r/Bitcoin: warning about misinformation around COLDCARD
reddit-coldcard-misinformation-warning
https://www.reddit.com/r/Bitcoin/comments/1vf5ohi/a_warning_about_misinformation_about_coldcard/
Latest reviewed change
source content difference between and
A comment accusing dice-roll users of laziness was deleted and now shows [deleted].
comment: p22xe52
parent: t1_p1n10lr
-author: evgeniy_pp
+author: [deleted]
created_utc: 1786031172
edited: false
body:
First lines only. The complete diff is in the timeline below.
- Organisation
- Evidence role
- Community discussion
- Published
- not established
- Source changes
- 3
- Detected differences
- 3
- Unreviewed
- 0
- Copies held
- 4
Every check is recorded, including checks that found no text change. A detected edit is therefore bounded between two checks. The publisher's exact save time is not observable from this record. Last checked .
This post is held twice: here, with this project's own note on why it matters, and again as part of the conversation captured at , which is polled for changes. Both copies are the same post; neither is a separate event.
Snapshot and diff bodies for this chain monitor are held in the local evidence archive but withheld from the public site because they can contain the addresses of people who published nothing themselves. Capture times and reviewed change summaries remain available below.
Held captures
-
A comment accusing dice-roll users of laziness was deleted and now shows [deleted].
Recovered from the Internet Archive rather than captured by this project. The row records that third-party provenance separately from captures made by this project.
What changed from the previous capture 4 lines
comment: p22xe52 parent: t1_p1n10lr -author: evgeniy_pp +author: [deleted] created_utc: 1786031172 edited: false body: -Who are these people who selected 24 words and dice, but was too lazy to finish the job and stoped halfway rolling? +[deleted] comment: p281ntn parent: t1_p22xe52Extracted text as captured
post: 1vf5ohi author: thomascr9695 created_utc: 1785836609 title: A warning about misinformation about coldcard body: I want to make this post because there is a lot of misinformation out there, and I believe this will result in many people losing their coins in panic, moving them to wrong wallets, addresses, weak security setups that are decided in splits seconds etc... First of all, wallets do not store your seedphrase, it matters how you generate your seedphrase. If you generated your seedphrase on a ledger, moved it to a coldcald wallet, there is no reason to move your coins. Second, if you generated a seedphrase on a coldcard wallet through their internal random generation, and then create a new seedphrase using dices you must still move your coins from your old seedphrase to your new seedphrase, yes I've seen people make this mistake. Second and most important, dice generation has not been hit, and dice generation can be tested with multiple wallets for example seedsigner. This specific bug contains only the internal seed creation, and again, if you have dice rolled your coins there is no need to worry. There are a lot of posts such as MOVE YOUR COINS FROM COLDWALLET NOW! or ALL COLDCARD WALLETS HACKED! But again, it simply matters **how** you generated the seed. If you generated your seed using sufficient dice rolls, the chance of moving your coins suddenly to a different wallet without thinking this through creates a higher risk of losing your coins. People hype up posts on X and Reddit, and it can be hard to understand this difference. If you do not remember how you generated your seedphrase, move your coins. If you generated them with a mix of internal generation + dices, move your coins. If you created your seed using ONLY dice rolls, you are safe. Second, regarding the internal seed generation on other devices besides the MK3, if you have an MK3 and used their internal seed generation without a passphrase those coins are now gone. However, for the MK4 for example and other devices, it still depends, and from what is known, it **may** still be unlikely that any other devices will get hacked. Or atleast its not that simple. There is a split between this, older coldcards prior to March 2021 are not a target in this bug as the bug was introduced on March 2021. The MK4 and wallets beyond were saved because the internal seed generation was slightly different from the MK3. The seed generation is still flawed, but coldcard itself estimates 72 bit, with some experts estimating 50-55 bit at minimum in some cases. While its hard to predict, your coins are at risk, but these are not as simple to be taken like MK3. For example, if indeed 72 bit is the correct number, it would still take billions and billions of dollars to bruteforce such addresses and it would require many many years. If its at minimum 50, that would be a matter of days. But this would only happen if the attacker has sufficient information regarding your device. While it can be hard to predict, if you are for example on holiday on the other side of the planet, it would be possible to slowly contact your friends, family, to go your house, get the seedphrase, and slowly but carefuly move your coins, and make sure you backup your seed correctly if you move to a different wallet. Third, if you have generated your seedphrase on an mk or any other coldcard wallet using their INTERNAL seed generation, and you do not have any wallet near you. Generating a new pasphrase through the internal dice generation is sufficient. It may sound scary because you're generating a new seed through coldcard, but the dice generation has been back tested, and can be tested through multiple wallet vendors such as for example seedsign. Fourth, there is a lot of people claiming that this is the end of cold storage. It is not. For example, think about planes. Planes crash all the time, and while things improve, planes still crash. Just because a plane crashed doesn't mean people will stop taking planes. This hack is a plane crash, and it is horrible, but this will not be the end of cold storage. There have been many planes that have crashed due bugs very similar to the coldcard bug. A single digit wrong. Even Even mars climate orbiter crashed due a very simple calculation error. These hacks will continue to happen, but they will not be the end of cold storage. Its scary but not the end. Fith, I see people being upset about coldcard and moving their coins to Ledger, trezos or exchanges. Important to note that we do not know how seed generation happens on Ledger for example. Ledger is closed source, and however it is unlikely, it is possible that ledger too has, or had, a seed generation error. Dice generation on a coldcard is still more secure than generating your seed on any device that programs its own seed generation, as wrong as that sounds. If you have a coldcard, generating your own seed using dices is still sufficient, however, I would take a different signing device for your transactions as the chance of them going out of business is high and firmware updates will stop updating and adjust to any future bitcoin updates. Sixth, if you have a passphrase you would have been saved. I believe setting a passphrase is important, even if you has a passphrase of your own name, your dogs name, your address, a single "A" charachter you would have likely been saved. I talked to someone who generated their wallet on an MK3 and got saved by a 2 word passphrase. Your wallet generation on dices is sufficient, but a passphrase can help you sleep better at night. If you any internal seed generation I think setting a passphrase is standard. At last, depending on how much coins you have, there may not be any need for a cold storage wallet, dice generation, seedphrases. I would only worry about such things when losing your coins could significantly hurt your financial status. Keeping your coins on coinbase, a simple ledger, is sufficient for most. comment: p1macel parent: t3_1vf5ohi author: Mak333 created_utc: 1785836817 edited: false body: Explain like I'm 5: Why can't these cold wallets simply use a USB key like Ubikey or similar? comment: p1manzl parent: t1_p1macel author: thomascr9695 created_utc: 1785836968 edited: false body: Its not relevant to the issueExcerpt only. The complete copy is held offline and backs quotations on this site. The original publication remains the canonical public source.
-
New reply by ukieninger telling the previous commenter they are completely missing the point.
Recovered from the Internet Archive rather than captured by this project. The row records that third-party provenance separately from captures made by this project.
What changed from the previous capture 8 lines
edited: false body: Who are these people who selected 24 words and dice, but was too lazy to finish the job and stoped halfway rolling? + +comment: p281ntn +parent: t1_p22xe52 +author: ukieninger +created_utc: 1786088966 +edited: false +body: +you are completely missing the point hereExtracted text as captured
post: 1vf5ohi author: thomascr9695 created_utc: 1785836609 title: A warning about misinformation about coldcard body: I want to make this post because there is a lot of misinformation out there, and I believe this will result in many people losing their coins in panic, moving them to wrong wallets, addresses, weak security setups that are decided in splits seconds etc... First of all, wallets do not store your seedphrase, it matters how you generate your seedphrase. If you generated your seedphrase on a ledger, moved it to a coldcald wallet, there is no reason to move your coins. Second, if you generated a seedphrase on a coldcard wallet through their internal random generation, and then create a new seedphrase using dices you must still move your coins from your old seedphrase to your new seedphrase, yes I've seen people make this mistake. Second and most important, dice generation has not been hit, and dice generation can be tested with multiple wallets for example seedsigner. This specific bug contains only the internal seed creation, and again, if you have dice rolled your coins there is no need to worry. There are a lot of posts such as MOVE YOUR COINS FROM COLDWALLET NOW! or ALL COLDCARD WALLETS HACKED! But again, it simply matters **how** you generated the seed. If you generated your seed using sufficient dice rolls, the chance of moving your coins suddenly to a different wallet without thinking this through creates a higher risk of losing your coins. People hype up posts on X and Reddit, and it can be hard to understand this difference. If you do not remember how you generated your seedphrase, move your coins. If you generated them with a mix of internal generation + dices, move your coins. If you created your seed using ONLY dice rolls, you are safe. Second, regarding the internal seed generation on other devices besides the MK3, if you have an MK3 and used their internal seed generation without a passphrase those coins are now gone. However, for the MK4 for example and other devices, it still depends, and from what is known, it **may** still be unlikely that any other devices will get hacked. Or atleast its not that simple. There is a split between this, older coldcards prior to March 2021 are not a target in this bug as the bug was introduced on March 2021. The MK4 and wallets beyond were saved because the internal seed generation was slightly different from the MK3. The seed generation is still flawed, but coldcard itself estimates 72 bit, with some experts estimating 50-55 bit at minimum in some cases. While its hard to predict, your coins are at risk, but these are not as simple to be taken like MK3. For example, if indeed 72 bit is the correct number, it would still take billions and billions of dollars to bruteforce such addresses and it would require many many years. If its at minimum 50, that would be a matter of days. But this would only happen if the attacker has sufficient information regarding your device. While it can be hard to predict, if you are for example on holiday on the other side of the planet, it would be possible to slowly contact your friends, family, to go your house, get the seedphrase, and slowly but carefuly move your coins, and make sure you backup your seed correctly if you move to a different wallet. Third, if you have generated your seedphrase on an mk or any other coldcard wallet using their INTERNAL seed generation, and you do not have any wallet near you. Generating a new pasphrase through the internal dice generation is sufficient. It may sound scary because you're generating a new seed through coldcard, but the dice generation has been back tested, and can be tested through multiple wallet vendors such as for example seedsign. Fourth, there is a lot of people claiming that this is the end of cold storage. It is not. For example, think about planes. Planes crash all the time, and while things improve, planes still crash. Just because a plane crashed doesn't mean people will stop taking planes. This hack is a plane crash, and it is horrible, but this will not be the end of cold storage. There have been many planes that have crashed due bugs very similar to the coldcard bug. A single digit wrong. Even Even mars climate orbiter crashed due a very simple calculation error. These hacks will continue to happen, but they will not be the end of cold storage. Its scary but not the end. Fith, I see people being upset about coldcard and moving their coins to Ledger, trezos or exchanges. Important to note that we do not know how seed generation happens on Ledger for example. Ledger is closed source, and however it is unlikely, it is possible that ledger too has, or had, a seed generation error. Dice generation on a coldcard is still more secure than generating your seed on any device that programs its own seed generation, as wrong as that sounds. If you have a coldcard, generating your own seed using dices is still sufficient, however, I would take a different signing device for your transactions as the chance of them going out of business is high and firmware updates will stop updating and adjust to any future bitcoin updates. Sixth, if you have a passphrase you would have been saved. I believe setting a passphrase is important, even if you has a passphrase of your own name, your dogs name, your address, a single "A" charachter you would have likely been saved. I talked to someone who generated their wallet on an MK3 and got saved by a 2 word passphrase. Your wallet generation on dices is sufficient, but a passphrase can help you sleep better at night. If you any internal seed generation I think setting a passphrase is standard. At last, depending on how much coins you have, there may not be any need for a cold storage wallet, dice generation, seedphrases. I would only worry about such things when losing your coins could significantly hurt your financial status. Keeping your coins on coinbase, a simple ledger, is sufficient for most. comment: p1macel parent: t3_1vf5ohi author: Mak333 created_utc: 1785836817 edited: false body: Explain like I'm 5: Why can't these cold wallets simply use a USB key like Ubikey or similar? comment: p1manzl parent: t1_p1macel author: thomascr9695 created_utc: 1785836968 edited: false body: Its not relevant to the issueExcerpt only. The complete copy is held offline and backs quotations on this site. The original publication remains the canonical public source.
-
New comment by evgeniy_pp mocking users who chose 24 words and dice but stopped rolling halfway.
Recovered from the Internet Archive rather than captured by this project. The row records that third-party provenance separately from captures made by this project.
What changed from the previous capture 8 lines
edited: false body: Away at work for another couple months. No way to check anything. Used 300 dice rolls…. Hoping I’m ok. If I’m not coinkite will be getting an in person visit. + +comment: p22xe52 +parent: t1_p1n10lr +author: evgeniy_pp +created_utc: 1786031172 +edited: false +body: +Who are these people who selected 24 words and dice, but was too lazy to finish the job and stoped halfway rolling?Extracted text as captured
post: 1vf5ohi author: thomascr9695 created_utc: 1785836609 title: A warning about misinformation about coldcard body: I want to make this post because there is a lot of misinformation out there, and I believe this will result in many people losing their coins in panic, moving them to wrong wallets, addresses, weak security setups that are decided in splits seconds etc... First of all, wallets do not store your seedphrase, it matters how you generate your seedphrase. If you generated your seedphrase on a ledger, moved it to a coldcald wallet, there is no reason to move your coins. Second, if you generated a seedphrase on a coldcard wallet through their internal random generation, and then create a new seedphrase using dices you must still move your coins from your old seedphrase to your new seedphrase, yes I've seen people make this mistake. Second and most important, dice generation has not been hit, and dice generation can be tested with multiple wallets for example seedsigner. This specific bug contains only the internal seed creation, and again, if you have dice rolled your coins there is no need to worry. There are a lot of posts such as MOVE YOUR COINS FROM COLDWALLET NOW! or ALL COLDCARD WALLETS HACKED! But again, it simply matters **how** you generated the seed. If you generated your seed using sufficient dice rolls, the chance of moving your coins suddenly to a different wallet without thinking this through creates a higher risk of losing your coins. People hype up posts on X and Reddit, and it can be hard to understand this difference. If you do not remember how you generated your seedphrase, move your coins. If you generated them with a mix of internal generation + dices, move your coins. If you created your seed using ONLY dice rolls, you are safe. Second, regarding the internal seed generation on other devices besides the MK3, if you have an MK3 and used their internal seed generation without a passphrase those coins are now gone. However, for the MK4 for example and other devices, it still depends, and from what is known, it **may** still be unlikely that any other devices will get hacked. Or atleast its not that simple. There is a split between this, older coldcards prior to March 2021 are not a target in this bug as the bug was introduced on March 2021. The MK4 and wallets beyond were saved because the internal seed generation was slightly different from the MK3. The seed generation is still flawed, but coldcard itself estimates 72 bit, with some experts estimating 50-55 bit at minimum in some cases. While its hard to predict, your coins are at risk, but these are not as simple to be taken like MK3. For example, if indeed 72 bit is the correct number, it would still take billions and billions of dollars to bruteforce such addresses and it would require many many years. If its at minimum 50, that would be a matter of days. But this would only happen if the attacker has sufficient information regarding your device. While it can be hard to predict, if you are for example on holiday on the other side of the planet, it would be possible to slowly contact your friends, family, to go your house, get the seedphrase, and slowly but carefuly move your coins, and make sure you backup your seed correctly if you move to a different wallet. Third, if you have generated your seedphrase on an mk or any other coldcard wallet using their INTERNAL seed generation, and you do not have any wallet near you. Generating a new pasphrase through the internal dice generation is sufficient. It may sound scary because you're generating a new seed through coldcard, but the dice generation has been back tested, and can be tested through multiple wallet vendors such as for example seedsign. Fourth, there is a lot of people claiming that this is the end of cold storage. It is not. For example, think about planes. Planes crash all the time, and while things improve, planes still crash. Just because a plane crashed doesn't mean people will stop taking planes. This hack is a plane crash, and it is horrible, but this will not be the end of cold storage. There have been many planes that have crashed due bugs very similar to the coldcard bug. A single digit wrong. Even Even mars climate orbiter crashed due a very simple calculation error. These hacks will continue to happen, but they will not be the end of cold storage. Its scary but not the end. Fith, I see people being upset about coldcard and moving their coins to Ledger, trezos or exchanges. Important to note that we do not know how seed generation happens on Ledger for example. Ledger is closed source, and however it is unlikely, it is possible that ledger too has, or had, a seed generation error. Dice generation on a coldcard is still more secure than generating your seed on any device that programs its own seed generation, as wrong as that sounds. If you have a coldcard, generating your own seed using dices is still sufficient, however, I would take a different signing device for your transactions as the chance of them going out of business is high and firmware updates will stop updating and adjust to any future bitcoin updates. Sixth, if you have a passphrase you would have been saved. I believe setting a passphrase is important, even if you has a passphrase of your own name, your dogs name, your address, a single "A" charachter you would have likely been saved. I talked to someone who generated their wallet on an MK3 and got saved by a 2 word passphrase. Your wallet generation on dices is sufficient, but a passphrase can help you sleep better at night. If you any internal seed generation I think setting a passphrase is standard. At last, depending on how much coins you have, there may not be any need for a cold storage wallet, dice generation, seedphrases. I would only worry about such things when losing your coins could significantly hurt your financial status. Keeping your coins on coinbase, a simple ledger, is sufficient for most. comment: p1macel parent: t3_1vf5ohi author: Mak333 created_utc: 1785836817 edited: false body: Explain like I'm 5: Why can't these cold wallets simply use a USB key like Ubikey or similar? comment: p1manzl parent: t1_p1macel author: thomascr9695 created_utc: 1785836968 edited: false body: Its not relevant to the issueExcerpt only. The complete copy is held offline and backs quotations on this site. The original publication remains the canonical public source.
-
Recovered from the Internet Archive rather than captured by this project. The row records that third-party provenance separately from captures made by this project.
What changed from the previous capture 0 lines
Extracted text as captured
post: 1vf5ohi author: thomascr9695 created_utc: 1785836609 title: A warning about misinformation about coldcard body: I want to make this post because there is a lot of misinformation out there, and I believe this will result in many people losing their coins in panic, moving them to wrong wallets, addresses, weak security setups that are decided in splits seconds etc... First of all, wallets do not store your seedphrase, it matters how you generate your seedphrase. If you generated your seedphrase on a ledger, moved it to a coldcald wallet, there is no reason to move your coins. Second, if you generated a seedphrase on a coldcard wallet through their internal random generation, and then create a new seedphrase using dices you must still move your coins from your old seedphrase to your new seedphrase, yes I've seen people make this mistake. Second and most important, dice generation has not been hit, and dice generation can be tested with multiple wallets for example seedsigner. This specific bug contains only the internal seed creation, and again, if you have dice rolled your coins there is no need to worry. There are a lot of posts such as MOVE YOUR COINS FROM COLDWALLET NOW! or ALL COLDCARD WALLETS HACKED! But again, it simply matters **how** you generated the seed. If you generated your seed using sufficient dice rolls, the chance of moving your coins suddenly to a different wallet without thinking this through creates a higher risk of losing your coins. People hype up posts on X and Reddit, and it can be hard to understand this difference. If you do not remember how you generated your seedphrase, move your coins. If you generated them with a mix of internal generation + dices, move your coins. If you created your seed using ONLY dice rolls, you are safe. Second, regarding the internal seed generation on other devices besides the MK3, if you have an MK3 and used their internal seed generation without a passphrase those coins are now gone. However, for the MK4 for example and other devices, it still depends, and from what is known, it **may** still be unlikely that any other devices will get hacked. Or atleast its not that simple. There is a split between this, older coldcards prior to March 2021 are not a target in this bug as the bug was introduced on March 2021. The MK4 and wallets beyond were saved because the internal seed generation was slightly different from the MK3. The seed generation is still flawed, but coldcard itself estimates 72 bit, with some experts estimating 50-55 bit at minimum in some cases. While its hard to predict, your coins are at risk, but these are not as simple to be taken like MK3. For example, if indeed 72 bit is the correct number, it would still take billions and billions of dollars to bruteforce such addresses and it would require many many years. If its at minimum 50, that would be a matter of days. But this would only happen if the attacker has sufficient information regarding your device. While it can be hard to predict, if you are for example on holiday on the other side of the planet, it would be possible to slowly contact your friends, family, to go your house, get the seedphrase, and slowly but carefuly move your coins, and make sure you backup your seed correctly if you move to a different wallet. Third, if you have generated your seedphrase on an mk or any other coldcard wallet using their INTERNAL seed generation, and you do not have any wallet near you. Generating a new pasphrase through the internal dice generation is sufficient. It may sound scary because you're generating a new seed through coldcard, but the dice generation has been back tested, and can be tested through multiple wallet vendors such as for example seedsign. Fourth, there is a lot of people claiming that this is the end of cold storage. It is not. For example, think about planes. Planes crash all the time, and while things improve, planes still crash. Just because a plane crashed doesn't mean people will stop taking planes. This hack is a plane crash, and it is horrible, but this will not be the end of cold storage. There have been many planes that have crashed due bugs very similar to the coldcard bug. A single digit wrong. Even Even mars climate orbiter crashed due a very simple calculation error. These hacks will continue to happen, but they will not be the end of cold storage. Its scary but not the end. Fith, I see people being upset about coldcard and moving their coins to Ledger, trezos or exchanges. Important to note that we do not know how seed generation happens on Ledger for example. Ledger is closed source, and however it is unlikely, it is possible that ledger too has, or had, a seed generation error. Dice generation on a coldcard is still more secure than generating your seed on any device that programs its own seed generation, as wrong as that sounds. If you have a coldcard, generating your own seed using dices is still sufficient, however, I would take a different signing device for your transactions as the chance of them going out of business is high and firmware updates will stop updating and adjust to any future bitcoin updates. Sixth, if you have a passphrase you would have been saved. I believe setting a passphrase is important, even if you has a passphrase of your own name, your dogs name, your address, a single "A" charachter you would have likely been saved. I talked to someone who generated their wallet on an MK3 and got saved by a 2 word passphrase. Your wallet generation on dices is sufficient, but a passphrase can help you sleep better at night. If you any internal seed generation I think setting a passphrase is standard. At last, depending on how much coins you have, there may not be any need for a cold storage wallet, dice generation, seedphrases. I would only worry about such things when losing your coins could significantly hurt your financial status. Keeping your coins on coinbase, a simple ledger, is sufficient for most. comment: p1macel parent: t3_1vf5ohi author: Mak333 created_utc: 1785836817 edited: false body: Explain like I'm 5: Why can't these cold wallets simply use a USB key like Ubikey or similar? comment: p1manzl parent: t1_p1macel author: thomascr9695 created_utc: 1785836968 edited: false body: Its not relevant to the issueExcerpt only. The complete copy is held offline and backs quotations on this site. The original publication remains the canonical public source.
0 presentation-noise differences. Sidebar, ticker and other page chrome churn that our review classified as not being changes to what the source says.
The excerpts and plain unified diffs above show the text this project held and how it changed. To verify a quotation, compare it against the page itself or against the Internet Archive's copies, which are independent of this project.
Complete captures are held offline rather than mirrored here, so this page shows diffs and excerpts. If a quotation is ever disputed, the full copy can be produced. Ask.
Compare the screenshot or a quotation against the original while it is available.