COLDCARD RNG incident the public record, collected and explained
Informational only, and this site never asks for your seed words. details

Informational only. This is an open source collection of what others have published about the incident, together with an explanation of it. It is not financial, security or legal advice, and not a substitute for professional advice about your own situation. It is not affiliated with, endorsed by, or speaking for Coinkite. Material is attributed and quoted as published; where sources disagree their scenarios are kept separate with their assumptions rather than reconciled into one answer. Everything is meant to be checked against the linked evidence rather than taken on trust. Act on your own judgement about a particular situation. Editorial standards and corrections.

Do not disclose recovery material to a website, form, message or support account. This site never asks for it, and contributions containing recovery words or private keys are not accepted.

r/Bitcoin: best way to keep bitcoin safe after the incident

reddit-best-way-keep-safe

https://www.reddit.com/r/Bitcoin/comments/1vedae9/with_the_coldcard_stuff_going_on_i_want_to_know/

Latest reviewed change

source content difference between and

The thread gained a brief reply saying there was no need for the item under discussion.

seen +8 -0 full history below
 edited: false
 body:
 Analogies aren’t your thing, huh?
+
+comment: p1velta
+parent: t1_p1rzat3
+author: EyesFor1
+created_utc: 1785943309

First lines only. The complete diff is in the timeline below.

Organisation
reddit
Evidence role
Community discussion
Published
not established
Source changes
6
Detected differences
6
Unreviewed
0
Copies held
7

Every check is recorded, including checks that found no text change. A detected edit is therefore bounded between two checks. The publisher's exact save time is not observable from this record. Last checked .

  1. source content difference between and Current source content +8 -0

    The thread gained a brief reply saying there was no need for the item under discussion.

    seen · Captured here 17,017 chars
    What changed from the previous capture 8 lines
     edited: false
     body:
     Analogies aren’t your thing, huh?
    +
    +comment: p1velta
    +parent: t1_p1rzat3
    +author: EyesFor1
    +created_utc: 1785943309
    +edited: false
    +body:
    +no need for them. 
    
    Extracted text as captured
    post: 1vedae9
    author: coinwin
    created_utc: 1785763310
    title: With the coldcard stuff going on, I want to know the best way to keep my bitcoin safe.
    body:
    I've had some bitcoin in a keepkey and trezor for a long time.  I have my seed phrase and a pin on it.  Are there additional steps that would make it more secure?  Should I move the coins to a new wallet?  Are there any BIPs that have made modern wallets more secure?  I believe you can make a wallet with a 24 word seed phrase as opposed to a 12 word one.  Would that help significantly?
    
    comment: p1fz9z5
    parent: t3_1vedae9
    author: CatsBeerGardenCoffee
    created_utc: 1785763648
    edited: false
    body:
    I believe the people who got hacked were only relying on the cold card generated entropy. 
    
    If you have created your own randomness you should be good. If not, you should.
    
    comment: p1fzgir
    parent: t3_1vedae9
    author: Alive-Material4405
    created_utc: 1785763699
    edited: false
    body:
    iBit
    
    comment: p1fzvsl
    parent: t3_1vedae9
    author: boy_tue
    created_utc: 1785763823
    edited: false
    body:
    Give it to me, I'll watch it for you 😎
    
    comment: p1g1265
    parent: t3_1vedae9
    author: EyesFor1
    created_utc: 1785764167
    edited: false
    body:
    Its not what people want to hear because emotions and anger are high but CC are safe to use on the new firmware especially with 100+ dice roll. The error has been found and the bug fixed. The device is secure with dice roll but trust has been destroyed. People will still use them with dice rolls

    Excerpt only. The complete copy is held offline and backs quotations on this site. The original publication remains the canonical public source.

  2. source content difference between and source content +4 -6

    Two comments advising readers to generate a seed with dice were replaced with deleted-account placeholders.

    seen · Captured here 16,900 chars
    What changed from the previous capture 10 lines
     
     comment: p1gdmud
     parent: t1_p1gcyqw
    -author: OldHamburger7923
    +author: [deleted]
     created_utc: 1785767661
     edited: false
     body:
    -You roll your own dice and you make your own seed. You don't rely on the wallet to create it. 
    +[deleted]
     
     comment: p1gef3t
     parent: t3_1vedae9
     
     comment: p1ghroq
     parent: t1_p1gga0h
    -author: OldHamburger7923
    +author: [deleted]
     created_utc: 1785768757
     edited: false
     body:
    -That's why I said roll your own dice and make your own seed. Don't use the wallet to generate the words at all. Once you make your 23 words, coldcard will list the possible matching 24th word for you to select from. Should be about 7 that give you proper checksum. Pick one and you are set.
    -
    -You can verify it with another wallet if you think your input seed is somehow not being used by the wallet.
    +[deleted]
     
     comment: p1gnjd7
     parent: t1_p1gga0h
    
    Extracted text as captured
    post: 1vedae9
    author: coinwin
    created_utc: 1785763310
    title: With the coldcard stuff going on, I want to know the best way to keep my bitcoin safe.
    body:
    I've had some bitcoin in a keepkey and trezor for a long time.  I have my seed phrase and a pin on it.  Are there additional steps that would make it more secure?  Should I move the coins to a new wallet?  Are there any BIPs that have made modern wallets more secure?  I believe you can make a wallet with a 24 word seed phrase as opposed to a 12 word one.  Would that help significantly?
    
    comment: p1fz9z5
    parent: t3_1vedae9
    author: CatsBeerGardenCoffee
    created_utc: 1785763648
    edited: false
    body:
    I believe the people who got hacked were only relying on the cold card generated entropy. 
    
    If you have created your own randomness you should be good. If not, you should.
    
    comment: p1fzgir
    parent: t3_1vedae9
    author: Alive-Material4405
    created_utc: 1785763699
    edited: false
    body:
    iBit
    
    comment: p1fzvsl
    parent: t3_1vedae9
    author: boy_tue
    created_utc: 1785763823
    edited: false
    body:
    Give it to me, I'll watch it for you 😎
    
    comment: p1g1265
    parent: t3_1vedae9
    author: EyesFor1
    created_utc: 1785764167
    edited: false
    body:
    Its not what people want to hear because emotions and anger are high but CC are safe to use on the new firmware especially with 100+ dice roll. The error has been found and the bug fixed. The device is secure with dice roll but trust has been destroyed. People will still use them with dice rolls

    Excerpt only. The complete copy is held offline and backs quotations on this site. The original publication remains the canonical public source.

  3. source content difference between and source content +8 -0

    The thread gained a brief reply criticising another participant's use of analogies.

    seen · Captured here 17,389 chars
    What changed from the previous capture 8 lines
     Obviously not everyone needs to test that they're not shipping devices that are spoofing the dice roll seed, but enough of us should. 
     
     You shouldn't think that buying a Trezor or other HWW that takes more control away from you is the solution, that is literally driving straight into the next multi-vehicle collision and learning nothing from this.
    +
    +comment: p1rzat3
    +parent: t1_p1lldt9
    +author: moviemaker2
    +created_utc: 1785896728
    +edited: false
    +body:
    +Analogies aren’t your thing, huh?
    
    Extracted text as captured
    post: 1vedae9
    author: coinwin
    created_utc: 1785763310
    title: With the coldcard stuff going on, I want to know the best way to keep my bitcoin safe.
    body:
    I've had some bitcoin in a keepkey and trezor for a long time.  I have my seed phrase and a pin on it.  Are there additional steps that would make it more secure?  Should I move the coins to a new wallet?  Are there any BIPs that have made modern wallets more secure?  I believe you can make a wallet with a 24 word seed phrase as opposed to a 12 word one.  Would that help significantly?
    
    comment: p1fz9z5
    parent: t3_1vedae9
    author: CatsBeerGardenCoffee
    created_utc: 1785763648
    edited: false
    body:
    I believe the people who got hacked were only relying on the cold card generated entropy. 
    
    If you have created your own randomness you should be good. If not, you should.
    
    comment: p1fzgir
    parent: t3_1vedae9
    author: Alive-Material4405
    created_utc: 1785763699
    edited: false
    body:
    iBit
    
    comment: p1fzvsl
    parent: t3_1vedae9
    author: boy_tue
    created_utc: 1785763823
    edited: false
    body:
    Give it to me, I'll watch it for you 😎
    
    comment: p1g1265
    parent: t3_1vedae9
    author: EyesFor1
    created_utc: 1785764167
    edited: false
    body:
    Its not what people want to hear because emotions and anger are high but CC are safe to use on the new firmware especially with 100+ dice roll. The error has been found and the bug fixed. The device is secure with dice roll but trust has been destroyed. People will still use them with dice rolls

    Excerpt only. The complete copy is held offline and backs quotations on this site. The original publication remains the canonical public source.

  4. source content difference between and source content +22 -0

    2 new Reddit comments were posted, including CiaranCarroll advocating user-supplied entropy and independent verification.

    seen · Captured here 17,254 chars
    What changed from the previous capture 22 lines
     edited: false
     body:
     Can I generate a seed on Bitbox trustlessly, like I can on my CC Q? Can I roll dice or some other method of adding entropy that is easily accessible, and verify that the code on my device reproduces same seed from same inputs?
    +
    +comment: p1nrwmi
    +parent: t1_p1g1265
    +author: CiaranCarroll
    +created_utc: 1785854763
    +edited: false
    +body:
    +Yup
    +
    +comment: p1nt5v5
    +parent: t1_p1i9z4h
    +author: CiaranCarroll
    +created_utc: 1785855093
    +edited: false
    +body:
    +If Trezor code supplies the entropy thats a problem. If you learn anything from this it is that whatever HWW you choose should allow you to dice roll (or cards or whatever) and there should be an independent source that you can test the device against to make sure it's not spoofing.
    +
    +I use Cold Card and Ian Coleman's site, and I'm a happy Coin Kite customer. 
    +
    +Obviously not everyone needs to test that they're not shipping devices that are spoofing the dice roll seed, but enough of us should. 
    +
    +You shouldn't think that buying a Trezor or other HWW that takes more control away from you is the solution, that is literally driving straight into the next multi-vehicle collision and learning nothing from this.
    
    Extracted text as captured
    post: 1vedae9
    author: coinwin
    created_utc: 1785763310
    title: With the coldcard stuff going on, I want to know the best way to keep my bitcoin safe.
    body:
    I've had some bitcoin in a keepkey and trezor for a long time.  I have my seed phrase and a pin on it.  Are there additional steps that would make it more secure?  Should I move the coins to a new wallet?  Are there any BIPs that have made modern wallets more secure?  I believe you can make a wallet with a 24 word seed phrase as opposed to a 12 word one.  Would that help significantly?
    
    comment: p1fz9z5
    parent: t3_1vedae9
    author: CatsBeerGardenCoffee
    created_utc: 1785763648
    edited: false
    body:
    I believe the people who got hacked were only relying on the cold card generated entropy. 
    
    If you have created your own randomness you should be good. If not, you should.
    
    comment: p1fzgir
    parent: t3_1vedae9
    author: Alive-Material4405
    created_utc: 1785763699
    edited: false
    body:
    iBit
    
    comment: p1fzvsl
    parent: t3_1vedae9
    author: boy_tue
    created_utc: 1785763823
    edited: false
    body:
    Give it to me, I'll watch it for you 😎
    
    comment: p1g1265
    parent: t3_1vedae9
    author: EyesFor1
    created_utc: 1785764167
    edited: false
    body:
    Its not what people want to hear because emotions and anger are high but CC are safe to use on the new firmware especially with 100+ dice roll. The error has been found and the bug fixed. The device is secure with dice roll but trust has been destroyed. People will still use them with dice rolls

    Excerpt only. The complete copy is held offline and backs quotations on this site. The original publication remains the canonical public source.

  5. source content difference between and source content +8 -0

    1 new Reddit comment was posted, including CiaranCarroll.

    seen · Captured here 16,331 chars
    What changed from the previous capture 8 lines
     edited: false
     body:
     You audit their firmware thouroughly 
    +
    +comment: p1nri5t
    +parent: t1_p1g58fk
    +author: CiaranCarroll
    +created_utc: 1785854657
    +edited: false
    +body:
    +Can I generate a seed on Bitbox trustlessly, like I can on my CC Q? Can I roll dice or some other method of adding entropy that is easily accessible, and verify that the code on my device reproduces same seed from same inputs?
    
    Extracted text as captured
    post: 1vedae9
    author: coinwin
    created_utc: 1785763310
    title: With the coldcard stuff going on, I want to know the best way to keep my bitcoin safe.
    body:
    I've had some bitcoin in a keepkey and trezor for a long time.  I have my seed phrase and a pin on it.  Are there additional steps that would make it more secure?  Should I move the coins to a new wallet?  Are there any BIPs that have made modern wallets more secure?  I believe you can make a wallet with a 24 word seed phrase as opposed to a 12 word one.  Would that help significantly?
    
    comment: p1fz9z5
    parent: t3_1vedae9
    author: CatsBeerGardenCoffee
    created_utc: 1785763648
    edited: false
    body:
    I believe the people who got hacked were only relying on the cold card generated entropy. 
    
    If you have created your own randomness you should be good. If not, you should.
    
    comment: p1fzgir
    parent: t3_1vedae9
    author: Alive-Material4405
    created_utc: 1785763699
    edited: false
    body:
    iBit
    
    comment: p1fzvsl
    parent: t3_1vedae9
    author: boy_tue
    created_utc: 1785763823
    edited: false
    body:
    Give it to me, I'll watch it for you 😎
    
    comment: p1g1265
    parent: t3_1vedae9
    author: EyesFor1
    created_utc: 1785764167
    edited: false
    body:
    Its not what people want to hear because emotions and anger are high but CC are safe to use on the new firmware especially with 100+ dice roll. The error has been found and the bug fixed. The device is secure with dice roll but trust has been destroyed. People will still use them with dice rolls

    Excerpt only. The complete copy is held offline and backs quotations on this site. The original publication remains the canonical public source.

  6. source content difference between and source content +16 -0

    2 new Reddit comments were posted, including Javanaut018.

    seen · Captured here 16,001 chars
    What changed from the previous capture 16 lines
     Secure elements are standard in the industry by now, no HWW manufacturer would dare launching a device without one unless their UX gets incredibly hampered by it, and in such case the best practice would be to let users know, but AFAIK, no single competitor is launching devices without one, and the ones who don't have a physical one have a virtual one.
     
     The secure element is a complete separe part of the device and Trezor's libraries have been battle tested, peer reviewed, audited and actively attacked multiple times, yet they still stand the test of time.
    +
    +comment: p1mbhjz
    +parent: t1_p1gdmud
    +author: Javanaut018
    +created_utc: 1785837360
    +edited: false
    +body:
    +If that created seed is properly processed by the device ...
    +
    +comment: p1mbt7u
    +parent: t1_p1gnjd7
    +author: Javanaut018
    +created_utc: 1785837516
    +edited: false
    +body:
    +You audit their firmware thouroughly 
    
    Extracted text as captured
    post: 1vedae9
    author: coinwin
    created_utc: 1785763310
    title: With the coldcard stuff going on, I want to know the best way to keep my bitcoin safe.
    body:
    I've had some bitcoin in a keepkey and trezor for a long time.  I have my seed phrase and a pin on it.  Are there additional steps that would make it more secure?  Should I move the coins to a new wallet?  Are there any BIPs that have made modern wallets more secure?  I believe you can make a wallet with a 24 word seed phrase as opposed to a 12 word one.  Would that help significantly?
    
    comment: p1fz9z5
    parent: t3_1vedae9
    author: CatsBeerGardenCoffee
    created_utc: 1785763648
    edited: false
    body:
    I believe the people who got hacked were only relying on the cold card generated entropy. 
    
    If you have created your own randomness you should be good. If not, you should.
    
    comment: p1fzgir
    parent: t3_1vedae9
    author: Alive-Material4405
    created_utc: 1785763699
    edited: false
    body:
    iBit
    
    comment: p1fzvsl
    parent: t3_1vedae9
    author: boy_tue
    created_utc: 1785763823
    edited: false
    body:
    Give it to me, I'll watch it for you 😎
    
    comment: p1g1265
    parent: t3_1vedae9
    author: EyesFor1
    created_utc: 1785764167
    edited: false
    body:
    Its not what people want to hear because emotions and anger are high but CC are safe to use on the new firmware especially with 100+ dice roll. The error has been found and the bug fixed. The device is secure with dice roll but trust has been destroyed. People will still use them with dice rolls

    Excerpt only. The complete copy is held offline and backs quotations on this site. The original publication remains the canonical public source.

  7. Earliest copy held
    seen · Captured here 15,700 chars
    Extracted text as captured
    post: 1vedae9
    author: coinwin
    created_utc: 1785763310
    title: With the coldcard stuff going on, I want to know the best way to keep my bitcoin safe.
    body:
    I've had some bitcoin in a keepkey and trezor for a long time.  I have my seed phrase and a pin on it.  Are there additional steps that would make it more secure?  Should I move the coins to a new wallet?  Are there any BIPs that have made modern wallets more secure?  I believe you can make a wallet with a 24 word seed phrase as opposed to a 12 word one.  Would that help significantly?
    
    comment: p1fz9z5
    parent: t3_1vedae9
    author: CatsBeerGardenCoffee
    created_utc: 1785763648
    edited: false
    body:
    I believe the people who got hacked were only relying on the cold card generated entropy. 
    
    If you have created your own randomness you should be good. If not, you should.
    
    comment: p1fzgir
    parent: t3_1vedae9
    author: Alive-Material4405
    created_utc: 1785763699
    edited: false
    body:
    iBit
    
    comment: p1fzvsl
    parent: t3_1vedae9
    author: boy_tue
    created_utc: 1785763823
    edited: false
    body:
    Give it to me, I'll watch it for you 😎
    
    comment: p1g1265
    parent: t3_1vedae9
    author: EyesFor1
    created_utc: 1785764167
    edited: false
    body:
    Its not what people want to hear because emotions and anger are high but CC are safe to use on the new firmware especially with 100+ dice roll. The error has been found and the bug fixed. The device is secure with dice roll but trust has been destroyed. People will still use them with dice rolls

    Excerpt only. The complete copy is held offline and backs quotations on this site. The original publication remains the canonical public source.

How to check this yourself

The excerpts and plain unified diffs above show the text this project held and how it changed. To verify a quotation, compare it against the page itself or against the Internet Archive's copies, which are independent of this project.

Complete captures are held offline rather than mirrored here, so this page shows diffs and excerpts. If a quotation is ever disputed, the full copy can be produced. Ask.