COLDCARD RNG incident the public record, collected and explained
Informational only, and this site never asks for your seed words. details

Informational only. This is an open source collection of what others have published about the incident, together with an explanation of it. It is not financial, security or legal advice, and not a substitute for professional advice about your own situation. It is not affiliated with, endorsed by, or speaking for Coinkite. Material is attributed and quoted as published; where sources disagree their scenarios are kept separate with their assumptions rather than reconciled into one answer. Everything is meant to be checked against the linked evidence rather than taken on trust. Act on your own judgement about a particular situation. Editorial standards and corrections.

Do not disclose recovery material to a website, form, message or support account. This site never asks for it, and contributions containing recovery words or private keys are not accepted.

r/coldcard: owner exposure self-assessment (dice seed, dice passphrase)

reddit-am-i-affected-dice

https://www.reddit.com/r/coldcard/comments/1vewq6y/am_i_affected/

Latest reviewed change

source content difference between and

The poster Individual_Gate9375 deleted their account content: the original post body and two of their own comments (describing their dice-only seed setup and their January 2021 conclusion they were unaffected) now show [deleted].

seen +2 -22 full history below
 post: 1vewq6y
-author: Individual_Gate9375
+author: [deleted]
 created_utc: 1785807996
 title: Am I affected?
 body:
-I switched from trezor to coldcard back in early january of 2021. It was a mk3 at the time and I remember I bought dice to roll when setting up the wallet. I remember sitting there forever just rolling over and over until like 100+. I know I made the seed phrase late december 2020 or early january 2021 because the first transaction (was dca at the time so buying some off cashapp and immediately transfering every day or two) was january 5th 2021. I also have a fairly long bip39 passphrase on top of this that I generated offline also using dice with a physical eff wordlist book. I went sort of crackpot tinfoil hat with the security when I did this. My coins are all still there. Am I good until I can get another hardware wallet?  
-  

First lines only. The complete diff is in the timeline below.

Organisation
reddit
Evidence role
Community discussion
Published
not established
Source changes
8
Detected differences
8
Unreviewed
0
Copies held
9

Every check is recorded, including checks that found no text change. A detected edit is therefore bounded between two checks. The publisher's exact save time is not observable from this record. Last checked .

  1. source content difference between and Current source content +2 -22

    The poster Individual_Gate9375 deleted their account content: the original post body and two of their own comments (describing their dice-only seed setup and their January 2021 conclusion they were unaffected) now show [deleted].

    seen · Captured here 11,297 chars
    What changed from the previous capture 24 lines
     post: 1vewq6y
    -author: Individual_Gate9375
    +author: [deleted]
     created_utc: 1785807996
     title: Am I affected?
     body:
    -I switched from trezor to coldcard back in early january of 2021. It was a mk3 at the time and I remember I bought dice to roll when setting up the wallet. I remember sitting there forever just rolling over and over until like 100+. I know I made the seed phrase late december 2020 or early january 2021 because the first transaction (was dca at the time so buying some off cashapp and immediately transfering every day or two) was january 5th 2021. I also have a fairly long bip39 passphrase on top of this that I generated offline also using dice with a physical eff wordlist book. I went sort of crackpot tinfoil hat with the security when I did this. My coins are all still there. Am I good until I can get another hardware wallet?  
    -  
    -I think someone dusted my wallet in early april, sent me 294 satoshis out of the blue. My wallet hasn't been active since 2021 so I guess they flagged inactive wallets with funds for potential targeting or something?
    +[deleted]
     
     comment: p1khl27
     parent: t3_1vewq6y
     body:
     It seems all Mk3 are affected, so don't take any chances. It doesn't matter how many dice rolls you've, it's a matter of time for attackers. [Someone else reported](https://www.reddit.com/r/Bitcoin/comments/1ja3uua/coldcard_mk4_ux_flaw/) on Reddit 50+ rolls and it was already gone like 2+ years ago.
     
    -comment: p1qe3zh
    -parent: t1_p1po8lz
    -author: Individual_Gate9375
    -created_utc: 1785878908
    -edited: false
    -body:
    -Apparently I created my wallet before the bugged firmware ever existed. Saw that mentioned here and went to look. March 2021 was the first time the bugged firmware was pushed out and I had my first transaction on my wallet in January 2021. So I generated my seed with the actual randomizer chip on the device. I would have apparently been unaffected even if I didn't have the dice rolls or the passphrase.
    -
     comment: p1qrgcs
     parent: t1_p1po8lz
     author: adequate_redditor
     So it's another variable to take into the account stored somewhere in memory, so I think it doesn't help in overall to secure the broken low entropy key and it's most likely part of the broken process.  
     Here is some good [technical article](https://engineering.block.xyz/blog/predictable-rng-fallback-and-32-bit-reseed-in-coldcard-firmware), so I think once attacker can brutal force UID and similar, then potentially it's easier to brutal force other variables (including dice rolls).
     
    -comment: p1szxc1
    -parent: t1_p1runuq
    -author: Individual_Gate9375
    -created_utc: 1785911487
    -edited: false
    -body:
    -There are two ways to roll dice. One where you add dice rolls to the generated seed, and one where you determine the seed with only dice rolls and bypass the rng entirely. I did the second method. I basically booted up the device and went through the setup. Then went into the settings and made a seed completely with dice rolls only and sha256 and wrote it down. Wiped the device and imported that seed I generated only with dicerolls. What I did bypassed all of the on device rng generation entirely.   
    -  
    -My point though in my last comment was apparently I wasn't affected by any of this at all because the broken firmware that introduced this rng bug came out in march 2021, and I generated my seed in January of 2021. So none of the precautions I took really mattered in this case. I would have been unaffected regardless of if I did the dice rolls or put the passphrase on the wallet.
    -
     comment: p2168q8
     parent: t3_1vewq6y
     author: Javanaut018
    
    Extracted text as captured
    post: 1vewq6y
    author: [deleted]
    created_utc: 1785807996
    title: Am I affected?
    body:
    [deleted]
    
    comment: p1khl27
    parent: t3_1vewq6y
    author: Fit_Assistant5708
    created_utc: 1785808618
    edited: false
    body:
    If you used dice u should be ok , but id double down on new wallet and multisig 
    
    comment: p1kk5bt
    parent: t3_1vewq6y
    author: SpareEconomy1849
    created_utc: 1785809477
    edited: false
    body:
    According to Coinkite, you're fine if you used 50+ dice rolls. 
    
    But if I were you, I'd move funds off, upgrade, move back to a new seed (with 100 dice rolls, *and* use a passphrase) to be safe. Who knows if there's another bug or pattern that will be discovered soon
    
    comment: p1kmia2
    parent: t3_1vewq6y
    author: BigJRecords
    created_utc: 1785810267
    edited: false
    body:
    Don’t take a chance. Move your funds 
    
    comment: p1krac4
    parent: t3_1vewq6y
    author: grraarr
    created_utc: 1785811908
    edited: false
    body:
    Seems like hardened security to me. Unless you want off the CC platform, you're in good shape where you are. You could keep your seed and change wallets or update seed too. Either way, you're extremely low risk and can take your time deciding, or do nothing.

    Excerpt only. The complete copy is held offline and backs quotations on this site. The original publication remains the canonical public source.

  2. source content difference between and source content +8 -0

    One new comment by Javanaut018 suggests the poster can probably just update firmware and keep using the device.

    seen · Captured here 13,771 chars
    What changed from the previous capture 8 lines
     There are two ways to roll dice. One where you add dice rolls to the generated seed, and one where you determine the seed with only dice rolls and bypass the rng entirely. I did the second method. I basically booted up the device and went through the setup. Then went into the settings and made a seed completely with dice rolls only and sha256 and wrote it down. Wiped the device and imported that seed I generated only with dicerolls. What I did bypassed all of the on device rng generation entirely.   
       
     My point though in my last comment was apparently I wasn't affected by any of this at all because the broken firmware that introduced this rng bug came out in march 2021, and I generated my seed in January of 2021. So none of the precautions I took really mattered in this case. I would have been unaffected regardless of if I did the dice rolls or put the passphrase on the wallet.
    +
    +comment: p2168q8
    +parent: t3_1vewq6y
    +author: Javanaut018
    +created_utc: 1786011925
    +edited: false
    +body:
    +You can just update firmware and keep the device using probably.
    
    Extracted text as captured
    post: 1vewq6y
    author: Individual_Gate9375
    created_utc: 1785807996
    title: Am I affected?
    body:
    I switched from trezor to coldcard back in early january of 2021. It was a mk3 at the time and I remember I bought dice to roll when setting up the wallet. I remember sitting there forever just rolling over and over until like 100+. I know I made the seed phrase late december 2020 or early january 2021 because the first transaction (was dca at the time so buying some off cashapp and immediately transfering every day or two) was january 5th 2021. I also have a fairly long bip39 passphrase on top of this that I generated offline also using dice with a physical eff wordlist book. I went sort of crackpot tinfoil hat with the security when I did this. My coins are all still there. Am I good until I can get another hardware wallet?  
      
    I think someone dusted my wallet in early april, sent me 294 satoshis out of the blue. My wallet hasn't been active since 2021 so I guess they flagged inactive wallets with funds for potential targeting or something?
    
    comment: p1khl27
    parent: t3_1vewq6y
    author: Fit_Assistant5708
    created_utc: 1785808618
    edited: false
    body:
    If you used dice u should be ok , but id double down on new wallet and multisig 
    
    comment: p1kk5bt
    parent: t3_1vewq6y
    author: SpareEconomy1849
    created_utc: 1785809477
    edited: false
    body:
    According to Coinkite, you're fine if you used 50+ dice rolls. 
    
    But if I were you, I'd move funds off, upgrade, move back to a new seed (with 100 dice rolls, *and* use a passphrase) to be safe. Who knows if there's another bug or pattern that will be discovered soon
    
    comment: p1kmia2
    parent: t3_1vewq6y
    author: BigJRecords
    created_utc: 1785810267
    edited: false
    body:
    Don’t take a chance. Move your funds 
    
    comment: p1krac4
    parent: t3_1vewq6y
    author: grraarr
    created_utc: 1785811908
    edited: false

    Excerpt only. The complete copy is held offline and backs quotations on this site. The original publication remains the canonical public source.

  3. source content difference between and source content +21 -0

    The thread gained a discussion distinguishing added dice rolls from a dice-only seed, with the original poster saying they used the latter and created their seed before the reported affected firmware window.

    seen · Captured here 13,605 chars
    What changed from the previous capture 21 lines
     edited: false
     body:
     I don’t think that’s true. If you did 100 rolls you did not used the flawed random generator on the device. That doesn’t mean that the device is safe from other vulnerabilities though…
    +
    +comment: p1runuq
    +parent: t1_p1qrgcs
    +author: kenorb
    +created_utc: 1785895191
    +edited: 1785896129
    +body:
    +I think there is confusion around the rolls.  
    +"Dice rolls" are just virtual ('punching numbers, not rolling dice') which you press some keys on the screen. See this [video on X](https://x.com/SteveSimple/status/2084635670572573155).  
    +So it's another variable to take into the account stored somewhere in memory, so I think it doesn't help in overall to secure the broken low entropy key and it's most likely part of the broken process.  
    +Here is some good [technical article](https://engineering.block.xyz/blog/predictable-rng-fallback-and-32-bit-reseed-in-coldcard-firmware), so I think once attacker can brutal force UID and similar, then potentially it's easier to brutal force other variables (including dice rolls).
    +
    +comment: p1szxc1
    +parent: t1_p1runuq
    +author: Individual_Gate9375
    +created_utc: 1785911487
    +edited: false
    +body:
    +There are two ways to roll dice. One where you add dice rolls to the generated seed, and one where you determine the seed with only dice rolls and bypass the rng entirely. I did the second method. I basically booted up the device and went through the setup. Then went into the settings and made a seed completely with dice rolls only and sha256 and wrote it down. Wiped the device and imported that seed I generated only with dicerolls. What I did bypassed all of the on device rng generation entirely.   
    +  
    +My point though in my last comment was apparently I wasn't affected by any of this at all because the broken firmware that introduced this rng bug came out in march 2021, and I generated my seed in January of 2021. So none of the precautions I took really mattered in this case. I would have been unaffected regardless of if I did the dice rolls or put the passphrase on the wallet.
    
    Extracted text as captured
    post: 1vewq6y
    author: Individual_Gate9375
    created_utc: 1785807996
    title: Am I affected?
    body:
    I switched from trezor to coldcard back in early january of 2021. It was a mk3 at the time and I remember I bought dice to roll when setting up the wallet. I remember sitting there forever just rolling over and over until like 100+. I know I made the seed phrase late december 2020 or early january 2021 because the first transaction (was dca at the time so buying some off cashapp and immediately transfering every day or two) was january 5th 2021. I also have a fairly long bip39 passphrase on top of this that I generated offline also using dice with a physical eff wordlist book. I went sort of crackpot tinfoil hat with the security when I did this. My coins are all still there. Am I good until I can get another hardware wallet?  
      
    I think someone dusted my wallet in early april, sent me 294 satoshis out of the blue. My wallet hasn't been active since 2021 so I guess they flagged inactive wallets with funds for potential targeting or something?
    
    comment: p1khl27
    parent: t3_1vewq6y
    author: Fit_Assistant5708
    created_utc: 1785808618
    edited: false
    body:
    If you used dice u should be ok , but id double down on new wallet and multisig 
    
    comment: p1kk5bt
    parent: t3_1vewq6y
    author: SpareEconomy1849
    created_utc: 1785809477
    edited: false
    body:
    According to Coinkite, you're fine if you used 50+ dice rolls. 
    
    But if I were you, I'd move funds off, upgrade, move back to a new seed (with 100 dice rolls, *and* use a passphrase) to be safe. Who knows if there's another bug or pattern that will be discovered soon
    
    comment: p1kmia2
    parent: t3_1vewq6y
    author: BigJRecords
    created_utc: 1785810267
    edited: false
    body:
    Don’t take a chance. Move your funds 
    
    comment: p1krac4
    parent: t3_1vewq6y
    author: grraarr
    created_utc: 1785811908
    edited: false

    Excerpt only. The complete copy is held offline and backs quotations on this site. The original publication remains the canonical public source.

  4. source content difference between and source content +8 -0

    The Reddit thread gained 1 new comment distinguishing dice input from other possible device vulnerabilities.

    seen · Captured here 11,780 chars
    What changed from the previous capture 8 lines
     edited: false
     body:
     Apparently I created my wallet before the bugged firmware ever existed. Saw that mentioned here and went to look. March 2021 was the first time the bugged firmware was pushed out and I had my first transaction on my wallet in January 2021. So I generated my seed with the actual randomizer chip on the device. I would have apparently been unaffected even if I didn't have the dice rolls or the passphrase.
    +
    +comment: p1qrgcs
    +parent: t1_p1po8lz
    +author: adequate_redditor
    +created_utc: 1785882710
    +edited: false
    +body:
    +I don’t think that’s true. If you did 100 rolls you did not used the flawed random generator on the device. That doesn’t mean that the device is safe from other vulnerabilities though…
    
    Extracted text as captured
    post: 1vewq6y
    author: Individual_Gate9375
    created_utc: 1785807996
    title: Am I affected?
    body:
    I switched from trezor to coldcard back in early january of 2021. It was a mk3 at the time and I remember I bought dice to roll when setting up the wallet. I remember sitting there forever just rolling over and over until like 100+. I know I made the seed phrase late december 2020 or early january 2021 because the first transaction (was dca at the time so buying some off cashapp and immediately transfering every day or two) was january 5th 2021. I also have a fairly long bip39 passphrase on top of this that I generated offline also using dice with a physical eff wordlist book. I went sort of crackpot tinfoil hat with the security when I did this. My coins are all still there. Am I good until I can get another hardware wallet?  
      
    I think someone dusted my wallet in early april, sent me 294 satoshis out of the blue. My wallet hasn't been active since 2021 so I guess they flagged inactive wallets with funds for potential targeting or something?
    
    comment: p1khl27
    parent: t3_1vewq6y
    author: Fit_Assistant5708
    created_utc: 1785808618
    edited: false
    body:
    If you used dice u should be ok , but id double down on new wallet and multisig 
    
    comment: p1kk5bt
    parent: t3_1vewq6y
    author: SpareEconomy1849
    created_utc: 1785809477
    edited: false
    body:
    According to Coinkite, you're fine if you used 50+ dice rolls. 
    
    But if I were you, I'd move funds off, upgrade, move back to a new seed (with 100 dice rolls, *and* use a passphrase) to be safe. Who knows if there's another bug or pattern that will be discovered soon
    
    comment: p1kmia2
    parent: t3_1vewq6y
    author: BigJRecords
    created_utc: 1785810267
    edited: false
    body:
    Don’t take a chance. Move your funds 
    
    comment: p1krac4
    parent: t3_1vewq6y
    author: grraarr
    created_utc: 1785811908
    edited: false

    Excerpt only. The complete copy is held offline and backs quotations on this site. The original publication remains the canonical public source.

  5. source content difference between and source content +8 -0

    The Reddit thread gained 1 new comment about seed generation before the affected firmware release.

    seen · Captured here 11,488 chars
    What changed from the previous capture 8 lines
     edited: false
     body:
     It seems all Mk3 are affected, so don't take any chances. It doesn't matter how many dice rolls you've, it's a matter of time for attackers. [Someone else reported](https://www.reddit.com/r/Bitcoin/comments/1ja3uua/coldcard_mk4_ux_flaw/) on Reddit 50+ rolls and it was already gone like 2+ years ago.
    +
    +comment: p1qe3zh
    +parent: t1_p1po8lz
    +author: Individual_Gate9375
    +created_utc: 1785878908
    +edited: false
    +body:
    +Apparently I created my wallet before the bugged firmware ever existed. Saw that mentioned here and went to look. March 2021 was the first time the bugged firmware was pushed out and I had my first transaction on my wallet in January 2021. So I generated my seed with the actual randomizer chip on the device. I would have apparently been unaffected even if I didn't have the dice rolls or the passphrase.
    
    Extracted text as captured
    post: 1vewq6y
    author: Individual_Gate9375
    created_utc: 1785807996
    title: Am I affected?
    body:
    I switched from trezor to coldcard back in early january of 2021. It was a mk3 at the time and I remember I bought dice to roll when setting up the wallet. I remember sitting there forever just rolling over and over until like 100+. I know I made the seed phrase late december 2020 or early january 2021 because the first transaction (was dca at the time so buying some off cashapp and immediately transfering every day or two) was january 5th 2021. I also have a fairly long bip39 passphrase on top of this that I generated offline also using dice with a physical eff wordlist book. I went sort of crackpot tinfoil hat with the security when I did this. My coins are all still there. Am I good until I can get another hardware wallet?  
      
    I think someone dusted my wallet in early april, sent me 294 satoshis out of the blue. My wallet hasn't been active since 2021 so I guess they flagged inactive wallets with funds for potential targeting or something?
    
    comment: p1khl27
    parent: t3_1vewq6y
    author: Fit_Assistant5708
    created_utc: 1785808618
    edited: false
    body:
    If you used dice u should be ok , but id double down on new wallet and multisig 
    
    comment: p1kk5bt
    parent: t3_1vewq6y
    author: SpareEconomy1849
    created_utc: 1785809477
    edited: false
    body:
    According to Coinkite, you're fine if you used 50+ dice rolls. 
    
    But if I were you, I'd move funds off, upgrade, move back to a new seed (with 100 dice rolls, *and* use a passphrase) to be safe. Who knows if there's another bug or pattern that will be discovered soon
    
    comment: p1kmia2
    parent: t3_1vewq6y
    author: BigJRecords
    created_utc: 1785810267
    edited: false
    body:
    Don’t take a chance. Move your funds 
    
    comment: p1krac4
    parent: t3_1vewq6y
    author: grraarr
    created_utc: 1785811908
    edited: false

    Excerpt only. The complete copy is held offline and backs quotations on this site. The original publication remains the canonical public source.

  6. source content difference between and source content +8 -0

    The Reddit thread gained 1 new comment.

    seen · Captured here 10,973 chars
    What changed from the previous capture 8 lines
     edited: false
     body:
     Just DMd you! 
    +
    +comment: p1po8lz
    +parent: t3_1vewq6y
    +author: kenorb
    +created_utc: 1785872021
    +edited: false
    +body:
    +It seems all Mk3 are affected, so don't take any chances. It doesn't matter how many dice rolls you've, it's a matter of time for attackers. [Someone else reported](https://www.reddit.com/r/Bitcoin/comments/1ja3uua/coldcard_mk4_ux_flaw/) on Reddit 50+ rolls and it was already gone like 2+ years ago.
    
    Extracted text as captured
    post: 1vewq6y
    author: Individual_Gate9375
    created_utc: 1785807996
    title: Am I affected?
    body:
    I switched from trezor to coldcard back in early january of 2021. It was a mk3 at the time and I remember I bought dice to roll when setting up the wallet. I remember sitting there forever just rolling over and over until like 100+. I know I made the seed phrase late december 2020 or early january 2021 because the first transaction (was dca at the time so buying some off cashapp and immediately transfering every day or two) was january 5th 2021. I also have a fairly long bip39 passphrase on top of this that I generated offline also using dice with a physical eff wordlist book. I went sort of crackpot tinfoil hat with the security when I did this. My coins are all still there. Am I good until I can get another hardware wallet?  
      
    I think someone dusted my wallet in early april, sent me 294 satoshis out of the blue. My wallet hasn't been active since 2021 so I guess they flagged inactive wallets with funds for potential targeting or something?
    
    comment: p1khl27
    parent: t3_1vewq6y
    author: Fit_Assistant5708
    created_utc: 1785808618
    edited: false
    body:
    If you used dice u should be ok , but id double down on new wallet and multisig 
    
    comment: p1kk5bt
    parent: t3_1vewq6y
    author: SpareEconomy1849
    created_utc: 1785809477
    edited: false
    body:
    According to Coinkite, you're fine if you used 50+ dice rolls. 
    
    But if I were you, I'd move funds off, upgrade, move back to a new seed (with 100 dice rolls, *and* use a passphrase) to be safe. Who knows if there's another bug or pattern that will be discovered soon
    
    comment: p1kmia2
    parent: t3_1vewq6y
    author: BigJRecords
    created_utc: 1785810267
    edited: false
    body:
    Don’t take a chance. Move your funds 
    
    comment: p1krac4
    parent: t3_1vewq6y
    author: grraarr
    created_utc: 1785811908
    edited: false

    Excerpt only. The complete copy is held offline and backs quotations on this site. The original publication remains the canonical public source.

  7. source content difference between and source content +16 -0

    2 new Reddit comments were posted, including an offer to help using a 16-digit invoice ID.

    seen · Captured here 10,576 chars
    What changed from the previous capture 16 lines
     edited: false
     body:
     it sounds like your firmware didn't have this bug and the dice rolls and passphrase are added peace of mind. Your good. And don't do multisig without understanding everything thats required to back it up
    +
    +comment: p1oi1sy
    +parent: t1_p1lhbkk
    +author: HodlDee
    +created_utc: 1785861464
    +edited: false
    +body:
    +DM me your 16 digit invoice ID. I’ll do my best to help.
    +
    +comment: p1oinjj
    +parent: t1_p1oi1sy
    +author: AntZealousideal3728
    +created_utc: 1785861616
    +edited: false
    +body:
    +Just DMd you! 
    
    Extracted text as captured
    post: 1vewq6y
    author: Individual_Gate9375
    created_utc: 1785807996
    title: Am I affected?
    body:
    I switched from trezor to coldcard back in early january of 2021. It was a mk3 at the time and I remember I bought dice to roll when setting up the wallet. I remember sitting there forever just rolling over and over until like 100+. I know I made the seed phrase late december 2020 or early january 2021 because the first transaction (was dca at the time so buying some off cashapp and immediately transfering every day or two) was january 5th 2021. I also have a fairly long bip39 passphrase on top of this that I generated offline also using dice with a physical eff wordlist book. I went sort of crackpot tinfoil hat with the security when I did this. My coins are all still there. Am I good until I can get another hardware wallet?  
      
    I think someone dusted my wallet in early april, sent me 294 satoshis out of the blue. My wallet hasn't been active since 2021 so I guess they flagged inactive wallets with funds for potential targeting or something?
    
    comment: p1khl27
    parent: t3_1vewq6y
    author: Fit_Assistant5708
    created_utc: 1785808618
    edited: false
    body:
    If you used dice u should be ok , but id double down on new wallet and multisig 
    
    comment: p1kk5bt
    parent: t3_1vewq6y
    author: SpareEconomy1849
    created_utc: 1785809477
    edited: false
    body:
    According to Coinkite, you're fine if you used 50+ dice rolls. 
    
    But if I were you, I'd move funds off, upgrade, move back to a new seed (with 100 dice rolls, *and* use a passphrase) to be safe. Who knows if there's another bug or pattern that will be discovered soon
    
    comment: p1kmia2
    parent: t3_1vewq6y
    author: BigJRecords
    created_utc: 1785810267
    edited: false
    body:
    Don’t take a chance. Move your funds 
    
    comment: p1krac4
    parent: t3_1vewq6y
    author: grraarr
    created_utc: 1785811908
    edited: false

    Excerpt only. The complete copy is held offline and backs quotations on this site. The original publication remains the canonical public source.

  8. source content difference between and source content +48 -0

    5 new Reddit comments were posted, including Silent_Ad_9963,JunketTurbulent2114,grraarr.

    seen · Captured here 10,298 chars
    What changed from the previous capture 48 lines
     edited: false
     body:
     Technically you are safe but I would sleep better if I create a new seed phrase with passphrase on the Trezor wallet.
    +
    +comment: p1m72rh
    +parent: t1_p1l5ogr
    +author: Silent_Ad_9963
    +created_utc: 1785835214
    +edited: false
    +body:
    +And he generated his seed before the broken firmware was even released .
    +
    +On top of that the code has now been audited by multiple sources more than any other code out there 
    +
    +I 100% agree that moving just because of emotional feeling and panic while all info say seed is fine is risky , possibly more risky than staying where he is now. 
    +
    +Unfortunately now this "can't trust anything this dev ever wrote or done" risk to create more problems down the road ... Is an emotional response and it should be treated as such
    +
    +comment: p1mg22g
    +parent: t3_1vewq6y
    +author: JunketTurbulent2114
    +created_utc: 1785839418
    +edited: false
    +body:
    +The issue is coldcard likely won't be around in the future to support firmware upgrades and what not.  Probably a good idea to go back to trezor. But the dice I think saved your ass. 
    +
    +comment: p1mg5nu
    +parent: t1_p1kyeov
    +author: JunketTurbulent2114
    +created_utc: 1785839461
    +edited: false
    +body:
    +They told us to not trust them and we didn't bother to verify.  Our fault. 
    +
    +comment: p1mjocd
    +parent: t1_p1m72rh
    +author: grraarr
    +created_utc: 1785840938
    +edited: false
    +body:
    +Thank you! I didn't even calculate the firmware timeline but that's a great point.
    +
    +I also see a bunch of people not only insisting on switching wallets, but also recommending passphrases and multisig blindly without knowing what they're meant to protect against or if they're appropriate for the individual's inheritance model. I understand those are important security measures, but lot of people are hardening and will be locked out.
    +
    +comment: p1movkz
    +parent: t3_1vewq6y
    +author: No_Position_8581
    +created_utc: 1785842980
    +edited: false
    +body:
    +it sounds like your firmware didn't have this bug and the dice rolls and passphrase are added peace of mind. Your good. And don't do multisig without understanding everything thats required to back it up
    
    Extracted text as captured
    post: 1vewq6y
    author: Individual_Gate9375
    created_utc: 1785807996
    title: Am I affected?
    body:
    I switched from trezor to coldcard back in early january of 2021. It was a mk3 at the time and I remember I bought dice to roll when setting up the wallet. I remember sitting there forever just rolling over and over until like 100+. I know I made the seed phrase late december 2020 or early january 2021 because the first transaction (was dca at the time so buying some off cashapp and immediately transfering every day or two) was january 5th 2021. I also have a fairly long bip39 passphrase on top of this that I generated offline also using dice with a physical eff wordlist book. I went sort of crackpot tinfoil hat with the security when I did this. My coins are all still there. Am I good until I can get another hardware wallet?  
      
    I think someone dusted my wallet in early april, sent me 294 satoshis out of the blue. My wallet hasn't been active since 2021 so I guess they flagged inactive wallets with funds for potential targeting or something?
    
    comment: p1khl27
    parent: t3_1vewq6y
    author: Fit_Assistant5708
    created_utc: 1785808618
    edited: false
    body:
    If you used dice u should be ok , but id double down on new wallet and multisig 
    
    comment: p1kk5bt
    parent: t3_1vewq6y
    author: SpareEconomy1849
    created_utc: 1785809477
    edited: false
    body:
    According to Coinkite, you're fine if you used 50+ dice rolls. 
    
    But if I were you, I'd move funds off, upgrade, move back to a new seed (with 100 dice rolls, *and* use a passphrase) to be safe. Who knows if there's another bug or pattern that will be discovered soon
    
    comment: p1kmia2
    parent: t3_1vewq6y
    author: BigJRecords
    created_utc: 1785810267
    edited: false
    body:
    Don’t take a chance. Move your funds 
    
    comment: p1krac4
    parent: t3_1vewq6y
    author: grraarr
    created_utc: 1785811908
    edited: false

    Excerpt only. The complete copy is held offline and backs quotations on this site. The original publication remains the canonical public source.

  9. Earliest copy held
    seen · Captured here 8,353 chars
    Extracted text as captured
    post: 1vewq6y
    author: Individual_Gate9375
    created_utc: 1785807996
    title: Am I affected?
    body:
    I switched from trezor to coldcard back in early january of 2021. It was a mk3 at the time and I remember I bought dice to roll when setting up the wallet. I remember sitting there forever just rolling over and over until like 100+. I know I made the seed phrase late december 2020 or early january 2021 because the first transaction (was dca at the time so buying some off cashapp and immediately transfering every day or two) was january 5th 2021. I also have a fairly long bip39 passphrase on top of this that I generated offline also using dice with a physical eff wordlist book. I went sort of crackpot tinfoil hat with the security when I did this. My coins are all still there. Am I good until I can get another hardware wallet?  
      
    I think someone dusted my wallet in early april, sent me 294 satoshis out of the blue. My wallet hasn't been active since 2021 so I guess they flagged inactive wallets with funds for potential targeting or something?
    
    comment: p1khl27
    parent: t3_1vewq6y
    author: Fit_Assistant5708
    created_utc: 1785808618
    edited: false
    body:
    If you used dice u should be ok , but id double down on new wallet and multisig 
    
    comment: p1kk5bt
    parent: t3_1vewq6y
    author: SpareEconomy1849
    created_utc: 1785809477
    edited: false
    body:
    According to Coinkite, you're fine if you used 50+ dice rolls. 
    
    But if I were you, I'd move funds off, upgrade, move back to a new seed (with 100 dice rolls, *and* use a passphrase) to be safe. Who knows if there's another bug or pattern that will be discovered soon
    
    comment: p1kmia2
    parent: t3_1vewq6y
    author: BigJRecords
    created_utc: 1785810267
    edited: false
    body:
    Don’t take a chance. Move your funds 
    
    comment: p1krac4
    parent: t3_1vewq6y
    author: grraarr
    created_utc: 1785811908
    edited: false

    Excerpt only. The complete copy is held offline and backs quotations on this site. The original publication remains the canonical public source.

How to check this yourself

The excerpts and plain unified diffs above show the text this project held and how it changed. To verify a quotation, compare it against the page itself or against the Internet Archive's copies, which are independent of this project.

Complete captures are held offline rather than mirrored here, so this page shows diffs and excerpts. If a quotation is ever disputed, the full copy can be produced. Ask.