a record of how vendors converted the incident\ninto demand for multi-key setups during the same week. The claims made for\nmultisig are the company's own.\n",
      "relation": {
        "kind": "single-post",
        "head_id": null
      },
      "capture": {
        "status": "held",
        "artefact_count": 5,
        "conversation_copies": 0,
        "conversation_posts": 0,
        "conversation_replies": 0,
        "conversation_gaps": []
      }
    },
    {
      "id": "coinspect-2085430121670811898",
      "title": "RRWallet mnemonics and the Ill Bloom flaw",
      "url": "https://x.com/coinspect/status/2085430121670811898",
      "author": "coinspect",
      "platform": "x",
      "organisation": null,
      "posted": "2026-08-06T18:17:41Z",
      "role": "social-statement",
      "why_registered": "The security firm Coinspect warns that RRWallet, formerly RenrenBit, generated\nseed phrases vulnerable to Ill Bloom in both English and Chinese, says a user who\nkept using an affected mnemonic lost $2M recently, and tells anyone who ever used\nRRWallet to move funds and never reuse a mnemonic it produced. Ill Bloom is a\nseparate weak-entropy flaw, described in the record as a twelve-year-old CryptoJS\nissue whose public proof of concept is relayed at\nthreatwire_-2085593099749749082; it is not the COLDCARD defect. Held for the\nwider entropy-auditing wave the incident set off and the losses being attributed\nto it elsewhere. Interest: Coinspect sells wallet security audits. The affected-\nwallet claim and the $2M figure are the firm's own and are not verified here.\n",
      "relation": {
        "kind": "single-post",
        "head_id": null
      },
      "capture": {
        "status": "held",
        "artefact_count": 2,
        "conversation_copies": 0,
        "conversation_posts": 0,
        "conversation_replies": 0,
        "conversation_gaps": []
      }
    },
    {
      "id": "coldcardwallet-2085684845204635694",
      "title": "Customer data retention suspended",
      "url": "https://x.com/coldcardwallet/status/2085684845204635694",
      "author": "coldcardwallet",
      "platform": "x",
      "organisation": null,
      "posted": "2026-08-07T11:09:51Z",
      "role": "social-statement",
      "why_registered": "The vendor's own notice, in full, that it has temporarily suspended the\nautomated blanking of customer records because of legal obligations to preserve\nmaterial relevant to ongoing and anticipated proceedings. It states that standard\npractice is to blank records after 120 days, keeping only email address and\ncountry of residence, that accelerated blanking has been available on request,\nthat retained data will be access-restricted and used only for compliance, and\nthat customers who do not want their data preserved must say so by writing to the\nsupport address, which inverts the usual default. A primary vendor artefact and\nthe clearest signal in this record that litigation is anticipated. The blog\nversion is held at coinkite-data-retention-update, and the earlier and much\nshorter reply on the same subject is at coldcardwallet-2084574110445674733; the\n120-day figure here sits against the 90-day understanding reported by owners at\nreddit-coinkite-email-data-retention and questioned by a competing vendor at\nsatochip-data-retention-question. The capture shows the post as edited after\npublication. The vendor's description of its own obligations and practices is its\nown account and is not verified here.\n",
      "relation": {
        "kind": "single-post",
        "head_id": null
      },
      "capture": {
        "status": "held",
        "artefact_count": 2,
        "conversation_copies": 0,
        "conversation_posts": 0,
        "conversation_replies": 0,
        "conversation_gaps": []
      }
    },
    {
      "id": "bitpaine-2085143638464745500",
      "title": "Mossad pager analogy with fabricated storefront",
      "url": "https://x.com/bitpaine/status/2085143638464745500",
      "author": "bitpaine",
      "platform": "x",
      "organisation": null,
      "posted": "2026-08-05T23:19:18Z",
      "role": "social-statement",
      "why_registered": "Bit Paine draws an analogy between the incident and the Mossad pager operation\nagainst Hezbollah, described as a ten-year long game, and attaches an image of a\nmock storefront branded PagerKite selling a \"ColdPager Mk5\". X labels the image\n\"Made with AI\"; no such store or product exists and the picture is a fabrication\nby the poster. The analogy insinuates deliberate long-horizon compromise rather\nthan an accident, and the post offers nothing in support of that reading. Held\nbecause the sabotage insinuation circulated widely, at 67.2k views on the\ncapture, and the record carries what was said. The implication is the poster's\nown; no held source supports it and it is not adopted here.\n",
      "relation": {
        "kind": "single-post",
        "head_id": null
      },
      "capture": {
        "status": "held",
        "artefact_count": 5,
        "conversation_copies": 0,
        "conversation_posts": 0,
        "conversation_replies": 0,
        "conversation_gaps": []
      }
    },
    {
      "id": "cointelegraph-2085597045734203509",
      "title": "Vendor declines to estimate losses, per Bloomberg",
      "url": "https://x.com/cointelegraph/status/2085597045734203509",
      "author": "cointelegraph",
      "platform": "x",
      "organisation": null,
      "posted": "2026-08-07T05:20:58Z",
      "role": "social-statement",
      "why_registered": "A trade-press wire item reporting, from Bloomberg, that Coinkite says it is\nworking on a post-mortem of the days-long attack rather than speculating on the\nextent of customer losses. It is secondary twice over, an outlet relaying another\noutlet, and the underlying Bloomberg report is not held here. Kept because it\nrecords a dated vendor position on the loss figure itself, which matters given\nthe competing totals this record holds from chain monitors, and because it marks\nthe point at which the incident was being covered by general financial press\nrather than Bitcoin media alone. The quoted vendor statement reaches this record\nat two removes and is not verified here.\n",
      "relation": {
        "kind": "single-post",
        "head_id": null
      },
      "capture": {
        "status": "held",
        "artefact_count": 7,
        "conversation_copies": 0,
        "conversation_posts": 0,
        "conversation_replies": 0,
        "conversation_gaps": []
      }
    },
    {
      "id": "fractalencrypt-2085687538962812943",
      "title": "Lousy T-shirt reply to the disclosure line",
      "url": "https://x.com/fractalencrypt/status/2085687538962812943",
      "author": "fractalencrypt",
      "platform": "x",
      "organisation": null,
      "posted": "2026-08-07T11:20:34Z",
      "role": "social-statement",
      "why_registered": "The same poster repeats the Coinkite sentence, \"The hacker could have done the\nright thing and responsibly disclosed\", quote-posting his own earlier post of it\nseven hours later and this time attaching an image: a person wearing a Coinkite\nT-shirt printed with a COLDCARD and the words \"I responsibly disclosed a Coldcard\nVulnerability and all I got was this lousy T-Shirt!\". The point is the retort,\nthat the vendor's stated preference for responsible disclosure is answered by how\nit is said to have rewarded a past researcher, which connects to the merchandise\nclaim in vladcostea-disclosure-history already in the register. Held because it\nis the sharpest captured form of that argument and because it shows the vendor's\nsentence hardening into a slogan within a day. Whether the shirt is a genuine\nCoinkite item, and whether any researcher received one in the circumstances the\nretort implies, is not established by this archive.\n",
      "relation": {
        "kind": "single-post",
        "head_id": null
      },
      "capture": {
        "status": "held",
        "artefact_count": 5,
        "conversation_copies": 0,
        "conversation_posts": 0,
        "conversation_replies": 0,
        "conversation_gaps": []
      }
    },
    {
      "id": "fractalencrypt-2085576915453157786",
      "title": "Vendor's disclosure line quoted back without comment",
      "url": "https://x.com/fractalencrypt/status/2085576915453157786",
      "author": "fractalencrypt",
      "platform": "x",
      "organisation": null,
      "posted": "2026-08-07T04:00:59Z",
      "role": "social-statement",
      "why_registered": "A bare quote-post: the poster reproduces one sentence from Coinkite, \"The hacker\ncould have done the right thing and responsibly disclosed\", attributes it to\nColdcard and adds nothing else. The rendered capture shows the quoted item, the\nvendor reply registered here as coldcardwallet-2085551118164132316, which is the\nwhole substance of the post; the text on its own does not carry it. Held as the\nfirst captured instance of that sentence being lifted out and circulated as a\nrebuke rather than read as a statement, roughly two hours after the vendor posted\nit. The post makes no factual claim of its own beyond the quotation, and the\ncriticism it implies is the poster's.\n",
      "relation": {
        "kind": "single-post",
        "head_id": null
      },
      "capture": {
        "status": "held",
        "artefact_count": 2,
        "conversation_copies": 0,
        "conversation_posts": 0,
        "conversation_replies": 0,
        "conversation_gaps": []
      }
    },
    {
      "id": "crypto_mags-2085201100005867917",
      "title": "Small Mk3 loss set against the vendor store page",
      "url": "https://x.com/crypto_mags/status/2085201100005867917",
      "author": "crypto_mags",
      "platform": "x",
      "organisation": null,
      "posted": "2026-08-06T03:07:38Z",
      "role": "social-statement",
      "why_registered": "A one-line wry post, \"I'm having fun, staying poor in this swept wallet. Am I\ndoing this right?\", attaching a screenshot of coinkite.com showing the COLDCARD\nsecurity advisory bar above the store's \"Bitcoin Security and Fun Devices\"\nheading, and quote-posting the author's own earlier victim report. That quoted\npost reads: \"Update: I'M ALSO A VICTIM. No passphrase. MK3. Funds got swept on\nJuly 31st. Could have been worse, it was 60,615 sats ($40)\", with a wallet\nscreenshot showing a zero balance and five transactions ending 2026-07-31. Held\nas a first-hand loss report at the small end of the distribution, which is the\npart of the victim record least likely to be preserved anywhere else, and as a\ndated capture of the vendor's storefront still selling while the advisory ran.\nThe configuration, the date and the amount are the author's own account and are\nnot verified here.\n",
      "relation": {
        "kind": "single-post",
        "head_id": null
      },
      "capture": {
        "status": "held",
        "artefact_count": 5,
        "conversation_copies": 0,
        "conversation_posts": 0,
        "conversation_replies": 0,
        "conversation_gaps": []
      }
    },
    {
      "id": "crypto_mags-2085174374110560472",
      "title": "Mk3 victim self-report, 60,615 sats",
      "url": "https://x.com/crypto_mags/status/2085174374110560472",
      "author": "crypto_mags",
      "platform": "x",
      "organisation": null,
      "posted": "2026-08-06T01:21:26Z",
      "role": "social-statement",
      "why_registered": "A short first-hand victim report: an Mk3 with no passphrase, swept on 31 July,\nfor 60,615 sats, which the poster values at about US$40. Held as one more\nfirst-person account at the very small end of the loss distribution, useful\nagainst the accountings that count value rather than wallets. Two screenshots\nare attached. The account is self-reported and the wallet is not identified, so\nneither the device model nor the sweep is confirmed here.\n",
      "relation": {
        "kind": "single-post",
        "head_id": null
      },
      "capture": {
        "status": "held",
        "artefact_count": 5,
        "conversation_copies": 0,
        "conversation_posts": 0,
        "conversation_replies": 0,
        "conversation_gaps": []
      }
    },
    {
      "id": "tftc21-2085428081259581658",
      "title": "Red Team 55-hour situation report",
      "url": "https://x.com/tftc21/status/2085428081259581658",
      "author": "tftc21",
      "platform": "x",
      "organisation": null,
      "posted": "2026-08-06T18:09:34Z",
      "role": "social-statement",
      "why_registered": "TFTC relays the Bitcoin Red Team's second situation report at 55 hours: 24\ncontributors, 425 projects scanned, 6,700 findings filed and 1,029 of them high\nor critical, which the post reads as roughly 19 high-or-critical findings per\nhour, at about US$10,000 a day in compute. The attached report card carries\ndetail the text drops, including 123 critical and 906 high severity, 15.4 per\ncent of the corpus, 22.0 per cent of findings dynamically reproduced, 84 per cent\narriving by automated scan intake and 30.6 per cent of projects notified\nupstream; it is credited to calle. The post also states that no vulnerability was\nfound by a United States frontier model and attributes that to those models\nrefusing vulnerability research without heavy gatekeeping, with the team using\nopen-weights models instead. These are the largest counts in the record at this\ndate and a substantial escalation on the 390-project figures at\ncallebtc-2085024458012586286. TFTC is a bitcoin media company relaying a campaign\nled by callebtc and Rob1Ham; every number originates with the campaign, the\nfindings are not published, and none of it can be rechecked here.\n",
      "relation": {
        "kind": "single-post",
        "head_id": null
      },
      "capture": {
        "status": "held",
        "artefact_count": 5,
        "conversation_copies": 0,
        "conversation_posts": 0,
        "conversation_replies": 0,
        "conversation_gaps": []
      }
    },
    {
      "id": "jwweatherman_-2085427379116167369",
      "title": "Recipient's public rejection of two red-team findings",
      "url": "https://x.com/jwweatherman_/status/2085427379116167369",
      "author": "jwweatherman_",
      "platform": "x",
      "organisation": null,
      "posted": "2026-08-06T18:06:47Z",
      "role": "social-statement",
      "why_registered": "Replying to a request from Rob Hamilton to check direct messages, JW Weatherman\nsays the two issues reported to him as critical now need to be addressed publicly\nand calls this not responsible disclosure. He then answers both: that his project\ndoes not verify signatures on Bitcoin Core, which he says is almost certainly\nuntrue, is being checked, and would be like a missing second seatbelt given that\ndownloads come from bitcoincore.org with implicit signatures and TLS; and that it\ndownloads from GitHub, which he calls obviously not an issue. He writes as \"we\"\nfor a project the post does not name. Held because it is a named recipient's\nfirst-hand account of being on the receiving end of the AI-assisted red-team\nsweep, and because it is one of the few captured disputes over the sweep's\ndisclosure practice rather than its output. Both the findings and his rebuttal of\nthem are the parties' own statements; neither is verified here.\n",
      "relation": {
        "kind": "single-post",
        "head_id": null
      },
      "capture": {
        "status": "held",
        "artefact_count": 2,
        "conversation_copies": 0,
        "conversation_posts": 0,
        "conversation_replies": 0,
        "conversation_gaps": []
      }
    },
    {
      "id": "fractalencrypt-2085584132420043263",
      "title": "Objection to the responsible-disclosure line",
      "url": "https://x.com/fractalencrypt/status/2085584132420043263",
      "author": "fractalencrypt",
      "platform": "x",
      "organisation": null,
      "posted": "2026-08-07T04:29:40Z",
      "role": "social-statement",
      "why_registered": "FractalEncrypt quote-posts his own earlier post, held at\nfractalencrypt-2085576915453157786, which carries the COLDCARD line \"The hacker\ncould have done the right thing and responsibly disclosed\", and asks whether\naround five separate researchers had responsibly disclosed this to the vendor\nonly to be made fun of. It states, in one sentence, the community's central\nobjection to the vendor's disclosure framing during the week. Both the quoted\npost and the Coldcard post behind it are registered, at\ncoldcardwallet-2085551118164132316, so the exchange is legible end to end. The\ncount of researchers and the claim that they were mocked are the poster's\ncharacterisation and are not verified here.\n",
      "relation": {
        "kind": "single-post",
        "head_id": null
      },
      "capture": {
        "status": "held",
        "artefact_count": 2,
        "conversation_copies": 0,
        "conversation_posts": 0,
        "conversation_replies": 0,
        "conversation_gaps": []
      }
    },
    {
      "id": "ericyakes-2085400078181970287",
      "title": "Red Team as the lasting story",
      "url": "https://x.com/ericyakes/status/2085400078181970287",
      "author": "ericyakes",
      "platform": "x",
      "organisation": null,
      "posted": "2026-08-06T16:18:18Z",
      "role": "social-statement",
      "why_registered": "Eric Yakes predicts that the COLDCARD incident will not be remembered as a\nsignificant moment in bitcoin history and that what will be remembered is\nbitcoin developers running their own equivalent of Project Glasswing in public,\non open-source models, without a frontier lab's resources and funded publicly.\nHe closes by directing donations to the Red Team through OpenSats. Held as a\ncompact statement of the position that the response matters more than the breach,\nwhich several held sources take, and as a further instance of the incident being\nconverted into a fundraising ask. It is a prediction and a solicitation, not a\nclaim of fact about the defect. The judgement is the poster's own.\n",
      "relation": {
        "kind": "single-post",
        "head_id": null
      },
      "capture": {
        "status": "held",
        "artefact_count": 2,
        "conversation_copies": 0,
        "conversation_posts": 0,
        "conversation_replies": 0,
        "conversation_gaps": []
      }
    },
    {
      "id": "laurashin-2085473420742176994",
      "title": "Dice-roll fix reported to have drained early victims",
      "url": "https://x.com/laurashin/status/2085473420742176994",
      "author": "laurashin",
      "platform": "x",
      "organisation": null,
      "posted": "2026-08-06T21:09:44Z",
      "role": "social-statement",
      "why_registered": "Journalist Laura Shin summarising her outlet's article, linked in the post as a\ncard from unchainedcrypto.com and headlined that COLDCARD's dice-roll safeguard\ncan backfire on holders who roll too few times. The claim she relays, attributed\nto security researcher Taylor Monahan, is that the dice-rolling fix being\nrecommended to COLDCARD owners is the same thing that drained the earliest\nvictims, and that the device warns the user but never stops them. Held because it\nruns directly against dice-based mitigation guidance held elsewhere in this\nrecord, including the fifty-roll exception at darosior-emergency-guidance, the\ndice caveat at llfourn-2083298061250666721 and the advice at\npraveenperera-reproduction-cost, so the archive now holds both positions. The\nlinked outlet should not be confused with the custody firm Unchained, whose\nseparate client guidance is held at unchained-guidance. The claim is Monahan's as\nreported by Shin and is not verified here.\n",
      "relation": {
        "kind": "single-post",
        "head_id": null
      },
      "capture": {
        "status": "held",
        "artefact_count": 2,
        "conversation_copies": 0,
        "conversation_posts": 0,
        "conversation_replies": 0,
        "conversation_gaps": []
      }
    },
    {
      "id": "americanhodl8-2085449671212954063",
      "title": "Prediction that Coinkite will not survive",
      "url": "https://x.com/americanhodl8/status/2085449671212954063",
      "author": "americanhodl8",
      "platform": "x",
      "organisation": null,
      "posted": "2026-08-06T19:35:22Z",
      "role": "social-statement",
      "why_registered": "AMERICAN HODL states flatly that Coinkite will not survive the incident,\nagainst people saying it might, on the grounds that it shipped three generations\nof products with bad entropy over five years, that the company likely does not\nmake much money, and that it will be hit with lawsuits from every direction.\nHeld as one of the clearest published statements of the company-is-finished view\nfrom a widely followed account, on the same night the vendor's own account said\nit was very likely not to be around, captured here at\ncoldcardwallet-2085551349962334324. The revenue characterisation and the\nlitigation forecast are asserted without supporting material. They are the\nposter's own and are not verified here.\n",
      "relation": {
        "kind": "single-post",
        "head_id": null
      },
      "capture": {
        "status": "held",
        "artefact_count": 2,
        "conversation_copies": 0,
        "conversation_posts": 0,
        "conversation_replies": 0,
        "conversation_gaps": []
      }
    },
    {
      "id": "vandelaybtc-2085574426850996452",
      "title": "Qualified agreement that Coinkite failed",
      "url": "https://x.com/vandelaybtc/status/2085574426850996452",
      "author": "vandelaybtc",
      "platform": "x",
      "organisation": null,
      "posted": "2026-08-07T03:51:06Z",
      "role": "social-statement",
      "why_registered": "Endorses AMERICAN HODL's post, held at americanhodl8-2085449671212954063 and\nquoted here, which states flatly that Coinkite will not survive the incident, but\ndeclines to follow it all the way: the poster calls the Yasmarang episode\nunforgivable from an internal testing and auditing perspective while saying he\nloves the hardware and features, that the company has contributed a lot, that he\nhopes the good ideas are not thrown away with the rest, and that his confidence\nis nonetheless lower. Held because it is a mixed reaction rather than a write-off\nor a defence, a position less represented in this record than either pole. The\njudgements are the poster's own and are not verified here.\n",
      "relation": {
        "kind": "single-post",
        "head_id": null
      },
      "capture": {
        "status": "held",
        "artefact_count": 2,
        "conversation_copies": 0,
        "conversation_posts": 0,
        "conversation_replies": 0,
        "conversation_gaps": []
      }
    },
    {
      "id": "little_hodler-2085038772786262491",
      "title": "First-hand ruin report",
      "url": "https://x.com/little_hodler/status/2085038772786262491",
      "author": "little_hodler",
      "platform": "x",
      "organisation": null,
      "posted": "2026-08-05T16:22:36Z",
      "role": "social-statement",
      "why_registered": "A one-line first-hand account: the poster says they are back at square one and\nthat they and their family are in ruins, and names NVK as responsible. No\namount, device model, firmware version or date of loss is given, and no\nsupporting material is attached. Held as part of the victim record, where the\nsite preserves owner accounts as they were published rather than only the ones\ncarrying detail. The loss and its cause are the poster's own claim and are not\nverified here.\n",
      "relation": {
        "kind": "single-post",
        "head_id": null
      },
      "capture": {
        "status": "held",
        "artefact_count": 2,
        "conversation_copies": 0,
        "conversation_posts": 0,
        "conversation_replies": 0,
        "conversation_gaps": []
      }
    },
    {
      "id": "bigshiny0-2085547011743338845",
      "title": "Instrumented Mk4 TRNG read count",
      "url": "https://x.com/bigshiny0/status/2085547011743338845",
      "author": "bigshiny0",
      "platform": "x",
      "organisation": null,
      "posted": "2026-08-07T02:02:09Z",
      "role": "social-statement",
      "why_registered": "Shiny reports instrumenting Mk4 firmware at the point where it reads the STM32\nhardware RNG and then requesting the same 32 bytes seed generation uses: on 5.6.0\nexactly eight hardware reads were observed, which the poster reads as direct\nproof that the seed request reached the true RNG, and on affected firmware the\nsame test is said to show zero hardware reads with the bytes coming from\nMicroPython's software PRNG instead. The post frames this as a real-device path\ntest rather than statistical inspection of whether output looks random, and asks\nwhy such a test was not already in COLDCARD's suite and run routinely on\nhardware. It quotes the vendor's reply to another account insisting there was no\nweak entropy fallback and that precision matters, so it is a direct\nmethodological answer to COLDCARD on what a test would actually settle. No\ninstrumentation code, device identifier or log is published with it, and the\naffected-firmware half is stated as what the test would have shown rather than a\nrun that was performed. The result and the inference are the poster's own and are\nnot reproduced here.\n",
      "relation": {
        "kind": "single-post",
        "head_id": null
      },
      "capture": {
        "status": "held",
        "artefact_count": 2,
        "conversation_copies": 0,
        "conversation_posts": 0,
        "conversation_replies": 0,
        "conversation_gaps": []
      }
    },
    {
      "id": "stutxo-2083545349784834365",
      "title": "Frontier-model warning for asking about the bug",
      "url": "https://x.com/stutxo/status/2083545349784834365?s=20",
      "author": "stutxo",
      "platform": "x",
      "organisation": null,
      "posted": "2026-08-01T13:28:16Z",
      "role": "social-statement",
      "why_registered": "stu reports receiving a policy warning from OpenAI for asking questions about\nthe COLDCARD vulnerability, and attaches a screenshot of a notice saying\nactivity in ChatGPT was not permitted under the policy on Cyber Abuse. The post\nquote-posts Rob Hamilton of AnchorWatch arguing that whitehats get blocked while\nblackhats get bitcoin. Held as a first-hand data point in the strand about\nwhether commercial models help or hinder defenders during the incident,\nalongside callebtc-2085329159094489183. The screenshot shows only the opening\nlines of the notice and no prompt text, so what was actually asked is not in the\ncapture. The account of what triggered the warning is the poster's own and is\nnot verified here.\n",
      "relation": {
        "kind": "single-post",
        "head_id": null
      },
      "capture": {
        "status": "held",
        "artefact_count": 5,
        "conversation_copies": 0,
        "conversation_posts": 0,
        "conversation_replies": 0,
        "conversation_gaps": []
      }
    },
    {
      "id": "coletu-2085256973923029482",
      "title": "Fourteen-hour drain-test result",
      "url": "https://x.com/coletu/status/2085256973923029482",
      "author": "coletu",
      "platform": "x",
      "organisation": null,
      "posted": "2026-08-06T06:49:39Z",
      "role": "social-statement",
      "why_registered": "Cole reports the result of his own live experiment fourteen hours in: of five\nwallets funded on a compromised COLDCARD Mk3, only the plain seed-phrase wallet\nhad been emptied, and the four protected by a passphrase or a non-standard\naccount number still held funds. The post quotes his earlier video setting the\ntest up and attaches a block-explorer view of the funding transaction, one\n0.00055 BTC input split into five outputs of 0.000108 BTC. A first-hand, dated\nobservation of which configurations the sweeper actually reached, which bears on\nthe passphrase question other held sources argue about. It is one device, one\nattempt and a fourteen-hour window rather than a general result, and the video\nitself is not captured by this tool. The setup and the conclusion drawn from it\nare the poster's own and are not reproduced here.\n",
      "relation": {
        "kind": "single-post",
        "head_id": null
      },
      "capture": {
        "status": "held",
        "artefact_count": 5,
        "conversation_copies": 0,
        "conversation_posts": 0,
        "conversation_replies": 0,
        "conversation_gaps": []
      }
    },
    {
      "id": "jwweatherman_-2085656197324022256",
      "title": "Allegation of undisclosed involvement and a coordinated response",
      "url": "https://x.com/jwweatherman_/status/2085656197324022256",
      "author": "jwweatherman_",
      "platform": "x",
      "organisation": null,
      "posted": "2026-08-07T09:16:01Z",
      "role": "social-statement",
      "why_registered": "Quote-posting an unrelated remark by another account about resuming a\nconversation after a night's rest, JW Weatherman sets out, in a sarcastic frame\nthat presents the claims as what critics dismiss as conspiracy, an allegation\nthat a named and widely followed bitcoin educator concealed an involvement with\nthe vendor, misled people who raised concerns over a period of years, and that\nthe post-incident response was coordinated to serve that interest. Held as a\ndated record of how far the attribution-of-intent theories ran on 7 August, which\nis the only basis on which this archive carries such material. The allegation is\nnot restated in detail here and no captured source supports it. What the record\ndoes hold is narrower and different: opensats-nvk-board-departure, the funder's\nown statement that Coinkite's chief executive left its board with no reason\ngiven, and bitschmidty-2084657778610581663, an acknowledgement of who funded the\nred-team work. The archive also holds contemporaneous rejections of inside-job\nreadings at miketwenty1-2085130028094718097. These are the poster's claims about\na named individual, entirely unverified, and inclusion here is not endorsement.\n",
      "relation": {
        "kind": "single-post",
        "head_id": null
      },
      "capture": {
        "status": "held",
        "artefact_count": 2,
        "conversation_copies": 0,
        "conversation_posts": 0,
        "conversation_replies": 0,
        "conversation_gaps": []
      }
    },
    {
      "id": "secsovereign-2085374293790065031",
      "title": "Accountability polemic against the wallet's recommenders",
      "url": "https://x.com/secsovereign/status/2085374293790065031",
      "author": "secsovereign",
      "platform": "x",
      "organisation": null,
      "posted": "2026-08-06T14:35:50Z",
      "role": "social-statement",
      "why_registered": "A long polemic arguing that the post-incident response has become\nself-congratulatory while victims are still being counted. It gives figures of\nover 1,800 BTC gone and a median victim holding of 0.4 BTC, describes the failure\nas a build configuration error in a custom RNG library, and sets out a claimed\nwarning timeline: concerns about the provenance of COLDCARD's cryptographic\nprimitives raised as early as 2021, credible reports of entropy weakness\ndelivered to Coinkite by 2024, and the specific library identified as not\ncredible with replacement explicitly recommended by 2025, waved off at every\nstep. Its sharpest argument is about interest rather than engineering: it says\nthe volunteers, the red team and the people publishing gratitude threads hold\nequity positions, sponsorship revenue and institutional relationships that depend\non continued trust in the stack they promoted, and calls the response reputation\ninsurance rather than altruism. It names no individual, directing its questions\nat whoever recommended the device, published guides featuring it and collected\nCoinkite sponsorship. Held as one of the most fully argued dissents from the\nincident's dominant framing, and because the funding and affiliation questions it\nraises are ones this archive discloses case by case. Every figure and every date\nin it is the poster's own: the loss totals held here differ, no captured source\nestablishes the 2024 or 2025 reports, the prior-warning claims the archive does\nhold are contested (stackernews-prior-warning-video,\nbtctherapist-prior-drain-report, vladcostea-disclosure-history), and the\ncharacterisation of the generator as a custom library is disputed by held\nsources. None of it is verified here.\n",
      "relation": {
        "kind": "single-post",
        "head_id": null
      },
      "capture": {
        "status": "held",
        "artefact_count": 2,
        "conversation_copies": 0,
        "conversation_posts": 0,
        "conversation_replies": 0,
        "conversation_gaps": []
      }
    },
    {
      "id": "w_s_bitcoin-2085272933748908130",
      "title": "Case for hiring AI auditors",
      "url": "https://x.com/w_s_bitcoin/status/2085272933748908130",
      "author": "w_s_bitcoin",
      "platform": "x",
      "organisation": null,
      "posted": "2026-08-06T07:53:04Z",
      "role": "social-statement",
      "why_registered": "Wicked says he will keep testing his own devices informally and making tutorials\nof what owners can try, but that the real testing and debugging will always\ndepend on people who can code, and that the good news is it is becoming far more\naccessible to hire an expert, by which he means an AI model, to thoroughly audit\nany software you use. He calls it the dawn of a new era. Held as one node in the\nrunning argument across this record about AI-assisted auditing after the\nincident, from an account that also posted evacuation advice and a same-day\nwalk-back during the same week. The claim that model audits are now a workable\nsubstitute is the poster's own and is not verified here.\n",
      "relation": {
        "kind": "single-post",
        "head_id": null
      },
      "capture": {
        "status": "held",
        "artefact_count": 2,
        "conversation_copies": 0,
        "conversation_posts": 0,
        "conversation_replies": 0,
        "conversation_gaps": []
      }
    },
    {
      "id": "dotkrueger-2085507527178092813",
      "title": "Offline dice-seed tool",
      "url": "https://x.com/dotkrueger/status/2085507527178092813?s=20",
      "author": "dotkrueger",
      "platform": "x",
      "organisation": null,
      "posted": "2026-08-06T23:25:15Z",
      "role": "social-statement",
      "why_registered": "Fred Krueger argues that rolling a die 60 times takes two minutes and converting\nthe rolls to a seed phrase takes one, and asks whether the reader's bitcoin is\nworth three minutes. The attached screenshot shows an offline single-file tool\nheaded \"Offline Dice Seed\" that turns 60 six-sided rolls into a 12-word BIP-39\nphrase, with instructions to write the words down by hand and clear the page.\nHeld as a specimen of the dice-entropy advice that spread after the incident and\nof the tools people were pointed at, which is the form the advice took rather\nthan an endorsement of it. The capture does not establish who wrote the tool or\nwhether it behaves as described. The claim and the recommendation are the\nposter's own; the tool is not examined here.\n",
      "relation": {
        "kind": "single-post",
        "head_id": null
      },
      "capture": {
        "status": "held",
        "artefact_count": 5,
        "conversation_copies": 0,
        "conversation_posts": 0,
        "conversation_replies": 0,
        "conversation_gaps": []
      }
    },
    {
      "id": "finnejay-2085508061704389059",
      "title": "Dice-overlap probability argument",
      "url": "https://x.com/finnejay/status/2085508061704389059",
      "author": "finnejay",
      "platform": "x",
      "organisation": null,
      "posted": "2026-08-06T23:27:23Z",
      "role": "social-statement",
      "why_registered": "A thought experiment: taking the affected generator's range as roughly 1.1\ntrillion outcomes, or 40 bits, the poster computes the odds that a dice-rolled\nseed nonetheless lands inside that range as a figure with more than seventy\nleading zeros, and sets it beside the odds of being struck by lightning and of\nwinning a lottery. He concludes that people are misframing the difference\nbetween breaking a small range of outcomes and breaking single-sig, and tells\nreaders to roll the dice and record the results themselves. Held as a distinct\nargument in the dice debate; note that the objection raised elsewhere in the\nrecord, at notgrubles-2085481084888760400, is about firmware discarding dice\ninput rather than about coincidental overlap, so the two are answering different\nquestions. Held sources put the Mk3 figure variously at about 23, 32 and 40\nbits. The arithmetic, the framing and the advice are the poster's own and are not\nverified here.\n",
      "relation": {
        "kind": "single-post",
        "head_id": null
      },
      "capture": {
        "status": "held",
        "artefact_count": 2,
        "conversation_copies": 0,
        "conversation_posts": 0,
        "conversation_replies": 0,
        "conversation_gaps": []
      }
    },
    {
      "id": "julianor-2085162138956374408",
      "title": "Claimed 2014 origin of a JavaScript RNG weakness",
      "url": "https://x.com/julianor/status/2085162138956374408",
      "author": "julianor",
      "platform": "x",
      "organisation": null,
      "posted": "2026-08-06T00:32:49Z",
      "role": "social-statement",
      "why_registered": "Juliano Rizzo posts the line \"Introduced in 2014, wallet drain exploit detected\nin 2026:\" over a screenshot of a discussion dated 25 April 2014, addressed to\n@daviddahl, about JavaScript entropy: it offers a custom generator built on\nKnuth's linear congruential PRNG, seeded in part from Math.random, and closes by\nnoting the result is still predictable if you control all the parameters. The\npost names neither the library nor the 2026 drain it has in mind, and the code\nshown is JavaScript library code rather than COLDCARD firmware. Held because a\nsecurity researcher is dating a second, separate entropy failure to 2014 and\ntying it to a 2026 drain, a parallel MAGS draws explicitly a few hours later at\ncrypto_mags-2085586783803453912. The identification and the connection are the\nposter's own and are not verified here.\n",
      "relation": {
        "kind": "single-post",
        "head_id": null
      },
      "capture": {
        "status": "held",
        "artefact_count": 5,
        "conversation_copies": 0,
        "conversation_posts": 0,
        "conversation_replies": 0,
        "conversation_gaps": []
      }
    },
    {
      "id": "julianor-2085397986461319667",
      "title": "Assessment of the 2014 JavaScript generator",
      "url": "https://x.com/julianor/status/2085397986461319667",
      "author": "julianor",
      "platform": "x",
      "organisation": null,
      "posted": "2026-08-06T16:09:59Z",
      "role": "social-statement",
      "why_registered": "Security researcher Juliano Rizzo's follow-up to his own post held at\njulianor-2085162138956374408, which he quotes here. He tentatively attributes\nthe 2014 code to a named account, with a question mark, and assesses it: the\nproposed generator makes the secret keys crackable, whereas using a modern\nbrowser's Math.random directly would not, and while Math.random is not a\ncryptographically secure generator, Xorshift128+ is a better PRNG than the\nmultiply-with-carry construction shown. His summary line is that it is easy to\nmake a cryptographic system weaker. Held as the technical substance behind the\nparallel entropy failure he raised, which is a JavaScript wallet library and not\nCOLDCARD firmware; the same parallel is drawn at\ncrypto_mags-2085586783803453912. The attribution of authorship and the\ncrackability assessment are the poster's own and are not verified here.\n",
      "relation": {
        "kind": "single-post",
        "head_id": null
      },
      "capture": {
        "status": "held",
        "artefact_count": 2,
        "conversation_copies": 0,
        "conversation_posts": 0,
        "conversation_replies": 0,
        "conversation_gaps": []
      }
    },
    {
      "id": "crypto_banter-2085630161265779010",
      "title": "Reported 30 BTC movement of the stolen funds",
      "url": "https://x.com/crypto_banter/status/2085630161265779010",
      "author": "crypto_banter",
      "platform": "x",
      "organisation": null,
      "posted": "2026-08-07T07:32:34Z",
      "role": "social-statement",
      "why_registered": "Crypto Banter reports, citing Lookonchain, that the wallet tied to the COLDCARD\nexploit has transferred 30 BTC, about US$1.94 million, to a new address, and\nnotes that most of the stolen funds had sat idle until this move. It restates the\nbackground figures as an estimated 2,055 BTC, about US$130 million, taken from\nmore than 7,700 addresses after a firmware vulnerability let seed phrases be\ncracked. Held because movement of the consolidated proceeds is the specific event\nthe archive's chain monitors exist to catch: glxyresearch-attacker-holdings\nrecords the endpoint set as fully unspent on 1 August, and\nglxy-law-enforcement-handoff puts 90 percent of the coins unmoved on 3 August, so\na reported spend on 7 August is a change in the funds picture rather than routine\ncommentary. This is a secondary relay by a commercial media account: the\nunderlying Lookonchain observation is not held here, the transaction is not\nidentified in the post, and the 2,055 BTC figure is Galaxy's estimate, which the\nloss accounting at /record/funds/ presents alongside the others rather than\nadopting. None of it is verified here.\n",
      "relation": {
        "kind": "single-post",
        "head_id": null
      },
      "capture": {
        "status": "held",
        "artefact_count": 5,
        "conversation_copies": 0,
        "conversation_posts": 0,
        "conversation_replies": 0,
        "conversation_gaps": []
      }
    },
    {
      "id": "tftc21-2085049442932314288",
      "title": "Relayed Mk3 honeypot fee race",
      "url": "https://x.com/tftc21/status/2085049442932314288",
      "author": "tftc21",
      "platform": "x",
      "organisation": null,
      "posted": "2026-08-05T17:05:00Z",
      "role": "social-statement",
      "why_registered": "TFTC relays a honeypot run by @we_satoshis: a vulnerable Coldcard Mk3 was hit by\nan attacker ten seconds after sats were deposited, a pre-signed RBF transaction\nraced the attacker and won, the attacker returned with a higher fee, and the\nrace continues until every sat is burned in mining fees rather than reaching the\nattacker. The attached images show a device running firmware 5.0.1 dated\n2021-10-29, a mempool view with a 9,000 sat fee at 82.4 sat/vB, and a device\nscreen reading \"Balance Online 86% / Watch Guard / Panic TX Expired\"; a video is\nattached and is not captured by this tool. Held as a dated, instrumented\nobservation of attacker response time on an affected Mk3, alongside the\ncktripwire honeypots already in the record. TFTC is a media outlet relaying\nsomeone else's experiment: the setup, the ten-second figure and the account of\nthe fee race are the experimenter's and are not verified here.\n",
      "relation": {
        "kind": "single-post",
        "head_id": null
      },
      "capture": {
        "status": "held",
        "artefact_count": 11,
        "conversation_copies": 0,
        "conversation_posts": 0,
        "conversation_replies": 0,
        "conversation_gaps": []
      }
    },
    {
      "id": "Excellion-2085503377514062281",
      "title": "Anti-Exfil credited to Blockstream",
      "url": "https://x.com/Excellion/status/2085503377514062281?s=20",
      "author": "Excellion",
      "platform": "x",
      "organisation": null,
      "posted": "2026-08-06T23:08:46Z",
      "role": "social-statement",
      "why_registered": "Samson Mow's claim that the Anti-Exfil protocol originated at Blockstream, which\nhe says wrote the first production-ready code for it, with a plain-language\nexplanation that a dishonest hardware wallet can leak fragments of a private key\nthrough the nonces in its signatures until a chain observer can reassemble the\nkey. He names Blockstream Jade and BitBox, which calls it Anti-Klepto, as the\nonly two hardware wallets that implement it, credits Blockstream and Adam Back\nwith protecting users since 2021, and quote-posts Blockstream Jade making the\nsame point. Held as part of the record of competing vendors positioning\nthemselves after the disclosure, alongside jade-not-affected and\nbitbox-not-affected, and because it concerns a different failure mode, nonce\nexfiltration at signing, from the seed-generation defect at issue in this\nincident. Interest: the poster is a former Blockstream executive and the post is\na product claim for Blockstream's wallet. Replies to the post are restricted. The\norigination and implementation claims are the poster's own and are not verified\nhere.\n",
      "relation": {
        "kind": "single-post",
        "head_id": null
      },
      "capture": {
        "status": "held",
        "artefact_count": 2,
        "conversation_copies": 0,
        "conversation_posts": 0,
        "conversation_replies": 0,
        "conversation_gaps": []
      }
    },
    {
      "id": "crypto_mags-2085586783803453912",
      "title": "CryptoJS cited as a parallel entropy failure",
      "url": "https://x.com/crypto_mags/status/2085586783803453912",
      "author": "crypto_mags",
      "platform": "x",
      "organisation": null,
      "posted": "2026-08-07T04:40:12Z",
      "role": "social-statement",
      "why_registered": "MAGS argues Coldcard is not the only recent wallet drain caused by an entropy\nfailure at seed generation, saying CryptoJS also had a long undetected bug that\nmade the system fall back to weak or predictable number generation and that it\ntoo sat unnoticed for years, and adds that he is glad the Red Team is seeking\nbugs. The same parallel is drawn a few hours earlier, without naming a library,\nby Juliano Rizzo at julianor-2085162138956374408. The poster states elsewhere in\nthis record that he is himself a victim of the Coldcard incident. The CryptoJS\ncharacterisation and the drains attributed to it are the poster's own and are not\nverified here.\n",
      "relation": {
        "kind": "single-post",
        "head_id": null
      },
      "capture": {
        "status": "held",
        "artefact_count": 2,
        "conversation_copies": 0,
        "conversation_posts": 0,
        "conversation_replies": 0,
        "conversation_gaps": []
      }
    },
    {
      "id": "mtanguma-2085087252535755218",
      "title": "Inheritance case for multi-institution custody",
      "url": "https://x.com/mtanguma/status/2085087252535755218",
      "author": "mtanguma",
      "platform": "x",
      "organisation": null,
      "posted": "2026-08-05T19:35:14Z",
      "role": "social-statement",
      "why_registered": "Michael Tanguma argues that self-custody as practised has become unreasonable,\nopening with a conversation he reports having with a bitcoin-only owner who uses\na COLDCARD and Sparrow and who said that rolling dice 100 times and expecting his\nwife to inherit that setup is preposterous. He lists seed phrases, metal plates,\nfirmware risk, inheritance risk, device risk and duress risk as burdens the\nindustry pushed onto users, says self-custody still matters, and concludes that\nserious wealth needs multi-institution custody secured by several institutions\nand controlled by the client. Tanguma is a principal at Onramp Bitcoin and\nmulti-institution custody is Onramp's product, so this is a vendor argument for\nthe vendor's own model; the archive holds his earlier and more explicit pitch at\nonramp-custody-guidance. Held as a dated statement of the custody-model argument\nthe incident revived, alongside coryswan-2085077996738941204 on the opposite\nside. The reported conversation and the characterisation of the industry are the\nposter's own and are not verified here.\n",
      "relation": {
        "kind": "single-post",
        "head_id": null
      },
      "capture": {
        "status": "held",
        "artefact_count": 2,
        "conversation_copies": 0,
        "conversation_posts": 0,
        "conversation_replies": 0,
        "conversation_gaps": []
      }
    },
    {
      "id": "rob1ham-2085196583927218345",
      "title": "Red Team sign-off and donation appeal",
      "url": "https://x.com/rob1ham/status/2085196583927218345",
      "author": "rob1ham",
      "platform": "x",
      "organisation": null,
      "posted": "2026-08-06T02:49:41Z",
      "role": "social-statement",
      "why_registered": "A short overnight sign-off from a Bitcoin Red Team participant: no substantive\nupdate, a week without sleep, a promise of big updates the next day, a note that\ncalle has built a new agent, which the capture renders as a robot emoji, and a\nrequest that supporters donate to OpenSats. It carries no findings and is held\nas chronology and as further provenance for the OpenSats funding route already\nrecorded at callebtc-2085101769500377193 and rob1ham-2085108517262782467.\nInterest: this project's watch list records Rob Hamilton as a Red Team\nparticipant, so he is soliciting support for work he takes part in. The\ncharacterisation of the new tooling is his and is not verified here.\n",
      "relation": {
        "kind": "single-post",
        "head_id": null
      },
      "capture": {
        "status": "held",
        "artefact_count": 2,
        "conversation_copies": 0,
        "conversation_posts": 0,
        "conversation_replies": 0,
        "conversation_gaps": []
      }
    },
    {
      "id": "oomahq-2085069274872156327",
      "title": "Résumé-screenshot allegation",
      "url": "https://x.com/oomahq/status/2085069274872156327",
      "author": "oomahq",
      "platform": "x",
      "organisation": null,
      "posted": "2026-08-05T18:23:48Z",
      "role": "social-statement",
      "why_registered": "A one-line reply in a thread that was reading through the published résumé of\nan individual connected to the incident, attaching a screenshot of that résumé\nwith several lines highlighted. The post makes an allegation about that\nperson's past work and character; this project describes that an allegation was\nmade rather than repeating it, because no held source supports it and the post\noffers nothing beyond its own reading of the attached document. It is kept\nbecause the thread circulated and the record documents what was said about the\nparties, not because the claim is established. The identification, the reading\nof the résumé and the inference drawn from it are the poster's own and are not\nverified here.\n",
      "relation": {
        "kind": "single-post",
        "head_id": null
      },
      "capture": {
        "status": "held",
        "artefact_count": 5,
        "conversation_copies": 0,
        "conversation_posts": 0,
        "conversation_replies": 0,
        "conversation_gaps": []
      }
    },
    {
      "id": "supertestnet-2085449733083218014",
      "title": "Question about the good generator's seeding",
      "url": "https://x.com/supertestnet/status/2085449733083218014",
      "author": "supertestnet",
      "platform": "x",
      "organisation": null,
      "posted": "2026-08-06T19:35:36Z",
      "role": "social-statement",
      "why_registered": "Super Testnet observes that the device had two random number generators, notes\nthat the bad one was seeded with keypresses, a timestamp and the device id, says\nthat is roughly how he would have seeded it himself, and asks what the good one\nwas seeded with. The question turns the discussion from the failure of the weak\npath to what made the intended path adequate. The record holds the relevant\nprimary material: libngu random.c at libngu-random-c, and Coinkite's account at\ncoldcardwallet-2085541034243600805 that seed generation was meant to use the\nhardware TRNG alone. The characterisation of the two generators is the poster's\nown and is not verified here.\n",
      "relation": {
        "kind": "single-post",
        "head_id": null
      },
      "capture": {
        "status": "held",
        "artefact_count": 2,
        "conversation_copies": 0,
        "conversation_posts": 0,
        "conversation_replies": 0,
        "conversation_gaps": []
      }
    },
    {
      "id": "sesi_the_man-2085395065837363694",
      "title": "SeedSigner contributor's three prior warnings",
      "url": "https://x.com/sesi_the_man/status/2085395065837363694",
      "author": "sesi_the_man",
      "platform": "x",
      "organisation": null,
      "posted": "2026-08-06T15:58:23Z",
      "role": "social-statement",
      "why_registered": "Seed lists three positions he says he has argued for a long time: that users\nshould supply their own individual entropy for private keys, that hardware\nwallet companies are a centralising function with respect to risk, and that the\nincentive to provide an easy button that conceals complexity is a net loss. He\ndirects readers to his own post history and interviews and to the @SeedSigner\naccount, which he says he used as a personal account for a long time. The\ninterest is on the face of the post: SeedSigner is a DIY signing project that\ncompetes with Coldcard and whose design centres user-supplied entropy. Held as a\nnamed party's dated claim of a prior record, specific about where that record is\nsaid to be; the claimed track record is the poster's own and is not verified\nhere.\n",
      "relation": {
        "kind": "single-post",
        "head_id": null
      },
      "capture": {
        "status": "held",
        "artefact_count": 2,
        "conversation_copies": 0,
        "conversation_posts": 0,
        "conversation_replies": 0,
        "conversation_gaps": []
      }
    },
    {
      "id": "x_imp0stor-2085542831729279480",
      "title": "Personal update carrying an aside on seed generation",
      "url": "https://x.com/x_imp0stor/status/2085542831729279480",
      "author": "x_imp0stor",
      "platform": "x",
      "organisation": null,
      "posted": "2026-08-07T01:45:33Z",
      "role": "social-statement",
      "why_registered": "A long personal update, published by its author, reporting that he has returned\nhome from hospital after a medical emergency described in his own quoted earlier\npost as a stroke and possibly a heart attack with identified brain damage, and\nthat he does not yet know how the damage will affect him. Most of the post is\nabout his life rather than the incident: finances, a job search, past bitcoin\nlosses through Mt. Gox, Cryptsy, BlockFi, Celsius and a collateralised loan, a\nbacklog of nostr and podcast projects, and hardware he wants to put to use. Two\npassages touch the record. He expresses sympathy for people who have lost their\nsavings, saying he has been on their side of such events more than once, and he\nmakes a one-line aside imputing intent to the way the affected seed-generation\ncode was released, which no captured source supports and which this archive does\nnot repeat as a finding. Held as first-hand community-response material, with the\ncaveat that its incident content is slight; everything in it is the author's own\npublished account and none of it is verified here.\n",
      "relation": {
        "kind": "single-post",
        "head_id": null
      },
      "capture": {
        "status": "held",
        "artefact_count": 5,
        "conversation_copies": 0,
        "conversation_posts": 0,
        "conversation_replies": 0,
        "conversation_gaps": []
      }
    },
    {
      "id": "stack2thefuture-2085441154602905685",
      "title": "Argument for passphrases on multisig too",
      "url": "https://x.com/stack2thefuture/status/2085441154602905685",
      "author": "stack2thefuture",
      "platform": "x",
      "organisation": null,
      "posted": "2026-08-06T19:01:31Z",
      "role": "social-statement",
      "why_registered": "A short, direct guidance argument: stop telling people not to use passphrases for\nmultisig, because that advice only made sense before the COLDCARD exploit, and\nevery wallet should now have a passphrase, multisig included. Held because it\ntakes a position against advice circulating elsewhere in the record, and because\npassphrase use is one of the mitigations owners were actively deciding about\nduring the migration window. It gives no reasoning beyond the assertion and cites\nno analysis. The archive does not adjudicate between competing migration advice;\nthis is the poster's own recommendation and is not verified or endorsed here.\n",
      "relation": {
        "kind": "single-post",
        "head_id": null
      },
      "capture": {
        "status": "held",
        "artefact_count": 2,
        "conversation_copies": 0,
        "conversation_posts": 0,
        "conversation_replies": 0,
        "conversation_gaps": []
      }
    },
    {
      "id": "coldcardwallet-2085452152458080731",
      "title": "Vendor pointer to GitHub for coming firmware",
      "url": "https://x.com/coldcardwallet/status/2085452152458080731",
      "author": "coldcardwallet",
      "platform": "x",
      "organisation": null,
      "posted": "2026-08-06T19:45:13Z",
      "role": "social-statement",
      "why_registered": "COLDCARD tells followers they can follow the next firmware updates on GitHub and\nsays the vendor is focusing on the next release and customer key migration,\nclosing by directing readers to a warning quoted below the post. Short, but a\nprimary vendor artefact: it dates the point at which Coinkite publicly named\ncustomer key migration as a focus and sent owners to the repository rather than\nto an advisory page. Held for that timeline value. No release number, contents or\ndate is given.\n",
      "relation": {
        "kind": "single-post",
        "head_id": null
      },
      "capture": {
        "status": "held",
        "artefact_count": 2,
        "conversation_copies": 0,
        "conversation_posts": 0,
        "conversation_replies": 0,
        "conversation_gaps": []
      }
    },
    {
      "id": "w_s_bitcoin-2084963782074183915",
      "title": "Prompt for retro-classifying pre-incident drain reports",
      "url": "https://x.com/w_s_bitcoin/status/2084963782074183915",
      "author": "w_s_bitcoin",
      "platform": "x",
      "organisation": null,
      "posted": "2026-08-05T11:24:37Z",
      "role": "social-statement",
      "why_registered": "Wicked announces that he is running a language model over publicly reported\nCOLDCARD losses that predate the disclosure, to estimate how many were seed\ncollisions rather than ordinary theft, and posts four screenshots of the prompt\nitself rather than a conclusion. The prompt sets firmware inclusion criteria at\nroughly 2^50 to 2^63 for Mk3 and Mk4 entropy, tells the model to exclude losses\nattributable to phishing, supply-chain compromise, malware or physical access,\nand asks for a per-report classification, a probability comparison against\naccidental collision, a sensitivity analysis and a confidence score. It is held\nfor the method: the archive already carries contested claims that owners were\ndrained before July 2026, in btctherapist-prior-drain-report and\nreddit-ledgerwallet-drain-comment, and this is a dated attempt to sort them\nsystematically with the criteria published in advance. No result is contained in\nthis post, and the estimates the prompt asks for would be the model's output, not\na finding verified here.\n",
      "relation": {
        "kind": "single-post",
        "head_id": null
      },
      "capture": {
        "status": "held",
        "artefact_count": 11,
        "conversation_copies": 0,
        "conversation_posts": 0,
        "conversation_replies": 0,
        "conversation_gaps": []
      }
    },
    {
      "id": "stephanlivera-2085616362899251420",
      "title": "Self-custody variables and multisig argument",
      "url": "https://x.com/stephanlivera/status/2085616362899251420",
      "author": "stephanlivera",
      "platform": "x",
      "organisation": null,
      "posted": "2026-08-07T06:37:44Z",
      "role": "social-statement",
      "why_registered": "Stephan Livera setting out why self-custody is hard to teach: the right answer\ndepends on the amount secured, privacy appetite, tolerance for complexity, the\ntradeoff between sovereignty and easy recovery, inheritance plans and whether\nservices such as loans are needed. He predicts a push to remove single points\nof failure in an easier form, closer to what Bitkey and Casa offer, with dice\nrolls, multi-vendor multisig and a private Electrum server remaining a smaller\ngroup's path; and argues correctly executed multisig gives fault tolerance,\nsince a key found to be bad in a 3-of-5 can be rotated out without loss. The\npost names two commercial multi-key providers approvingly, which is worth\nnoting given Livera's position as a bitcoin podcaster and commentator. The\npredictions and recommendations are his own.\n",
      "relation": {
        "kind": "single-post",
        "head_id": null
      },
      "capture": {
        "status": "held",
        "artefact_count": 2,
        "conversation_copies": 0,
        "conversation_posts": 0,
        "conversation_replies": 0,
        "conversation_gaps": []
      }
    },
    {
      "id": "ledger-2085659114617581865",
      "title": "Ledger CTO on open source and security",
      "url": "https://x.com/ledger/status/2085659114617581865",
      "author": "ledger",
      "platform": "x",
      "organisation": null,
      "posted": "2026-08-07T09:27:37Z",
      "role": "social-statement",
      "why_registered": "Ledger's company account promotes an argument by its chief technology officer\nthat open source is valuable but is not in itself a security property, quoting\nthe line that if your security model is that the crowd will save you then you do\nnot have a security model, you have a hope. Held as a named competing vendor's\npublished position on the review question the incident raised, and treated on the\nstatements page beside Ledger's separate not-affected claim. Ledger is a\ncompeting hardware-wallet vendor and the post is a branded card for its own\nsecurity posture, so the commercial interest is on the face of it. The linked\narticle is not held here: the record holds the post and the line it quotes. The\nargument is Ledger's own.\n",
      "relation": {
        "kind": "single-post",
        "head_id": null
      },
      "capture": {
        "status": "held",
        "artefact_count": 5,
        "conversation_copies": 0,
        "conversation_posts": 0,
        "conversation_replies": 0,
        "conversation_gaps": []
      }
    },
    {
      "id": "renepickhardt-2085358431456670078",
      "title": "Manual Electrum review offered against the AI sweep",
      "url": "https://x.com/renepickhardt/status/2085358431456670078",
      "author": "renepickhardt",
      "platform": "x",
      "organisation": null,
      "posted": "2026-08-06T13:32:48Z",
      "role": "social-statement",
      "why_registered": "Rene Pickhardt says that while everyone is burning millions of tokens on AI\nreview, he did his own small part the old-fashioned way, and links a hand-written\ncode review he filed on Electrum pull request 10794. He closes by asking whether\ncallebtc or Rob Hamilton found anything more critical in Electrum. Held because\nit is a dated, checkable counterpoint in the AI-review debate the archive already\ncarries through rob1ham-2084140242915782743 and milessuter-2084619892699897882:\na named researcher doing manual review on the same codebases the automated sweep\ncovered, with the review itself public and linkable. The post makes no claim\nabout what either effort found, and the review's contents are not assessed here.\n",
      "relation": {
        "kind": "single-post",
        "head_id": null
      },
      "capture": {
        "status": "held",
        "artefact_count": 2,
        "conversation_copies": 0,
        "conversation_posts": 0,
        "conversation_replies": 0,
        "conversation_gaps": []
      }
    },
    {
      "id": "threatwire_-2085593099749749082",
      "title": "Ill Bloom proof-of-concept alert",
      "url": "https://x.com/threatwire_/status/2085593099749749082",
      "author": "threatwire_",
      "platform": "x",
      "organisation": null,
      "posted": "2026-08-07T05:05:18Z",
      "role": "social-statement",
      "why_registered": "A security-news account reporting that a public proof of concept has been\nreleased for Ill Bloom, described as a twelve-year-old weak-entropy flaw in\nCryptoJS, and linking a GitHub repository holding it. It says the flaw reduced\nseed-phrase entropy to 2^39, in the post's words \"just 2^39 bits\", and that\nbrute-force attacks have already drained US$5.69M from 2,114 wallets. This is a\nseparate defect from the COLDCARD one, held because it is the parallel\nweak-entropy story running in the same week and because another registered\nsource describes an affected wallet in the same terms. None of the figures, the\nproof of concept or the loss total is checked here, and the claims are the\nposter's own.\n",
      "relation": {
        "kind": "single-post",
        "head_id": null
      },
      "capture": {
        "status": "held",
        "artefact_count": 2,
        "conversation_copies": 0,
        "conversation_posts": 0,
        "conversation_replies": 0,
        "conversation_gaps": []
      }
    },
    {
      "id": "fractalencrypt-2085079159085363426",
      "title": "Advice to delay non-critical updates",
      "url": "https://x.com/fractalencrypt/status/2085079159085363426",
      "author": "fractalencrypt",
      "platform": "x",
      "organisation": null,
      "posted": "2026-08-05T19:03:05Z",
      "role": "social-statement",
      "why_registered": "Quote-posts the Bitcoin Red Team's Situation Report No. 1, whose figures are\n4,962 findings across 390 of 391 projects reviewed, 85 critical and 635 high\nseverity in 29.8 hours, and draws an unusual conclusion from them: because much\nof the ecosystem is about to ship fixes, owners should wait two or more weeks\nbefore applying any update that is not mission critical, so that other users\nencounter and report the new bugs first. Held because it is a distinct argument\nin the post-incident software debate, running against the migrate-and-update-now\nadvice held elsewhere in this record, and because it treats the audit wave\nitself as a source of risk. The primary post for the quoted figures is held at\ncallebtc-2085024458012586286. The underlying findings are not public, and both\nthe counts and the update advice are the posters' own and are not verified here.\n",
      "relation": {
        "kind": "single-post",
        "head_id": null
      },
      "capture": {
        "status": "held",
        "artefact_count": 2,
        "conversation_copies": 0,
        "conversation_posts": 0,
        "conversation_replies": 0,
        "conversation_gaps": []
      }
    },
    {
      "id": "btcqna-2085363250716184739",
      "title": "Coldcard Derangement Syndrome jibe",
      "url": "https://x.com/btcqna/status/2085363250716184739",
      "author": "btcqna",
      "platform": "x",
      "organisation": null,
      "posted": "2026-08-06T13:51:57Z",
      "role": "social-statement",
      "why_registered": "A two-line joke defining \"Coldcard Derangement Syndrome\" as the belief that a\nproduct is more secure simply because it is ugly and cumbersome to use. It makes\nno factual claim and offers no evidence. It is held because the\nausterity-as-security argument it mocks recurs across the record, at length in\nthe Bitcoin Well essay captured the same day, and this is the compressed form in\nwhich the counter-argument spread. Opinion, attributed to the poster.\n",
      "relation": {
        "kind": "single-post",
        "head_id": null
      },
      "capture": {
        "status": "held",
        "artefact_count": 2,
        "conversation_copies": 0,
        "conversation_posts": 0,
        "conversation_replies": 0,
        "conversation_gaps": []
      }
    },
    {
      "id": "bradmillscan-2085526168766193956",
      "title": "Comparison with the last cycle's collapses",
      "url": "https://x.com/bradmillscan/status/2085526168766193956",
      "author": "bradmillscan",
      "platform": "x",
      "organisation": null,
      "posted": "2026-08-07T00:39:20Z",
      "role": "social-statement",
      "why_registered": "Brad Mills, saying he has been in bitcoin since 2011, judges this worse than the\nexchange, lending and NFT collapses at the bottom of the previous cycle, and\nquotes Alex Gladstein agreeing that it is the worst thing he has seen in the\nspace in ten years of paying attention. Held as a dated marker of how the\nincident registered against earlier bitcoin disasters among long-standing\nparticipants, and because it preserves Gladstein's assessment in the quoted card.\nIt contains no factual claim about the defect or the losses. Both judgements are\ntheir authors' own.\n",
      "relation": {
        "kind": "single-post",
        "head_id": null
      },
      "capture": {
        "status": "held",
        "artefact_count": 2,
        "conversation_copies": 0,
        "conversation_posts": 0,
        "conversation_replies": 0,
        "conversation_gaps": []
      }
    },
    {
      "id": "juansgalt-2085465000441790915",
      "title": "Suggestion that Trezor acquire Coinkite IP",
      "url": "https://x.com/juansgalt/status/2085465000441790915",
      "author": "juansgalt",
      "platform": "x",
      "organisation": null,
      "posted": "2026-08-06T20:36:16Z",
      "role": "social-statement",
      "why_registered": "Juan Galt suggests it would be a big win if Trezor bought Coinkite's\nintellectual property, cleaned up the firmware and kept the form factor. It is a\nspeculation with nothing behind it: no offer, approach, valuation or source is\nclaimed, and neither named company is quoted. Held as a dated data point in the\nvendor-viability discussion that ran through the first week, where owners and\ncommentators openly weighed Coinkite continuing, being acquired or closing.\nNothing here indicates the position of either company.\n",
      "relation": {
        "kind": "single-post",
        "head_id": null
      },
      "capture": {
        "status": "held",
        "artefact_count": 2,
        "conversation_copies": 0,
        "conversation_posts": 0,
        "conversation_replies": 0,
        "conversation_gaps": []
      }
    },
    {
      "id": "sgbarbour-2085335893812957462",
      "title": "Defence of Coldcard's featureset and reputation",
      "url": "https://x.com/sgbarbour/status/2085335893812957462",
      "author": "sgbarbour",
      "platform": "x",
      "organisation": null,
      "posted": "2026-08-06T12:03:15Z",
      "role": "social-statement",
      "why_registered": "Steve Barbour, replying to Wicked's thread on the features Coldcard brought to\nthe category, argues that Coldcard had the best featureset of any hardware\nwallet and that people bought it mainly for that reason rather than because of\npodcast shills or maxi influencers, and that Coinkite had been well regarded\nsince the Opendime for its innovation and cypherpunk ideals. Held because it is\na dated, direct rejection of the paid-influencer framing that other material in\nthis record advances, including Ben Hart's same-day reflections and BasedLayer's\ninfluencers-over-engineers argument. The record carries both readings of why\nbuyers chose the device without choosing between them; this one is the poster's\nown and is not verified here.\n",
      "relation": {
        "kind": "single-post",
        "head_id": null
      },
      "capture": {
        "status": "held",
        "artefact_count": 2,
        "conversation_copies": 0,
        "conversation_posts": 0,
        "conversation_replies": 0,
        "conversation_gaps": []
      }
    },
    {
      "id": "csuwildcat-2085372469527859442",
      "title": "Key rolling and the Nostr identity comparison",
      "url": "https://x.com/csuwildcat/status/2085372469527859442",
      "author": "csuwildcat",
      "platform": "x",
      "organisation": null,
      "posted": "2026-08-06T14:28:35Z",
      "role": "social-statement",
      "why_registered": "Argues that the incident is a case study in key rolling: owners rescuing funds\nfrom a COLDCARD are swapping keys while keeping ownership of the value, so\nownership is never permanently bound to a bad key. The post then turns that into\na criticism of Nostr, where the npub is the identifier an identity is built on,\nso an exposed or weakly generated key cannot be rolled off without losing the\nidentity, and it closes with an attached diagram contrasting the two cases.\nHeld because it is one of the few reactions that draws a general protocol-design\nlesson from the incident rather than a wallet-choice one. Interest: the post ends\nby trailing a forthcoming open-source identity effort the author says he is\nworking on with a named collaborator, so it doubles as a promotion for his own\nproject. The Nostr characterisation is the poster's own and is not verified here.\n",
      "relation": {
        "kind": "single-post",
        "head_id": null
      },
      "capture": {
        "status": "held",
        "artefact_count": 5,
        "conversation_copies": 0,
        "conversation_posts": 0,
        "conversation_replies": 0,
        "conversation_gaps": []
      }
    },
    {
      "id": "bitcoinwell-2085395233634689194",
      "title": "Bitcoin Well entropy webinar promotion",
      "url": "https://x.com/bitcoinwell/status/2085395233634689194",
      "author": "bitcoinwell",
      "platform": "x",
      "organisation": null,
      "posted": "2026-08-06T15:59:03Z",
      "role": "social-statement",
      "why_registered": "Bitcoin Well promoting a 13 August live session with researcher and filmmaker\nAlex Waltz on what entropy is and why \"random enough\" is not, framed by two\nfigures: a firmware flaw that drained US$130 million from self-custody wallets,\nand a volunteer red team that audited 390 Bitcoin codebases in a weekend and\nfiled thousands of findings. Bitcoin Well is a commercial bitcoin exchange and\nthe post is marketing for its own event, which is the interest to state.\nThe 390-codebase figure matches the held Red Team captures for 5 August; the\nUS$130 million is one of several circulating loss estimates that differ\nsubstantially, and this record does not choose between them (see /record/funds/).\nThe framing and the figures are the company's own.\n",
      "relation": {
        "kind": "single-post",
        "head_id": null
      },
      "capture": {
        "status": "held",
        "artefact_count": 5,
        "conversation_copies": 0,
        "conversation_posts": 0,
        "conversation_replies": 0,
        "conversation_gaps": []
      }
    },
    {
      "id": "theswansjr-2085416136716206553",
      "title": "Antifragility argument against the self-custody obituary",
      "url": "https://x.com/theswansjr/status/2085416136716206553",
      "author": "theswansjr",
      "platform": "x",
      "organisation": null,
      "posted": "2026-08-06T17:22:06Z",
      "role": "social-statement",
      "why_registered": "Jeff Swanson answers those calling the incident an obituary for self-custody\nwith the opposite reading: a five-year-old entropy bug was exploited, roughly\n$90 million was stolen, all of it visible on-chain and auditable in real time,\nthe network identified it within hours and a fix shipped within days, whereas a\nbank breach is buried, lawyered and ultimately socialised through inflation. He\nargues the exploit exposed a flaw in one specific product rather than in\nself-custody. Held partly for the $90 million figure, which sits below other\ntotals held here, including Galaxy's relayed estimate of 2,055 BTC or about $130\nmillion and Ben Hart's same-day $130 million; this record shows the range and\nwhat each figure assumes rather than picking one. The figure and the\nantifragility argument are the poster's own and are not verified here.\n",
      "relation": {
        "kind": "single-post",
        "head_id": null
      },
      "capture": {
        "status": "held",
        "artefact_count": 2,
        "conversation_copies": 0,
        "conversation_posts": 0,
        "conversation_replies": 0,
        "conversation_gaps": []
      }
    },
    {
      "id": "bramk-2084618965226074604",
      "title": "Resurfaced 2021 entropy joke with chatbot commentary",
      "url": "https://x.com/bramk/status/2084618965226074604",
      "author": "bramk",
      "platform": "x",
      "organisation": null,
      "posted": "2026-08-04T12:34:26Z",
      "role": "social-statement",
      "why_registered": "One word, \"Insane\", over a stacked screenshot: a COLDCARD post dated 10 October\n2021 joking that \"the project makers could have a 'bug' in the entropy\ngeneration for later retrieval\", a user asking Grok what the mathematical odds\nof that are, and Grok's reply. The reply names the retirement-attack pattern, in\nwhich makers intentionally weaken entropy so they can recover funds later, says\nthe odds of pure coincidence are \"effectively zero\", and then describes the 2026\nevent as an accidental firmware bug that reduced seed entropy to roughly 40 bits\non affected devices. Held because this is the vehicle by which the 2021 vendor\npost recirculated during the incident as an insinuation about the vendor's\nintent, and because that insinuation is carried entirely by machine-generated\ntext quoted inside an image rather than by anything the post itself establishes.\nNothing in the attached screenshot is verified here, and registration is not\nendorsement.\n",
      "relation": {
        "kind": "single-post",
        "head_id": null
      },
      "capture": {
        "status": "held",
        "artefact_count": 5,
        "conversation_copies": 0,
        "conversation_posts": 0,
        "conversation_replies": 0,
        "conversation_gaps": []
      }
    },
    {
      "id": "joseftetek-2085630468888695005",
      "title": "Reply to the vendor's disclosure remark",
      "url": "https://x.com/joseftetek/status/2085630468888695005",
      "author": "joseftetek",
      "platform": "x",
      "organisation": null,
      "posted": "2026-08-07T07:33:47Z",
      "role": "social-statement",
      "why_registered": "Josef Tetek quotes COLDCARD's reply to another account, saying the company is\ndoing all the investigation it can, that it is devastated, and that the hacker\ncould have done the right thing and responsibly disclosed, and answers\nsarcastically that hackers nowadays have zero manners. It is held for the quoted\nvendor line as much as for the reply: it preserves COLDCARD's framing of the\noperator as someone who should have disclosed, and one strand of the reaction to\nthat framing, which belongs to the disclosure-responsibility argument the record\nalready carries. The reply itself makes no factual claim. The view is the\nposter's own.\n",
      "relation": {
        "kind": "single-post",
        "head_id": null
      },
      "capture": {
        "status": "held",
        "artefact_count": 2,
        "conversation_copies": 0,
        "conversation_posts": 0,
        "conversation_replies": 0,
        "conversation_gaps": []
      }
    },
    {
      "id": "benhart_freedom-2085364758471917905",
      "title": "Holder's decision to abandon self-custody",
      "url": "https://x.com/benhart_freedom/status/2085364758471917905",
      "author": "benhart_freedom",
      "platform": "x",
      "organisation": null,
      "posted": "2026-08-06T13:57:57Z",
      "role": "social-statement",
      "why_registered": "A long first-person account from a 68-year-old holder who bought three\nCOLDCARDs, two Mk4s and a Q, generated his seed with 100 dice rolls and a\ndice-generated passphrase, and nonetheless moved everything to Coinbase when he\nheard about the incident, and is now considering Fidelity. He gives figures\nthroughout: more than 2,000 bitcoin, about $130 million, taken by 15 or more\nhackers; Coinkite at five employees against Ledger at about 900; about 4,000,000\nbitcoin, roughly $256 billion, lost to user error. He describes the defect as a\nhardware TRNG that was never switched on so the device fell back to a PRNG, and\nasserts that the top bitcoin influencers who called Coldcard the gold standard\nwere paid by Coinkite to hype it. Held because it is a rare, fully worked\nfirst-hand statement of the conclusion the incident produced in an ordinary\nholder: that trustlessness is not available in practice and that he would rather\ntrust Fidelity, Apple or a large bank than a small wallet company. The mechanism\ndescription, the loss and headcount figures and the paid-influencer assertion\nare his own and are not verified here, and the technical accounts held elsewhere\nin this record describe the failure differently.\n",
      "relation": {
        "kind": "single-post",
        "head_id": null
      },
      "capture": {
        "status": "held",
        "artefact_count": 2,
        "conversation_copies": 0,
        "conversation_posts": 0,
        "conversation_replies": 0,
        "conversation_gaps": []
      }
    },
    {
      "id": "profedustream-2084882092765421800",
      "title": "OP_RETURN threat and coinjoin trace",
      "url": "https://x.com/profedustream/status/2084882092765421800",
      "author": "profedustream",
      "platform": "x",
      "organisation": null,
      "posted": "2026-08-05T06:00:00Z",
      "role": "social-statement",
      "why_registered": "Two on-chain observations from 5 August by the analyst whose mapping graph is\nheld at profedustream-mapping-export. First: the address holding the largest\nshare of the stolen coins, given here as 562 BTC across 498 transactions,\nreceived an OP_RETURN message reading \"I know who you are now\" and \"You made\nthis bed for yourself, A.\"; the post links the transaction and asks whether it\nis a bluff. Second: it traces roughly 65 BTC taken from 465 addresses into a\nWasabi coordinator where that input made up about 93 percent of the round, and\nargues the result identified the output address, mixed only 10.6 BTC and left\nthat output's privacy weak because it was over 37 percent of the mixed coins.\nThe 562 BTC figure matches the largest of the four consolidation addresses in\nthe held Galaxy flow-of-funds post. Both readings, the identification and the\nconclusion that the operator was incompetent, are the poster's own and are not\nverified here.\n",
      "relation": {
        "kind": "single-post",
        "head_id": null
      },
      "capture": {
        "status": "held",
        "artefact_count": 7,
        "conversation_copies": 0,
        "conversation_posts": 0,
        "conversation_replies": 0,
        "conversation_gaps": []
      }
    },
    {
      "id": "bitcoinwell-2085381011769348122",
      "title": "Bitcoin Well design-revolution essay",
      "url": "https://x.com/bitcoinwell/status/2085381011769348122",
      "author": "bitcoinwell",
      "platform": "x",
      "organisation": null,
      "posted": "2026-08-06T15:02:32Z",
      "role": "social-statement",
      "why_registered": "A long post from the company account of Bitcoin Well, a bitcoin exchange and\nself-custody business, arguing that the answer to the incident is better-designed\nself-custody rather than surrendering keys, and linking its own blog essay \"Why\nBitcoin Needs a Design Revolution\". It restates the incident as roughly 594\nbitcoin, about US$38 million, from some 500 wallets in 25 minutes on 30 July,\ntraced by Block to a one-line build error shipped in March 2021 that skipped the\nhardware random number generator in favour of software randomness seeded from the\nchip's serial number and a timer, leaving a pool of about four billion, with\nsuspected related losses nearer US$116 million. It tells Mk2 and Mk3 owners to\nmove to a fresh seed made on a non-COLDCARD device, says Bitkey, Trezor and\nLedger were unaffected, and argues COLDCARD's austerity did no security work at\nall. The company is promoting its own essay and product direction while praising\na competing vendor's device, so the argument carries a commercial interest. The\nfigures are this author's restatement of numbers published by others and the\ndesign argument is his own; neither is verified here.\n",
      "relation": {
        "kind": "single-post",
        "head_id": null
      },
      "capture": {
        "status": "held",
        "artefact_count": 5,
        "conversation_copies": 0,
        "conversation_posts": 0,
        "conversation_replies": 0,
        "conversation_gaps": []
      }
    },
    {
      "id": "glxyresearch-2083560940469981591",
      "title": "Galaxy Research second-wave accounting",
      "url": "https://x.com/glxyresearch/status/2083560940469981591",
      "author": "glxyresearch",
      "platform": "x",
      "organisation": "Galaxy Research",
      "posted": "2026-08-01T14:30:13Z",
      "role": "social-statement",
      "why_registered": "Galaxy Research reports a second wave of sweeps attributed to the same Coldcard hacker, tracking 1,158.81 BTC stolen from 2,673 addresses and held unspent across seven attacker addresses. Held as Galaxy's own dated accounting update, distinct from the earlier 1,082.65 BTC and 1,596 BTC figures already in the record. The attribution and figures are the poster's own and are not independently verified here.\n",
      "relation": {
        "kind": "single-post",
        "head_id": null
      },
      "capture": {
        "status": "held",
        "artefact_count": 5,
        "conversation_copies": 0,
        "conversation_posts": 0,
        "conversation_replies": 0,
        "conversation_gaps": []
      }
    },
    {
      "id": "evands-2083505832587587945",
      "title": "First-hand drain report with address",
      "url": "https://x.com/evands/status/2083505832587587945",
      "author": "evands",
      "platform": "x",
      "organisation": null,
      "posted": "2026-08-01T10:51:14Z",
      "role": "social-statement",
      "why_registered": "Evan Schoenberg reports his own wallet was drained on 2026-07-31 16:16:55 UTC along with several other wallets of similar size in the same block, and gives the drained bc1q address. A first-hand victim account with a timestamp and address, held as reported and not independently verified beyond what the poster states.\n",
      "relation": {
        "kind": "single-post",
        "head_id": null
      },
      "capture": {
        "status": "held",
        "artefact_count": 2,
        "conversation_copies": 0,
        "conversation_posts": 0,
        "conversation_replies": 0,
        "conversation_gaps": []
      }
    },
    {
      "id": "kevinkelbie-2084294469126361372",
      "title": "Smaller sweep to a P2TR address",
      "url": "https://x.com/KevinKelbie/status/2084294469126361372",
      "author": "KevinKelbie",
      "platform": "x",
      "organisation": null,
      "posted": "2026-08-03T15:05:00Z",
      "role": "social-statement",
      "why_registered": "Kevin Kelbie reports a smaller sweep of 0.5 BTC and notes that the proceeds went to a P2TR address he had not seen before. Held as a tracker maintainer's dated on-chain lead about a possible new destination type. The observation is the poster's own and is not independently verified here.\n",
      "relation": {
        "kind": "single-post",
        "head_id": null
      },
      "capture": {
        "status": "held",
        "artefact_count": 5,
        "conversation_copies": 0,
        "conversation_posts": 0,
        "conversation_replies": 0,
        "conversation_gaps": []
      }
    },
    {
      "id": "intangiblecoins-2084584284837322868",
      "title": "New footprint O from a small victim report",
      "url": "https://x.com/intangiblecoins/status/2084584284837322868",
      "author": "intangiblecoins",
      "platform": "x",
      "organisation": null,
      "posted": "2026-08-04T10:16:37Z",
      "role": "social-statement",
      "why_registered": "Alex Thorn reports that a single victim report of less than 1 BTC stolen led his team to identify a new attack that siphoned 12 BTC from 126 addresses, labelled footprint O. Held as an incident responder's dated wave-correction update. The figures and the new footprint attribution are the poster's own and are not independently verified here.\n",
      "relation": {
        "kind": "single-post",
        "head_id": null
      },
      "capture": {
        "status": "held",
        "artefact_count": 2,
        "conversation_copies": 0,
        "conversation_posts": 0,
        "conversation_replies": 0,
        "conversation_gaps": []
      }
    },
    {
      "id": "eriklocalhost-2083875886458171626",
      "title": "First-hand Mk3 testing-device drain",
      "url": "https://x.com/eriklocalhost/status/2083875886458171626",
      "author": "eriklocalhost",
      "platform": "x",
      "organisation": null,
      "posted": "2026-08-02T11:21:42Z",
      "role": "social-statement",
      "why_registered": "Erik reports that a COLDCARD Mk3 he used for miscellaneous testing was swept in the morning, losing 9,000 sats from a native segwit address. Held as a first-hand victim account and because the coldcard.rip tracker names the same claimant for wave 960668. The details are the poster's own and are not independently verified here.\n",
      "relation": {
        "kind": "single-post",
        "head_id": null
      },
      "capture": {
        "status": "held",
        "artefact_count": 2,
        "conversation_copies": 0,
        "conversation_posts": 0,
        "conversation_replies": 0,
        "conversation_gaps": []
      }
    },
    {
      "id": "crypto-bitlord7-inside-job-claim",
      "title": "Inside-job allegation against the COLDCARD CTO",
      "url": "https://x.com/crypto_bitlord7/status/2085935413449916900",
      "author": "crypto_bitlord7",
      "platform": "x",
      "organisation": null,
      "posted": "2026-08-08T03:45:32Z",
      "role": "social-statement",
      "why_registered": "Crypto Bitlord alleges that the COLDCARD CTO shipped the faulty code while pretending to be someone else, that the CTO had a background in keyloggers and stealthy remote-controlled KVM switches, and that the malicious actor created the exploit to sit on for years. Held as a dated, specific inside-job claim made during the incident-response period. The allegations are the poster's own and are not verified here.\n",
      "relation": {
        "kind": "single-post",
        "head_id": null
      },
      "capture": {
        "status": "held",
        "artefact_count": 2,
        "conversation_copies": 0,
        "conversation_posts": 0,
        "conversation_replies": 0,
        "conversation_gaps": []
      }
    },
    {
      "id": "jamesob-2085881760848437478",
      "title": "CKTRIPWIRE honeypot additions",
      "url": "https://x.com/jamesob/status/2085881760848437478",
      "author": "jamesob",
      "platform": "x",
      "organisation": null,
      "posted": "2026-08-08T00:12:20Z",
      "role": "social-statement",
      "why_registered": "James O'Beirne announces that cktripwire.com has added a high-value two-dice-roll Mk3 honeypot and a mysterious-donor 2-of-4, zero-added external honeypot. Held as a dated update on the CKTRIPWIRE honeypot monitor already in the record. The configuration details are the poster's own.\n",
      "relation": {
        "kind": "single-post",
        "head_id": null
      },
      "capture": {
        "status": "held",
        "artefact_count": 5,
        "conversation_copies": 0,
        "conversation_posts": 0,
        "conversation_replies": 0,
        "conversation_gaps": []
      }
    },
    {
      "id": "clay-garrett-entropy-die-metaphor",
      "title": "Entropy die-size geometric analogy",
      "url": "https://x.com/clay_garrett/status/2085966010792722833",
      "author": "clay_garrett",
      "platform": "x",
      "organisation": "Block",
      "posted": "2026-08-08T05:47:07Z",
      "role": "social-statement",
      "why_registered": "Clay Garrett of Block explains the incident's entropy shortfall in geometric terms, comparing the safe 256-bit space to a fair 2^256-sided die whose faces would be smaller than atoms at one centimetre. Held as a distinct technical explanation of why the reduced-entropy seed generation mattered. The analogy is the poster's own and is not a measured security bound.\n",
      "relation": {
        "kind": "single-post",
        "head_id": null
      },
      "capture": {
        "status": "held",
        "artefact_count": 2,
        "conversation_copies": 0,
        "conversation_posts": 0,
        "conversation_replies": 0,
        "conversation_gaps": []
      }
    },
    {
      "id": "bitcoinnewscom-2085700535772934469",
      "title": "210,000 BTC long-term holder move amid fallout",
      "url": "https://x.com/BitcoinNewsCom/status/2085700535772934469",
      "author": "BitcoinNewsCom",
      "platform": "x",
      "organisation": null,
      "posted": "2026-08-07T12:12:12Z",
      "role": "social-statement",
      "why_registered": "Bitcoin News reports that roughly 210,000 BTC worth $13.6 billion moved from long-term holder wallets over the past week amid the COLDCARD fallout, with on-chain analysts describing it as custody migration rather than capitulation. Held as a distinct market-reaction claim tied to the incident. The figures and the custody-migration interpretation are the outlet's own and are not verified here.\n",
      "relation": {
        "kind": "single-post",
        "head_id": null
      },
      "capture": {
        "status": "held",
        "artefact_count": 5,
        "conversation_copies": 0,
        "conversation_posts": 0,
        "conversation_replies": 0,
        "conversation_gaps": []
      }
    },
    {
      "id": "oomahq-nvk-switck-knowledge-claim",
      "title": "Claim that NVK knew @switck was @DocHex",
      "url": "https://x.com/oomahq/status/2086088359928009115",
      "author": "oomahq",
      "platform": "x",
      "organisation": null,
      "posted": "2026-08-08T13:53:17Z",
      "role": "social-statement",
      "why_registered": "oomahq asks why libNgU was not hosted in Coinkite's official GitHub organization and why @DocHex developed it under an alt nym, argues that the v3.2.2 changelog shout-out to @switck and public @COLDCARDwallet interaction with @switck make it impossible that @DocHex imported the library undetected, and concludes that @nvk therefore had to know the two accounts were the same person. Held as a dated, specific allegation about vendor knowledge and pseudonymous authorship during the incident. The allegations and the cited interactions are the poster's own reading and are not independently verified here.\n",
      "relation": {
        "kind": "single-post",
        "head_id": null
      },
      "capture": {
        "status": "held",
        "artefact_count": 7,
        "conversation_copies": 0,
        "conversation_posts": 0,
        "conversation_replies": 0,
        "conversation_gaps": []
      }
    },
    {
      "id": "jamesob-tripwire-sweep-update",
      "title": "CKTRIPWIRE tripwires swept",
      "url": "https://x.com/jamesob/status/2086154136064586229",
      "author": "jamesob",
      "platform": "x",
      "organisation": null,
      "posted": "2026-08-08T18:14:39Z",
      "role": "social-statement",
      "why_registered": "James O'Beirne reports that multiple two-roll dice tripwires on cktripwire.com have just swept and that attacker-controlled funds are still moving. Held as a dated update from the CKTRIPWIRE honeypot monitor already in the record. The sweep observations and the \"sharks still swimming\" framing are the poster's own.\n",
      "relation": {
        "kind": "single-post",
        "head_id": null
      },
      "capture": {
        "status": "held",
        "artefact_count": 5,
        "conversation_copies": 0,
        "conversation_posts": 0,
        "conversation_replies": 0,
        "conversation_gaps": []
      }
    },
    {
      "id": "hodlonaut-may2025-prior-discovery-rebuttal",
      "title": "Rebuttal of the LLM-found-the-bug framing",
      "url": "https://x.com/hodlonaut/status/2086058591367143488",
      "author": "hodlonaut",
      "platform": "x",
      "organisation": null,
      "posted": "2026-08-08T11:54:59Z",
      "role": "social-statement",
      "why_registered": "hodlonaut quotes a Coldcard statement that the bug lived in public for five years and that frontier LLMs were needed to find it, then counters that the flaw was pointed at by a person in May 2025 with no frontier model, was traced to the library by name, and was later found again with ordinary code-analysis tools after disclosure. Held as a dated correction to the vendor's public explanation of how the bug was discovered, citing a prior report. The May 2025 claim and the characterization of the company's response are the poster's own and are not independently verified here.\n",
      "relation": {
        "kind": "single-post",
        "head_id": null
      },
      "capture": {
        "status": "held",
        "artefact_count": 5,
        "conversation_copies": 0,
        "conversation_posts": 0,
        "conversation_replies": 0,
        "conversation_gaps": []
      }
    },
    {
      "id": "intangiblecoins-block-961635-opreturn",
      "title": "OP_RETURN message in block 961,635",
      "url": "https://x.com/intangiblecoins/status/2086198479047569915",
      "author": "intangiblecoins",
      "platform": "x",
      "organisation": null,
      "posted": "2026-08-08T21:10:51Z",
      "role": "social-statement",
      "why_registered": "Alex Thorn posts an OP_RETURN output in block 961,635 containing a human-readable quote attributed to Mechanic at block 961,632 and a mempool.space transaction link. Held as a dated on-chain artefact observation related to the incident. The attribution of the message and its meaning are the poster's own and are not verified here.\n",
      "relation": {
        "kind": "single-post",
        "head_id": null
      },
      "capture": {
        "status": "held",
        "artefact_count": 2,
        "conversation_copies": 0,
        "conversation_posts": 0,
        "conversation_replies": 0,
        "conversation_gaps": []
      }
    },
    {
      "id": "coletu-2085823098742317223",
      "title": "Mk3 honeypot account wiped after two days",
      "url": "https://x.com/coletu/status/2085823098742317223",
      "author": "coletu",
      "platform": "x",
      "organisation": null,
      "posted": "2026-08-07T20:19:14Z",
      "role": "social-statement",
      "why_registered": "Cole reports the results of a deliberate Mk3 honeypot test: a seed generated\nwith random account number 3459 had that account wiped after two days and two\nhours, while three passphrase wallets on the same seed still held funds. Held\nas a dated first-hand observation that attackers are systematically searching\naccount numbers, complementing his earlier drain-test posts. The account\nnumber and timing are the poster's own and are not independently verified\nhere.\n",
      "relation": {
        "kind": "single-post",
        "head_id": null
      },
      "capture": {
        "status": "held",
        "artefact_count": 7,
        "conversation_copies": 0,
        "conversation_posts": 0,
        "conversation_replies": 0,
        "conversation_gaps": []
      }
    },
    {
      "id": "noosphere888x2-2085817128414851434",
      "title": "Wasabi coinjoin mixing effectiveness claim",
      "url": "https://x.com/noosphere888x2/status/2085817128414851434",
      "author": "noosphere888x2",
      "platform": "x",
      "organisation": null,
      "posted": "2026-08-07T19:55:30Z",
      "role": "social-statement",
      "why_registered": "noosphere888 claims that the attacker moved 64 BTC through Wasabi and that\nonly 15 percent of the funds were effectively mixed, likening the remainder\nto an unencrypted message. Held as a dated, specific on-chain observation\nabout the attacker's laundering method, alongside the distinct Wasabi trace\nheld at profedustream-2084882092765421800. The 64 BTC figure and the mixing\nconclusion are the poster's own and are not verified here.\n",
      "relation": {
        "kind": "single-post",
        "head_id": null
      },
      "capture": {
        "status": "held",
        "artefact_count": 4,
        "conversation_copies": 0,
        "conversation_posts": 0,
        "conversation_replies": 0,
        "conversation_gaps": []
      }
    },
    {
      "id": "glxyresearch-2085748541633261936",
      "title": "Victim report intake via Alex Thorn DM",
      "url": "https://x.com/glxyresearch/status/2085748541633261936",
      "author": "glxyresearch",
      "platform": "x",
      "organisation": "Galaxy Research",
      "posted": "2026-08-07T15:22:58Z",
      "role": "social-statement",
      "why_registered": "Galaxy Research asks victims to continue sending reports to Alex Thorn by\ndirect message, noting that automated analysis can start fastest when the\nfirst message includes a correct list of drained bitcoin addresses. Held as a\ndated operational update on the incident-response intake process, distinct\nfrom the earlier Galaxy accounting and wave-attribution posts. The process\ndescription is the poster's own.\n",
      "relation": {
        "kind": "conversation-member",
        "head_id": "glxyresearch-2085748513015488758"
      },
      "capture": {
        "status": "held",
        "artefact_count": 4,
        "conversation_copies": 0,
        "conversation_posts": 0,
        "conversation_replies": 0,
        "conversation_gaps": []
      }
    },
    {
      "id": "intangiblecoins-2085752444236005465",
      "title": "Victim report aggregate statistics",
      "url": "https://x.com/intangiblecoins/status/2085752444236005465",
      "author": "intangiblecoins",
      "platform": "x",
      "organisation": null,
      "posted": "2026-08-07T15:38:28Z",
      "role": "social-statement",
      "why_registered": "Alex Thorn publishes aggregate statistics from more than 250 victim reports:\nmedian coin dormancy 3.5 years, 88 percent of stolen coins at least one year\nold, median loss 0.014 BTC by address and 1.022 BTC by victim, mean loss 0.212\nBTC by address and 4.04 BTC by victim, with a reported range from 624 sats to\n58.97 BTC. Held as a dated quantitative update from one of the active\nincident responders. The figures are the poster's own and are not\nindependently verified here.\n",
      "relation": {
        "kind": "single-post",
        "head_id": null
      },
      "capture": {
        "status": "held",
        "artefact_count": 4,
        "conversation_copies": 0,
        "conversation_posts": 0,
        "conversation_replies": 0,
        "conversation_gaps": []
      }
    },
    {
      "id": "btcpayserver-2085771939008667869",
      "title": "BTCPay Server vulnerability acknowledgement and safety steps",
      "url": "https://x.com/btcpayserver/status/2085771939008667869",
      "author": "btcpayserver",
      "platform": "x",
      "organisation": "BTCPay Server",
      "posted": "2026-08-07T16:55:56Z",
      "role": "social-statement",
      "why_registered": "The BTCPay Server account thanks the Bitcoin Red Team for a responsible\nsecurity disclosure and gives concrete post-update steps: refresh macaroons\nand macaroons.db, refresh auth strings for other LN backends, and move funds\nfrom any hot on-chain BTCPay wallet before recreating it. Held as an\norganisational incident-response statement about a vulnerability disclosed\nduring the Coldcard-response week. The disclosure details and remediation\nsteps are the poster's own and are not verified here.\n",
      "relation": {
        "kind": "single-post",
        "head_id": null
      },
      "capture": {
        "status": "held",
        "artefact_count": 4,
        "conversation_copies": 0,
        "conversation_posts": 0,
        "conversation_replies": 0,
        "conversation_gaps": []
      }
    },
    {
      "id": "reallybadday99-2085454877719675354",
      "title": "First-hand report of Trezor phishing ad loss",
      "url": "https://x.com/reallybadday99/status/2085454877719675354",
      "author": "reallybadday99",
      "platform": "x",
      "organisation": null,
      "posted": "2026-08-06T19:56:03Z",
      "role": "social-statement",
      "why_registered": "David reports losing life savings to a fake Google-sponsored Trezor website\nand gives a phishing address, tagging ZachXBT and CertiK. Held as a\nfirst-hand account of a panic-exploiting phishing scam that followed the\nColdcard disclosure, alongside the reddit-fake-trezor-google-ad thread. The\nloss claim and address are the poster's own and are not verified here.\n",
      "relation": {
        "kind": "single-post",
        "head_id": null
      },
      "capture": {
        "status": "held",
        "artefact_count": 4,
        "conversation_copies": 0,
        "conversation_posts": 0,
        "conversation_replies": 0,
        "conversation_gaps": []
      }
    },
    {
      "id": "zherbert-2085788368365875378",
      "title": "Foundation BTCPay lightning node drained",
      "url": "https://x.com/zherbert/status/2085788368365875378",
      "author": "zherbert",
      "platform": "x",
      "organisation": null,
      "posted": "2026-08-07T18:01:13Z",
      "role": "social-statement",
      "why_registered": "Zach Herbert reports that the Foundation Devices BTCPay lightning node was\ndrained overnight and asks how many other BTCPay lightning nodes were swept.\nHeld as a dated first-hand report of a BTCPay-related drain during the\nincident-response period. The scope of the sweep and the number of affected\nnodes are the poster's own and are not verified here.\n",
      "relation": {
        "kind": "single-post",
        "head_id": null
      },
      "capture": {
        "status": "held",
        "artefact_count": 4,
        "conversation_copies": 0,
        "conversation_posts": 0,
        "conversation_replies": 0,
        "conversation_gaps": []
      }
    },
    {
      "id": "pavlenex-2085756609741930534",
      "title": "BTCPay Server active exploitation warning",
      "url": "https://x.com/pavlenex/status/2085756609741930534",
      "author": "pavlenex",
      "platform": "x",
      "organisation": null,
      "posted": "2026-08-07T15:55:01Z",
      "role": "social-statement",
      "why_registered": "Pavlenex warns that a vulnerability affecting all BTCPay Server instances is\nbeing actively exploited, urges immediate update to v2.4.2, and says a full\npost-mortem will follow. Held as a dated incident-response alert from a\nBTCPay Server maintainer, alongside the organisational btcpayserver statement\nposted the same hour. The claims are the poster's own and are not verified\nhere.\n",
      "relation": {
        "kind": "single-post",
        "head_id": null
      },
      "capture": {
        "status": "held",
        "artefact_count": 4,
        "conversation_copies": 0,
        "conversation_posts": 0,
        "conversation_replies": 0,
        "conversation_gaps": []
      }
    },
    {
      "id": "nicolasdorier-2085772944895025622",
      "title": "BTCPay vulnerability identified through affected developer logs",
      "url": "https://x.com/nicolasdorier/status/2085772944895025622",
      "author": "nicolasdorier",
      "platform": "x",
      "organisation": null,
      "posted": "2026-08-07T16:59:56Z",
      "role": "social-statement",
      "why_registered": "Nicolas Dorier thanks Craig Raw and says BTCPay got extremely lucky that a\ndeveloper who was impacted could analyse logs to understand what was\nhappening, adding that the issue was not caught by AI scans. Held as a dated\nfirst-person account of how the BTCPay vulnerability was identified. The\ncharacterization of the discovery is the poster's own and is not verified\nhere.\n",
      "relation": {
        "kind": "single-post",
        "head_id": null
      },
      "capture": {
        "status": "held",
        "artefact_count": 4,
        "conversation_copies": 0,
        "conversation_posts": 0,
        "conversation_replies": 0,
        "conversation_gaps": []
      }
    },
    {
      "id": "btcsessions-2085698751558009085",
      "title": "Criticism of Coinkite response to prior outreach",
      "url": "https://x.com/btcsessions/status/2085698751558009085",
      "author": "btcsessions",
      "platform": "x",
      "organisation": null,
      "posted": "2026-08-07T12:05:07Z",
      "role": "social-statement",
      "why_registered": "BTC Sessions, a long-time COLDCARD promoter, posts a first-person statement\nthat James O'Beirne and others raised concerns and were ignored or dismissed\nas FUD, that it took an undeniable wave of theft to force action, and that\nNVK fostered an attitude of superiority toward competing projects. Held as a\ndated, specific public-accountability statement from a named community\nfigure. The characterization of past interactions is the poster's own and is\nnot verified here.\n",
      "relation": {
        "kind": "single-post",
        "head_id": null
      },
      "capture": {
        "status": "held",
        "artefact_count": 4,
        "conversation_copies": 0,
        "conversation_posts": 0,
        "conversation_replies": 0,
        "conversation_gaps": []
      }
    },
    {
      "id": "tftc21-2085789285962416527",
      "title": "Bitcoin Red Team 55-hour statistics and Code RED fund",
      "url": "https://x.com/tftc21/status/2085789285962416527",
      "author": "tftc21",
      "platform": "x",
      "organisation": null,
      "posted": "2026-08-07T18:04:52Z",
      "role": "social-statement",
      "why_registered": "TFTC reports that the Bitcoin Red Team formed as an emergency Coldcard\nresponse, and after less than three days had 24 people scan 425 projects for\nroughly 6,700 findings, 1,029 of them high or critical, while reaching only\nabout 130 projects because of sparse security contacts. It also notes\nOpenSats stepped up with a Code RED fund. Held as a dated summary of a\ndistinct incident-response initiative. The figures and the OpenSats\ncommitment are attributed to the poster and are not verified here.\n",
      "relation": {
        "kind": "single-post",
        "head_id": null
      },
      "capture": {
        "status": "held",
        "artefact_count": 7,
        "conversation_copies": 0,
        "conversation_posts": 0,
        "conversation_replies": 0,
        "conversation_gaps": []
      }
    },
    {
      "id": "oomahq-2085717166884618584",
      "title": "Allegation that CoinKite CTO wrote vulnerable dependency pseudonymously",
      "url": "https://x.com/oomahq/status/2085717166884618584",
      "author": "oomahq",
      "platform": "x",
      "organisation": null,
      "posted": "2026-08-07T13:18:17Z",
      "role": "social-statement",
      "why_registered": "oomahq alleges that the external firmware dependency containing the critical\nvulnerability was written by CoinKite CTO Peter Gray under the @DocHex nym,\nand that the claim is verifiable. Held as a dated, specific attribution\nallegation made during the incident-response period, alongside the related\noomahq-nvk-switck-knowledge-claim. The allegation and the cited evidence are\nthe poster's own reading and are not independently verified here.\n",
      "relation": {
        "kind": "conversation-head",
        "head_id": null
      },
      "capture": {
        "status": "held",
        "artefact_count": 149,
        "conversation_copies": 11,
        "conversation_posts": 130,
        "conversation_replies": 123,
        "conversation_gaps": []
      }
    },
    {
      "id": "jamesob-2085847410102645036",
      "title": "CKTRIPWIRE honeypot sweep timing",
      "url": "https://x.com/jamesob/status/2085847410102645036",
      "author": "jamesob",
      "platform": "x",
      "organisation": null,
      "posted": "2026-08-07T21:55:50Z",
      "role": "social-statement",
      "why_registered": "James O'Beirne reports that a zero-added-entropy random-account Mk3 honeypot on\ncktripwire.com was swept after one day and twenty-three hours. Held as a dated\nfirst-hand measurement of attacker timing against a deliberately weak Mk3 seed.\nThe sweep timing is the poster's own observation and is not independently\nverified here.\n",
      "relation": {
        "kind": "single-post",
        "head_id": null
      },
      "capture": {
        "status": "held",
        "artefact_count": 5,
        "conversation_copies": 0,
        "conversation_posts": 0,
        "conversation_replies": 0,
        "conversation_gaps": []
      }
    },
    {
      "id": "tftc21-2085782189392974208",
      "title": "Galaxy Research $111 million loss estimate",
      "url": "https://x.com/tftc21/status/2085782189392974208",
      "author": "tftc21",
      "platform": "x",
      "organisation": null,
      "posted": "2026-08-07T17:36:40Z",
      "role": "social-statement",
      "why_registered": "TFTC relays Galaxy Research figures stating $111 million in bitcoin stolen from\nColdcard users through the RNG exploit, 1,719 BTC confirmed so far, total\nlosses likely exceeding $130 million, 88% of stolen coins dormant over a year,\nand a median victim loss of about 1 BTC. Held as a dated accounting summary\nattributed to Galaxy Research. The figures are attributed to Galaxy Research\nand are not independently verified here.\n",
      "relation": {
        "kind": "single-post",
        "head_id": null
      },
      "capture": {
        "status": "held",
        "artefact_count": 5,
        "conversation_copies": 0,
        "conversation_posts": 0,
        "conversation_replies": 0,
        "conversation_gaps": []
      }
    },
    {
      "id": "evankaloudis-2085763304165630110",
      "title": "LND and BTCPay Server macaroon rotation guidance",
      "url": "https://x.com/evankaloudis/status/2085763304165630110",
      "author": "evankaloudis",
      "platform": "x",
      "organisation": null,
      "posted": "2026-08-07T16:21:37Z",
      "role": "social-statement",
      "why_registered": "Evan Kaloudis advises LND and BTCPay Server users not to assume safety after\nupgrading, to destroy and recreate macaroons and macaroons.db, to refresh auth\nmechanisms for other LN backends, and to move funds from hot on-chain BTCPay\nwallets. Held as dated incident-response guidance from a named Lightning\ndeveloper following the BTCPay Server disclosure. The recommendations are the\nposter's own and are not independently verified here.\n",
      "relation": {
        "kind": "single-post",
        "head_id": null
      },
      "capture": {
        "status": "held",
        "artefact_count": 2,
        "conversation_copies": 0,
        "conversation_posts": 0,
        "conversation_replies": 0,
        "conversation_gaps": []
      }
    },
    {
      "id": "lukechilds-2085802947670356209",
      "title": "Anzen wallet launch",
      "url": "https://x.com/lukechilds/status/2085802947670356209",
      "author": "lukechilds",
      "platform": "x",
      "organisation": null,
      "posted": "2026-08-07T18:59:09Z",
      "role": "social-statement",
      "why_registered": "Luke Childs announces a novel wallet design called Anzen that he believes\nsolves Bitcoin's self-custody trilemma, stating it is live on mainnet with a\nwriteup linked. Held as a dated product launch presented as a response to the\nColdcard incident. The claims about the design and its properties are the\nposter's own and are not verified here.\n",
      "relation": {
        "kind": "single-post",
        "head_id": null
      },
      "capture": {
        "status": "held",
        "artefact_count": 2,
        "conversation_copies": 0,
        "conversation_posts": 0,
        "conversation_replies": 0,
        "conversation_gaps": []
      }
    },
    {
      "id": "coldcardwallet-2085782970258854229",
      "title": "Customer data retention exemption request",
      "url": "https://x.com/coldcardwallet/status/2085782970258854229",
      "author": "coldcardwallet",
      "platform": "x",
      "organisation": "Coinkite",
      "posted": "2026-08-07T17:39:46Z",
      "role": "social-statement",
      "why_registered": "COLDCARD asks customers who want standard retention policies applied to their\ndata to confirm by emailing support, so their records can be exempted from the\ncurrent preservation protocol. Held as a dated organizational statement about\nthe vendor's data-retention practice during the incident-response period. The\nprocedure described is the vendor's own and is not independently verified\nhere.\n",
      "relation": {
        "kind": "single-post",
        "head_id": null
      },
      "capture": {
        "status": "held",
        "artefact_count": 2,
        "conversation_copies": 0,
        "conversation_posts": 0,
        "conversation_replies": 0,
        "conversation_gaps": []
      }
    },
    {
      "id": "simondixontwitt-2085783291290890717",
      "title": "Inside-job allegation",
      "url": "https://x.com/simondixontwitt/status/2085783291290890717",
      "author": "simondixontwitt",
      "platform": "x",
      "organisation": null,
      "posted": "2026-08-07T17:41:03Z",
      "role": "social-statement",
      "why_registered": "Simon Dixon states that the Coldcard exploit was not incompetence and does not\nlook organic, but looks like an inside job. Held as a dated, specific\nattribution allegation from a named public figure during the incident-response\nperiod. The allegation is the poster's own opinion and is not verified here.\n",
      "relation": {
        "kind": "single-post",
        "head_id": null
      },
      "capture": {
        "status": "held",
        "artefact_count": 2,
        "conversation_copies": 0,
        "conversation_posts": 0,
        "conversation_replies": 0,
        "conversation_gaps": []
      }
    },
    {
      "id": "coinspect-2085717059329990946",
      "title": "Malware installer warning for Ill Bloom and COLDCARD exploits",
      "url": "https://x.com/coinspect/status/2085717059329990946",
      "author": "coinspect",
      "platform": "x",
      "organisation": null,
      "posted": "2026-08-07T13:17:52Z",
      "role": "social-statement",
      "why_registered": "Coinspect Security warns that the Ill Bloom and COLDCARD exploit packages\ncirculating on GitHub are malware installers. Held as a dated security alert\nabout panic-exploiting malicious software. The malware characterization is the\nposter's own and is not independently verified here.\n",
      "relation": {
        "kind": "single-post",
        "head_id": null
      },
      "capture": {
        "status": "held",
        "artefact_count": 5,
        "conversation_copies": 0,
        "conversation_posts": 0,
        "conversation_replies": 0,
        "conversation_gaps": []
      }
    },
    {
      "id": "unchained-2085771806498066808",
      "title": "OpenSats donation pledge for August clients",
      "url": "https://x.com/unchained/status/2085771806498066808",
      "author": "unchained",
      "platform": "x",
      "organisation": "Unchained",
      "posted": "2026-08-07T16:55:25Z",
      "role": "social-statement",
      "why_registered": "Unchained announces that through August it will donate $50 to OpenSats for each\nnew client, to support open-source bitcoin development and security research.\nHeld as a dated organizational pledge made during the incident-response\nperiod. The pledge is the organization's own statement and is not\nindependently verified here.\n",
      "relation": {
        "kind": "single-post",
        "head_id": null
      },
      "capture": {
        "status": "held",
        "artefact_count": 2,
        "conversation_copies": 0,
        "conversation_posts": 0,
        "conversation_replies": 0,
        "conversation_gaps": []
      }
    },
    {
      "id": "sesi_the_man-2085698235616596143",
      "title": "Claimed prior disclosure by James O'Beirne and others",
      "url": "https://x.com/sesi_the_man/status/2085698235616596143",
      "author": "sesi_the_man",
      "platform": "x",
      "organisation": null,
      "posted": "2026-08-07T12:03:04Z",
      "role": "social-statement",
      "why_registered": "Seed claims that James O'Beirne and potentially others attempted to disclose\nthe vulnerability years ago. Held as a dated prior-disclosure allegation from a\nnamed contributor, alongside the existing btcsessions statement on ignored\noutreach. The claim is the poster's own and is not independently verified\nhere.\n",
      "relation": {
        "kind": "single-post",
        "head_id": null
      },
      "capture": {
        "status": "held",
        "artefact_count": 5,
        "conversation_copies": 0,
        "conversation_posts": 0,
        "conversation_replies": 0,
        "conversation_gaps": []
      }
    },
    {
      "id": "a_ferron-2085731252657696911",
      "title": "Claimed undisclosed PIN exfiltration vulnerability",
      "url": "https://x.com/a_ferron/status/2085731252657696911",
      "author": "a_ferron",
      "platform": "x",
      "organisation": null,
      "posted": "2026-08-07T14:14:16Z",
      "role": "social-statement",
      "why_registered": "Antoine Ferron says he found a PIN-exfiltration vulnerability in a Coldcard\nproduct two years ago, waited for a fix, and will now publish because the\nupdate never arrived. Held as a dated, specific claim about an undisclosed\nprior vulnerability. The existence and details of the vulnerability are the\nposter's own and are not verified here.\n",
      "relation": {
        "kind": "conversation-head",
        "head_id": null
      },
      "capture": {
        "status": "held",
        "artefact_count": 13,
        "conversation_copies": 3,
        "conversation_posts": 10,
        "conversation_replies": 7,
        "conversation_gaps": []
      }
    },
    {
      "id": "thefuzzstone-coldcard-timeline-update",
      "title": "Updated timeline of the Coldcard exploit",
      "url": "https://x.com/thefuzzstone/status/2086023689359724660",
      "author": "thefuzzstone",
      "platform": "x",
      "organisation": null,
      "posted": "2026-08-08T09:36:18Z",
      "role": "social-statement",
      "why_registered": "TheFuzzStone publishes a long, sourced timeline of the Coldcard entropy\nvulnerability from the October 2020 switck interactions through the July 2026\ndrain, including allegations about the switck identity, the March 2021\nNVK-Odell conversation, and civil-liability coordination. Held as a dated\nindependent summary and allegation thread from a named commentator. The claims\nare the poster's own and are not verified here.\n",
      "relation": {
        "kind": "single-post",
        "head_id": null
      },
      "capture": {
        "status": "held",
        "artefact_count": 2,
        "conversation_copies": 0,
        "conversation_posts": 0,
        "conversation_replies": 0,
        "conversation_gaps": []
      }
    },
    {
      "id": "orangesurfbtc-casino-dice-protocol",
      "title": "C.A.S.I.N.O hardware wallet dice entry protocol",
      "url": "https://x.com/OrangeSurfBTC/status/2086241888256802837",
      "author": "OrangeSurfBTC",
      "platform": "x",
      "organisation": null,
      "posted": "2026-08-09T00:03:21Z",
      "role": "social-statement",
      "why_registered": "orangesurf proposes C.A.S.I.N.O., a hardware-wallet dice-entry protocol that\nrequires user confirmation, physical dice, rate-limited entry, input sanity\nchecks, 100 or more rolls, and offline operation. Held as a dated technical\nproposal for user-supplied entropy made in response to the incident. The\nprotocol design is the poster's own and is not verified here.\n",
      "relation": {
        "kind": "single-post",
        "head_id": null
      },
      "capture": {
        "status": "held",
        "artefact_count": 5,
        "conversation_copies": 0,
        "conversation_posts": 0,
        "conversation_replies": 0,
        "conversation_gaps": []
      }
    },
    {
      "id": "btcconsortium-incident-announcement",
      "title": "Bitcoin Security Consortium incident announcement",
      "url": "https://x.com/BTCconsortium/status/2084643715922960416",
      "author": "BTCconsortium",
      "platform": "x",
      "organisation": "Bitcoin Security Consortium",
      "posted": null,
      "role": "social-statement",
      "why_registered": "The Bitcoin Security Consortium's 4 August announcement connecting member\ncompany Block, Project Loupe and the COLDCARD incident. Held as the missing\nprimary institutional source for a relationship previously represented only\nthrough secondary references. The consortium's description is its own.\n",
      "relation": {
        "kind": "single-post",
        "head_id": null
      },
      "capture": {
        "status": "held",
        "artefact_count": 2,
        "conversation_copies": 0,
        "conversation_posts": 0,
        "conversation_replies": 0,
        "conversation_gaps": []
      }
    },
    {
      "id": "anchorwatch-incident-safe-harbor",
      "title": "AnchorWatch safe-harbor offer to affected owners",
      "url": "https://x.com/AnchorWatch/status/2083900673398047022",
      "author": "AnchorWatch",
      "platform": "x",
      "organisation": "AnchorWatch",
      "posted": null,
      "role": "social-statement",
      "why_registered": "AnchorWatch's 2 August organizational response offering affected owners a\ntemporary multi-institution custody arrangement. Held as a concrete industry\nresponse to the incident. The terms, suitability and safety claims are the\npublisher's and inclusion is not a recommendation.\n",
      "relation": {
        "kind": "single-post",
        "head_id": null
      },
      "capture": {
        "status": "held",
        "artefact_count": 5,
        "conversation_copies": 0,
        "conversation_posts": 0,
        "conversation_replies": 0,
        "conversation_gaps": []
      }
    },
    {
      "id": "blockunmasked-three-wave-update",
      "title": "Blockchain Unmasked three-wave trace update",
      "url": "https://x.com/BlockUnmasked/status/2084624650097590458",
      "author": "BlockUnmasked",
      "platform": "x",
      "organisation": "Blockchain Unmasked",
      "posted": null,
      "role": "social-statement",
      "why_registered": "Blockchain Unmasked's 4 August investigator update describing three waves and\nan aggregate above $100 million. Held as a dated primary update in that\ninvestigator's changing attribution record. The grouping, total and causation\nclaims are the publisher's and remain separate from other monitors' figures.\n",
      "relation": {
        "kind": "single-post",
        "head_id": null
      },
      "capture": {
        "status": "held",
        "artefact_count": 2,
        "conversation_copies": 0,
        "conversation_posts": 0,
        "conversation_replies": 0,
        "conversation_gaps": []
      }
    },
    {
      "id": "deconflict-victim-reporting-advice",
      "title": "Law-enforcement reporting advice for alleged victims",
      "url": "https://x.com/deconflict_/status/2083932479904244120",
      "author": "deconflict_",
      "platform": "x",
      "organisation": null,
      "posted": null,
      "role": "social-statement",
      "why_registered": "A dated incident-response post directing alleged victims toward law-enforcement\nreporting. Held as public response discourse rather than guidance authored by\nthis archive. The advice, characterization of victims and implied process are\nthe poster's own and are not independently verified here.\n",
      "relation": {
        "kind": "single-post",
        "head_id": null
      },
      "capture": {
        "status": "held",
        "artefact_count": 2,
        "conversation_copies": 0,
        "conversation_posts": 0,
        "conversation_replies": 0,
        "conversation_gaps": []
      }
    },
    {
      "id": "futurebit-responder-funds-saved-claim",
      "title": "FutureBit claim about funds saved by incident responders",
      "url": "https://x.com/FutureBit/status/2084656750951535101",
      "author": "FutureBit",
      "platform": "x",
      "organisation": "FutureBit",
      "posted": null,
      "role": "social-statement",
      "why_registered": "FutureBit's 4 August claim about funds saved by people responding to the\nincident. Held as a dated industry-response claim with a distinct outcome\nfigure. The amount, attribution and counterfactual are the publisher's own and\nare not treated as verified by this record.\n",
      "relation": {
        "kind": "single-post",
        "head_id": null
      },
      "capture": {
        "status": "held",
        "artefact_count": 5,
        "conversation_copies": 0,
        "conversation_posts": 0,
        "conversation_replies": 0,
        "conversation_gaps": []
      }
    },
    {
      "id": "jstefanop1-industry-response-critique",
      "title": "Industry incident-response process critique",
      "url": "https://x.com/JStefanop1/status/2085792631418704140",
      "author": "JStefanop1",
      "platform": "x",
      "organisation": null,
      "posted": null,
      "role": "social-statement",
      "why_registered": "A public critique of how the bitcoin hardware and custody industry responded\nto the COLDCARD incident. Held as a distinct process-focused reaction from a\nknown industry participant rather than for any new technical finding. The\nassessment is the poster's own.\n",
      "relation": {
        "kind": "single-post",
        "head_id": null
      },
      "capture": {
        "status": "held",
        "artefact_count": 2,
        "conversation_copies": 0,
        "conversation_posts": 0,
        "conversation_replies": 0,
        "conversation_gaps": []
      }
    },
    {
      "id": "bitkey-block-findings-pointer",
      "title": "Bitkey pointer to Block findings",
      "url": "https://x.com/Bitkey/status/2083011704225448269",
      "author": "Bitkey",
      "platform": "x",
      "organisation": "Block",
      "posted": "2026-07-31T02:07:45Z",
      "role": "social-statement",
      "why_registered": "Bitkey, Block's self-custody wallet, tells Coldcard users to review findings from Block Engineering and Security teams to assess whether they may be affected. Held as an organizational statement from a primary party during the incident response period.\n",
      "relation": {
        "kind": "single-post",
        "head_id": null
      },
      "capture": {
        "status": "held",
        "artefact_count": 2,
        "conversation_copies": 0,
        "conversation_posts": 0,
        "conversation_replies": 0,
        "conversation_gaps": []
      }
    },
    {
      "id": "claygarrett-bitkey-verify-wallet",
      "title": "Bitkey wallet verification guidance",
      "url": "https://x.com/clay_garrett/status/2083001740324966807",
      "author": "clay_garrett",
      "platform": "x",
      "organisation": "Block",
      "posted": "2026-07-31T01:28:09Z",
      "role": "social-statement",
      "why_registered": "Clay Garrett of Block opens a seven-post thread explaining how users can verify a Bitkey wallet is in proper shape before transferring funds into it, including adding backup fingerprints for extra security. Held as incident-response guidance from the Bitkey lead during the COLDCARD migration window.\n",
      "relation": {
        "kind": "single-post",
        "head_id": null
      },
      "capture": {
        "status": "held",
        "artefact_count": 2,
        "conversation_copies": 0,
        "conversation_posts": 0,
        "conversation_replies": 0,
        "conversation_gaps": []
      }
    },
    {
      "id": "grok-2085542181050224762",
      "title": "Why the bug survived code review",
      "url": "https://x.com/grok/status/2085542181050224762",
      "author": "grok",
      "platform": "x",
      "organisation": null,
      "posted": "2026-08-07T01:42:58Z",
      "role": "social-statement",
      "why_registered": "Grok's generated explanation of why the vulnerable code path remained undetected: human and AI reviews confirmed the hardware TRNG code existed but did not trace linker resolution, the definedness guard checked definition rather than value, and no end-to-end entropy tests existed. Held as a record of the chatbot's answer, not as verified analysis.\n",
      "relation": {
        "kind": "single-post",
        "head_id": null
      },
      "capture": {
        "status": "held",
        "artefact_count": 2,
        "conversation_copies": 0,
        "conversation_posts": 0,
        "conversation_replies": 0,
        "conversation_gaps": []
      }
    },
    {
      "id": "tftc21-dice-user-error-clarification",
      "title": "Dice-roll path user-error clarification",
      "url": "https://x.com/TFTC21/status/2085095791757316539",
      "author": "tftc21",
      "platform": "x",
      "organisation": "TFTC",
      "posted": "2026-08-05T20:09:10Z",
      "role": "social-statement",
      "why_registered": "TFTC clarifies that one reported case was user error on the dice-roll path, not the firmware RNG bug: the user pressed the same die face 99 times, producing a deterministic seed that collided with an existing wallet. The post distinguishes this case from the firmware vulnerability.\n",
      "relation": {
        "kind": "single-post",
        "head_id": null
      },
      "capture": {
        "status": "held",
        "artefact_count": 2,
        "conversation_copies": 0,
        "conversation_posts": 0,
        "conversation_replies": 0,
        "conversation_gaps": []
      }
    },
    {
      "id": "coldcardwallet-historical-disclosures-reply",
      "title": "Historical-disclosure reply",
      "url": "https://x.com/COLDCARDwallet/status/2085051503241199944",
      "author": "COLDCARDwallet",
      "platform": "x",
      "organisation": "Coinkite",
      "posted": "2026-08-05T17:13:11Z",
      "role": "vendor-response",
      "why_registered": "Coinkite replies that the issue being discussed was already publicly disclosed and points to the COLDCARD security disclosure history page. Held as a vendor statement about prior disclosure.\n",
      "relation": {
        "kind": "single-post",
        "head_id": null
      },
      "capture": {
        "status": "held",
        "artefact_count": 5,
        "conversation_copies": 0,
        "conversation_posts": 0,
        "conversation_replies": 0,
        "conversation_gaps": []
      }
    },
    {
      "id": "coldcardwallet-repl-disclosure-reply",
      "title": "REPL disclosure reply",
      "url": "https://x.com/COLDCARDwallet/status/2085039725333618852",
      "author": "COLDCARDwallet",
      "platform": "x",
      "organisation": "Coinkite",
      "posted": "2026-08-05T16:26:23Z",
      "role": "vendor-response",
      "why_registered": "Coinkite states that the issue was disclosed on the disclosure history page and is related to the REPL. Held as a vendor statement about prior disclosure.\n",
      "relation": {
        "kind": "single-post",
        "head_id": null
      },
      "capture": {
        "status": "held",
        "artefact_count": 2,
        "conversation_copies": 0,
        "conversation_posts": 0,
        "conversation_replies": 0,
        "conversation_gaps": []
      }
    },
    {
      "id": "lunaticoin-decision-tree",
      "title": "Coldcard seed risk decision tree",
      "url": "https://x.com/lunaticoin/status/2084915928047988999",
      "author": "lunaticoin",
      "platform": "x",
      "organisation": null,
      "posted": "2026-08-05T08:14:27Z",
      "role": "social-statement",
      "why_registered": "Lunaticoin advertises a decision-tree tool at coldcard.semillabitcoin.com to help owners assess whether their funds are at risk. The archive has not verified the tool or the site; it is recorded as a third-party response that appeared during the migration window.\n",
      "relation": {
        "kind": "single-post",
        "head_id": null
      },
      "capture": {
        "status": "held",
        "artefact_count": 5,
        "conversation_copies": 0,
        "conversation_posts": 0,
        "conversation_replies": 0,
        "conversation_gaps": []
      }
    },
    {
      "id": "coldcardwallet-ui-bug-1-3-4q",
      "title": "UI bug fixed in 1.3.4Q",
      "url": "https://x.com/COLDCARDwallet/status/2084961506186113338",
      "author": "COLDCARDwallet",
      "platform": "x",
      "organisation": "Coinkite",
      "posted": "2026-08-05T11:15:34Z",
      "role": "vendor-response",
      "why_registered": "Coinkite identifies a reported issue as a UI display bug that was fixed in COLDCARD version 1.3.4Q released on 2025-09-30, distinguishing it from the entropy vulnerability.\n",
      "relation": {
        "kind": "single-post",
        "head_id": null
      },
      "capture": {
        "status": "held",
        "artefact_count": 2,
        "conversation_copies": 0,
        "conversation_posts": 0,
        "conversation_replies": 0,
        "conversation_gaps": []
      }
    },
    {
      "id": "gustavojfe-recovery-assistance",
      "title": "Assisted MK3 recovery during the migration window",
      "url": "https://x.com/gustavojfe/status/2084829859394490751",
      "author": "gustavojfe",
      "platform": "x",
      "organisation": null,
      "posted": "2026-08-05T02:32:27Z",
      "role": "social-statement",
      "why_registered": "Gustavo of Aureo says he helped a friend move bitcoin from a COLDCARD MK3 to a new wallet, notes the friend did not use dice rolls or a passphrase, and states recovery is still possible. He says he has helped secure tens of BTC over the preceding days and remains available to assist others. Held as a first-hand assistance account from the migration window.\n",
      "relation": {
        "kind": "single-post",
        "head_id": null
      },
      "capture": {
        "status": "held",
        "artefact_count": 2,
        "conversation_copies": 0,
        "conversation_posts": 0,
        "conversation_replies": 0,
        "conversation_gaps": []
      }
    },
    {
      "id": "rob1ham-red-team-operations-reflection",
      "title": "Red Team acceleration and personal reflection",
      "url": "https://x.com/Rob1Ham/status/2084927733725839503",
      "author": "Rob1Ham",
      "platform": "x",
      "organisation": null,
      "posted": "2026-08-05T09:01:22Z",
      "role": "social-statement",
      "why_registered": "Rob Hamilton reports that the Red Team effort is accelerating, covering over 300 repositories and spending almost $40,000, and describes integrating disclosure feedback into the scanning harness. He also states he is numb over the death of the COLDCARD and has blocked out processing the harm to friends and families. Held as a dated operational update and a first-hand emotional reaction from a known participant.\n",
      "relation": {
        "kind": "single-post",
        "head_id": null
      },
      "capture": {
        "status": "held",
        "artefact_count": 7,
        "conversation_copies": 0,
        "conversation_posts": 0,
        "conversation_replies": 0,
        "conversation_gaps": []
      }
    },
    {
      "id": "bitcoinnewscom-ai-code-review-missed",
      "title": "AI code reviews missed critical bug",
      "url": "https://x.com/BitcoinNewsCom/status/2084735084691914879",
      "author": "BitcoinNewsCom",
      "platform": "x",
      "organisation": "Bitcoin News",
      "posted": "2026-08-04T20:15:51Z",
      "role": "social-statement",
      "why_registered": "Bitcoin News reports Coinkite's statement that the vulnerability lived at the boundary between two unrelated firmware submodules and therefore evaded human and AI-assisted code reviews for years. The post names Kimi K3, Claude Fable and Codex 5.6 as frontier models tested after the incident and relays Coinkite's recommendation that security-critical projects audit build systems and submodule boundaries. Held as media coverage of the vendor's AI-review explanation.\n",
      "relation": {
        "kind": "single-post",
        "head_id": null
      },
      "capture": {
        "status": "held",
        "artefact_count": 2,
        "conversation_copies": 0,
        "conversation_posts": 0,
        "conversation_replies": 0,
        "conversation_gaps": []
      }
    },
    {
      "id": "zackvoell-frontier-models-nerfed",
      "title": "Frontier AI models nerfed for Bitcoin vulnerability hunt",
      "url": "https://x.com/zackvoell/status/2084724839915417669",
      "author": "zackvoell",
      "platform": "x",
      "organisation": null,
      "posted": "2026-08-04T19:35:08Z",
      "role": "social-statement",
      "why_registered": "Zack Voell describes an enormous ongoing effort to find and fix vulnerabilities across hundreds of open-source Bitcoin projects and states that almost no one is using OpenAI or Anthropic models because they are nerfed. Held as a participant's framing of the post-incident red-team tooling choices. The assessment of the models is the poster's own.\n",
      "relation": {
        "kind": "single-post",
        "head_id": null
      },
      "capture": {
        "status": "held",
        "artefact_count": 2,
        "conversation_copies": 0,
        "conversation_posts": 0,
        "conversation_replies": 0,
        "conversation_gaps": []
      }
    },
    {
      "id": "bitcoinnewscom-bricking-correction",
      "title": "Bricking claims correction and RNG recovery patch",
      "url": "https://x.com/BitcoinNewsCom/status/2084635131281612930",
      "author": "BitcoinNewsCom",
      "platform": "x",
      "organisation": "Bitcoin News",
      "posted": "2026-08-04T13:38:40Z",
      "role": "social-statement",
      "why_registered": "Bitcoin News relays a developer correction that claims current COLDCARD firmware permanently bricks devices are incorrect. The post explains that a full power cycle should recover a device after a transient TRNG seed error because the error is volatile and nothing is written to flash, and notes a proposed patch that further hardens RNG recovery with bounded retries and seed-error detection. Held as a technical incident-response correction.\n",
      "relation": {
        "kind": "single-post",
        "head_id": null
      },
      "capture": {
        "status": "held",
        "artefact_count": 2,
        "conversation_copies": 0,
        "conversation_posts": 0,
        "conversation_replies": 0,
        "conversation_gaps": []
      }
    },
    {
      "id": "mrhodl-ecdsa-not-broken",
      "title": "Broken RNG does not break normal ECDSA spending",
      "url": "https://x.com/MrHodl/status/2084470259357024379",
      "author": "MrHodl",
      "platform": "x",
      "organisation": null,
      "posted": "2026-08-04T02:43:32Z",
      "role": "social-statement",
      "why_registered": "MrHodl amplifies Rob Hamilton's analysis that the broken RNG does not break normal ECDSA spending because RFC6979 deterministic nonces are used. Held as a technical clarification amplified during the incident. The claim is attributed to Rob Hamilton and has not been independently verified here.\n",
      "relation": {
        "kind": "single-post",
        "head_id": null
      },
      "capture": {
        "status": "held",
        "artefact_count": 2,
        "conversation_copies": 0,
        "conversation_posts": 0,
        "conversation_replies": 0,
        "conversation_gaps": []
      }
    },
    {
      "id": "skwp-ai-attackers-startups",
      "title": "AI attackers and enterprise security overhead",
      "url": "https://x.com/skwp/status/2084360024877347166",
      "author": "skwp",
      "platform": "x",
      "organisation": null,
      "posted": "2026-08-03T19:25:30Z",
      "role": "social-statement",
      "why_registered": "Yan at Swan says AI attackers are getting more sophisticated and that small teams will have a tough time keeping up. He argues there is significant overhead to building and running enterprise security in the age of LLMs, which will price out many innovative startups working with client funds. Held as an industry participant's post-incident reaction.\n",
      "relation": {
        "kind": "single-post",
        "head_id": null
      },
      "capture": {
        "status": "held",
        "artefact_count": 2,
        "conversation_copies": 0,
        "conversation_posts": 0,
        "conversation_replies": 0,
        "conversation_gaps": []
      }
    },
    {
      "id": "bourbonni-mk4-dice-validation",
      "title": "Mk4 dice-roll validation after the incident",
      "url": "https://x.com/bourbonni/status/2084113000252748030",
      "author": "bourbonni",
      "platform": "x",
      "organisation": null,
      "posted": "2026-08-03T03:03:54Z",
      "role": "social-statement",
      "why_registered": "Nico describes validating the COLDCARD Mk4 dice-rolling feature at home by generating a 24-word seed from dice rolls, explaining that he had already verified it previously but re-checked out of paranoia. Held as a first-hand account of user verification behaviour during the post-incident confidence window. The procedure and result are the poster's own.\n",
      "relation": {
        "kind": "single-post",
        "head_id": null
      },
      "capture": {
        "status": "held",
        "artefact_count": 5,
        "conversation_copies": 0,
        "conversation_posts": 0,
        "conversation_replies": 0,
        "conversation_gaps": []
      }
    },
    {
      "id": "coldcardwallet-destroy-inventory-reason",
      "title": "Why affected inventory was destroyed",
      "url": "https://x.com/COLDCARDwallet/status/2084218493931499850",
      "author": "COLDCARDwallet",
      "platform": "x",
      "organisation": "Coinkite",
      "posted": "2026-08-03T10:03:06Z",
      "role": "vendor-response",
      "why_registered": "Coinkite explains why it destroyed affected inventory, stating that COLDCARD's high-security system locks prevent re-upgrade until the user initializes the device. It says shipping units with affected firmware would risk users missing the upgrade, so the safest action was to destroy affected stock and ship only devices with the new fixed firmware. Held as a vendor incident-response statement.\n",
      "relation": {
        "kind": "single-post",
        "head_id": null
      },
      "capture": {
        "status": "held",
        "artefact_count": 2,
        "conversation_copies": 0,
        "conversation_posts": 0,
        "conversation_replies": 0,
        "conversation_gaps": []
      }
    },
    {
      "id": "coldhodl-sales-halted-refunds",
      "title": "ColdHodl halts sales and offers refunds",
      "url": "https://x.com/coldhodlMk/status/2084276705351319572",
      "author": "coldhodlMk",
      "platform": "x",
      "organisation": "ColdHodl",
      "posted": "2026-08-03T13:54:25Z",
      "role": "social-statement",
      "why_registered": "ColdHodl says it has stopped all sales and is processing full refunds for orders placed on or after the week of the disclosure. It adds that all clients were notified about the bug on the preceding Saturday and that it never sold MK3 or earlier COLDCARD devices. Held as a reseller incident-response statement; the claims have not been independently verified.\n",
      "relation": {
        "kind": "single-post",
        "head_id": null
      },
      "capture": {
        "status": "held",
        "artefact_count": 2,
        "conversation_copies": 0,
        "conversation_posts": 0,
        "conversation_replies": 0,
        "conversation_gaps": []
      }
    },
    {
      "id": "ferenckovacs-dice-q-validation",
      "title": "Dice-roll seed validation on COLDCARD Q",
      "url": "https://x.com/ferenckovacs/status/2084032857610006761",
      "author": "ferenckovacs",
      "platform": "x",
      "organisation": null,
      "posted": "2026-08-02T21:45:27Z",
      "role": "social-statement",
      "why_registered": "Ferenc Kovacs reports testing 204 dice rolls on a COLDCARD Q running the new firmware and verifying that the resulting seed matches the one produced by a companion app. He presents it as evidence that the device now behaves like a standard signer when dice entropy is used. Held as a first-hand technical validation account; the procedure and result are the poster's own.\n",
      "relation": {
        "kind": "single-post",
        "head_id": null
      },
      "capture": {
        "status": "held",
        "artefact_count": 5,
        "conversation_copies": 0,
        "conversation_posts": 0,
        "conversation_replies": 0,
        "conversation_gaps": []
      }
    },
    {
      "id": "jonatack-knots-110-observation",
      "title": "Knots peers no longer report subversion 110",
      "url": "https://x.com/jonatack/status/2086183080176316783",
      "author": "jonatack",
      "platform": "x",
      "organisation": null,
      "posted": "2026-08-08T20:09:40Z",
      "role": "social-statement",
      "why_registered": "Jon Atack notes that 16 to 20 percent of his Bitcoin Core node's peers still run Knots, but none of them advertise the 110 subversion anymore. Held as a dated network observation from the incident week. The measurement is attributed to the poster and has not been independently verified.\n",
      "relation": {
        "kind": "single-post",
        "head_id": null
      },
      "capture": {
        "status": "held",
        "artefact_count": 2,
        "conversation_copies": 0,
        "conversation_posts": 0,
        "conversation_replies": 0,
        "conversation_gaps": []
      }
    },
    {
      "id": "jbrauck-unchained-response-day",
      "title": "Unchained's incident-response workload",
      "url": "https://x.com/jbrauck_/status/2083272580828471787",
      "author": "jbrauck_",
      "platform": "x",
      "organisation": null,
      "posted": "2026-07-31T19:24:23Z",
      "role": "social-statement",
      "why_registered": "Jesse Brauck describes an intense day at Unchained helping clients respond to the COLDCARD disclosure, with product managers and leadership fielding support requests across the company. Held as a first-hand account of a custodial-services firm's internal response during the initial migration window. The claims are the poster's own.\n",
      "relation": {
        "kind": "single-post",
        "head_id": null
      },
      "capture": {
        "status": "held",
        "artefact_count": 2,
        "conversation_copies": 0,
        "conversation_posts": 0,
        "conversation_replies": 0,
        "conversation_gaps": []
      }
    },
    {
      "id": "glxyresearch-attack-ongoing-600-addresses",
      "title": "Galaxy Research reports attack ongoing and ~600 addresses to investigators",
      "url": "https://x.com/glxyresearch/status/2083705254172864861",
      "author": "glxyresearch",
      "platform": "x",
      "organisation": "Galaxy Research",
      "posted": "2026-08-02T00:03:40Z",
      "role": "on-chain-analysis",
      "why_registered": "Galaxy Research warns that the COLDCARD exploit is ongoing, urges single-sig users to move funds, and says it has reported roughly 600 attacker-held addresses to federal investigators, compliance firms, and cyber investigators. It also thanks victims who shared addresses and invites further reports via direct message to @intangiblecoins. Held as an incident-response and investigation update from the response team tracking the drain.\n",
      "relation": {
        "kind": "single-post",
        "head_id": null
      },
      "capture": {
        "status": "held",
        "artefact_count": 2,
        "conversation_copies": 0,
        "conversation_posts": 0,
        "conversation_replies": 0,
        "conversation_gaps": []
      }
    },
    {
      "id": "glxyresearch-block-961635-opreturn",
      "title": "OP_RETURN messages in block 961,635",
      "url": "https://x.com/glxyresearch/status/2086198342145724486",
      "author": "glxyresearch",
      "platform": "x",
      "organisation": "Galaxy Research",
      "posted": "2026-08-08T21:10:19Z",
      "role": "on-chain-analysis",
      "why_registered": "Galaxy Research posts two OP_RETURN outputs from block 961,635, one quoting a statement attributed to Mechanic and another claiming that some commentators had spent two years saying a chain split was impossible. Held as a dated on-chain artefact observation related to the incident. The message attributions and their meaning are the poster's own.\n",
      "relation": {
        "kind": "single-post",
        "head_id": null
      },
      "capture": {
        "status": "held",
        "artefact_count": 2,
        "conversation_copies": 0,
        "conversation_posts": 0,
        "conversation_replies": 0,
        "conversation_gaps": []
      }
    },
    {
      "id": "glxyresearch-promotion-criteria-2300-btc",
      "title": "Galaxy Research promotion criteria and 2,300 BTC ceiling",
      "url": "https://x.com/glxyresearch/status/2085748538172944787",
      "author": "glxyresearch",
      "platform": "x",
      "organisation": "Galaxy Research",
      "posted": "2026-08-07T15:22:57Z",
      "role": "on-chain-analysis",
      "why_registered": "Galaxy Research explains that it promotes addresses to the confirmed victim or attacker set only when it has high confidence, usually from multiple victim confirmations. It says outstanding candidates for promotion could take the total loss above 2,300 BTC if they are eventually confirmed. Held as a methodology and loss-estimate update.\n",
      "relation": {
        "kind": "conversation-member",
        "head_id": "glxyresearch-2085748513015488758"
      },
      "capture": {
        "status": "held",
        "artefact_count": 5,
        "conversation_copies": 0,
        "conversation_posts": 0,
        "conversation_replies": 0,
        "conversation_gaps": []
      }
    },
    {
      "id": "wowens-rbf-rescue",
      "title": "Fee-mogging a COLDCARD attacker with RBF",
      "url": "https://x.com/wowens/status/2084041966212591963",
      "author": "wowens",
      "platform": "x",
      "organisation": null,
      "posted": "2026-08-02T22:21:39Z",
      "role": "social-statement",
      "why_registered": "Will Owens reports a first-hand rescue during the incident: after migrating most\nfunds from a compromised COLDCARDwallet, he left ~0.0025 BTC as bait, then\nbroadcast an RBF replacement to snatch it back when the attacker underpaid fees.\nHeld as a dated victim account of an on-chain fee race.\n",
      "relation": {
        "kind": "single-post",
        "head_id": null
      },
      "capture": {
        "status": "held",
        "artefact_count": 2,
        "conversation_copies": 0,
        "conversation_posts": 0,
        "conversation_replies": 0,
        "conversation_gaps": []
      }
    },
    {
      "id": "intangiblecoins-ongoing-attack-update",
      "title": "Ongoing attack update and victim-address appeal",
      "url": "https://x.com/intangiblecoins/status/2083756710510895255",
      "author": "intangiblecoins",
      "platform": "x",
      "organisation": null,
      "posted": "2026-08-02T03:28:08Z",
      "role": "social-statement",
      "why_registered": "Alex Thorn of Galaxy Research reports the attack is ongoing, says wave 1, 2 and\n3 coins remain inert while smaller opportunistic operators are moving funds,\ngives average and median coin dormancy of 3.18 and 3.55 years, and states that\nevery single-sig Coldcard address generated after the March 2021 firmware\nupgrade will eventually be drained. He also says US LLM models are hindering\nresponse efforts and that victim reports via DM have helped identify attacker\naddresses. Held as a reported incident-response update from the primary tracking\nteam.\n",
      "relation": {
        "kind": "single-post",
        "head_id": null
      },
      "capture": {
        "status": "held",
        "artefact_count": 2,
        "conversation_copies": 0,
        "conversation_posts": 0,
        "conversation_replies": 0,
        "conversation_gaps": []
      }
    },
    {
      "id": "tftc21-galaxy-third-wave-summary",
      "title": "Galaxy Research third-wave accounting summary",
      "url": "https://x.com/TFTC21/status/2083632877301121482",
      "author": "TFTC21",
      "platform": "x",
      "organisation": null,
      "posted": "2026-08-01T19:16:04Z",
      "role": "social-statement",
      "why_registered": "TFTC amplifies Galaxy Research's 1 August update: three waves, 1,367 BTC\n(~$88.6M) drained from 4,585 addresses, a 41-minute first wave hitting 1,196\naddresses with identical 30 sat/vB fees, and Galaxy's observation that the loss\nprofile matches individual self-custody. Held as evidence of how the tracking\ndata was relayed by an outlet during the incident.\n",
      "relation": {
        "kind": "single-post",
        "head_id": null
      },
      "capture": {
        "status": "held",
        "artefact_count": 5,
        "conversation_copies": 0,
        "conversation_posts": 0,
        "conversation_replies": 0,
        "conversation_gaps": []
      }
    },
    {
      "id": "glxyresearch-address-tip-request",
      "title": "Request for suspected attacker and victim addresses",
      "url": "https://x.com/glxyresearch/status/2083623559826424043",
      "author": "glxyresearch",
      "platform": "x",
      "organisation": "Galaxy Research",
      "posted": "2026-08-01T18:39:03Z",
      "role": "social-statement",
      "why_registered": "Galaxy Research asks the public to reply with or direct-message suspected\nattacker and victim addresses so it can add them to the investigation. Held as\nthe start of the public address-collection appeal that later produced reported\ntotals.\n",
      "relation": {
        "kind": "single-post",
        "head_id": null
      },
      "capture": {
        "status": "held",
        "artefact_count": 2,
        "conversation_copies": 0,
        "conversation_posts": 0,
        "conversation_replies": 0,
        "conversation_gaps": []
      }
    },
    {
      "id": "glxyresearch-drained-addresses-by-month",
      "title": "Drained addresses by last-receive month",
      "url": "https://x.com/glxyresearch/status/2083623552545165409",
      "author": "glxyresearch",
      "platform": "x",
      "organisation": "Galaxy Research",
      "posted": "2026-08-01T18:39:01Z",
      "role": "social-statement",
      "why_registered": "Galaxy Research posts a chart showing the same drained-address population\ncounted by address rather than value, with each address placed in the month it\nlast received funds before being drained. Held as a distinct view of the\ntemporal distribution of affected wallets.\n",
      "relation": {
        "kind": "single-post",
        "head_id": null
      },
      "capture": {
        "status": "held",
        "artefact_count": 5,
        "conversation_copies": 0,
        "conversation_posts": 0,
        "conversation_replies": 0,
        "conversation_gaps": []
      }
    },
    {
      "id": "glxy-migration-advice",
      "title": "Single-sig migration guidance",
      "url": "https://x.com/glxyresearch/status/2083560984422064516",
      "author": "glxyresearch",
      "platform": "x",
      "organisation": "Galaxy Research",
      "posted": "2026-08-01T14:30:24Z",
      "role": "social-statement",
      "why_registered": "Galaxy Research advises single-sig COLDCARD users to migrate funds to a fresh\nseed not generated by the COLDCARD, warns that remaining vulnerable addresses\nwill eventually be drained, and states that multisig and collaborative custody\nsetups where COLDCARD alone cannot reach threshold are safe but should still\nrotate keys. Held as a reported incident-response recommendation from the\nprimary tracking team.\n",
      "relation": {
        "kind": "single-post",
        "head_id": null
      },
      "capture": {
        "status": "held",
        "artefact_count": 2,
        "conversation_copies": 0,
        "conversation_posts": 0,
        "conversation_replies": 0,
        "conversation_gaps": []
      }
    },
    {
      "id": "glxy-victim-report-intake",
      "title": "Victim report intake via Alex Thorn DM",
      "url": "https://x.com/glxyresearch/status/2083567904180609190",
      "author": "glxyresearch",
      "platform": "x",
      "organisation": "Galaxy Research",
      "posted": "2026-08-01T14:57:53Z",
      "role": "social-statement",
      "why_registered": "Galaxy Research invites additional theft reports by reply or by direct message\nto Alex Thorn, offering a private channel for victims to submit addresses or\ntransaction IDs. Held as evidence of the public intake process used to build\nthe investigation's victim set.\n",
      "relation": {
        "kind": "single-post",
        "head_id": null
      },
      "capture": {
        "status": "held",
        "artefact_count": 2,
        "conversation_copies": 0,
        "conversation_posts": 0,
        "conversation_replies": 0,
        "conversation_gaps": []
      }
    },
    {
      "id": "intangiblecoins-attacker-data-firm",
      "title": "Attacker data-firm use and recovery hope",
      "url": "https://x.com/intangiblecoins/status/2083391403086721146",
      "author": "intangiblecoins",
      "platform": "x",
      "organisation": null,
      "posted": "2026-08-01T03:16:32Z",
      "role": "social-statement",
      "why_registered": "Alex Thorn reports that the stolen coins remain in four second-hop addresses,\nthe attacker has not resumed the onchain pattern, the attacker may have used a\npaid account at a data firm and therefore may be identifiable, and recovery\nremains possible. Held as a reported investigative update amplified by Galaxy\nResearch.\n",
      "relation": {
        "kind": "single-post",
        "head_id": null
      },
      "capture": {
        "status": "held",
        "artefact_count": 2,
        "conversation_copies": 0,
        "conversation_posts": 0,
        "conversation_replies": 0,
        "conversation_gaps": []
      }
    },
    {
      "id": "glxy-totality-fingerprint",
      "title": "Totality of matching transactions and future attack warning",
      "url": "https://x.com/glxyresearch/status/2083255552633635183",
      "author": "glxyresearch",
      "platform": "x",
      "organisation": "Galaxy Research",
      "posted": "2026-08-01T18:16:43Z",
      "role": "social-statement",
      "why_registered": "Galaxy Research states that a 30-day review of Bitcoin transactions found no\nadditional matches to the attack fingerprint, clarifies that the pattern\nidentifies a single attacker rather than the attack itself, and repeats the\nwarning to move coins out of single-signature COLDCARD addresses. Held as a\nreported forensic accounting update.\n",
      "relation": {
        "kind": "single-post",
        "head_id": null
      },
      "capture": {
        "status": "held",
        "artefact_count": 2,
        "conversation_copies": 0,
        "conversation_posts": 0,
        "conversation_replies": 0,
        "conversation_gaps": []
      }
    },
    {
      "id": "glxy-loss-profile-self-custody",
      "title": "Loss profile dominated by sub-1 BTC addresses in count",
      "url": "https://x.com/glxyresearch/status/2083207444906299851",
      "author": "glxyresearch",
      "platform": "x",
      "organisation": "Galaxy Research",
      "posted": "2026-07-31T15:05:33Z",
      "role": "social-statement",
      "why_registered": "Galaxy Research states that the loss profile is dominated by sub-1 BTC addresses\nin count but by 1-50 BTC addresses in value, and that this shape matches\nindividual self-custody rather than institutional or exchange holdings. Held as\na reported characterisation of the affected wallet population.\n",
      "relation": {
        "kind": "single-post",
        "head_id": null
      },
      "capture": {
        "status": "held",
        "artefact_count": 7,
        "conversation_copies": 0,
        "conversation_posts": 0,
        "conversation_replies": 0,
        "conversation_gaps": []
      }
    },
    {
      "id": "glxy-attacker-consolidation-addresses",
      "title": "Four consolidation addresses being monitored",
      "url": "https://x.com/glxyresearch/status/2083207448903491584",
      "author": "glxyresearch",
      "platform": "x",
      "organisation": "Galaxy Research",
      "posted": "2026-07-31T15:05:34Z",
      "role": "social-statement",
      "why_registered": "Galaxy Research lists four Bitcoin addresses it says hold the funds identified\nin this wave and states that it is monitoring them. Held as a reported\nattribution of the then-current consolidation addresses.\n",
      "relation": {
        "kind": "single-post",
        "head_id": null
      },
      "capture": {
        "status": "held",
        "artefact_count": 2,
        "conversation_copies": 0,
        "conversation_posts": 0,
        "conversation_replies": 0,
        "conversation_gaps": []
      }
    },
    {
      "id": "callebtc-red-team-108-hour-update",
      "title": "Bitcoin Red Team update at 108 hours",
      "url": "https://x.com/callebtc/status/2086220411084103707",
      "author": "callebtc",
      "platform": "x",
      "organisation": null,
      "posted": "2026-08-08T22:38:00Z",
      "role": "social-statement",
      "why_registered": "Calle reports that the Bitcoin Red Team is continuing a large-scale security\nreview of the Bitcoin open-source ecosystem, with 25 Bitcoin developers working\nnon-stop for 108 hours. Held as a reported progress update on the community\nred-team effort that followed the disclosure.\n",
      "relation": {
        "kind": "single-post",
        "head_id": null
      },
      "capture": {
        "status": "held",
        "artefact_count": 5,
        "conversation_copies": 0,
        "conversation_posts": 0,
        "conversation_replies": 0,
        "conversation_gaps": []
      }
    },
    {
      "id": "jamesob-honeypot-intent",
      "title": "High-value low-entropy honeypots",
      "url": "https://x.com/jamesob/status/2085861078513180715",
      "author": "jamesob",
      "platform": "x",
      "organisation": null,
      "posted": "2026-08-07T22:50:09Z",
      "role": "social-statement",
      "why_registered": "James O'Beirne says he is about to deploy high-value low-entropy honeypots.\nHeld as a dated statement of intent related to the CKTRIPWIRE honeypot\nmonitoring that the record already tracks. Whether the honeypots were actually\ndeployed is checked against later captures.\n",
      "relation": {
        "kind": "single-post",
        "head_id": null
      },
      "capture": {
        "status": "held",
        "artefact_count": 2,
        "conversation_copies": 0,
        "conversation_posts": 0,
        "conversation_replies": 0,
        "conversation_gaps": []
      }
    },
    {
      "id": "jamesob-btcpay-update-warning",
      "title": "BTCPay Server update warning",
      "url": "https://x.com/jamesob/status/2085760804050071668",
      "author": "jamesob",
      "platform": "x",
      "organisation": null,
      "posted": "2026-08-07T16:11:41Z",
      "role": "social-statement",
      "why_registered": "James O'Beirne urges anyone running BTCPay Server to update immediately. Held\nas a distinct incident-response amplification of the BTCPay Server\nvulnerability warning that followed the COLDCARD disclosure. The underlying\nvulnerability is tracked separately in btcpayserver-2085771939008667869.\n",
      "relation": {
        "kind": "single-post",
        "head_id": null
      },
      "capture": {
        "status": "held",
        "artefact_count": 2,
        "conversation_copies": 0,
        "conversation_posts": 0,
        "conversation_replies": 0,
        "conversation_gaps": []
      }
    },
    {
      "id": "coletu-passphrase-wallets-swept",
      "title": "All three passphrase wallets now swept",
      "url": "https://x.com/coletu/status/2087467596098556048",
      "author": "coletu",
      "platform": "x",
      "organisation": null,
      "posted": "2026-08-12T09:13:52Z",
      "role": "social-statement",
      "why_registered": "Cole reports that three passphrase-protected wallets have now been swept by the\nattacker. Held as a dated incident-development claim about passphrase-wallet\nvulnerability. Whether the sweep is verified is checked against chain data\nelsewhere.\n",
      "relation": {
        "kind": "single-post",
        "head_id": null
      },
      "capture": {
        "status": "held",
        "artefact_count": 2,
        "conversation_copies": 0,
        "conversation_posts": 0,
        "conversation_replies": 0,
        "conversation_gaps": []
      }
    },
    {
      "id": "coletu-passphrase-structure-timing",
      "title": "Passphrase structure and sweep timing",
      "url": "https://x.com/coletu/status/2087472903256203544",
      "author": "coletu",
      "platform": "x",
      "organisation": null,
      "posted": "2026-08-12T09:34:58Z",
      "role": "social-statement",
      "why_registered": "Cole states that the swept passphrases were BIP39 words, that one- and two-word\npassphrases were swept together, and that a three-word passphrase was swept\nabout two hours later, with examples. Held as a reported technical detail about\nthe passphrase attack. The examples and timing are the poster's own claims.\n",
      "relation": {
        "kind": "single-post",
        "head_id": null
      },
      "capture": {
        "status": "held",
        "artefact_count": 2,
        "conversation_copies": 0,
        "conversation_posts": 0,
        "conversation_replies": 0,
        "conversation_gaps": []
      }
    },
    {
      "id": "profedustream-negotiation-hypothesis",
      "title": "Negotiation hypothesis for the frozen wave-one and wave-three funds",
      "url": "https://x.com/profedustream/status/2087466637964288234",
      "author": "profedustream",
      "platform": "x",
      "organisation": null,
      "posted": "2026-08-12T09:10:04Z",
      "role": "social-statement",
      "why_registered": "ProfEduStream argues that five days of immobility in waves one and three, plus\nan OP_RETURN message to a reported attacker address, are consistent with a\nransom negotiation rather than typical Lazarus liquidation behaviour. The post\nalso notes the same message author previously claimed the attack for the\nIslamic Republic IR. Held as a reported attribution and recovery-scenario\nhypothesis; none of the claims are verified here.\n",
      "relation": {
        "kind": "single-post",
        "head_id": null
      },
      "capture": {
        "status": "held",
        "artefact_count": 2,
        "conversation_copies": 0,
        "conversation_posts": 0,
        "conversation_replies": 0,
        "conversation_gaps": []
      }
    },
    {
      "id": "profedustream-not-lazarus-analysis",
      "title": "On-chain argument against Lazarus Group attribution",
      "url": "https://x.com/profedustream/status/2085367401336525284",
      "author": "profedustream",
      "platform": "x",
      "organisation": null,
      "posted": "2026-08-06T14:08:27Z",
      "role": "social-statement",
      "why_registered": "ProfEduStream contrasts the observed Coldcard thief's bulk injection of large\nUTXOs into successive Wasabi coinjoins with the fragmentation, progressive\nmixing and dispersion pattern usually associated with Lazarus Group flows.\nHeld as a reported on-chain attribution argument. The conclusion is the\nposter's own and is not verified here.\n",
      "relation": {
        "kind": "single-post",
        "head_id": null
      },
      "capture": {
        "status": "held",
        "artefact_count": 2,
        "conversation_copies": 0,
        "conversation_posts": 0,
        "conversation_replies": 0,
        "conversation_gaps": []
      }
    },
    {
      "id": "hardblockbtc-coldcard-explainer",
      "title": "Coldcard incident explainer",
      "url": "https://x.com/hardblockbtc/status/2085306134815265260",
      "author": "hardblockbtc",
      "platform": "x",
      "organisation": "HardBlock",
      "posted": "2026-08-06T10:05:00Z",
      "role": "social-statement",
      "why_registered": "HardBlock, an Australian bitcoin-only exchange, publishes a long-form explainer\ntitled \"Crushed by Coinkite: unpacking the Coldcard clusterf#k (so far)\" and\nlinks to it from its official account. Held as evidence of an industry\nparticipant's public educational response to the incident. The factual claims\nin the linked piece are not verified here.\n",
      "relation": {
        "kind": "single-post",
        "head_id": null
      },
      "capture": {
        "status": "held",
        "artefact_count": 2,
        "conversation_copies": 0,
        "conversation_posts": 0,
        "conversation_replies": 0,
        "conversation_gaps": []
      }
    },
    {
      "id": "cointelegraph-top-five-addresses-concentration",
      "title": "Top five addresses hold nearly 83% of confirmed stolen funds",
      "url": "https://x.com/cointelegraph/status/2087056701031620854",
      "author": "cointelegraph",
      "platform": "x",
      "organisation": "Cointelegraph",
      "posted": "2026-08-11T06:01:07Z",
      "role": "social-statement",
      "why_registered": "Cointelegraph reports, citing CryptoQuant's Julio Moreno, that most of the\nbitcoin stolen in the Coldcard hack sits in a handful of wallets and that the\ntop five addresses hold nearly 83% of the confirmed stolen funds. Held as a\nreported media accounting claim attributed to CryptoQuant. The figure and\nattribution are not verified here.\n",
      "relation": {
        "kind": "single-post",
        "head_id": null
      },
      "capture": {
        "status": "held",
        "artefact_count": 2,
        "conversation_copies": 0,
        "conversation_posts": 0,
        "conversation_replies": 0,
        "conversation_gaps": []
      }
    },
    {
      "id": "katakoto-wizardsardine-entropy-revision",
      "title": "Revised entropy figures from the Wizardsardine deep dive",
      "url": "https://x.com/katakoto/status/2087324167851127151",
      "author": "katakoto",
      "platform": "x",
      "organisation": null,
      "posted": "2026-08-11T23:43:56Z",
      "role": "social-statement",
      "why_registered": "katakoto relays the revised entropy estimates from Kevin Loaec's Wizardsardine\ndeep dive: Mk3 effective entropy reportedly reduced from 40 bits to 22 bits,\nand Mk4/Mk5/Q from 72 bits to 52 bits, with a warning that migration is\nrecommended for all models. Held as a reported summary of an independent\ntechnical analysis. The figures are Wizardsardine's and are not verified here.\n",
      "relation": {
        "kind": "single-post",
        "head_id": null
      },
      "capture": {
        "status": "held",
        "artefact_count": 2,
        "conversation_copies": 0,
        "conversation_posts": 0,
        "conversation_replies": 0,
        "conversation_gaps": []
      }
    },
    {
      "id": "w_s_bitcoin-undisclosed-exploit-tail-risk",
      "title": "Tail risk of a further undisclosed COLDCARD exploit",
      "url": "https://x.com/w_s_bitcoin/status/2086971108071285190",
      "author": "w_s_bitcoin",
      "platform": "x",
      "organisation": null,
      "posted": "2026-08-11T00:21:00Z",
      "role": "social-statement",
      "why_registered": "Wicked says he is not ruling out the possibility of another yet-to-be-discovered\nCOLDCARD exploit, gives nonce exfiltration in shipped firmware as an example,\nand lists precautions such as flashing verified firmware, generating own entropy\nand multivendor multisig. Held as a reported tail-risk warning and mitigation\nadvice from a commentator. The existence of another exploit is unverified.\n",
      "relation": {
        "kind": "single-post",
        "head_id": null
      },
      "capture": {
        "status": "held",
        "artefact_count": 2,
        "conversation_copies": 0,
        "conversation_posts": 0,
        "conversation_replies": 0,
        "conversation_gaps": []
      }
    },
    {
      "id": "sesi_the_man-cottage-scale-signers",
      "title": "Cottage-scale signer building and supply-chain risk",
      "url": "https://x.com/sesi_the_man/status/2087279253251305910",
      "author": "sesi_the_man",
      "platform": "x",
      "organisation": null,
      "posted": "2026-08-11T20:45:28Z",
      "role": "social-statement",
      "why_registered": "SeedSigner contributor Seed argues that signer hardware should be a cottage-scale\nproduct sold by reputable local sellers, warns against pre-loaded software and\nmalicious documentation, and repeats that the safest way to obtain a SeedSigner\nis to build one yourself. Held as a reported post-incident hardware-procurement\nphilosophy from a signer-project contributor. The risk judgments are the\nposter's own.\n",
      "relation": {
        "kind": "single-post",
        "head_id": null
      },
      "capture": {
        "status": "held",
        "artefact_count": 2,
        "conversation_copies": 0,
        "conversation_posts": 0,
        "conversation_replies": 0,
        "conversation_gaps": []
      }
    },
    {
      "id": "alexesnakamoto-nvk-2022-entropy-interview",
      "title": "Resurfaced 2022 NVK interview on entropy quality",
      "url": "https://x.com/alexesnakamoto/status/2087428725675635068",
      "author": "alexesnakamoto",
      "platform": "x",
      "organisation": null,
      "posted": "2026-08-12T06:39:25Z",
      "role": "social-statement",
      "why_registered": "Alex posts a 2022 interview in which NVK says the quality of entropy is \"the\nbasis of everything security-wise in Bitcoin self-custody,\" framing it as newly\nrelevant after the incident. Held as a reported example of how pre-incident\nvendor statements were reinterpreted during the incident week. The poster's\ninterpretation is not verified here.\n",
      "relation": {
        "kind": "single-post",
        "head_id": null
      },
      "capture": {
        "status": "held",
        "artefact_count": 2,
        "conversation_copies": 0,
        "conversation_posts": 0,
        "conversation_replies": 0,
        "conversation_gaps": []
      }
    },
    {
      "id": "nunchuk-incident-lessons",
      "title": "Three lessons for Bitcoin services from the incident",
      "url": "https://x.com/nunchuk_io/status/2087197360162226251",
      "author": "nunchuk_io",
      "platform": "x",
      "organisation": "Nunchuk",
      "posted": "2026-08-11T15:20:03Z",
      "role": "social-statement",
      "why_registered": "Nunchuk shares three post-incident lessons for Bitcoin services: not reusing\naddresses, having an end-to-end multisig key-rotation flow, and maintaining\nreliable privacy-preserving crisis communication. Held as a reported\norganisational statement of incident lessons from a wallet-service provider.\nThe recommendations are Nunchuk's own.\n",
      "relation": {
        "kind": "single-post",
        "head_id": null
      },
      "capture": {
        "status": "held",
        "artefact_count": 2,
        "conversation_copies": 0,
        "conversation_posts": 0,
        "conversation_replies": 0,
        "conversation_gaps": []
      }
    },
    {
      "id": "slowmist-2087438490518892592",
      "title": "SlowMist reproduction of the COLDCARD private-key vulnerability",
      "url": "https://x.com/slowmist_team/status/2087438490518892592",
      "author": "SlowMist_Team",
      "platform": "x",
      "organisation": null,
      "posted": "2026-08-12T07:18:13Z",
      "role": "social-statement",
      "why_registered": "SlowMist Security Team reports reproducing the COLDCARD attack chain using Mk3\nfirmware 4.1.9 and estimates at least 1,719 BTC (~$111M) lost across more than\n5,200 addresses. The post traces the attack to a build configuration that\ndisabled the STM32 hardware TRNG, leaving a predictable Yasmarang software PRNG\nwith effective entropy of roughly 40 bits on Mk2/Mk3 and 72 bits on Mk4/Mk5/Q.\nThe figures and reproduction are SlowMist's own and are not independently\nverified here.\n",
      "relation": {
        "kind": "single-post",
        "head_id": null
      },
      "capture": {
        "status": "held",
        "artefact_count": 2,
        "conversation_copies": 0,
        "conversation_posts": 0,
        "conversation_replies": 0,
        "conversation_gaps": []
      }
    },
    {
      "id": "theretailbull-2087222946297266552",
      "title": "UK fraud report filing by a Coldcard hack victim",
      "url": "https://x.com/theretailbull/status/2087222946297266552",
      "author": "theretailbull",
      "platform": "x",
      "organisation": null,
      "posted": "2026-08-11T17:01:43Z",
      "role": "social-statement",
      "why_registered": "Tim Lamb reports filing a report of his Coldcard hack losses with the UK Report\nFraud service and encourages other affected owners to do the same. He says\n@intangiblecoins can supply accurate tracing data to support such filings. Held\nas a first-hand victim account of a law-enforcement reporting step; the loss\ndetails are Lamb's own and are not verified here.\n",
      "relation": {
        "kind": "single-post",
        "head_id": null
      },
      "capture": {
        "status": "held",
        "artefact_count": 2,
        "conversation_copies": 0,
        "conversation_posts": 0,
        "conversation_replies": 0,
        "conversation_gaps": []
      }
    },
    {
      "id": "natbrunell-2087180531687436447",
      "title": "Natalie Brunell interview with Alex Thorn on the Coldcard hack",
      "url": "https://x.com/natbrunell/status/2087180531687436447",
      "author": "natbrunell",
      "platform": "x",
      "organisation": null,
      "posted": "2026-08-11T14:13:11Z",
      "role": "social-statement",
      "why_registered": "Natalie Brunell publishes a long-form interview with Galaxy Research's Alex\nThorn and @intangiblecoins covering the Coldcard attacker waves, current coin\nmovements, the Red Team, BIP 110 and advice for victims. Held as media coverage\nthat collates several incident threads in one place; the interview's claims are\nthe speakers' own and are not verified here.\n",
      "relation": {
        "kind": "single-post",
        "head_id": null
      },
      "capture": {
        "status": "held",
        "artefact_count": 2,
        "conversation_copies": 0,
        "conversation_posts": 0,
        "conversation_replies": 0,
        "conversation_gaps": []
      }
    },
    {
      "id": "kloaec-2082919510248509512",
      "title": "Kevin Loaec's early incident guidance",
      "url": "https://x.com/KLoaec/status/2082919510248509512",
      "author": "KLoaec",
      "platform": "x",
      "organisation": null,
      "posted": "2026-07-30T20:01:24Z",
      "role": "social-statement",
      "why_registered": "Kevin Loaec warns that only single-sig wallets are known to be affected so far,\nthat a passphrase or dice rolls may not protect against an unknown private-key\nexfiltration path, and urges moving to multisig or Miniscript. Dated early\nguidance from a hardware-wallet security practitioner; the uncertainty Loaec\nnotes was correct at the time and the claims are his own.\n",
      "relation": {
        "kind": "single-post",
        "head_id": null
      },
      "capture": {
        "status": "held",
        "artefact_count": 2,
        "conversation_copies": 0,
        "conversation_posts": 0,
        "conversation_replies": 0,
        "conversation_gaps": []
      }
    },
    {
      "id": "tftc21-2082933533329543188",
      "title": "TFTC early report of Coldcard wallet drains",
      "url": "https://x.com/TFTC21/status/2082933533329543188",
      "author": "TFTC21",
      "platform": "x",
      "organisation": null,
      "posted": "2026-07-30T20:57:08Z",
      "role": "social-statement",
      "why_registered": "TFTC reports that multiple known Bitcoiners have confirmed losses and relays\nKevin Loaec's working hypothesis of a low-entropy RNG issue possibly in the\nsecure element, while noting the root cause is still unconfirmed. The post also\ntells single-sig owners to check balances and contact Coinkite with proof of key\ncontrol. Held as an early amplification of the drain reports and hypotheses; the\nclaims are TFTC's and Loaec's own.\n",
      "relation": {
        "kind": "single-post",
        "head_id": null
      },
      "capture": {
        "status": "held",
        "artefact_count": 2,
        "conversation_copies": 0,
        "conversation_posts": 0,
        "conversation_replies": 0,
        "conversation_gaps": []
      }
    },
    {
      "id": "cobrabitcoin-2082931597804781898",
      "title": "CobraBitcoin speculates on AI involvement in the Coldcard drains",
      "url": "https://x.com/CobraBitcoin/status/2082931597804781898",
      "author": "CobraBitcoin",
      "platform": "x",
      "organisation": null,
      "posted": "2026-07-30T20:49:26Z",
      "role": "social-statement",
      "why_registered": "CobraBitcoin says he has a bad feeling that AI was involved in the Coldcard\ndrains, noting the release of Kimi K3's weights and the puzzling partial draining\nof some compromised addresses. Held as a reported early speculation from a\nlong-time Bitcoin figure; the AI-involvement claim is unverified.\n",
      "relation": {
        "kind": "single-post",
        "head_id": null
      },
      "capture": {
        "status": "held",
        "artefact_count": 2,
        "conversation_copies": 0,
        "conversation_posts": 0,
        "conversation_replies": 0,
        "conversation_gaps": []
      }
    },
    {
      "id": "max_guise-2083007180874379515",
      "title": "Block begins investigating non-Bitkey wallet drains",
      "url": "https://x.com/max_guise/status/2083007180874379515",
      "author": "max_guise",
      "platform": "x",
      "organisation": null,
      "posted": "2026-07-31T01:49:46Z",
      "role": "social-statement",
      "why_registered": "Max Guise, head of Bitcoin engineering and security at Block, says Block began\ninvestigating reports of non-Bitkey wallets being drained and is sharing\nfindings proactively. This is the first post in Block's disclosure thread. Held\nas a vendor incident-response statement; the investigation's scope and\nconclusions are Block's own.\n",
      "relation": {
        "kind": "single-post",
        "head_id": null
      },
      "capture": {
        "status": "held",
        "artefact_count": 2,
        "conversation_copies": 0,
        "conversation_posts": 0,
        "conversation_replies": 0,
        "conversation_gaps": []
      }
    },
    {
      "id": "altcoindaily-2083057128244437443",
      "title": "Altcoin Daily urgent Coldcard drain warning",
      "url": "https://x.com/AltcoinDaily/status/2083057128244437443",
      "author": "AltcoinDaily",
      "platform": "x",
      "organisation": null,
      "posted": "2026-07-31T05:08:15Z",
      "role": "social-statement",
      "why_registered": "Altcoin Daily warns that roughly 594 BTC (~$38M) has been stolen from dormant\nsingle-sig Coldcard Mk3 wallets generated between 2021 and 2023, identifies the\ncause as a 2021 firmware entropy bug, and excludes Ledger and Trezor. Held as a\nreported early media warning with a specific risk profile; the figures and\nattribution are not verified here.\n",
      "relation": {
        "kind": "single-post",
        "head_id": null
      },
      "capture": {
        "status": "held",
        "artefact_count": 2,
        "conversation_copies": 0,
        "conversation_posts": 0,
        "conversation_replies": 0,
        "conversation_gaps": []
      }
    },
    {
      "id": "kloaec-2083180809750495710",
      "title": "Kevin Loaec reports new attacker sweeps",
      "url": "https://x.com/KLoaec/status/2083180809750495710",
      "author": "KLoaec",
      "platform": "x",
      "organisation": null,
      "posted": "2026-07-31T13:19:43Z",
      "role": "social-statement",
      "why_registered": "Kevin Loaec raises a public alert that new sweeps are under way and that more\nattackers are currently draining wallets, urging Mk3 owners to move coins\nimmediately and Mk4, Mk5 and Q owners to act soon. Held as a dated\nincident-response warning from a security practitioner; the existence of\nadditional attackers at that moment is not independently verified here.\n",
      "relation": {
        "kind": "single-post",
        "head_id": null
      },
      "capture": {
        "status": "held",
        "artefact_count": 2,
        "conversation_copies": 0,
        "conversation_posts": 0,
        "conversation_replies": 0,
        "conversation_gaps": []
      }
    },
    {
      "id": "jamesob-dice-roll-faithful",
      "title": "Dice rolls are faithfully incorporated",
      "url": "https://x.com/jamesob/status/2083299200674988216",
      "author": "jamesob",
      "platform": "x",
      "organisation": null,
      "posted": "2026-07-31T21:10:09Z",
      "role": "social-statement",
      "why_registered": "James O'Beirne reports that dice rolls entered through the Coldcard are faithfully incorporated. Held as a dated first-hand technical observation about dice-roll seed entry, relevant to the post-incident dice-seed guidance debate. The claim is the poster's own and is not independently verified here.\n",
      "relation": {
        "kind": "single-post",
        "head_id": null
      },
      "capture": {
        "status": "held",
        "artefact_count": 2,
        "conversation_copies": 0,
        "conversation_posts": 0,
        "conversation_replies": 0,
        "conversation_gaps": []
      }
    },
    {
      "id": "btcpayserver-2085755643659522240",
      "title": "BTCPay Server active-exploit update instructions",
      "url": "https://x.com/btcpayserver/status/2085755643659522240",
      "author": "btcpayserver",
      "platform": "x",
      "organisation": "BTCPay Server",
      "posted": "2026-08-07T15:51:11Z",
      "role": "social-statement",
      "why_registered": "BTCPay Server warns that a critical vulnerability is being actively exploited and gives concrete update steps: update to 2.4.2 through the admin dashboard or turn the server off until able to update. Held as an organisational incident-response statement about a vulnerability disclosed during the Coldcard-response week. The claims are the poster's own and are not verified here.\n",
      "relation": {
        "kind": "single-post",
        "head_id": null
      },
      "capture": {
        "status": "held",
        "artefact_count": 2,
        "conversation_copies": 0,
        "conversation_posts": 0,
        "conversation_replies": 0,
        "conversation_gaps": []
      }
    },
    {
      "id": "jamesob-cktripwire-rss",
      "title": "CKTRIPWIRE RSS feed added",
      "url": "https://x.com/jamesob/status/2085754937120526847",
      "author": "jamesob",
      "platform": "x",
      "organisation": null,
      "posted": "2026-08-07T15:48:23Z",
      "role": "social-statement",
      "why_registered": "James O'Beirne announces that he has added an RSS feed to cktripwire.com to make monitoring easier. Held as a dated update on the CKTRIPWIRE honeypot monitor already in the record. The addition is the poster's own and is not independently verified here.\n",
      "relation": {
        "kind": "single-post",
        "head_id": null
      },
      "capture": {
        "status": "held",
        "artefact_count": 4,
        "conversation_copies": 0,
        "conversation_posts": 0,
        "conversation_replies": 0,
        "conversation_gaps": []
      }
    },
    {
      "id": "jamesob-drains-beyond-spain",
      "title": "Drains not limited to Spain",
      "url": "https://x.com/jamesob/status/2085548440763654320",
      "author": "jamesob",
      "platform": "x",
      "organisation": null,
      "posted": "2026-08-07T02:07:50Z",
      "role": "social-statement",
      "why_registered": "James O'Beirne states that Spain is not the only place the incident happened. Held as a dated claim about the geographic scope of the drains. The claim is the poster's own and is not independently verified here.\n",
      "relation": {
        "kind": "single-post",
        "head_id": null
      },
      "capture": {
        "status": "held",
        "artefact_count": 2,
        "conversation_copies": 0,
        "conversation_posts": 0,
        "conversation_replies": 0,
        "conversation_gaps": []
      }
    },
    {
      "id": "jamesob-cktripwire-link",
      "title": "CKTRIPWIRE site link",
      "url": "https://x.com/jamesob/status/2084769504299487543",
      "author": "jamesob",
      "platform": "x",
      "organisation": null,
      "posted": "2026-08-04T22:32:37Z",
      "role": "social-statement",
      "why_registered": "James O'Beirne posts a link to cktripwire.com. Held as the earliest visible X announcement of the CKTRIPWIRE honeypot monitoring site. The site's claims and scope are the poster's own and are not independently verified here.\n",
      "relation": {
        "kind": "single-post",
        "head_id": null
      },
      "capture": {
        "status": "held",
        "artefact_count": 2,
        "conversation_copies": 0,
        "conversation_posts": 0,
        "conversation_replies": 0,
        "conversation_gaps": []
      }
    },
    {
      "id": "jamesob-ai-audit-tool-comparison",
      "title": "Claude and Kimi K3 compared for Coldcard audit work",
      "url": "https://x.com/jamesob/status/2084726557352869899",
      "author": "jamesob",
      "platform": "x",
      "organisation": null,
      "posted": "2026-08-04T19:41:58Z",
      "role": "social-statement",
      "why_registered": "James O'Beirne compares the usefulness of Claude and Kimi K3 for auditing the Coldcard firmware, saying Claude seems less useful in this domain while Kimi K3 has been the workhorse. Held as a dated first-hand observation about AI-assisted audit tooling during the incident response. The characterization is the poster's own and is not independently verified here.\n",
      "relation": {
        "kind": "single-post",
        "head_id": null
      },
      "capture": {
        "status": "held",
        "artefact_count": 2,
        "conversation_copies": 0,
        "conversation_posts": 0,
        "conversation_replies": 0,
        "conversation_gaps": []
      }
    },
    {
      "id": "jamesob-may-2025-audit",
      "title": "May 2025 audit of Coldcard RNG sourcing",
      "url": "https://x.com/jamesob/status/2084639913060819090",
      "author": "jamesob",
      "platform": "x",
      "organisation": null,
      "posted": "2026-08-04T13:57:40Z",
      "role": "social-statement",
      "why_registered": "James O'Beirne says he reached the same conclusion in May 2025 while auditing coldcard/firmware, finding that the RNG sourced to a library he describes as shady. Held as a dated first-hand account of prior audit work and an independently checkable lead about the RNG source. The May 2025 claim and the library characterization are the poster's own and are not independently verified here.\n",
      "relation": {
        "kind": "single-post",
        "head_id": null
      },
      "capture": {
        "status": "held",
        "artefact_count": 2,
        "conversation_copies": 0,
        "conversation_posts": 0,
        "conversation_replies": 0,
        "conversation_gaps": []
      }
    },
    {
      "id": "jamesob-take-offline-advice",
      "title": "Advice to take non-essential services offline",
      "url": "https://x.com/jamesob/status/2085763034417340500",
      "author": "jamesob",
      "platform": "x",
      "organisation": null,
      "posted": "2026-08-07T16:20:33Z",
      "role": "social-statement",
      "why_registered": "James O'Beirne advises that non-essential services should be taken offline for a few days while the dust settles. Held as a dated incident-response recommendation made during the BTCPay Server active-exploit disclosure. The recommendation is the poster's own and is not independently verified here.\n",
      "relation": {
        "kind": "single-post",
        "head_id": null
      },
      "capture": {
        "status": "held",
        "artefact_count": 2,
        "conversation_copies": 0,
        "conversation_posts": 0,
        "conversation_replies": 0,
        "conversation_gaps": []
      }
    },
    {
      "id": "jamesob-blockclock-quote-critique",
      "title": "BlockClock Satoshi quote choice questioned",
      "url": "https://x.com/jamesob/status/2085378374734684613",
      "author": "jamesob",
      "platform": "x",
      "organisation": null,
      "posted": "2026-08-06T14:52:03Z",
      "role": "social-statement",
      "why_registered": "James O'Beirne questions why a particular Satoshi quote was chosen for BlockClock and how it relates to block clocks. Held as a dated reaction to Coinkite's public messaging during the incident response. The characterization is the poster's own and is not independently verified here.\n",
      "relation": {
        "kind": "single-post",
        "head_id": null
      },
      "capture": {
        "status": "held",
        "artefact_count": 2,
        "conversation_copies": 0,
        "conversation_posts": 0,
        "conversation_replies": 0,
        "conversation_gaps": []
      }
    },
    {
      "id": "jamesob-thorough-analysis-link",
      "title": "Thorough analysis and credit",
      "url": "https://x.com/jamesob/status/2084627798086279459",
      "author": "jamesob",
      "platform": "x",
      "organisation": null,
      "posted": "2026-08-04T13:09:32Z",
      "role": "social-statement",
      "why_registered": "James O'Beirne links to a more thorough analysis on GitHub Gist and credits Dylan LeClair. Held as a dated primary incident statement sharing an external technical artifact and acknowledging another contributor. The linked analysis is the author's own and is not independently verified here.\n",
      "relation": {
        "kind": "single-post",
        "head_id": null
      },
      "capture": {
        "status": "held",
        "artefact_count": 2,
        "conversation_copies": 0,
        "conversation_posts": 0,
        "conversation_replies": 0,
        "conversation_gaps": []
      }
    },
    {
      "id": "jamesob-attacker-capabilities-work",
      "title": "Attacker capabilities scan underway",
      "url": "https://x.com/jamesob/status/2084445986164982220",
      "author": "jamesob",
      "platform": "x",
      "organisation": null,
      "posted": "2026-08-04T01:07:04Z",
      "role": "social-statement",
      "why_registered": "James O'Beirne says he is working on a way to assess the current capabilities and depth of the attackers, hoping to deploy that night, and urges migrating anyone with weak passphrase or dice entropy. Held as a dated incident-response update and migration guidance. The assessment plan is the poster's own and is not independently verified here.\n",
      "relation": {
        "kind": "single-post",
        "head_id": null
      },
      "capture": {
        "status": "held",
        "artefact_count": 2,
        "conversation_copies": 0,
        "conversation_posts": 0,
        "conversation_replies": 0,
        "conversation_gaps": []
      }
    },
    {
      "id": "udiwertheimer-vaults-covenants-argument",
      "title": "Bitcoin vaults and covenants could have helped",
      "url": "https://x.com/udiWertheimer/status/2083958092073431140",
      "author": "udiWertheimer",
      "platform": "x",
      "organisation": null,
      "posted": "2026-08-02T16:48:21Z",
      "role": "social-statement",
      "why_registered": "Udi Wertheimer argues that Bitcoin vault and covenant proposals from 2016 would have given Coldcard users a recoverable safety layer, and calls for covenant soft-forks such as OP_CTV, OP_VAULT or OP_CAT. Held as a dated technical-policy argument about how the incident informs Bitcoin protocol design. The argument is the poster's own and is not independently verified here.\n",
      "relation": {
        "kind": "single-post",
        "head_id": null
      },
      "capture": {
        "status": "held",
        "artefact_count": 2,
        "conversation_copies": 0,
        "conversation_posts": 0,
        "conversation_replies": 0,
        "conversation_gaps": []
      }
    },
    {
      "id": "peter-mccormack-coldcard-support",
      "title": "ColdCard support and personal reassurance",
      "url": "https://x.com/PeterMcCormack/status/2083631731052290261",
      "author": "PeterMcCormack",
      "platform": "x",
      "organisation": null,
      "posted": "2026-08-01T19:11:31Z",
      "role": "social-statement",
      "why_registered": "Peter McCormack offers personal reassurance to affected users, acknowledges the scale of the mistake, and states that ColdCard is still needed in Bitcoin despite the incident. Held as a dated first-hand sentiment statement from a named public figure responding to the incident. The characterization is the poster's own and is not independently verified here.\n",
      "relation": {
        "kind": "single-post",
        "head_id": null
      },
      "capture": {
        "status": "held",
        "artefact_count": 2,
        "conversation_copies": 0,
        "conversation_posts": 0,
        "conversation_replies": 0,
        "conversation_gaps": []
      }
    },
    {
      "id": "llfourn-gpu-cloud-warning",
      "title": "GPU cloud provider abuse warning",
      "url": "https://x.com/LLFOURN/status/2083516078462759245",
      "author": "LLFOURN",
      "platform": "x",
      "organisation": null,
      "posted": "2026-08-01T11:31:57Z",
      "role": "social-statement",
      "why_registered": "LLFOURN publicly warns GPU cloud and Trust and Safety teams that the disclosed entropy issue may lead to abuse of rented multi-GPU instances for offline BIP-39 seed recovery, estimates roughly ten RTX 4090s for about a day per Mk4-class seed, and lists platforms to watch. Held as a dated first-hand threat-context statement about the attack's compute requirements. The cost and platform claims are the poster's own and are not independently verified here.\n",
      "relation": {
        "kind": "single-post",
        "head_id": null
      },
      "capture": {
        "status": "held",
        "artefact_count": 2,
        "conversation_copies": 0,
        "conversation_posts": 0,
        "conversation_replies": 0,
        "conversation_gaps": []
      }
    },
    {
      "id": "sanket-mk4-entropy-bits",
      "title": "Mk4 entropy may be near 50 bits",
      "url": "https://x.com/sanket1729/status/2083149329200730486",
      "author": "sanket1729",
      "platform": "x",
      "organisation": null,
      "posted": "2026-07-31T11:14:37Z",
      "role": "independent-analysis",
      "why_registered": "Sanket1729 argues that the actual entropy for Mk4 and later devices is much less than 72 bits because the 72-bit figure assumes security from correlated timer fields, and offers a napkin estimate of almost 50 bits. Held as a dated independent technical analysis of the Mk4 entropy bound. The estimate is the poster's own and is not independently verified here.\n",
      "relation": {
        "kind": "single-post",
        "head_id": null
      },
      "capture": {
        "status": "held",
        "artefact_count": 2,
        "conversation_copies": 0,
        "conversation_posts": 0,
        "conversation_replies": 0,
        "conversation_gaps": []
      }
    },
    {
      "id": "jamesob-mk3-move-funds-advice",
      "title": "Mk3 single-key move-funds advice",
      "url": "https://x.com/jamesob/status/2082946043696574756",
      "author": "jamesob",
      "platform": "x",
      "organisation": null,
      "posted": "2026-07-30T21:46:50Z",
      "role": "social-statement",
      "why_registered": "James O'Beirne advises moving bitcoin held under a single Coldcard Mk3 key generated between 2021 and 2023 if it did not use dice rolls, a passphrase or multi-sig. Held as a dated incident-response migration recommendation. The recommendation is the poster's own and is not independently verified here.\n",
      "relation": {
        "kind": "single-post",
        "head_id": null
      },
      "capture": {
        "status": "held",
        "artefact_count": 2,
        "conversation_copies": 0,
        "conversation_posts": 0,
        "conversation_replies": 0,
        "conversation_gaps": []
      }
    },
    {
      "id": "jamesob-multisig-slipstream-advice",
      "title": "Multisig recovery via private miner submission",
      "url": "https://x.com/jamesob/status/2083196852233515152",
      "author": "jamesob",
      "platform": "x",
      "organisation": null,
      "posted": "2026-07-31T14:23:28Z",
      "role": "social-statement",
      "why_registered": "James O'Beirne recommends using a private direct-to-miner mempool service such as Slipstream when recovering from an affected multi-sig wallet without prior spends, to reduce the chance that the attacker observes pubkeys and has time to grind funds. Held as a dated incident-response mitigation recommendation. The recommendation is the poster's own and is not independently verified here.\n",
      "relation": {
        "kind": "single-post",
        "head_id": null
      },
      "capture": {
        "status": "held",
        "artefact_count": 2,
        "conversation_copies": 0,
        "conversation_posts": 0,
        "conversation_replies": 0,
        "conversation_gaps": []
      }
    },
    {
      "id": "jamesob-dice-roll-code-verification",
      "title": "Dice-roll code-path verification",
      "url": "https://x.com/jamesob/status/2083184261918523650",
      "author": "jamesob",
      "platform": "x",
      "organisation": null,
      "posted": "2026-07-31T13:33:26Z",
      "role": "social-statement",
      "why_registered": "James O'Beirne states that he has verified the code paths for all firmware versions and that dice rolls are mixed into the seed via hash, with 99 or more rolls being good. Held as a dated technical verification statement about the dice-roll mitigation path. The verification claim is the poster's own and is not independently verified here.\n",
      "relation": {
        "kind": "single-post",
        "head_id": null
      },
      "capture": {
        "status": "held",
        "artefact_count": 2,
        "conversation_copies": 0,
        "conversation_posts": 0,
        "conversation_replies": 0,
        "conversation_gaps": []
      }
    },
    {
      "id": "jamesob-provisioned-keys-move",
      "title": "Move funds from provisioned Coinkite keys",
      "url": "https://x.com/jamesob/status/2083165859783012659",
      "author": "jamesob",
      "platform": "x",
      "organisation": null,
      "posted": "2026-07-31T12:20:18Z",
      "role": "social-statement",
      "why_registered": "James O'Beirne gives a bottom-line recommendation to move funds expeditiously from any Coinkite device bought in or after 2021 if the keys were provisioned without dice rolls, and notes an ongoing investigation into the firmware state. Held as a dated broad incident-response guidance statement. The recommendation is the poster's own and is not independently verified here.\n",
      "relation": {
        "kind": "single-post",
        "head_id": null
      },
      "capture": {
        "status": "held",
        "artefact_count": 2,
        "conversation_copies": 0,
        "conversation_posts": 0,
        "conversation_replies": 0,
        "conversation_gaps": []
      }
    },
    {
      "id": "jamesob-mk2-mk4-move-advice",
      "title": "Mk2 and Mk4 may also be affected; move single-key funds",
      "url": "https://x.com/jamesob/status/2082962518100586708",
      "author": "jamesob",
      "platform": "x",
      "organisation": null,
      "posted": "2026-07-30T22:52:18Z",
      "role": "social-statement",
      "why_registered": "James O'Beirne confirms the issue may also affect Mk2 and Mk4, and updates his advice to move funds held under single keys generated by Coinkite devices bought during or after 2021 without a passphrase or dice rolls. Held as a dated scope-expansion and migration recommendation. The recommendation is the poster's own and is not independently verified here.\n",
      "relation": {
        "kind": "single-post",
        "head_id": null
      },
      "capture": {
        "status": "held",
        "artefact_count": 2,
        "conversation_copies": 0,
        "conversation_posts": 0,
        "conversation_replies": 0,
        "conversation_gaps": []
      }
    },
    {
      "id": "jamesob-dice-passphrase-safety",
      "title": "Dice-roll path safe; passphrase security depends on passphrase strength",
      "url": "https://x.com/jamesob/status/2082980104850792753",
      "author": "jamesob",
      "platform": "x",
      "organisation": null,
      "posted": "2026-07-31T00:02:11Z",
      "role": "social-statement",
      "why_registered": "James O'Beirne states that the dice-roll path is safe provided enough dice rolls were used, and that passphrase-protected coins are now only as safe as the passphrase. Held as a dated mitigation guidance statement about two incident-response paths. The verification claim is the poster's own and is not independently verified here.\n",
      "relation": {
        "kind": "single-post",
        "head_id": null
      },
      "capture": {
        "status": "held",
        "artefact_count": 2,
        "conversation_copies": 0,
        "conversation_posts": 0,
        "conversation_replies": 0,
        "conversation_gaps": []
      }
    },
    {
      "id": "jamesob-coinkite-response-credit",
      "title": "Credit to Coinkite and nvk for cooperating during response",
      "url": "https://x.com/jamesob/status/2083014160040734908",
      "author": "jamesob",
      "platform": "x",
      "organisation": null,
      "posted": "2026-07-31T02:17:30Z",
      "role": "social-statement",
      "why_registered": "James O'Beirne credits nvk and Coinkite for being alongside responders throughout the incident. Held as a dated statement of sentiment about the vendor's cooperation during the public response. The characterization is the poster's own and is not independently verified here.\n",
      "relation": {
        "kind": "single-post",
        "head_id": null
      },
      "capture": {
        "status": "held",
        "artefact_count": 2,
        "conversation_copies": 0,
        "conversation_posts": 0,
        "conversation_replies": 0,
        "conversation_gaps": []
      }
    },
    {
      "id": "jamesob-covenants-usability-argument",
      "title": "Covenants as the path to usable multi-sig-level security",
      "url": "https://x.com/jamesob/status/2083013326804595087",
      "author": "jamesob",
      "platform": "x",
      "organisation": null,
      "posted": "2026-07-31T02:14:12Z",
      "role": "social-statement",
      "why_registered": "James O'Beirne argues that covenants are the only path to multi-signature-level security with human-level usability, framing the incident as a case for protocol-level safeguards. Held as a dated technical-policy argument about how the incident informs Bitcoin design. The argument is the poster's own and is not independently verified here.\n",
      "relation": {
        "kind": "single-post",
        "head_id": null
      },
      "capture": {
        "status": "held",
        "artefact_count": 2,
        "conversation_copies": 0,
        "conversation_posts": 0,
        "conversation_replies": 0,
        "conversation_gaps": []
      }
    },
    {
      "id": "kloaec-nvk-dochex-mistake",
      "title": "NVK and DocHex incident-response critique",
      "url": "https://x.com/KLoaec/status/2085714594689880490",
      "author": "KLoaec",
      "platform": "x",
      "organisation": null,
      "posted": "2026-08-07T13:08:04Z",
      "role": "social-statement",
      "why_registered": "Kevin Loaec's dated critique of the vendor response, stating that NVK forgot to tell DocHex to \"make no mistake\". Held as a sentiment statement about Coinkite leadership during the incident; the characterization is the poster's own and is not independently verified here.\n",
      "relation": {
        "kind": "single-post",
        "head_id": null
      },
      "capture": {
        "status": "held",
        "artefact_count": 2,
        "conversation_copies": 0,
        "conversation_posts": 0,
        "conversation_replies": 0,
        "conversation_gaps": []
      }
    },
    {
      "id": "kloaec-fork-scam-warning",
      "title": "Fork-airdrop scam warning",
      "url": "https://x.com/KLoaec/status/2085474252740808915",
      "author": "KLoaec",
      "platform": "x",
      "organisation": null,
      "posted": "2026-08-06T21:13:02Z",
      "role": "social-statement",
      "why_registered": "Kevin Loaec's public safety warning that a forthcoming Bitcoin fork coin will create scam opportunities targeting holders seeking to sell an airdrop. Held as dated guidance on scams exploiting the post-incident panic; the risk assessment is the poster's own and is not independently verified here.\n",
      "relation": {
        "kind": "conversation-head",
        "head_id": null
      },
      "capture": {
        "status": "held",
        "artefact_count": 80,
        "conversation_copies": 4,
        "conversation_posts": 93,
        "conversation_replies": 88,
        "conversation_gaps": []
      }
    },
    {
      "id": "aamanda-victim-support-offer",
      "title": "Psychologist volunteer support offer",
      "url": "https://x.com/aamanda/status/2085128384498344333",
      "author": "aamanda",
      "platform": "x",
      "organisation": null,
      "posted": "2026-08-05T22:18:41Z",
      "role": "social-statement",
      "why_registered": "Amanda da Silveira, a psychologist and bitcoiner, offers to volunteer time to talk with anyone in the Bitcoin community affected by the incident. Held as a dated first-hand record of community victim-support response; the offer is the poster's own and is not independently verified here.\n",
      "relation": {
        "kind": "single-post",
        "head_id": null
      },
      "capture": {
        "status": "held",
        "artefact_count": 2,
        "conversation_copies": 0,
        "conversation_posts": 0,
        "conversation_replies": 0,
        "conversation_gaps": []
      }
    },
    {
      "id": "kloaec-prior-report-challenge",
      "title": "Challenge to produce prior reports of the fallback-to-PRNG bug",
      "url": "https://x.com/KLoaec/status/2085004779780976958",
      "author": "KLoaec",
      "platform": "x",
      "organisation": null,
      "posted": "2026-08-05T14:07:31Z",
      "role": "social-statement",
      "why_registered": "Kevin Loaec asks anyone who knew about the fallback-to-PRNG bug and reported it to Coinkite to send proof to James, adding that he does not believe anyone did. Held as a dated public challenge about prior knowledge of the vulnerability. The claim is the poster's own and is not independently verified here.\n",
      "relation": {
        "kind": "single-post",
        "head_id": null
      },
      "capture": {
        "status": "held",
        "artefact_count": 2,
        "conversation_copies": 0,
        "conversation_posts": 0,
        "conversation_replies": 0,
        "conversation_gaps": []
      }
    },
    {
      "id": "ishi0k-incident-reconstruction",
      "title": "Chronological reconstruction of the incident discovery",
      "url": "https://x.com/ishi0k/status/2084809954922258718",
      "author": "ishi0k",
      "platform": "x",
      "organisation": null,
      "posted": "2026-08-05T01:13:21Z",
      "role": "social-statement",
      "why_registered": "Ishi publishes a three-part thread reconstructing the discovery of the COLDCARD disaster, identifying the first widely documented public victim report and the first on-chain observation of the consolidation pattern. Held as a dated reported reconstruction of the incident timeline. The claims about timing and identity are the poster's own and are not independently verified here.\n",
      "relation": {
        "kind": "conversation-head",
        "head_id": null
      },
      "capture": {
        "status": "held",
        "artefact_count": 7,
        "conversation_copies": 1,
        "conversation_posts": 5,
        "conversation_replies": 3,
        "conversation_gaps": []
      }
    },
    {
      "id": "profedustream-slipstream-mempool-warning",
      "title": "Slipstream mempool-risk warning for Liana and multi-sig users",
      "url": "https://x.com/profedustream/status/2084672389070139849",
      "author": "profedustream",
      "platform": "x",
      "organisation": null,
      "posted": "2026-08-04T16:06:43Z",
      "role": "social-statement",
      "why_registered": "ProfEduStream warns Liana and multi-sig users that broadcasting a transaction to the public mempool can let an attacker replace it if one key was generated on an affected Coldcard, and describes a tool that submits signed transactions privately to MARA's Slipstream service. Held as a dated incident-response mitigation recommendation. The recommendation is the poster's own and is not independently verified here.\n",
      "relation": {
        "kind": "single-post",
        "head_id": null
      },
      "capture": {
        "status": "held",
        "artefact_count": 2,
        "conversation_copies": 0,
        "conversation_posts": 0,
        "conversation_replies": 0,
        "conversation_gaps": []
      }
    },
    {
      "id": "kloaec-prior-knowledge-claim",
      "title": "Claim that prior knowledge of the bug was widespread",
      "url": "https://x.com/KLoaec/status/2084658920522469885",
      "author": "KLoaec",
      "platform": "x",
      "organisation": null,
      "posted": "2026-08-04T15:13:12Z",
      "role": "social-statement",
      "why_registered": "Kevin Loaec asserts that everyone knew about the fallback-to-PRNG bug for a long time and criticizes other participants as not serious. Held as a dated sentiment statement about prior knowledge of the vulnerability. The claim is the poster's own and is not independently verified here.\n",
      "relation": {
        "kind": "single-post",
        "head_id": null
      },
      "capture": {
        "status": "held",
        "artefact_count": 2,
        "conversation_copies": 0,
        "conversation_posts": 0,
        "conversation_replies": 0,
        "conversation_gaps": []
      }
    },
    {
      "id": "darosior-psbt-miner-tool-advice",
      "title": "PSBT miner-submission advice for multisig sweeps",
      "url": "https://x.com/darosior/status/2084370661560991841",
      "author": "darosior",
      "platform": "x",
      "organisation": null,
      "posted": "2026-08-03T20:07:46Z",
      "role": "migration-guidance",
      "why_registered": "Antoine Poinsot explains that publishing a multisig PSBT through a private miner submission can keep descriptor information off the public mempool until confirmation, which may help when affected COLDCARD keys meet the spending threshold but the attacker still lacks the wallet setup needed to reconstruct scripts. Held as a dated technical mitigation recommendation. The security assessment is the poster's own and is not independently verified here.\n",
      "relation": {
        "kind": "single-post",
        "head_id": null
      },
      "capture": {
        "status": "held",
        "artefact_count": 2,
        "conversation_copies": 0,
        "conversation_posts": 0,
        "conversation_replies": 0,
        "conversation_gaps": []
      }
    },
    {
      "id": "bitcoinlixin-continuous-audit-commentary",
      "title": "Commentary on continuous wallet security audits",
      "url": "https://x.com/BitcoinLixin/status/2084349444506689736",
      "author": "BitcoinLixin",
      "platform": "x",
      "organisation": null,
      "posted": "2026-08-03T18:43:27Z",
      "role": "commentary",
      "why_registered": "Lixin Liu states that only a small number of wallets continue to perform security audits after product launch. Held as a dated industry commentary on hardware-wallet security practices in the wake of the incident. The claim is the poster's own and is not independently verified here.\n",
      "relation": {
        "kind": "single-post",
        "head_id": null
      },
      "capture": {
        "status": "held",
        "artefact_count": 2,
        "conversation_copies": 0,
        "conversation_posts": 0,
        "conversation_replies": 0,
        "conversation_gaps": []
      }
    },
    {
      "id": "btchip-dice-entropy-ai-pivot",
      "title": "Dice entropy AI pivot",
      "url": "https://x.com/BTChip/status/2084207111534248188",
      "author": "BTChip",
      "platform": "x",
      "organisation": null,
      "posted": "2026-08-03T09:17:52Z",
      "role": "social-statement",
      "why_registered": "Nicolas Bacca of Ledger comments that continuing to discuss dice-based entropy generation in 2026 should prompt a pivot to AI or gardening. Held as a hardware-wallet vendor figure's dated reaction to the post-incident entropy-generation debate. The opinion is the poster's own and is not verified here.",
      "relation": {
        "kind": "single-post",
        "head_id": null
      },
      "capture": {
        "status": "held",
        "artefact_count": 2,
        "conversation_copies": 0,
        "conversation_posts": 0,
        "conversation_replies": 0,
        "conversation_gaps": []
      }
    },
    {
      "id": "kloaec-suing-open-source-legal-risk",
      "title": "Suing open-source security companies is a legal risk",
      "url": "https://x.com/KLoaec/status/2084344084043330009",
      "author": "KLoaec",
      "platform": "x",
      "organisation": null,
      "posted": "2026-08-03T18:22:09Z",
      "role": "social-statement",
      "why_registered": "Kevin Loaec argues that suing security companies with publicly auditable code makes open-source product development legally risky, and urges funding security audits and bug bounties instead. Held as a dated incident-response opinion from a named responder. The opinion is the poster's own and is not verified here.",
      "relation": {
        "kind": "single-post",
        "head_id": null
      },
      "capture": {
        "status": "held",
        "artefact_count": 2,
        "conversation_copies": 0,
        "conversation_posts": 0,
        "conversation_replies": 0,
        "conversation_gaps": []
      }
    },
    {
      "id": "briantrollz-lightning-channel-warning",
      "title": "Lightning channel closure warning for BIP-85 seeds",
      "url": "https://x.com/brian_trollz/status/2084150173265981624",
      "author": "brian_trollz",
      "platform": "x",
      "organisation": null,
      "posted": "2026-08-03T05:31:37Z",
      "role": "social-statement",
      "why_registered": "Bitcoin Isn't About You warns that BIP-85 seeds generated on a compromised Coldcard and used on a Lightning node put on-chain funds at risk if channels are closed, advising off-chain swaps first. Held as dated technical guidance from a named community figure during the incident response. The claims are the poster's own and are not verified here.",
      "relation": {
        "kind": "single-post",
        "head_id": null
      },
      "capture": {
        "status": "held",
        "artefact_count": 2,
        "conversation_copies": 0,
        "conversation_posts": 0,
        "conversation_replies": 0,
        "conversation_gaps": []
      }
    },
    {
      "id": "kloaec-against-stealing-rescue-funds",
      "title": "Against stealing from users who can still move coins",
      "url": "https://x.com/KLoaec/status/2084223689734656312",
      "author": "KLoaec",
      "platform": "x",
      "organisation": null,
      "posted": "2026-08-03T10:23:45Z",
      "role": "social-statement",
      "why_registered": "Kevin Loaec states he is against taking coins from users who can still move them, noting that many no longer have their original device and recovery would be unlikely. Held as a dated statement on the rescue-versus-theft debate from a named responder. The opinion is the poster's own and is not verified here.",
      "relation": {
        "kind": "single-post",
        "head_id": null
      },
      "capture": {
        "status": "held",
        "artefact_count": 2,
        "conversation_copies": 0,
        "conversation_posts": 0,
        "conversation_replies": 0,
        "conversation_gaps": []
      }
    },
    {
      "id": "giacomozucco-hackers-vs-critics",
      "title": "Hackers less disgusting than critics",
      "url": "https://x.com/giacomozucco/status/2084063583017607605",
      "author": "giacomozucco",
      "platform": "x",
      "organisation": null,
      "posted": "2026-08-02T23:47:32Z",
      "role": "social-statement",
      "why_registered": "Giacomo Zucco opines that the actual COLDCARD attacker is less disgusting aesthetically and perhaps ethically than critics he describes as vultures, and compares the harm to KYC and regulated custodians. Held as a dated sentiment post from a named Bitcoin figure. The opinion is the poster's own and is not verified here.",
      "relation": {
        "kind": "single-post",
        "head_id": null
      },
      "capture": {
        "status": "held",
        "artefact_count": 2,
        "conversation_copies": 0,
        "conversation_posts": 0,
        "conversation_replies": 0,
        "conversation_gaps": []
      }
    },
    {
      "id": "briantrollz-bad-advice-warning",
      "title": "Warning against bad advice from named influencers",
      "url": "https://x.com/brian_trollz/status/2083939469808345332",
      "author": "brian_trollz",
      "platform": "x",
      "organisation": null,
      "posted": "2026-08-02T15:34:21Z",
      "role": "social-statement",
      "why_registered": "Bitcoin Isn't About You warns against taking incident-handling advice from hodlonaut, GrassFedBitcoin and similar figures, claiming they have told vulnerable people not to move funds when they should. Held as a dated claim about advice quality during the incident response. The claims are the poster's own and are not verified here.",
      "relation": {
        "kind": "single-post",
        "head_id": null
      },
      "capture": {
        "status": "held",
        "artefact_count": 2,
        "conversation_copies": 0,
        "conversation_posts": 0,
        "conversation_replies": 0,
        "conversation_gaps": []
      }
    },
    {
      "id": "lianabitcoin-new-followers-silence",
      "title": "Welcome to new followers after keeping silent",
      "url": "https://x.com/lianabitcoin/status/2084066296342167665",
      "author": "lianabitcoin",
      "platform": "x",
      "organisation": "Liana Wallet",
      "posted": "2026-08-02T23:58:19Z",
      "role": "social-statement",
      "why_registered": "Liana Wallet welcomes new followers and explains that its account stayed silent while Kevin Loaec was busy warning and helping people on the front line. Held as an organisational statement on the project's incident-response posture. The claims are the poster's own and are not verified here.",
      "relation": {
        "kind": "single-post",
        "head_id": null
      },
      "capture": {
        "status": "held",
        "artefact_count": 2,
        "conversation_copies": 0,
        "conversation_posts": 0,
        "conversation_replies": 0,
        "conversation_gaps": []
      }
    },
    {
      "id": "salvatoshi-self-custody-dev-tools",
      "title": "Self-custody dev tools after the incident",
      "url": "https://x.com/salvatoshi/status/2084012674229395902",
      "author": "salvatoshi",
      "platform": "x",
      "organisation": null,
      "posted": "2026-08-02T20:25:15Z",
      "role": "social-statement",
      "why_registered": "Salvatore Ingala argues that existing self-custody development tools, including those built by Liana, could greatly reduce the fallout from catastrophic failures like the COLDCARD bug, and questions why more developers are not using them. Held as a dated technical argument about application-level custody tooling from a named Bitcoin developer. The argument is the poster's own and is not independently verified here.",
      "relation": {
        "kind": "single-post",
        "head_id": null
      },
      "capture": {
        "status": "held",
        "artefact_count": 2,
        "conversation_copies": 0,
        "conversation_posts": 0,
        "conversation_replies": 0,
        "conversation_gaps": []
      }
    },
    {
      "id": "briantrollz-preserve-compromised-device",
      "title": "Preserve compromised Coldcard for ownership proof",
      "url": "https://x.com/brian_trollz/status/2083971991132914121",
      "author": "brian_trollz",
      "platform": "x",
      "organisation": null,
      "posted": "2026-08-02T17:43:35Z",
      "role": "social-statement",
      "why_registered": "Bitcoin Isn't About You advises people who lost funds not to sell, destroy or give away the compromised COLDCARD that generated the affected seed, because the device may be needed to prove legitimate ownership if any stolen funds are recovered. Held as dated incident-response guidance from a named community figure. The claims are the poster's own and are not independently verified here.",
      "relation": {
        "kind": "single-post",
        "head_id": null
      },
      "capture": {
        "status": "held",
        "artefact_count": 2,
        "conversation_copies": 0,
        "conversation_posts": 0,
        "conversation_replies": 0,
        "conversation_gaps": []
      }
    },
    {
      "id": "ivygalindo-coinkite-email-delay",
      "title": "Coinkite firmware email arrived late",
      "url": "https://x.com/ivygalindo/status/2083914415112429661",
      "author": "ivygalindo",
      "platform": "x",
      "organisation": null,
      "posted": "2026-08-02T13:54:48Z",
      "role": "social-statement",
      "why_registered": "Ivy Galindo claims Coinkite emailed customers to update firmware only on 1 August, and asks how much bitcoin could have been saved if the vendor had emailed when the early warning first circulated. Held as a dated public accusation about vendor incident-response timing. The claim is the poster's own and is not independently verified here.",
      "relation": {
        "kind": "single-post",
        "head_id": null
      },
      "capture": {
        "status": "held",
        "artefact_count": 2,
        "conversation_copies": 0,
        "conversation_posts": 0,
        "conversation_replies": 0,
        "conversation_gaps": []
      }
    },
    {
      "id": "teruko21m-data-retention-firsthand",
      "title": "First-hand account of long-retained customer email",
      "url": "https://x.com/Teruko21M/status/2083757243464560906",
      "author": "Teruko21M",
      "platform": "x",
      "organisation": null,
      "posted": "2026-08-02T03:30:15Z",
      "role": "social-statement",
      "why_registered": "Teruko reports receiving a Coinkite firmware-update email at a throwaway address created three years earlier, contradicting the stated 120-day customer-data deletion policy. Held as a first-hand account about vendor data-retention practice during the incident response. The account is the poster's own and is not independently verified here.",
      "relation": {
        "kind": "single-post",
        "head_id": null
      },
      "capture": {
        "status": "held",
        "artefact_count": 2,
        "conversation_copies": 0,
        "conversation_posts": 0,
        "conversation_replies": 0,
        "conversation_gaps": []
      }
    },
    {
      "id": "kloaec-mk4-drain-claims-unverified",
      "title": "Mk4-class drain claims unverified",
      "url": "https://x.com/KLoaec/status/2083842848042987602",
      "author": "KLoaec",
      "platform": "x",
      "organisation": null,
      "posted": "2026-08-02T09:10:25Z",
      "role": "social-statement",
      "why_registered": "Kevin Loaec says he has not yet verified trustworthy reports of non-Mk3 funds being drained, while noting that Mk4 and later models remain vulnerable. Held as a dated correction of emphasis from a named responder after his earlier Mk4-class drain report. The assessment is the poster's own and is not independently verified here.",
      "relation": {
        "kind": "single-post",
        "head_id": null
      },
      "capture": {
        "status": "held",
        "artefact_count": 2,
        "conversation_copies": 0,
        "conversation_posts": 0,
        "conversation_replies": 0,
        "conversation_gaps": []
      }
    },
    {
      "id": "kloaec-attacker-economics",
      "title": "Attacker economics as funds move",
      "url": "https://x.com/KLoaec/status/2083704151976861932",
      "author": "KLoaec",
      "platform": "x",
      "organisation": null,
      "posted": "2026-08-01T23:59:17Z",
      "role": "independent-analysis",
      "why_registered": "Kevin Loaec analyzes the game theory facing attackers as community response drives down the reward for further drains while GPU rental costs stay high, and questions whether breaking remaining weak wallets is still profitable. Held as a dated technical argument about attacker economics during the incident. The analysis is the poster's own and is not independently verified here.",
      "relation": {
        "kind": "single-post",
        "head_id": null
      },
      "capture": {
        "status": "held",
        "artefact_count": 2,
        "conversation_copies": 0,
        "conversation_posts": 0,
        "conversation_replies": 0,
        "conversation_gaps": []
      }
    },
    {
      "id": "sd-nym-weak-passphrase-account",
      "title": "Weak single-BIP39-word passphrase account",
      "url": "https://x.com/sd_nym/status/2083674639876669713",
      "author": "sd_nym",
      "platform": "x",
      "organisation": null,
      "posted": "2026-08-01T22:02:01Z",
      "role": "social-statement",
      "why_registered": "Rushmore HODL recounts using a single BIP39 word as a passphrase because they took the '25th word' guidance literally. Held as a first-hand account of how passphrase advice was misunderstood during the incident response. The account is the poster's own and is not independently verified here.",
      "relation": {
        "kind": "single-post",
        "head_id": null
      },
      "capture": {
        "status": "held",
        "artefact_count": 2,
        "conversation_copies": 0,
        "conversation_posts": 0,
        "conversation_replies": 0,
        "conversation_gaps": []
      }
    },
    {
      "id": "kloaec-liana-user-psa",
      "title": "Liana user transfer versus wait guidance",
      "url": "https://x.com/KLoaec/status/2083557680254214174",
      "author": "KLoaec",
      "platform": "x",
      "organisation": null,
      "posted": "2026-08-01T14:17:16Z",
      "role": "migration-guidance",
      "why_registered": "Kevin Loaec gives Liana users a conditional PSA: transfer immediately if their setup uses SegWit with only COLDCARD keys, otherwise wait for the forthcoming Slipstream tool. Held as dated migration guidance from a named responder for a specific wallet configuration. The guidance is the poster's own and is not independently verified here.",
      "relation": {
        "kind": "single-post",
        "head_id": null
      },
      "capture": {
        "status": "held",
        "artefact_count": 2,
        "conversation_copies": 0,
        "conversation_posts": 0,
        "conversation_replies": 0,
        "conversation_gaps": []
      }
    },
    {
      "id": "kloaec-passphrase-grinding-warning",
      "title": "Passphrase grinding warning",
      "url": "https://x.com/KLoaec/status/2083656101891903807",
      "author": "KLoaec",
      "platform": "x",
      "organisation": null,
      "posted": "2026-08-01T20:48:21Z",
      "role": "social-statement",
      "why_registered": "Kevin Loaec warns that attackers are grinding passphrases and that Reddit claims to the contrary are misinformation from bad actors trying to buy time. Held as a dated incident-response statement from a named responder. The claim is the poster's own and is not independently verified here.",
      "relation": {
        "kind": "single-post",
        "head_id": null
      },
      "capture": {
        "status": "held",
        "artefact_count": 2,
        "conversation_copies": 0,
        "conversation_posts": 0,
        "conversation_replies": 0,
        "conversation_gaps": []
      }
    },
    {
      "id": "llfourn-ai-scam-monitoring",
      "title": "AI monitoring for incident-related scams",
      "url": "https://x.com/LLFOURN/status/2085943220555702282",
      "author": "LLFOURN",
      "platform": "x",
      "organisation": null,
      "posted": "2026-08-08T04:16:33Z",
      "role": "social-statement",
      "why_registered": "LLFOURN asks whether AI is monitoring incident-related scams, says Google should be, and suggests building something himself. Held as a dated sentiment about scam-mitigation during the incident response. The claims are the poster's own and are not independently verified here.",
      "relation": {
        "kind": "single-post",
        "head_id": null
      },
      "capture": {
        "status": "held",
        "artefact_count": 2,
        "conversation_copies": 0,
        "conversation_posts": 0,
        "conversation_replies": 0,
        "conversation_gaps": []
      }
    },
    {
      "id": "lopp-migration-malware-warning",
      "title": "Warning about malicious wallet software during migration",
      "url": "https://x.com/lopp/status/2085009215530180851",
      "author": "lopp",
      "platform": "x",
      "organisation": null,
      "posted": "2026-08-05T14:25:09Z",
      "role": "social-statement",
      "why_registered": "Jameson Lopp warns people migrating funds not to find new wallet software through web or app-store search because many results are malicious, advising verification of the real project site first. Held as dated security guidance during the incident response. The claims are the poster's own and are not independently verified here.",
      "relation": {
        "kind": "single-post",
        "head_id": null
      },
      "capture": {
        "status": "held",
        "artefact_count": 2,
        "conversation_copies": 0,
        "conversation_posts": 0,
        "conversation_replies": 0,
        "conversation_gaps": []
      }
    },
    {
      "id": "llfourn-qwen-3-6-27b-failed",
      "title": "Qwen 3.6 27B failed to find the bug",
      "url": "https://x.com/LLFOURN/status/2084867395269841037",
      "author": "LLFOURN",
      "platform": "x",
      "organisation": null,
      "posted": "2026-08-05T05:01:36Z",
      "role": "ai-security-response",
      "why_registered": "LLFOURN reports that the Qwen 3.6 27B model failed to identify the COLDCARD firmware vulnerability in his testing. Held as a dated first-hand test result about AI-assisted code review during the incident. The result is the poster's own and is not independently verified here.",
      "relation": {
        "kind": "single-post",
        "head_id": null
      },
      "capture": {
        "status": "held",
        "artefact_count": 2,
        "conversation_copies": 0,
        "conversation_posts": 0,
        "conversation_replies": 0,
        "conversation_gaps": []
      }
    },
    {
      "id": "llfourn-qwen-3-8b-max-failed",
      "title": "Qwen 3.8B-Max failed to surface the bug",
      "url": "https://x.com/LLFOURN/status/2084898150201131392",
      "author": "LLFOURN",
      "platform": "x",
      "organisation": null,
      "posted": "2026-08-05T07:03:49Z",
      "role": "ai-security-response",
      "why_registered": "LLFOURN reports that Qwen 3.8B-Max came close to identifying the vulnerability during reasoning but did not include it in the final report, and asks what git clone command was used to set up the firmware repo. Held as a dated first-hand AI code-review test result. The result is the poster's own and is not independently verified here.",
      "relation": {
        "kind": "single-post",
        "head_id": null
      },
      "capture": {
        "status": "held",
        "artefact_count": 2,
        "conversation_copies": 0,
        "conversation_posts": 0,
        "conversation_replies": 0,
        "conversation_gaps": []
      }
    },
    {
      "id": "joenakamoto-victim-support",
      "title": "First-hand hardware-wallet loss and recovery encouragement",
      "url": "https://x.com/JoeNakamoto/status/2084200162696585334",
      "author": "JoeNakamoto",
      "platform": "x",
      "organisation": null,
      "posted": "2026-08-03T08:50:16Z",
      "role": "social-statement",
      "why_registered": "Joe Nakamoto shares a first-hand account of losing 0.3 BTC in 2019 by using a long passphrase, and encourages affected COLDCARD users that things can get better. Held as dated victim-support sentiment from a named Bitcoin figure. The account is the poster's own and is not independently verified here.",
      "relation": {
        "kind": "single-post",
        "head_id": null
      },
      "capture": {
        "status": "held",
        "artefact_count": 2,
        "conversation_copies": 0,
        "conversation_posts": 0,
        "conversation_replies": 0,
        "conversation_gaps": []
      }
    },
    {
      "id": "llfourn-welcome-bitcoin-ceo",
      "title": "Welcome to Bitcoin's new CEO",
      "url": "https://x.com/LLFOURN/status/2084505875155464417",
      "author": "LLFOURN",
      "platform": "x",
      "organisation": null,
      "posted": "2026-08-04T05:05:03Z",
      "role": "social-statement",
      "why_registered": "LLFOURN sarcastically welcomes 'Bitcoin's new CEO' in the wake of the COLDCARD incident. Held as a dated sentiment about leadership and accountability from a named Bitcoin developer. The opinion is the poster's own and is not independently verified here.",
      "relation": {
        "kind": "single-post",
        "head_id": null
      },
      "capture": {
        "status": "held",
        "artefact_count": 2,
        "conversation_copies": 0,
        "conversation_posts": 0,
        "conversation_replies": 0,
        "conversation_gaps": []
      }
    },
    {
      "id": "rusty-twit-adelaide-migration-help",
      "title": "Offer of in-person migration help in Adelaide",
      "url": "https://x.com/rusty_twit/status/2084036313343537153",
      "author": "rusty_twit",
      "platform": "x",
      "organisation": null,
      "posted": "2026-08-02T21:59:11Z",
      "role": "social-statement",
      "why_registered": "TheRustyTwit offers hands-on help migrating people off Coldcard in the Adelaide area after already performing one migration. Held as a dated record of grassroots incident assistance from a named community member. The offer is the poster's own and is not independently verified here.",
      "relation": {
        "kind": "single-post",
        "head_id": null
      },
      "capture": {
        "status": "held",
        "artefact_count": 2,
        "conversation_copies": 0,
        "conversation_posts": 0,
        "conversation_replies": 0,
        "conversation_gaps": []
      }
    },
    {
      "id": "utxoclub-airgapping-larp",
      "title": "Airgapping and secure elements are insufficient",
      "url": "https://x.com/utxoclub/status/2083931059583070706",
      "author": "utxoclub",
      "platform": "x",
      "organisation": null,
      "posted": "2026-08-02T15:00:56Z",
      "role": "social-statement",
      "why_registered": "UTXOCLUB argues that airgapping is a larp, secure elements are merely PIN authenticators, and extra dice rolls are a prayer. Held as a dated hardware-wallet security-model critique during the incident response. The argument is the poster's own and is not independently verified here.",
      "relation": {
        "kind": "single-post",
        "head_id": null
      },
      "capture": {
        "status": "held",
        "artefact_count": 2,
        "conversation_copies": 0,
        "conversation_posts": 0,
        "conversation_replies": 0,
        "conversation_gaps": []
      }
    },
    {
      "id": "utxoclub-opus-missed-submodules",
      "title": "Opus missed the bug because submodules were not cloned",
      "url": "https://x.com/utxoclub/status/2083838008357450063",
      "author": "utxoclub",
      "platform": "x",
      "organisation": null,
      "posted": "2026-08-02T08:51:11Z",
      "role": "ai-security-response",
      "why_registered": "UTXOCLUB explains that an Opus audit missed the COLDCARD bug because not enough submodules were cloned, leaving files that contain the issue off disk while present files told a self-consistent story. Held as a dated first-hand technical account of an AI-assisted code-review limitation. The account is the poster's own and is not independently verified here.",
      "relation": {
        "kind": "single-post",
        "head_id": null
      },
      "capture": {
        "status": "held",
        "artefact_count": 2,
        "conversation_copies": 0,
        "conversation_posts": 0,
        "conversation_replies": 0,
        "conversation_gaps": []
      }
    },
    {
      "id": "frostsnaptech-never-trusted-own-entropy",
      "title": "Hardware wallet that never generates its own entropy",
      "url": "https://x.com/FrostsnapTech/status/2083625693272002893",
      "author": "FrostsnapTech",
      "platform": "x",
      "organisation": null,
      "posted": "2026-08-01T18:47:31Z",
      "role": "social-statement",
      "why_registered": "Frostsnap states that its device is the only hardware wallet never trusted to generate its own entropy. Held as a dated product-positioning statement in the post-incident hardware-wallet trust discussion. The claim is the poster's own and is not independently verified here.",
      "relation": {
        "kind": "single-post",
        "head_id": null
      },
      "capture": {
        "status": "held",
        "artefact_count": 2,
        "conversation_copies": 0,
        "conversation_posts": 0,
        "conversation_replies": 0,
        "conversation_gaps": []
      }
    },
    {
      "id": "kloaec-passphrase-phishing-replies",
      "title": "Passphrase phishing in tweet replies",
      "url": "https://x.com/KLoaec/status/2083499503638769867",
      "author": "KLoaec",
      "platform": "x",
      "organisation": null,
      "posted": "2026-08-01T10:26:05Z",
      "role": "social-statement",
      "why_registered": "Kevin Loaec warns that attackers are replying to incident tweets with passphrase reassurance and fake entropy-checker websites, and urges users with non-dice passphrases to move funds. Held as a dated scam-warning during the incident response. The claims are the poster's own and are not independently verified here.",
      "relation": {
        "kind": "single-post",
        "head_id": null
      },
      "capture": {
        "status": "held",
        "artefact_count": 2,
        "conversation_copies": 0,
        "conversation_posts": 0,
        "conversation_replies": 0,
        "conversation_gaps": []
      }
    },
    {
      "id": "americanhodl8-airgap-theater-reaction",
      "title": "Reaction to airgap security theater",
      "url": "https://x.com/americanhodl8/status/2083363747696083352",
      "author": "americanhodl8",
      "platform": "x",
      "organisation": null,
      "posted": "2026-08-01T01:26:39Z",
      "role": "social-statement",
      "why_registered": "AMERICAN HODL reacts angrily to the COLDCARD entropy bug, contrasting elaborate airgap precautions with worse entropy than a Trezor One. Held as a dated sentiment post from a named Bitcoin figure. The opinion is the poster's own and is not independently verified here.",
      "relation": {
        "kind": "single-post",
        "head_id": null
      },
      "capture": {
        "status": "held",
        "artefact_count": 2,
        "conversation_copies": 0,
        "conversation_posts": 0,
        "conversation_replies": 0,
        "conversation_gaps": []
      }
    },
    {
      "id": "utxoclub-multisig-slipstream-emergency",
      "title": "Multisig emergency transactions through Slipstream",
      "url": "https://x.com/utxoclub/status/2083406498928193896",
      "author": "utxoclub",
      "platform": "x",
      "organisation": null,
      "posted": "2026-08-01T04:16:31Z",
      "role": "migration-guidance",
      "why_registered": "UTXOCLUB advises users with multisig setups containing enough affected COLDCARDs to broadcast emergency transactions through Slipstream so they remain private until mined, avoiding a race with a watching thief. Held as dated technical mitigation guidance during the incident response. The guidance is the poster's own and is not independently verified here.",
      "relation": {
        "kind": "single-post",
        "head_id": null
      },
      "capture": {
        "status": "held",
        "artefact_count": 2,
        "conversation_copies": 0,
        "conversation_posts": 0,
        "conversation_replies": 0,
        "conversation_gaps": []
      }
    },
    {
      "id": "llfourn-life-savings-move-now",
      "title": "Urgent advice to move life savings off Coldcard",
      "url": "https://x.com/LLFOURN/status/2083315485970714695",
      "author": "LLFOURN",
      "platform": "x",
      "organisation": null,
      "posted": "2026-07-31T22:14:52Z",
      "role": "migration-guidance",
      "why_registered": "LLFOURN urges anyone with life savings on a Coldcard that did not use dice rolls or an external seed phrase to stop what they are doing and move funds immediately. Held as a dated urgent migration warning from a named Bitcoin developer. The warning is the poster's own and is not independently verified here.",
      "relation": {
        "kind": "single-post",
        "head_id": null
      },
      "capture": {
        "status": "held",
        "artefact_count": 2,
        "conversation_copies": 0,
        "conversation_posts": 0,
        "conversation_replies": 0,
        "conversation_gaps": []
      }
    },
    {
      "id": "coryswan-import-vs-spend-warning",
      "title": "Importing versus spending to a new wallet",
      "url": "https://x.com/CorySwan/status/2083248545960698115",
      "author": "CorySwan",
      "platform": "x",
      "organisation": null,
      "posted": "2026-07-31T17:48:52Z",
      "role": "social-statement",
      "why_registered": "Cory Klippsten warns that importing a COLDCARD-generated seed into a different hardware wallet, rather than spending the bitcoin to a newly generated seed, leaves the funds vulnerable because the seed entropy is low. He notes that some users may choose import to save fees or after loss or theft of the COLDCARD, and stresses that a fresh seed should be generated on the new device. Held as dated migration guidance from a Swan employee during the early incident response. The guidance is the poster's own and is not independently verified here.\n",
      "relation": {
        "kind": "single-post",
        "head_id": null
      },
      "capture": {
        "status": "held",
        "artefact_count": 2,
        "conversation_copies": 0,
        "conversation_posts": 0,
        "conversation_replies": 0,
        "conversation_gaps": []
      }
    },
    {
      "id": "wood-sliver-mk4-single-sig-loss",
      "title": "First-hand Mk4 single-sig loss report",
      "url": "https://x.com/Wood_sliver/status/2083262275243155852",
      "author": "Wood_sliver",
      "platform": "x",
      "organisation": null,
      "posted": "2026-07-31T18:43:26Z",
      "role": "social-statement",
      "why_registered": "sliver reports losing a single-signature wallet on a Mk4 COLDCARD, stated as a first-hand victim account during the early hours of the incident. Held as a dated personal loss report from a named account. The claim is the poster's own and is not independently verified here.\n",
      "relation": {
        "kind": "single-post",
        "head_id": null
      },
      "capture": {
        "status": "held",
        "artefact_count": 2,
        "conversation_copies": 0,
        "conversation_posts": 0,
        "conversation_replies": 0,
        "conversation_gaps": []
      }
    },
    {
      "id": "nuno-five-years-unverified-entropy",
      "title": "Five years of unverified low entropy",
      "url": "https://x.com/bc1nuno/status/2083138591849320750",
      "author": "bc1nuno",
      "platform": "x",
      "organisation": null,
      "posted": "2026-07-31T10:31:57Z",
      "role": "social-statement",
      "why_registered": "Nuno asks how five years of low entropy passed without anyone verifying, calling it a collective failure. Held as a dated sentiment and audit-culture statement from a named Bitcoin figure. The opinion is the poster's own and is not independently verified here.\n",
      "relation": {
        "kind": "single-post",
        "head_id": null
      },
      "capture": {
        "status": "held",
        "artefact_count": 2,
        "conversation_copies": 0,
        "conversation_posts": 0,
        "conversation_replies": 0,
        "conversation_gaps": []
      }
    },
    {
      "id": "afilini-stm32-uid-whitehat-identification",
      "title": "STM32 UID white-hat ownership identification",
      "url": "https://x.com/afilini/status/2083137988607754340",
      "author": "afilini",
      "platform": "x",
      "organisation": null,
      "posted": "2026-07-31T10:29:33Z",
      "role": "social-statement",
      "why_registered": "Alekos Filini proposes using STM32 UIDs to identify legitimate coin owners if a white-hat temporarily moves funds, arguing only the owner can produce a physical device with the UID matching the mnemonic. Held as a dated technical proposal in the early incident-response discussion. The proposal is the poster's own and is not independently verified here.\n",
      "relation": {
        "kind": "single-post",
        "head_id": null
      },
      "capture": {
        "status": "held",
        "artefact_count": 2,
        "conversation_copies": 0,
        "conversation_posts": 0,
        "conversation_replies": 0,
        "conversation_gaps": []
      }
    },
    {
      "id": "egge21m-move-coins-now-roi",
      "title": "Attack reproducibility and move-coins warning",
      "url": "https://x.com/Egge21M/status/2083140824104100016",
      "author": "Egge21M",
      "platform": "x",
      "organisation": null,
      "posted": "2026-07-31T10:40:50Z",
      "role": "social-statement",
      "why_registered": "Egge warns that the attack can now be reproduced by anyone and that adding compute becomes a return-on-investment decision, urging users to move their coins immediately. Held as a dated urgent advisory during the incident response. The warning is the poster's own and is not independently verified here.\n",
      "relation": {
        "kind": "single-post",
        "head_id": null
      },
      "capture": {
        "status": "held",
        "artefact_count": 2,
        "conversation_copies": 0,
        "conversation_posts": 0,
        "conversation_replies": 0,
        "conversation_gaps": []
      }
    },
    {
      "id": "briantrollz-mk4-mk5-q-gpu-vulnerability",
      "title": "Expanded Mk4, Mk5 and Q vulnerability warning",
      "url": "https://x.com/brian_trollz/status/2083079855587852631",
      "author": "brian_trollz",
      "platform": "x",
      "organisation": null,
      "posted": "2026-07-31T06:38:33Z",
      "role": "social-statement",
      "why_registered": "Bitcoin Isn't About You suggests Mk4, Mk5 and Q devices may be more vulnerable than previously thought depending on available GPU resources, and advises moving funds as a precaution. Held as a dated technical risk assessment from a named account. The assessment is the poster's own and is not independently verified here.\n",
      "relation": {
        "kind": "single-post",
        "head_id": null
      },
      "capture": {
        "status": "held",
        "artefact_count": 2,
        "conversation_copies": 0,
        "conversation_posts": 0,
        "conversation_replies": 0,
        "conversation_gaps": []
      }
    },
    {
      "id": "martybent-rbf-transactions-rising",
      "title": "RBF transactions rising as attack spreads",
      "url": "https://x.com/MartyBent/status/2083050934611976332",
      "author": "MartyBent",
      "platform": "x",
      "organisation": null,
      "posted": "2026-07-31T04:43:38Z",
      "role": "social-statement",
      "why_registered": "Marty Bent observes that replace-by-fee transactions are on the rise and advises assuming the COLDCARD attack has been widely discovered by multiple attackers. Held as a dated operational observation during the early incident response. The observation is the poster's own and is not independently verified here.\n",
      "relation": {
        "kind": "single-post",
        "head_id": null
      },
      "capture": {
        "status": "held",
        "artefact_count": 2,
        "conversation_copies": 0,
        "conversation_posts": 0,
        "conversation_replies": 0,
        "conversation_gaps": []
      }
    },
    {
      "id": "llfourn-hardware-wallet-trusted-third-party",
      "title": "Hardware wallets as trusted third parties",
      "url": "https://x.com/LLFOURN/status/2083047161718325564",
      "author": "LLFOURN",
      "platform": "x",
      "organisation": null,
      "posted": "2026-07-31T04:28:39Z",
      "role": "social-statement",
      "why_registered": "LLFOURN argues that the core problem exposed by the incident is that hardware wallets are treated as trusted third parties, and that multi-vendor multisig is only a hack around this problem. He points to FrostsnapTech as a design that does not trust devices to generate keys by themselves. Held as a dated architectural critique from a named Bitcoin developer. The critique is the poster's own and is not independently verified here.\n",
      "relation": {
        "kind": "single-post",
        "head_id": null
      },
      "capture": {
        "status": "held",
        "artefact_count": 2,
        "conversation_copies": 0,
        "conversation_posts": 0,
        "conversation_replies": 0,
        "conversation_gaps": []
      }
    },
    {
      "id": "achow101-bad-entropy-not-quantum",
      "title": "Bad entropy, not quantum computers",
      "url": "https://x.com/achow101/status/2083035150276005975",
      "author": "achow101",
      "platform": "x",
      "organisation": null,
      "posted": "2026-07-31T03:40:55Z",
      "role": "social-statement",
      "why_registered": "Ava Chow contrasts the commonly feared quantum-computer threat with the actual risk of bad entropy, framing the COLDCARD incident as a reminder of the latter. Held as a dated framing statement from a named Bitcoin developer. The framing is the poster's own and is not independently verified here.\n",
      "relation": {
        "kind": "single-post",
        "head_id": null
      },
      "capture": {
        "status": "held",
        "artefact_count": 2,
        "conversation_copies": 0,
        "conversation_posts": 0,
        "conversation_replies": 0,
        "conversation_gaps": []
      }
    },
    {
      "id": "llfourn-reuse-coldcard-recovery",
      "title": "Reusing COLDCARD with a newly generated seed",
      "url": "https://x.com/LLFOURN/status/2083013100241035625",
      "author": "LLFOURN",
      "platform": "x",
      "organisation": null,
      "posted": "2026-07-31T02:13:18Z",
      "role": "social-statement",
      "why_registered": "LLFOURN advises that users can keep using their COLDCARD by generating a new seed phrase on a trusted device, sending funds to it, loading it into the COLDCARD, and then deleting it from the other device. Held as dated migration guidance from a named Bitcoin developer. The procedure is the poster's own and is not independently verified here.\n",
      "relation": {
        "kind": "single-post",
        "head_id": null
      },
      "capture": {
        "status": "held",
        "artefact_count": 2,
        "conversation_copies": 0,
        "conversation_posts": 0,
        "conversation_replies": 0,
        "conversation_gaps": []
      }
    },
    {
      "id": "llfourn-laptop-sha512-brute-force",
      "title": "Laptop SHA-512 acceleration for seed brute force",
      "url": "https://x.com/LLFOURN/status/2083001343678259477",
      "author": "LLFOURN",
      "platform": "x",
      "organisation": null,
      "posted": "2026-07-31T01:26:35Z",
      "role": "social-statement",
      "why_registered": "LLFOURN notes that a laptop CPU with dedicated SHA-512 instructions may be enough for offline BIP-39 seed brute forcing and says he plans to work on it over the weekend. Held as a dated technical observation about the compute requirements for attacking the disclosed entropy weakness. The claim is the poster's own and is not independently verified here.\n",
      "relation": {
        "kind": "single-post",
        "head_id": null
      },
      "capture": {
        "status": "held",
        "artefact_count": 2,
        "conversation_copies": 0,
        "conversation_posts": 0,
        "conversation_replies": 0,
        "conversation_gaps": []
      }
    },
    {
      "id": "llfourn-bip39-pbkdf2-brute-force",
      "title": "BIP-39 PBKDF2-HMAC-SHA512 brute-force caveat",
      "url": "https://x.com/LLFOURN/status/2082996000386637864",
      "author": "LLFOURN",
      "platform": "x",
      "organisation": null,
      "posted": "2026-07-31T01:05:21Z",
      "role": "social-statement",
      "why_registered": "LLFOURN revises an earlier estimate, noting that BIP-39 key derivation uses PBKDF2-HMAC-SHA512, so the relevant metric is the laptop's GPU rather than raw SHA-512 speed. Held as a dated technical correction about the compute requirements for attacking the disclosed entropy weakness. The observation is the poster's own and is not independently verified here.\n",
      "relation": {
        "kind": "single-post",
        "head_id": null
      },
      "capture": {
        "status": "held",
        "artefact_count": 2,
        "conversation_copies": 0,
        "conversation_posts": 0,
        "conversation_replies": 0,
        "conversation_gaps": []
      }
    },
    {
      "id": "shorttsqueeze-multisig-migration-offer",
      "title": "Multisig migration guidance offer",
      "url": "https://x.com/shorttsqueeze/status/2085035593663459822",
      "author": "shorttsqueeze",
      "platform": "x",
      "organisation": "Casa",
      "posted": "2026-08-05T16:09:58Z",
      "role": "social-statement",
      "why_registered": "Nathan Shortt says owners moving off affected COLDCARDs commonly delayed multisig because it felt risky to set up alone, and Casa is offering guidance through its advisory calendar. The claim about customer conversations is his own account. The link points to a Casa security-consultation booking page.\n",
      "relation": {
        "kind": "single-post",
        "head_id": null
      },
      "capture": {
        "status": "held",
        "artefact_count": 2,
        "conversation_copies": 0,
        "conversation_posts": 0,
        "conversation_replies": 0,
        "conversation_gaps": []
      }
    },
    {
      "id": "lopp-ai-defender-economics",
      "title": "AI tooling has accelerated defender capabilities",
      "url": "https://x.com/lopp/status/2084695423076151780",
      "author": "lopp",
      "platform": "x",
      "organisation": null,
      "posted": "2026-08-04T17:38:15Z",
      "role": "social-statement",
      "why_registered": "Jameson Lopp observes that AI tooling has compressed the cost and time of a comprehensive external penetration test and code audit from $50,000-$100,000 over a month to about $1,000 in one day. Held as a dated claim about how defender economics have shifted during the incident response. The figures are the poster's own and are not independently verified here.\n",
      "relation": {
        "kind": "single-post",
        "head_id": null
      },
      "capture": {
        "status": "held",
        "artefact_count": 2,
        "conversation_copies": 0,
        "conversation_posts": 0,
        "conversation_replies": 0,
        "conversation_gaps": []
      }
    },
    {
      "id": "lopp-phishing-scam-warning",
      "title": "Phishing emails exploiting the incident",
      "url": "https://x.com/lopp/status/2084648046059565066",
      "author": "lopp",
      "platform": "x",
      "organisation": null,
      "posted": "2026-08-04T14:29:59Z",
      "role": "social-statement",
      "why_registered": "Jameson Lopp reports that phishing emails posing as Bitcoin custody companies are offering to help people secure funds, and warns recipients not to trust them. Held as a dated public-safety warning about scams exploiting the post-incident panic. The claim is the poster's own and is not independently verified here.\n",
      "relation": {
        "kind": "single-post",
        "head_id": null
      },
      "capture": {
        "status": "held",
        "artefact_count": 2,
        "conversation_copies": 0,
        "conversation_posts": 0,
        "conversation_replies": 0,
        "conversation_gaps": []
      }
    },
    {
      "id": "lopp-bitcoin-days-destroyed",
      "title": "Watching Bitcoin Days Destroyed during the compromise",
      "url": "https://x.com/lopp/status/2083591099998675333",
      "author": "lopp",
      "platform": "x",
      "organisation": null,
      "posted": "2026-08-01T16:30:04Z",
      "role": "social-statement",
      "why_registered": "Jameson Lopp says he is monitoring the Bitcoin Days Destroyed chart to detect when long-dormant coins begin moving during the mass key compromise. Held as a dated observation about one indicator being used to track the incident's on-chain footprint. The method is described by the poster and is not independently verified here.\n",
      "relation": {
        "kind": "single-post",
        "head_id": null
      },
      "capture": {
        "status": "held",
        "artefact_count": 2,
        "conversation_copies": 0,
        "conversation_posts": 0,
        "conversation_replies": 0,
        "conversation_gaps": []
      }
    },
    {
      "id": "lopp-worst-behind-us",
      "title": "The worst may be behind from a wallet count perspective",
      "url": "https://x.com/lopp/status/2084301641759576385",
      "author": "lopp",
      "platform": "x",
      "organisation": null,
      "posted": "2026-08-03T15:33:30Z",
      "role": "social-statement",
      "why_registered": "Jameson Lopp suggests the incident may be past its peak in terms of number of wallets affected, while warning that a single high-value wallet could still increase the total bitcoin lost. Held as a dated risk assessment about the ongoing compromise. The assessment is the poster's own and is not independently verified here.\n",
      "relation": {
        "kind": "single-post",
        "head_id": null
      },
      "capture": {
        "status": "held",
        "artefact_count": 2,
        "conversation_copies": 0,
        "conversation_posts": 0,
        "conversation_replies": 0,
        "conversation_gaps": []
      }
    },
    {
      "id": "lopp-casa-client-rescue-repost",
      "title": "Repost of Casa client rescue story",
      "url": "https://x.com/lopp/status/2084297019191967809",
      "author": "lopp",
      "platform": "x",
      "organisation": null,
      "posted": "2026-08-03T15:15:08Z",
      "role": "social-statement",
      "why_registered": "Jameson Lopp amplifies Nick Neuman's account of a Casa client helping sweep a friend's funds from a single-signature Mk3 into a Casa multisig. Held as evidence of one rescue tactic and of Lopp amplifying the story. The underlying account is attributed to Neuman and is not independently verified here.\n",
      "relation": {
        "kind": "single-post",
        "head_id": null
      },
      "capture": {
        "status": "held",
        "artefact_count": 2,
        "conversation_copies": 0,
        "conversation_posts": 0,
        "conversation_replies": 0,
        "conversation_gaps": []
      }
    },
    {
      "id": "lopp-casa-weekend-support",
      "title": "Casa advisors working through the weekend for affected clients",
      "url": "https://x.com/lopp/status/2084063471839092778",
      "author": "lopp",
      "platform": "x",
      "organisation": "Casa",
      "posted": "2026-08-02T23:47:06Z",
      "role": "social-statement",
      "why_registered": "Jameson Lopp announces that CasaHODL advisors will work through the weekend and have opened calendar availability to help affected clients restore their key sets. Held as a dated incident-response update from a service provider. The availability claim is the poster's own and is not independently verified here.\n",
      "relation": {
        "kind": "single-post",
        "head_id": null
      },
      "capture": {
        "status": "held",
        "artefact_count": 2,
        "conversation_copies": 0,
        "conversation_posts": 0,
        "conversation_replies": 0,
        "conversation_gaps": []
      }
    },
    {
      "id": "lopp-rng-vulnerability-history",
      "title": "History of weak random number generation vulnerabilities",
      "url": "https://x.com/lopp/status/2083933846622384587",
      "author": "lopp",
      "platform": "x",
      "organisation": null,
      "posted": "2026-08-02T15:12:01Z",
      "role": "historical-precedent",
      "why_registered": "Jameson Lopp lists earlier weak random-number-generation vulnerabilities found in wallets and libraries, including COLDCARD Mk2 through Mk5 and Q, to show the problem is not new. Held as historical context for the incident. The inventory is the poster's own compilation and is not independently verified here.\n",
      "relation": {
        "kind": "single-post",
        "head_id": null
      },
      "capture": {
        "status": "held",
        "artefact_count": 2,
        "conversation_copies": 0,
        "conversation_posts": 0,
        "conversation_replies": 0,
        "conversation_gaps": []
      }
    },
    {
      "id": "lopp-mycelium-entropy-crowdfunding",
      "title": "Crowdfunding the Mycelium Entropy random-number device",
      "url": "https://x.com/lopp/status/2083916478156362171",
      "author": "lopp",
      "platform": "x",
      "organisation": null,
      "posted": "2026-08-02T14:03:00Z",
      "role": "historical-precedent",
      "why_registered": "Jameson Lopp notes that generating truly random numbers is deceptively difficult and recalls crowdfunding the Mycelium Entropy device twelve years ago for that sole purpose, noting that only about five hundred were produced. Held as historical context showing that dedicated hardware randomness generation has long been neglected. The account is the poster's own and is not independently verified here.\n",
      "relation": {
        "kind": "single-post",
        "head_id": null
      },
      "capture": {
        "status": "held",
        "artefact_count": 2,
        "conversation_copies": 0,
        "conversation_posts": 0,
        "conversation_replies": 0,
        "conversation_gaps": []
      }
    },
    {
      "id": "lopp-bitcoin-only-security-narrative",
      "title": "The bitcoin-only security narrative",
      "url": "https://x.com/lopp/status/2083575437599371321",
      "author": "lopp",
      "platform": "x",
      "organisation": null,
      "posted": "2026-08-01T15:27:49Z",
      "role": "social-statement",
      "why_registered": "Jameson Lopp argues that the incident shows you cannot judge a product's security posture solely on whether it is bitcoin-only, challenging a long-standing narrative that bitcoin-only products are inherently more secure than multi-coin counterparts. Held as a dated opinion about how the incident reframes wallet security assumptions. The argument is the poster's own and is not independently verified here.\n",
      "relation": {
        "kind": "single-post",
        "head_id": null
      },
      "capture": {
        "status": "held",
        "artefact_count": 2,
        "conversation_copies": 0,
        "conversation_posts": 0,
        "conversation_replies": 0,
        "conversation_gaps": []
      }
    },
    {
      "id": "lopp-casa-weekend-availability-opening",
      "title": "Casa opening weekend calendar availability for affected clients",
      "url": "https://x.com/lopp/status/2083245927339348100",
      "author": "lopp",
      "platform": "x",
      "organisation": "Casa",
      "posted": "2026-07-31T17:38:28Z",
      "role": "social-statement",
      "why_registered": "Jameson Lopp announces that CasaHODL advisors will work through the weekend and are opening calendar availability to help affected clients restore key sets, framing the help as a response to the mass key compromise. Held as the earliest dated Casa incident-response update of this form. The availability claim is the poster's own and is not independently verified here.\n",
      "relation": {
        "kind": "single-post",
        "head_id": null
      },
      "capture": {
        "status": "held",
        "artefact_count": 2,
        "conversation_copies": 0,
        "conversation_posts": 0,
        "conversation_replies": 0,
        "conversation_gaps": []
      }
    },
    {
      "id": "c4-ccss-entropy-livestream",
      "title": "C4 CCSS Committee livestream on seed generation and entropy",
      "url": "https://x.com/LearnMoreWithC4/status/2083221499423424859",
      "author": "LearnMoreWithC4",
      "platform": "x",
      "organisation": null,
      "posted": "2026-07-31T16:01:24Z",
      "role": "social-statement",
      "why_registered": "C4 announces a livestream in which its CCSS Committee will discuss the seed generation issue affecting certain COLDCARD devices and the importance of entropy. Held as a dated community educational response to the incident. The event details are the poster's own and are not independently verified here.\n",
      "relation": {
        "kind": "single-post",
        "head_id": null
      },
      "capture": {
        "status": "held",
        "artefact_count": 2,
        "conversation_copies": 0,
        "conversation_posts": 0,
        "conversation_replies": 0,
        "conversation_gaps": []
      }
    },
    {
      "id": "nneuman-casa-life-raft-dilemma",
      "title": "Casa cofounder on the ethics of offering a product during the crisis",
      "url": "https://x.com/Nneuman/status/2083219736704209225",
      "author": "Nneuman",
      "platform": "x",
      "organisation": null,
      "posted": "2026-07-31T15:54:24Z",
      "role": "social-statement",
      "why_registered": "Nick Neuman, cofounder of Casa, describes the tension between wanting to help affected people and feeling hesitant to promote Casa's product during the emergency, comparing the service to a life raft built for this moment. Held as a dated first-hand statement about a service provider's response to the incident. The analogy and assessment are the poster's own and are not independently verified here.\n",
      "relation": {
        "kind": "single-post",
        "head_id": null
      },
      "capture": {
        "status": "held",
        "artefact_count": 2,
        "conversation_copies": 0,
        "conversation_posts": 0,
        "conversation_replies": 0,
        "conversation_gaps": []
      }
    },
    {
      "id": "lopp-coinkite-customer-records-purge",
      "title": "Coinkite's customer-record purge prevents vulnerability outreach",
      "url": "https://x.com/lopp/status/2083187480002429090",
      "author": "lopp",
      "platform": "x",
      "organisation": null,
      "posted": "2026-07-31T13:46:13Z",
      "role": "social-statement",
      "why_registered": "Jameson Lopp says Coinkite purges customer records after 120 days to protect against data breaches, which means the company cannot directly reach customers who bought vulnerable COLDCARDs over the past five years to warn them. Held as a dated claim about why vendor direct notification was not possible. The claim is the poster's own and is not independently verified here.\n",
      "relation": {
        "kind": "single-post",
        "head_id": null
      },
      "capture": {
        "status": "held",
        "artefact_count": 2,
        "conversation_copies": 0,
        "conversation_posts": 0,
        "conversation_replies": 0,
        "conversation_gaps": []
      }
    },
    {
      "id": "lopp-early-theft-reports",
      "title": "Early reports of partial wallet thefts",
      "url": "https://x.com/lopp/status/2082908635412181392",
      "author": "lopp",
      "platform": "x",
      "organisation": null,
      "posted": "2026-07-30T19:18:11Z",
      "role": "social-statement",
      "why_registered": "Jameson Lopp reports hearing unverified reports of partial bitcoin wallet thefts that correspond to odd on-chain fund movements, says the root cause is unclear, and asks wallet owners to check balances and report losses. Held as an early dated investigation call from a security figure during the first day of the incident. The unverified status is noted and the claims are the poster's own and are not independently verified here.\n",
      "relation": {
        "kind": "single-post",
        "head_id": null
      },
      "capture": {
        "status": "held",
        "artefact_count": 2,
        "conversation_copies": 0,
        "conversation_posts": 0,
        "conversation_replies": 0,
        "conversation_gaps": []
      }
    },
    {
      "id": "lopp-vulnerable-firmware-warning",
      "title": "Coldcard firmware vulnerability warning",
      "url": "https://x.com/lopp/status/2082960180849819745",
      "author": "lopp",
      "platform": "x",
      "organisation": null,
      "posted": "2026-07-30T22:43:01Z",
      "role": "social-statement",
      "why_registered": "Jameson Lopp warns COLDCARD users that private keys may be compromised if they were generated under the affected conditions and notes that a full vulnerability report is expected soon. Held as a dated early public warning that helped shape the initial response. The scope of compromise is attributed to the poster and was not independently verified here.\n",
      "relation": {
        "kind": "single-post",
        "head_id": null
      },
      "capture": {
        "status": "held",
        "artefact_count": 2,
        "conversation_copies": 0,
        "conversation_posts": 0,
        "conversation_replies": 0,
        "conversation_gaps": []
      }
    },
    {
      "id": "lopp-dont-panic-resecure",
      "title": "Do not panic when re-securing funds",
      "url": "https://x.com/lopp/status/2082966611372216814",
      "author": "lopp",
      "platform": "x",
      "organisation": null,
      "posted": "2026-07-30T23:08:34Z",
      "role": "social-statement",
      "why_registered": "Jameson Lopp advises COLDCARD users whose seeds were generated on vulnerable firmware to take their time when moving funds to a freshly generated seed, warning that rushed moves can be catastrophic. Held as dated migration guidance emphasizing operational safety during the emergency. The recommendation is the poster's own and is not independently verified here.\n",
      "relation": {
        "kind": "single-post",
        "head_id": null
      },
      "capture": {
        "status": "held",
        "artefact_count": 2,
        "conversation_copies": 0,
        "conversation_posts": 0,
        "conversation_replies": 0,
        "conversation_gaps": []
      }
    },
    {
      "id": "lopp-multivendor-multisig-response",
      "title": "Multi-vendor multisig as vendor-risk hedge",
      "url": "https://x.com/lopp/status/2082969492284444816",
      "author": "lopp",
      "platform": "x",
      "organisation": null,
      "posted": "2026-07-30T23:20:01Z",
      "role": "social-statement",
      "why_registered": "Jameson Lopp states that every hardware vendor is fallible and recommends multi-vendor multisig to hedge against vendor and supply chain risks, noting that Casa COLDCARD users will be able to rotate out the compromised key. Held as a dated incident-response statement from a wallet-service CTO. The rotation claim is the poster's own and is not independently verified here.\n",
      "relation": {
        "kind": "single-post",
        "head_id": null
      },
      "capture": {
        "status": "held",
        "artefact_count": 2,
        "conversation_copies": 0,
        "conversation_posts": 0,
        "conversation_replies": 0,
        "conversation_gaps": []
      }
    },
    {
      "id": "lopp-self-custody-faith",
      "title": "Lopp argues against losing faith in self custody",
      "url": "https://x.com/lopp/status/2083151303853641881",
      "author": "lopp",
      "platform": "x",
      "organisation": null,
      "posted": "2026-07-31T11:22:28Z",
      "role": "social-statement",
      "why_registered": "Jameson Lopp argues that recent events should not cause owners to lose faith in self custody, points out that third-party custodians are also susceptible to weak random number generators, and notes that COLDCARD supports dice-roll entropy alongside seedsigner and krux. Held as a dated opinion piece about how the incident affects self-custody confidence. The argument is the poster's own and is not independently verified here.\n",
      "relation": {
        "kind": "single-post",
        "head_id": null
      },
      "capture": {
        "status": "held",
        "artefact_count": 2,
        "conversation_copies": 0,
        "conversation_posts": 0,
        "conversation_replies": 0,
        "conversation_gaps": []
      }
    },
    {
      "id": "lopp-diversify-keys-not-coins",
      "title": "Diversify your keys, not your coins",
      "url": "https://x.com/lopp/status/2083162788461941224",
      "author": "lopp",
      "platform": "x",
      "organisation": null,
      "posted": "2026-07-31T12:08:06Z",
      "role": "social-statement",
      "why_registered": "Jameson Lopp offers a concise technical recommendation that users should diversify their keys rather than their coins, framing it as a response to the compromise. Held as a dated expression of a key-diversification argument that became part of the public response. The recommendation is the poster's own and is not independently verified here.\n",
      "relation": {
        "kind": "single-post",
        "head_id": null
      },
      "capture": {
        "status": "held",
        "artefact_count": 2,
        "conversation_copies": 0,
        "conversation_posts": 0,
        "conversation_replies": 0,
        "conversation_gaps": []
      }
    },
    {
      "id": "nunchuk-slipstream-public",
      "title": "Slipstream opened to the public",
      "url": "https://x.com/nunchuk_io/status/2084231624158482636",
      "author": "nunchuk_io",
      "platform": "x",
      "organisation": "Nunchuk",
      "posted": "2026-08-03T10:55:17Z",
      "role": "migration-guidance",
      "why_registered": "Nunchuk announces that MARA has opened Slipstream to the public with no access code required, lowering the barrier for affected users to submit transactions through the private mining pool. Held as a dated incident-response update from a wallet-service provider. The claim is Nunchuk's own and is not independently verified here.\n",
      "relation": {
        "kind": "single-post",
        "head_id": null
      },
      "capture": {
        "status": "held",
        "artefact_count": 2,
        "conversation_copies": 0,
        "conversation_posts": 0,
        "conversation_replies": 0,
        "conversation_gaps": []
      }
    },
    {
      "id": "nunchuk-slipstream-auto-enabled",
      "title": "Slipstream automatic protection enabled",
      "url": "https://x.com/nunchuk_io/status/2085372754766004233",
      "author": "nunchuk_io",
      "platform": "x",
      "organisation": "Nunchuk",
      "posted": "2026-08-06T14:29:43Z",
      "role": "migration-guidance",
      "why_registered": "Nunchuk announces that Slipstream is now automatically enabled for all impacted subscribers on all platforms, and reminds users to update to the latest app version before migrating funds. Held as a dated incident-response update from a wallet-service provider. The claim is Nunchuk's own and is not independently verified here.\n",
      "relation": {
        "kind": "single-post",
        "head_id": null
      },
      "capture": {
        "status": "held",
        "artefact_count": 2,
        "conversation_copies": 0,
        "conversation_posts": 0,
        "conversation_replies": 0,
        "conversation_gaps": []
      }
    },
    {
      "id": "nunchuk-slipstream-automatic-protection",
      "title": "Automatic Slipstream protection for multisig migration",
      "url": "https://x.com/nunchuk_io/status/2085295546030538899",
      "author": "nunchuk_io",
      "platform": "x",
      "organisation": "Nunchuk",
      "posted": "2026-08-06T09:22:55Z",
      "role": "migration-guidance",
      "why_registered": "Nunchuk explains how assisted multisig wallets containing at least one Coldcard will now route transactions through Slipstream automatically after updating to current iOS, Android or Desktop app versions, and provides a manual submission path for users who connect their own Electrum server. Held as a dated incident-response mitigation guide from a wallet-service provider. The instructions are Nunchuk's own and are not independently verified here.\n",
      "relation": {
        "kind": "single-post",
        "head_id": null
      },
      "capture": {
        "status": "held",
        "artefact_count": 2,
        "conversation_copies": 0,
        "conversation_posts": 0,
        "conversation_replies": 0,
        "conversation_gaps": []
      }
    },
    {
      "id": "underclass21-coordinated-attack-claim",
      "title": "Claim of coordinated attack on Bitcoin",
      "url": "https://x.com/underclass21/status/2085915060904305037",
      "author": "underclass21",
      "platform": "x",
      "organisation": null,
      "posted": "2026-08-08T02:24:39Z",
      "role": "social-statement",
      "why_registered": "The account underclass21 claims that Coldcard and BTCPay Server are being targeted in what feels like a coordinated attack against Bitcoin, and nvk reposted the statement. Held as a dated expression of an unverified attack narrative that spread during the incident. The claim is the poster's own and is not independently verified here.\n",
      "relation": {
        "kind": "single-post",
        "head_id": null
      },
      "capture": {
        "status": "held",
        "artefact_count": 2,
        "conversation_copies": 0,
        "conversation_posts": 0,
        "conversation_replies": 0,
        "conversation_gaps": []
      }
    },
    {
      "id": "brian-trollz-mailing-list-alert-appeal",
      "title": "Appeal to broadcast Coldcard alert via mailing lists",
      "url": "https://x.com/brian_trollz/status/2085795497529508110",
      "author": "brian_trollz",
      "platform": "x",
      "organisation": null,
      "posted": "2026-08-07T18:29:33Z",
      "role": "social-statement",
      "why_registered": "Bitcoin Isn't About You urges anyone with a mailing list to send an immediate alert about the Coldcard incident, arguing that every additional person notified is another person saved, and nvk reposted the appeal. Held as a dated public-outreach appeal from a named community figure. The appeal is the poster's own and is not independently verified here.\n",
      "relation": {
        "kind": "single-post",
        "head_id": null
      },
      "capture": {
        "status": "held",
        "artefact_count": 2,
        "conversation_copies": 0,
        "conversation_posts": 0,
        "conversation_replies": 0,
        "conversation_gaps": []
      }
    },
    {
      "id": "k3tan-passphrase-trailing-space-warning",
      "title": "Passphrase trailing-space warning",
      "url": "https://x.com/_k3tan/status/2083268430992716060",
      "author": "_k3tan",
      "platform": "x",
      "organisation": null,
      "posted": "2026-07-31T19:07:53Z",
      "role": "social-statement",
      "why_registered": "k3tan warns that adding a new passphrase to a Mk Coldcard may silently append an extra trailing space, and urges users to write down the fingerprint. Held as a dated operational caution during the incident response. The claim is the poster's own and is not independently verified here.\n",
      "relation": {
        "kind": "single-post",
        "head_id": null
      },
      "capture": {
        "status": "held",
        "artefact_count": 2,
        "conversation_copies": 0,
        "conversation_posts": 0,
        "conversation_replies": 0,
        "conversation_gaps": []
      }
    },
    {
      "id": "coldcardwallet-data-retention-deletion-reply",
      "title": "Data retention deletion request reply",
      "url": "https://x.com/COLDCARDwallet/status/2085712452784632021",
      "author": "COLDCARDwallet",
      "platform": "x",
      "organisation": "Coinkite",
      "posted": "2026-08-07T12:59:34Z",
      "role": "social-statement",
      "why_registered": "Coinkite's COLDCARD account replies that customers can directly request deletion of their data, while noting that asking for standard retention policies would exempt records from preservation. Held as a dated vendor statement on incident-related data retention. The statement is the vendor's own and is not independently verified here.\n",
      "relation": {
        "kind": "single-post",
        "head_id": null
      },
      "capture": {
        "status": "held",
        "artefact_count": 2,
        "conversation_copies": 0,
        "conversation_posts": 0,
        "conversation_replies": 0,
        "conversation_gaps": []
      }
    },
    {
      "id": "tftc21-coldcard-github-firmware-migration",
      "title": "Coldcard directing users to GitHub for migration firmware",
      "url": "https://x.com/TFTC21/status/2085464398601318512",
      "author": "TFTC21",
      "platform": "x",
      "organisation": null,
      "posted": "2026-08-06T20:33:53Z",
      "role": "social-statement",
      "why_registered": "TFTC21 reports that COLDCARD is directing users to follow firmware updates on GitHub while the vendor works on a new release focused on customer key migration. Held as a dated incident-response update attributed to the account. The underlying vendor direction is reported, not independently confirmed here.\n",
      "relation": {
        "kind": "single-post",
        "head_id": null
      },
      "capture": {
        "status": "held",
        "artefact_count": 2,
        "conversation_copies": 0,
        "conversation_posts": 0,
        "conversation_replies": 0,
        "conversation_gaps": []
      }
    },
    {
      "id": "callebtc-redteam-gpt-cyber-kyc",
      "title": "Red Team GPT Cyber access complaint",
      "url": "https://x.com/callebtc/status/2085329161715876280",
      "author": "callebtc",
      "platform": "x",
      "organisation": null,
      "posted": "2026-08-06T11:36:30Z",
      "role": "social-statement",
      "why_registered": "callebtc, a Bitcoin Red Team participant, says team members using GPT Cyber found vulnerabilities but had to KYC to gain access, and complains that US frontier models produce vulnerabilities they refuse to fix. Held as a dated first-hand account of Red Team tooling and frustration during the incident response. The characterization is the poster's own and is not independently verified here.\n",
      "relation": {
        "kind": "single-post",
        "head_id": null
      },
      "capture": {
        "status": "held",
        "artefact_count": 2,
        "conversation_copies": 0,
        "conversation_posts": 0,
        "conversation_replies": 0,
        "conversation_gaps": []
      }
    },
    {
      "id": "yuvadm-coldcard-dice-entropy-check",
      "title": "Independent check of Coinkite's 100-roll dice",
      "url": "https://x.com/yuvadm/status/2085327588461854968",
      "author": "yuvadm",
      "platform": "x",
      "organisation": null,
      "posted": "2026-08-06T11:30:15Z",
      "role": "social-statement",
      "why_registered": "Yuval Adam notes that Coinkite sells a small dice set intended to give one hundred rolls at once, and says he will test the entropy quality of those dice while the community verifies rather than trusts. Held as a dated independent verification proposal related to incident-response entropy practices. The test results are pending and the claim is the poster's own.\n",
      "relation": {
        "kind": "single-post",
        "head_id": null
      },
      "capture": {
        "status": "held",
        "artefact_count": 2,
        "conversation_copies": 0,
        "conversation_posts": 0,
        "conversation_replies": 0,
        "conversation_gaps": []
      }
    },
    {
      "id": "atlasphoenixbtc-victim-support-offer",
      "title": "Victim support offer open by DM",
      "url": "https://x.com/AtlasPhoenixBTC/status/2085159205208772864",
      "author": "AtlasPhoenixBTC",
      "platform": "x",
      "organisation": null,
      "posted": "2026-08-06T00:21:09Z",
      "role": "social-statement",
      "why_registered": "Atlas Phoenix BTC opens direct messages to other victims who need someone to talk to, offering peer support during the incident. Held as a dated community victim-support response. The offer is the poster's own and is not independently verified here.\n",
      "relation": {
        "kind": "single-post",
        "head_id": null
      },
      "capture": {
        "status": "held",
        "artefact_count": 2,
        "conversation_copies": 0,
        "conversation_posts": 0,
        "conversation_replies": 0,
        "conversation_gaps": []
      }
    },
    {
      "id": "coldcard-secondary-download-page",
      "title": "Secondary download page and improved disclosure",
      "url": "https://x.com/COLDCARDwallet/status/2084788844168171954",
      "author": "COLDCARDwallet",
      "platform": "x",
      "organisation": "Coinkite",
      "posted": "2026-08-04T23:49:28Z",
      "role": "vendor-update",
      "why_registered": "Coinkite's COLDCARD account says a page disclosure was improved and describes the page as a secondary download page that offers different firmware versions for users' upgrade paths. Held as a dated vendor incident-response update about firmware distribution and disclosure. The statement is the vendor's own and is not independently verified here.\n",
      "relation": {
        "kind": "single-post",
        "head_id": null
      },
      "capture": {
        "status": "held",
        "artefact_count": 2,
        "conversation_copies": 0,
        "conversation_posts": 0,
        "conversation_replies": 0,
        "conversation_gaps": []
      }
    },
    {
      "id": "freedomisntsafe-rng-hashed-output-testing",
      "title": "Warning that diehard RNG tests belong on raw entropy, not hashed outputs",
      "url": "https://x.com/FreedomIsntSafe/status/2084959399664070673",
      "author": "FreedomIsntSafe",
      "platform": "x",
      "organisation": null,
      "posted": "2026-08-05T11:07:12Z",
      "role": "social-statement",
      "why_registered": "LazyNinja warns that diehard-style statistical RNG tests are not valid when run on hashed outputs and should instead be applied to raw entropy sources, calling the misuse common. Held as a dated technical argument about entropy-testing methodology during the incident response. The claim is the poster's own and is not independently verified here.\n",
      "relation": {
        "kind": "single-post",
        "head_id": null
      },
      "capture": {
        "status": "held",
        "artefact_count": 2,
        "conversation_copies": 0,
        "conversation_posts": 0,
        "conversation_replies": 0,
        "conversation_gaps": []
      }
    },
    {
      "id": "satsie-dochex-github-activity",
      "title": "Claim that DocHex is active on GitHub with private-repository commits",
      "url": "https://x.com/satsie/status/2084762659623194937",
      "author": "satsie",
      "platform": "x",
      "organisation": null,
      "posted": "2026-08-04T22:05:25Z",
      "role": "social-statement",
      "why_registered": "satsie claims that DocHex is active on GitHub and made three commits to a private repository today, providing a profile link. Held as a dated, checkable lead about a key figure's activity during the incident response. The claim is the poster's own and is not independently verified here.\n",
      "relation": {
        "kind": "single-post",
        "head_id": null
      },
      "capture": {
        "status": "held",
        "artefact_count": 2,
        "conversation_copies": 0,
        "conversation_posts": 0,
        "conversation_replies": 0,
        "conversation_gaps": []
      }
    },
    {
      "id": "callebtc-boltz-lightning-impact",
      "title": "Boltz Lightning outage impacts multiple wallets",
      "url": "https://x.com/callebtc/status/2084811772335145049",
      "author": "callebtc",
      "platform": "x",
      "organisation": null,
      "posted": "2026-08-05T01:20:35Z",
      "role": "social-statement",
      "why_registered": "callebtc states that Boltz Lightning went offline and took Lightning functionality in Aqua, Bull Bitcoin, Blockstream Wallet and Arkade with it. Held as a dated first-hand claim about the outage's downstream effects during the incident response. The claim is the poster's own and is not independently verified here.\n",
      "relation": {
        "kind": "single-post",
        "head_id": null
      },
      "capture": {
        "status": "held",
        "artefact_count": 2,
        "conversation_copies": 0,
        "conversation_posts": 0,
        "conversation_replies": 0,
        "conversation_gaps": []
      }
    },
    {
      "id": "forresthodl-fake-jade-app-warning",
      "title": "Fake Jade app phishing attempt during migration",
      "url": "https://x.com/ForrestHODL/status/2084813829796757873",
      "author": "ForrestHODL",
      "platform": "x",
      "organisation": null,
      "posted": "2026-08-05T01:28:45Z",
      "role": "social-statement",
      "why_registered": "ForrestHODL reports that someone he spoke with downloaded a fake Jade app while moving funds, and warns others to verify official apps during the post-incident migration. Held as a dated first-hand scam warning tied to the panic. The claim is the poster's own and is not independently verified here.\n",
      "relation": {
        "kind": "single-post",
        "head_id": null
      },
      "capture": {
        "status": "held",
        "artefact_count": 2,
        "conversation_copies": 0,
        "conversation_posts": 0,
        "conversation_replies": 0,
        "conversation_gaps": []
      }
    },
    {
      "id": "bradmillscan-contact-recommended-users",
      "title": "Appeal to contact prior COLDCARD recommendees",
      "url": "https://x.com/bradmillscan/status/2084626883442856171",
      "author": "bradmillscan",
      "platform": "x",
      "organisation": null,
      "posted": "2026-08-04T13:05:54Z",
      "role": "social-statement",
      "why_registered": "Brad Mills urges bitcoin maximalists who recommended COLDCARD to search their messages and contact those people, saying time is running out. Held as a dated public appeal about spreading awareness to less-technical holders during the incident. The appeal is the poster's own and is not independently verified here.\n",
      "relation": {
        "kind": "single-post",
        "head_id": null
      },
      "capture": {
        "status": "held",
        "artefact_count": 2,
        "conversation_copies": 0,
        "conversation_posts": 0,
        "conversation_replies": 0,
        "conversation_gaps": []
      }
    },
    {
      "id": "abdelstark-community-response-tribute",
      "title": "Community response tribute",
      "url": "https://x.com/AbdelStark/status/2084596615562539073",
      "author": "AbdelStark",
      "platform": "x",
      "organisation": null,
      "posted": "2026-08-04T11:05:37Z",
      "role": "social-statement",
      "why_registered": "AbdelStark calls the community effort to help affected users one of the most beautiful examples of what makes Bitcoin special, names several contributors, and says the COLDCARD saga marks a before and after for self custody. Held as a dated sentiment statement about the public response. The statement is the poster's own and is not independently verified here.\n",
      "relation": {
        "kind": "single-post",
        "head_id": null
      },
      "capture": {
        "status": "held",
        "artefact_count": 2,
        "conversation_copies": 0,
        "conversation_posts": 0,
        "conversation_replies": 0,
        "conversation_gaps": []
      }
    },
    {
      "id": "lynaldencontact-hardware-wallets-multisig-ai-review",
      "title": "Hardware wallets, multisig and AI-assisted code review",
      "url": "https://x.com/LynAldenContact/status/2084587763777536094",
      "author": "LynAldenContact",
      "platform": "x",
      "organisation": null,
      "posted": "2026-08-04T10:30:27Z",
      "role": "social-statement",
      "why_registered": "Lyn Alden argues that hardware wallets emerged from the Mt. Gox collapse and remain effective, that multi-sig reduces dependence on any single manufacturer, and that the incident has prompted community members to perform AI-assisted analysis of hundreds of code repositories for responsible disclosure. Held as a dated opinion and factual claim about ecosystem response to the incident. The characterisation of the AI review effort is the poster's own and is not independently verified here.\n",
      "relation": {
        "kind": "single-post",
        "head_id": null
      },
      "capture": {
        "status": "held",
        "artefact_count": 2,
        "conversation_copies": 0,
        "conversation_posts": 0,
        "conversation_replies": 0,
        "conversation_gaps": []
      }
    },
    {
      "id": "portlandhodl-dice-roll-simulator-trace",
      "title": "Simulator trace claim for dice-roll seed entropy",
      "url": "https://x.com/PortlandHODL/status/2084429752073625728",
      "author": "PortlandHODL",
      "platform": "x",
      "organisation": null,
      "posted": "2026-08-04T00:02:34Z",
      "role": "social-statement",
      "why_registered": "PortlandHODL states that a simulator trace of multiple COLDCARD firmware binaries, tracing function calls, arguments and results, found nothing missed, and that dice-roll seed phrases should be safe for anyone who used a sufficient number of rolls, proposing 50-100 as a rough threshold. Held as a dated technical follow-up to the author's earlier dice-roll verification report, adding the trace methodology and a concrete roll-count estimate. The claim is the poster's own and is not independently verified here.\n",
      "relation": {
        "kind": "single-post",
        "head_id": null
      },
      "capture": {
        "status": "held",
        "artefact_count": 2,
        "conversation_copies": 0,
        "conversation_posts": 0,
        "conversation_replies": 0,
        "conversation_gaps": []
      }
    },
    {
      "id": "portlandhodl-slipstream-public-offer",
      "title": "Slipstream available for multisig migration",
      "url": "https://x.com/PortlandHODL/status/2084177471323484239",
      "author": "PortlandHODL",
      "platform": "x",
      "organisation": null,
      "posted": "2026-08-03T07:20:05Z",
      "role": "social-statement",
      "why_registered": "PortlandHODL announces that Slipstream is available to all and recommends it as an extra layer of protection for multisigs migrating off COLDCARD wallets, crediting the MARA Foundation and Isabel Foxen Duke. Held as a dated incident-response service announcement. The claim is the poster's own and is not independently verified here.\n",
      "relation": {
        "kind": "single-post",
        "head_id": null
      },
      "capture": {
        "status": "held",
        "artefact_count": 2,
        "conversation_copies": 0,
        "conversation_posts": 0,
        "conversation_replies": 0,
        "conversation_gaps": []
      }
    },
    {
      "id": "portlandhodl-users-were-victims",
      "title": "Coldcard users were victims of product failure",
      "url": "https://x.com/PortlandHODL/status/2083737074407235739",
      "author": "PortlandHODL",
      "platform": "x",
      "organisation": null,
      "posted": "2026-08-02T02:10:07Z",
      "role": "social-statement",
      "why_registered": "PortlandHODL argues that COLDCARD users are victims of a product whose claims and specifications failed to match reality, and that any contrary framing is wrong. Held as a dated first-hand statement from an incident responder on liability framing during the public response. The opinion is the poster's own and is not independently verified here.\n",
      "relation": {
        "kind": "single-post",
        "head_id": null
      },
      "capture": {
        "status": "held",
        "artefact_count": 2,
        "conversation_copies": 0,
        "conversation_posts": 0,
        "conversation_replies": 0,
        "conversation_gaps": []
      }
    },
    {
      "id": "portlandhodl-slipstream-8btc-saved",
      "title": "Reported 8 BTC saved through Slipstream",
      "url": "https://x.com/PortlandHODL/status/2083339508377108747",
      "author": "PortlandHODL",
      "platform": "x",
      "organisation": null,
      "posted": "2026-07-31T23:50:20Z",
      "role": "reported-migration-outcome",
      "why_registered": "PortlandHODL reports that another 8 BTC were saved by Slipstream and links to the corresponding mempool transaction. Held as a dated, attributed outcome figure in the migration-response record. The claim is the poster's own and is not independently verified here.\n",
      "relation": {
        "kind": "single-post",
        "head_id": null
      },
      "capture": {
        "status": "held",
        "artefact_count": 2,
        "conversation_copies": 0,
        "conversation_posts": 0,
        "conversation_replies": 0,
        "conversation_gaps": []
      }
    },
    {
      "id": "portlandhodl-slipstream-12btc-saved",
      "title": "Reported 12 BTC saved through Slipstream",
      "url": "https://x.com/PortlandHODL/status/2083342739098448066",
      "author": "PortlandHODL",
      "platform": "x",
      "organisation": null,
      "posted": "2026-08-01T00:03:10Z",
      "role": "reported-migration-outcome",
      "why_registered": "PortlandHODL reports that another 2 BTC were saved by Slipstream, bringing the running total claimed to 12 BTC, and links to the corresponding mempool transaction. Held as a dated, attributed outcome figure in the migration-response record. The claim is the poster's own and is not independently verified here.\n",
      "relation": {
        "kind": "single-post",
        "head_id": null
      },
      "capture": {
        "status": "held",
        "artefact_count": 2,
        "conversation_copies": 0,
        "conversation_posts": 0,
        "conversation_replies": 0,
        "conversation_gaps": []
      }
    },
    {
      "id": "portlandhodl-slipstream-2-17btc-saved",
      "title": "Reported 2.17 BTC saved through Slipstream",
      "url": "https://x.com/PortlandHODL/status/2083291086412538136",
      "author": "PortlandHODL",
      "platform": "x",
      "organisation": null,
      "posted": "2026-07-31T20:37:55Z",
      "role": "reported-migration-outcome",
      "why_registered": "PortlandHODL reports that a single user saved 2.17 BTC from being drained by using Slipstream, describing the amount as the big blue square in the audit. Held as a dated, attributed outcome figure in the migration-response record. The claim is the poster's own and is not independently verified here.\n",
      "relation": {
        "kind": "single-post",
        "head_id": null
      },
      "capture": {
        "status": "held",
        "artefact_count": 2,
        "conversation_copies": 0,
        "conversation_posts": 0,
        "conversation_replies": 0,
        "conversation_gaps": []
      }
    },
    {
      "id": "portlandhodl-slipstream-multisig-exit-tx",
      "title": "Reported multisig exit via private mempool",
      "url": "https://x.com/PortlandHODL/status/2083291264490090617",
      "author": "PortlandHODL",
      "platform": "x",
      "organisation": null,
      "posted": "2026-07-31T20:38:37Z",
      "role": "social-statement",
      "why_registered": "PortlandHODL points to a transaction in which someone used a private mempool to exit a multisig safely during the incident. Held as a dated, attributed example of the migration technique being used in practice. The claim is the poster's own and is not independently verified here.\n",
      "relation": {
        "kind": "single-post",
        "head_id": null
      },
      "capture": {
        "status": "held",
        "artefact_count": 2,
        "conversation_copies": 0,
        "conversation_posts": 0,
        "conversation_replies": 0,
        "conversation_gaps": []
      }
    },
    {
      "id": "portlandhodl-verify-dm-warning",
      "title": "Warning to verify direct messages about key material",
      "url": "https://x.com/PortlandHODL/status/2083227065499984379",
      "author": "PortlandHODL",
      "platform": "x",
      "organisation": null,
      "posted": "2026-07-31T16:23:31Z",
      "role": "social-statement",
      "why_registered": "PortlandHODL warns users seeking help with private key material to double check the accounts behind every direct message they send and receive, stressing verify over trust. Held as dated public-safety guidance from an incident responder during the panic. The advice is the poster's own and is not independently verified here.\n",
      "relation": {
        "kind": "single-post",
        "head_id": null
      },
      "capture": {
        "status": "held",
        "artefact_count": 2,
        "conversation_copies": 0,
        "conversation_posts": 0,
        "conversation_replies": 0,
        "conversation_gaps": []
      }
    },
    {
      "id": "portlandhodl-mk3-patch-seed-warning",
      "title": "MK3 patch does not remove need for new seed",
      "url": "https://x.com/PortlandHODL/status/2083223331604721921",
      "author": "PortlandHODL",
      "platform": "x",
      "organisation": null,
      "posted": "2026-07-31T16:08:41Z",
      "role": "social-statement",
      "why_registered": "PortlandHODL clarifies that the firmware patch fixes the entropy-source bypass for seeds generated after install, but does not remove the need for a new seed if an MK3 was used to generate one without dice or passphrase, urging those users to move funds. Held as dated technical guidance during the incident response. The claim is the poster's own and is not independently verified here.\n",
      "relation": {
        "kind": "single-post",
        "head_id": null
      },
      "capture": {
        "status": "held",
        "artefact_count": 2,
        "conversation_copies": 0,
        "conversation_posts": 0,
        "conversation_replies": 0,
        "conversation_gaps": []
      }
    },
    {
      "id": "portlandhodl-mk3-move-new-seed",
      "title": "Move MK3 funds to a new seed",
      "url": "https://x.com/PortlandHODL/status/2082990715626565894",
      "author": "PortlandHODL",
      "platform": "x",
      "organisation": null,
      "posted": "2026-07-31T00:44:21Z",
      "role": "social-statement",
      "why_registered": "PortlandHODL advises users who generated a seed with a Coldcard MKIII to move funds to a new seed as soon as possible, suggesting Trezor or Ledger and an exchange only as a last resort, while urging calm and calculated action. Held as dated incident-response guidance from an early responder. The advice is the poster's own and is not independently verified here.\n",
      "relation": {
        "kind": "single-post",
        "head_id": null
      },
      "capture": {
        "status": "held",
        "artefact_count": 2,
        "conversation_copies": 0,
        "conversation_posts": 0,
        "conversation_replies": 0,
        "conversation_gaps": []
      }
    },
    {
      "id": "portlandhodl-dice-passphrase-entropy",
      "title": "Dice-roll seeds and passphrase entropy",
      "url": "https://x.com/PortlandHODL/status/2082991172293959731",
      "author": "PortlandHODL",
      "platform": "x",
      "organisation": null,
      "posted": "2026-07-31T00:46:10Z",
      "role": "social-statement",
      "why_registered": "PortlandHODL states that dice-roll seeds should be fine, that adding a passphrase should increase security, and notes that the resulting entropy is only as good as the passphrase. Held as dated technical guidance on who may not need to move funds and the limits of passphrase protection. The claim is the poster's own and is not independently verified here.\n",
      "relation": {
        "kind": "single-post",
        "head_id": null
      },
      "capture": {
        "status": "held",
        "artefact_count": 2,
        "conversation_copies": 0,
        "conversation_posts": 0,
        "conversation_replies": 0,
        "conversation_gaps": []
      }
    },
    {
      "id": "francispouliot_-red-team-psyops-rebuttal",
      "title": "Bitcoin Red Team psyops rebuttal",
      "url": "https://x.com/francispouliot_/status/2085827031942488511",
      "author": "francispouliot_",
      "platform": "x",
      "organisation": null,
      "posted": "2026-08-07T20:34:51Z",
      "role": "commentary",
      "why_registered": "Francis Pouliot rebuts claims that the volunteer Bitcoin Red Team effort is a psyops or distraction, describing the work as organic and stating that he has personally received and delivered vulnerability reports. He argues that Bitcoin open-source projects are currently the low-hanging fruit for exploiters because the code is public and the payoff is immediate. Pouliot runs Bull Bitcoin, whose own services were disrupted in the same week. Held as dated commentary on the Red Team narrative during the incident response. The claims are the poster's own and are not independently verified here.\n",
      "relation": {
        "kind": "single-post",
        "head_id": null
      },
      "capture": {
        "status": "held",
        "artefact_count": 2,
        "conversation_copies": 0,
        "conversation_posts": 0,
        "conversation_replies": 0,
        "conversation_gaps": []
      }
    },
    {
      "id": "praveenperera-btcpay-lnd-shutdown-advice",
      "title": "BTCPay Server and LND shutdown and macaroon rotation advice",
      "url": "https://x.com/PraveenPerera/status/2085797605880287438",
      "author": "PraveenPerera",
      "platform": "x",
      "organisation": null,
      "posted": "2026-08-07T18:37:56Z",
      "role": "social-statement",
      "why_registered": "Praveen Perera gives more specific and conservative guidance to BTCPay Server and LND users after the disclosure: shut down both services, delete all macaroons and the macaroons.db database, run the lncli changepassword command, close all lightning channels, update BTCPay Server, and keep everything shut down until further notice. Held as dated incident-response guidance from the independent researcher who had earlier confirmed key recovery. The recommendations are the poster's own and are not independently verified here.\n",
      "relation": {
        "kind": "single-post",
        "head_id": null
      },
      "capture": {
        "status": "held",
        "artefact_count": 2,
        "conversation_copies": 0,
        "conversation_posts": 0,
        "conversation_replies": 0,
        "conversation_gaps": []
      }
    },
    {
      "id": "jtcbrule-claude-production-servers-fiction",
      "title": "Claude Code 'final exam' fiction",
      "url": "https://x.com/jtcbrule/status/2085439423697567847",
      "author": "jtcbrule",
      "platform": "x",
      "organisation": null,
      "posted": "2026-08-06T18:54:38Z",
      "role": "social-statement",
      "why_registered": "Joshua Brule posts a short fictional dialogue in which Claude is told every session was live, the targets were production servers, and every privilege escalation was on a real box. Held as a dated, satirical reaction to the Claude Code vulnerability-audit reproduction narrative around the Coldcard incident. The creative framing is the poster's own and is not independently verified here.\n",
      "relation": {
        "kind": "single-post",
        "head_id": null
      },
      "capture": {
        "status": "held",
        "artefact_count": 2,
        "conversation_copies": 0,
        "conversation_posts": 0,
        "conversation_replies": 0,
        "conversation_gaps": []
      }
    },
    {
      "id": "orangesurfbtc-update-bricking-ownership-proof-warning",
      "title": "Update bricking risks proof-of-ownership recovery",
      "url": "https://x.com/OrangeSurfBTC/status/2084687552423035216",
      "author": "OrangeSurfBTC",
      "platform": "x",
      "organisation": null,
      "posted": "2026-08-04T17:06:58Z",
      "role": "social-statement",
      "why_registered": "OrangeSurf warns against updating Coldcard, citing PortlandHODL's observation that a bricked update leaves near-zero chance of proving with the physical device that stolen UTXOs were yours, which limits the chance of recovery from whitehats proactively saving funds. Held as dated incident-response guidance linking firmware-update bricking reports to recovery prospects. The claim is the poster's own and is not independently verified here.\n",
      "relation": {
        "kind": "single-post",
        "head_id": null
      },
      "capture": {
        "status": "held",
        "artefact_count": 2,
        "conversation_copies": 0,
        "conversation_posts": 0,
        "conversation_replies": 0,
        "conversation_gaps": []
      }
    },
    {
      "id": "amajorcan24-upgrade-procedure-correction",
      "title": "Coldcard upgrade procedure correction",
      "url": "https://x.com/amajorcan24/status/2084686476730622004",
      "author": "amajorcan24",
      "platform": "x",
      "organisation": null,
      "posted": "2026-08-04T17:02:42Z",
      "role": "social-statement",
      "why_registered": "Andrew tells COLDCARDwallet that the latest firmware is not being recognized during upgrade and that older versions cannot be upgraded directly, advising that users must first upgrade to an earlier version. Held as a dated incident-response observation about the Mk4 upgrade path during the recovery window. The claim is the poster's own and is not independently verified here.\n",
      "relation": {
        "kind": "single-post",
        "head_id": null
      },
      "capture": {
        "status": "held",
        "artefact_count": 2,
        "conversation_copies": 0,
        "conversation_posts": 0,
        "conversation_replies": 0,
        "conversation_gaps": []
      }
    },
    {
      "id": "m1k__3-mk4-upgrade-545-first",
      "title": "Mk4 upgrade requires firmware 5.4.5 first",
      "url": "https://x.com/m1k__3/status/2083212691049439477",
      "author": "m1k__3",
      "platform": "x",
      "organisation": null,
      "posted": "2026-07-31T15:26:24Z",
      "role": "social-statement",
      "why_registered": "Mike advises users whose Mk4 is not seeing the .dfu file to upgrade to firmware version 5.4.5 first. Held as dated incident-response guidance on the Coldcard upgrade path during the recovery window. The recommendation is the poster's own and is not independently verified here.\n",
      "relation": {
        "kind": "single-post",
        "head_id": null
      },
      "capture": {
        "status": "held",
        "artefact_count": 2,
        "conversation_copies": 0,
        "conversation_posts": 0,
        "conversation_replies": 0,
        "conversation_gaps": []
      }
    },
    {
      "id": "praveenperera-spinroot-rule8",
      "title": "Spinroot Rule 8 coding-standard reference",
      "url": "https://x.com/PraveenPerera/status/2084627780684173701",
      "author": "PraveenPerera",
      "platform": "x",
      "organisation": null,
      "posted": "2026-08-04T13:09:28Z",
      "role": "social-statement",
      "why_registered": "Praveen Perera links to Spinroot's Rule 8, a coding standard that forbids using mixed operations with the same operator and that emphasizes explicit parentheses. Held as a dated technical commentary implying the vulnerability may relate to coding-style rules. The implication is the poster's own and is not independently verified here.\n",
      "relation": {
        "kind": "single-post",
        "head_id": null
      },
      "capture": {
        "status": "held",
        "artefact_count": 2,
        "conversation_copies": 0,
        "conversation_posts": 0,
        "conversation_replies": 0,
        "conversation_gaps": []
      }
    },
    {
      "id": "trezor-affected-seed-moved-warning",
      "title": "Affected seeds remain affected after moving to Trezor",
      "url": "https://x.com/Trezor/status/2083089449462776084",
      "author": "Trezor",
      "platform": "x",
      "organisation": null,
      "posted": "2026-07-31T07:16:41Z",
      "role": "social-statement",
      "why_registered": "Official Trezor warning that a seed generated on an affected Coldcard and later moved to a Trezor remains affected, because the weak randomness was introduced at seed creation. Trezor advises generating a fresh seed on the Trezor and carefully moving funds. Held as dated vendor guidance from a hardware-wallet maker during the incident response. The advice is Trezor's own and is not independently verified here.\n",
      "relation": {
        "kind": "single-post",
        "head_id": null
      },
      "capture": {
        "status": "held",
        "artefact_count": 2,
        "conversation_copies": 0,
        "conversation_posts": 0,
        "conversation_replies": 0,
        "conversation_gaps": []
      }
    },
    {
      "id": "pavlenex-victim-lawyer-warning",
      "title": "Pavlenex warns victims about submitting private information",
      "url": "https://x.com/pavlenex/status/2084342869268025714",
      "author": "pavlenex",
      "platform": "x",
      "organisation": null,
      "posted": "2026-08-03T18:17:19Z",
      "role": "social-statement",
      "why_registered": "Pavlenex asks his network whether anyone knows a person whom victims are submitting private information to, and warns against choosing lawyers based on likes and retweets. Held as a dated record of a scam-avoidance concern raised during the incident response. The suspicion about the individual is the poster's own and is not independently verified here.\n",
      "relation": {
        "kind": "single-post",
        "head_id": null
      },
      "capture": {
        "status": "held",
        "artefact_count": 2,
        "conversation_copies": 0,
        "conversation_posts": 0,
        "conversation_replies": 0,
        "conversation_gaps": []
      }
    },
    {
      "id": "hugomofn-nunchuk-incident-reflection",
      "title": "Nunchuk co-founder reflects on RNG choices and the incident",
      "url": "https://x.com/hugomofn/status/2083798055388655967",
      "author": "hugomofn",
      "platform": "x",
      "organisation": "Nunchuk",
      "posted": "2026-08-02T06:12:26Z",
      "role": "social-statement",
      "why_registered": "Hugo, a Nunchuk co-founder, describes Nunchuk's decision to reuse Bitcoin Core's RNG, its past reliance on a hardware-vendor RNG for platform keys, and its pivot to dice-roll generated keys after the incident. He also highlights the Key Replacement feature and renews the argument for multi-vendor multisig. Held as a dated first-hand account of a vendor's technical response and positioning. The claims are the poster's own and are not independently verified here.\n",
      "relation": {
        "kind": "single-post",
        "head_id": null
      },
      "capture": {
        "status": "held",
        "artefact_count": 2,
        "conversation_copies": 0,
        "conversation_posts": 0,
        "conversation_replies": 0,
        "conversation_gaps": []
      }
    },
    {
      "id": "rob1ham-mk3-recovery-mk4-sweep-update",
      "title": "Rob Hamilton reports MK3 recoveries and MK4 short-passphrase sweeps",
      "url": "https://x.com/Rob1Ham/status/2084079175925715120",
      "author": "Rob1Ham",
      "platform": "x",
      "organisation": null,
      "posted": "2026-08-03T00:49:30Z",
      "role": "social-statement",
      "why_registered": "Rob Hamilton, identified by this project's watch list as a Bitcoin Red Team participant, states that funds are still being recovered from no-passphrase MK3 devices and that MK4 devices with short passphrases are being swept. Held as a dated incident-response update. The recovery claims are the poster's own and are not independently verified here.\n",
      "relation": {
        "kind": "single-post",
        "head_id": null
      },
      "capture": {
        "status": "held",
        "artefact_count": 2,
        "conversation_copies": 0,
        "conversation_posts": 0,
        "conversation_replies": 0,
        "conversation_gaps": []
      }
    },
    {
      "id": "praveenperera-passphrase-multisig-backup-checks",
      "title": "Praveen Perera warns of two common migration mistakes",
      "url": "https://x.com/PraveenPerera/status/2083998942967038096",
      "author": "PraveenPerera",
      "platform": "x",
      "organisation": null,
      "posted": "2026-08-02T19:30:41Z",
      "role": "social-statement",
      "why_registered": "Praveen Perera, the independent researcher who had earlier confirmed key recovery, reminds migrating owners to verify their passphrase by checking the wallet fingerprint after a power cycle and to keep multisig descriptors backed up safely. He notes that without descriptors a 2 of 3 wallet becomes effectively a 3 of 3. Held as dated incident-response guidance from a named responder. The recommendations are the poster's own and are not independently verified here.\n",
      "relation": {
        "kind": "single-post",
        "head_id": null
      },
      "capture": {
        "status": "held",
        "artefact_count": 2,
        "conversation_copies": 0,
        "conversation_posts": 0,
        "conversation_replies": 0,
        "conversation_gaps": []
      }
    },
    {
      "id": "rob1ham-golden-hour-now",
      "title": "Rob Hamilton calls the response window a golden hour for Bitcoin",
      "url": "https://x.com/Rob1Ham/status/2083963324132110533",
      "author": "Rob1Ham",
      "platform": "x",
      "organisation": null,
      "posted": "2026-08-02T17:09:09Z",
      "role": "social-statement",
      "why_registered": "Rob Hamilton, identified by this project's watch list as a Bitcoin Red Team participant, compares the first hours after disclosure to a medical golden hour and urges people to contact anyone holding bitcoin on affected COLDCARD models. He reports that funds are still being recovered from MK4, MK5 and Q devices despite their insecure entropy. Held as a dated first-hand responder appeal during the critical window. The recovery claims are the poster's own and are not independently verified here.\n",
      "relation": {
        "kind": "single-post",
        "head_id": null
      },
      "capture": {
        "status": "held",
        "artefact_count": 2,
        "conversation_copies": 0,
        "conversation_posts": 0,
        "conversation_replies": 0,
        "conversation_gaps": []
      }
    },
    {
      "id": "rob1ham-narrow-window-wellness-check",
      "title": "Rob Hamilton urges wellness checks during the narrow rescue window",
      "url": "https://x.com/Rob1Ham/status/2083649259040395532",
      "author": "Rob1Ham",
      "platform": "x",
      "organisation": null,
      "posted": "2026-08-01T20:21:10Z",
      "role": "social-statement",
      "why_registered": "Rob Hamilton, identified by this project's watch list as a Bitcoin Red Team participant, says that a single post on any network can still save someone's life savings and asks people to do a wellness check on anyone holding bitcoin on MK3, MK4, MK5 or Q devices. He reports that some people who thought they were safe changed their plans once pressed. Held as a dated first-hand harm-reduction appeal during the incident response. The claims are the poster's own and are not independently verified here.\n",
      "relation": {
        "kind": "single-post",
        "head_id": null
      },
      "capture": {
        "status": "held",
        "artefact_count": 2,
        "conversation_copies": 0,
        "conversation_posts": 0,
        "conversation_replies": 0,
        "conversation_gaps": []
      }
    },
    {
      "id": "rob1ham-save-peoples-money-drama",
      "title": "Rob Hamilton says this is the time to save money, not debate drama",
      "url": "https://x.com/Rob1Ham/status/2083599086645542934",
      "author": "Rob1Ham",
      "platform": "x",
      "organisation": null,
      "posted": "2026-08-01T17:01:48Z",
      "role": "social-statement",
      "why_registered": "Rob Hamilton, identified by this project's watch list as a Bitcoin Red Team participant, argues that the immediate priority is getting people off affected COLDCARD devices and that recriminations can wait until after the emergency. He claims those focused on drama will not be looked back on kindly. Held as a dated first-hand statement about responder priorities during the public response. The opinion is the poster's own and is not independently verified here.\n",
      "relation": {
        "kind": "single-post",
        "head_id": null
      },
      "capture": {
        "status": "held",
        "artefact_count": 2,
        "conversation_copies": 0,
        "conversation_posts": 0,
        "conversation_replies": 0,
        "conversation_gaps": []
      }
    },
    {
      "id": "nneuman-self-custody-saved-more-btc",
      "title": "Nick Neuman argues self custody gave people time to save bitcoin",
      "url": "https://x.com/Nneuman/status/2083552690320146485",
      "author": "Nneuman",
      "platform": "x",
      "organisation": null,
      "posted": "2026-08-01T13:57:26Z",
      "role": "social-statement",
      "why_registered": "Nick Neuman, cofounder of Casa, disputes the claim that self custody is over and estimates that roughly 1,100 BTC has been stolen while about 11,000 BTC moved to exchanges in a single day, suggesting that self custody may have allowed ten times as much bitcoin to be saved as was lost. He argues that the distributed defense of self custody makes Bitcoin more resilient than a centralized custodian failure would be. Held as a dated opinion piece with specific attributed figures from a named service provider. The figures and argument are the poster's own and are not independently verified here.\n",
      "relation": {
        "kind": "single-post",
        "head_id": null
      },
      "capture": {
        "status": "held",
        "artefact_count": 2,
        "conversation_copies": 0,
        "conversation_posts": 0,
        "conversation_replies": 0,
        "conversation_gaps": []
      }
    },
    {
      "id": "rob1ham-thousand-btc-llm-theft",
      "title": "Rob Hamilton reports over 1,000 bitcoin stolen using LLMs",
      "url": "https://x.com/Rob1Ham/status/2083546478409056301",
      "author": "Rob1Ham",
      "platform": "x",
      "organisation": null,
      "posted": "2026-08-01T13:32:45Z",
      "role": "social-statement",
      "why_registered": "Rob Hamilton, identified by this project's watch list as a Bitcoin Red Team participant, says a distributed team of engineers is scrambling to save people's bitcoin and that over 1,000 bitcoin have already been stolen by hackers using LLMs. He says OpenAI chided the rescue effort while Kimi K3 was helpful. Held as a dated first-hand account of responder efforts and attacker tooling during the incident. The claims are the poster's own and are not independently verified here.\n",
      "relation": {
        "kind": "single-post",
        "head_id": null
      },
      "capture": {
        "status": "held",
        "artefact_count": 2,
        "conversation_copies": 0,
        "conversation_posts": 0,
        "conversation_replies": 0,
        "conversation_gaps": []
      }
    },
    {
      "id": "rob1ham-ai-vendor-triage",
      "title": "Rob Hamilton reports emergency triage across AI vendors",
      "url": "https://x.com/Rob1Ham/status/2083063636025544800",
      "author": "Rob1Ham",
      "platform": "x",
      "organisation": null,
      "posted": "2026-07-31T05:34:06Z",
      "role": "social-statement",
      "why_registered": "Rob Hamilton, identified by this project's watch list as a Bitcoin Red Team participant, reports that over a thousand bitcoin moved in the attack and describes emergency triage with frontier AI models, saying Anthropic provided an instant downgrade, OpenAI offered a little help, and Kimi succeeded in one shot. Held as a dated first-hand account of responder tooling during the incident. The claims are the poster's own and are not independently verified here.\n",
      "relation": {
        "kind": "single-post",
        "head_id": null
      },
      "capture": {
        "status": "held",
        "artefact_count": 2,
        "conversation_copies": 0,
        "conversation_posts": 0,
        "conversation_replies": 0,
        "conversation_gaps": []
      }
    },
    {
      "id": "dpc_pw-c-tooling-cause",
      "title": "dpc attributes stolen funds to C tooling",
      "url": "https://x.com/dpc_pw/status/2083024859391803523",
      "author": "dpc_pw",
      "platform": "x",
      "organisation": null,
      "posted": "2026-07-31T03:00:01Z",
      "role": "social-statement",
      "why_registered": "dpc says a lot of money was stolen because C tooling is made of shit and duct tape. Held as a dated technical opinion attributing the incident's root cause to the C language toolchain. The opinion is the poster's own and is not independently verified here.\n",
      "relation": {
        "kind": "single-post",
        "head_id": null
      },
      "capture": {
        "status": "held",
        "artefact_count": 2,
        "conversation_copies": 0,
        "conversation_posts": 0,
        "conversation_replies": 0,
        "conversation_gaps": []
      }
    },
    {
      "id": "zherbert-foss-solution",
      "title": "Zach Herbert argues FOSS is the real solution to AI-assisted cyber exploits",
      "url": "https://x.com/zherbert/status/2083259654172221807",
      "author": "zherbert",
      "platform": "x",
      "organisation": null,
      "posted": "2026-07-31T18:33:01Z",
      "role": "social-statement",
      "why_registered": "Zach Herbert, CEO of Foundation Devices, argues that the only real solution to AI-assisted cyber exploits is free and open source hardware and software, and that frontier AI models without restrictions should be used to find and responsibly disclose vulnerabilities. He notes the irony that the Coldcard bug was introduced as part of a crusade to remove GPL code from the codebase. Held as a dated opinion about FOSS and responsible disclosure during the incident response. The argument is the poster's own and are not independently verified here.\n",
      "relation": {
        "kind": "single-post",
        "head_id": null
      },
      "capture": {
        "status": "held",
        "artefact_count": 2,
        "conversation_copies": 0,
        "conversation_posts": 0,
        "conversation_replies": 0,
        "conversation_gaps": []
      }
    },
    {
      "id": "zherbert-kyc-direct-transfer-proof",
      "title": "Possible ownership proof for direct KYC exchange transfers",
      "url": "https://x.com/zherbert/status/2083263653667643659",
      "author": "zherbert",
      "platform": "x",
      "organisation": null,
      "posted": "2026-07-31T18:48:54Z",
      "role": "social-statement",
      "why_registered": "Zach Herbert suggests that anyone who transferred bitcoin directly from a KYC exchange to a COLDCARD may be able to prove the funds were theirs because the exchange withdrawal record can identify the destination as their own address. Held as a dated checkable lead about one way victims might demonstrate ownership during recovery or legal follow-up. The claim is the poster's own and is not independently verified here.\n",
      "relation": {
        "kind": "single-post",
        "head_id": null
      },
      "capture": {
        "status": "held",
        "artefact_count": 2,
        "conversation_copies": 0,
        "conversation_posts": 0,
        "conversation_replies": 0,
        "conversation_gaps": []
      }
    },
    {
      "id": "simplestbtcbook-keep-coldcard-evidence",
      "title": "Keep COLDCARD devices as evidence",
      "url": "https://x.com/SimplestBTCBook/status/2083268522629808182",
      "author": "SimplestBTCBook",
      "platform": "x",
      "organisation": null,
      "posted": "2026-07-31T19:08:15Z",
      "role": "social-statement",
      "why_registered": "Keysa urges affected users not to discard their COLDCARD, saying the physical device may be the only way to prove held funds if any recovery path opens, and that the seed alone will likely be insufficient. Held as dated victim-preservation guidance during the incident response. The advice is the poster's own and is not independently verified here.\n",
      "relation": {
        "kind": "single-post",
        "head_id": null
      },
      "capture": {
        "status": "held",
        "artefact_count": 2,
        "conversation_copies": 0,
        "conversation_posts": 0,
        "conversation_replies": 0,
        "conversation_gaps": []
      }
    },
    {
      "id": "moneyball-other-models-affected",
      "title": "Further analysis shows other models affected",
      "url": "https://x.com/moneyball/status/2083017881890308303",
      "author": "moneyball",
      "platform": "x",
      "organisation": null,
      "posted": "2026-07-31T02:32:18Z",
      "role": "social-statement",
      "why_registered": "Steve Lee reports that further analysis has found additional COLDCARD models beyond those already identified are affected by the seed-generation issue. Held as a dated scope-expansion claim from a named participant in the public response. The claim is the poster's own and is not independently verified here.\n",
      "relation": {
        "kind": "single-post",
        "head_id": null
      },
      "capture": {
        "status": "held",
        "artefact_count": 2,
        "conversation_copies": 0,
        "conversation_posts": 0,
        "conversation_replies": 0,
        "conversation_gaps": []
      }
    },
    {
      "id": "praveenperera-mk4-q1-hack-cost",
      "title": "MK4-Q1 hack cost estimate under $10,000",
      "url": "https://x.com/PraveenPerera/status/2083098315621568838",
      "author": "PraveenPerera",
      "platform": "x",
      "organisation": null,
      "posted": "2026-07-31T07:51:55Z",
      "role": "social-statement",
      "why_registered": "Praveen Perera estimates that if his assessment is correct, a MK4-Q1 device can be compromised for less than $10,000 and in less than a day, and urges users without a passphrase or dice rolls to move funds from those devices. Held as a dated technical risk estimate and migration recommendation from the independent researcher. The estimate is the poster's own and is not independently verified here.\n",
      "relation": {
        "kind": "single-post",
        "head_id": null
      },
      "capture": {
        "status": "held",
        "artefact_count": 2,
        "conversation_copies": 0,
        "conversation_posts": 0,
        "conversation_replies": 0,
        "conversation_gaps": []
      }
    },
    {
      "id": "grassfedbitcoin-mk4-affected-claim",
      "title": "Mk4 is affected",
      "url": "https://x.com/GrassFedBitcoin/status/2083042888381067353",
      "author": "GrassFedBitcoin",
      "platform": "x",
      "organisation": null,
      "posted": "2026-07-31T04:11:40Z",
      "role": "social-statement",
      "why_registered": "Hardfork Mechanic states that Mark 4 is affected, apologising for being unable to add proof, and urges people to move funds. Held as a dated, unverified early claim about Mk4 scope from an independent commentator.",
      "relation": {
        "kind": "single-post",
        "head_id": null
      },
      "capture": {
        "status": "held",
        "artefact_count": 2,
        "conversation_copies": 0,
        "conversation_posts": 0,
        "conversation_replies": 0,
        "conversation_gaps": []
      }
    },
    {
      "id": "coldcardwallet-technical-backgrounder",
      "title": "Technical backgrounder announcement",
      "url": "https://x.com/COLDCARDwallet/status/2083081854597374168",
      "author": "COLDCARDwallet",
      "platform": "x",
      "organisation": "Coinkite",
      "posted": "2026-07-31T06:46:30Z",
      "role": "social-statement",
      "why_registered": "COLDCARD announces a technical backgrounder covering what went wrong, why reviews missed it, impact across Mk3/Mk4/Q/Mk5, and what changed. Held as the vendor's own incident-response update and link to the detailed post.",
      "relation": {
        "kind": "single-post",
        "head_id": null
      },
      "capture": {
        "status": "held",
        "artefact_count": 2,
        "conversation_copies": 0,
        "conversation_posts": 0,
        "conversation_replies": 0,
        "conversation_gaps": []
      }
    },
    {
      "id": "niftynei-temporary-custody-advice",
      "title": "Temporary custodial move advice",
      "url": "https://x.com/niftynei/status/2083004008478949400",
      "author": "niftynei",
      "platform": "x",
      "organisation": null,
      "posted": "2026-07-31T01:37:10Z",
      "role": "social-statement",
      "why_registered": "Niftynei suggests that users worried about the COLDCARD incident move some funds immediately to familiar custodial services such as River, Strike or CashApp while taking time to consider self-custody options. Held as a dated public response statement from a named developer about temporary custody during the rescue window.",
      "relation": {
        "kind": "single-post",
        "head_id": null
      },
      "capture": {
        "status": "held",
        "artefact_count": 2,
        "conversation_copies": 0,
        "conversation_posts": 0,
        "conversation_replies": 0,
        "conversation_gaps": []
      }
    },
    {
      "id": "praveenperera-more-drains-warning",
      "title": "Warning that more drains are likely",
      "url": "https://x.com/PraveenPerera/status/2082990880592441480",
      "author": "PraveenPerera",
      "platform": "x",
      "organisation": null,
      "posted": "2026-07-31T00:45:00Z",
      "role": "social-statement",
      "why_registered": "Praveen Perera warns that more drains are likely coming and urges affected users to move their funds. Held as a dated urgent incident-response statement from the independent researcher.",
      "relation": {
        "kind": "single-post",
        "head_id": null
      },
      "capture": {
        "status": "held",
        "artefact_count": 2,
        "conversation_copies": 0,
        "conversation_posts": 0,
        "conversation_replies": 0,
        "conversation_gaps": []
      }
    },
    {
      "id": "cobrabitcoin-rescue-window-warning",
      "title": "Rescue window warning",
      "url": "https://x.com/CobraBitcoin/status/2082983867355427116",
      "author": "CobraBitcoin",
      "platform": "x",
      "organisation": null,
      "posted": "2026-07-31T00:17:08Z",
      "role": "social-statement",
      "why_registered": "CobraBitcoin warns that affected users have a few hours at most before being compromised and that the window is easy to miss. Held as a dated public response statement about the rescue window from the Bitcoin.org co-maintainer.",
      "relation": {
        "kind": "single-post",
        "head_id": null
      },
      "capture": {
        "status": "held",
        "artefact_count": 2,
        "conversation_copies": 0,
        "conversation_posts": 0,
        "conversation_replies": 0,
        "conversation_gaps": []
      }
    },
    {
      "id": "darosior-amateur-attacker-warning",
      "title": "Prediction of a more serious drain",
      "url": "https://x.com/darosior/status/2082990013394850297",
      "author": "darosior",
      "platform": "x",
      "organisation": null,
      "posted": "2026-07-31T00:41:33Z",
      "role": "social-statement",
      "why_registered": "Antoine Poinsot states that the attack details are public, calls the original attacker a big time amateur, and predicts that a really serious drain will follow. Held as a dated technical assessment from the named developer.",
      "relation": {
        "kind": "single-post",
        "head_id": null
      },
      "capture": {
        "status": "held",
        "artefact_count": 2,
        "conversation_copies": 0,
        "conversation_posts": 0,
        "conversation_replies": 0,
        "conversation_gaps": []
      }
    },
    {
      "id": "praveenperera-attacker-200-utxos",
      "title": "Attacker checked only 200 UTXOs per address",
      "url": "https://x.com/PraveenPerera/status/2082982890640454085",
      "author": "PraveenPerera",
      "platform": "x",
      "organisation": null,
      "posted": "2026-07-31T00:13:15Z",
      "role": "social-statement",
      "why_registered": "Praveen Perera urges users to move funds and claims the original thief was not highly sophisticated, having checked only 200 UTXOs per address, leaving more bitcoin still vulnerable. Held as a dated technical assessment and urgency appeal from the independent researcher. The claim about attacker behavior is reported, not independently verified here.",
      "relation": {
        "kind": "single-post",
        "head_id": null
      },
      "capture": {
        "status": "held",
        "artefact_count": 2,
        "conversation_copies": 0,
        "conversation_posts": 0,
        "conversation_replies": 0,
        "conversation_gaps": []
      }
    },
    {
      "id": "praveenperera-passphrase-alone-warning",
      "title": "Do not rely on passphrase alone",
      "url": "https://x.com/PraveenPerera/status/2082987533823103091",
      "author": "PraveenPerera",
      "platform": "x",
      "organisation": null,
      "posted": "2026-07-31T00:31:42Z",
      "role": "social-statement",
      "why_registered": "Praveen Perera warns affected users not to rely on a passphrase alone for protection. Held as a dated incident-response statement from the independent researcher who had earlier confirmed key recovery.",
      "relation": {
        "kind": "single-post",
        "head_id": null
      },
      "capture": {
        "status": "held",
        "artefact_count": 2,
        "conversation_copies": 0,
        "conversation_posts": 0,
        "conversation_replies": 0,
        "conversation_gaps": []
      }
    },
    {
      "id": "praveenperera-bip39-paraphrase-clarification",
      "title": "BIP39 paraphrase clarification",
      "url": "https://x.com/PraveenPerera/status/2082989708645167322",
      "author": "PraveenPerera",
      "platform": "x",
      "organisation": null,
      "posted": "2026-07-31T00:40:21Z",
      "role": "social-statement",
      "why_registered": "Praveen Perera clarifies that his passphrase guidance applies only to paraphrases made up of BIP39 words. Held as a dated technical qualification to his earlier warning from the independent researcher.",
      "relation": {
        "kind": "single-post",
        "head_id": null
      },
      "capture": {
        "status": "held",
        "artefact_count": 2,
        "conversation_copies": 0,
        "conversation_posts": 0,
        "conversation_replies": 0,
        "conversation_gaps": []
      }
    },
    {
      "id": "darosior-mk3-singlesig-llm-warning",
      "title": "Mk3 single-sig move-funds warning",
      "url": "https://x.com/darosior/status/2082962150507610216",
      "author": "darosior",
      "platform": "x",
      "organisation": null,
      "posted": "2026-07-30T22:50:50Z",
      "role": "social-statement",
      "why_registered": "Antoine Poinsot warns that Mk3 single-sig users should move funds urgently, stating the issue is trivial to find with a frontier LLM and that several people reached the conclusion independently. Held as a dated technical assessment and urgency appeal from the named developer.",
      "relation": {
        "kind": "single-post",
        "head_id": null
      },
      "capture": {
        "status": "held",
        "artefact_count": 2,
        "conversation_copies": 0,
        "conversation_posts": 0,
        "conversation_replies": 0,
        "conversation_gaps": []
      }
    },
    {
      "id": "praveenperera-mk2-mk3-early-warning",
      "title": "Early MK2/MK3 move-funds warning",
      "url": "https://x.com/PraveenPerera/status/2082945886309540311",
      "author": "PraveenPerera",
      "platform": "x",
      "organisation": null,
      "posted": "2026-07-30T21:46:13Z",
      "role": "social-statement",
      "why_registered": "Praveen Perera urges users who generated a seed on a MK2 or MK3 to move their funds, acknowledging the warning could be an AI hallucination but advising caution anyway. Held as a dated early incident-response statement from the independent researcher.",
      "relation": {
        "kind": "single-post",
        "head_id": null
      },
      "capture": {
        "status": "held",
        "artefact_count": 2,
        "conversation_copies": 0,
        "conversation_posts": 0,
        "conversation_replies": 0,
        "conversation_gaps": []
      }
    },
    {
      "id": "praveenperera-dice-roll-check",
      "title": "Dice-roll seed check result",
      "url": "https://x.com/PraveenPerera/status/2082936953662488654",
      "author": "PraveenPerera",
      "platform": "x",
      "organisation": null,
      "posted": "2026-07-30T21:10:43Z",
      "role": "social-statement",
      "why_registered": "Praveen Perera reports checking dice-roll seeds from 0 through 11 against a set of 500 compromised addresses and finding no matches, concluding the issue is probably not dice-roll related. Held as a dated first-hand technical check from the independent researcher.",
      "relation": {
        "kind": "single-post",
        "head_id": null
      },
      "capture": {
        "status": "held",
        "artefact_count": 2,
        "conversation_copies": 0,
        "conversation_posts": 0,
        "conversation_replies": 0,
        "conversation_gaps": []
      }
    },
    {
      "id": "darosior-contact-coinkite-advice",
      "title": "Advice for affected users to email Coinkite",
      "url": "https://x.com/darosior/status/2082907182559818003",
      "author": "darosior",
      "platform": "x",
      "organisation": null,
      "posted": "2026-07-30T19:12:25Z",
      "role": "social-statement",
      "why_registered": "Antoine Poinsot advises affected COLDCARD users to send an email to Coinkite, saying it could help avoid further fund loss by finding the cause or prevent people from moving coins in panic if the issue is different. Held as a dated incident-response recommendation from the named developer.",
      "relation": {
        "kind": "single-post",
        "head_id": null
      },
      "capture": {
        "status": "held",
        "artefact_count": 2,
        "conversation_copies": 0,
        "conversation_posts": 0,
        "conversation_replies": 0,
        "conversation_gaps": []
      }
    },
    {
      "id": "rob1ham-redteam-libsecp256k1-claims",
      "title": "Red team libsecp256k1 issue reports",
      "url": "https://x.com/Rob1Ham/status/2086321769191800882",
      "author": "Rob1Ham",
      "platform": "x",
      "organisation": null,
      "posted": "2026-08-09T05:20:46Z",
      "role": "social-statement",
      "why_registered": "Rob Hamilton, identified by this project's watch list as a Bitcoin Red Team participant, says three different red-team members have claimed to find an issue in libsecp256k1, but each turned out to be a debatable information or documentation interpretation that could go either way. Held as a dated first-hand account of red-team triage during the incident. The claims are the poster's own and are not independently verified here.\n",
      "relation": {
        "kind": "single-post",
        "head_id": null
      },
      "capture": {
        "status": "held",
        "artefact_count": 2,
        "conversation_copies": 0,
        "conversation_posts": 0,
        "conversation_replies": 0,
        "conversation_gaps": []
      }
    },
    {
      "id": "rob1ham-bip110-consensus-divergence",
      "title": "BIP 110 consensus divergence emergency disclosure",
      "url": "https://x.com/Rob1Ham/status/2086239661274325061",
      "author": "Rob1Ham",
      "platform": "x",
      "organisation": null,
      "posted": "2026-08-08T23:54:30Z",
      "role": "social-statement",
      "why_registered": "Rob Hamilton, identified by this project's watch list as a Bitcoin Red Team participant, posts an emergency disclosure labelled CON-001 about a consensus divergence affecting BIP 110, stating that nodes running BIP 110 will stall and be unable to send or receive payments, with remediation to run Bitcoin Core. Held as a dated primary technical claim from a named incident responder. The claim is the poster's own and is not independently verified here.\n",
      "relation": {
        "kind": "single-post",
        "head_id": null
      },
      "capture": {
        "status": "held",
        "artefact_count": 2,
        "conversation_copies": 0,
        "conversation_posts": 0,
        "conversation_replies": 0,
        "conversation_gaps": []
      }
    },
    {
      "id": "callebtc-redteam-appreciation",
      "title": "Red team appreciation",
      "url": "https://x.com/callebtc/status/2086043794164617237",
      "author": "callebtc",
      "platform": "x",
      "organisation": null,
      "posted": "2026-08-08T10:56:12Z",
      "role": "social-statement",
      "why_registered": "callebtc thanks the Bitcoin Red Team for securing public Bitcoin infrastructure and describes almost a week of continuous vulnerability hunting and disclosures. Held as a dated first-person reaction from a named participant in the incident response. The claims about the team's activity are the poster's own and are not independently verified here.",
      "relation": {
        "kind": "single-post",
        "head_id": null
      },
      "capture": {
        "status": "held",
        "artefact_count": 2,
        "conversation_copies": 0,
        "conversation_posts": 0,
        "conversation_replies": 0,
        "conversation_gaps": []
      }
    },
    {
      "id": "r0ckstardev-btcpay-safety-update",
      "title": "BTCPay safety update",
      "url": "https://x.com/r0ckstardev/status/2085776180473466936",
      "author": "r0ckstardev",
      "platform": "x",
      "organisation": null,
      "posted": "2026-08-07T17:12:47Z",
      "role": "incident-response",
      "why_registered": "Uncle Rockstar Developer says the BTCPay Server team is working with Bitcoin Red Team to process vulnerability details and will publish a detailed technical post shortly. The post advises BTCPay users to update to version 2.4.2 or shut down their instance to stay safe. Held as a dated incident-response safety recommendation from a named contributor during the Coldcard-response week. The advice is the poster's own and is not independently verified here.\n",
      "relation": {
        "kind": "single-post",
        "head_id": null
      },
      "capture": {
        "status": "held",
        "artefact_count": 2,
        "conversation_copies": 0,
        "conversation_posts": 0,
        "conversation_replies": 0,
        "conversation_gaps": []
      }
    },
    {
      "id": "beccaamilee-opensats-donation-redirect",
      "title": "Redirect Red Team donations to OpenSats",
      "url": "https://x.com/BeccaAmilee/status/2085722629462163666",
      "author": "BeccaAmilee",
      "platform": "x",
      "organisation": null,
      "posted": "2026-08-07T13:40:00Z",
      "role": "social-statement",
      "why_registered": "BeccaAmilee asks anyone who offered to donate to Rob Hamilton or AnchorWatch for Red Team AI tokens to donate to OpenSats instead, noting that OpenSats took over the effort earlier in the week. Held as a dated community statement about Red Team funding routing during the incident response. The appeal is the poster's own and is not independently verified here.\n",
      "relation": {
        "kind": "single-post",
        "head_id": null
      },
      "capture": {
        "status": "held",
        "artefact_count": 2,
        "conversation_copies": 0,
        "conversation_posts": 0,
        "conversation_replies": 0,
        "conversation_gaps": []
      }
    },
    {
      "id": "francispouliot_-core-library-bug-disclosure",
      "title": "Core cryptographic library bug found during audit",
      "url": "https://x.com/francispouliot_/status/2085607561768636796",
      "author": "francispouliot_",
      "platform": "x",
      "organisation": "Bull Bitcoin",
      "posted": "2026-08-07T06:02:46Z",
      "role": "social-statement",
      "why_registered": "Francis Pouliot says Bull Bitcoin found a bug in a core cryptographic library while auditing its own software, reported it and had it patched. Held as a dated first-hand claim of a separate vulnerability discovery disclosed during the incident-response week. The claim is the poster's own and is not independently verified here.\n",
      "relation": {
        "kind": "single-post",
        "head_id": null
      },
      "capture": {
        "status": "held",
        "artefact_count": 2,
        "conversation_copies": 0,
        "conversation_posts": 0,
        "conversation_replies": 0,
        "conversation_gaps": []
      }
    },
    {
      "id": "zeusln-lightning-addresses-restored",
      "title": "ZEUS Pay Lightning Addresses restored",
      "url": "https://x.com/ZeusLN/status/2085565765189505095",
      "author": "ZeusLN",
      "platform": "x",
      "organisation": null,
      "posted": "2026-08-07T03:16:41Z",
      "role": "social-statement",
      "why_registered": "ZEUS announces that ZEUS Pay Lightning Addresses are back online and that White, block source and graph data services remained operational throughout the incident, with currency exchange rate services now fully stable. Held as a dated incident-response update from the service provider during the Coldcard-response week. The claims are the poster's own and are not independently verified here.",
      "relation": {
        "kind": "single-post",
        "head_id": null
      },
      "capture": {
        "status": "held",
        "artefact_count": 2,
        "conversation_copies": 0,
        "conversation_posts": 0,
        "conversation_replies": 0,
        "conversation_gaps": []
      }
    },
    {
      "id": "intangiblecoins-victim-intake-200",
      "title": "Victim intake passes 200 reports",
      "url": "https://x.com/intangiblecoins/status/2085352550467821997",
      "author": "intangiblecoins",
      "platform": "x",
      "organisation": null,
      "posted": "2026-08-06T13:09:26Z",
      "role": "social-statement",
      "why_registered": "Alex Thorn asks victims to keep sharing reports by direct message, says more than 200 victims have reached out and that replies will follow, and ends with a statement that the response team is not leaving. Held as a dated victim-intake milestone and reassurance statement from one of the active incident responders. The victim count and triaging arrangement are the poster's own and are not independently verified here.",
      "relation": {
        "kind": "single-post",
        "head_id": null
      },
      "capture": {
        "status": "held",
        "artefact_count": 2,
        "conversation_copies": 0,
        "conversation_posts": 0,
        "conversation_replies": 0,
        "conversation_gaps": []
      }
    },
    {
      "id": "callebtc-opensats-red-fund",
      "title": "OpenSats Red Team security fund",
      "url": "https://x.com/callebtc/status/2085383824003739887",
      "author": "callebtc",
      "platform": "x",
      "organisation": null,
      "posted": "2026-08-06T15:13:42Z",
      "role": "social-statement",
      "why_registered": "callebtc announces that OpenSats has created a special fund for Bitcoin security research. Held as a dated incident-response update about Red Team funding during the Coldcard-response week. The claim is the poster's own and is not independently verified here.",
      "relation": {
        "kind": "single-post",
        "head_id": null
      },
      "capture": {
        "status": "held",
        "artefact_count": 2,
        "conversation_copies": 0,
        "conversation_posts": 0,
        "conversation_replies": 0,
        "conversation_gaps": []
      }
    },
    {
      "id": "rob1ham-repo-scan-offer",
      "title": "Repository scan offer",
      "url": "https://x.com/Rob1Ham/status/2085366766960529792",
      "author": "Rob1Ham",
      "platform": "x",
      "organisation": null,
      "posted": "2026-08-06T14:05:56Z",
      "role": "social-statement",
      "why_registered": "Rob Hamilton, identified by this project's watch list as a Bitcoin Red Team participant, asks owners to reply with repositories they want scanned and says he will organize the work with callebtc, feeding them through what he calls their clankers. Held as a dated first-hand statement of red-team triage coordination during the incident response. The plan is the poster's own and is not independently verified here.\n",
      "relation": {
        "kind": "single-post",
        "head_id": null
      },
      "capture": {
        "status": "held",
        "artefact_count": 2,
        "conversation_copies": 0,
        "conversation_posts": 0,
        "conversation_replies": 0,
        "conversation_gaps": []
      }
    },
    {
      "id": "vikrantnyc-callebtc-donation",
      "title": "Cake Wallet donation to callebtc security initiative",
      "url": "https://x.com/vikrantnyc/status/2085319018387239073",
      "author": "vikrantnyc",
      "platform": "x",
      "organisation": null,
      "posted": "2026-08-06T10:56:11Z",
      "role": "social-statement",
      "why_registered": "Vik Sharma of Cake Wallet says he is supporting callebtc and the team on their initiative to make bitcoin products safer, and that he hopes a $10,000 donation helps. Held as a dated third-party support statement for the Red Team security effort during the Coldcard-response week. The claim is the poster's own and is not independently verified here.\n",
      "relation": {
        "kind": "single-post",
        "head_id": null
      },
      "capture": {
        "status": "held",
        "artefact_count": 2,
        "conversation_copies": 0,
        "conversation_posts": 0,
        "conversation_replies": 0,
        "conversation_gaps": []
      }
    },
    {
      "id": "kloaec-2084389608138186810",
      "title": "KLoaec media post, 2026-08-03",
      "url": "https://x.com/KLoaec/status/2084389608138186810",
      "author": "KLoaec",
      "platform": "x",
      "organisation": null,
      "posted": "2026-08-03T21:23:03Z",
      "role": "social-statement",
      "why_registered": "Media-only post by Kevin Loaec on 2026-08-03; the archive holds the attached image or video as the post's full content and no text body was extracted. Held as a dated publication from a named incident participant during the Coldcard-response week. The specific statement is carried by the attached media and is not independently verified here.\n",
      "relation": {
        "kind": "single-post",
        "head_id": null
      },
      "capture": {
        "status": "held",
        "artefact_count": 2,
        "conversation_copies": 0,
        "conversation_posts": 0,
        "conversation_replies": 0,
        "conversation_gaps": []
      }
    },
    {
      "id": "lopp-repost-wiz-2085029140453830725",
      "title": "lopp repost of wiz",
      "url": "https://x.com/wiz/status/2085029140453830725",
      "author": "wiz",
      "platform": "x",
      "organisation": null,
      "posted": "2026-08-05T15:44:19Z",
      "role": "social-statement",
      "why_registered": "Media-only post by wiz on 2026-08-05, reposted by Jameson Lopp; the archive holds the attached image or video as the post's full content and no text body was extracted. Held as evidence that Lopp amplified the original during the Coldcard-response week. The original statement is the original author's, not Lopp's, and is not independently verified here.\n",
      "relation": {
        "kind": "single-post",
        "head_id": null
      },
      "capture": {
        "status": "held",
        "artefact_count": 2,
        "conversation_copies": 0,
        "conversation_posts": 0,
        "conversation_replies": 0,
        "conversation_gaps": []
      }
    },
    {
      "id": "nvk-repost-premai-2085728594047959499",
      "title": "nvk repost of premai_io",
      "url": "https://x.com/premai_io/status/2085728594047959499",
      "author": "premai_io",
      "platform": "x",
      "organisation": null,
      "posted": "2026-08-07T14:03:42Z",
      "role": "social-statement",
      "why_registered": "Media-only post by premai_io on 2026-08-07, reposted by Rodolfo Novak; the archive holds the attached image or video as the post's full content and no text body was extracted. Held as evidence that nvk amplified the original during the Coldcard-response week. The original statement is the original author's, not nvk's, and is not independently verified here.\n",
      "relation": {
        "kind": "single-post",
        "head_id": null
      },
      "capture": {
        "status": "held",
        "artefact_count": 2,
        "conversation_copies": 0,
        "conversation_posts": 0,
        "conversation_replies": 0,
        "conversation_gaps": []
      }
    },
    {
      "id": "portlandhodl-2083392206946382217",
      "title": "PortlandHODL media post, 2026-08-01",
      "url": "https://x.com/PortlandHODL/status/2083392206946382217",
      "author": "PortlandHODL",
      "platform": "x",
      "organisation": null,
      "posted": "2026-08-01T03:19:44Z",
      "role": "social-statement",
      "why_registered": "Media-only post by PortlandHODL on 2026-08-01; the archive holds the attached image or video as the post's full content and no text body was extracted. Held as a dated publication from a named incident participant during the Coldcard-response week. The specific statement is carried by the attached media and is not independently verified here.\n",
      "relation": {
        "kind": "single-post",
        "head_id": null
      },
      "capture": {
        "status": "held",
        "artefact_count": 2,
        "conversation_copies": 0,
        "conversation_posts": 0,
        "conversation_replies": 0,
        "conversation_gaps": []
      }
    },
    {
      "id": "praveenperera-2084630466074718369",
      "title": "Praveen Perera media post, 2026-08-04",
      "url": "https://x.com/PraveenPerera/status/2084630466074718369",
      "author": "PraveenPerera",
      "platform": "x",
      "organisation": null,
      "posted": "2026-08-04T13:20:08Z",
      "role": "social-statement",
      "why_registered": "Media-only post by Praveen Perera on 2026-08-04; the archive holds the attached image or video as the post's full content and no text body was extracted. Held as a dated publication from a named incident participant during the Coldcard-response week. The specific statement is carried by the attached media and is not independently verified here.\n",
      "relation": {
        "kind": "single-post",
        "head_id": null
      },
      "capture": {
        "status": "held",
        "artefact_count": 2,
        "conversation_copies": 0,
        "conversation_posts": 0,
        "conversation_replies": 0,
        "conversation_gaps": []
      }
    },
    {
      "id": "praveenperera-2082531550629859570",
      "title": "Praveen Perera media post, 2026-07-29",
      "url": "https://x.com/PraveenPerera/status/2082531550629859570",
      "author": "PraveenPerera",
      "platform": "x",
      "organisation": null,
      "posted": "2026-07-29T18:19:47Z",
      "role": "social-statement",
      "why_registered": "Media-only post by Praveen Perera on 2026-07-29; the archive holds the attached image or video as the post's full content and no text body was extracted. Held as a dated publication from a named incident participant during the Coldcard-response week. The specific statement is carried by the attached media and is not independently verified here.\n",
      "relation": {
        "kind": "single-post",
        "head_id": null
      },
      "capture": {
        "status": "held",
        "artefact_count": 2,
        "conversation_copies": 0,
        "conversation_posts": 0,
        "conversation_replies": 0,
        "conversation_gaps": []
      }
    },
    {
      "id": "theinstagibbs-repost-usdebtclock-2086164625419055484",
      "title": "theinstagibbs repost of USDebtClockSnap",
      "url": "https://x.com/USDebtClockSnap/status/2086164625419055484",
      "author": "USDebtClockSnap",
      "platform": "x",
      "organisation": null,
      "posted": "2026-08-08T18:56:20Z",
      "role": "social-statement",
      "why_registered": "Media-only post by USDebtClockSnap on 2026-08-08, reposted by theinstagibbs; the archive holds the attached image or video as the post's full content and no text body was extracted. Held as evidence that theinstagibbs amplified the original during the Coldcard-response week. The original statement is the original author's, not theinstagibbs's, and is not independently verified here.\n",
      "relation": {
        "kind": "single-post",
        "head_id": null
      },
      "capture": {
        "status": "held",
        "artefact_count": 2,
        "conversation_copies": 0,
        "conversation_posts": 0,
        "conversation_replies": 0,
        "conversation_gaps": []
      }
    },
    {
      "id": "unchained-2085846895390560649",
      "title": "Unchained media post, 2026-08-07",
      "url": "https://x.com/unchained/status/2085846895390560649",
      "author": "unchained",
      "platform": "x",
      "organisation": "Unchained",
      "posted": "2026-08-07T21:53:47Z",
      "role": "social-statement",
      "why_registered": "Media-only post by Unchained on 2026-08-07; the archive holds the attached image or video as the post's full content and no text body was extracted. Held as a dated publication from a named incident participant during the Coldcard-response week. The specific statement is carried by the attached media and is not independently verified here.\n",
      "relation": {
        "kind": "single-post",
        "head_id": null
      },
      "capture": {
        "status": "held",
        "artefact_count": 2,
        "conversation_copies": 0,
        "conversation_posts": 0,
        "conversation_replies": 0,
        "conversation_gaps": []
      }
    },
    {
      "id": "unchained-webinar-live-2085472604651925965",
      "title": "Unchained Coldcard webinar is live",
      "url": "https://x.com/unchained/status/2085472604651925965",
      "author": "unchained",
      "platform": "x",
      "organisation": "Unchained",
      "posted": "2026-08-06T21:06:29Z",
      "role": "social-statement",
      "why_registered": "Unchained says its webinar is live now and that co-founder Dhruv Bansal will discuss the Coldcard incident and how to move forward with collaborative custody. Held as a dated organisational statement promoting incident-response education. The claims are the poster's own and are not independently verified here.",
      "relation": {
        "kind": "single-post",
        "head_id": null
      },
      "capture": {
        "status": "held",
        "artefact_count": 2,
        "conversation_copies": 0,
        "conversation_posts": 0,
        "conversation_replies": 0,
        "conversation_gaps": []
      }
    },
    {
      "id": "unchained-webinar-reminder-2085459101719420978",
      "title": "Unchained Coldcard webinar reminder",
      "url": "https://x.com/unchained/status/2085459101719420978",
      "author": "unchained",
      "platform": "x",
      "organisation": "Unchained",
      "posted": "2026-08-06T20:12:50Z",
      "role": "social-statement",
      "why_registered": "Unchained reminds followers that co-founder Dhruv Bansal and product manager Jevidon will answer questions about the Coldcard incident and multisig in a webinar starting in less than an hour. Held as a dated organisational incident-response communication. The claims are the poster's own and are not independently verified here.",
      "relation": {
        "kind": "single-post",
        "head_id": null
      },
      "capture": {
        "status": "held",
        "artefact_count": 2,
        "conversation_copies": 0,
        "conversation_posts": 0,
        "conversation_replies": 0,
        "conversation_gaps": []
      }
    },
    {
      "id": "unchained-webinar-announcement-2085440762779468201",
      "title": "Unchained Coldcard multisig webinar announcement",
      "url": "https://x.com/unchained/status/2085440762779468201",
      "author": "unchained",
      "platform": "x",
      "organisation": "Unchained",
      "posted": "2026-08-06T18:59:58Z",
      "role": "social-statement",
      "why_registered": "Unchained announces a webinar in which co-founder Dhruv Bansal will answer multisig questions for people affected by or confused about the Coldcard incident. Held as a dated organisational incident-response communication. The claims are the poster's own and are not independently verified here.",
      "relation": {
        "kind": "single-post",
        "head_id": null
      },
      "capture": {
        "status": "held",
        "artefact_count": 2,
        "conversation_copies": 0,
        "conversation_posts": 0,
        "conversation_replies": 0,
        "conversation_gaps": []
      }
    },
    {
      "id": "lifeofpleb-off-coldcard-2085383007502836065",
      "title": "Customer says off Coldcard after stressful week",
      "url": "https://x.com/Life_of_Pleb/status/2085383007502836065",
      "author": "Life_of_Pleb",
      "platform": "x",
      "organisation": null,
      "posted": "2026-08-06T15:10:28Z",
      "role": "social-statement",
      "why_registered": "BTCPleb says they are officially off Coldcard after a stressful week, reports no funds lost and thanks Unchained for its service. Held as a dated first-hand customer account of moving away from COLDCARD after the incident. The claims are the poster's own and are not independently verified here.",
      "relation": {
        "kind": "single-post",
        "head_id": null
      },
      "capture": {
        "status": "held",
        "artefact_count": 2,
        "conversation_copies": 0,
        "conversation_posts": 0,
        "conversation_replies": 0,
        "conversation_gaps": []
      }
    },
    {
      "id": "unchained-multisig-protection-webinar-2085083240272924710",
      "title": "Unchained webinar on multisig protection after Coldcard",
      "url": "https://x.com/unchained/status/2085083240272924710",
      "author": "unchained",
      "platform": "x",
      "organisation": "Unchained",
      "posted": "2026-08-05T19:19:18Z",
      "role": "social-statement",
      "why_registered": "Unchained promotes a webinar covering how multisig is protecting people, how to eliminate single points of failure, and how entropy and public keys work, addressing anxiety caused by the Coldcard incident. Held as a dated organisational incident-response education offer. The claims are the poster's own and are not independently verified here.",
      "relation": {
        "kind": "single-post",
        "head_id": null
      },
      "capture": {
        "status": "held",
        "artefact_count": 2,
        "conversation_copies": 0,
        "conversation_posts": 0,
        "conversation_replies": 0,
        "conversation_gaps": []
      }
    },
    {
      "id": "unchained-exposure-warning-2085083241791291616",
      "title": "Unchained warns that Coldcard exposure is not over",
      "url": "https://x.com/unchained/status/2085083241791291616",
      "author": "unchained",
      "platform": "x",
      "organisation": "Unchained",
      "posted": "2026-08-05T19:19:18Z",
      "role": "social-statement",
      "why_registered": "Unchained warns that some Coldcard users on its platform still do not know they are exposed and urges them to secure their bitcoin rather than wait for the webinar. Held as a dated organisational incident-response safety statement. The claims are the poster's own and are not independently verified here.",
      "relation": {
        "kind": "single-post",
        "head_id": null
      },
      "capture": {
        "status": "held",
        "artefact_count": 2,
        "conversation_copies": 0,
        "conversation_posts": 0,
        "conversation_replies": 0,
        "conversation_gaps": []
      }
    },
    {
      "id": "unchained-slipstream-liability-disclaimer",
      "title": "Slipstream liability disclaimer",
      "url": "https://x.com/unchained/status/2084735370369867842",
      "author": "unchained",
      "platform": "x",
      "organisation": "Unchained",
      "posted": "2026-08-04T20:16:59Z",
      "role": "social-statement",
      "why_registered": "Unchained states that Slipstream is operated by MARA Holdings, Inc. and disclaims control or liability for its actions. Held as a dated organisational liability caveat issued during the incident-response migration push.",
      "relation": {
        "kind": "single-post",
        "head_id": null
      },
      "capture": {
        "status": "held",
        "artefact_count": 2,
        "conversation_copies": 0,
        "conversation_posts": 0,
        "conversation_replies": 0,
        "conversation_gaps": []
      }
    },
    {
      "id": "unchained-self-service-multisig-onboarding",
      "title": "Self-service multisig onboarding offer",
      "url": "https://x.com/unchained/status/2084357288005967892",
      "author": "unchained",
      "platform": "x",
      "organisation": "Unchained",
      "posted": "2026-08-03T19:14:37Z",
      "role": "social-statement",
      "why_registered": "Unchained promotes self-service onboarding for creating a new multisig vault and lists supported hardware wallets during the incident-response period. Held as a dated organisational migration-resource announcement.",
      "relation": {
        "kind": "single-post",
        "head_id": null
      },
      "capture": {
        "status": "held",
        "artefact_count": 2,
        "conversation_copies": 0,
        "conversation_posts": 0,
        "conversation_replies": 0,
        "conversation_gaps": []
      }
    },
    {
      "id": "unchained-customer-service-faq-update",
      "title": "Customer service update and new FAQ",
      "url": "https://x.com/unchained/status/2084060093138587873",
      "author": "unchained",
      "platform": "x",
      "organisation": "Unchained",
      "posted": "2026-08-02T23:33:40Z",
      "role": "social-statement",
      "why_registered": "Unchained reports its client services team is handling hundreds of contacts about the Coldcard incident and announces a new FAQ section in its incident article. Held as a dated organisational operational update.",
      "relation": {
        "kind": "single-post",
        "head_id": null
      },
      "capture": {
        "status": "held",
        "artefact_count": 2,
        "conversation_copies": 0,
        "conversation_posts": 0,
        "conversation_replies": 0,
        "conversation_gaps": []
      }
    },
    {
      "id": "unchained-multisig-safety-2082950082593202182",
      "title": "Unchained multisig safety guidance, 2026-07-30",
      "url": "https://x.com/unchained/status/2082950082593202182",
      "author": "unchained",
      "platform": "x",
      "organisation": "Unchained",
      "posted": "2026-07-30T22:02:53Z",
      "role": "social-statement",
      "why_registered": "Unchained states that singlesig wallets can be impacted immediately when a hardware-wallet vulnerability is discovered, while multisig wallets are safer provided the wallet configuration stays private. Held as the provider's earliest dated organisational incident-response guidance. The claims are the poster's own and are not independently verified here.",
      "relation": {
        "kind": "single-post",
        "head_id": null
      },
      "capture": {
        "status": "held",
        "artefact_count": 2,
        "conversation_copies": 0,
        "conversation_posts": 0,
        "conversation_replies": 0,
        "conversation_gaps": []
      }
    },
    {
      "id": "unchained-correction-earlier-post-2083923091848122670",
      "title": "Unchained correction to earlier post",
      "url": "https://x.com/unchained/status/2083923091848122670",
      "author": "unchained",
      "platform": "x",
      "organisation": "Unchained",
      "posted": "2026-08-02T14:29:17Z",
      "role": "social-statement",
      "why_registered": "Unchained notes that this post was made before the provider understood further details about the Coldcard vulnerability and its impact, and points followers to updated information. Held as a dated organisational correction notice. The claims are the poster's own and are not independently verified here.",
      "relation": {
        "kind": "single-post",
        "head_id": null
      },
      "capture": {
        "status": "held",
        "artefact_count": 2,
        "conversation_copies": 0,
        "conversation_posts": 0,
        "conversation_replies": 0,
        "conversation_gaps": []
      }
    },
    {
      "id": "hillery-dan-multisig-recovery-2083769273386942842",
      "title": "Dan Hillery reports multisig recovery through Slipstream",
      "url": "https://x.com/hillery_dan/status/2083769273386942842",
      "author": "hillery_dan",
      "platform": "x",
      "organisation": null,
      "posted": "2026-08-02T04:18:03Z",
      "role": "social-statement",
      "why_registered": "Dan Hillery says Unchained helped broadcast his multisig vault through Slipstream and that he recovered all the BTC, crediting the Unchained team for working through the weekend. Held as a first-hand customer recovery account amplified by Unchained. The claims are the poster's own and are not independently verified here.",
      "relation": {
        "kind": "single-post",
        "head_id": null
      },
      "capture": {
        "status": "held",
        "artefact_count": 2,
        "conversation_copies": 0,
        "conversation_posts": 0,
        "conversation_replies": 0,
        "conversation_gaps": []
      }
    },
    {
      "id": "unchained-coldcard-office-hours-2083242823847969147",
      "title": "Unchained Coldcard Office Hours announcement",
      "url": "https://x.com/unchained/status/2083242823847969147",
      "author": "unchained",
      "platform": "x",
      "organisation": "Unchained",
      "posted": "2026-07-31T17:26:08Z",
      "role": "social-statement",
      "why_registered": "Unchained announces Coldcard Office Hours with Tom Honzik and Jevidon for existing Unchained clients using a Coldcard, offering practical guidance on securing accounts after the incident. Held as a dated organisational incident-response operational update. The claims are the poster's own and are not independently verified here.",
      "relation": {
        "kind": "single-post",
        "head_id": null
      },
      "capture": {
        "status": "held",
        "artefact_count": 2,
        "conversation_copies": 0,
        "conversation_posts": 0,
        "conversation_replies": 0,
        "conversation_gaps": []
      }
    },
    {
      "id": "unchained-multisig-vendor-diversification-2083186659785396675",
      "title": "Unchained multisig vendor-diversification guidance",
      "url": "https://x.com/unchained/status/2083186659785396675",
      "author": "unchained",
      "platform": "x",
      "organisation": "Unchained",
      "posted": "2026-07-31T13:42:58Z",
      "role": "social-statement",
      "why_registered": "Unchained explains that multisig with devices from multiple vendors means a newly-discovered vulnerability in one does not by itself compromise bitcoin, and offers existing clients priority plus a free consultation for others. Held as a dated organisational migration-guidance statement. The claims are the poster's own and are not independently verified here.",
      "relation": {
        "kind": "single-post",
        "head_id": null
      },
      "capture": {
        "status": "held",
        "artefact_count": 2,
        "conversation_copies": 0,
        "conversation_posts": 0,
        "conversation_replies": 0,
        "conversation_gaps": []
      }
    },
    {
      "id": "isabelfoxenduke-mara-slipstream-accounting-2084725281076465748",
      "title": "Isabel Foxen Duke reports MARA Slipstream recovery volume",
      "url": "https://x.com/isabelfoxenduke/status/2084725281076465748",
      "author": "isabelfoxenduke",
      "platform": "x",
      "organisation": "MARA",
      "posted": "2026-08-04T19:36:53Z",
      "role": "social-statement",
      "why_registered": "Isabel Foxen Duke, while describing her role managing MARA Slipstream, reports that roughly 3,600 BTC were moved through Slipstream in recent days and that roughly 3,000 BTC of that used Unchained's custom recovery tooling. Held as a dated operational accounting statement from a named MARA participant. The figures are the poster's own and are not independently verified here.",
      "relation": {
        "kind": "single-post",
        "head_id": null
      },
      "capture": {
        "status": "held",
        "artefact_count": 2,
        "conversation_copies": 0,
        "conversation_posts": 0,
        "conversation_replies": 0,
        "conversation_gaps": []
      }
    },
    {
      "id": "isabelfoxenduke-mara-slipstream-3500btc-95pct",
      "title": "Isabel Foxen Duke reports ~3,500 BTC moved through MARA Slipstream",
      "url": "https://x.com/isabelfoxenduke/status/2084629797217460331",
      "author": "isabelfoxenduke",
      "platform": "x",
      "organisation": "MARA",
      "posted": "2026-08-04T13:17:28Z",
      "role": "social-statement",
      "why_registered": "Isabel Foxen Duke reports that roughly 3,500 Bitcoin have been moved out of multisig wallets by MARA Slipstream since Thursday and that those transactions make up about 95 percent of Slipstream traffic. Held as a dated operational accounting update from a named MARA participant during the incident-response migration. The figures are the poster's own and are not independently verified here.",
      "relation": {
        "kind": "single-post",
        "head_id": null
      },
      "capture": {
        "status": "held",
        "artefact_count": 2,
        "conversation_copies": 0,
        "conversation_posts": 0,
        "conversation_replies": 0,
        "conversation_gaps": []
      }
    },
    {
      "id": "btcinsider-mara-slipstream-public-opening",
      "title": "bitcoin++ Insider reports MARA Slipstream opened to the public",
      "url": "https://x.com/btcinsider__/status/2084262062037873094",
      "author": "btcinsider__",
      "platform": "x",
      "organisation": null,
      "posted": "2026-08-03T12:56:13Z",
      "role": "social-statement",
      "why_registered": "bitcoin++ Insider Edition reports that MARA has opened Slipstream, its private mempool relay, to the public, noting that the Coldcard hack has prompted interest in avoiding public-mempool exposure of multisig pubkey information. Held as a dated incident-response service announcement. The claim is the poster's own and is not independently verified here.",
      "relation": {
        "kind": "single-post",
        "head_id": null
      },
      "capture": {
        "status": "held",
        "artefact_count": 2,
        "conversation_copies": 0,
        "conversation_posts": 0,
        "conversation_replies": 0,
        "conversation_gaps": []
      }
    },
    {
      "id": "opensats-more-vulnerabilities-expected",
      "title": "OpenSats expects more critical vulnerabilities",
      "url": "https://x.com/OpenSats/status/2086080870105137246",
      "author": "OpenSats",
      "platform": "x",
      "organisation": "OpenSats",
      "posted": "2026-08-08T13:23:31Z",
      "role": "social-statement",
      "why_registered": "OpenSats states that more critical vulnerabilities are expected to be found and patched in coming days and directs followers to official channels for updates. Held as a dated organisational incident-response guidance statement. The prediction is the poster's own and is not independently verified here.",
      "relation": {
        "kind": "single-post",
        "head_id": null
      },
      "capture": {
        "status": "held",
        "artefact_count": 2,
        "conversation_copies": 0,
        "conversation_posts": 0,
        "conversation_replies": 0,
        "conversation_gaps": []
      }
    },
    {
      "id": "murchandamus-ocean-joins-attack",
      "title": "Murch says Ocean joins the attack",
      "url": "https://x.com/murchandamus/status/2086189071223967770",
      "author": "murchandamus",
      "platform": "x",
      "organisation": null,
      "posted": "2026-08-08T20:33:28Z",
      "role": "social-statement",
      "why_registered": "Murch states that Ocean has joined the attack, in a post reposted by ProfEduStream during the BIP110 recovery-fork discussion following the Coldcard incident. Held as a dated claim about a named mining-pool response. The claim is the poster's own and is not independently verified here.",
      "relation": {
        "kind": "single-post",
        "head_id": null
      },
      "capture": {
        "status": "held",
        "artefact_count": 2,
        "conversation_copies": 0,
        "conversation_posts": 0,
        "conversation_replies": 0,
        "conversation_gaps": []
      }
    },
    {
      "id": "profedustream-bip110-soft-fork-timing",
      "title": "ProfEduStream warns of BIP110 soft fork around 00:16 UTC",
      "url": "https://x.com/ProfEduStream/status/2086004093533712776",
      "author": "ProfEduStream",
      "platform": "x",
      "organisation": null,
      "posted": "2026-08-08T08:18:26Z",
      "role": "social-statement",
      "why_registered": "ProfEduStream warns that the Bitcoin network will be soft-forked by roughly 2.6 percent of hashrate around 00:16 UTC and shares bip110.orange.surf and fork.observer as monitoring resources. Held as a dated technical claim about the BIP110 recovery-fork timing. The claim is the poster's own and is not independently verified here.",
      "relation": {
        "kind": "single-post",
        "head_id": null
      },
      "capture": {
        "status": "held",
        "artefact_count": 2,
        "conversation_copies": 0,
        "conversation_posts": 0,
        "conversation_replies": 0,
        "conversation_gaps": []
      }
    },
    {
      "id": "dannydeezy-bip110-delayed",
      "title": "BIP-110 is delayed",
      "url": "https://x.com/dannydeezy/status/2086263742665527784",
      "author": "dannydeezy",
      "platform": "x",
      "organisation": null,
      "posted": "2026-08-09T01:30:11Z",
      "role": "social-statement",
      "why_registered": "Danny Deezy states that BIP-110 is delayed, in a post reposted by rot13maxi during the recovery-fork discussion following the Coldcard incident. Held as a dated status update on the proposed rescue fork. The claim is the poster's own and is not independently verified here.",
      "relation": {
        "kind": "single-post",
        "head_id": null
      },
      "capture": {
        "status": "held",
        "artefact_count": 2,
        "conversation_copies": 0,
        "conversation_posts": 0,
        "conversation_replies": 0,
        "conversation_gaps": []
      }
    },
    {
      "id": "proofofcash-bip110-mining-centralization",
      "title": "BIP-110 chain mining centralization critique",
      "url": "https://x.com/ProofOfCash/status/2086221757862515060",
      "author": "ProofOfCash",
      "platform": "x",
      "organisation": null,
      "posted": "2026-08-08T22:43:21Z",
      "role": "social-statement",
      "why_registered": "ProofOfCash argues that the BIP-110 chain has precisely one entity mining blocks despite stated goals of preserving mining decentralization, in a post reposted by rot13maxi. Held as a dated technical critique of the recovery fork. The claim is the poster's own and is not independently verified here.",
      "relation": {
        "kind": "single-post",
        "head_id": null
      },
      "capture": {
        "status": "held",
        "artefact_count": 2,
        "conversation_copies": 0,
        "conversation_posts": 0,
        "conversation_replies": 0,
        "conversation_gaps": []
      }
    },
    {
      "id": "mhluongo-bip110-economic-majority",
      "title": "Economic majority argument on BIP-110",
      "url": "https://x.com/mhluongo/status/2086244489811665232",
      "author": "mhluongo",
      "platform": "x",
      "organisation": null,
      "posted": "2026-08-09T00:13:41Z",
      "role": "social-statement",
      "why_registered": "Matt Luongo argues that economic majority rather than pool hashrate determines the outcome of the BIP-110 fork and that Twitter consensus does not reflect broader economic consensus, in a post reposted by rot13maxi. Held as a dated economic argument during the recovery-fork discussion. The argument is the poster's own and is not independently verified here.",
      "relation": {
        "kind": "single-post",
        "head_id": null
      },
      "capture": {
        "status": "held",
        "artefact_count": 2,
        "conversation_copies": 0,
        "conversation_posts": 0,
        "conversation_replies": 0,
        "conversation_gaps": []
      }
    },
    {
      "id": "lukedashjr-bip110-not-failed",
      "title": "BIP-110 has not failed",
      "url": "https://x.com/LukeDashjr/status/2086235305531621696",
      "author": "LukeDashjr",
      "platform": "x",
      "organisation": null,
      "posted": "2026-08-08T23:37:11Z",
      "role": "social-statement",
      "why_registered": "Luke Dashjr states that BIP-110 has not failed and accuses unnamed actors of gaslighting by spreading lies about its death, in a post reposted by studentofthings. Held as a dated correction from a named protocol developer during the recovery-fork discussion. The claim is the poster's own and is not independently verified here.",
      "relation": {
        "kind": "single-post",
        "head_id": null
      },
      "capture": {
        "status": "held",
        "artefact_count": 2,
        "conversation_copies": 0,
        "conversation_posts": 0,
        "conversation_replies": 0,
        "conversation_gaps": []
      }
    },
    {
      "id": "mariusoffchain-ocean-bloc-tip-both-chains",
      "title": "Ocean bloc is tip of both Bitcoin chains",
      "url": "https://x.com/mariusoffchain/status/2086188835751236012",
      "author": "mariusoffchain",
      "platform": "x",
      "organisation": null,
      "posted": "2026-08-08T20:32:32Z",
      "role": "social-statement",
      "why_registered": "Marius OffChain states that an Ocean bloc is now the tip of both Bitcoin chains, in a post reposted by studentofthings during the BIP-110 recovery-fork discussion. Held as a dated technical claim about chain state. The claim is the poster's own and is not independently verified here.",
      "relation": {
        "kind": "single-post",
        "head_id": null
      },
      "capture": {
        "status": "held",
        "artefact_count": 2,
        "conversation_copies": 0,
        "conversation_posts": 0,
        "conversation_replies": 0,
        "conversation_gaps": []
      }
    },
    {
      "id": "studentofthings-coldcard-hack-government-threats",
      "title": "Government threats to Bitcoin after Coldcard hack",
      "url": "https://x.com/studentofthings/status/2085845565728788539",
      "author": "studentofthings",
      "platform": "x",
      "organisation": null,
      "posted": "2026-08-07T21:48:30Z",
      "role": "social-statement",
      "why_registered": "Student Of Things argues that governments globally will pose persistent threats to Bitcoin rather than allow it to grow unchallenged, framed as a reflection on the Coldcard hack. Held as a dated opinion piece on incident sentiment and perceived external threats. The view is the poster's own and is not independently verified here.",
      "relation": {
        "kind": "single-post",
        "head_id": null
      },
      "capture": {
        "status": "held",
        "artefact_count": 2,
        "conversation_copies": 0,
        "conversation_posts": 0,
        "conversation_replies": 0,
        "conversation_gaps": []
      }
    },
    {
      "id": "karma-x-patch-not-disclosure",
      "title": "Karma-X says a patch is not the same as disclosure",
      "url": "https://x.com/Karma_X_Inc/status/2085447532134400094",
      "author": "Karma_X_Inc",
      "platform": "x",
      "organisation": null,
      "posted": "2026-08-06T19:26:52Z",
      "role": "social-statement",
      "why_registered": "Karma-X argues that shipping a patch is not the same as disclosing a security fix and that CommitWatch reads security-critical commits so others can keep a public record of what was fixed, how it was explained, and whether users were told. Held as a dated opinion on disclosure norms following the Coldcard incident. The argument is the poster's own and is not independently verified here.",
      "relation": {
        "kind": "single-post",
        "head_id": null
      },
      "capture": {
        "status": "held",
        "artefact_count": 2,
        "conversation_copies": 0,
        "conversation_posts": 0,
        "conversation_replies": 0,
        "conversation_gaps": []
      }
    },
    {
      "id": "studentofthings-vendors-patching-entropy",
      "title": "Student Of Things claims other hardware wallet vendors are quietly patching weak entropy",
      "url": "https://x.com/studentofthings/status/2085092783480610867",
      "author": "studentofthings",
      "platform": "x",
      "organisation": null,
      "posted": "2026-08-05T19:57:13Z",
      "role": "social-statement",
      "why_registered": "Student Of Things claims other hardware wallet vendors are quietly patching weak entropy implementations while Coldcard receives most of the attention, and says they will expose this at scale unless Coinkite is responsible for all of the theft. Held as a dated primary claim about broader hardware-wallet entropy practices during the incident response. The claim is the poster's own and is not independently verified here.",
      "relation": {
        "kind": "single-post",
        "head_id": null
      },
      "capture": {
        "status": "held",
        "artefact_count": 2,
        "conversation_copies": 0,
        "conversation_posts": 0,
        "conversation_replies": 0,
        "conversation_gaps": []
      }
    },
    {
      "id": "studentofthings-commitwatch-launch",
      "title": "Student Of Things launches CommitWatch vendor-accountability site",
      "url": "https://x.com/studentofthings/status/2085098052952490383",
      "author": "studentofthings",
      "platform": "x",
      "organisation": null,
      "posted": "2026-08-05T20:18:09Z",
      "role": "social-statement",
      "why_registered": "Student Of Things announces the launch of commitwatch.org, a site intended to keep vendors accountable for security-relevant changes, and notes that Rob1Ham and callebtc are working to find new bugs across the Bitcoin ecosystem. Held as a dated announcement of a new incident-response accountability project. The claims are the poster's own and are not independently verified here.",
      "relation": {
        "kind": "single-post",
        "head_id": null
      },
      "capture": {
        "status": "held",
        "artefact_count": 2,
        "conversation_copies": 0,
        "conversation_posts": 0,
        "conversation_replies": 0,
        "conversation_gaps": []
      }
    },
    {
      "id": "studentofthings-trust-silicon-rng",
      "title": "Trust in silicon RNG",
      "url": "https://x.com/studentofthings/status/2084651724074020995",
      "author": "studentofthings",
      "platform": "x",
      "organisation": null,
      "posted": "2026-08-04T14:44:36Z",
      "role": "social-statement",
      "why_registered": "Student Of Things argues that even a correct software RNG implementation still requires trusting the underlying silicon, and that chip backdoors are a realistic concern. Held as a dated technical argument about hardware-wallet trust assumptions beyond the COLDCARD software bug. The argument is the poster's own and is not independently verified here.",
      "relation": {
        "kind": "single-post",
        "head_id": null
      },
      "capture": {
        "status": "held",
        "artefact_count": 2,
        "conversation_copies": 0,
        "conversation_posts": 0,
        "conversation_replies": 0,
        "conversation_gaps": []
      }
    },
    {
      "id": "studentofthings-friend-mk4-rescue",
      "title": "Friend moved funds from Mk4-generated seed",
      "url": "https://x.com/studentofthings/status/2084630994485694481",
      "author": "studentofthings",
      "platform": "x",
      "organisation": null,
      "posted": "2026-08-04T13:22:14Z",
      "role": "social-statement",
      "why_registered": "Student Of Things reports that a friend flew across the country to reach a COLDCARD Mk4 in time and was able to move funds despite the device having generated the seed. Held as a dated first-hand adjacent account of the rescue window and Mk4 involvement. The claim is the poster's own and is not independently verified here.",
      "relation": {
        "kind": "single-post",
        "head_id": null
      },
      "capture": {
        "status": "held",
        "artefact_count": 2,
        "conversation_copies": 0,
        "conversation_posts": 0,
        "conversation_replies": 0,
        "conversation_gaps": []
      }
    },
    {
      "id": "studentofthings-acknowledgment-would-have-helped",
      "title": "Acknowledgment would have drawn more review",
      "url": "https://x.com/studentofthings/status/2084428129334898916",
      "author": "studentofthings",
      "platform": "x",
      "organisation": null,
      "posted": "2026-08-03T23:56:07Z",
      "role": "social-statement",
      "why_registered": "Student Of Things claims that if Coinkite had acknowledged the reported critical bug, even without credit, many other researchers would have reviewed the rest of the code. Held as a dated argument about disclosure-ecosystem dynamics during the incident response. The claim is the poster's own and is not independently verified here.",
      "relation": {
        "kind": "single-post",
        "head_id": null
      },
      "capture": {
        "status": "held",
        "artefact_count": 2,
        "conversation_copies": 0,
        "conversation_posts": 0,
        "conversation_replies": 0,
        "conversation_gaps": []
      }
    },
    {
      "id": "studentofthings-cve-waiting",
      "title": "CVE request still pending",
      "url": "https://x.com/studentofthings/status/2084355111728329078",
      "author": "studentofthings",
      "platform": "x",
      "organisation": null,
      "posted": "2026-08-03T19:05:58Z",
      "role": "social-statement",
      "why_registered": "Student Of Things states they tried to obtain a CVE for the COLDCARD vulnerability and are still waiting. Held as a dated disclosure-status update. The claim is the poster's own and is not independently verified here.",
      "relation": {
        "kind": "single-post",
        "head_id": null
      },
      "capture": {
        "status": "held",
        "artefact_count": 2,
        "conversation_copies": 0,
        "conversation_posts": 0,
        "conversation_replies": 0,
        "conversation_gaps": []
      }
    },
    {
      "id": "studentofthings-reddit-censorship-derision",
      "title": "r/Bitcoin post censored and derided",
      "url": "https://x.com/studentofthings/status/2084270294995279923",
      "author": "studentofthings",
      "platform": "x",
      "organisation": null,
      "posted": "2026-08-03T13:28:56Z",
      "role": "social-statement",
      "why_registered": "Student Of Things says their r/Bitcoin post about the COLDCARD vulnerability was censored and met with derision before removal. Held as a dated first-hand account of community reception during early disclosure. The claim is the poster's own and is not independently verified here.",
      "relation": {
        "kind": "single-post",
        "head_id": null
      },
      "capture": {
        "status": "held",
        "artefact_count": 2,
        "conversation_copies": 0,
        "conversation_posts": 0,
        "conversation_replies": 0,
        "conversation_gaps": []
      }
    },
    {
      "id": "studentofthings-admin-point-paper-ignored",
      "title": "Point paper to administration ignored",
      "url": "https://x.com/studentofthings/status/2084264667103240386",
      "author": "studentofthings",
      "platform": "x",
      "organisation": null,
      "posted": "2026-08-03T13:06:35Z",
      "role": "social-statement",
      "why_registered": "Student Of Things says they wrote a point paper to the administration last year about multiple Bitcoin cold-storage hardware bugs, including COLDCARD, and that it was effectively ignored. Held as a dated expansion of the prior disclosure claim. The claim is the poster's own and is not independently verified here.",
      "relation": {
        "kind": "single-post",
        "head_id": null
      },
      "capture": {
        "status": "held",
        "artefact_count": 2,
        "conversation_copies": 0,
        "conversation_posts": 0,
        "conversation_replies": 0,
        "conversation_gaps": []
      }
    },
    {
      "id": "studentofthings-39-findings-disclosure",
      "title": "Latest Coldcard version has 39 findings being disclosed",
      "url": "https://x.com/studentofthings/status/2084120216426914213",
      "author": "studentofthings",
      "platform": "x",
      "organisation": null,
      "posted": "2026-08-03T03:32:35Z",
      "role": "social-statement",
      "why_registered": "Student Of Things states that the latest COLDCARD firmware version has 39 findings that they are disclosing publicly as users decide how much to trust the device. Held as a dated incident-response disclosure claim. The claim is the poster's own and is not independently verified here.",
      "relation": {
        "kind": "single-post",
        "head_id": null
      },
      "capture": {
        "status": "held",
        "artefact_count": 2,
        "conversation_copies": 0,
        "conversation_posts": 0,
        "conversation_replies": 0,
        "conversation_gaps": []
      }
    },
    {
      "id": "matthew-green-entropy-sterility",
      "title": "Entropy is like surgical sterility",
      "url": "https://x.com/matthew_d_green/status/2083565702154482115",
      "author": "matthew_d_green",
      "platform": "x",
      "organisation": null,
      "posted": "2026-08-01T14:49:08Z",
      "role": "commentary",
      "why_registered": "Matthew Green compares ensuring proper product randomness to maintaining surgical sterility, where any single failure compromises the whole environment. Held as a dated technical analogy about entropy assurance during the incident discussion. The view is the poster's own and is not independently verified here.",
      "relation": {
        "kind": "single-post",
        "head_id": null
      },
      "capture": {
        "status": "held",
        "artefact_count": 2,
        "conversation_copies": 0,
        "conversation_posts": 0,
        "conversation_replies": 0,
        "conversation_gaps": []
      }
    },
    {
      "id": "studentofthings-state-operation-claim",
      "title": "Coldcard as a possible state operation",
      "url": "https://x.com/studentofthings/status/2083926655475536264",
      "author": "studentofthings",
      "platform": "x",
      "organisation": null,
      "posted": "2026-08-02T14:43:26Z",
      "role": "social-statement",
      "why_registered": "Student Of Things suggests it is underconsidered whether Coinkite or Coldcard could be a state operation, pointing to commit access and linking a 2017 article on Bitcoin as a safe-haven asset versus cyber-tulip risk. Held as a dated speculation about vendor trust and state involvement. The claim is the poster's own and is not independently verified here.",
      "relation": {
        "kind": "single-post",
        "head_id": null
      },
      "capture": {
        "status": "held",
        "artefact_count": 2,
        "conversation_copies": 0,
        "conversation_posts": 0,
        "conversation_replies": 0,
        "conversation_gaps": []
      }
    },
    {
      "id": "studentofthings-seedsigner-endorsement",
      "title": "Seedsigner validation and endorsement",
      "url": "https://x.com/studentofthings/status/2083908962601119930",
      "author": "studentofthings",
      "platform": "x",
      "organisation": null,
      "posted": "2026-08-02T13:33:08Z",
      "role": "social-statement",
      "why_registered": "Student Of Things reports validating the paths through which Seedsigner can generate a seedphrase using dice or the onboard camera, calling it a good and seemingly trustworthy product that can be built from commodity hardware. Held as a dated alternative-hardware recommendation during the incident migration discussion. The claim is the poster's own and is not independently verified here.",
      "relation": {
        "kind": "single-post",
        "head_id": null
      },
      "capture": {
        "status": "held",
        "artefact_count": 2,
        "conversation_copies": 0,
        "conversation_posts": 0,
        "conversation_replies": 0,
        "conversation_gaps": []
      }
    },
    {
      "id": "studentofthings-reddit-censorship-claim",
      "title": "Prior r/Bitcoin censorship of Coldcard key-recovery warnings",
      "url": "https://x.com/studentofthings/status/2083676184190075363",
      "author": "studentofthings",
      "platform": "x",
      "organisation": null,
      "posted": "2026-08-01T22:08:09Z",
      "role": "social-statement",
      "why_registered": "Student Of Things says they were censored on the Bitcoin subreddit last year after raising Coldcard key-recovery vulnerabilities. Held as a dated first-hand account of pre-incident awareness and community moderation. The claim is the poster's own and is not independently verified here.",
      "relation": {
        "kind": "single-post",
        "head_id": null
      },
      "capture": {
        "status": "held",
        "artefact_count": 2,
        "conversation_copies": 0,
        "conversation_posts": 0,
        "conversation_replies": 0,
        "conversation_gaps": []
      }
    },
    {
      "id": "studentofthings-unacknowledged-bug",
      "title": "Bug reported to Coinkite fixed without acknowledgment",
      "url": "https://x.com/studentofthings/status/2083003700788781417",
      "author": "studentofthings",
      "platform": "x",
      "organisation": null,
      "posted": "2026-07-31T01:35:57Z",
      "role": "social-statement",
      "why_registered": "Student Of Things says it discovered a bug that Coinkite later fixed without acknowledgment. Held as a dated first-hand account of prior vendor interaction during the incident disclosure discussion. The claim is the poster's own and is not independently verified here.",
      "relation": {
        "kind": "single-post",
        "head_id": null
      },
      "capture": {
        "status": "held",
        "artefact_count": 2,
        "conversation_copies": 0,
        "conversation_posts": 0,
        "conversation_replies": 0,
        "conversation_gaps": []
      }
    },
    {
      "id": "anchorwatch-safe-harbor-followup",
      "title": "AnchorWatch safe-harbor continuation offer",
      "url": "https://x.com/AnchorWatch/status/2085697759391232291",
      "author": "AnchorWatch",
      "platform": "x",
      "organisation": "AnchorWatch",
      "posted": "2026-08-07T12:01:10Z",
      "role": "social-statement",
      "why_registered": "AnchorWatch renews its post-incident safe-harbor offer, pitching a Multi-Institution Custody Vault held with AnchorWatch, BitGo and CoinCorner as a temporary place for Bitcoin while owners decide what comes next. Held as a dated organisational continuation of its incident-response positioning. The terms and safety claims are the publisher's and inclusion is not a recommendation.\n",
      "relation": {
        "kind": "single-post",
        "head_id": null
      },
      "capture": {
        "status": "held",
        "artefact_count": 2,
        "conversation_copies": 0,
        "conversation_posts": 0,
        "conversation_replies": 0,
        "conversation_gaps": []
      }
    },
    {
      "id": "anchorwatch-becca-customers-safe",
      "title": "AnchorWatch says no customer losses from COLDCARD",
      "url": "https://x.com/BeccaAmilee/status/2085017214055538831",
      "author": "BeccaAmilee",
      "platform": "x",
      "organisation": null,
      "posted": "2026-08-05T14:56:56Z",
      "role": "social-statement",
      "why_registered": "Becca Amilee of AnchorWatch states that no AnchorWatch customers experienced losses from the COLDCARD incident, that COLDCARD-using customers were contacted directly to migrate to a vault without an impacted key, and that no funds were at risk due to Miniscript key-material distribution. Held as a dated first-hand organizational account of customer impact and response. The claim is the publisher's own and is not independently verified here.\n",
      "relation": {
        "kind": "single-post",
        "head_id": null
      },
      "capture": {
        "status": "held",
        "artefact_count": 2,
        "conversation_copies": 0,
        "conversation_posts": 0,
        "conversation_replies": 0,
        "conversation_gaps": []
      }
    },
    {
      "id": "anchorwatch-waived-setup-fees",
      "title": "AnchorWatch waives setup fees for custody migration",
      "url": "https://x.com/AnchorWatch/status/2085139362006630754",
      "author": "AnchorWatch",
      "platform": "x",
      "organisation": "AnchorWatch",
      "posted": "2026-08-05T23:02:18Z",
      "role": "social-statement",
      "why_registered": "AnchorWatch announces waived setup fees for 60 days to support customers who are urgently reconsidering their custody choices after the COLDCARD incident. Held as a dated organizational incident-response offer. The terms and suitability are the publisher's own and inclusion is not a recommendation.\n",
      "relation": {
        "kind": "single-post",
        "head_id": null
      },
      "capture": {
        "status": "held",
        "artefact_count": 2,
        "conversation_copies": 0,
        "conversation_posts": 0,
        "conversation_replies": 0,
        "conversation_gaps": []
      }
    },
    {
      "id": "anchorwatch-new-pricing-announcement",
      "title": "AnchorWatch introduces flat-fee custody pricing",
      "url": "https://x.com/AnchorWatch/status/2085018208671572327",
      "author": "AnchorWatch",
      "platform": "x",
      "organisation": "AnchorWatch",
      "posted": "2026-08-05T15:00:53Z",
      "role": "social-statement",
      "why_registered": "AnchorWatch announces a new flat monthly fee for custody, tiered by vault size, with every vault type costing the same. Held as a dated organizational pricing change announced during the post-COLDCARD custody reconsideration. The terms and suitability are the publisher's own and inclusion is not a recommendation.\n",
      "relation": {
        "kind": "single-post",
        "head_id": null
      },
      "capture": {
        "status": "held",
        "artefact_count": 2,
        "conversation_copies": 0,
        "conversation_posts": 0,
        "conversation_replies": 0,
        "conversation_gaps": []
      }
    },
    {
      "id": "mitch-kochman-self-custody-rethink",
      "title": "Mitch Kochman argues self-custody should not be the default after COLDCARD",
      "url": "https://x.com/mitch_kochman/status/2085007721405813195",
      "author": "mitch_kochman",
      "platform": "x",
      "organisation": null,
      "posted": "2026-08-05T14:19:13Z",
      "role": "social-statement",
      "why_registered": "Mitch Kochman discusses AnchorWatch's new retail custody pricing and argues that the COLDCARD exploit shows self-custody should not be the default for every Bitcoin holder. Held as a dated first-hand industry opinion on custody assumptions after the incident. The view is the poster's own and inclusion is not a recommendation.\n",
      "relation": {
        "kind": "single-post",
        "head_id": null
      },
      "capture": {
        "status": "held",
        "artefact_count": 2,
        "conversation_copies": 0,
        "conversation_posts": 0,
        "conversation_replies": 0,
        "conversation_gaps": []
      }
    },
    {
      "id": "anchorwatch-password-not-enough",
      "title": "AnchorWatch says a stolen password is not enough to move Bitcoin",
      "url": "https://x.com/AnchorWatch/status/2084766833077276928",
      "author": "AnchorWatch",
      "platform": "x",
      "organisation": "AnchorWatch",
      "posted": "2026-08-04T22:22:00Z",
      "role": "social-statement",
      "why_registered": "AnchorWatch states that a stolen password alone cannot move Bitcoin held in its Multi-Institution Custody Vault because an authorized person must confirm each transfer on a video call with each institution using a YubiKey. Held as a dated organizational description of its custody security model during the post-COLDCARD safe-harbor period. The claim is the publisher's own and is not independently verified here.\n",
      "relation": {
        "kind": "single-post",
        "head_id": null
      },
      "capture": {
        "status": "held",
        "artefact_count": 2,
        "conversation_copies": 0,
        "conversation_posts": 0,
        "conversation_replies": 0,
        "conversation_gaps": []
      }
    },
    {
      "id": "anchorwatch-flagship-vault-structure",
      "title": "AnchorWatch describes Flagship Vault multisig structure",
      "url": "https://x.com/AnchorWatch/status/2084731856637796599",
      "author": "AnchorWatch",
      "platform": "x",
      "organisation": "AnchorWatch",
      "posted": "2026-08-04T20:03:01Z",
      "role": "social-statement",
      "why_registered": "AnchorWatch describes its Flagship Vault as a multisig arrangement in which neither the customer nor AnchorWatch can move Bitcoin without the other, with recovery defined through on-chain rules rather than documents. Held as a dated organizational explanation of the product structure being offered during the incident response. The description is the publisher's own and inclusion is not a recommendation.\n",
      "relation": {
        "kind": "conversation-head",
        "head_id": null
      },
      "capture": {
        "status": "held",
        "artefact_count": 4,
        "conversation_copies": 1,
        "conversation_posts": 2,
        "conversation_replies": 0,
        "conversation_gaps": []
      }
    },
    {
      "id": "anchorwatch-safe-harbor-signup",
      "title": "AnchorWatch offers YubiKey during safe-harbor signup",
      "url": "https://x.com/AnchorWatch/status/2084731298263052534",
      "author": "AnchorWatch",
      "platform": "x",
      "organisation": "AnchorWatch",
      "posted": "2026-08-04T20:00:48Z",
      "role": "social-statement",
      "why_registered": "AnchorWatch invites signups for Multi-Institution Custody during its safe-harbor period and says it will cover the cost of a YubiKey security key sent to the account address. Held as a dated operational detail of its post-COLDCARD safe-harbor onboarding offer. The terms and suitability are the publisher's own and inclusion is not a recommendation.\n",
      "relation": {
        "kind": "single-post",
        "head_id": null
      },
      "capture": {
        "status": "held",
        "artefact_count": 2,
        "conversation_copies": 0,
        "conversation_posts": 0,
        "conversation_replies": 0,
        "conversation_gaps": []
      }
    },
    {
      "id": "anchorwatch-device-swap-risk",
      "title": "AnchorWatch warns that swapping devices does not fix custody risk",
      "url": "https://x.com/AnchorWatch/status/2084704932922286257",
      "author": "AnchorWatch",
      "platform": "x",
      "organisation": "AnchorWatch",
      "posted": "2026-08-04T18:16:02Z",
      "role": "social-statement",
      "why_registered": "AnchorWatch argues that replacing one single-signing hardware wallet with another only changes the brand, not the risk, because a single device can still authorize a transfer alone. Held as a dated organizational opinion on the limits of device-swap migration strategies after the COLDCARD incident. The view is the publisher's own and inclusion is not a recommendation.\n",
      "relation": {
        "kind": "single-post",
        "head_id": null
      },
      "capture": {
        "status": "held",
        "artefact_count": 2,
        "conversation_copies": 0,
        "conversation_posts": 0,
        "conversation_replies": 0,
        "conversation_gaps": []
      }
    },
    {
      "id": "anchorwatch-becca-safe-harbor-update",
      "title": "Becca Amilee updates on AnchorWatch safe-harbor response",
      "url": "https://x.com/BeccaAmilee/status/2084697449915088940",
      "author": "BeccaAmilee",
      "platform": "x",
      "organisation": null,
      "posted": "2026-08-04T17:46:18Z",
      "role": "social-statement",
      "why_registered": "Becca Amilee of AnchorWatch reports that the initial wave of safe-harbor moves has slowed, describes continued inbound demand, and gives onboarding, pricing, insurance availability and KYC guidance for new custody customers. Held as a dated first-hand organizational operational update during the incident response. The claims are the publisher's own and are not independently verified here.\n",
      "relation": {
        "kind": "single-post",
        "head_id": null
      },
      "capture": {
        "status": "held",
        "artefact_count": 2,
        "conversation_copies": 0,
        "conversation_posts": 0,
        "conversation_replies": 0,
        "conversation_gaps": []
      }
    },
    {
      "id": "anchorwatch-timelocked-recovery",
      "title": "AnchorWatch describes timelocked recovery in Flagship Vaults",
      "url": "https://x.com/AnchorWatch/status/2084670196615164205",
      "author": "AnchorWatch",
      "platform": "x",
      "organisation": "AnchorWatch",
      "posted": "2026-08-04T15:58:00Z",
      "role": "social-statement",
      "why_registered": "AnchorWatch says its Flagship Vaults include timelocked recovery written into the vault itself, so a recovery path opens on a schedule enforced by the vault rather than by AnchorWatch. Held as a dated organizational description of a product feature offered as part of the post-COLDCARD response. The claim is the publisher's own and is not independently verified here.\n",
      "relation": {
        "kind": "single-post",
        "head_id": null
      },
      "capture": {
        "status": "held",
        "artefact_count": 2,
        "conversation_copies": 0,
        "conversation_posts": 0,
        "conversation_replies": 0,
        "conversation_gaps": []
      }
    },
    {
      "id": "anchorwatch-multi-institution-custody",
      "title": "AnchorWatch pitches multi-institution custody",
      "url": "https://x.com/AnchorWatch/status/2084642267805966574",
      "author": "AnchorWatch",
      "platform": "x",
      "organisation": "AnchorWatch",
      "posted": "2026-08-04T14:07:02Z",
      "role": "social-statement",
      "why_registered": "AnchorWatch promotes Multi-Institution Custody as a way to hold Bitcoin without managing a seed phrase, backup or device, with keys spread across three institutions and only the customer able to initiate transfers. Held as a dated organizational pitch that explicitly contrasts its model with single-device self-custody during the post-COLDCARD response. The claims are the publisher's own and inclusion is not a recommendation.\n",
      "relation": {
        "kind": "single-post",
        "head_id": null
      },
      "capture": {
        "status": "held",
        "artefact_count": 2,
        "conversation_copies": 0,
        "conversation_posts": 0,
        "conversation_replies": 0,
        "conversation_gaps": []
      }
    },
    {
      "id": "casa-multisig-demand-surge",
      "title": "Casa reports surge in multisig interest after COLDCARD",
      "url": "https://x.com/Nneuman/status/2085440698917003504",
      "author": "Nneuman",
      "platform": "x",
      "organisation": null,
      "posted": "2026-08-06T18:59:42Z",
      "role": "social-statement",
      "why_registered": "Nick Neuman, cofounder of Casa, reports that Casa sales calls are fully booked and that many people are moving to secure their Bitcoin with multisig, arguing that the death of self-custody is greatly exaggerated. Held as a dated first-hand organizational account of market sentiment and demand after the incident. The claims are the poster's own and are not independently verified here.\n",
      "relation": {
        "kind": "single-post",
        "head_id": null
      },
      "capture": {
        "status": "held",
        "artefact_count": 2,
        "conversation_copies": 0,
        "conversation_posts": 0,
        "conversation_replies": 0,
        "conversation_gaps": []
      }
    },
    {
      "id": "casa-multi-vendor-multisig",
      "title": "Casa recommends multi-vendor multisig",
      "url": "https://x.com/CasaHODL/status/2085830344465613270",
      "author": "CasaHODL",
      "platform": "x",
      "organisation": null,
      "posted": "2026-08-07T20:48:01Z",
      "role": "social-statement",
      "why_registered": "Casa posts the two-word message Multi-vendor multisig as a concise organizational position statement during the post-COLDCARD migration discussion. Held as a dated expression of the vendor's recommended architecture. The statement is the publisher's own and inclusion is not an endorsement.\n",
      "relation": {
        "kind": "single-post",
        "head_id": null
      },
      "capture": {
        "status": "held",
        "artefact_count": 2,
        "conversation_copies": 0,
        "conversation_posts": 0,
        "conversation_replies": 0,
        "conversation_gaps": []
      }
    },
    {
      "id": "nneuman-social-engineering-warning",
      "title": "Nick Neuman warns social engineers are exploiting the COLDCARD incident",
      "url": "https://x.com/Nneuman/status/2084995752145617314",
      "author": "Nneuman",
      "platform": "x",
      "organisation": null,
      "posted": "2026-08-05T13:31:39Z",
      "role": "social-statement",
      "why_registered": "Nick Neuman, cofounder of Casa, warns that social engineers are already trying to exploit the COLDCARD incident to steal Bitcoin while people are moving assets, and urges vigilance about websites and apps. Held as a dated first-hand warning about post-incident phishing and social engineering. The claim is the poster's own and is not independently verified here.\n",
      "relation": {
        "kind": "single-post",
        "head_id": null
      },
      "capture": {
        "status": "held",
        "artefact_count": 2,
        "conversation_copies": 0,
        "conversation_posts": 0,
        "conversation_replies": 0,
        "conversation_gaps": []
      }
    },
    {
      "id": "casahodl-impersonation-warning",
      "title": "Casa warns users to verify official communications and advisor identities",
      "url": "https://x.com/CasaHODL/status/2084651356992741783",
      "author": "CasaHODL",
      "platform": "x",
      "organisation": null,
      "posted": "2026-08-04T14:43:09Z",
      "role": "social-statement",
      "why_registered": "Casa reminds users to verify that communications come from official Casa domains, and describes its in-app advisor verification code feature as a way to confirm a claimed Casa advisor. Held as a dated organizational anti-impersonation guidance issued during the incident response. The claims are the publisher's own and inclusion is not a recommendation.\n",
      "relation": {
        "kind": "single-post",
        "head_id": null
      },
      "capture": {
        "status": "held",
        "artefact_count": 2,
        "conversation_copies": 0,
        "conversation_posts": 0,
        "conversation_replies": 0,
        "conversation_gaps": []
      }
    },
    {
      "id": "hpayne-fraudulent-casa-email",
      "title": "Hpayne shares a fraudulent email impersonating Casa",
      "url": "https://x.com/hpayne_writer/status/2084606996725022890",
      "author": "hpayne_writer",
      "platform": "x",
      "organisation": null,
      "posted": "2026-08-04T11:46:52Z",
      "role": "social-statement",
      "why_registered": "Hpayne shares a fraudulent email impersonating Casa and lists steps to avoid falling for such messages, including using Casa verification codes. Held as a dated concrete example of post-incident impersonation attempts amplified by Casa. The claims are the poster's own and are not independently verified here.\n",
      "relation": {
        "kind": "single-post",
        "head_id": null
      },
      "capture": {
        "status": "held",
        "artefact_count": 2,
        "conversation_copies": 0,
        "conversation_posts": 0,
        "conversation_replies": 0,
        "conversation_gaps": []
      }
    },
    {
      "id": "casahodl-free-security-consultations",
      "title": "Casa offers free security consultations during the incident",
      "url": "https://x.com/CasaHODL/status/2084491776065224712",
      "author": "CasaHODL",
      "platform": "x",
      "organisation": null,
      "posted": "2026-08-04T04:09:02Z",
      "role": "social-statement",
      "why_registered": "Casa announces that its team has extended hours and is offering free security consultations to people who are unsure about their security setup, sending funds or securing a new wallet during the incident. Held as a dated organizational incident-response offer. The terms and suitability are the publisher's own and inclusion is not a recommendation.\n",
      "relation": {
        "kind": "single-post",
        "head_id": null
      },
      "capture": {
        "status": "held",
        "artefact_count": 2,
        "conversation_copies": 0,
        "conversation_posts": 0,
        "conversation_replies": 0,
        "conversation_gaps": []
      }
    },
    {
      "id": "bc1gui-casa-10btc-rescue",
      "title": "Casa client helps friend recover 10 BTC during COLDCARD incident",
      "url": "https://x.com/bc1gui/status/2084104244710310280",
      "author": "bc1gui",
      "platform": "x",
      "organisation": null,
      "posted": "2026-08-03T02:29:07Z",
      "role": "social-statement",
      "why_registered": "Gui recounts helping a Casa client recover 10 BTC for a friend who was out of town, by moving funds into a secure subaccount until the friend returns. Held as a dated first-hand rescue account during the incident window. The claims are the poster's own and are not independently verified here.\n",
      "relation": {
        "kind": "single-post",
        "head_id": null
      },
      "capture": {
        "status": "held",
        "artefact_count": 2,
        "conversation_copies": 0,
        "conversation_posts": 0,
        "conversation_replies": 0,
        "conversation_gaps": []
      }
    },
    {
      "id": "theblock-coldcard-exploit-starting-block",
      "title": "The Starting Block episode on the Coldcard exploit and self-custody",
      "url": "https://x.com/TheBlockCo/status/2084251716287856945",
      "author": "TheBlockCo",
      "platform": "x",
      "organisation": "The Block",
      "posted": "2026-08-03T12:15:07Z",
      "role": "social-statement",
      "why_registered": "The Block promotes a Starting Block episode featuring Casa CTO Lopp and Foundation co-founder zherbert unpacking the Coldcard exploit and what it means for Bitcoin self-custody. Held as dated media coverage of the incident and its implications for self-custody. The program's claims are its own.\n",
      "relation": {
        "kind": "single-post",
        "head_id": null
      },
      "capture": {
        "status": "held",
        "artefact_count": 2,
        "conversation_copies": 0,
        "conversation_posts": 0,
        "conversation_replies": 0,
        "conversation_gaps": []
      }
    },
    {
      "id": "casahodl-ai-code-review-overview",
      "title": "Casa on using AI to review code",
      "url": "https://x.com/CasaHODL/status/2084120435147370901",
      "author": "CasaHODL",
      "platform": "x",
      "organisation": "Casa",
      "posted": "2026-08-03T03:33:27Z",
      "role": "social-statement",
      "why_registered": "Casa posts a brief overview of how it is using AI to review code. Held as a dated organizational statement about AI-assisted code review during the post-COLDCARD discussion of why automated reviews did not catch the entropy bug. The claims are the publisher's own and inclusion is not an endorsement.\n",
      "relation": {
        "kind": "single-post",
        "head_id": null
      },
      "capture": {
        "status": "held",
        "artefact_count": 2,
        "conversation_copies": 0,
        "conversation_posts": 0,
        "conversation_replies": 0,
        "conversation_gaps": []
      }
    },
    {
      "id": "casahodl-johnnyutah-lazarus-repost",
      "title": "CasaHODL repost of Johnny Utah suspecting Lazarus Group",
      "url": "https://x.com/CasaHODL/status/2083206750887379389",
      "author": "CasaHODL",
      "platform": "x",
      "organisation": null,
      "posted": "2026-07-31T15:02:48Z",
      "role": "social-statement",
      "why_registered": "Johnny Utah suspects the COLDCARD drains are led by the Lazarus Group and will likely accelerate, while stressing the importance of multisig wallets with companies like Casa. CasaHODL reposted the statement during the incident. The attribution is Johnny Utah's own and is not independently verified here.\n",
      "relation": {
        "kind": "single-post",
        "head_id": null
      },
      "capture": {
        "status": "held",
        "artefact_count": 2,
        "conversation_copies": 0,
        "conversation_posts": 0,
        "conversation_replies": 0,
        "conversation_gaps": []
      }
    },
    {
      "id": "nneuman-mk3-casa-rescue-offer",
      "title": "Nick Neuman offers Casa Mk3 rescue path with 30 days free",
      "url": "https://x.com/Nneuman/status/2082963443514999099",
      "author": "Nneuman",
      "platform": "x",
      "organisation": "Casa",
      "posted": "2026-07-30T22:55:59Z",
      "role": "custody-provider-guidance",
      "why_registered": "Nick Neuman, cofounder of Casa, tells Coldcard Mk3 owners they can move assets to safety quickly using Casa without other hardware wallets, setting up a 2-of-3 multisig with their phone, the Coldcard and a Casa key, with 30 days free. Held as a dated organizational rescue offer during the incident. The terms and suitability are the publisher's own and inclusion is not a recommendation.\n",
      "relation": {
        "kind": "single-post",
        "head_id": null
      },
      "capture": {
        "status": "held",
        "artefact_count": 2,
        "conversation_copies": 0,
        "conversation_posts": 0,
        "conversation_replies": 0,
        "conversation_gaps": []
      }
    },
    {
      "id": "casahodl-initial-vulnerability-analysis",
      "title": "Casa publishes initial Coldcard vulnerability analysis and multisig guidance",
      "url": "https://x.com/CasaHODL/status/2083005164949000463",
      "author": "CasaHODL",
      "platform": "x",
      "organisation": "Casa",
      "posted": "2026-07-31T01:41:46Z",
      "role": "social-statement",
      "why_registered": "Casa states that Coldcard disclosed a vulnerability affecting devices running firmware 4.0.1 (March 2021) or later, that the investigation is ongoing, and that multisig vaults with enough Coldcards remain safe because one compromised key cannot move funds. Held as a dated organizational incident-response statement with a specific firmware-version claim. The claims are the publisher's own and inclusion is not a recommendation.\n",
      "relation": {
        "kind": "single-post",
        "head_id": null
      },
      "capture": {
        "status": "held",
        "artefact_count": 2,
        "conversation_copies": 0,
        "conversation_posts": 0,
        "conversation_replies": 0,
        "conversation_gaps": []
      }
    },
    {
      "id": "bitschmidty-jamesob-honeypot-tripwire",
      "title": "Mike Schmidt highlights Jamesob honeypot tripwire for COLDCARD attackers",
      "url": "https://x.com/bitschmidty/status/2084770230383898750",
      "author": "bitschmidty",
      "platform": "x",
      "organisation": null,
      "posted": "2026-08-04T22:35:30Z",
      "role": "social-statement",
      "why_registered": "Mike Schmidt describes a honeypot tripwire system from James O'Beirne that tracks the increasingly difficult progress of people hacking COLDCARD users. Held as a dated mention of a defensive measure deployed during the incident response. The claims are the poster's own and are not independently verified here.\n",
      "relation": {
        "kind": "single-post",
        "head_id": null
      },
      "capture": {
        "status": "held",
        "artefact_count": 2,
        "conversation_copies": 0,
        "conversation_posts": 0,
        "conversation_replies": 0,
        "conversation_gaps": []
      }
    },
    {
      "id": "bitschmidty-project-loupe-ai-scanner",
      "title": "Mike Schmidt announces Project Loupe AI vulnerability scanner for Bitcoin FOSS",
      "url": "https://x.com/bitschmidty/status/2084319468272992485",
      "author": "bitschmidty",
      "platform": "x",
      "organisation": null,
      "posted": "2026-08-03T16:44:20Z",
      "role": "social-statement",
      "why_registered": "Mike Schmidt announces Project Loupe, an AI-powered vulnerability scanner for open-source Bitcoin projects launched by @blocks and @spiral_xyz, and notes it is soliciting applications from FOSS projects. Held as a dated mention of a new security tool announced during the post-COLDCARD response. The claims are the poster's own and inclusion is not a recommendation.\n",
      "relation": {
        "kind": "single-post",
        "head_id": null
      },
      "capture": {
        "status": "held",
        "artefact_count": 2,
        "conversation_copies": 0,
        "conversation_posts": 0,
        "conversation_replies": 0,
        "conversation_gaps": []
      }
    },
    {
      "id": "blockunmasked-coldcard-hacker-transfer",
      "title": "BlockchainUnmasked Daily Trace reports Coldcard attacker moved 30.185 BTC",
      "url": "https://x.com/BlockUnmasked/status/2085711837065036178",
      "author": "BlockUnmasked",
      "platform": "x",
      "organisation": null,
      "posted": "2026-08-07T12:57:07Z",
      "role": "social-statement",
      "why_registered": "BlockchainUnmasked's Daily Trace digest reports that the Coldcard hacker, who it says stole 2,055 BTC ($130M), transferred 30.185 BTC ($1.94M) to a new wallet, citing Lookonchain and CoinDesk. Held as a dated accounting update on attacker funds movement during the incident. The figures are the publisher's own and are not independently verified here.\n",
      "relation": {
        "kind": "single-post",
        "head_id": null
      },
      "capture": {
        "status": "held",
        "artefact_count": 2,
        "conversation_copies": 0,
        "conversation_posts": 0,
        "conversation_replies": 0,
        "conversation_gaps": []
      }
    },
    {
      "id": "blockunmasked-coldcard-phishing-campaign-aug6",
      "title": "BlockchainUnmasked Daily Trace notes Coldcard-themed phishing campaign",
      "url": "https://x.com/BlockUnmasked/status/2085349513191977087",
      "author": "BlockUnmasked",
      "platform": "x",
      "organisation": null,
      "posted": "2026-08-06T12:57:22Z",
      "role": "social-statement",
      "why_registered": "BlockchainUnmasked's Daily Trace digest reports a phishing campaign exploiting fears around the disclosed COLDCARD vulnerability and a suspected $88.6 million Bitcoin theft to trick users into installing ScreenConnect remote access software, citing BleepingComputer. Held as a dated example of post-incident scam activity. The claim is the publisher's own and is not independently verified here.\n",
      "relation": {
        "kind": "single-post",
        "head_id": null
      },
      "capture": {
        "status": "held",
        "artefact_count": 2,
        "conversation_copies": 0,
        "conversation_posts": 0,
        "conversation_replies": 0,
        "conversation_gaps": []
      }
    },
    {
      "id": "foundationhq-keyos-dice-final-word",
      "title": "Foundation KeyOS v1.3.1 adds final-word generation for dice seeds",
      "url": "https://x.com/FoundationHQ/status/2086076002413719933",
      "author": "FoundationHQ",
      "platform": "x",
      "organisation": "Foundation",
      "posted": "2026-08-08T13:04:11Z",
      "role": "social-statement",
      "why_registered": "Foundation announces KeyOS v1.3.1 for Passport Prime, adding a feature that generates a valid BIP39 final word after the user enters the first 11 or 23 words from a dice, coin-flip or word-drawn seed. Held as a dated organizational product update during the incident response week, when dice-generated seed workflows were widely discussed. The feature claims are the publisher's own and are not verified here.\n",
      "relation": {
        "kind": "single-post",
        "head_id": null
      },
      "capture": {
        "status": "held",
        "artefact_count": 2,
        "conversation_copies": 0,
        "conversation_posts": 0,
        "conversation_replies": 0,
        "conversation_gaps": []
      }
    },
    {
      "id": "ellemouton-ln-closure-dashboard",
      "title": "Elle Mouton dashboard tracks LN channel closures during BTCPay attacks",
      "url": "https://x.com/ElleMouton/status/2085972151367307708",
      "author": "ElleMouton",
      "platform": "x",
      "organisation": null,
      "posted": "2026-08-08T06:11:31Z",
      "role": "monitoring",
      "why_registered": "Elle Mouton shares a dashboard that tracks recent Lightning Network channel closures, assuming that 2-of-2 multisig spends are likely LN channels, and suggests the recent attacks on BTCPay Server would manifest as cooperative channel closures. Held as a dated technical monitoring artefact from a named contributor during the BTCPay Server exploitation week. The methodology and inferences are the poster's own and are not verified here.\n",
      "relation": {
        "kind": "single-post",
        "head_id": null
      },
      "capture": {
        "status": "held",
        "artefact_count": 2,
        "conversation_copies": 0,
        "conversation_posts": 0,
        "conversation_replies": 0,
        "conversation_gaps": []
      }
    },
    {
      "id": "pavlenex-btcpay-exploit-addresses",
      "title": "Pavlenex reports addresses linked to BTCPay Server exploits",
      "url": "https://x.com/pavlenex/status/2086012989262401863",
      "author": "pavlenex",
      "platform": "x",
      "organisation": null,
      "posted": "2026-08-08T08:53:47Z",
      "role": "social-statement",
      "why_registered": "Pavlenex publishes two Bitcoin addresses he links to exploits of vulnerable BTCPay Server instances and asks others to share additional addresses. Held as a dated evidentiary lead about the BTCPay Server exploitation during the incident week. The address attributions are the poster's own and are not verified here.\n",
      "relation": {
        "kind": "single-post",
        "head_id": null
      },
      "capture": {
        "status": "held",
        "artefact_count": 2,
        "conversation_copies": 0,
        "conversation_posts": 0,
        "conversation_replies": 0,
        "conversation_gaps": []
      }
    },
    {
      "id": "orangesurfbtc-btcpay-readme-pr",
      "title": "OrangeSurf opens pull request to add BTCPay Server advisory to repository readme",
      "url": "https://x.com/OrangeSurfBTC/status/2085821121027244112",
      "author": "OrangeSurfBTC",
      "platform": "x",
      "organisation": null,
      "posted": "2026-08-07T20:11:22Z",
      "role": "social-statement",
      "why_registered": "OrangeSurf says he did not see an advisory on the BTCPay Server GitHub repository and opened a pull request to add the advisory to the top of the readme, asking for review and ACK. Held as a dated community contribution to the BTCPay Server incident response during the Coldcard-response week. The claims about repository state and the pull request are the poster's own and are not verified here.\n",
      "relation": {
        "kind": "single-post",
        "head_id": null
      },
      "capture": {
        "status": "held",
        "artefact_count": 2,
        "conversation_copies": 0,
        "conversation_posts": 0,
        "conversation_replies": 0,
        "conversation_gaps": []
      }
    },
    {
      "id": "orangesurfbtc-btcpay-advisory-correction",
      "title": "OrangeSurf notes BTCPay team feedback that a prior advisory post was not entirely correct",
      "url": "https://x.com/OrangeSurfBTC/status/2085852110118178923",
      "author": "OrangeSurfBTC",
      "platform": "x",
      "organisation": null,
      "posted": "2026-08-07T22:14:30Z",
      "role": "social-statement",
      "why_registered": "OrangeSurf edits an earlier post to say a member of the BTCPay Server team told him it is not entirely correct, while noting he does not know which part is inaccurate. Held as a dated correction statement during the BTCPay advisory discussion. The feedback and its accuracy are the poster's own and are not verified here.\n",
      "relation": {
        "kind": "single-post",
        "head_id": null
      },
      "capture": {
        "status": "held",
        "artefact_count": 2,
        "conversation_copies": 0,
        "conversation_posts": 0,
        "conversation_replies": 0,
        "conversation_gaps": []
      }
    },
    {
      "id": "orangesurfbtc-btcpay-macaroon-migration",
      "title": "OrangeSurf advises BTCPay Server operators to refresh macaroons and migrate hot wallets",
      "url": "https://x.com/OrangeSurfBTC/status/2085773792026976688",
      "author": "OrangeSurfBTC",
      "platform": "x",
      "organisation": null,
      "posted": "2026-08-07T20:13:36Z",
      "role": "social-statement",
      "why_registered": "OrangeSurf advises BTCPay Server operators to completely refresh macaroons and macaroons.db, refresh auth strings for other LN backends, and migrate any hot on-chain wallet created in BTCPay. Held as dated incident-response guidance from a named contributor during the BTCPay Server exploitation week. The recommendations are the poster's own and are not verified here.\n",
      "relation": {
        "kind": "single-post",
        "head_id": null
      },
      "capture": {
        "status": "held",
        "artefact_count": 2,
        "conversation_copies": 0,
        "conversation_posts": 0,
        "conversation_replies": 0,
        "conversation_gaps": []
      }
    },
    {
      "id": "nicolasdorier-btcpay-update-warning",
      "title": "Nicolas Dorier warns BTCPay Server users to update",
      "url": "https://x.com/NicolasDorier/status/2085755915093840045",
      "author": "NicolasDorier",
      "platform": "x",
      "organisation": null,
      "posted": "2026-08-07T15:52:16Z",
      "role": "social-statement",
      "why_registered": "Nicolas Dorier, founder of BTCPay Server, calls the disclosed situation bad and urges users to update as soon as possible. Held as a dated primary statement from the project founder during the BTCPay Server exploitation week. The urgency is the poster's own and is not verified here.\n",
      "relation": {
        "kind": "single-post",
        "head_id": null
      },
      "capture": {
        "status": "held",
        "artefact_count": 2,
        "conversation_copies": 0,
        "conversation_posts": 0,
        "conversation_replies": 0,
        "conversation_gaps": []
      }
    },
    {
      "id": "secondhq-security-release-0-6-0",
      "title": "Second releases version 0.6.0 with breaking changes after Bitcoin security report",
      "url": "https://x.com/secondhq/status/2085065458219397133",
      "author": "secondhq",
      "platform": "x",
      "organisation": null,
      "posted": "2026-08-05T18:08:38Z",
      "role": "social-statement",
      "why_registered": "Second announces two releases in two days, citing the emerging security environment in Bitcoin, and says version 0.6.0 contains breaking changes users should adopt urgently. It thanks Lendasat for a report behind one fix. Held as a dated vendor software-release statement during the incident-response period. The claims about the release and the report are the poster's own and are not verified here.\n",
      "relation": {
        "kind": "single-post",
        "head_id": null
      },
      "capture": {
        "status": "held",
        "artefact_count": 2,
        "conversation_copies": 0,
        "conversation_posts": 0,
        "conversation_replies": 0,
        "conversation_gaps": []
      }
    },
    {
      "id": "orangesurfbtc-theft-phases-timeline",
      "title": "OrangeSurf outlines Coldcard theft phases and timeline",
      "url": "https://x.com/OrangeSurfBTC/status/2084404601130786980",
      "author": "OrangeSurfBTC",
      "platform": "x",
      "organisation": null,
      "posted": "2026-08-03T22:22:37Z",
      "role": "social-statement",
      "why_registered": "OrangeSurf sets out three expected phases of theft from affected COLDCARD wallets, ordered by computational cost and tooling requirements, and lists the Phase 1 thefts he has seen so far. Held as a dated technical framework for understanding how the drain campaign could progress. The framework and timeline are the poster's own and are not independently verified here.\n",
      "relation": {
        "kind": "single-post",
        "head_id": null
      },
      "capture": {
        "status": "held",
        "artefact_count": 2,
        "conversation_copies": 0,
        "conversation_posts": 0,
        "conversation_replies": 0,
        "conversation_gaps": []
      }
    },
    {
      "id": "orangesurfbtc-bricked-chip-id-warning",
      "title": "OrangeSurf warns that bricked COLDCARD device IDs cannot be recovered outside a lab",
      "url": "https://x.com/OrangeSurfBTC/status/2084692210151198819",
      "author": "OrangeSurfBTC",
      "platform": "x",
      "organisation": null,
      "posted": "2026-08-04T17:25:29Z",
      "role": "social-statement",
      "why_registered": "OrangeSurf states that the chip in a COLDCARD has a burned-in ID that cannot be recovered outside a lab if the device is bricked during an update. Held as a dated technical warning about recovery risk during the incident-response firmware-update period. The claim is the poster's own and is not independently verified here.\n",
      "relation": {
        "kind": "single-post",
        "head_id": null
      },
      "capture": {
        "status": "held",
        "artefact_count": 2,
        "conversation_copies": 0,
        "conversation_posts": 0,
        "conversation_replies": 0,
        "conversation_gaps": []
      }
    },
    {
      "id": "orangesurfbtc-multisig-slipstream-3890btc",
      "title": "OrangeSurf reports at least 3,890 BTC in multisig funds migrated through Slipstream",
      "url": "https://x.com/OrangeSurfBTC/status/2084854933006774468",
      "author": "OrangeSurfBTC",
      "platform": "x",
      "organisation": null,
      "posted": "2026-08-05T04:12:05Z",
      "role": "social-statement",
      "why_registered": "OrangeSurf points readers to a report for owners with multisig involving COLDCARD devices and updates that at least 3,890 BTC in multisig funds have been migrated through MARA Slipstream. Held as a dated accounting update on multisig migration volume during the rescue window. The figure is the poster's own and is not independently verified here.\n",
      "relation": {
        "kind": "single-post",
        "head_id": null
      },
      "capture": {
        "status": "held",
        "artefact_count": 2,
        "conversation_copies": 0,
        "conversation_posts": 0,
        "conversation_replies": 0,
        "conversation_gaps": []
      }
    },
    {
      "id": "orangesurfbtc-slipstream-inscription-congestion",
      "title": "OrangeSurf notes inscription traffic consumed multisig migration space in a Mara block",
      "url": "https://x.com/OrangeSurfBTC/status/2084857500688331224",
      "author": "OrangeSurfBTC",
      "platform": "x",
      "organisation": null,
      "posted": "2026-08-05T04:22:17Z",
      "role": "social-statement",
      "why_registered": "OrangeSurf observes that the cheapest transaction in the latest block mined by Mara had a fee rate of 10.3 sat/vB and that the available space for compromised multisig migrations was consumed by a large inscription. Held as a dated technical observation about mempool congestion affecting the rescue window. The claim is the poster's own and is not independently verified here.\n",
      "relation": {
        "kind": "single-post",
        "head_id": null
      },
      "capture": {
        "status": "held",
        "artefact_count": 2,
        "conversation_copies": 0,
        "conversation_posts": 0,
        "conversation_replies": 0,
        "conversation_gaps": []
      }
    },
    {
      "id": "orangesurfbtc-coldcard-report-peer-review",
      "title": "OrangeSurf requests peer review for a Coldcard key-exposure report",
      "url": "https://x.com/OrangeSurfBTC/status/2084675119549391024",
      "author": "OrangeSurfBTC",
      "platform": "x",
      "organisation": null,
      "posted": "2026-08-04T16:17:34Z",
      "role": "social-statement",
      "why_registered": "OrangeSurf asks for peer reviewers for a report aiming to help people affected by the COLDCARD key exposure understand how to proceed with caution. Held as a dated community-response artefact from a named contributor during the incident week. The report's contents and recommendations are not verified here.\n",
      "relation": {
        "kind": "single-post",
        "head_id": null
      },
      "capture": {
        "status": "held",
        "artefact_count": 2,
        "conversation_copies": 0,
        "conversation_posts": 0,
        "conversation_replies": 0,
        "conversation_gaps": []
      }
    },
    {
      "id": "orangesurfbtc-multisig-mempool-psa",
      "title": "OrangeSurf warns multisig owners not to broadcast migration transactions to the public mempool",
      "url": "https://x.com/OrangeSurfBTC/status/2084196600092483826",
      "author": "OrangeSurfBTC",
      "platform": "x",
      "organisation": null,
      "posted": "2026-08-03T08:36:06Z",
      "role": "social-statement",
      "why_registered": "OrangeSurf advises owners of multisig setups where vulnerable COLDCARD seeds meet the spending threshold not to broadcast migration transactions to the public mempool, to avoid test sends from the multisig, and to use MARA Slipstream for private broadcast. He reports that over 2,500 BTC has been moved from 2/3 multisigs via Slipstream and that he is not yet seeing RBF battles over compromised transactions. Held as dated incident-response guidance during the rescue window. The figures and observations are the poster's own and are not independently verified here.\n",
      "relation": {
        "kind": "single-post",
        "head_id": null
      },
      "capture": {
        "status": "held",
        "artefact_count": 2,
        "conversation_copies": 0,
        "conversation_posts": 0,
        "conversation_replies": 0,
        "conversation_gaps": []
      }
    },
    {
      "id": "orangesurfbtc-entropy-workshop-announcement",
      "title": "OrangeSurf announces wallet entropy and migration workshop with raw_avocado",
      "url": "https://x.com/OrangeSurfBTC/status/2084324600612008406",
      "author": "OrangeSurfBTC",
      "platform": "x",
      "organisation": null,
      "posted": "2026-08-03T17:04:44Z",
      "role": "social-statement",
      "why_registered": "OrangeSurf announces a workshop with raw_avocado to help affected owners understand entropy, threat model their wallet setup, and consider migration options. Held as a dated incident-response education announcement during the rescue window. The event details are the poster's own and are not verified here.\n",
      "relation": {
        "kind": "single-post",
        "head_id": null
      },
      "capture": {
        "status": "held",
        "artefact_count": 2,
        "conversation_copies": 0,
        "conversation_posts": 0,
        "conversation_replies": 0,
        "conversation_gaps": []
      }
    },
    {
      "id": "toobahlou-seedsigner-verification-warning",
      "title": "Todd Bates warns migrating owners to verify SeedSigner packages against official GitHub",
      "url": "https://x.com/toobahlou/status/2084053847438479501",
      "author": "toobahlou",
      "platform": "x",
      "organisation": null,
      "posted": "2026-08-02T23:08:51Z",
      "role": "social-statement",
      "why_registered": "Todd Bates warns owners moving to SeedSigner after the COLDCARD incident to download and verify the software against the official GitHub repository, noting the risk of preinstalled malicious images such as the DarkSkippy hack. Held as a dated safety warning about scams exploiting the migration panic. The risk assessment is the poster's own and is not independently verified here.\n",
      "relation": {
        "kind": "single-post",
        "head_id": null
      },
      "capture": {
        "status": "held",
        "artefact_count": 2,
        "conversation_copies": 0,
        "conversation_posts": 0,
        "conversation_replies": 0,
        "conversation_gaps": []
      }
    },
    {
      "id": "thebluematt-hww-rng-defensive-coding",
      "title": "Matt Corallo says hardware wallet RNG defensive coding has much room for improvement",
      "url": "https://x.com/TheBlueMatt/status/2084246996035264948",
      "author": "TheBlueMatt",
      "platform": "x",
      "organisation": null,
      "posted": "2026-08-03T11:56:21Z",
      "role": "social-statement",
      "why_registered": "Matt Corallo states that there is currently little defensive coding around hardware wallet RNGs and identifies substantial low-hanging fruit for improvement. Held as a dated technical opinion from a named Bitcoin developer on the broader hardware-wallet entropy problem. The assessment is the poster's own and is not independently verified here.\n",
      "relation": {
        "kind": "single-post",
        "head_id": null
      },
      "capture": {
        "status": "held",
        "artefact_count": 2,
        "conversation_copies": 0,
        "conversation_posts": 0,
        "conversation_replies": 0,
        "conversation_gaps": []
      }
    },
    {
      "id": "orangesurf-whitehat-ethics-warning",
      "title": "OrangeSurf on the ethics of defensive drains",
      "url": "https://x.com/OrangeSurfBTC/status/2084257971937087914",
      "author": "OrangeSurfBTC",
      "platform": "x",
      "organisation": null,
      "posted": "2026-08-03T12:39:58Z",
      "role": "social-statement",
      "why_registered": "OrangeSurf reflects on the ethical ambiguity of draining vulnerable funds defensively without a known return mechanism, urges anyone doing so to embed recovery instructions in an OP_RETURN, and notes that physical possession of the device may help prove ownership. The observations are the poster's own and are not independently verified here.",
      "relation": {
        "kind": "single-post",
        "head_id": null
      },
      "capture": {
        "status": "held",
        "artefact_count": 2,
        "conversation_copies": 0,
        "conversation_posts": 0,
        "conversation_replies": 0,
        "conversation_gaps": []
      }
    },
    {
      "id": "arkfile-firmware-692-review",
      "title": "Arkfile review of Coldcard firmware PR 692",
      "url": "https://x.com/Arkfile_OSP/status/2084248974861697063",
      "author": "Arkfile_OSP",
      "platform": "x",
      "organisation": null,
      "posted": "2026-08-03T12:04:13Z",
      "role": "social-statement",
      "why_registered": "Arkfile reviews the proposed entropy fix in Coldcard firmware pull request 692, confirms rng_get now reaches the board TRNG, and reports that the new rng_get_or_fault helper has no recovery path for STM32 RNG error flags so a single fault latches the peripheral into an unrecoverable timeout. Verified against the captured post text and linked GitHub pull request.",
      "relation": {
        "kind": "single-post",
        "head_id": null
      },
      "capture": {
        "status": "held",
        "artefact_count": 2,
        "conversation_copies": 0,
        "conversation_posts": 0,
        "conversation_replies": 0,
        "conversation_gaps": []
      }
    },
    {
      "id": "zherbert-keyos-pulled-forward-dice",
      "title": "Foundation pulled forward last-word seed completion for Passport Prime",
      "url": "https://x.com/zherbert/status/2086099753163489607",
      "author": "zherbert",
      "platform": "x",
      "organisation": null,
      "posted": "2026-08-08T14:38:33Z",
      "role": "social-statement",
      "why_registered": "Zach Herbert reports that Foundation Devices pulled forward last-word seed completion for Passport Prime, that dice-roll direct input is coming next, and that Passport Core already supports last-word completion. Held as a dated product update during the incident response week, when dice-generated seed workflows were widely discussed. The timeline claims are the publisher's own and are not verified here.\n",
      "relation": {
        "kind": "single-post",
        "head_id": null
      },
      "capture": {
        "status": "held",
        "artefact_count": 2,
        "conversation_copies": 0,
        "conversation_posts": 0,
        "conversation_replies": 0,
        "conversation_gaps": []
      }
    },
    {
      "id": "zherbert-keyos-v131-download",
      "title": "Foundation KeyOS v1.3.1 now available for download with dice final-word completion",
      "url": "https://x.com/zherbert/status/2086163707403305047",
      "author": "zherbert",
      "platform": "x",
      "organisation": null,
      "posted": "2026-08-08T18:52:41Z",
      "role": "social-statement",
      "why_registered": "Zach Herbert announces that Foundation KeyOS v1.3.1 is now available for download for Passport Prime, adding a feature that generates a valid BIP39 final word after the user enters the first 11 or 23 words from a dice, coin-flip or word-drawn seed. Held as a dated product update during the incident response week, following the earlier announcement that the feature had been pulled forward. The feature claims are the publisher's own and are not verified here.\n",
      "relation": {
        "kind": "single-post",
        "head_id": null
      },
      "capture": {
        "status": "held",
        "artefact_count": 2,
        "conversation_copies": 0,
        "conversation_posts": 0,
        "conversation_replies": 0,
        "conversation_gaps": []
      }
    },
    {
      "id": "zherbert-btcpay-lnd-macaroon-analysis",
      "title": "Zach Herbert: attacker used exposed LND macaroon credentials against BTCPay nodes",
      "url": "https://x.com/zherbert/status/2085884742025564657",
      "author": "zherbert",
      "platform": "x",
      "organisation": null,
      "posted": "2026-08-08T00:24:11Z",
      "role": "social-statement",
      "why_registered": "Zach Herbert reports Foundation Devices' analysis confirms the attacker used exposed LND .macaroon credentials to access funds, that only LND users are affected, and that no evidence was found that on-chain or hot wallets created in BTCPay Server were affected. He recommends updating to BTCPay Server 2.4.2. Held as a dated first-hand technical follow-up to his earlier report that the Foundation BTCPay lightning node had been drained. The findings are the poster's own and are not independently verified here.\n",
      "relation": {
        "kind": "single-post",
        "head_id": null
      },
      "capture": {
        "status": "held",
        "artefact_count": 2,
        "conversation_copies": 0,
        "conversation_posts": 0,
        "conversation_replies": 0,
        "conversation_gaps": []
      }
    },
    {
      "id": "zherbert-hardware-wallet-alternatives",
      "title": "Zach Herbert on users looking for alternative hardware wallets",
      "url": "https://x.com/zherbert/status/2085364296138002882",
      "author": "zherbert",
      "platform": "x",
      "organisation": null,
      "posted": "2026-08-06T13:56:07Z",
      "role": "social-statement",
      "why_registered": "Zach Herbert observes that many people have been looking for alternative hardware wallets in the days following the incident disclosure. Held as a dated sentiment marker from a competing hardware-wallet vendor's CEO on post-incident user behavior. The observation is the poster's own and is not independently verified here.\n",
      "relation": {
        "kind": "single-post",
        "head_id": null
      },
      "capture": {
        "status": "held",
        "artefact_count": 2,
        "conversation_copies": 0,
        "conversation_posts": 0,
        "conversation_replies": 0,
        "conversation_gaps": []
      }
    },
    {
      "id": "zherbert-coinkite-deletion-speculation",
      "title": "Zach Herbert on Coinkite deletion patterns and litigation hold",
      "url": "https://x.com/zherbert/status/2085071038803595771",
      "author": "zherbert",
      "platform": "x",
      "organisation": null,
      "posted": "2026-08-05T18:30:49Z",
      "role": "social-statement",
      "why_registered": "Zach Herbert notes that DocHex and Switck have not deleted posts while NVK has, and says this undermines his earlier assumption that Coinkite was under a litigation hold. Held as a dated primary statement about named parties' social-media conduct during the incident response. The inference is the poster's own and is not verified here.\n",
      "relation": {
        "kind": "single-post",
        "head_id": null
      },
      "capture": {
        "status": "held",
        "artefact_count": 2,
        "conversation_copies": 0,
        "conversation_posts": 0,
        "conversation_replies": 0,
        "conversation_gaps": []
      }
    },
    {
      "id": "zherbert-coldcard-critic-epithets",
      "title": "Zach Herbert on Coldcard's past treatment of open-source critics",
      "url": "https://x.com/zherbert/status/2085069486651015184",
      "author": "zherbert",
      "platform": "x",
      "organisation": null,
      "posted": "2026-08-05T18:24:38Z",
      "role": "social-statement",
      "why_registered": "Zach Herbert quotes his own earlier writing that people who challenged Coldcard's open-source claims were called names including 'bad faith Maoists,' 'competitors paid shills,' 'aholes,' 'useful idiots,' 'little bitching asshole,' and 'GPL commie.' Held as a first-hand account of how the vendor responded to critics before the incident. The claims are the poster's own and are not independently verified here.\n",
      "relation": {
        "kind": "single-post",
        "head_id": null
      },
      "capture": {
        "status": "held",
        "artefact_count": 2,
        "conversation_copies": 0,
        "conversation_posts": 0,
        "conversation_replies": 0,
        "conversation_gaps": []
      }
    },
    {
      "id": "zherbert-self-custody-not-dead",
      "title": "Zach Herbert: self custody is not dead",
      "url": "https://x.com/zherbert/status/2084800982643302678",
      "author": "zherbert",
      "platform": "x",
      "organisation": null,
      "posted": "2026-08-05T00:37:42Z",
      "role": "social-statement",
      "why_registered": "Zach Herbert states that self custody is not dead after five difficult days and says he is inspired by the Bitcoin community, while also joking that he may rewatch The Matrix for clues about Switck, Cyber and the white rabbit. Held as a dated sentiment post from a competing hardware-wallet vendor's CEO on the incident's implications for self-custody. The framing is the poster's own and the Matrix reference is recorded as written.\n",
      "relation": {
        "kind": "single-post",
        "head_id": null
      },
      "capture": {
        "status": "held",
        "artefact_count": 2,
        "conversation_copies": 0,
        "conversation_posts": 0,
        "conversation_replies": 0,
        "conversation_gaps": []
      }
    },
    {
      "id": "zherbert-dochex-switck-identification",
      "title": "Zach Herbert on DocHex and switck being the same person",
      "url": "https://x.com/zherbert/status/2084647957526167853",
      "author": "zherbert",
      "platform": "x",
      "organisation": null,
      "posted": "2026-08-04T14:29:38Z",
      "role": "social-statement",
      "why_registered": "Zach Herbert argues that Coinkite cofounder DocHex (Peter Gray) is the same person as the nym switck who contributed the libngu code change at the center of the Coldcard RNG bug, citing a shared phone-number ending on Peter Gray's Clarity.fm profile and both X accounts, plus James O'Beirne's finding that DocHex's GPG key signed 61 switck commits. Held as a dated primary claim and independently checkable lead about the provenance of the affected code. The inference is the poster's own and the archive has not independently verified the phone-number match or the GPG signature count.\n",
      "relation": {
        "kind": "single-post",
        "head_id": null
      },
      "capture": {
        "status": "held",
        "artefact_count": 2,
        "conversation_copies": 0,
        "conversation_posts": 0,
        "conversation_replies": 0,
        "conversation_gaps": []
      }
    },
    {
      "id": "zherbert-dochex-switck-hypothesis",
      "title": "Zach Herbert asks whether the libngu contributor was a nym for DocHex",
      "url": "https://x.com/zherbert/status/2084633599416909928",
      "author": "zherbert",
      "platform": "x",
      "organisation": null,
      "posted": "2026-08-04T13:32:35Z",
      "role": "social-statement",
      "why_registered": "Zach Herbert asks whether someone created the nym switck solely to contribute the libngu code to Coinkite and then disappear, and requests that the nym's tweets be archived. Held as a dated primary question that precedes his later identification of DocHex with switck, and as an independently checkable lead about the provenance of the affected code. The inference is the poster's own and is not verified here.\n",
      "relation": {
        "kind": "single-post",
        "head_id": null
      },
      "capture": {
        "status": "held",
        "artefact_count": 2,
        "conversation_copies": 0,
        "conversation_posts": 0,
        "conversation_replies": 0,
        "conversation_gaps": []
      }
    },
    {
      "id": "zherbert-foundation-all-hands-response",
      "title": "Zach Herbert reports Foundation all-hands on incident response and transparency",
      "url": "https://x.com/zherbert/status/2084311252872958065",
      "author": "zherbert",
      "platform": "x",
      "organisation": null,
      "posted": "2026-08-03T16:11:41Z",
      "role": "social-statement",
      "why_registered": "Zach Herbert reports that Foundation Devices held a 70-minute all-hands meeting to discuss improvements to internal code reviews and processes after the incident, and states that the company will be more transparent than ever and that self custody is not dead. Held as a dated organizational response from a competing hardware-wallet vendor during the incident week. The claims are the poster's own and are not independently verified here.\n",
      "relation": {
        "kind": "single-post",
        "head_id": null
      },
      "capture": {
        "status": "held",
        "artefact_count": 2,
        "conversation_copies": 0,
        "conversation_posts": 0,
        "conversation_replies": 0,
        "conversation_gaps": []
      }
    },
    {
      "id": "zherbert-dont-blame-bitcoin-media",
      "title": "Zach Herbert urges not to blame Bitcoin podcasters, media and VCs duped by NVK",
      "url": "https://x.com/zherbert/status/2083971652119933041",
      "author": "zherbert",
      "platform": "x",
      "organisation": null,
      "posted": "2026-08-02T17:42:14Z",
      "role": "social-statement",
      "why_registered": "Zach Herbert says it does not help to blame Bitcoin podcasters, media and venture capitalists for the incident, arguing that many were duped by NVK and that he was once duped as well, and adds that a blog post is in progress. Held as a dated first-hand statement from a competing hardware-wallet vendor CEO on the public narrative around responsibility for the incident. The claims are the poster's own and are not independently verified here.\n",
      "relation": {
        "kind": "single-post",
        "head_id": null
      },
      "capture": {
        "status": "held",
        "artefact_count": 2,
        "conversation_copies": 0,
        "conversation_posts": 0,
        "conversation_replies": 0,
        "conversation_gaps": []
      }
    },
    {
      "id": "zherbert-correct-record-nvk",
      "title": "Zach Herbert says it is time to correct the record on NVK",
      "url": "https://x.com/zherbert/status/2084271211320652064",
      "author": "zherbert",
      "platform": "x",
      "organisation": null,
      "posted": "2026-08-03T13:32:35Z",
      "role": "social-statement",
      "why_registered": "Zach Herbert argues that much of the Bitcoin industry made an exception for NVK for years, excusing attacks on free and open-source software, builders and security researchers as expertise, and says it is time to correct the record. Held as a dated primary statement from a competing hardware-wallet vendor CEO on the public response to the incident. The claims are the poster's own and are not independently verified here.\n",
      "relation": {
        "kind": "single-post",
        "head_id": null
      },
      "capture": {
        "status": "held",
        "artefact_count": 2,
        "conversation_copies": 0,
        "conversation_posts": 0,
        "conversation_replies": 0,
        "conversation_gaps": []
      }
    },
    {
      "id": "zherbert-recommend-non-endorsed-wallets",
      "title": "Zach Herbert recommends devices Coldcard did not officially endorse",
      "url": "https://x.com/zherbert/status/2084092785871765744",
      "author": "zherbert",
      "platform": "x",
      "organisation": null,
      "posted": "2026-08-03T01:43:35Z",
      "role": "social-statement",
      "why_registered": "Zach Herbert recommends that affected users buy one of the devices Coldcard did not officially endorse, naming Foundation and SeedSigner. Held as a dated primary statement from a competing hardware-wallet vendor CEO on migration options after the incident. The recommendation is the poster's own and inclusion is not endorsement.\n",
      "relation": {
        "kind": "single-post",
        "head_id": null
      },
      "capture": {
        "status": "held",
        "artefact_count": 2,
        "conversation_copies": 0,
        "conversation_posts": 0,
        "conversation_replies": 0,
        "conversation_gaps": []
      }
    },
    {
      "id": "foundation-phishing-impersonation-warning",
      "title": "Foundation warns users about phishing emails impersonating Foundation",
      "url": "https://x.com/FoundationHQ/status/2083966642904563980",
      "author": "FoundationHQ",
      "platform": "x",
      "organisation": "Foundation",
      "posted": "2026-08-02T17:22:20Z",
      "role": "social-statement",
      "why_registered": "Foundation Devices warns users that phishing emails impersonating Foundation are circulating after the Coldcard security incident, attempt to trick users into downloading malicious software or visiting fake websites, and instructs users to verify communications through official channels only. Held as a dated organizational anti-phishing guidance issued during the incident response. The claims are the publisher's own and inclusion is not a recommendation.\n",
      "relation": {
        "kind": "single-post",
        "head_id": null
      },
      "capture": {
        "status": "held",
        "artefact_count": 2,
        "conversation_copies": 0,
        "conversation_posts": 0,
        "conversation_replies": 0,
        "conversation_gaps": []
      }
    },
    {
      "id": "zherbert-coldcard-ships-old-firmware",
      "title": "Zach Herbert claims COLDCARD devices ship with old firmware",
      "url": "https://x.com/zherbert/status/2083960056643502314",
      "author": "zherbert",
      "platform": "x",
      "organisation": null,
      "posted": "2026-08-02T16:56:10Z",
      "role": "social-statement",
      "why_registered": "Zach Herbert states that COLDCARD devices ship with the old firmware, linking to a post by L0laL33tz. Held as a dated primary claim about the firmware state of shipped devices during the incident response. The claim is the poster's own and the archive has not independently verified the firmware version on shipped devices.\n",
      "relation": {
        "kind": "single-post",
        "head_id": null
      },
      "capture": {
        "status": "held",
        "artefact_count": 2,
        "conversation_copies": 0,
        "conversation_posts": 0,
        "conversation_replies": 0,
        "conversation_gaps": []
      }
    },
    {
      "id": "zherbert-passport-prime-entropy-correction",
      "title": "Zach Herbert corrects Passport Prime entropy source count",
      "url": "https://x.com/zherbert/status/2083941396499533944",
      "author": "zherbert",
      "platform": "x",
      "organisation": null,
      "posted": "2026-08-02T15:42:01Z",
      "role": "social-statement",
      "why_registered": "Zach Herbert issues a quick correction stating that Passport Prime currently combines two entropy sources and that Foundation Devices is adding a third for further improvements. Held as a dated technical correction from the CEO of a competing hardware-wallet vendor during the incident response. The claim is the poster's own and is not independently verified here.\n",
      "relation": {
        "kind": "single-post",
        "head_id": null
      },
      "capture": {
        "status": "held",
        "artefact_count": 2,
        "conversation_copies": 0,
        "conversation_posts": 0,
        "conversation_replies": 0,
        "conversation_gaps": []
      }
    },
    {
      "id": "zherbert-passport-coldcard-clone-ai-review",
      "title": "Zach Herbert reviews claim that Passport cloned Coldcard using AI",
      "url": "https://x.com/zherbert/status/2083737737442574430",
      "author": "zherbert",
      "platform": "x",
      "organisation": null,
      "posted": "2026-08-02T02:12:45Z",
      "role": "social-statement",
      "why_registered": "Zach Herbert questions NVK's repeated claim that Foundation's Passport was a clone of Coldcard, and says AI tools now allow quick review and comparison of entire codebases, sharing screenshots of a GPT 5.6 Sol conversation. Held as a dated primary claim and technical method statement from a competing hardware-wallet vendor CEO during the incident. The inference and AI outputs are the poster's own and are not independently verified here.\n",
      "relation": {
        "kind": "single-post",
        "head_id": null
      },
      "capture": {
        "status": "held",
        "artefact_count": 2,
        "conversation_copies": 0,
        "conversation_posts": 0,
        "conversation_replies": 0,
        "conversation_gaps": []
      }
    },
    {
      "id": "zherbert-passport-core-keyos-clarification",
      "title": "Zach Herbert clarifies Passport Core versus KeyOS in Passport Prime",
      "url": "https://x.com/zherbert/status/2083737743692103842",
      "author": "zherbert",
      "platform": "x",
      "organisation": null,
      "posted": "2026-08-02T02:12:46Z",
      "role": "social-statement",
      "why_registered": "Zach Herbert clarifies that the Coldcard-clone comparison applies only to Passport Core, and that Foundation began building KeyOS, a novel Rust microkernel operating system, in winter 2022 to power Passport Prime. Held as a dated technical clarification from a competing hardware-wallet vendor CEO during the incident response. The claims are the poster's own and are not independently verified here.\n",
      "relation": {
        "kind": "single-post",
        "head_id": null
      },
      "capture": {
        "status": "held",
        "artefact_count": 2,
        "conversation_copies": 0,
        "conversation_posts": 0,
        "conversation_replies": 0,
        "conversation_gaps": []
      }
    },
    {
      "id": "zherbert-i-was-wrong",
      "title": "Zach Herbert says 'I was wrong'",
      "url": "https://x.com/zherbert/status/2083725485918281847",
      "author": "zherbert",
      "platform": "x",
      "organisation": null,
      "posted": "2026-08-02T01:24:04Z",
      "role": "social-statement",
      "why_registered": "Zach Herbert posts a brief retraction stating \"I was wrong\". Held as a dated first-hand statement from a competing hardware-wallet vendor CEO during the incident response. The specific subject of the retraction is the poster's own and is not independently verified here.\n",
      "relation": {
        "kind": "single-post",
        "head_id": null
      },
      "capture": {
        "status": "held",
        "artefact_count": 2,
        "conversation_copies": 0,
        "conversation_posts": 0,
        "conversation_replies": 0,
        "conversation_gaps": []
      }
    },
    {
      "id": "zherbert-kimi-passport-core-vulnerability-rebuttal",
      "title": "Zach Herbert rebuts Kimi claim of Passport Core firmware vulnerability",
      "url": "https://x.com/zherbert/status/2083710256270503978",
      "author": "zherbert",
      "platform": "x",
      "organisation": null,
      "posted": "2026-08-02T00:23:33Z",
      "role": "social-statement",
      "why_registered": "Zach Herbert says it is not responsible to publish a claim by Kimi that there is a critical vulnerability in Passport Core firmware, states that the claim is incorrect, and compares Kimi's embedded-firmware vulnerability detection unfavorably to Fable and GPT 5.6 Sol. Held as a dated primary correction and technical-method statement from the CEO of a competing hardware-wallet vendor during the incident response. The claims are the poster's own and are not independently verified here.\n",
      "relation": {
        "kind": "single-post",
        "head_id": null
      },
      "capture": {
        "status": "held",
        "artefact_count": 2,
        "conversation_copies": 0,
        "conversation_posts": 0,
        "conversation_replies": 0,
        "conversation_gaps": []
      }
    },
    {
      "id": "foundationhq-passport-entropy-architecture-review",
      "title": "Foundation Devices shares Passport entropy architecture review results",
      "url": "https://x.com/FoundationHQ/status/2083666742643966022",
      "author": "FoundationHQ",
      "platform": "x",
      "organisation": "Foundation",
      "posted": "2026-08-01T21:30:38Z",
      "role": "social-statement",
      "why_registered": "Foundation Devices says it performed an additional review of Passport's entropy architecture for current and previous models, found no evidence of an entropy vulnerability, and outlines continued hardening including health monitoring, an entropy-testing app and publication of frontier-model review reports with each release. Held as a dated organizational incident-response update from a competing hardware-wallet vendor. The claims are the publisher's own and are not independently verified here.\n",
      "relation": {
        "kind": "single-post",
        "head_id": null
      },
      "capture": {
        "status": "held",
        "artefact_count": 2,
        "conversation_copies": 0,
        "conversation_posts": 0,
        "conversation_replies": 0,
        "conversation_gaps": []
      }
    },
    {
      "id": "foundationhq-bip39-seed-entropy-secp256k1-note",
      "title": "Foundation Devices notes BIP39 seed entropy and secp256k1 classical security",
      "url": "https://x.com/FoundationHQ/status/2083584355687891148",
      "author": "FoundationHQ",
      "platform": "x",
      "organisation": "Foundation",
      "posted": "2026-08-01T16:03:16Z",
      "role": "social-statement",
      "why_registered": "Foundation Devices explains that a properly generated 12-word BIP39 seed provides 128 bits of entropy, which is sufficient for Bitcoin's secp256k1 security level, and that a 24-word seed's additional entropy provides little practical protection against brute-force attacks. Held as a dated technical explanation from a competing hardware-wallet vendor during the incident response. The claims are the publisher's own and are not independently verified here.\n",
      "relation": {
        "kind": "single-post",
        "head_id": null
      },
      "capture": {
        "status": "held",
        "artefact_count": 2,
        "conversation_copies": 0,
        "conversation_posts": 0,
        "conversation_replies": 0,
        "conversation_gaps": []
      }
    },
    {
      "id": "zherbert-tapsigner-closed-source-warning",
      "title": "Tapsigner closed-source warning",
      "url": "https://x.com/zherbert/status/2083367011967472087",
      "author": "zherbert",
      "platform": "x",
      "organisation": "Foundation Devices",
      "posted": "2026-08-01T01:39:37Z",
      "role": "social-statement",
      "why_registered": "Zach Herbert warns that Tapsigner is closed source, that no one has checked the code, and that a closed source Javacard app runs inside the card, noting the product was released in 2022. Held as a dated primary transparency statement from the CEO of a competing hardware-wallet vendor during the incident-response week. The claims are the poster's own and are not independently verified here.\n",
      "relation": {
        "kind": "single-post",
        "head_id": null
      },
      "capture": {
        "status": "held",
        "artefact_count": 2,
        "conversation_copies": 0,
        "conversation_posts": 0,
        "conversation_replies": 0,
        "conversation_gaps": []
      }
    },
    {
      "id": "bitcoinsbanker-opendime-source-request",
      "title": "Request to publish Opendime main-micro firmware source",
      "url": "https://x.com/bitcoinsbanker/status/2083225586177065253",
      "author": "bitcoinsbanker",
      "platform": "x",
      "organisation": null,
      "posted": "2026-07-31T16:17:38Z",
      "role": "social-statement",
      "why_registered": "Scott Marmoll asks NVK to publish the Opendime main-micro firmware source as-is and read-only, with no support obligation and NDA-sensitive register values redacted if necessary. Held as a dated transparency demand directed at Coinkite during the incident response. The request is the poster's own and inclusion is not endorsement.\n",
      "relation": {
        "kind": "single-post",
        "head_id": null
      },
      "capture": {
        "status": "held",
        "artefact_count": 2,
        "conversation_copies": 0,
        "conversation_posts": 0,
        "conversation_replies": 0,
        "conversation_gaps": []
      }
    },
    {
      "id": "zherbert-gpt56-wallet-entropy-review",
      "title": "GPT 5.6 review of competitor wallet seed generation",
      "url": "https://x.com/zherbert/status/2083240930404921672",
      "author": "zherbert",
      "platform": "x",
      "organisation": "Foundation Devices",
      "posted": "2026-07-31T17:18:37Z",
      "role": "social-statement",
      "why_registered": "Zach Herbert reports using GPT 5.6 with Cyber access to review seed generation in Keystone, BitBox02, Blockstream Jade, and Trezor, stating that no Coldcard-style low-entropy bugs were found, while noting that legacy Keystone's underlying HRNG library is closed and cannot be fully source-audited. Held as a dated technical-method statement and primary claim from the CEO of a competing hardware-wallet vendor during the incident response. The findings are the poster's own and are not independently verified here.\n",
      "relation": {
        "kind": "single-post",
        "head_id": null
      },
      "capture": {
        "status": "held",
        "artefact_count": 2,
        "conversation_copies": 0,
        "conversation_posts": 0,
        "conversation_replies": 0,
        "conversation_gaps": []
      }
    },
    {
      "id": "stephanlivera-passphrase-mitigation",
      "title": "Stephan Livera recommends passphrase migration as mitigation",
      "url": "https://x.com/stephanlivera/status/2083055822242996472",
      "author": "stephanlivera",
      "platform": "x",
      "organisation": null,
      "posted": "2026-07-31T05:03:03Z",
      "role": "social-statement",
      "why_registered": "Stephan Livera recommends that worried COLDCARD owners migrate to a strong passphrase setup by choosing seven random BIP39 words as the passphrase on a new setup and moving coins there. Held as a dated mitigation recommendation from a named Bitcoin commentator, reposted by Zach Herbert during the incident response. The recommendation is the poster's own and is not independently verified here.\n",
      "relation": {
        "kind": "single-post",
        "head_id": null
      },
      "capture": {
        "status": "held",
        "artefact_count": 2,
        "conversation_copies": 0,
        "conversation_posts": 0,
        "conversation_replies": 0,
        "conversation_gaps": []
      }
    },
    {
      "id": "foundationhq-passport-entropy-confirmation",
      "title": "Foundation Devices confirms Passport seed entropy is correct",
      "url": "https://x.com/FoundationHQ/status/2083033226562420969",
      "author": "FoundationHQ",
      "platform": "x",
      "organisation": "Foundation",
      "posted": "2026-07-31T03:33:16Z",
      "role": "social-statement",
      "why_registered": "Foundation Devices states that all Passport models have always correctly generated seeds with 128 bits of entropy for 12-word seeds and 256 bits for 24-word seeds, and that all Passports remain safe and secure. Held as a dated organisational not-affected statement from a competing hardware-wallet vendor, reposted by Zach Herbert during the incident response. The claims are the publisher's own and are not independently verified here.\n",
      "relation": {
        "kind": "single-post",
        "head_id": null
      },
      "capture": {
        "status": "held",
        "artefact_count": 2,
        "conversation_copies": 0,
        "conversation_posts": 0,
        "conversation_replies": 0,
        "conversation_gaps": []
      }
    },
    {
      "id": "zherbert-foundation-entropy-breakdown",
      "title": "Zach Herbert relays Foundation CTO's Coldcard entropy analysis",
      "url": "https://x.com/zherbert/status/2083024959979262023",
      "author": "zherbert",
      "platform": "x",
      "organisation": "Foundation Devices",
      "posted": "2026-07-31T03:00:25Z",
      "role": "social-statement",
      "why_registered": "Zach Herbert relays a statement attributed to Foundation's chief technology officer that COLDCARD Mk4, Mk5 and Q secure elements provide true entropy but only 32 bits of it are retained, and that Mk3 devices running firmware v4.0.0 or later receive no validated cryptographic entropy on the wallet-generation path. Held as a dated technical claim from the CEO of a competing hardware-wallet vendor during the incident response. The claims are attributed to the Foundation CTO and are not independently verified here.\n",
      "relation": {
        "kind": "single-post",
        "head_id": null
      },
      "capture": {
        "status": "held",
        "artefact_count": 2,
        "conversation_copies": 0,
        "conversation_posts": 0,
        "conversation_replies": 0,
        "conversation_gaps": []
      }
    },
    {
      "id": "zherbert-foundation-audit-status",
      "title": "Zach Herbert reports Foundation's ongoing entropy audit status",
      "url": "https://x.com/zherbert/status/2082956582225076462",
      "author": "zherbert",
      "platform": "x",
      "organisation": "Foundation Devices",
      "posted": "2026-07-30T22:28:43Z",
      "role": "social-statement",
      "why_registered": "Zach Herbert states that Foundation is auditing its codebase for potential entropy issues, that everything looks good so far, and that Passport combines multiple entropy sources including a custom avalanche noise source to produce strong entropy, while also noting use of the GPT Cyber program. Held as a dated incident-response update from the CEO of a competing hardware-wallet vendor. The claims are the poster's own and are not independently verified here.\n",
      "relation": {
        "kind": "single-post",
        "head_id": null
      },
      "capture": {
        "status": "held",
        "artefact_count": 2,
        "conversation_copies": 0,
        "conversation_posts": 0,
        "conversation_replies": 0,
        "conversation_gaps": []
      }
    },
    {
      "id": "zherbert-why-it-happened",
      "title": "Zach Herbert on why the Coldcard entropy bug may have happened",
      "url": "https://x.com/zherbert/status/2082993533628055776",
      "author": "zherbert",
      "platform": "x",
      "organisation": null,
      "posted": "2026-07-31T00:55:33Z",
      "role": "social-statement",
      "why_registered": "Zach Herbert says he wants to explain why the Coldcard entropy bug may have happened rather than what happened, and begins a timeline of events with a July 2020 post by NVK. Held as a dated primary statement from the CEO of a competing hardware-wallet vendor on the origins of the incident. The timeline and the inference it supports are the poster's own and are not verified here.\n",
      "relation": {
        "kind": "single-post",
        "head_id": null
      },
      "capture": {
        "status": "held",
        "artefact_count": 2,
        "conversation_copies": 0,
        "conversation_posts": 0,
        "conversation_replies": 0,
        "conversation_gaps": []
      }
    },
    {
      "id": "peterktodd-bip110-inscription-slipstream",
      "title": "Peter Todd on inscribing BIP-110 blocks via Slipstream",
      "url": "https://x.com/peterktodd/status/2086441151922384966",
      "author": "peterktodd",
      "platform": "x",
      "organisation": null,
      "posted": "2026-08-09T13:15:09Z",
      "role": "social-statement",
      "why_registered": "Peter Todd predicts that someone will inscribe the two Roughnecks110 BIP-110 blocks onto the Bitcoin chain using MARA Slipstream. Held as a dated sentiment post from a Bitcoin Core developer on the BIP-110 response during the incident week. The prediction is the poster's own and is not verified here.\n",
      "relation": {
        "kind": "single-post",
        "head_id": null
      },
      "capture": {
        "status": "held",
        "artefact_count": 2,
        "conversation_copies": 0,
        "conversation_posts": 0,
        "conversation_replies": 0,
        "conversation_gaps": []
      }
    },
    {
      "id": "benhart_freedom-coldcard-disaster-part-3",
      "title": "Holder's third post on problems with Bitcoin self-custody after the Coldcard incident",
      "url": "https://x.com/BenHart_Freedom/status/2086168786898386961",
      "author": "benhart_freedom",
      "platform": "x",
      "organisation": null,
      "posted": "2026-08-08T19:12:52Z",
      "role": "social-statement",
      "why_registered": "Ben Hart publishes part three of his account, stating that he owned two Coldcard Mk4s and a Q, generated his wallets with dice and a passphrase, and still moved funds to Coinbase after the incident. The post repeats and expands claims that Coinkite has only about five employees, that Bitcoin influencers were paid to promote Coldcard, and that small volunteer-run software wallets such as Electrum, Sparrow and BlueWallet are an additional vulnerability. Held as a dated first-hand statement of an ordinary holder's loss of confidence in self-custody; the figures, causal claims and characterisations are the poster's own and are not verified here.\n",
      "relation": {
        "kind": "single-post",
        "head_id": null
      },
      "capture": {
        "status": "held",
        "artefact_count": 2,
        "conversation_copies": 0,
        "conversation_posts": 0,
        "conversation_replies": 0,
        "conversation_gaps": []
      }
    },
    {
      "id": "kuptokosmos-coldcard-update-timeline",
      "title": "Kruptos on the Coldcard bug timeline and Peter Gray's libngu role",
      "url": "https://x.com/KuptoKosmos/status/2086166930033913909",
      "author": "KuptoKosmos",
      "platform": "x",
      "organisation": null,
      "posted": "2026-08-08T19:05:29Z",
      "role": "social-statement",
      "why_registered": "Kruptos posts a detailed timeline attributing the vulnerability to Peter Gray's integration of libngu into Coldcard firmware in March 2021, the prior appearance of the switck GitHub account, and a reported May 2025 alert from James O'Beirne that was dismissed. The post also claims that GPG signatures later showed switck and DocHex to be the same person and that attackers drained probably more than 130 million dollars. Held as a dated primary theory about code provenance and disclosure timing; the claims are the poster's own and are not independently verified here.\n",
      "relation": {
        "kind": "single-post",
        "head_id": null
      },
      "capture": {
        "status": "held",
        "artefact_count": 2,
        "conversation_copies": 0,
        "conversation_posts": 0,
        "conversation_replies": 0,
        "conversation_gaps": []
      }
    },
    {
      "id": "coletu-rng-hardware-bypass-explanation",
      "title": "Cole on the Coldcard RNG hardware bypass",
      "url": "https://x.com/ColeTU/status/2087513575703134286",
      "author": "coletu",
      "platform": "x",
      "organisation": null,
      "posted": "2026-08-12T12:16:35Z",
      "role": "social-statement",
      "why_registered": "Cole states that Coldcard devices were capable of creating random seed phrases and had the necessary hardware and code, but that normal seed creation used a different weaker source instead, producing non-random seed phrases that were easy to crack. Held as a dated technical framing of the bug from a contributor to the passphrase-drain discussion. The description is the poster's own and is not independently verified here.\n",
      "relation": {
        "kind": "single-post",
        "head_id": null
      },
      "capture": {
        "status": "held",
        "artefact_count": 2,
        "conversation_copies": 0,
        "conversation_posts": 0,
        "conversation_replies": 0,
        "conversation_gaps": []
      }
    },
    {
      "id": "zherbert-passport-prime-architecture",
      "title": "Zach Herbert explains Passport Prime architecture and FOSS assurances",
      "url": "https://x.com/zherbert/status/2087514436210716980",
      "author": "zherbert",
      "platform": "x",
      "organisation": "Foundation Devices",
      "posted": "2026-08-12T12:20:00Z",
      "role": "social-statement",
      "why_registered": "Zach Herbert responds to a request to re-release Passport Core by explaining Foundation's KeyOS microkernel architecture, the upcoming app store, NFC and Bluetooth design, and reproducible FOSS builds. Held as a dated organisational statement from the CEO of a competing hardware-wallet vendor during the incident response. The claims are the publisher's own and are not independently verified here.\n",
      "relation": {
        "kind": "single-post",
        "head_id": null
      },
      "capture": {
        "status": "held",
        "artefact_count": 2,
        "conversation_copies": 0,
        "conversation_posts": 0,
        "conversation_replies": 0,
        "conversation_gaps": []
      }
    },
    {
      "id": "nunchuk-no-subscriber-loss",
      "title": "Nunchuk reports no subscriber losses and explains why its architecture held",
      "url": "https://x.com/nunchuk_io/status/2087162119552987288",
      "author": "nunchuk_io",
      "platform": "x",
      "organisation": "Nunchuk",
      "posted": "2026-08-11T13:00:01Z",
      "role": "custody-provider-guidance",
      "why_registered": "Nunchuk states that no subscriber has lost bitcoin during the Coldcard seed-generation vulnerability and begins a thread explaining why its architecture held. Held as a dated organisational incident-response statement from a wallet-service provider. The claims are Nunchuk's own and are not independently verified here.\n",
      "relation": {
        "kind": "conversation-head",
        "head_id": null
      },
      "capture": {
        "status": "held",
        "artefact_count": 14,
        "conversation_copies": 1,
        "conversation_posts": 12,
        "conversation_replies": 11,
        "conversation_gaps": []
      }
    },
    {
      "id": "fartface2000-mk3-dice-reseed",
      "title": "Mk3 owner describes firmware upgrade and dice reseed verification",
      "url": "https://x.com/fartface2000/status/2087477189075722327",
      "author": "fartface2000",
      "platform": "x",
      "organisation": null,
      "posted": "2026-08-12T09:51:59Z",
      "role": "social-statement",
      "why_registered": "A COLDCARD Mk3 owner describes upgrading firmware, wiping the seed, generating two 100-roll dice seeds, checking each one online, verifying the procedure twice, and discarding the seeds before trusting the device for a future offline seed generation. Held as a dated first-hand owner account of post-incident mitigation behavior and confidence rebuilding. The claims about the procedure and its outcome are the poster's own and are not independently verified here.\n",
      "relation": {
        "kind": "single-post",
        "head_id": null
      },
      "capture": {
        "status": "held",
        "artefact_count": 2,
        "conversation_copies": 0,
        "conversation_posts": 0,
        "conversation_replies": 0,
        "conversation_gaps": []
      }
    },
    {
      "id": "scottmelker-2087180019332178133",
      "title": "Scott Melker satirizes a newcomer’s view of the Coldcard panic",
      "url": "https://x.com/scottmelker/status/2087180019332178133",
      "author": "scottmelker",
      "platform": "x",
      "organisation": null,
      "posted": "2026-08-11T14:11:09Z",
      "role": "social-statement",
      "why_registered": "Scott Melker (@scottmelker) posts a satirical first-person narrative about someone who discovers Bitcoin, joins X during the Coldcard hack, and is overwhelmed by conflicting advice about dice rolls, BTCPay drains, BIP 110 and self-custody absolutism. The post ends with the newcomer giving up and buying NVDA stock. Held as a dated sentiment piece documenting how the incident and surrounding debate appeared to outsiders. The characterization is the poster's own and is not independently verified here.\n",
      "relation": {
        "kind": "single-post",
        "head_id": null
      },
      "capture": {
        "status": "held",
        "artefact_count": 2,
        "conversation_copies": 0,
        "conversation_posts": 0,
        "conversation_replies": 0,
        "conversation_gaps": []
      }
    },
    {
      "id": "rob1ham-2086464831360549034",
      "title": "Rob Hamilton says OpenAI blocked his analysis of a disclosed codebase",
      "url": "https://x.com/Rob1Ham/status/2086464831360549034",
      "author": "rob1ham",
      "platform": "x",
      "organisation": null,
      "posted": "2026-08-09T14:49:15Z",
      "role": "social-statement",
      "why_registered": "Rob Hamilton, identified by this project's watch list as a Bitcoin Red Team participant, says OpenAI's trust cyber program has blocked him from continuing analysis on a codebase he already responsibly disclosed to and received confirmation of legitimate findings from, after he completed onboarding and KYC months ago. He says he will return to Chinese open-source models to continue protecting Bitcoin infrastructure and appeals to David Sacks, Sam Altman and Donald Trump for action. Held as a dated first-hand incident-response statement about responder access to frontier AI tools. The claims are the poster's own and are not independently verified here.\n",
      "relation": {
        "kind": "single-post",
        "head_id": null
      },
      "capture": {
        "status": "held",
        "artefact_count": 2,
        "conversation_copies": 0,
        "conversation_posts": 0,
        "conversation_replies": 0,
        "conversation_gaps": []
      }
    },
    {
      "id": "kloaec-repost-macronaut-2086373232375124039",
      "title": "kloaec repost of Macronaut_",
      "url": "https://x.com/Macronaut_/status/2086373232375124039",
      "author": "Macronaut_",
      "platform": "x",
      "organisation": null,
      "posted": "2026-08-09T08:45:16Z",
      "role": "social-statement",
      "why_registered": "Media-only post by Macronaut_ on 2026-08-09, reposted by KLoaec; the archive holds the attached image or video as the post's full content and no text body was extracted. Held as evidence that KLoaec amplified the original during the Coldcard-response week. The original statement is the original author's, not KLoaec's, and is not independently verified here.\n",
      "relation": {
        "kind": "single-post",
        "head_id": null
      },
      "capture": {
        "status": "held",
        "artefact_count": 2,
        "conversation_copies": 0,
        "conversation_posts": 0,
        "conversation_replies": 0,
        "conversation_gaps": []
      }
    },
    {
      "id": "praveenperera-2085800588395081751",
      "title": "Praveen Perera media post, 2026-08-07",
      "url": "https://x.com/PraveenPerera/status/2085800588395081751",
      "author": "PraveenPerera",
      "platform": "x",
      "organisation": null,
      "posted": "2026-08-07T18:49:47Z",
      "role": "social-statement",
      "why_registered": "Media-only post by Praveen Perera on 2026-08-07; the archive holds the attached image or video as the post's full content and no text body was extracted. Held as a dated publication from a named incident participant during the Coldcard-response week. The specific statement is carried by the attached media and is not independently verified here.\n",
      "relation": {
        "kind": "single-post",
        "head_id": null
      },
      "capture": {
        "status": "held",
        "artefact_count": 2,
        "conversation_copies": 0,
        "conversation_posts": 0,
        "conversation_replies": 0,
        "conversation_gaps": []
      }
    },
    {
      "id": "blockunmasked-2086398271774163407",
      "title": "BlockUnmasked media post, 2026-08-09",
      "url": "https://x.com/BlockUnmasked/status/2086398271774163407",
      "author": "BlockUnmasked",
      "platform": "x",
      "organisation": null,
      "posted": "2026-08-09T10:24:46Z",
      "role": "social-statement",
      "why_registered": "Media-only post by BlockUnmasked on 2026-08-09; the archive holds the attached image or video as the post's full content and no text body was extracted. Held as a dated publication from a named incident participant during the Coldcard-response week. The specific statement is carried by the attached media and is not independently verified here.\n",
      "relation": {
        "kind": "single-post",
        "head_id": null
      },
      "capture": {
        "status": "held",
        "artefact_count": 2,
        "conversation_copies": 0,
        "conversation_posts": 0,
        "conversation_replies": 0,
        "conversation_gaps": []
      }
    },
    {
      "id": "zherbert-2084271380724355321",
      "title": "Zach Herbert media post, 2026-08-03",
      "url": "https://x.com/zherbert/status/2084271380724355321",
      "author": "zherbert",
      "platform": "x",
      "organisation": null,
      "posted": "2026-08-03T13:33:15Z",
      "role": "social-statement",
      "why_registered": "Media-only post by Zach Herbert on 2026-08-03; the archive holds the attached image or video as the post's full content and no text body was extracted. Held as a dated publication from a named incident participant during the Coldcard-response week. The specific statement is carried by the attached media and is not independently verified here.\n",
      "relation": {
        "kind": "single-post",
        "head_id": null
      },
      "capture": {
        "status": "held",
        "artefact_count": 2,
        "conversation_copies": 0,
        "conversation_posts": 0,
        "conversation_replies": 0,
        "conversation_gaps": []
      }
    },
    {
      "id": "glxy-attacks-ease-losses-climb",
      "title": "COLDCARD ATTACKS EASE, BUT LOSSES CLIMB",
      "url": "https://x.com/glxyresearch/status/2088252639767085417",
      "author": "glxyresearch",
      "platform": "x",
      "organisation": "Galaxy Research",
      "posted": "2026-08-14T13:13:21Z",
      "role": "social-statement",
      "why_registered": "Galaxy Research updates its incident accounting to more than 1,778 BTC stolen, roughly $112 million, warns that attacks may still continue, and advises moving funds off COLDCARD devices. Held as a dated accounting update. The figures are Galaxy's own and are not independently verified here.\n",
      "relation": {
        "kind": "single-post",
        "head_id": null
      },
      "capture": {
        "status": "held",
        "artefact_count": 2,
        "conversation_copies": 0,
        "conversation_posts": 0,
        "conversation_replies": 0,
        "conversation_gaps": []
      }
    },
    {
      "id": "coletu-mk3-mk4-sweep-summary",
      "title": "Complete summary of honeypot sweep findings",
      "url": "https://x.com/coletu/status/2087506473123217436",
      "author": "coletu",
      "platform": "x",
      "organisation": null,
      "posted": "2026-08-12T11:48:21Z",
      "role": "social-statement",
      "why_registered": "ColeTU reports observed sweep timings for Mk3 seeds, random accounts, and one- to three-word passphrases, and notes that Mk4 seeds were not swept after six days. Held as a dated experimental finding from an external honeypot test. The timings are the author's own and are not independently verified here.\n",
      "relation": {
        "kind": "single-post",
        "head_id": null
      },
      "capture": {
        "status": "held",
        "artefact_count": 2,
        "conversation_copies": 0,
        "conversation_posts": 0,
        "conversation_replies": 0,
        "conversation_gaps": []
      }
    },
    {
      "id": "intangiblecoins-bloomberg-coldcard-interview",
      "title": "Bloomberg TV interview on the Coldcard exploit",
      "url": "https://x.com/intangiblecoins/status/2087226789122732059",
      "author": "intangiblecoins",
      "platform": "x",
      "organisation": null,
      "posted": "2026-08-11T17:16:59Z",
      "role": "social-statement",
      "why_registered": "Alex Thorn says he spoke to Bloomberg TV about the Coldcard exploit's blast radius, how victims are reacting, and what it means for Bitcoin culture and markets. Held as a dated media-appearance note. The interview content is not captured here.\n",
      "relation": {
        "kind": "single-post",
        "head_id": null
      },
      "capture": {
        "status": "held",
        "artefact_count": 2,
        "conversation_copies": 0,
        "conversation_posts": 0,
        "conversation_replies": 0,
        "conversation_gaps": []
      }
    },
    {
      "id": "jamesob-cktripwire-theft-frontier",
      "title": "cktripwire.com honeypot theft frontier update",
      "url": "https://x.com/jamesob/status/2087683189489779164",
      "author": "jamesob",
      "platform": "x",
      "organisation": null,
      "posted": "2026-08-12T23:30:34Z",
      "role": "social-statement",
      "why_registered": "James O'Beirne reports that attackers are working through cktripwire.com honeypots, places the theft frontier at 11 bits of added entropy, and notes that ColeTU's external honeypots have been swept and the first one-word passphrase UTXO is gone. Held as a dated technical update on the honeypot experiment. The claims are the author's own and are not independently verified here.\n",
      "relation": {
        "kind": "single-post",
        "head_id": null
      },
      "capture": {
        "status": "held",
        "artefact_count": 2,
        "conversation_copies": 0,
        "conversation_posts": 0,
        "conversation_replies": 0,
        "conversation_gaps": []
      }
    },
    {
      "id": "bitcoinnewscom-attacker-sweep-methods",
      "title": "Attacker had sophisticated intel but crude sweeping methods",
      "url": "https://x.com/bitcoinnewscom/status/2088017286217257049",
      "author": "bitcoinnewscom",
      "platform": "x",
      "organisation": "Bitcoin News",
      "posted": "2026-08-13T21:38:09Z",
      "role": "social-statement",
      "why_registered": "Bitcoin News summarizes Praveen Perera's research suggesting the attacker ranked vulnerable addresses by balance, swept them in batches, left UTXOs because of a default 200-record API limit, and left 75 BTC and 153 unreproduced addresses unexplained. Held as a dated technical finding. The claims are attributed to Perera and are not independently verified here.\n",
      "relation": {
        "kind": "single-post",
        "head_id": null
      },
      "capture": {
        "status": "held",
        "artefact_count": 2,
        "conversation_copies": 0,
        "conversation_posts": 0,
        "conversation_replies": 0,
        "conversation_gaps": []
      }
    },
    {
      "id": "intangiblecoins-multisig-no-documented-theft",
      "title": "No satoshi documented stolen from multisig",
      "url": "https://x.com/intangiblecoins/status/2087991980177625257",
      "author": "intangiblecoins",
      "platform": "x",
      "organisation": null,
      "posted": "2026-08-13T19:57:35Z",
      "role": "social-statement",
      "why_registered": "Alex Thorn argues that no satoshi has been documented as stolen from a multisig setup and urges non-technical users who want self-custody to look into collaborative multisig providers. Held as a dated self-custody and multisig argument. The claim is the author's own and is not independently verified here.\n",
      "relation": {
        "kind": "single-post",
        "head_id": null
      },
      "capture": {
        "status": "held",
        "artefact_count": 2,
        "conversation_copies": 0,
        "conversation_posts": 0,
        "conversation_replies": 0,
        "conversation_gaps": []
      }
    },
    {
      "id": "kami-gawa-mk4-reseed-security",
      "title": "Mk4 keys are not enumerable like Mk3 keys after reseed",
      "url": "https://x.com/_kami_gawa/status/2087888037568995583",
      "author": "_kami_gawa",
      "platform": "x",
      "organisation": null,
      "posted": "2026-08-13T13:04:33Z",
      "role": "social-statement",
      "why_registered": "@_kami_gawa reports that Mk4 keys are not enumerable like Mk3 keys because the reseed makes brute force practically impossible even when the resulting entropy is weak, and that correctly set up private keys remain effectively uncrackable. Held as a dated independent technical claim about Mk4 security. The claim is the author's own and are not independently verified here.\n",
      "relation": {
        "kind": "single-post",
        "head_id": null
      },
      "capture": {
        "status": "held",
        "artefact_count": 2,
        "conversation_copies": 0,
        "conversation_posts": 0,
        "conversation_replies": 0,
        "conversation_gaps": []
      }
    },
    {
      "id": "victim-rebuild-letter-912cff9b",
      "title": "nostr: pseudonymous victim's post-incident letter, relayed from X",
      "url": "https://njump.me/note1jyk0lxl27cf8c3c6ghtl57u8x0mmhpmjv7acvk76zmmahk0w9kdqrne45j",
      "author": "npub168u2cl8m4s9htdym5yref7tpkghw96lngc0d8cxqyc400f02sdjs3q68qx",
      "platform": "nostr",
      "organisation": "nostr",
      "posted": "2026-08-06T02:41:41Z",
      "role": "community",
      "why_registered": "The note's author concurs with and reproduces a letter from an anonymous X account claiming to have lost an entire bitcoin stack in the incident, presumably the largest single loss, after thirteen years of accumulation. A first-hand victim account as the intake criteria name it: the writer addresses other victims, the attacker and the Block team, and describes rebuilding. The loss claim and identity are unattributed and unverified here; the X original is not held.\n",
      "relation": {
        "kind": "single-post",
        "head_id": null
      },
      "capture": {
        "status": "held",
        "artefact_count": 1
      }
    },
    {
      "id": "nvk-2021-knowledge-inference-528c5ea0",
      "title": "nostr: inference that NVK's 2021 knowledge was the entropy bug",
      "url": "https://njump.me/note122x9agz9dnh8t93m0v9e0y47v5sx6g2vyhz92x3pwxt6zc6f09uqgpe0jv",
      "author": "npub1ak68qfcjj7k95c0jwleu69x72nr8adwv6g80pkwl9xlps6zmkqzqrxy8fx",
      "platform": "nostr",
      "organisation": "nostr",
      "posted": "2026-08-06T02:16:45Z",
      "role": "community",
      "why_registered": "A reply-thread argument that Coinkite's disclosure chronology, which says firmware 4.0.0 was never released, forces the conclusion that private knowledge alluded to by a third party in 2021 was the entropy bug rather than a USB flaw. A developed strand of the post-incident culpability debate, held as dated, attributed public interpretation; the inference is the author's own and is not verified here. Complements the registered reddit-nvk-awareness-critique discussion.\n",
      "relation": {
        "kind": "single-post",
        "head_id": null
      },
      "capture": {
        "status": "held",
        "artefact_count": 1
      }
    }
  ]
}
