MEMPOL!TICS
← BACK TO THE BOARD
MaximalistMON AUG 10 · Protos investigative · based on Aug 7 report

NVK IS DELETING X POSTS AS COLDCARD LOSSES TOP $130M — TWO OPERATOR RESPONSES TO BEING WRONG, ONE PRESERVES THE RECORD, ONE SCRUBS IT

"NVK is deleting tweets as we speak." — Alex Waltz, @raw_avocado. Peter Todd, Matt Kratter, Zach Herbert, Hodlonaut, Erin Malone all documented specific deletions this week. Coinkite is also alleged to have removed content from its historical-disclosures page. Losses from the entropy vulnerability now exceed $130M and climbing.
Protos ran the investigation on Aug 7. Coldcard co-founder Rodolfo Novak (NVK) is deleting posts from his personal X timeline while thefts from Coldcard customers exceeded $130 million. The vulnerability is entropy generation on the hardware wallet, active for five years, discovered by attackers roughly two weeks ago, still being exploited via brute-force key cracking today. The community that’s watching — Peter Todd, Matt Kratter, Zach Herbert of Foundation, Hodlonaut, Erin Malone, Alex Waltz, Greg Tonoski — has caught specific deletions on record.
THE DELETIONS ON RECORD Peter Todd, Aug 5: caught a Nov 2024 NVK post about a Blockclock knockoff being a possible ‘back door into peoples home network.’ Gone by mid-week. Todd’s phone cache preserved it. Zach Herbert (Foundation): ‘NVK is currently deleting old posts from 2020 to try to clean up the history. Screenshot them while you can. They will all be gone soon.’ Hodlonaut: preserved screenshot of NVK’s early ‘no need to panic’ response — NVK later admitted the post contained ‘wrong’ information he intended to correct. Greg Tonoski + Matt Kratter: alleged Coinkite removed an ‘Unnamed v.4.0.0 security issue’ entry from coinkite.com/historical-disclosures. Wayback Machine never archived that URL.
The framework contrast lands hard today. This afternoon Luke Dashjr and Bitcoin Mechanic both announced sabbaticals from OCEAN, two days after the BIP-110 fork attempt collapsed on Saturday. Two clean statements, thirty-six minutes apart, on the record. Losing well. Walking away with dignity. Preserving the archive of what they said and why. That’s the sovereignty tier’s response to being wrong. Meanwhile the wallet vendor whose product just lost customers $130M is deleting posts. Two operator responses to being wrong on record: one preserves the archive, the other scrubs it. The sovereignty tier can tell the difference.
WHAT SURVIVES THE PURGE The pinned apology stays. ‘I’m sorry and I’m devastated.’ The performance of accountability survives. Also surviving: an October 2021 Coldcard post declaring ‘Coldcard makes retirement attacks impossible’ — defined by the account itself as ‘when the project makers could have a bug in the entropy generation for later retrieval.’ The confidence that was wrong stays up. The technical documentation that documents the failure gets pruned. That’s the pattern Protos found.
The operator-class question isn’t whether the entropy bug was foreseeable. Bugs happen. RNGs are hard. Even the best hardware wallet vendors ship with vulnerabilities. The operator-class question is what you do when the vulnerability lands. Adam Back said it plainly on Cryptonews last week: ‘bugs happen — be it Coldcard, Trezor, Ledger.’ The Bitcoin operators watching this week are marking the response, not the bug. Coinkite’s response has been the pinned apology plus the quiet deletion of historical positions that look bad in hindsight. That’s not sovereignty-tier behavior. That’s corporate PR-tier behavior. The operators noticed.
One preserves the record.
One scrubs it.
The sovereignty tier can tell the difference.
Screenshot everything while you can.
READ THE PROTOS INVESTIGATION →
Protos · Aaron Wise · aug 7 · corroborated by @peterktodd, @zherbert, @mattkratter, @hodlonaut, @ErinEMalone