COLDCARD RNG incident the public record, collected and explained
Informational only, and this site never asks for your seed words. details

Informational only. This is an open source collection of what others have published about the incident, together with an explanation of it. It is not financial, security or legal advice, and not a substitute for professional advice about your own situation. It is not affiliated with, endorsed by, or speaking for Coinkite. Material is attributed and quoted as published; where sources disagree their scenarios are kept separate with their assumptions rather than reconciled into one answer. Everything is meant to be checked against the linked evidence rather than taken on trust. Act on your own judgement about a particular situation. Editorial standards and corrections.

Do not disclose recovery material to a website, form, message or support account. This site never asks for it, and contributions containing recovery words or private keys are not accepted.

Possible all Bitcoin Hardware Wallets be hacked due to 'Trust in Device Entropy?

bitcointalk-device-entropy-trust

https://bitcointalk.org/index.php?topic=5590481.0

Latest reviewed change

source content difference between and

A new post argued that entropy hardware should be isolated from firmware updates because buggy software can compromise even high-grade randomness generators.

seen +3 -0 full history below
 As far as I know that was never the intended design, otherwise it would be a really bad design for something that is designed to be very secure, they intended to use hardware TRNG by disabling MICROPHY_HW_ENABLE_RNG to 0 but MicroPhyton is falling back to use inferior software PRNG. They thought the MicroPython fallback didn't exist.
 Quote from: https://blog.coinkite.com/entropy-technical-backgrounder/
 The bulk of randomness on the COLDCARD was coming from a PRNG that I didn�t know was actually in the source code base (it is from a submodule, Micropython). At the same time the carefully crafted TRNG code I wrote was being used, but just by chance, and only for less important things.
+Title: Re: Possible all Bitcoin Hardware Wallets be hacked due to 'Trust in Device Entropy?
+Post by: dim_mak5 on August 09, 2026, 01:09:14 AM
+The Entropy hardware chip should be Isolated from firmware updates because buggy firmware/software updates can compromise the entropy randomness of the chip correct? For example you can have the state of the art military grade 1zillion bit entropy randomness generator hardware chip that took $billions in R&D that can be ruined compromised by a slave wage below minimum wage low paid cheap programmer in India working 20hr shifts in the software team releasing a buggy firmware update because the hardware wallet company want to cut operation costs to appease their shareholders.
 Powered by SMF 1.1.19 |
 SMF © 2006-2009, Simple Machines
Organisation
BitcoinTalk
Evidence role
Community discussion
Published
2026-08-06
Source changes
3
Detected differences
3
Unreviewed
0
Copies held
4

dim_mak5 asking how holders can verify, rather than trust, the entropy of any hardware wallet, framing the COLDCARD hack as proof of the problem and ranging into quantum, AI and confiscation speculation. Replies point to user-generated seeds and to the registered bitcointalk-entropy-warning-design discussion. An entropy-verifiability debate the incident triggered on the Bitcoin Discussion board. The claims and speculation are the posters' own, not verified here.

Every check is recorded, including checks that found no text change. A detected edit is therefore bounded between two checks. The publisher's exact save time is not observable from this record. Last checked .

  1. source content difference between and Current source content +3 -0

    A new post argued that entropy hardware should be isolated from firmware updates because buggy software can compromise even high-grade randomness generators.

    seen · Captured here 39,005 chars
    What changed from the previous capture 3 lines
     As far as I know that was never the intended design, otherwise it would be a really bad design for something that is designed to be very secure, they intended to use hardware TRNG by disabling MICROPHY_HW_ENABLE_RNG to 0 but MicroPhyton is falling back to use inferior software PRNG. They thought the MicroPython fallback didn't exist.
     Quote from: https://blog.coinkite.com/entropy-technical-backgrounder/
     The bulk of randomness on the COLDCARD was coming from a PRNG that I didn�t know was actually in the source code base (it is from a submodule, Micropython). At the same time the carefully crafted TRNG code I wrote was being used, but just by chance, and only for less important things.
    +Title: Re: Possible all Bitcoin Hardware Wallets be hacked due to 'Trust in Device Entropy?
    +Post by: dim_mak5 on August 09, 2026, 01:09:14 AM
    +The Entropy hardware chip should be Isolated from firmware updates because buggy firmware/software updates can compromise the entropy randomness of the chip correct? For example you can have the state of the art military grade 1zillion bit entropy randomness generator hardware chip that took $billions in R&D that can be ruined compromised by a slave wage below minimum wage low paid cheap programmer in India working 20hr shifts in the software team releasing a buggy firmware update because the hardware wallet company want to cut operation costs to appease their shareholders.
     Powered by SMF 1.1.19 |
     SMF © 2006-2009, Simple Machines
    
    Extracted text as captured
    Bitcoin Forum
    Bitcoin => Bitcoin Discussion => Topic started by: dim_mak5 on August 05, 2026, 07:55:23 PM
    Title: Possible all Bitcoin Hardware Wallets be hacked due to 'Trust in Device Entropy?
    Post by: dim_mak5 on August 05, 2026, 07:55:23 PM
    Hello,
    Bitcoiners are told the main motto/slogan is Verify not Trust.
    How the hell do Bitcoiners verify that their hardware wallet device has proper Entropy (Randomness) instead of trusting the manufacturers claims? Manufacturers care about profit so they not going to use proper hardware entropy chips in their devices that cost a lot of money and instead use cheaper software entropy. Its kinda like buying a so called gaming pc with no graphics GPU and your running games through software cpu that is slow and laggy not smooth and looks shite or instead they use cheap hardware emulation via software emulation or whatever due to hardware licensing issues or whatever excuses these manufacturers come up with.
    I find it hard to believe that a single $50-100 hardware wallet device can safely self custody a bitcoin wallet address worth $1 Trillion. There has to be a catch somewhere. Or is the catch no insurance, not insured for BTC losses?
    The ColdCard hardware wallet hack is nothing compare to Quantum computers. If human hackers can do hacks like this today without quantum computers and with assistance from Ai then imagine what Ai hack bots can do when Ai gets quantum computers to find vulnerabilities in Entropy chips in older hardware wallets instead of brute forcing 12 or 24 words :o
    For example can anyone confirm that the first Ledger & Trezor hardware wallets will be safe from Entropy vulnerabilities in 50 years time or even in 5 years time?
    Hardware manufacturers should be banned from selling hardware wallets unless they offer insurance. This of course will increase prices hardware wallets to much higher but if your securing a $Trillion dollars worth of bitcoin then a good hardware wallet with a proper fast hardware Entropy chip costing $1000 or $10000 is worth the investment right but then again Satoshi said Bitcoin is for everyone and not everyone can afford $1000 hardware wallets.
    Governments want people to store their bitcoin on centralized exchanges so governments can easily confiscate people bitcoin so governments are going to attack the hardware wallet entropy of bitcoin to persuade people not to self custody. Blackrock dont want hodlers to self custody Bitcoin so they are investing $Billions in hacking Entropy chips.
    There will replies saying trust and open-source code can be verified but which experienced knowledgeable programmers out there is going to spend their time manually looking through 1000s lines of codes to spot 1 mistake/vulnerability? As of now Ai Hackers have the edge over Ai Audits because Ai audits are not jailbroken like Ai hackers and Ai hackers are always 1 step ahead while Ai audits are playing catch up always 1 step behind.
    Lastly why the hell Btc hodlers are paying money to roll dices? They paid money for a hardware device to do the dice rolling randomness for them so a hardware wallet manufacturer selling devices that includes dices to tell their customers to roll a dice is a huge red flag because it clearly says our software entropy in your hardware wallet device is useless or we used a cheap hardware entropy chip that is useless too so you have better security by rolling dices yourselves.
    Finally when there is firmware update for the hardware wallet then how do hodlers verify that is not a software update to improve the security of the software entropy and instead it is an actual update for the hardware chip in the hardware wallet?
    This is insanity, bitcoin cannot be the global money until this fundamental problem is fixed unless you see bitcoin as global money custodied by Blackrock wall street and governments who are happy to hold your btc for you for free like a bank ::)
    Title: Re: Possible all Bitcoin Hardware Wallets be hacked due to 'Trust in Device Entropy?
    Post by: Zaguru12 on August 05, 2026, 08:17:26 PM
    Quote from: dim_mak5 on August 05, 2026, 07:55:23 PM
    How the hell do Bitcoiners verify that their hardware wallet device has proper Entropy (Randomness) instead of trusting the manufacturers claims? Manufacturers care about profit so they not going to use proper hardware entropy chips in their devices that cost a lot of money and instead use cheaper software entropy. Its kinda like buying a so called gaming pc with no graphics GPU and your running games through software cpu that is slow and laggy not smooth and looks shite or instead they use cheap hardware emulation via software emulation or whatever due to hardware licensing issues or whatever excuses these manufacturers come up with.
    The thing is even the manufacturers do not know how random your seed phrase was generated because it�s the underlying software that does this mathematical calculations. My straight answer is even if hardware wallets say they are random but you do not believe them, simply just generate your own seed phrase either with dice or other software you trust then proceed to add extended words (Passphrase).
    There is an ongoing discussion about why this wallets cannot even identify their own randomness here https://bitcointalk.org/index.php?topic=5590329.msg67010210#msg67010210 (https://bitcointalk.org/index.php?topic=5590329.msg67010210#msg67010210)
    Quote
    Hardware manufacturers should be banned from selling hardware wallets unless they offer insurance. This of course will increase prices hardware wallets to much higher but if your securing a $Trillion dollars worth of bitcoin then a good hardware wallet with a proper fast hardware Entropy chip costing $1000 or $10000 is worth the investment right but then again Satoshi said Bitcoin is for everyone and not everyone can afford $1000 hardware wallets.
    Do you know hardware wallets are simply part of self custody, self custody means you are taking junk of the risk alone. So I don�t understand why you even blame Satoshi for something you want them to implement which is insurance, the exact example you give is the reason why bitcoin is for everyone. If someone has $1trillion then $1k is cheap to and then if they don�t have such high amount it�s not worth it and that�s why bitcoin is for eveyone
    For me if you want insurance you definitely have to use centralized platforms like exchange or ETF not actually claiming to be your own self custody and wants insurance. Although due to some negligence I understand your point but hardware wallets running on insurance have the right to ask for your seed phrase as a security feature which is bad
    Title: Re: Possible all Bitcoin Hardware Wallets be hacked due to 'Trust in Device Entropy?
    Post by: CryptoBuds on August 05, 2026, 08:48:55 PM
    Quote from: dim_mak5 on August 05, 2026, 07:55:23 PM
    Bitcoiners are told the main motto/slogan is Verify not Trust.
    How the hell do Bitcoiners verify that their hardware wallet device has proper Entropy (Randomness) instead of trusting the manufacturers claims? Manufacturers care about profit so they not going to use proper hardware entropy chips in their devices that cost a lot of money and instead use cheaper software entropy. Its kinda like buying a so called gaming pc with no graphics GPU and your running games through software cpu that is slow and laggy not smooth and looks shite or instead they use cheap hardware emulation via software emulation or whatever due to hardware licensing issues or whatever excuses these manufacturers come up with.
    I find it hard to believe that a single $50-100 hardware wallet device can safely self custody a bitcoin wallet address worth $1 Trillion. There has to be a catch somewhere. Or is the catch no insurance, not insured for BTC losses?
    Verify, don't trust, doesn't mean I have to test every transistor on a hardware wallet myself. Verification in Bitcoin is a spectrum, that mean verification exists on a spectrum. You need to minimize trust by combining source code, deterministic build, firmware signature, reproducible build, BIP-39 compatibility, open review and your own operational security. You can never eliminate trust completely. Using hardware means there will be some trust assumptions.
    Title: Re: Possible all Bitcoin Hardware Wallets be hacked due to 'Trust in Device Entropy?
    Post by: un_rank on August 05, 2026, 09:06:29 PM
    Quote from: dim_mak5 on August 05, 2026, 07:55:23 PM
    I find it hard to believe that a single $50-100 hardware wallet device can safely self custody a bitcoin wallet address worth $1 Trillion. There has to be a catch somewhere. Or is the catch no insurance, not insured for BTC losses?
    A paper wallet is free and it can safely store all the bitcoins that are in circulation with no hitches, every other security precaution you can apply like multi signatures and passphrase are all also free. You're thinking so much interest of the conventional financial system which is why you're looking for an insurance.
    Quote from: dim_mak5 on August 05, 2026, 07:55:23 PM
    Hardware manufacturers should be banned from selling hardware wallets unless they offer insurance. This of course will increase prices hardware wallets to much higher but if your securing a $Trillion dollars worth of bitcoin then a good hardware wallet with a proper fast hardware Entropy chip costing $1000 or $10000 is worth the investment right but then again Satoshi said Bitcoin is for everyone and not everyone can afford $1000 hardware wallets.

    Excerpt only. The complete copy is held offline and backs quotations on this site. The original publication remains the canonical public source.

  2. source content difference between and source content +7 -0

    The thread gained a new post quoting Coinkite's entropy technical backgrounder about the MicroPython software PRNG fallback.

    seen · Captured here 38,282 chars
    What changed from the previous capture 7 lines
     Also Hardware Wallets should not have a back up built in software entropy randomness generator if the hardware entropy chip in the hardware wallet fails. Also firmware software updates should be isolated from the software entropy generator as a simple bug in the code in the update could compromise the software entropy generator.
     What's the point of a hardware wallet when it uses software for entropy  ??? ???. Why call it hardware when its really a cheap software? Coldcard should have called their wallet a hardware/software hybrid wallet They misled their customers.
     Indeed, the susceptibility of the physical randomness chip is also true risk on it is own. It is exactly to avoid the single point of failure in the electronic elements that a hybrid software based approach is used. The name physical wallet does not lose its validity by the fact that its main purpose is not process algorithms but to isolated offline transactions. The alternative of randomization of dice separately has shown to be a workable solution in the dissolution of doubts in tampering with inner codes.
    +Title: Re: Possible all Bitcoin Hardware Wallets be hacked due to 'Trust in Device Entropy?
    +Post by: shinratensei_ on August 08, 2026, 03:40:01 AM
    +Quote from: dim_mak5 on August 07, 2026, 10:44:02 PM
    +Also Hardware Wallets should not have a back up built in software entropy randomness generator if the hardware entropy chip in the hardware wallet fails.
    +As far as I know that was never the intended design, otherwise it would be a really bad design for something that is designed to be very secure, they intended to use hardware TRNG by disabling MICROPHY_HW_ENABLE_RNG to 0 but MicroPhyton is falling back to use inferior software PRNG. They thought the MicroPython fallback didn't exist.
    +Quote from: https://blog.coinkite.com/entropy-technical-backgrounder/
    +The bulk of randomness on the COLDCARD was coming from a PRNG that I didn�t know was actually in the source code base (it is from a submodule, Micropython). At the same time the carefully crafted TRNG code I wrote was being used, but just by chance, and only for less important things.
     Powered by SMF 1.1.19 |
     SMF © 2006-2009, Simple Machines
    
    Extracted text as captured
    Bitcoin Forum
    Bitcoin => Bitcoin Discussion => Topic started by: dim_mak5 on August 05, 2026, 07:55:23 PM
    Title: Possible all Bitcoin Hardware Wallets be hacked due to 'Trust in Device Entropy?
    Post by: dim_mak5 on August 05, 2026, 07:55:23 PM
    Hello,
    Bitcoiners are told the main motto/slogan is Verify not Trust.
    How the hell do Bitcoiners verify that their hardware wallet device has proper Entropy (Randomness) instead of trusting the manufacturers claims? Manufacturers care about profit so they not going to use proper hardware entropy chips in their devices that cost a lot of money and instead use cheaper software entropy. Its kinda like buying a so called gaming pc with no graphics GPU and your running games through software cpu that is slow and laggy not smooth and looks shite or instead they use cheap hardware emulation via software emulation or whatever due to hardware licensing issues or whatever excuses these manufacturers come up with.
    I find it hard to believe that a single $50-100 hardware wallet device can safely self custody a bitcoin wallet address worth $1 Trillion. There has to be a catch somewhere. Or is the catch no insurance, not insured for BTC losses?
    The ColdCard hardware wallet hack is nothing compare to Quantum computers. If human hackers can do hacks like this today without quantum computers and with assistance from Ai then imagine what Ai hack bots can do when Ai gets quantum computers to find vulnerabilities in Entropy chips in older hardware wallets instead of brute forcing 12 or 24 words :o
    For example can anyone confirm that the first Ledger & Trezor hardware wallets will be safe from Entropy vulnerabilities in 50 years time or even in 5 years time?
    Hardware manufacturers should be banned from selling hardware wallets unless they offer insurance. This of course will increase prices hardware wallets to much higher but if your securing a $Trillion dollars worth of bitcoin then a good hardware wallet with a proper fast hardware Entropy chip costing $1000 or $10000 is worth the investment right but then again Satoshi said Bitcoin is for everyone and not everyone can afford $1000 hardware wallets.
    Governments want people to store their bitcoin on centralized exchanges so governments can easily confiscate people bitcoin so governments are going to attack the hardware wallet entropy of bitcoin to persuade people not to self custody. Blackrock dont want hodlers to self custody Bitcoin so they are investing $Billions in hacking Entropy chips.
    There will replies saying trust and open-source code can be verified but which experienced knowledgeable programmers out there is going to spend their time manually looking through 1000s lines of codes to spot 1 mistake/vulnerability? As of now Ai Hackers have the edge over Ai Audits because Ai audits are not jailbroken like Ai hackers and Ai hackers are always 1 step ahead while Ai audits are playing catch up always 1 step behind.
    Lastly why the hell Btc hodlers are paying money to roll dices? They paid money for a hardware device to do the dice rolling randomness for them so a hardware wallet manufacturer selling devices that includes dices to tell their customers to roll a dice is a huge red flag because it clearly says our software entropy in your hardware wallet device is useless or we used a cheap hardware entropy chip that is useless too so you have better security by rolling dices yourselves.
    Finally when there is firmware update for the hardware wallet then how do hodlers verify that is not a software update to improve the security of the software entropy and instead it is an actual update for the hardware chip in the hardware wallet?
    This is insanity, bitcoin cannot be the global money until this fundamental problem is fixed unless you see bitcoin as global money custodied by Blackrock wall street and governments who are happy to hold your btc for you for free like a bank ::)
    Title: Re: Possible all Bitcoin Hardware Wallets be hacked due to 'Trust in Device Entropy?
    Post by: Zaguru12 on August 05, 2026, 08:17:26 PM
    Quote from: dim_mak5 on August 05, 2026, 07:55:23 PM
    How the hell do Bitcoiners verify that their hardware wallet device has proper Entropy (Randomness) instead of trusting the manufacturers claims? Manufacturers care about profit so they not going to use proper hardware entropy chips in their devices that cost a lot of money and instead use cheaper software entropy. Its kinda like buying a so called gaming pc with no graphics GPU and your running games through software cpu that is slow and laggy not smooth and looks shite or instead they use cheap hardware emulation via software emulation or whatever due to hardware licensing issues or whatever excuses these manufacturers come up with.
    The thing is even the manufacturers do not know how random your seed phrase was generated because it�s the underlying software that does this mathematical calculations. My straight answer is even if hardware wallets say they are random but you do not believe them, simply just generate your own seed phrase either with dice or other software you trust then proceed to add extended words (Passphrase).
    There is an ongoing discussion about why this wallets cannot even identify their own randomness here https://bitcointalk.org/index.php?topic=5590329.msg67010210#msg67010210 (https://bitcointalk.org/index.php?topic=5590329.msg67010210#msg67010210)
    Quote
    Hardware manufacturers should be banned from selling hardware wallets unless they offer insurance. This of course will increase prices hardware wallets to much higher but if your securing a $Trillion dollars worth of bitcoin then a good hardware wallet with a proper fast hardware Entropy chip costing $1000 or $10000 is worth the investment right but then again Satoshi said Bitcoin is for everyone and not everyone can afford $1000 hardware wallets.
    Do you know hardware wallets are simply part of self custody, self custody means you are taking junk of the risk alone. So I don�t understand why you even blame Satoshi for something you want them to implement which is insurance, the exact example you give is the reason why bitcoin is for everyone. If someone has $1trillion then $1k is cheap to and then if they don�t have such high amount it�s not worth it and that�s why bitcoin is for eveyone
    For me if you want insurance you definitely have to use centralized platforms like exchange or ETF not actually claiming to be your own self custody and wants insurance. Although due to some negligence I understand your point but hardware wallets running on insurance have the right to ask for your seed phrase as a security feature which is bad
    Title: Re: Possible all Bitcoin Hardware Wallets be hacked due to 'Trust in Device Entropy?
    Post by: CryptoBuds on August 05, 2026, 08:48:55 PM
    Quote from: dim_mak5 on August 05, 2026, 07:55:23 PM
    Bitcoiners are told the main motto/slogan is Verify not Trust.
    How the hell do Bitcoiners verify that their hardware wallet device has proper Entropy (Randomness) instead of trusting the manufacturers claims? Manufacturers care about profit so they not going to use proper hardware entropy chips in their devices that cost a lot of money and instead use cheaper software entropy. Its kinda like buying a so called gaming pc with no graphics GPU and your running games through software cpu that is slow and laggy not smooth and looks shite or instead they use cheap hardware emulation via software emulation or whatever due to hardware licensing issues or whatever excuses these manufacturers come up with.
    I find it hard to believe that a single $50-100 hardware wallet device can safely self custody a bitcoin wallet address worth $1 Trillion. There has to be a catch somewhere. Or is the catch no insurance, not insured for BTC losses?
    Verify, don't trust, doesn't mean I have to test every transistor on a hardware wallet myself. Verification in Bitcoin is a spectrum, that mean verification exists on a spectrum. You need to minimize trust by combining source code, deterministic build, firmware signature, reproducible build, BIP-39 compatibility, open review and your own operational security. You can never eliminate trust completely. Using hardware means there will be some trust assumptions.
    Title: Re: Possible all Bitcoin Hardware Wallets be hacked due to 'Trust in Device Entropy?
    Post by: un_rank on August 05, 2026, 09:06:29 PM
    Quote from: dim_mak5 on August 05, 2026, 07:55:23 PM
    I find it hard to believe that a single $50-100 hardware wallet device can safely self custody a bitcoin wallet address worth $1 Trillion. There has to be a catch somewhere. Or is the catch no insurance, not insured for BTC losses?
    A paper wallet is free and it can safely store all the bitcoins that are in circulation with no hitches, every other security precaution you can apply like multi signatures and passphrase are all also free. You're thinking so much interest of the conventional financial system which is why you're looking for an insurance.
    Quote from: dim_mak5 on August 05, 2026, 07:55:23 PM
    Hardware manufacturers should be banned from selling hardware wallets unless they offer insurance. This of course will increase prices hardware wallets to much higher but if your securing a $Trillion dollars worth of bitcoin then a good hardware wallet with a proper fast hardware Entropy chip costing $1000 or $10000 is worth the investment right but then again Satoshi said Bitcoin is for everyone and not everyone can afford $1000 hardware wallets.

    Excerpt only. The complete copy is held offline and backs quotations on this site. The original publication remains the canonical public source.

  3. source content difference between and source content +21 -1

    The thread gained new posts arguing hardware wallets mislead customers by using software entropy and speculating about Wall Street-backed wallets, plus a reply defending hybrid software approaches.

    seen · Captured here 37,236 chars
    What changed from the previous capture 22 lines
     The insurance isn't foolproof solution, it's always better if you can take care your things than depending on insurance but in case you need one, understand the clause.
     Title: Re: Possible all Bitcoin Hardware Wallets be hacked due to 'Trust in Device Entropy?
     Post by: BlackBoss_ on August 07, 2026, 05:02:11 AM
    -Quote from: X-ray on Today at 03:49:34 AM
    +Quote from: X-ray on August 07, 2026, 03:49:34 AM
     If you ever thinking of one, be sure to do your extensive research about what losses they cover and properly learn about how to file a claim so that you don't give them free money for nothing.
     Crypto insurance that covers holding often exclude the real risk that people usually face like phishing, social engineering, or even pure technical defects which in this case might very well be referred to incident like Coldcard.
     The insurance isn't foolproof solution, it's always better if you can take care your things than depending on insurance but in case you need one, understand the clause.
     https://en.wikipedia.org/wiki/Enron
     https://en.wikipedia.org/wiki/Enron
     Bitcoin is designed to give everyone private keys that have very strong security, so they just have to find a good Bitcoin wallet to use and secure their wallets as well as their bitcoins by themselves.
    +Title: Re: Possible all Bitcoin Hardware Wallets be hacked due to 'Trust in Device Entropy?
    +Post by: dim_mak5 on August 07, 2026, 10:09:06 PM
    +I have a feeling BlackRock Wall Street in the near future is going to fund a new hardware wallet company and release a new closed source hardware btc wallet that is so called 'Government Approved' that is insured up to max 0.1 BTC for retail customers and 1 BTC for commercial customers kinda like FDIC insurance because they can afford to. Only by doing this they can trick the nearly all btc hodlers to give up self custody. They will try to corner the bitcoin hardware wallet and be like like Iphone in the cell phone market.
    +They will sponsor most of the hacks to get hodlers to fear self custody.
    +True Entropy is suppose to be more random that the lottery number being drawn out.
    +Can anyone confirm whether existing hardware wallets entropy will still be secure in 5-10 years time? Never mind quantum computers.
    +I still cant understand someone paying money for a hardware wallet for Entropy yet still expect to roll the dice for added randomness is insane. It is like paying for a cheeseburger but buying your own cheese slice and adding it in yourself in the burger. The customers paid for Entropy so why they rolling the dice? The hardware wallet manufacturers are implying are entropy chips are not as good as your old fashioned dice rolling?
    +What if wall st sponsored hackers or Ai hackers figured out the randomness of lets say Ledger and Trezor devices and most BTC in cold storage gets hacked.
    +Why Michael Saylor not stash any of his bitcoins in a hardware wallet and instead use a third party insured Custodian like Coinbase?
    +Satoshi Wallet that has a million bitcoins in it, that must be truly random generated as it hasn't been hacked yet. What randomness Entropy Satoshi used?
    +Title: Re: Possible all Bitcoin Hardware Wallets be hacked due to 'Trust in Device Entropy?
    +Post by: dim_mak5 on August 07, 2026, 10:44:02 PM
    +Also Hardware Wallets should not have a back up built in software entropy randomness generator if the hardware entropy chip in the hardware wallet fails. Also firmware software updates should be isolated from the software entropy generator as a simple bug in the code in the update could compromise the software entropy generator.
    +What's the point of a hardware wallet when it uses software for entropy  ??? ???. Why call it hardware when its really a cheap software? Coldcard should have called their wallet a hardware/software hybrid wallet They misled their customers.
    +Title: Re: Possible all Bitcoin Hardware Wallets be hacked due to 'Trust in Device Entropy?
    +Post by: lombok on August 07, 2026, 11:57:28 PM
    +Quote from: dim_mak5 on August 07, 2026, 10:44:02 PM
    +Also Hardware Wallets should not have a back up built in software entropy randomness generator if the hardware entropy chip in the hardware wallet fails. Also firmware software updates should be isolated from the software entropy generator as a simple bug in the code in the update could compromise the software entropy generator.
    +What's the point of a hardware wallet when it uses software for entropy  ??? ???. Why call it hardware when its really a cheap software? Coldcard should have called their wallet a hardware/software hybrid wallet They misled their customers.
    +Indeed, the susceptibility of the physical randomness chip is also true risk on it is own. It is exactly to avoid the single point of failure in the electronic elements that a hybrid software based approach is used. The name physical wallet does not lose its validity by the fact that its main purpose is not process algorithms but to isolated offline transactions. The alternative of randomization of dice separately has shown to be a workable solution in the dissolution of doubts in tampering with inner codes.
     Powered by SMF 1.1.19 |
     SMF © 2006-2009, Simple Machines
    
    Extracted text as captured
    Bitcoin Forum
    Bitcoin => Bitcoin Discussion => Topic started by: dim_mak5 on August 05, 2026, 07:55:23 PM
    Title: Possible all Bitcoin Hardware Wallets be hacked due to 'Trust in Device Entropy?
    Post by: dim_mak5 on August 05, 2026, 07:55:23 PM
    Hello,
    Bitcoiners are told the main motto/slogan is Verify not Trust.
    How the hell do Bitcoiners verify that their hardware wallet device has proper Entropy (Randomness) instead of trusting the manufacturers claims? Manufacturers care about profit so they not going to use proper hardware entropy chips in their devices that cost a lot of money and instead use cheaper software entropy. Its kinda like buying a so called gaming pc with no graphics GPU and your running games through software cpu that is slow and laggy not smooth and looks shite or instead they use cheap hardware emulation via software emulation or whatever due to hardware licensing issues or whatever excuses these manufacturers come up with.
    I find it hard to believe that a single $50-100 hardware wallet device can safely self custody a bitcoin wallet address worth $1 Trillion. There has to be a catch somewhere. Or is the catch no insurance, not insured for BTC losses?
    The ColdCard hardware wallet hack is nothing compare to Quantum computers. If human hackers can do hacks like this today without quantum computers and with assistance from Ai then imagine what Ai hack bots can do when Ai gets quantum computers to find vulnerabilities in Entropy chips in older hardware wallets instead of brute forcing 12 or 24 words :o
    For example can anyone confirm that the first Ledger & Trezor hardware wallets will be safe from Entropy vulnerabilities in 50 years time or even in 5 years time?
    Hardware manufacturers should be banned from selling hardware wallets unless they offer insurance. This of course will increase prices hardware wallets to much higher but if your securing a $Trillion dollars worth of bitcoin then a good hardware wallet with a proper fast hardware Entropy chip costing $1000 or $10000 is worth the investment right but then again Satoshi said Bitcoin is for everyone and not everyone can afford $1000 hardware wallets.
    Governments want people to store their bitcoin on centralized exchanges so governments can easily confiscate people bitcoin so governments are going to attack the hardware wallet entropy of bitcoin to persuade people not to self custody. Blackrock dont want hodlers to self custody Bitcoin so they are investing $Billions in hacking Entropy chips.
    There will replies saying trust and open-source code can be verified but which experienced knowledgeable programmers out there is going to spend their time manually looking through 1000s lines of codes to spot 1 mistake/vulnerability? As of now Ai Hackers have the edge over Ai Audits because Ai audits are not jailbroken like Ai hackers and Ai hackers are always 1 step ahead while Ai audits are playing catch up always 1 step behind.
    Lastly why the hell Btc hodlers are paying money to roll dices? They paid money for a hardware device to do the dice rolling randomness for them so a hardware wallet manufacturer selling devices that includes dices to tell their customers to roll a dice is a huge red flag because it clearly says our software entropy in your hardware wallet device is useless or we used a cheap hardware entropy chip that is useless too so you have better security by rolling dices yourselves.
    Finally when there is firmware update for the hardware wallet then how do hodlers verify that is not a software update to improve the security of the software entropy and instead it is an actual update for the hardware chip in the hardware wallet?
    This is insanity, bitcoin cannot be the global money until this fundamental problem is fixed unless you see bitcoin as global money custodied by Blackrock wall street and governments who are happy to hold your btc for you for free like a bank ::)
    Title: Re: Possible all Bitcoin Hardware Wallets be hacked due to 'Trust in Device Entropy?
    Post by: Zaguru12 on August 05, 2026, 08:17:26 PM
    Quote from: dim_mak5 on August 05, 2026, 07:55:23 PM
    How the hell do Bitcoiners verify that their hardware wallet device has proper Entropy (Randomness) instead of trusting the manufacturers claims? Manufacturers care about profit so they not going to use proper hardware entropy chips in their devices that cost a lot of money and instead use cheaper software entropy. Its kinda like buying a so called gaming pc with no graphics GPU and your running games through software cpu that is slow and laggy not smooth and looks shite or instead they use cheap hardware emulation via software emulation or whatever due to hardware licensing issues or whatever excuses these manufacturers come up with.
    The thing is even the manufacturers do not know how random your seed phrase was generated because it�s the underlying software that does this mathematical calculations. My straight answer is even if hardware wallets say they are random but you do not believe them, simply just generate your own seed phrase either with dice or other software you trust then proceed to add extended words (Passphrase).
    There is an ongoing discussion about why this wallets cannot even identify their own randomness here https://bitcointalk.org/index.php?topic=5590329.msg67010210#msg67010210 (https://bitcointalk.org/index.php?topic=5590329.msg67010210#msg67010210)
    Quote
    Hardware manufacturers should be banned from selling hardware wallets unless they offer insurance. This of course will increase prices hardware wallets to much higher but if your securing a $Trillion dollars worth of bitcoin then a good hardware wallet with a proper fast hardware Entropy chip costing $1000 or $10000 is worth the investment right but then again Satoshi said Bitcoin is for everyone and not everyone can afford $1000 hardware wallets.
    Do you know hardware wallets are simply part of self custody, self custody means you are taking junk of the risk alone. So I don�t understand why you even blame Satoshi for something you want them to implement which is insurance, the exact example you give is the reason why bitcoin is for everyone. If someone has $1trillion then $1k is cheap to and then if they don�t have such high amount it�s not worth it and that�s why bitcoin is for eveyone
    For me if you want insurance you definitely have to use centralized platforms like exchange or ETF not actually claiming to be your own self custody and wants insurance. Although due to some negligence I understand your point but hardware wallets running on insurance have the right to ask for your seed phrase as a security feature which is bad
    Title: Re: Possible all Bitcoin Hardware Wallets be hacked due to 'Trust in Device Entropy?
    Post by: CryptoBuds on August 05, 2026, 08:48:55 PM
    Quote from: dim_mak5 on August 05, 2026, 07:55:23 PM
    Bitcoiners are told the main motto/slogan is Verify not Trust.
    How the hell do Bitcoiners verify that their hardware wallet device has proper Entropy (Randomness) instead of trusting the manufacturers claims? Manufacturers care about profit so they not going to use proper hardware entropy chips in their devices that cost a lot of money and instead use cheaper software entropy. Its kinda like buying a so called gaming pc with no graphics GPU and your running games through software cpu that is slow and laggy not smooth and looks shite or instead they use cheap hardware emulation via software emulation or whatever due to hardware licensing issues or whatever excuses these manufacturers come up with.
    I find it hard to believe that a single $50-100 hardware wallet device can safely self custody a bitcoin wallet address worth $1 Trillion. There has to be a catch somewhere. Or is the catch no insurance, not insured for BTC losses?
    Verify, don't trust, doesn't mean I have to test every transistor on a hardware wallet myself. Verification in Bitcoin is a spectrum, that mean verification exists on a spectrum. You need to minimize trust by combining source code, deterministic build, firmware signature, reproducible build, BIP-39 compatibility, open review and your own operational security. You can never eliminate trust completely. Using hardware means there will be some trust assumptions.
    Title: Re: Possible all Bitcoin Hardware Wallets be hacked due to 'Trust in Device Entropy?
    Post by: un_rank on August 05, 2026, 09:06:29 PM
    Quote from: dim_mak5 on August 05, 2026, 07:55:23 PM
    I find it hard to believe that a single $50-100 hardware wallet device can safely self custody a bitcoin wallet address worth $1 Trillion. There has to be a catch somewhere. Or is the catch no insurance, not insured for BTC losses?
    A paper wallet is free and it can safely store all the bitcoins that are in circulation with no hitches, every other security precaution you can apply like multi signatures and passphrase are all also free. You're thinking so much interest of the conventional financial system which is why you're looking for an insurance.
    Quote from: dim_mak5 on August 05, 2026, 07:55:23 PM
    Hardware manufacturers should be banned from selling hardware wallets unless they offer insurance. This of course will increase prices hardware wallets to much higher but if your securing a $Trillion dollars worth of bitcoin then a good hardware wallet with a proper fast hardware Entropy chip costing $1000 or $10000 is worth the investment right but then again Satoshi said Bitcoin is for everyone and not everyone can afford $1000 hardware wallets.

    Excerpt only. The complete copy is held offline and backs quotations on this site. The original publication remains the canonical public source.

  4. Earliest copy held
    seen · Captured here 33,400 chars
    Extracted text as captured
    Bitcoin Forum
    Bitcoin => Bitcoin Discussion => Topic started by: dim_mak5 on August 05, 2026, 07:55:23 PM
    Title: Possible all Bitcoin Hardware Wallets be hacked due to 'Trust in Device Entropy?
    Post by: dim_mak5 on August 05, 2026, 07:55:23 PM
    Hello,
    Bitcoiners are told the main motto/slogan is Verify not Trust.
    How the hell do Bitcoiners verify that their hardware wallet device has proper Entropy (Randomness) instead of trusting the manufacturers claims? Manufacturers care about profit so they not going to use proper hardware entropy chips in their devices that cost a lot of money and instead use cheaper software entropy. Its kinda like buying a so called gaming pc with no graphics GPU and your running games through software cpu that is slow and laggy not smooth and looks shite or instead they use cheap hardware emulation via software emulation or whatever due to hardware licensing issues or whatever excuses these manufacturers come up with.
    I find it hard to believe that a single $50-100 hardware wallet device can safely self custody a bitcoin wallet address worth $1 Trillion. There has to be a catch somewhere. Or is the catch no insurance, not insured for BTC losses?
    The ColdCard hardware wallet hack is nothing compare to Quantum computers. If human hackers can do hacks like this today without quantum computers and with assistance from Ai then imagine what Ai hack bots can do when Ai gets quantum computers to find vulnerabilities in Entropy chips in older hardware wallets instead of brute forcing 12 or 24 words :o
    For example can anyone confirm that the first Ledger & Trezor hardware wallets will be safe from Entropy vulnerabilities in 50 years time or even in 5 years time?
    Hardware manufacturers should be banned from selling hardware wallets unless they offer insurance. This of course will increase prices hardware wallets to much higher but if your securing a $Trillion dollars worth of bitcoin then a good hardware wallet with a proper fast hardware Entropy chip costing $1000 or $10000 is worth the investment right but then again Satoshi said Bitcoin is for everyone and not everyone can afford $1000 hardware wallets.
    Governments want people to store their bitcoin on centralized exchanges so governments can easily confiscate people bitcoin so governments are going to attack the hardware wallet entropy of bitcoin to persuade people not to self custody. Blackrock dont want hodlers to self custody Bitcoin so they are investing $Billions in hacking Entropy chips.
    There will replies saying trust and open-source code can be verified but which experienced knowledgeable programmers out there is going to spend their time manually looking through 1000s lines of codes to spot 1 mistake/vulnerability? As of now Ai Hackers have the edge over Ai Audits because Ai audits are not jailbroken like Ai hackers and Ai hackers are always 1 step ahead while Ai audits are playing catch up always 1 step behind.
    Lastly why the hell Btc hodlers are paying money to roll dices? They paid money for a hardware device to do the dice rolling randomness for them so a hardware wallet manufacturer selling devices that includes dices to tell their customers to roll a dice is a huge red flag because it clearly says our software entropy in your hardware wallet device is useless or we used a cheap hardware entropy chip that is useless too so you have better security by rolling dices yourselves.
    Finally when there is firmware update for the hardware wallet then how do hodlers verify that is not a software update to improve the security of the software entropy and instead it is an actual update for the hardware chip in the hardware wallet?
    This is insanity, bitcoin cannot be the global money until this fundamental problem is fixed unless you see bitcoin as global money custodied by Blackrock wall street and governments who are happy to hold your btc for you for free like a bank ::)
    Title: Re: Possible all Bitcoin Hardware Wallets be hacked due to 'Trust in Device Entropy?
    Post by: Zaguru12 on August 05, 2026, 08:17:26 PM
    Quote from: dim_mak5 on August 05, 2026, 07:55:23 PM
    How the hell do Bitcoiners verify that their hardware wallet device has proper Entropy (Randomness) instead of trusting the manufacturers claims? Manufacturers care about profit so they not going to use proper hardware entropy chips in their devices that cost a lot of money and instead use cheaper software entropy. Its kinda like buying a so called gaming pc with no graphics GPU and your running games through software cpu that is slow and laggy not smooth and looks shite or instead they use cheap hardware emulation via software emulation or whatever due to hardware licensing issues or whatever excuses these manufacturers come up with.
    The thing is even the manufacturers do not know how random your seed phrase was generated because it�s the underlying software that does this mathematical calculations. My straight answer is even if hardware wallets say they are random but you do not believe them, simply just generate your own seed phrase either with dice or other software you trust then proceed to add extended words (Passphrase).
    There is an ongoing discussion about why this wallets cannot even identify their own randomness here https://bitcointalk.org/index.php?topic=5590329.msg67010210#msg67010210 (https://bitcointalk.org/index.php?topic=5590329.msg67010210#msg67010210)
    Quote
    Hardware manufacturers should be banned from selling hardware wallets unless they offer insurance. This of course will increase prices hardware wallets to much higher but if your securing a $Trillion dollars worth of bitcoin then a good hardware wallet with a proper fast hardware Entropy chip costing $1000 or $10000 is worth the investment right but then again Satoshi said Bitcoin is for everyone and not everyone can afford $1000 hardware wallets.
    Do you know hardware wallets are simply part of self custody, self custody means you are taking junk of the risk alone. So I don�t understand why you even blame Satoshi for something you want them to implement which is insurance, the exact example you give is the reason why bitcoin is for everyone. If someone has $1trillion then $1k is cheap to and then if they don�t have such high amount it�s not worth it and that�s why bitcoin is for eveyone
    For me if you want insurance you definitely have to use centralized platforms like exchange or ETF not actually claiming to be your own self custody and wants insurance. Although due to some negligence I understand your point but hardware wallets running on insurance have the right to ask for your seed phrase as a security feature which is bad
    Title: Re: Possible all Bitcoin Hardware Wallets be hacked due to 'Trust in Device Entropy?
    Post by: CryptoBuds on August 05, 2026, 08:48:55 PM
    Quote from: dim_mak5 on August 05, 2026, 07:55:23 PM
    Bitcoiners are told the main motto/slogan is Verify not Trust.
    How the hell do Bitcoiners verify that their hardware wallet device has proper Entropy (Randomness) instead of trusting the manufacturers claims? Manufacturers care about profit so they not going to use proper hardware entropy chips in their devices that cost a lot of money and instead use cheaper software entropy. Its kinda like buying a so called gaming pc with no graphics GPU and your running games through software cpu that is slow and laggy not smooth and looks shite or instead they use cheap hardware emulation via software emulation or whatever due to hardware licensing issues or whatever excuses these manufacturers come up with.
    I find it hard to believe that a single $50-100 hardware wallet device can safely self custody a bitcoin wallet address worth $1 Trillion. There has to be a catch somewhere. Or is the catch no insurance, not insured for BTC losses?
    Verify, don't trust, doesn't mean I have to test every transistor on a hardware wallet myself. Verification in Bitcoin is a spectrum, that mean verification exists on a spectrum. You need to minimize trust by combining source code, deterministic build, firmware signature, reproducible build, BIP-39 compatibility, open review and your own operational security. You can never eliminate trust completely. Using hardware means there will be some trust assumptions.
    Title: Re: Possible all Bitcoin Hardware Wallets be hacked due to 'Trust in Device Entropy?
    Post by: un_rank on August 05, 2026, 09:06:29 PM
    Quote from: dim_mak5 on August 05, 2026, 07:55:23 PM
    I find it hard to believe that a single $50-100 hardware wallet device can safely self custody a bitcoin wallet address worth $1 Trillion. There has to be a catch somewhere. Or is the catch no insurance, not insured for BTC losses?
    A paper wallet is free and it can safely store all the bitcoins that are in circulation with no hitches, every other security precaution you can apply like multi signatures and passphrase are all also free. You're thinking so much interest of the conventional financial system which is why you're looking for an insurance.
    Quote from: dim_mak5 on August 05, 2026, 07:55:23 PM
    Hardware manufacturers should be banned from selling hardware wallets unless they offer insurance. This of course will increase prices hardware wallets to much higher but if your securing a $Trillion dollars worth of bitcoin then a good hardware wallet with a proper fast hardware Entropy chip costing $1000 or $10000 is worth the investment right but then again Satoshi said Bitcoin is for everyone and not everyone can afford $1000 hardware wallets.

    Excerpt only. The complete copy is held offline and backs quotations on this site. The original publication remains the canonical public source.

How to check this yourself

The excerpts and plain unified diffs above show the text this project held and how it changed. To verify a quotation, compare it against the page itself or against the Internet Archive's copies, which are independent of this project.

Complete captures are held offline rather than mirrored here, so this page shows diffs and excerpts. If a quotation is ever disputed, the full copy can be produced. Ask.