COLDCARD RNG incident the public record, collected and explained
Informational only, and this site never asks for your seed words. details

Informational only. This is an open source collection of what others have published about the incident, together with an explanation of it. It is not financial, security or legal advice, and not a substitute for professional advice about your own situation. It is not affiliated with, endorsed by, or speaking for Coinkite. Material is attributed and quoted as published; where sources disagree their scenarios are kept separate with their assumptions rather than reconciled into one answer. Everything is meant to be checked against the linked evidence rather than taken on trust. Act on your own judgement about a particular situation. Editorial standards and corrections.

Do not disclose recovery material to a website, form, message or support account. This site never asks for it, and contributions containing recovery words or private keys are not accepted.

r/Bitcoin: 1200 dice rolls testing bias in ordinary board-game dice

reddit-dice-bias-1200-rolls

https://www.reddit.com/r/Bitcoin/comments/1vi20y9/i_did_1200_dice_rolls_to_check_for_bias_in/

Latest reviewed change

source content difference between and

A comment from a since-deleted account was removed; it had argued that theoretical predictability is information and therefore decreases entropy.

seen +0 -9 full history below
 
 It would still be impossible to get to the key if you generated the key with the standard entropy.  
 
-comment: p2fzx36
-parent: t1_p2a4xfy
-author: [deleted]
-created_utc: 1786189209
-edited: false

First lines only. The complete diff is in the timeline below.

Organisation
reddit
Evidence role
Community discussion
Published
not established
Source changes
10
Detected differences
10
Unreviewed
0
Copies held
11

Every check is recorded, including checks that found no text change. A detected edit is therefore bounded between two checks. The publisher's exact save time is not observable from this record. Last checked .

  1. source content difference between and Current source content +0 -9

    A comment from a since-deleted account was removed; it had argued that theoretical predictability is information and therefore decreases entropy.

    seen · Captured here 34,921 chars
    What changed from the previous capture 9 lines
     
     It would still be impossible to get to the key if you generated the key with the standard entropy.  
     
    -comment: p2fzx36
    -parent: t1_p2a4xfy
    -author: [deleted]
    -created_utc: 1786189209
    -edited: false
    -body:
    -Practically I'm not sure but theoretically yes definitely true
    -This is information, so it decreases entropy
    -
     comment: p2gjia9
     parent: t3_1vi20y9
     author: abercrombezie
    
    Extracted text as captured
    post: 1vi20y9
    author: 10kpizza
    created_utc: 1786112563
    title: I did 1200 dice rolls to check for bias in ordinary board game dice
    body:
    Result: there is no detected bias, and regular dice can easily and quickly be used to generate good randomness
    
    I saw some FUD that you need special casino dice, and you have to roll them in some special way, and it's easy to get it wrong, and the surface needs to be completely flat, float the dice in water to check they're balanced, etc etc loads of FUD reasons why dice rolling won't work. So I checked myself in the spirit of don't trust verify.
    
    I found three dice lying around my house in some old board games. I rolled them inside a plastic cup that I'd shake for a second or two, then put the cup down bottom-up. The dice bounce off the walls of the cup and each other many times, which creates huge unpredictability.
    
    I originally was only meaning to do this for 200 rolls, but then became hyperfocused and just kept going. This data is brought to you by weaponized autism.
    
    Rolling 50 dice this way only took me 2-3 minutes, and it would be even faster if I had more dice.
    
    Now in any sample there will be some variation just by chance. We can understand that boundary with math. The binomial distribution describes these dice rolls. The standard deviation of the binomial distribution is sqrt(N p (1-p)) where p is probability (1/6 in this case) and N is number of trials (1200 in this case). Put the numbers in the formula, work out the percentage and you get a standard deviation of 1.08%, which means there's a 63% chance that those percentages in my graph will deviate by that much (and therefore 37% that the deviation will be outside that range just by chance). **Since my graph values are within that range there was no bias detected**. I worked out that to detect bias down to 0.1% I would need to roll 138888 time and I'm not going to roll that much. The percentage standard deviation goes as 1/sqrtN so it only improves slowly as you do more rolls.
    
    I was not affected by the recent coldcard hack and I've never owned that wallet, but it's interesting and important to check and improve.
    
    **I think the biggest thing people can do is multi-software multisig.** This is easy to do as many bitcoin wallets have multisig like electrum and sparrow. You just click buttons in the UI and don't need to do any math. Multisig security is additive. It removes a single point of failure. If coldcard users had made a 2-of-2 multisig with the most malware-ridden online desktop computer you've ever seen, then it will still be better security than coldcard alone, and they would still have their bitcoins today because the online desktop would have to be hacked separately which is unlikely.
    
    I've seen a big misunderstanding that most important thing is good randomness for seed generation, so people are thinking of using radioactive decay or something. It's not, **the most important thing for seed generation is having a secret number that nobody else knows**. Dice are perfect for this because they can be understood by anyone, and they can be used offline and behind closed doors.
    
    comment: p29sonv
    parent: t3_1vi20y9
    author: 10kpizza
    created_utc: 1786112730
    edited: false
    body:
    This is the raw data of my dice rolls if anyone wants to reanalyze.
    
    .
    
        32216412646314564633364534221253213652553224566313163632643544124326236135325523
        12544123366551535422366613131321211611363555611425665545313262362212631611321363
        36141542252166133224214114415314116546155162142351413352653624443445561415132245
        61134644513464136312624512512646433156245243323135316662611541511645524455344443
        32465121226561635253366236551242321432633512513126411311356145225421645145353411
        61242653446135335642654326136521133331146233621345452533215454345532544144162225
        64612245663461634153624544252545665313325243445366532466114341166245111352626635

    Excerpt only. The complete copy is held offline and backs quotations on this site. The original publication remains the canonical public source.

  2. source content difference between and source content +1 -21

    Two comments by OddBritishMan on dice technique and seed generation were removed, and another comment author changed to [deleted].

    seen · Captured here 35,128 chars
    What changed from the previous capture 22 lines
     body:
     And you could just offset it with a few extra rolls.
     
    -comment: p2bmlky
    -parent: t3_1vi20y9
    -author: OddBritishMan
    -created_utc: 1786129768
    -edited: false
    -body:
    -I read that the dice have to be rolled using the same technique everytime... But surely it's better to roll the dice differently everytime to add unpredictability. I  might order some casino dice, and try. Also coin flips might be better, but take longer to generate a seed. 
    -
     comment: p2bn085
     parent: t3_1vi20y9
     author: stargate425
     The math for this is that d6 dice create (6)\^(rolls) unique values, i.e. 100 rolls is about 10\^77 (a 77-digit integer, base 10) or about 2\^258. So, effectively, 100 d6 rolls is about 258 bits of entropy, which is quite good.
     
     The seed words are in a list of 2048 (2\^11) or exactly 11 bits of entropy per word. 24 words x 11 bits of entropy is 264 bits of total entropy. We can use dice rolls or words from a bag because in the end the order of them creates a very large integer that comfortably contains at least 256 bits of entropy.
    -
    -comment: p2bp0pi
    -parent: t1_p2avi14
    -author: OddBritishMan
    -created_utc: 1786130407
    -edited: false
    -body:
    -You don't total the dice results. 
    -
    -You have to roll a dice 99 times and enter the 99 character result into a seedsigner or coldcard to create the seed.
    -
    -Or, you can also create a seed using 256 coinflips, and then enter the 23 words into a seedsigner to create the checksum word
     
     comment: p2bv298
     parent: t1_p2apmzj
     
     comment: p2fzx36
     parent: t1_p2a4xfy
    -author: Any-Mousse9648
    +author: [deleted]
     created_utc: 1786189209
     edited: false
     body:
    
    Extracted text as captured
    post: 1vi20y9
    author: 10kpizza
    created_utc: 1786112563
    title: I did 1200 dice rolls to check for bias in ordinary board game dice
    body:
    Result: there is no detected bias, and regular dice can easily and quickly be used to generate good randomness
    
    I saw some FUD that you need special casino dice, and you have to roll them in some special way, and it's easy to get it wrong, and the surface needs to be completely flat, float the dice in water to check they're balanced, etc etc loads of FUD reasons why dice rolling won't work. So I checked myself in the spirit of don't trust verify.
    
    I found three dice lying around my house in some old board games. I rolled them inside a plastic cup that I'd shake for a second or two, then put the cup down bottom-up. The dice bounce off the walls of the cup and each other many times, which creates huge unpredictability.
    
    I originally was only meaning to do this for 200 rolls, but then became hyperfocused and just kept going. This data is brought to you by weaponized autism.
    
    Rolling 50 dice this way only took me 2-3 minutes, and it would be even faster if I had more dice.
    
    Now in any sample there will be some variation just by chance. We can understand that boundary with math. The binomial distribution describes these dice rolls. The standard deviation of the binomial distribution is sqrt(N p (1-p)) where p is probability (1/6 in this case) and N is number of trials (1200 in this case). Put the numbers in the formula, work out the percentage and you get a standard deviation of 1.08%, which means there's a 63% chance that those percentages in my graph will deviate by that much (and therefore 37% that the deviation will be outside that range just by chance). **Since my graph values are within that range there was no bias detected**. I worked out that to detect bias down to 0.1% I would need to roll 138888 time and I'm not going to roll that much. The percentage standard deviation goes as 1/sqrtN so it only improves slowly as you do more rolls.
    
    I was not affected by the recent coldcard hack and I've never owned that wallet, but it's interesting and important to check and improve.
    
    **I think the biggest thing people can do is multi-software multisig.** This is easy to do as many bitcoin wallets have multisig like electrum and sparrow. You just click buttons in the UI and don't need to do any math. Multisig security is additive. It removes a single point of failure. If coldcard users had made a 2-of-2 multisig with the most malware-ridden online desktop computer you've ever seen, then it will still be better security than coldcard alone, and they would still have their bitcoins today because the online desktop would have to be hacked separately which is unlikely.
    
    I've seen a big misunderstanding that most important thing is good randomness for seed generation, so people are thinking of using radioactive decay or something. It's not, **the most important thing for seed generation is having a secret number that nobody else knows**. Dice are perfect for this because they can be understood by anyone, and they can be used offline and behind closed doors.
    
    comment: p29sonv
    parent: t3_1vi20y9
    author: 10kpizza
    created_utc: 1786112730
    edited: false
    body:
    This is the raw data of my dice rolls if anyone wants to reanalyze.
    
    .
    
        32216412646314564633364534221253213652553224566313163632643544124326236135325523
        12544123366551535422366613131321211611363555611425665545313262362212631611321363
        36141542252166133224214114415314116546155162142351413352653624443445561415132245
        61134644513464136312624512512646433156245243323135316662611541511645524455344443
        32465121226561635253366236551242321432633512513126411311356145225421645145353411
        61242653446135335642654326136521133331146233621345452533215454345532544144162225
        64612245663461634153624544252545665313325243445366532466114341166245111352626635

    Excerpt only. The complete copy is held offline and backs quotations on this site. The original publication remains the canonical public source.

  3. source content difference between and source content +12 -0

    The thread gained a reply discussing why casino dice are rolled openly and noting that even a significant bias would cost little entropy.

    seen · Captured here 35,895 chars
    What changed from the previous capture 12 lines
     edited: false
     body:
     I wonder why you need perfect "casinio" dice playing craps at the Wynn but your 20 year old yahtzze dice will do the job against the most determined hackers on earth using an ever increasing and powerful AI to find "entropy" exploits? The casinos pay a premium for those dice for a reason and change them out frequently. 
    +
    +comment: p2u1zoj
    +parent: t1_p2kvl9n
    +author: 10kpizza
    +created_utc: 1786369392
    +edited: 1786369856
    +body:
    +I also wondered this. Maybe its because I'm rolling inside a plastic cup, but casinos make you roll the dice out in the open.
    +
    +The threat model is different. The person rolling dice in a casino wants them to be biased, so that they might win, and the casino people watching them try to make sure they throw it properly. Watching them is harder if they roll inside a cup. But for bitcoin the roller wants the dice to be unbiased and has to make sure nobody is watching them.
    +
    +Someone else in the comments calculated that even if there was a significant bias the entropy wouldnt drop very much. You could just do more rolls.
    
    Extracted text as captured
    post: 1vi20y9
    author: 10kpizza
    created_utc: 1786112563
    title: I did 1200 dice rolls to check for bias in ordinary board game dice
    body:
    Result: there is no detected bias, and regular dice can easily and quickly be used to generate good randomness
    
    I saw some FUD that you need special casino dice, and you have to roll them in some special way, and it's easy to get it wrong, and the surface needs to be completely flat, float the dice in water to check they're balanced, etc etc loads of FUD reasons why dice rolling won't work. So I checked myself in the spirit of don't trust verify.
    
    I found three dice lying around my house in some old board games. I rolled them inside a plastic cup that I'd shake for a second or two, then put the cup down bottom-up. The dice bounce off the walls of the cup and each other many times, which creates huge unpredictability.
    
    I originally was only meaning to do this for 200 rolls, but then became hyperfocused and just kept going. This data is brought to you by weaponized autism.
    
    Rolling 50 dice this way only took me 2-3 minutes, and it would be even faster if I had more dice.
    
    Now in any sample there will be some variation just by chance. We can understand that boundary with math. The binomial distribution describes these dice rolls. The standard deviation of the binomial distribution is sqrt(N p (1-p)) where p is probability (1/6 in this case) and N is number of trials (1200 in this case). Put the numbers in the formula, work out the percentage and you get a standard deviation of 1.08%, which means there's a 63% chance that those percentages in my graph will deviate by that much (and therefore 37% that the deviation will be outside that range just by chance). **Since my graph values are within that range there was no bias detected**. I worked out that to detect bias down to 0.1% I would need to roll 138888 time and I'm not going to roll that much. The percentage standard deviation goes as 1/sqrtN so it only improves slowly as you do more rolls.
    
    I was not affected by the recent coldcard hack and I've never owned that wallet, but it's interesting and important to check and improve.
    
    **I think the biggest thing people can do is multi-software multisig.** This is easy to do as many bitcoin wallets have multisig like electrum and sparrow. You just click buttons in the UI and don't need to do any math. Multisig security is additive. It removes a single point of failure. If coldcard users had made a 2-of-2 multisig with the most malware-ridden online desktop computer you've ever seen, then it will still be better security than coldcard alone, and they would still have their bitcoins today because the online desktop would have to be hacked separately which is unlikely.
    
    I've seen a big misunderstanding that most important thing is good randomness for seed generation, so people are thinking of using radioactive decay or something. It's not, **the most important thing for seed generation is having a secret number that nobody else knows**. Dice are perfect for this because they can be understood by anyone, and they can be used offline and behind closed doors.
    
    comment: p29sonv
    parent: t3_1vi20y9
    author: 10kpizza
    created_utc: 1786112730
    edited: false
    body:
    This is the raw data of my dice rolls if anyone wants to reanalyze.
    
    .
    
        32216412646314564633364534221253213652553224566313163632643544124326236135325523
        12544123366551535422366613131321211611363555611425665545313262362212631611321363
        36141542252166133224214114415314116546155162142351413352653624443445561415132245
        61134644513464136312624512512646433156245243323135316662611541511645524455344443
        32465121226561635253366236551242321432633512513126411311356145225421645145353411
        61242653446135335642654326136521133331146233621345452533215454345532544144162225
        64612245663461634153624544252545665313325243445366532466114341166245111352626635

    Excerpt only. The complete copy is held offline and backs quotations on this site. The original publication remains the canonical public source.

  4. source content difference between and source content +16 -1

    The author edited the post to clarify they do not support Coldcard and to defend dice rolls as a practical source of entropy.

    seen · Captured here 35,169 chars
    What changed from the previous capture 17 lines
     parent: t1_p2ejdfy
     author: Past_Permission_6123
     created_utc: 1786218345
    -edited: false
    +edited: 1786296805
     body:
     I think you make dice rolling sound a lot more complicated than it is. Any ColdCard hardware wallet user should be able to do it, the ColdCard devs even recommended to use dice rolls for the best security. It's an optional part of the setup and described in the official user guide: [https://coldcard.com/docs/master-seed/#create-a-new-master-seed](https://coldcard.com/docs/master-seed/#create-a-new-master-seed)
    +
    +Edit: Just to be clear I am in no way supporting ColdCard, and I've never owned one. I only mentioned them because they recommended dice rolling around the same time the seed generation vulnerability was introduced. Point being it's a simple, established method to generate entropy on your own, and it is/was easy to do on their device.
    +
    +>The best recommendation is to use a strong passphrase
    +
    +That's a good idea for sure, but the recent hack demonstrates that a lot of people simply didn't follow this advice. If you can use dice roll for the pass phrase, you can do so with the seed generation as well. Both methods are prone to be vulnerable if you don't know what you are doing. Making up your own pass phrase like many people do is well known to not be very secure.
    +
    +And I agree most people should not follow a complex process if they don't know what they are doing, but I think this is a given. Actually I think most "regular" people should not own a hardware wallet because of all the potential mistakes, there are many ways you can lose you keys or get hacked.
    +
    +>What maths qualifications does the op have to conclude that there is no bias... Let me guess none.  
    +My intuition says when computers do guess in the orders of millions and billions a thousand is insignificant.
    +
    +This comment tells me you have no clue about the math involved, so it would be pretty bold of you to imply that dice rolling is not good enough for entropy. This is high school level math, it's really not that hard. Generating good entropy on a computer is hard to do on your own with efficient algorithms, while doing it with dice is easy - anyone can do it. That is the real point I wanted to make in this thread.
    +
    +I understand the analogy with ‘*Don’t roll your own crypto*’, but I don't think it's fitting to this discussion. As mentioned in [this blogpost](https://samuellucas.com/2024/08/31/debunking-dont-roll-your-own-crypto.html), "Even cryptographers working in teams come up with [broken](https://eprint.iacr.org/2022/214) [algorithms](https://eprint.iacr.org/2022/975) all the time."
     
     comment: p2kvl9n
     parent: t3_1vi20y9
    
    Extracted text as captured
    post: 1vi20y9
    author: 10kpizza
    created_utc: 1786112563
    title: I did 1200 dice rolls to check for bias in ordinary board game dice
    body:
    Result: there is no detected bias, and regular dice can easily and quickly be used to generate good randomness
    
    I saw some FUD that you need special casino dice, and you have to roll them in some special way, and it's easy to get it wrong, and the surface needs to be completely flat, float the dice in water to check they're balanced, etc etc loads of FUD reasons why dice rolling won't work. So I checked myself in the spirit of don't trust verify.
    
    I found three dice lying around my house in some old board games. I rolled them inside a plastic cup that I'd shake for a second or two, then put the cup down bottom-up. The dice bounce off the walls of the cup and each other many times, which creates huge unpredictability.
    
    I originally was only meaning to do this for 200 rolls, but then became hyperfocused and just kept going. This data is brought to you by weaponized autism.
    
    Rolling 50 dice this way only took me 2-3 minutes, and it would be even faster if I had more dice.
    
    Now in any sample there will be some variation just by chance. We can understand that boundary with math. The binomial distribution describes these dice rolls. The standard deviation of the binomial distribution is sqrt(N p (1-p)) where p is probability (1/6 in this case) and N is number of trials (1200 in this case). Put the numbers in the formula, work out the percentage and you get a standard deviation of 1.08%, which means there's a 63% chance that those percentages in my graph will deviate by that much (and therefore 37% that the deviation will be outside that range just by chance). **Since my graph values are within that range there was no bias detected**. I worked out that to detect bias down to 0.1% I would need to roll 138888 time and I'm not going to roll that much. The percentage standard deviation goes as 1/sqrtN so it only improves slowly as you do more rolls.
    
    I was not affected by the recent coldcard hack and I've never owned that wallet, but it's interesting and important to check and improve.
    
    **I think the biggest thing people can do is multi-software multisig.** This is easy to do as many bitcoin wallets have multisig like electrum and sparrow. You just click buttons in the UI and don't need to do any math. Multisig security is additive. It removes a single point of failure. If coldcard users had made a 2-of-2 multisig with the most malware-ridden online desktop computer you've ever seen, then it will still be better security than coldcard alone, and they would still have their bitcoins today because the online desktop would have to be hacked separately which is unlikely.
    
    I've seen a big misunderstanding that most important thing is good randomness for seed generation, so people are thinking of using radioactive decay or something. It's not, **the most important thing for seed generation is having a secret number that nobody else knows**. Dice are perfect for this because they can be understood by anyone, and they can be used offline and behind closed doors.
    
    comment: p29sonv
    parent: t3_1vi20y9
    author: 10kpizza
    created_utc: 1786112730
    edited: false
    body:
    This is the raw data of my dice rolls if anyone wants to reanalyze.
    
    .
    
        32216412646314564633364534221253213652553224566313163632643544124326236135325523
        12544123366551535422366613131321211611363555611425665545313262362212631611321363
        36141542252166133224214114415314116546155162142351413352653624443445561415132245
        61134644513464136312624512512646433156245243323135316662611541511645524455344443
        32465121226561635253366236551242321432633512513126411311356145225421645145353411
        61242653446135335642654326136521133331146233621345452533215454345532544144162225
        64612245663461634153624544252545665313325243445366532466114341166245111352626635

    Excerpt only. The complete copy is held offline and backs quotations on this site. The original publication remains the canonical public source.

  5. source content difference between and source content +8 -0

    A new comment questioned why ordinary board-game dice would suffice against determined attackers when casinos pay a premium for controlled dice.

    seen · Captured here 33,084 chars
    What changed from the previous capture 8 lines
     edited: false
     body:
     I think you make dice rolling sound a lot more complicated than it is. Any ColdCard hardware wallet user should be able to do it, the ColdCard devs even recommended to use dice rolls for the best security. It's an optional part of the setup and described in the official user guide: [https://coldcard.com/docs/master-seed/#create-a-new-master-seed](https://coldcard.com/docs/master-seed/#create-a-new-master-seed)
    +
    +comment: p2kvl9n
    +parent: t3_1vi20y9
    +author: Live-Resident-6650
    +created_utc: 1786245196
    +edited: false
    +body:
    +I wonder why you need perfect "casinio" dice playing craps at the Wynn but your 20 year old yahtzze dice will do the job against the most determined hackers on earth using an ever increasing and powerful AI to find "entropy" exploits? The casinos pay a premium for those dice for a reason and change them out frequently. 
    
    Extracted text as captured
    post: 1vi20y9
    author: 10kpizza
    created_utc: 1786112563
    title: I did 1200 dice rolls to check for bias in ordinary board game dice
    body:
    Result: there is no detected bias, and regular dice can easily and quickly be used to generate good randomness
    
    I saw some FUD that you need special casino dice, and you have to roll them in some special way, and it's easy to get it wrong, and the surface needs to be completely flat, float the dice in water to check they're balanced, etc etc loads of FUD reasons why dice rolling won't work. So I checked myself in the spirit of don't trust verify.
    
    I found three dice lying around my house in some old board games. I rolled them inside a plastic cup that I'd shake for a second or two, then put the cup down bottom-up. The dice bounce off the walls of the cup and each other many times, which creates huge unpredictability.
    
    I originally was only meaning to do this for 200 rolls, but then became hyperfocused and just kept going. This data is brought to you by weaponized autism.
    
    Rolling 50 dice this way only took me 2-3 minutes, and it would be even faster if I had more dice.
    
    Now in any sample there will be some variation just by chance. We can understand that boundary with math. The binomial distribution describes these dice rolls. The standard deviation of the binomial distribution is sqrt(N p (1-p)) where p is probability (1/6 in this case) and N is number of trials (1200 in this case). Put the numbers in the formula, work out the percentage and you get a standard deviation of 1.08%, which means there's a 63% chance that those percentages in my graph will deviate by that much (and therefore 37% that the deviation will be outside that range just by chance). **Since my graph values are within that range there was no bias detected**. I worked out that to detect bias down to 0.1% I would need to roll 138888 time and I'm not going to roll that much. The percentage standard deviation goes as 1/sqrtN so it only improves slowly as you do more rolls.
    
    I was not affected by the recent coldcard hack and I've never owned that wallet, but it's interesting and important to check and improve.
    
    **I think the biggest thing people can do is multi-software multisig.** This is easy to do as many bitcoin wallets have multisig like electrum and sparrow. You just click buttons in the UI and don't need to do any math. Multisig security is additive. It removes a single point of failure. If coldcard users had made a 2-of-2 multisig with the most malware-ridden online desktop computer you've ever seen, then it will still be better security than coldcard alone, and they would still have their bitcoins today because the online desktop would have to be hacked separately which is unlikely.
    
    I've seen a big misunderstanding that most important thing is good randomness for seed generation, so people are thinking of using radioactive decay or something. It's not, **the most important thing for seed generation is having a secret number that nobody else knows**. Dice are perfect for this because they can be understood by anyone, and they can be used offline and behind closed doors.
    
    comment: p29sonv
    parent: t3_1vi20y9
    author: 10kpizza
    created_utc: 1786112730
    edited: false
    body:
    This is the raw data of my dice rolls if anyone wants to reanalyze.
    
    .
    
        32216412646314564633364534221253213652553224566313163632643544124326236135325523
        12544123366551535422366613131321211611363555611425665545313262362212631611321363
        36141542252166133224214114415314116546155162142351413352653624443445561415132245
        61134644513464136312624512512646433156245243323135316662611541511645524455344443
        32465121226561635253366236551242321432633512513126411311356145225421645145353411
        61242653446135335642654326136521133331146233621345452533215454345532544144162225
        64612245663461634153624544252545665313325243445366532466114341166245111352626635

    Excerpt only. The complete copy is held offline and backs quotations on this site. The original publication remains the canonical public source.

  6. source content difference between and source content +58 -0

    The thread gained new comments arguing that ordinary dice bias has little effect on seed entropy and that SHA-256 hashing destroys patterns.

    seen · Captured here 32,654 chars
    What changed from the previous capture 58 lines
     edited: false
     body:
     If you do the math it's actually quite surprising just how much bias is needed before it starts to become a problem. For instance, a seed phrase generated from biased coin flips only loses 3% of its entropy even with a 60/40 bias [(source)](https://www.wolframalpha.com/input?i=-.4*log2%28.4%29-.6*log2%28.6%29). Meaning that a 24 word seed phrase would drop down to 248 bits of entropy from 256, meanwhile even 128 bits is still secure.
    +
    +comment: p2hq6na
    +parent: t1_p2b282x
    +author: RefrigeratorLow1259
    +created_utc: 1786208878
    +edited: false
    +body:
    +
    +
    +Yes, if you roll it 100 times, then even if it seems completely biased towards 6, it will generate enough entropy. That's the Shannon equation for measuring uncertainty.
    + The probability of a number being 50%, and the rest 5 being 10% each, still gives 2.16 bits of entropy on each roll, which is 0.42 less than in a completely unbiased dice, but enough nevertheless if you simply roll it a few times more.
    +
    +It simply takes time to verify that the dice won't fare worse than that. In contrast, coin flipping using von Neumann's method necessitates no precautionary measures.
    +
    +comment: p2hyas3
    +parent: t3_1vi20y9
    +author: RefrigeratorLow1259
    +created_utc: 1786211145
    +edited: false
    +body:
    +Bias makes little difference in the entropy calculation...check out Shannon entropy. For dice rolls entropy should be 2.585, but even if the 6 came up twice as often as the other numbers it only reduces entropy to 2.522.
    +Also remember that running all the throws through a SHA-256 cryptograohic hashing function destroys any patterns. 
    +
    +comment: p2i3dox
    +parent: t1_p2hq6na
    +author: Deto
    +created_utc: 1786212580
    +edited: false
    +body:
    +I still don't see how you would even need precautionary measures with dice even.  Like you said - even a large bias (completely unrealistic) just reduces the entropy a little.  And an attacker couldn't even exploit that bias unless it was a systematic bias among ALL dice since they wouldn't be able to infer one accounts dice'  bias anyways. 
    +
    +All the unnecessary hand wringing and FUD about dice bias is just going to push people to less secure measures.
    +
    +comment: p2ih6rs
    +parent: t1_p2e9rda
    +author: marvinrabbit
    +created_utc: 1786216538
    +edited: false
    +body:
    +This is effectively doing so. This checks not just the dice, but the rolling technique and any ancillary equipment. Think of an extreme example; if you had perfect, verified, casino grade dice but very carefully placed every one so that it showed as '1'. The graph would show complete bias. So this is testing everything in the dice rolling system
    +
    +comment: p2iikjf
    +parent: t1_p2aux9j
    +author: marvinrabbit
    +created_utc: 1786216944
    +edited: false
    +body:
    +I think you missed the point, probably very purposely so. This is a mathematical experiment with average dice to show that perfect, casino grade, dice really aren't required and something that you already have should be good enough. This isn't something that every person would go through. 
    +
    +But your level of snark shows the true reason for your comment, so I don't expect you to see anything but what you already want to see.
    +
    +comment: p2inc6p
    +parent: t1_p2ejdfy
    +author: Past_Permission_6123
    +created_utc: 1786218345
    +edited: false
    +body:
    +I think you make dice rolling sound a lot more complicated than it is. Any ColdCard hardware wallet user should be able to do it, the ColdCard devs even recommended to use dice rolls for the best security. It's an optional part of the setup and described in the official user guide: [https://coldcard.com/docs/master-seed/#create-a-new-master-seed](https://coldcard.com/docs/master-seed/#create-a-new-master-seed)
    
    Extracted text as captured
    post: 1vi20y9
    author: 10kpizza
    created_utc: 1786112563
    title: I did 1200 dice rolls to check for bias in ordinary board game dice
    body:
    Result: there is no detected bias, and regular dice can easily and quickly be used to generate good randomness
    
    I saw some FUD that you need special casino dice, and you have to roll them in some special way, and it's easy to get it wrong, and the surface needs to be completely flat, float the dice in water to check they're balanced, etc etc loads of FUD reasons why dice rolling won't work. So I checked myself in the spirit of don't trust verify.
    
    I found three dice lying around my house in some old board games. I rolled them inside a plastic cup that I'd shake for a second or two, then put the cup down bottom-up. The dice bounce off the walls of the cup and each other many times, which creates huge unpredictability.
    
    I originally was only meaning to do this for 200 rolls, but then became hyperfocused and just kept going. This data is brought to you by weaponized autism.
    
    Rolling 50 dice this way only took me 2-3 minutes, and it would be even faster if I had more dice.
    
    Now in any sample there will be some variation just by chance. We can understand that boundary with math. The binomial distribution describes these dice rolls. The standard deviation of the binomial distribution is sqrt(N p (1-p)) where p is probability (1/6 in this case) and N is number of trials (1200 in this case). Put the numbers in the formula, work out the percentage and you get a standard deviation of 1.08%, which means there's a 63% chance that those percentages in my graph will deviate by that much (and therefore 37% that the deviation will be outside that range just by chance). **Since my graph values are within that range there was no bias detected**. I worked out that to detect bias down to 0.1% I would need to roll 138888 time and I'm not going to roll that much. The percentage standard deviation goes as 1/sqrtN so it only improves slowly as you do more rolls.
    
    I was not affected by the recent coldcard hack and I've never owned that wallet, but it's interesting and important to check and improve.
    
    **I think the biggest thing people can do is multi-software multisig.** This is easy to do as many bitcoin wallets have multisig like electrum and sparrow. You just click buttons in the UI and don't need to do any math. Multisig security is additive. It removes a single point of failure. If coldcard users had made a 2-of-2 multisig with the most malware-ridden online desktop computer you've ever seen, then it will still be better security than coldcard alone, and they would still have their bitcoins today because the online desktop would have to be hacked separately which is unlikely.
    
    I've seen a big misunderstanding that most important thing is good randomness for seed generation, so people are thinking of using radioactive decay or something. It's not, **the most important thing for seed generation is having a secret number that nobody else knows**. Dice are perfect for this because they can be understood by anyone, and they can be used offline and behind closed doors.
    
    comment: p29sonv
    parent: t3_1vi20y9
    author: 10kpizza
    created_utc: 1786112730
    edited: false
    body:
    This is the raw data of my dice rolls if anyone wants to reanalyze.
    
    .
    
        32216412646314564633364534221253213652553224566313163632643544124326236135325523
        12544123366551535422366613131321211611363555611425665545313262362212631611321363
        36141542252166133224214114415314116546155162142351413352653624443445561415132245
        61134644513464136312624512512646433156245243323135316662611541511645524455344443
        32465121226561635253366236551242321432633512513126411311356145225421645145353411
        61242653446135335642654326136521133331146233621345452533215454345532544144162225
        64612245663461634153624544252545665313325243445366532466114341166245111352626635

    Excerpt only. The complete copy is held offline and backs quotations on this site. The original publication remains the canonical public source.

  7. source content difference between and source content +25 -0

    The thread gained new replies discussing whether bias decreases entropy, the role of cup-shaking in mixing dice, and the resilience of a 24-word seed to biased coin flips.

    seen · Captured here 29,468 chars
    What changed from the previous capture 25 lines
     Even if a hacker knew the exact bias with billions of roles of data with the exact bias we see on this post ( which is a very small sample this post so the bias will even be much smaller)
     
     It would still be impossible to get to the key if you generated the key with the standard entropy.  
    +
    +comment: p2fzx36
    +parent: t1_p2a4xfy
    +author: Any-Mousse9648
    +created_utc: 1786189209
    +edited: false
    +body:
    +Practically I'm not sure but theoretically yes definitely true
    +This is information, so it decreases entropy
    +
    +comment: p2gjia9
    +parent: t3_1vi20y9
    +author: abercrombezie
    +created_utc: 1786196324
    +edited: false
    +body:
    +So, just got into the dice game after last weekend's fiasco with ColdCard.  I've found that the act of jumbling  the dice within the cup is the majority of the random mixing, emptying on the board is just a few tumbles.
    +
    +comment: p2gjyg0
    +parent: t3_1vi20y9
    +author: scottmsul
    +created_utc: 1786196469
    +edited: false
    +body:
    +If you do the math it's actually quite surprising just how much bias is needed before it starts to become a problem. For instance, a seed phrase generated from biased coin flips only loses 3% of its entropy even with a 60/40 bias [(source)](https://www.wolframalpha.com/input?i=-.4*log2%28.4%29-.6*log2%28.6%29). Meaning that a 24 word seed phrase would drop down to 248 bits of entropy from 256, meanwhile even 128 bits is still secure.
    
    Extracted text as captured
    post: 1vi20y9
    author: 10kpizza
    created_utc: 1786112563
    title: I did 1200 dice rolls to check for bias in ordinary board game dice
    body:
    Result: there is no detected bias, and regular dice can easily and quickly be used to generate good randomness
    
    I saw some FUD that you need special casino dice, and you have to roll them in some special way, and it's easy to get it wrong, and the surface needs to be completely flat, float the dice in water to check they're balanced, etc etc loads of FUD reasons why dice rolling won't work. So I checked myself in the spirit of don't trust verify.
    
    I found three dice lying around my house in some old board games. I rolled them inside a plastic cup that I'd shake for a second or two, then put the cup down bottom-up. The dice bounce off the walls of the cup and each other many times, which creates huge unpredictability.
    
    I originally was only meaning to do this for 200 rolls, but then became hyperfocused and just kept going. This data is brought to you by weaponized autism.
    
    Rolling 50 dice this way only took me 2-3 minutes, and it would be even faster if I had more dice.
    
    Now in any sample there will be some variation just by chance. We can understand that boundary with math. The binomial distribution describes these dice rolls. The standard deviation of the binomial distribution is sqrt(N p (1-p)) where p is probability (1/6 in this case) and N is number of trials (1200 in this case). Put the numbers in the formula, work out the percentage and you get a standard deviation of 1.08%, which means there's a 63% chance that those percentages in my graph will deviate by that much (and therefore 37% that the deviation will be outside that range just by chance). **Since my graph values are within that range there was no bias detected**. I worked out that to detect bias down to 0.1% I would need to roll 138888 time and I'm not going to roll that much. The percentage standard deviation goes as 1/sqrtN so it only improves slowly as you do more rolls.
    
    I was not affected by the recent coldcard hack and I've never owned that wallet, but it's interesting and important to check and improve.
    
    **I think the biggest thing people can do is multi-software multisig.** This is easy to do as many bitcoin wallets have multisig like electrum and sparrow. You just click buttons in the UI and don't need to do any math. Multisig security is additive. It removes a single point of failure. If coldcard users had made a 2-of-2 multisig with the most malware-ridden online desktop computer you've ever seen, then it will still be better security than coldcard alone, and they would still have their bitcoins today because the online desktop would have to be hacked separately which is unlikely.
    
    I've seen a big misunderstanding that most important thing is good randomness for seed generation, so people are thinking of using radioactive decay or something. It's not, **the most important thing for seed generation is having a secret number that nobody else knows**. Dice are perfect for this because they can be understood by anyone, and they can be used offline and behind closed doors.
    
    comment: p29sonv
    parent: t3_1vi20y9
    author: 10kpizza
    created_utc: 1786112730
    edited: false
    body:
    This is the raw data of my dice rolls if anyone wants to reanalyze.
    
    .
    
        32216412646314564633364534221253213652553224566313163632643544124326236135325523
        12544123366551535422366613131321211611363555611425665545313262362212631611321363
        36141542252166133224214114415314116546155162142351413352653624443445561415132245
        61134644513464136312624512512646433156245243323135316662611541511645524455344443
        32465121226561635253366236551242321432633512513126411311356145225421645145353411
        61242653446135335642654326136521133331146233621345452533215454345532544144162225
        64612245663461634153624544252545665313325243445366532466114341166245111352626635

    Excerpt only. The complete copy is held offline and backs quotations on this site. The original publication remains the canonical public source.

  8. source content difference between and source content +79 -0

    The Reddit thread gained several new participant comments about sample size, the Ian Coleman tool, /dev/random, dice-rolling technique and multisig as mitigation.

    seen · Captured here 28,396 chars
    What changed from the previous capture 79 lines
     edited: false
     body:
     situate pattern peasant bomb cannon unknown coral glare woman effort someone mobile wife mass tent toy mind tunnel improve charge blood weekend style differ
    +
    +comment: p2dz04r
    +parent: t3_1vi20y9
    +author: planetpluto3
    +created_utc: 1786155857
    +edited: false
    +body:
    + Bro never studied stats.   Sample size is too small to detect true differences.
    +
    +comment: p2e01z9
    +parent: t1_p29sonv
    +author: Vandaine
    +created_utc: 1786156231
    +edited: false
    +body:
    +Yahtzee!
    +
    +comment: p2e1duv
    +parent: t1_p29sonv
    +author: LNCrizzo
    +created_utc: 1786156710
    +edited: false
    +body:
    +I put your rolls into the Ian Coleman tool and got a 186 word seed phrase.
    +
    +    head lawsuit state vicious tent drop please mandate soda glue tank pet sell turn admit taxi chunk sort fence humble menu erase echo delay battle rare leader myth kid movie enable try toe major beach split icon thought curtain coin acid gospel laundry wheel cannon crush toilet business fluid bachelor usage coast slide rib sustain gaze stuff follow cargo welcome cram sea weasel found smile young mesh exchange sand pupil peasant clever artwork around critic enact extend learn grow job film lucky gallery loop hair broken use erase erode shift behind tide scale jar wheat pigeon kitten connect kangaroo limb use similar behave ghost drastic liar betray lab impose burger duck robust pride wire resist invite bar change modify aerobic tiger derive volcano hole foot spring cloud shiver seminar daughter art key swallow few gadget inherit foster earth dream congress idea glow bottom pledge open card poem lion giant talent flower grant piece educate joy skate century local gift letter choose vintage vault husband chimney stick basket cattle intact crane clip present patrol sadness describe gift anxiety drum ask emotion transfer kick rely promote split vessel
    +
    +comment: p2e9rda
    +parent: t3_1vi20y9
    +author: Be_Me_Anon_irl
    +created_utc: 1786159862
    +edited: false
    +body:
    +Did you check the cup for bias?
    +
    +comment: p2ednmo
    +parent: t3_1vi20y9
    +author: HoldenVJ
    +created_utc: 1786161392
    +edited: false
    +body:
    +Kudos!  
    +Good job destroying the FUD
    +
    +comment: p2eii5w
    +parent: t1_p2anufc
    +author: pizzapizza333
    +created_utc: 1786163339
    +edited: false
    +body:
    +I used 3 different color and always counted in same order. Not sure if thats best but it was way faster then rolling 1 by 1
    +
    +comment: p2ejdfy
    +parent: t1_p2d7s9c
    +author: Strong_Judge_3730
    +created_utc: 1786163700
    +edited: false
    +body:
    +Whether you use software or calculate things by hand the principal of the rule still applies.
    +
    +Don't implement you own crypto is a rule because software devs generally don't have the maths and statistics background to implement things correctly. It's not just about bugs in the implementation although it's a part of it. 
    +
    +When a bunch of r/bitcoin cultfluencers recommended avoid trusting reputable hardware wallet vendors because of one shit company and instead shill completely trusting some manual process given by some random non-technical Redditor, you are violating the principal of that rule.
    +
    +It had everything do to with the rolling the dice method, since that method requires you to follow a complex process to translate dice rolls to a cryptographic key, determining a checksum, avoiding bias and ensuring you have enough enthropy and avoiding op-sec mistakes.
    +
    +We are not asking you to completely trust a hardware wallet for all sources of enthropy. The best recommendation is to use a strong passphrase, you can roll dice to create this. 
    +
    +This adds your own enthropy source and combines with the secret generated in a secure environment.
    +
    +comment: p2etc3m
    +parent: t1_p2c1yma
    +author: TheMermanly
    +created_utc: 1786168146
    +edited: false
    +body:
    +Even if a hacker knew the exact bias with billions of roles of data with the exact bias we see on this post ( which is a very small sample this post so the bias will even be much smaller)
    +
    +It would still be impossible to get to the key if you generated the key with the standard entropy.  
    
    Extracted text as captured
    post: 1vi20y9
    author: 10kpizza
    created_utc: 1786112563
    title: I did 1200 dice rolls to check for bias in ordinary board game dice
    body:
    Result: there is no detected bias, and regular dice can easily and quickly be used to generate good randomness
    
    I saw some FUD that you need special casino dice, and you have to roll them in some special way, and it's easy to get it wrong, and the surface needs to be completely flat, float the dice in water to check they're balanced, etc etc loads of FUD reasons why dice rolling won't work. So I checked myself in the spirit of don't trust verify.
    
    I found three dice lying around my house in some old board games. I rolled them inside a plastic cup that I'd shake for a second or two, then put the cup down bottom-up. The dice bounce off the walls of the cup and each other many times, which creates huge unpredictability.
    
    I originally was only meaning to do this for 200 rolls, but then became hyperfocused and just kept going. This data is brought to you by weaponized autism.
    
    Rolling 50 dice this way only took me 2-3 minutes, and it would be even faster if I had more dice.
    
    Now in any sample there will be some variation just by chance. We can understand that boundary with math. The binomial distribution describes these dice rolls. The standard deviation of the binomial distribution is sqrt(N p (1-p)) where p is probability (1/6 in this case) and N is number of trials (1200 in this case). Put the numbers in the formula, work out the percentage and you get a standard deviation of 1.08%, which means there's a 63% chance that those percentages in my graph will deviate by that much (and therefore 37% that the deviation will be outside that range just by chance). **Since my graph values are within that range there was no bias detected**. I worked out that to detect bias down to 0.1% I would need to roll 138888 time and I'm not going to roll that much. The percentage standard deviation goes as 1/sqrtN so it only improves slowly as you do more rolls.
    
    I was not affected by the recent coldcard hack and I've never owned that wallet, but it's interesting and important to check and improve.
    
    **I think the biggest thing people can do is multi-software multisig.** This is easy to do as many bitcoin wallets have multisig like electrum and sparrow. You just click buttons in the UI and don't need to do any math. Multisig security is additive. It removes a single point of failure. If coldcard users had made a 2-of-2 multisig with the most malware-ridden online desktop computer you've ever seen, then it will still be better security than coldcard alone, and they would still have their bitcoins today because the online desktop would have to be hacked separately which is unlikely.
    
    I've seen a big misunderstanding that most important thing is good randomness for seed generation, so people are thinking of using radioactive decay or something. It's not, **the most important thing for seed generation is having a secret number that nobody else knows**. Dice are perfect for this because they can be understood by anyone, and they can be used offline and behind closed doors.
    
    comment: p29sonv
    parent: t3_1vi20y9
    author: 10kpizza
    created_utc: 1786112730
    edited: false
    body:
    This is the raw data of my dice rolls if anyone wants to reanalyze.
    
    .
    
        32216412646314564633364534221253213652553224566313163632643544124326236135325523
        12544123366551535422366613131321211611363555611425665545313262362212631611321363
        36141542252166133224214114415314116546155162142351413352653624443445561415132245
        61134644513464136312624512512646433156245243323135316662611541511645524455344443
        32465121226561635253366236551242321432633512513126411311356145225421645145353411
        61242653446135335642654326136521133331146233621345452533215454345532544144162225
        64612245663461634153624544252545665313325243445366532466114341166245111352626635

    Excerpt only. The complete copy is held offline and backs quotations on this site. The original publication remains the canonical public source.

  9. source content difference between and source content +137 -2

    The thread gained a substantial run of new comments on how to turn dice into entropy, including maidalit proposing that discarding rolls of 1 and 6 yields two binary digits per roll, with a self-edit correcting an earlier claim of four and noting the third of rolls discarded, and stanley_fatmax offering thrown toothpicks as an alternative source. The arithmetic is the posters' own and is not checked here.

    seen · Captured here 24,616 chars
    What changed from the previous capture 139 lines
     
     Or, you can also create a seed using 256 coinflips, and then enter the 23 words into a seedsigner to create the checksum word
     
    -comment: p2bqot9
    +comment: p2bv298
    +parent: t1_p2apmzj
    +author: maidalit
    +created_utc: 1786132018
    +edited: 1786132334
    +body:
    +That’s actually a really great idea. Discard rolls of 6 and 1. The remaining numbers translate ~~4~~ 2 binary digits for each dice roll.
    +
    +This makes it much faster to generate the full key than the usually suggested procedure of translating 1-3 to 0 and  
    +4-6 to 1.
    +
    +Edit: 2 digits per roll, not 4. Rolling two dices would give you 4 digits. There would also be 33% discarded rolls of ones and sixes, so it’s not actually twice as fast, but it should still be faster than generating one digit per roll.
    +
    +comment: p2bvbyx
    +parent: t3_1vi20y9
    +author: stanley_fatmax
    +created_utc: 1786132090
    +edited: false
    +body:
    +If you weren't confident in dice, throw 100 toothpicks in the air and record their orientation to the nearest 10° upon landing. That'll be plenty of entropy.
    +
    +comment: p2by0ks
    +parent: t1_p2ahxhk
    +author: maidalit
    +created_utc: 1786132807
    +edited: false
    +body:
    +Completely agree! People will not stop making mistakes. Hardware wallets were supposed to be the safe and easy to use security device for common folks and boost acceptance. 
    +
    +The damage this hack creates goes way beyond the stolen coins. 
    +
    +comment: p2c1yma
    +parent: t1_p2bdgth
    +author: vortexcortex21
    +created_utc: 1786133881
    +edited: false
    +body:
    +Nah, there are not that many ways a die can be biased.
    +
    +Also, it's easy (unless you are coldcard) to replicate a bias programmatically.
    +
    +comment: p2c4h7k
    +parent: t1_p2c1yma
    +author: coinminer2049er
    +created_utc: 1786134564
    +edited: false
    +body:
    +I think you sort of missed the point.
    +
    +comment: p2c53se
    +parent: t1_p2b282x
    +author: Str8CashHomiee
    +created_utc: 1786134735
    +edited: false
    +body:
    +Exactly which is the exact purpose of this post showing that 
    +
    +comment: p2cnm4w
    +parent: t1_p2a6jba
    +author: SoHigh420IShit360
    +created_utc: 1786140033
    +edited: false
    +body:
    +By saying this, I now only need to check 1296 combinations rather than 10000 to find your PIN number 
    +
    +comment: p2cny9e
    +parent: t1_p29vn9f
    +author: TheSkunksMisery
    +created_utc: 1786140136
    +edited: false
    +body:
    +Funny, I had to check. I'm safe here.
    +
    +comment: p2d2j6i
     parent: t3_1vi20y9
     author: rocket_beer
    -created_utc: 1786130849
    +created_utc: 1786144752
     edited: false
     body:
     1200?
     
     Invalid unless you do it 10,000 times
    +
    +comment: p2d703l
    +parent: t3_1vi20y9
    +author: OldWolf3
    +created_utc: 1786146218
    +edited: false
    +body:
    +Your math isn't good. It's not correct to just say the data is in range for variance therefore the dice are unbiased; because the data is also in range for bias.
    +
    +For example if there is a loaded coin designed for 55% heads, and you flip it 100 times and get 55 heads, your method would conclude the coin is unbiased .
    +
    +The proper way involves comparing the null hypothesis with a bias hypothesis and seeing which one the data favours. (It's more complex than this, I am just giving a one line summary for reddit post).
    +
    +Your data also matches the hypothesis that 6 is more likely on cheap dice, (because that face is lightest and 1 is heaviest) and without actually running the numbers the fact that 6 came up the most suggests the data favours this hypothesis over the null .
    +
    +comment: p2d7lli
    +parent: t1_p2cnm4w
    +author: Baiyko
    +created_utc: 1786146418
    +edited: false
    +body:
    +And?
    +
    +comment: p2d7s9c
    +parent: t1_p2am8zw
    +author: Past_Permission_6123
    +created_utc: 1786146479
    +edited: false
    +body:
    +"don't implement you own crypto" applies in software development, it has nothing to do with the entropy of dice rolls.
    +
    +If you're worried about a small bias, just do some more dice rolls.
    +
    +comment: p2d9ifg
    +parent: t1_p2avacj
    +author: Past_Permission_6123
    +created_utc: 1786147053
    +edited: false
    +body:
    +The bias of the dice would have to be extreme, to the point you'd easily notice it if you played a game with it. Some people are just bad at estimating probability with their intuition. No-one can guess from the distribution with dice like OP used with 256 dice rolls.
    +
    +comment: p2dfg4c
    +parent: t1_p2d703l
    +author: 10kpizza
    +created_utc: 1786149067
    +edited: 1786150153
    +body:
    +Yes I'm sure there are other ways of doing it. You could find a way to calculate the observed bias on the dice (and then bias = 0 to within error means unbiased)
    +
    +For your example N=100 and p=0.5 would result in a standard deviation of 5%, so getting 55/100 heads would not rule out a bias of 5% as you said. Thats because N=100 is too low. If you instead you did N=10000 now the standard deviation is 0.5% so a 5% bias would be very visible, it would be 10 standard deviations away, vanishingly unlikely to happen by chance.
    +
    +The 6 being slightly more likely as in my data is within one standard deviation. Meaning if there is a bias towards 6 then its very small, it cant be bigger than about 1%. And thats the key point that the dice are good enough to use for seed generation.
    +
    +EDIT: yeah i guess I shouldnt have said "no detected bias". But the keyword is "detected". If I had a higher N maybe a very small bias could be detected.
    +
    +comment: p2dr6fj
    +parent: t1_p29sonv
    +author: randousername888
    +created_utc: 1786153129
    +edited: false
    +body:
    +situate pattern peasant bomb cannon unknown coral glare woman effort someone mobile wife mass tent toy mind tunnel improve charge blood weekend style differ
    
    Extracted text as captured
    post: 1vi20y9
    author: 10kpizza
    created_utc: 1786112563
    title: I did 1200 dice rolls to check for bias in ordinary board game dice
    body:
    Result: there is no detected bias, and regular dice can easily and quickly be used to generate good randomness
    
    I saw some FUD that you need special casino dice, and you have to roll them in some special way, and it's easy to get it wrong, and the surface needs to be completely flat, float the dice in water to check they're balanced, etc etc loads of FUD reasons why dice rolling won't work. So I checked myself in the spirit of don't trust verify.
    
    I found three dice lying around my house in some old board games. I rolled them inside a plastic cup that I'd shake for a second or two, then put the cup down bottom-up. The dice bounce off the walls of the cup and each other many times, which creates huge unpredictability.
    
    I originally was only meaning to do this for 200 rolls, but then became hyperfocused and just kept going. This data is brought to you by weaponized autism.
    
    Rolling 50 dice this way only took me 2-3 minutes, and it would be even faster if I had more dice.
    
    Now in any sample there will be some variation just by chance. We can understand that boundary with math. The binomial distribution describes these dice rolls. The standard deviation of the binomial distribution is sqrt(N p (1-p)) where p is probability (1/6 in this case) and N is number of trials (1200 in this case). Put the numbers in the formula, work out the percentage and you get a standard deviation of 1.08%, which means there's a 63% chance that those percentages in my graph will deviate by that much (and therefore 37% that the deviation will be outside that range just by chance). **Since my graph values are within that range there was no bias detected**. I worked out that to detect bias down to 0.1% I would need to roll 138888 time and I'm not going to roll that much. The percentage standard deviation goes as 1/sqrtN so it only improves slowly as you do more rolls.
    
    I was not affected by the recent coldcard hack and I've never owned that wallet, but it's interesting and important to check and improve.
    
    **I think the biggest thing people can do is multi-software multisig.** This is easy to do as many bitcoin wallets have multisig like electrum and sparrow. You just click buttons in the UI and don't need to do any math. Multisig security is additive. It removes a single point of failure. If coldcard users had made a 2-of-2 multisig with the most malware-ridden online desktop computer you've ever seen, then it will still be better security than coldcard alone, and they would still have their bitcoins today because the online desktop would have to be hacked separately which is unlikely.
    
    I've seen a big misunderstanding that most important thing is good randomness for seed generation, so people are thinking of using radioactive decay or something. It's not, **the most important thing for seed generation is having a secret number that nobody else knows**. Dice are perfect for this because they can be understood by anyone, and they can be used offline and behind closed doors.
    
    comment: p29sonv
    parent: t3_1vi20y9
    author: 10kpizza
    created_utc: 1786112730
    edited: false
    body:
    This is the raw data of my dice rolls if anyone wants to reanalyze.
    
    .
    
        32216412646314564633364534221253213652553224566313163632643544124326236135325523
        12544123366551535422366613131321211611363555611425665545313262362212631611321363
        36141542252166133224214114415314116546155162142351413352653624443445561415132245
        61134644513464136312624512512646433156245243323135316662611541511645524455344443
        32465121226561635253366236551242321432633512513126411311356145225421645145353411
        61242653446135335642654326136521133331146233621345452533215454345532544144162225
        64612245663461634153624544252545665313325243445366532466114341166245111352626635

    Excerpt only. The complete copy is held offline and backs quotations on this site. The original publication remains the canonical public source.

  10. source content difference between and source content +186 -3

    The original poster edited their method note and the thread gained new comments about dice bias, entropy requirements, and whether bias is exploitable without knowing the dice used.

    seen · Captured here 19,554 chars
    What changed from the previous capture 189 lines
     parent: t1_p2a1cpx
     author: 10kpizza
     created_utc: 1786117309
    -edited: false
    -body:
    -It took surprisingly little time. The method with the plastic cup is pretty fast. Plus I had three dice not one. It took me slightly over an hour but I didnt do it all in one go, more like 10 minutes at a time with breaks doing other things.
    +edited: 1786122113
    +body:
    +It took surprisingly little time. The method with the plastic cup is pretty fast. Plus I had three dice not one. It took me slightly over an hour but I didnt do it all in one go, more like 10 minutes at a time with breaks doing other things. People could probably use a regular cup from the kitchen.
     
     And as you say a small bias wouldnt even matter.
     
     edited: false
     body:
     As a former nerd, I just want to say 'thank you' for taking the time to document and experiment. I'm too old and tired and I know that I don't have the smarts that I once did. So I appreciate you!
    +
    +comment: p2at5ir
    +parent: t1_p2am8zw
    +author: 10kpizza
    +created_utc: 1786122189
    +edited: false
    +body:
    +Wait so reading the wikipedia page on binomial distributions isnt enough??
    +
    +comment: p2aux9j
    +parent: t3_1vi20y9
    +author: Aidsfordayz
    +created_utc: 1786122646
    +edited: false
    +body:
    +this really screams mass adoption
    +
    +comment: p2avacj
    +parent: t1_p2am8zw
    +author: stoicparallax
    +created_utc: 1786122738
    +edited: false
    +body:
    +Let’s say OP states they’ve since used these same dice to generate a private key. If a someone comes along and has the distribution chart, would that advantage them in guessing OPs key in any meaningful way (assuming OP has done 256 rolls)?
    +
    +*To your point about maths qualifications, I have none. This is a genuine question.*
    +
    +comment: p2avhcv
    +parent: t1_p2at5ir
    +author: Strong_Judge_3730
    +created_utc: 1786122787
    +edited: false
    +body:
    +Holy shit didn't realize you can become an expert from reading a wiki page
    +
    +comment: p2avi14
    +parent: t3_1vi20y9
    +author: FreezedPeachNow
    +created_utc: 1786122792
    +edited: false
    +body:
    +can someone explain the dice roll like I am 5 in order to generate entropy.  because rolling a 6 sided dice 100 times willl just yiel a number between 100 and 600.  Or is it each dice roll is used in conjuction with something else to generate a new word or number?  So now you have 1X6 \^100 possible combinations?  Also there are 24 seed words, but 100 dice rolls.  So I am not sure how those 2 numbers reconcile each other.
    +
    +comment: p2awteb
    +parent: t3_1vi20y9
    +author: satoshisfeverdream
    +created_utc: 1786123127
    +edited: false
    +body:
    +It’s nice to see this place take a break from the usual mind numbing posts here.   
    +
    +comment: p2b282x
    +parent: t1_p2a2etx
    +author: Deto
    +created_utc: 1786124508
    +edited: false
    +body:
    +Even if that was very slightly true, it would only very slightly degrade the entropy so it wouldn't be a big deal
    +
    +comment: p2b78kb
    +parent: t3_1vi20y9
    +author: Flowa-Powa
    +created_utc: 1786125787
    +edited: false
    +body:
    +I used 10 dice, I didn't really care if they had small amounts of bias
    +
    +comment: p2bc7rc
    +parent: t3_1vi20y9
    +author: Setting-Conscious
    +created_utc: 1786127070
    +edited: false
    +body:
    +What a waste of time
    +
    +comment: p2bd0vz
    +parent: t1_p29vn9f
    +author: AlternativeCapybara9
    +created_utc: 1786127276
    +edited: false
    +body:
    +Yes, 1111 is in there.
    +
    +comment: p2bd7a3
    +parent: t3_1vi20y9
    +author: zooms
    +created_utc: 1786127322
    +edited: false
    +body:
    +This seems like a good place to ask. The basic advice is to do 100 rolls for maximum? entropy.. 
    +
    +What happens if I do 200 or 300 or 1200? Does it reduce the effectiveness of entropy somehow?
    +
    +comment: p2bdgth
    +parent: t3_1vi20y9
    +author: coinminer2049er
    +created_utc: 1786127390
    +edited: false
    +body:
    +I think the point most people are missing in this whole debacle, is that bias only matters if
    +
    +1. Someone knows how the item you used to generate them were biased
    +2. That person then has the ability to recreate that bias to generate your keys.
    +
    +Like, say you had a dice that had a +5% bias towards landing on 6. First, someone would need to know that was your bias, and then they'd have to find a way to replicate that bias. Anyone trying to replicate your keys with a standard set of fair dice is going to have a REALLY tough time. In a weird way, it's almost safer to have an uncommon bias.
    +
    +TL;DR - biases are fine if they're unknowable (i.e. not shared or visible in the source).
    +
    +comment: p2bdtuk
    +parent: t1_p29vn9f
    +author: coinminer2049er
    +created_utc: 1786127483
    +edited: false
    +body:
    +wait until this guy hears about De Bruijn sequences
    +
    +comment: p2bkodi
    +parent: t1_p2bd7a3
    +author: 10kpizza
    +created_utc: 1786129261
    +edited: false
    +body:
    +Entropy is additive so doing more rolls wont harm.
    +
    +comment: p2blj5v
    +parent: t1_p2b282x
    +author: GoldmezAddams
    +created_utc: 1786129487
    +edited: false
    +body:
    +And you could just offset it with a few extra rolls.
    +
    +comment: p2bmlky
    +parent: t3_1vi20y9
    +author: OddBritishMan
    +created_utc: 1786129768
    +edited: false
    +body:
    +I read that the dice have to be rolled using the same technique everytime... But surely it's better to roll the dice differently everytime to add unpredictability. I  might order some casino dice, and try. Also coin flips might be better, but take longer to generate a seed. 
    +
    +comment: p2bn085
    +parent: t3_1vi20y9
    +author: stargate425
    +created_utc: 1786129876
    +edited: false
    +body:
    +I rolled 240 times with 12 dices bought from a board game cafe (20 times), then I mentally rolled 16 times. With a passphrase, I'm satisfied with its entropy.
    +
    +comment: p2boymp
    +parent: t1_p2avi14
    +author: haltncatchfries
    +created_utc: 1786130391
    +edited: false
    +body:
    +If you simply add the dice values, i.e. 5 + 6 + 4 + 3 + 1 + 6 ... , it removes tremendous amounts of entropy because the order of the dice rolls no longer matters and the final values (as you pointed out) will be within a group of 500 unique values, and 500 = \~2\^8.9 (not quite 9 bits of entropy) in base-2, which is bad.
    +
    +However, if each dice roll becomes a digit in a base-6 integer, which can later be converted into a base-2 integer, then no entropy is lost and the final value becomes the binary data for creating/mixing entropy.
    +
    +The math for this is that d6 dice create (6)\^(rolls) unique values, i.e. 100 rolls is about 10\^77 (a 77-digit integer, base 10) or about 2\^258. So, effectively, 100 d6 rolls is about 258 bits of entropy, which is quite good.
    +
    +The seed words are in a list of 2048 (2\^11) or exactly 11 bits of entropy per word. 24 words x 11 bits of entropy is 264 bits of total entropy. We can use dice rolls or words from a bag because in the end the order of them creates a very large integer that comfortably contains at least 256 bits of entropy.
    +
    +comment: p2bp0pi
    +parent: t1_p2avi14
    +author: OddBritishMan
    +created_utc: 1786130407
    +edited: false
    +body:
    +You don't total the dice results. 
    +
    +You have to roll a dice 99 times and enter the 99 character result into a seedsigner or coldcard to create the seed.
    +
    +Or, you can also create a seed using 256 coinflips, and then enter the 23 words into a seedsigner to create the checksum word
    +
    +comment: p2bqot9
    +parent: t3_1vi20y9
    +author: rocket_beer
    +created_utc: 1786130849
    +edited: false
    +body:
    +1200?
    +
    +Invalid unless you do it 10,000 times
    
    Extracted text as captured
    post: 1vi20y9
    author: 10kpizza
    created_utc: 1786112563
    title: I did 1200 dice rolls to check for bias in ordinary board game dice
    body:
    Result: there is no detected bias, and regular dice can easily and quickly be used to generate good randomness
    
    I saw some FUD that you need special casino dice, and you have to roll them in some special way, and it's easy to get it wrong, and the surface needs to be completely flat, float the dice in water to check they're balanced, etc etc loads of FUD reasons why dice rolling won't work. So I checked myself in the spirit of don't trust verify.
    
    I found three dice lying around my house in some old board games. I rolled them inside a plastic cup that I'd shake for a second or two, then put the cup down bottom-up. The dice bounce off the walls of the cup and each other many times, which creates huge unpredictability.
    
    I originally was only meaning to do this for 200 rolls, but then became hyperfocused and just kept going. This data is brought to you by weaponized autism.
    
    Rolling 50 dice this way only took me 2-3 minutes, and it would be even faster if I had more dice.
    
    Now in any sample there will be some variation just by chance. We can understand that boundary with math. The binomial distribution describes these dice rolls. The standard deviation of the binomial distribution is sqrt(N p (1-p)) where p is probability (1/6 in this case) and N is number of trials (1200 in this case). Put the numbers in the formula, work out the percentage and you get a standard deviation of 1.08%, which means there's a 63% chance that those percentages in my graph will deviate by that much (and therefore 37% that the deviation will be outside that range just by chance). **Since my graph values are within that range there was no bias detected**. I worked out that to detect bias down to 0.1% I would need to roll 138888 time and I'm not going to roll that much. The percentage standard deviation goes as 1/sqrtN so it only improves slowly as you do more rolls.
    
    I was not affected by the recent coldcard hack and I've never owned that wallet, but it's interesting and important to check and improve.
    
    **I think the biggest thing people can do is multi-software multisig.** This is easy to do as many bitcoin wallets have multisig like electrum and sparrow. You just click buttons in the UI and don't need to do any math. Multisig security is additive. It removes a single point of failure. If coldcard users had made a 2-of-2 multisig with the most malware-ridden online desktop computer you've ever seen, then it will still be better security than coldcard alone, and they would still have their bitcoins today because the online desktop would have to be hacked separately which is unlikely.
    
    I've seen a big misunderstanding that most important thing is good randomness for seed generation, so people are thinking of using radioactive decay or something. It's not, **the most important thing for seed generation is having a secret number that nobody else knows**. Dice are perfect for this because they can be understood by anyone, and they can be used offline and behind closed doors.
    
    comment: p29sonv
    parent: t3_1vi20y9
    author: 10kpizza
    created_utc: 1786112730
    edited: false
    body:
    This is the raw data of my dice rolls if anyone wants to reanalyze.
    
    .
    
        32216412646314564633364534221253213652553224566313163632643544124326236135325523
        12544123366551535422366613131321211611363555611425665545313262362212631611321363
        36141542252166133224214114415314116546155162142351413352653624443445561415132245
        61134644513464136312624512512646433156245243323135316662611541511645524455344443
        32465121226561635253366236551242321432633512513126411311356145225421645145353411
        61242653446135335642654326136521133331146233621345452533215454345532544144162225
        64612245663461634153624544252545665313325243445366532466114341166245111352626635

    Excerpt only. The complete copy is held offline and backs quotations on this site. The original publication remains the canonical public source.

  11. Earliest copy held
    seen · Captured here 13,320 chars
    Extracted text as captured
    post: 1vi20y9
    author: 10kpizza
    created_utc: 1786112563
    title: I did 1200 dice rolls to check for bias in ordinary board game dice
    body:
    Result: there is no detected bias, and regular dice can easily and quickly be used to generate good randomness
    
    I saw some FUD that you need special casino dice, and you have to roll them in some special way, and it's easy to get it wrong, and the surface needs to be completely flat, float the dice in water to check they're balanced, etc etc loads of FUD reasons why dice rolling won't work. So I checked myself in the spirit of don't trust verify.
    
    I found three dice lying around my house in some old board games. I rolled them inside a plastic cup that I'd shake for a second or two, then put the cup down bottom-up. The dice bounce off the walls of the cup and each other many times, which creates huge unpredictability.
    
    I originally was only meaning to do this for 200 rolls, but then became hyperfocused and just kept going. This data is brought to you by weaponized autism.
    
    Rolling 50 dice this way only took me 2-3 minutes, and it would be even faster if I had more dice.
    
    Now in any sample there will be some variation just by chance. We can understand that boundary with math. The binomial distribution describes these dice rolls. The standard deviation of the binomial distribution is sqrt(N p (1-p)) where p is probability (1/6 in this case) and N is number of trials (1200 in this case). Put the numbers in the formula, work out the percentage and you get a standard deviation of 1.08%, which means there's a 63% chance that those percentages in my graph will deviate by that much (and therefore 37% that the deviation will be outside that range just by chance). **Since my graph values are within that range there was no bias detected**. I worked out that to detect bias down to 0.1% I would need to roll 138888 time and I'm not going to roll that much. The percentage standard deviation goes as 1/sqrtN so it only improves slowly as you do more rolls.
    
    I was not affected by the recent coldcard hack and I've never owned that wallet, but it's interesting and important to check and improve.
    
    **I think the biggest thing people can do is multi-software multisig.** This is easy to do as many bitcoin wallets have multisig like electrum and sparrow. You just click buttons in the UI and don't need to do any math. Multisig security is additive. It removes a single point of failure. If coldcard users had made a 2-of-2 multisig with the most malware-ridden online desktop computer you've ever seen, then it will still be better security than coldcard alone, and they would still have their bitcoins today because the online desktop would have to be hacked separately which is unlikely.
    
    I've seen a big misunderstanding that most important thing is good randomness for seed generation, so people are thinking of using radioactive decay or something. It's not, **the most important thing for seed generation is having a secret number that nobody else knows**. Dice are perfect for this because they can be understood by anyone, and they can be used offline and behind closed doors.
    
    comment: p29sonv
    parent: t3_1vi20y9
    author: 10kpizza
    created_utc: 1786112730
    edited: false
    body:
    This is the raw data of my dice rolls if anyone wants to reanalyze.
    
    .
    
        32216412646314564633364534221253213652553224566313163632643544124326236135325523
        12544123366551535422366613131321211611363555611425665545313262362212631611321363
        36141542252166133224214114415314116546155162142351413352653624443445561415132245
        61134644513464136312624512512646433156245243323135316662611541511645524455344443
        32465121226561635253366236551242321432633512513126411311356145225421645145353411
        61242653446135335642654326136521133331146233621345452533215454345532544144162225
        64612245663461634153624544252545665313325243445366532466114341166245111352626635

    Excerpt only. The complete copy is held offline and backs quotations on this site. The original publication remains the canonical public source.

How to check this yourself

The excerpts and plain unified diffs above show the text this project held and how it changed. To verify a quotation, compare it against the page itself or against the Internet Archive's copies, which are independent of this project.

Complete captures are held offline rather than mirrored here, so this page shows diffs and excerpts. If a quotation is ever disputed, the full copy can be produced. Ask.