COLDCARD RNG incident the public record, collected and explained
Informational only, and this site never asks for your seed words. details

Informational only. This is an open source collection of what others have published about the incident, together with an explanation of it. It is not financial, security or legal advice, and not a substitute for professional advice about your own situation. It is not affiliated with, endorsed by, or speaking for Coinkite. Material is attributed and quoted as published; where sources disagree their scenarios are kept separate with their assumptions rather than reconciled into one answer. Everything is meant to be checked against the linked evidence rather than taken on trust. Act on your own judgement about a particular situation. Editorial standards and corrections.

Do not disclose recovery material to a website, form, message or support account. This site never asks for it, and contributions containing recovery words or private keys are not accepted.

r/Bitcoin: dice rolls saved a stack, now moving to SeedSigner

reddit-dice-rolls-saved-seedsigner

https://www.reddit.com/r/Bitcoin/comments/1vie1vy/dice_rolls_saved_me_but/

Latest reviewed change

source content difference between and

The thread gained a reply advising against reusing part of the old seed as a new passphrase, recommending an independently generated strong passphrase, SeedQR handling, and recovery verification before funding.

seen +11 -0 full history below
 body:
 Cuz you’re spending money on something unnecessary? Nm, that is what bitcoin is.
 
+comment: p3qalhr
+parent: t1_p2cqynd
+author: Skinny_Human
+created_utc: 1786743794
+edited: false

First lines only. The complete diff is in the timeline below.

Organisation
reddit
Evidence role
Community discussion
Published
not established
Source changes
6
Detected differences
6
Unreviewed
0
Copies held
7

Every check is recorded, including checks that found no text change. A detected edit is therefore bounded between two checks. The publisher's exact save time is not observable from this record. Last checked .

  1. source content difference between and Current source content +11 -0

    The thread gained a reply advising against reusing part of the old seed as a new passphrase, recommending an independently generated strong passphrase, SeedQR handling, and recovery verification before funding.

    seen · Captured here 27,512 chars
    What changed from the previous capture 11 lines
     body:
     Cuz you’re spending money on something unnecessary? Nm, that is what bitcoin is.
     
    +comment: p3qalhr
    +parent: t1_p2cqynd
    +author: Skinny_Human
    +created_utc: 1786743794
    +edited: false
    +body:
    +Hi OP. Your basic plan is sound, but I would change one thing. Do not reuse part of the old seed as your new passphrase. A BIP39 passphrase can technically be any string, and 6 to 10 genuinely random BIP39 words would contain substantial entropy, but taking them from a seed that has already existed on another signing device unnecessarily links two secrets. If that old seed is ever recovered, photographed, backed up badly or otherwise exposed, you have potentially handed the attacker the entire passphrase. Generate the new passphrase independently.  
    +For SeedSigner, having to reload the seed is not really a weakness. Statelessness is one of its design goals. You can enter the words manually each time, but that gets tedious. SeedQR exists specifically to make reloading practical. The QR itself is not inherently less secure than 24 words written on paper because both represent the same secret. The important question is where and how you store it. If somebody obtains your SeedQR, treat that exactly as if they obtained your seed words. For a 24 word seed, 100 fair six sided dice rolls is plenty. SeedSigner itself uses 99 rolls for generating a 24 word mnemonic. Ideally verify the resulting mnemonic independently before putting meaningful funds behind it.  
    +If it were mine, I would use a fresh seed generated from 99 or 100 dice rolls, an independently generated strong passphrase, a physical seed backup, a separate passphrase backup, and I would verify recovery before funding the wallet. Then wipe the signing device and keep the watch only wallet on the online machine. Multisig is not automatically more secure for an individual. It reduces some risks but introduces considerably more backup and operational complexity, so avoiding it when your threat model does not require it is perfectly reasonable.  
    +The one thing I definitely would not do after an incident that has already made you question one secret is deliberately recycle part of that secret into the next wallet!!
    +
     more-stub: parent t1_p2x7o9i count <live-count>
    
    Extracted text as captured
    post: 1vie1vy
    author: Large_Still_1224
    created_utc: 1786139812
    title: Dice Rolls Saved Me, But…
    body:
    I am super fortunate that I wasn't a victim of the cold card hack (my heart goes out to everyone who was). I attribute me still having my BTC to the fact that I generated my seed from dice.
    
    Right when I heard about the news, I moved my coins, and right now I'm still sketched out by the cold card and my seed (even though I used 100 dice rolls to generate it)
    
    I'm looking for the best long term alternative for me now, which from my research seems to be:
    
    1. Seedsigner with a new seed from 100 dice rolls  
    2. Passphase  
    (I feel like multisig might be overshooting it for me personally.)
    
    Here are my questions though.
    
    1. I understand that you have to load in the seed into Seedsigner each time you want to transact, so what's the most secure way of doing this (aside from having the QR code feature, which seems risky to me keeping that QR code card laying around.)
    
    2. with my previous dice rolled seed phrase, is there any risk with using the first 6-10 words of that as a new passphrase?
    
    3. anything else I'm missing for this
    
    Thanks!
    
    comment: p2cnvr0
    parent: t3_1vie1vy
    author: ryt3n
    created_utc: 1786140114
    edited: false
    body:
    I do not think multi sig is too much. I think it’s absolutely worth it - probably mandatory - for any self custody.
    
    comment: p2co5b7
    parent: t3_1vie1vy
    author: Cryptotiptoe21
    created_utc: 1786140196
    edited: false
    body:
    I recommend the Keystone pro 3. They have Bitcoin only firmware. It is air gapped. Open source. They have also made commitments that they will never do what ledger did and that being offer a "recovery feature"

    Excerpt only. The complete copy is held offline and backs quotations on this site. The original publication remains the canonical public source.

  2. source content difference between and source content +85 -3

    The original post was edited to correct 'seize' to 'cease', and the thread gained comments about multisig practice, testnet setup, and alternatives to casino dice for generating entropy.

    seen · Captured here 25,414 chars
    What changed from the previous capture 88 lines
     parent: t1_p2et0po
     author: quintavious_danilo
     created_utc: 1786175875
    -edited: false
    -body:
    -You would not create enough entropy. Unfortunately when you start choosing things actively, they seize to be truly random. A die roll is random. 
    +edited: 1786363713
    +body:
    +You would not create enough entropy. Unfortunately when you start choosing things actively, they ~~seize~~ cease to be truly random. A die roll is random.
     
     comment: p2fdu5w
     parent: t1_p2djjlt
     edited: false
     body:
     I’m aware of the sub I’m in but using a one network device is nonsensical. I want something battle tested on all possibilities. Even if I only use one or two. 
    +
    +comment: p2qphjp
    +parent: t3_1vie1vy
    +author: markphillips401
    +created_utc: 1786320060
    +edited: false
    +body:
    +Multisig is not overshooting it, sorry. 
    +
    +comment: p2qt4rd
    +parent: t1_p2qphjp
    +author: Large_Still_1224
    +created_utc: 1786321314
    +edited: false
    +body:
    +I agree…I’ve been doing a lot of research and built a software multisig wallet on Sparrow and realize it’s not as complicated as I thought. Any other tips for multisig?
    +
    +comment: p2tjcki
    +parent: t1_p2qt4rd
    +author: NeighborhoodOld163
    +created_utc: 1786363461
    +edited: false
    +body:
    +Build a practice multi-sig on Testnet to practice transactions and backup recoveries without fear of losing any coins.
    +
    +comment: p2tjpi9
    +parent: t1_p2f8ybw
    +author: BusyFunny7267
    +created_utc: 1786363589
    +edited: false
    +body:
    +I think the word is "cease".
    +
    +comment: p2tk0dy
    +parent: t1_p2tjpi9
    +author: quintavious_danilo
    +created_utc: 1786363697
    +edited: false
    +body:
    +True, thanks. 
    +
    +comment: p2u0dge
    +parent: t1_p2f8ybw
    +author: step11111
    +created_utc: 1786368916
    +edited: false
    +body:
    +I don’t get why everyone says get casino dice. There’s tons of ways to do it without dice. 2 packs of cards, weighing things, keyboard mash… pretty much guaranteed people have those items and also they wouldn’t have to roll 100x. 
    +
    +comment: p2uzz1s
    +parent: t1_p2u0dge
    +author: quintavious_danilo
    +created_utc: 1786378533
    +edited: false
    +body:
    +It doesn’t matter if it’s dice or whatever. The result needs to be truly random. Maybe let your dog pick the cards. I don’t know. 
    +
    +comment: p2wk92q
    +parent: t1_p2uzz1s
    +author: step11111
    +created_utc: 1786392852
    +edited: false
    +body:
    +What I’m saying is everyone says the standard is go and buy casino dice. Uhh no, that’s horrible advice and there’s plenty of shit in your right now that can the same thing. 
    +
    +comment: p2wu7vu
    +parent: t1_p2wk92q
    +author: quintavious_danilo
    +created_utc: 1786395474
    +edited: false
    +body:
    +Why horrible? The entropy works, keeping the funds safe. Horrible advice would be to pick the words yourself. 
    +
    +comment: p2x7o9i
    +parent: t1_p2wu7vu
    +author: step11111
    +created_utc: 1786399211
    +edited: false
    +body:
    +Cuz you’re spending money on something unnecessary? Nm, that is what bitcoin is.
    +
    +more-stub: parent t1_p2x7o9i count <live-count>
    
    Extracted text as captured
    post: 1vie1vy
    author: Large_Still_1224
    created_utc: 1786139812
    title: Dice Rolls Saved Me, But…
    body:
    I am super fortunate that I wasn't a victim of the cold card hack (my heart goes out to everyone who was). I attribute me still having my BTC to the fact that I generated my seed from dice.
    
    Right when I heard about the news, I moved my coins, and right now I'm still sketched out by the cold card and my seed (even though I used 100 dice rolls to generate it)
    
    I'm looking for the best long term alternative for me now, which from my research seems to be:
    
    1. Seedsigner with a new seed from 100 dice rolls  
    2. Passphase  
    (I feel like multisig might be overshooting it for me personally.)
    
    Here are my questions though.
    
    1. I understand that you have to load in the seed into Seedsigner each time you want to transact, so what's the most secure way of doing this (aside from having the QR code feature, which seems risky to me keeping that QR code card laying around.)
    
    2. with my previous dice rolled seed phrase, is there any risk with using the first 6-10 words of that as a new passphrase?
    
    3. anything else I'm missing for this
    
    Thanks!
    
    comment: p2cnvr0
    parent: t3_1vie1vy
    author: ryt3n
    created_utc: 1786140114
    edited: false
    body:
    I do not think multi sig is too much. I think it’s absolutely worth it - probably mandatory - for any self custody.
    
    comment: p2co5b7
    parent: t3_1vie1vy
    author: Cryptotiptoe21
    created_utc: 1786140196
    edited: false
    body:
    I recommend the Keystone pro 3. They have Bitcoin only firmware. It is air gapped. Open source. They have also made commitments that they will never do what ledger did and that being offer a "recovery feature"

    Excerpt only. The complete copy is held offline and backs quotations on this site. The original publication remains the canonical public source.

  3. source content difference between and source content +8 -0

    The thread gained a reply arguing that relying on a single network device is nonsensical and that the user wants something tested against all possibilities.

    seen · Captured here 23,217 chars
    What changed from the previous capture 8 lines
     edited: false
     body:
     That would have included Coldcard just over a week ago though 😬 
    +
    +comment: p2n81ir
    +parent: t1_p2m8rui
    +author: ftball21
    +created_utc: 1786282963
    +edited: false
    +body:
    +I’m aware of the sub I’m in but using a one network device is nonsensical. I want something battle tested on all possibilities. Even if I only use one or two. 
    
    Extracted text as captured
    post: 1vie1vy
    author: Large_Still_1224
    created_utc: 1786139812
    title: Dice Rolls Saved Me, But…
    body:
    I am super fortunate that I wasn't a victim of the cold card hack (my heart goes out to everyone who was). I attribute me still having my BTC to the fact that I generated my seed from dice.
    
    Right when I heard about the news, I moved my coins, and right now I'm still sketched out by the cold card and my seed (even though I used 100 dice rolls to generate it)
    
    I'm looking for the best long term alternative for me now, which from my research seems to be:
    
    1. Seedsigner with a new seed from 100 dice rolls  
    2. Passphase  
    (I feel like multisig might be overshooting it for me personally.)
    
    Here are my questions though.
    
    1. I understand that you have to load in the seed into Seedsigner each time you want to transact, so what's the most secure way of doing this (aside from having the QR code feature, which seems risky to me keeping that QR code card laying around.)
    
    2. with my previous dice rolled seed phrase, is there any risk with using the first 6-10 words of that as a new passphrase?
    
    3. anything else I'm missing for this
    
    Thanks!
    
    comment: p2cnvr0
    parent: t3_1vie1vy
    author: ryt3n
    created_utc: 1786140114
    edited: false
    body:
    I do not think multi sig is too much. I think it’s absolutely worth it - probably mandatory - for any self custody.
    
    comment: p2co5b7
    parent: t3_1vie1vy
    author: Cryptotiptoe21
    created_utc: 1786140196
    edited: false
    body:
    I recommend the Keystone pro 3. They have Bitcoin only firmware. It is air gapped. Open source. They have also made commitments that they will never do what ledger did and that being offer a "recovery feature"

    Excerpt only. The complete copy is held offline and backs quotations on this site. The original publication remains the canonical public source.

  4. source content difference between and source content +8 -0

    A new reply notes that Coldcard would have been trusted just over a week ago.

    seen · Captured here 22,959 chars
    What changed from the previous capture 8 lines
     Multisig makes it practical to leave one key in a secure location such as a bank safe-deposit box. This creates a clear, controllable path for heirs to recover the funds without relying solely on a single passphrase that could be forgotten, lost, or disputed.
     
     In short, multisig turns a single point of failure into a distributed system that improves recovery, security against physical threats, and estate planning—advantages a passphrase alone cannot match.
    +
    +comment: p2m8rui
    +parent: t1_p2dkfgk
    +author: Large_Still_1224
    +created_utc: 1786268539
    +edited: false
    +body:
    +That would have included Coldcard just over a week ago though 😬 
    
    Extracted text as captured
    post: 1vie1vy
    author: Large_Still_1224
    created_utc: 1786139812
    title: Dice Rolls Saved Me, But…
    body:
    I am super fortunate that I wasn't a victim of the cold card hack (my heart goes out to everyone who was). I attribute me still having my BTC to the fact that I generated my seed from dice.
    
    Right when I heard about the news, I moved my coins, and right now I'm still sketched out by the cold card and my seed (even though I used 100 dice rolls to generate it)
    
    I'm looking for the best long term alternative for me now, which from my research seems to be:
    
    1. Seedsigner with a new seed from 100 dice rolls  
    2. Passphase  
    (I feel like multisig might be overshooting it for me personally.)
    
    Here are my questions though.
    
    1. I understand that you have to load in the seed into Seedsigner each time you want to transact, so what's the most secure way of doing this (aside from having the QR code feature, which seems risky to me keeping that QR code card laying around.)
    
    2. with my previous dice rolled seed phrase, is there any risk with using the first 6-10 words of that as a new passphrase?
    
    3. anything else I'm missing for this
    
    Thanks!
    
    comment: p2cnvr0
    parent: t3_1vie1vy
    author: ryt3n
    created_utc: 1786140114
    edited: false
    body:
    I do not think multi sig is too much. I think it’s absolutely worth it - probably mandatory - for any self custody.
    
    comment: p2co5b7
    parent: t3_1vie1vy
    author: Cryptotiptoe21
    created_utc: 1786140196
    edited: false
    body:
    I recommend the Keystone pro 3. They have Bitcoin only firmware. It is air gapped. Open source. They have also made commitments that they will never do what ledger did and that being offer a "recovery feature"

    Excerpt only. The complete copy is held offline and backs quotations on this site. The original publication remains the canonical public source.

  5. source content difference between and source content +19 -0

    A new reply argues multisig is preferable to a passphrase for recovery, physical-coercion resistance, and inheritance planning.

    seen · Captured here 22,787 chars
    What changed from the previous capture 19 lines
     edited: false
     body:
     I guess I forgot about that. Krux has the support also.
    +
    +comment: p2kxdoa
    +parent: t1_p2guxyu
    +author: Honest-Warning-7116
    +created_utc: 1786245905
    +edited: false
    +body:
    +Multisig is better than a passphrase for three key reasons:
    +
    +1.  Recovery from a lost or compromised seed  
    +With a 2-of-3 multisig setup, losing or compromising one seed does not lock you out of your funds. You still have two other keys that can authorize transactions, giving you a much higher chance of recovery compared to a single seed protected only by a passphrase.
    +
    +2.  Protection against physical coercion  
    +Recent waves of home invasions and extortion (such as those reported in France) show how dangerous it is to have all access concentrated in one place. By distributing the three devices across three separate locations, even you cannot move funds on short notice. An attacker who forces you to cooperate still cannot access the other keys quickly enough to steal the funds.
    +
    +3.  Better inheritance planning  
    +Multisig makes it practical to leave one key in a secure location such as a bank safe-deposit box. This creates a clear, controllable path for heirs to recover the funds without relying solely on a single passphrase that could be forgotten, lost, or disputed.
    +
    +In short, multisig turns a single point of failure into a distributed system that improves recovery, security against physical threats, and estate planning—advantages a passphrase alone cannot match.
    
    Extracted text as captured
    post: 1vie1vy
    author: Large_Still_1224
    created_utc: 1786139812
    title: Dice Rolls Saved Me, But…
    body:
    I am super fortunate that I wasn't a victim of the cold card hack (my heart goes out to everyone who was). I attribute me still having my BTC to the fact that I generated my seed from dice.
    
    Right when I heard about the news, I moved my coins, and right now I'm still sketched out by the cold card and my seed (even though I used 100 dice rolls to generate it)
    
    I'm looking for the best long term alternative for me now, which from my research seems to be:
    
    1. Seedsigner with a new seed from 100 dice rolls  
    2. Passphase  
    (I feel like multisig might be overshooting it for me personally.)
    
    Here are my questions though.
    
    1. I understand that you have to load in the seed into Seedsigner each time you want to transact, so what's the most secure way of doing this (aside from having the QR code feature, which seems risky to me keeping that QR code card laying around.)
    
    2. with my previous dice rolled seed phrase, is there any risk with using the first 6-10 words of that as a new passphrase?
    
    3. anything else I'm missing for this
    
    Thanks!
    
    comment: p2cnvr0
    parent: t3_1vie1vy
    author: ryt3n
    created_utc: 1786140114
    edited: false
    body:
    I do not think multi sig is too much. I think it’s absolutely worth it - probably mandatory - for any self custody.
    
    comment: p2co5b7
    parent: t3_1vie1vy
    author: Cryptotiptoe21
    created_utc: 1786140196
    edited: false
    body:
    I recommend the Keystone pro 3. They have Bitcoin only firmware. It is air gapped. Open source. They have also made commitments that they will never do what ledger did and that being offer a "recovery feature"

    Excerpt only. The complete copy is held offline and backs quotations on this site. The original publication remains the canonical public source.

  6. source content difference between and source content +16 -0

    The thread gained new comments from users who used dice-generated seeds and were planning SeedSigner or multisig setups.

    seen · Captured here 21,394 chars
    What changed from the previous capture 16 lines
     edited: false
     body:
     I did some research and apparently the encrypted SeedQR feature only exists if you’re running one of the modified/forked firmware builds, like the “Crypto Guide’s” seedsigner fork. Not the stock firmware from seedsigner.com/GitHub’s official repo.
    +
    +comment: p2ieesl
    +parent: t3_1vie1vy
    +author: Uhrenwerker
    +created_utc: 1786215725
    +edited: false
    +body:
    +I feel you bro I’m on the same boat, made my coldcard seeds with dice and dodged a terrifying bullet. I still freaked out and wiped the cold cards into a hot sparrow wallet and a exchange. I have ordered a seedsigner and a jade. Was planning to setup multisig 2-3 with these two plus maybe upgraded coldcard, I’ll anyway create new seeds with dice again.
    +
    +comment: p2iy6ht
    +parent: t1_p2i40y3
    +author: GadJedi
    +created_utc: 1786221557
    +edited: false
    +body:
    +I guess I forgot about that. Krux has the support also.
    
    Extracted text as captured
    post: 1vie1vy
    author: Large_Still_1224
    created_utc: 1786139812
    title: Dice Rolls Saved Me, But…
    body:
    I am super fortunate that I wasn't a victim of the cold card hack (my heart goes out to everyone who was). I attribute me still having my BTC to the fact that I generated my seed from dice.
    
    Right when I heard about the news, I moved my coins, and right now I'm still sketched out by the cold card and my seed (even though I used 100 dice rolls to generate it)
    
    I'm looking for the best long term alternative for me now, which from my research seems to be:
    
    1. Seedsigner with a new seed from 100 dice rolls  
    2. Passphase  
    (I feel like multisig might be overshooting it for me personally.)
    
    Here are my questions though.
    
    1. I understand that you have to load in the seed into Seedsigner each time you want to transact, so what's the most secure way of doing this (aside from having the QR code feature, which seems risky to me keeping that QR code card laying around.)
    
    2. with my previous dice rolled seed phrase, is there any risk with using the first 6-10 words of that as a new passphrase?
    
    3. anything else I'm missing for this
    
    Thanks!
    
    comment: p2cnvr0
    parent: t3_1vie1vy
    author: ryt3n
    created_utc: 1786140114
    edited: false
    body:
    I do not think multi sig is too much. I think it’s absolutely worth it - probably mandatory - for any self custody.
    
    comment: p2co5b7
    parent: t3_1vie1vy
    author: Cryptotiptoe21
    created_utc: 1786140196
    edited: false
    body:
    I recommend the Keystone pro 3. They have Bitcoin only firmware. It is air gapped. Open source. They have also made commitments that they will never do what ledger did and that being offer a "recovery feature"

    Excerpt only. The complete copy is held offline and backs quotations on this site. The original publication remains the canonical public source.

  7. Earliest copy held
    seen · Captured here 20,785 chars
    Extracted text as captured
    post: 1vie1vy
    author: Large_Still_1224
    created_utc: 1786139812
    title: Dice Rolls Saved Me, But…
    body:
    I am super fortunate that I wasn't a victim of the cold card hack (my heart goes out to everyone who was). I attribute me still having my BTC to the fact that I generated my seed from dice.
    
    Right when I heard about the news, I moved my coins, and right now I'm still sketched out by the cold card and my seed (even though I used 100 dice rolls to generate it)
    
    I'm looking for the best long term alternative for me now, which from my research seems to be:
    
    1. Seedsigner with a new seed from 100 dice rolls  
    2. Passphase  
    (I feel like multisig might be overshooting it for me personally.)
    
    Here are my questions though.
    
    1. I understand that you have to load in the seed into Seedsigner each time you want to transact, so what's the most secure way of doing this (aside from having the QR code feature, which seems risky to me keeping that QR code card laying around.)
    
    2. with my previous dice rolled seed phrase, is there any risk with using the first 6-10 words of that as a new passphrase?
    
    3. anything else I'm missing for this
    
    Thanks!
    
    comment: p2cnvr0
    parent: t3_1vie1vy
    author: ryt3n
    created_utc: 1786140114
    edited: false
    body:
    I do not think multi sig is too much. I think it’s absolutely worth it - probably mandatory - for any self custody.
    
    comment: p2co5b7
    parent: t3_1vie1vy
    author: Cryptotiptoe21
    created_utc: 1786140196
    edited: false
    body:
    I recommend the Keystone pro 3. They have Bitcoin only firmware. It is air gapped. Open source. They have also made commitments that they will never do what ledger did and that being offer a "recovery feature"

    Excerpt only. The complete copy is held offline and backs quotations on this site. The original publication remains the canonical public source.

How to check this yourself

The excerpts and plain unified diffs above show the text this project held and how it changed. To verify a quotation, compare it against the page itself or against the Internet Archive's copies, which are independent of this project.

Complete captures are held offline rather than mirrored here, so this page shows diffs and excerpts. If a quotation is ever disputed, the full copy can be produced. Ask.