r/coldcard: whether 100% dice-generated Mk4 wallets are at risk
reddit-dice-wallets-at-risk
https://www.reddit.com/r/coldcard/comments/1veixnw/coldcard_mk4_are_wallets_generated_with_100_dice/
Latest reviewed change
source content difference between and
The Reddit thread gained new participant comments about production test harnesses and moving to multi-sig.
edited: false
body:
Do not trust your memory.
+
+comment: p2bxff8
+parent: t1_p1lnjst
+author: KIFulgore
+created_utc: 1786132650
First lines only. The complete diff is in the timeline below.
- Organisation
- Evidence role
- Community discussion
- Published
- not established
- Source changes
- 7
- Detected differences
- 7
- Unreviewed
- 0
- Copies held
- 8
Every check is recorded, including checks that found no text change. A detected edit is therefore bounded between two checks. The publisher's exact save time is not observable from this record. Last checked .
This post is held twice: here, with this project's own note on why it matters, and again as part of the conversation captured at , which is polled for changes. Both copies are the same post; neither is a separate event.
Snapshot and diff bodies for this chain monitor are held in the local evidence archive but withheld from the public site because they can contain the addresses of people who published nothing themselves. Capture times and reviewed change summaries remain available below.
Held captures
-
The Reddit thread gained new participant comments about production test harnesses and moving to multi-sig.
Recovered from the Internet Archive rather than captured by this project. The row records that third-party provenance separately from captures made by this project.
What changed from the previous capture 16 lines
edited: false body: Do not trust your memory. + +comment: p2bxff8 +parent: t1_p1lnjst +author: KIFulgore +created_utc: 1786132650 +edited: false +body: +Yeah, that is totally reasonable. But they shouldn't deploy test harness code with the production build. I have never included mock servers or unit test code with any production service I've deployed. If code should never be reachable in production, it shouldn't be there. + +comment: p2cdz39 +parent: t3_1veixnw +author: phoneguy3 +created_utc: 1786137194 +edited: false +body: +I am in the same situation and I am still moving my Bitcoin. Safe for now is not safe enough. You never know when single sig could fail. Not right now. Not anytime soon. But in the age of AI, I can't rule out out. So I'm going multi-sig. Not waiting for another CC exploit that hasn't been found yet; not waiting for a single-sig vulnerability whatever that might be, whether or not I or anyone else can even imagine what a single-sig vulnerability would even look like. I'm multi-sigging. As soon as I receive the additional hardware.Extracted text as captured
post: 1veixnw author: muffinhalfling created_utc: 1785775816 title: Coldcard MK4 - are wallets generated with 100% dice at risk? body: So when i setup my mk4 few years ago i was paranoid enough that i used 100+ dice rolls done in the correct way. I did it 3 times. 2 of them i doublechecked with a seedsigner to verify they made the same seed, they did. Then i made my seed using the dice function on the mk4. I also have a 30+ character long passphrase on top. Mixed letters and numbers. As i understand this completely bypasses the RNG coldcard used, and it should not affect my seed. Am i missing something? Yes i see the time has come to move on to a multisig, and that is the next step.. comment: p1hbpwt parent: t3_1veixnw author: No_Position_8581 created_utc: 1785776378 edited: false body: As of now no. Dice Gang where we at!! 馃幉 comment: p1hde7y parent: t3_1veixnw author: Flowa-Powa created_utc: 1785776789 edited: false body: No. 100 dice rolls puts you in a safe place. There is nothing to suggest the dice roll feature is broken as long as you did at least 50 dice rolls. The random passphrase layered on top makes it doubly safe. I am in a similar position and I am not moving my Bitcoin comment: p1hewb3 parent: t1_p1hbpwt author: OptionbullsExcerpt only. The complete copy is held offline and backs quotations on this site. The original publication remains the canonical public source.
-
One new comment from Makunouchiipp0 warning readers not to trust their memory when doing dice rolls.
Recovered from the Internet Archive rather than captured by this project. The row records that third-party provenance separately from captures made by this project.
What changed from the previous capture 8 lines
edited: false body: It's there a particular dice roll method that people use? I plan to do it soon. Just curious if they're is a solid guide to follow or if it's pretty straight forward. + +comment: p28qr35 +parent: t3_1veixnw +author: Makunouchiipp0 +created_utc: 1786100638 +edited: false +body: +Do not trust your memory.Extracted text as captured
post: 1veixnw author: muffinhalfling created_utc: 1785775816 title: Coldcard MK4 - are wallets generated with 100% dice at risk? body: So when i setup my mk4 few years ago i was paranoid enough that i used 100+ dice rolls done in the correct way. I did it 3 times. 2 of them i doublechecked with a seedsigner to verify they made the same seed, they did. Then i made my seed using the dice function on the mk4. I also have a 30+ character long passphrase on top. Mixed letters and numbers. As i understand this completely bypasses the RNG coldcard used, and it should not affect my seed. Am i missing something? Yes i see the time has come to move on to a multisig, and that is the next step.. comment: p1hbpwt parent: t3_1veixnw author: No_Position_8581 created_utc: 1785776378 edited: false body: As of now no. Dice Gang where we at!! 馃幉 comment: p1hde7y parent: t3_1veixnw author: Flowa-Powa created_utc: 1785776789 edited: false body: No. 100 dice rolls puts you in a safe place. There is nothing to suggest the dice roll feature is broken as long as you did at least 50 dice rolls. The random passphrase layered on top makes it doubly safe. I am in a similar position and I am not moving my Bitcoin comment: p1hewb3 parent: t1_p1hbpwt author: OptionbullsExcerpt only. The complete copy is held offline and backs quotations on this site. The original publication remains the canonical public source.
-
Reddit served an additional comment asking whether there is a particular dice-roll method or guide to use when generating a wallet.
Recovered from the Internet Archive rather than captured by this project. The row records that third-party provenance separately from captures made by this project.
What changed from the previous capture 8 lines
You can cross reference dice roll seed phrases with software that confirms it (only do this on a clean computer that is not connected to the internet) or a different cold storage device You can also cross reference paraphrases by trying to set up the seed phrase containing the passphrase on a different cold storage device and see if the whole phrase is needed to gain access + +comment: p1uwbts +parent: t3_1veixnw +author: SmellyCummies +created_utc: 1785938529 +edited: false +body: +It's there a particular dice roll method that people use? I plan to do it soon. Just curious if they're is a solid guide to follow or if it's pretty straight forward.Extracted text as captured
post: 1veixnw author: muffinhalfling created_utc: 1785775816 title: Coldcard MK4 - are wallets generated with 100% dice at risk? body: So when i setup my mk4 few years ago i was paranoid enough that i used 100+ dice rolls done in the correct way. I did it 3 times. 2 of them i doublechecked with a seedsigner to verify they made the same seed, they did. Then i made my seed using the dice function on the mk4. I also have a 30+ character long passphrase on top. Mixed letters and numbers. As i understand this completely bypasses the RNG coldcard used, and it should not affect my seed. Am i missing something? Yes i see the time has come to move on to a multisig, and that is the next step.. comment: p1hbpwt parent: t3_1veixnw author: No_Position_8581 created_utc: 1785776378 edited: false body: As of now no. Dice Gang where we at!! 馃幉 comment: p1hde7y parent: t3_1veixnw author: Flowa-Powa created_utc: 1785776789 edited: false body: No. 100 dice rolls puts you in a safe place. There is nothing to suggest the dice roll feature is broken as long as you did at least 50 dice rolls. The random passphrase layered on top makes it doubly safe. I am in a similar position and I am not moving my Bitcoin comment: p1hewb3 parent: t1_p1hbpwt author: OptionbullsExcerpt only. The complete copy is held offline and backs quotations on this site. The original publication remains the canonical public source.
-
The Reddit thread gained 2 new comments.
Recovered from the Internet Archive rather than captured by this project. The row records that third-party provenance separately from captures made by this project.
What changed from the previous capture 20 lines
edited: false body: You are all good 馃憤 + +comment: p1om17i +parent: t3_1veixnw +author: painfuldrp +created_utc: 1785862454 +edited: false +body: +No, you should be very safe + +comment: p1onh59 +parent: t1_p1hsmgm +author: painfuldrp +created_utc: 1785862813 +edited: false +body: +I doubt the person with the dice roll did it properly or is confusing which device he used to dice roll. There鈥檚 only that one case and there鈥檚 a 99% chance it was some kind of user error or the person is lying for engagement + +You can cross reference dice roll seed phrases with software that confirms it (only do this on a clean computer that is not connected to the internet) or a different cold storage device + +You can also cross reference paraphrases by trying to set up the seed phrase containing the passphrase on a different cold storage device and see if the whole phrase is needed to gain accessExtracted text as captured
post: 1veixnw author: muffinhalfling created_utc: 1785775816 title: Coldcard MK4 - are wallets generated with 100% dice at risk? body: So when i setup my mk4 few years ago i was paranoid enough that i used 100+ dice rolls done in the correct way. I did it 3 times. 2 of them i doublechecked with a seedsigner to verify they made the same seed, they did. Then i made my seed using the dice function on the mk4. I also have a 30+ character long passphrase on top. Mixed letters and numbers. As i understand this completely bypasses the RNG coldcard used, and it should not affect my seed. Am i missing something? Yes i see the time has come to move on to a multisig, and that is the next step.. comment: p1hbpwt parent: t3_1veixnw author: No_Position_8581 created_utc: 1785776378 edited: false body: As of now no. Dice Gang where we at!! 馃幉 comment: p1hde7y parent: t3_1veixnw author: Flowa-Powa created_utc: 1785776789 edited: false body: No. 100 dice rolls puts you in a safe place. There is nothing to suggest the dice roll feature is broken as long as you did at least 50 dice rolls. The random passphrase layered on top makes it doubly safe. I am in a similar position and I am not moving my Bitcoin comment: p1hewb3 parent: t1_p1hbpwt author: OptionbullsExcerpt only. The complete copy is held offline and backs quotations on this site. The original publication remains the canonical public source.
-
2 new Reddit comments were posted, by Scissorhat and paulm95.
Recovered from the Internet Archive rather than captured by this project. The row records that third-party provenance separately from captures made by this project.
What changed from the previous capture 18 lines
exactly, using CC is simply adding new, extra bugs and vulnerabilities how do you know your CC is not leaking parts of your seed with every transaction for example + +comment: p1oegyp +parent: t1_p1hde7y +author: Scissorhat +created_utc: 1785860568 +edited: false +body: +> I am in a similar position and I am not moving my Bitcoin + +Ballsy. + +comment: p1ogrty +parent: t3_1veixnw +author: paulm95 +created_utc: 1785861144 +edited: false +body: +You are all good 馃憤Extracted text as captured
post: 1veixnw author: muffinhalfling created_utc: 1785775816 title: Coldcard MK4 - are wallets generated with 100% dice at risk? body: So when i setup my mk4 few years ago i was paranoid enough that i used 100+ dice rolls done in the correct way. I did it 3 times. 2 of them i doublechecked with a seedsigner to verify they made the same seed, they did. Then i made my seed using the dice function on the mk4. I also have a 30+ character long passphrase on top. Mixed letters and numbers. As i understand this completely bypasses the RNG coldcard used, and it should not affect my seed. Am i missing something? Yes i see the time has come to move on to a multisig, and that is the next step.. comment: p1hbpwt parent: t3_1veixnw author: No_Position_8581 created_utc: 1785776378 edited: false body: As of now no. Dice Gang where we at!! 馃幉 comment: p1hde7y parent: t3_1veixnw author: Flowa-Powa created_utc: 1785776789 edited: false body: No. 100 dice rolls puts you in a safe place. There is nothing to suggest the dice roll feature is broken as long as you did at least 50 dice rolls. The random passphrase layered on top makes it doubly safe. I am in a similar position and I am not moving my Bitcoin comment: p1hewb3 parent: t1_p1hbpwt author: OptionbullsExcerpt only. The complete copy is held offline and backs quotations on this site. The original publication remains the canonical public source.
-
4 new Reddit comments were posted, including didnt_hodl and _gianlucag_, discussing RNG certification and generating a seed elsewhere.
Recovered from the Internet Archive rather than captured by this project. The row records that third-party provenance separately from captures made by this project.
What changed from the previous capture 39 lines
edited: false body: Makes sense + +comment: p1nqn8f +parent: t1_p1liqng +author: didnt_hodl +created_utc: 1785854431 +edited: false +body: +for TRNG there are certification levels, and unlike ColdCard everyone else is fully certified I believe. meaning that their random number generator was properly tested. search for EAL5+, AIS-31. + + +the issue with TRNG certification was raised earlier with CC and they dismissed it + +comment: p1nr15t +parent: t1_p1lo69c +author: didnt_hodl +created_utc: 1785854532 +edited: false +body: +right. but if I have another device, why would not I just use that then? oh ... because CC is "safer"?? please + + + +comment: p1nwevo +parent: t1_p1nr15t +author: _gianlucag_ +created_utc: 1785855945 +edited: false +body: +well, if you used another device to generate the seed and imported it into the coldcard, the coldcard becomes just a "transaction signing" device. Which can either produce a valid transaction or an invalid one that doesnt broadcast (if more software bugs are found). + +comment: p1nwxcm +parent: t1_p1nwevo +author: didnt_hodl +created_utc: 1785856081 +edited: false +body: +exactly, using CC is simply adding new, extra bugs and vulnerabilities + +how do you know your CC is not leaking parts of your seed with every transaction for exampleExtracted text as captured
post: 1veixnw author: muffinhalfling created_utc: 1785775816 title: Coldcard MK4 - are wallets generated with 100% dice at risk? body: So when i setup my mk4 few years ago i was paranoid enough that i used 100+ dice rolls done in the correct way. I did it 3 times. 2 of them i doublechecked with a seedsigner to verify they made the same seed, they did. Then i made my seed using the dice function on the mk4. I also have a 30+ character long passphrase on top. Mixed letters and numbers. As i understand this completely bypasses the RNG coldcard used, and it should not affect my seed. Am i missing something? Yes i see the time has come to move on to a multisig, and that is the next step.. comment: p1hbpwt parent: t3_1veixnw author: No_Position_8581 created_utc: 1785776378 edited: false body: As of now no. Dice Gang where we at!! 馃幉 comment: p1hde7y parent: t3_1veixnw author: Flowa-Powa created_utc: 1785776789 edited: false body: No. 100 dice rolls puts you in a safe place. There is nothing to suggest the dice roll feature is broken as long as you did at least 50 dice rolls. The random passphrase layered on top makes it doubly safe. I am in a similar position and I am not moving my Bitcoin comment: p1hewb3 parent: t1_p1hbpwt author: OptionbullsExcerpt only. The complete copy is held offline and backs quotations on this site. The original publication remains the canonical public source.
-
1 new Reddit comment was posted, including WillemKadijk.
Recovered from the Internet Archive rather than captured by this project. The row records that third-party provenance separately from captures made by this project.
What changed from the previous capture 8 lines
edited: false body: Rolling dice alone will not automatically make you safe, you also need to trust the software you're using to convert the dice rolls into your keys. Comparing the results of various different softwares is good, however it's still theoretically possible all of the programs you compare could have the same bug and produce the same bad result. + +comment: p1mg1sh +parent: t1_p1jt1xm +author: WillemKadijk +created_utc: 1785839414 +edited: false +body: +Makes senseExtracted text as captured
post: 1veixnw author: muffinhalfling created_utc: 1785775816 title: Coldcard MK4 - are wallets generated with 100% dice at risk? body: So when i setup my mk4 few years ago i was paranoid enough that i used 100+ dice rolls done in the correct way. I did it 3 times. 2 of them i doublechecked with a seedsigner to verify they made the same seed, they did. Then i made my seed using the dice function on the mk4. I also have a 30+ character long passphrase on top. Mixed letters and numbers. As i understand this completely bypasses the RNG coldcard used, and it should not affect my seed. Am i missing something? Yes i see the time has come to move on to a multisig, and that is the next step.. comment: p1hbpwt parent: t3_1veixnw author: No_Position_8581 created_utc: 1785776378 edited: false body: As of now no. Dice Gang where we at!! 馃幉 comment: p1hde7y parent: t3_1veixnw author: Flowa-Powa created_utc: 1785776789 edited: false body: No. 100 dice rolls puts you in a safe place. There is nothing to suggest the dice roll feature is broken as long as you did at least 50 dice rolls. The random passphrase layered on top makes it doubly safe. I am in a similar position and I am not moving my Bitcoin comment: p1hewb3 parent: t1_p1hbpwt author: OptionbullsExcerpt only. The complete copy is held offline and backs quotations on this site. The original publication remains the canonical public source.
-
Recovered from the Internet Archive rather than captured by this project. The row records that third-party provenance separately from captures made by this project.
What changed from the previous capture 0 lines
Extracted text as captured
post: 1veixnw author: muffinhalfling created_utc: 1785775816 title: Coldcard MK4 - are wallets generated with 100% dice at risk? body: So when i setup my mk4 few years ago i was paranoid enough that i used 100+ dice rolls done in the correct way. I did it 3 times. 2 of them i doublechecked with a seedsigner to verify they made the same seed, they did. Then i made my seed using the dice function on the mk4. I also have a 30+ character long passphrase on top. Mixed letters and numbers. As i understand this completely bypasses the RNG coldcard used, and it should not affect my seed. Am i missing something? Yes i see the time has come to move on to a multisig, and that is the next step.. comment: p1hbpwt parent: t3_1veixnw author: No_Position_8581 created_utc: 1785776378 edited: false body: As of now no. Dice Gang where we at!! 馃幉 comment: p1hde7y parent: t3_1veixnw author: Flowa-Powa created_utc: 1785776789 edited: false body: No. 100 dice rolls puts you in a safe place. There is nothing to suggest the dice roll feature is broken as long as you did at least 50 dice rolls. The random passphrase layered on top makes it doubly safe. I am in a similar position and I am not moving my Bitcoin comment: p1hewb3 parent: t1_p1hbpwt author: OptionbullsExcerpt only. The complete copy is held offline and backs quotations on this site. The original publication remains the canonical public source.
0 presentation-noise differences. Sidebar, ticker and other page chrome churn that our review classified as not being changes to what the source says.
The excerpts and plain unified diffs above show the text this project held and how it changed. To verify a quotation, compare it against the page itself or against the Internet Archive's copies, which are independent of this project.
Complete captures are held offline rather than mirrored here, so this page shows diffs and excerpts. If a quotation is ever disputed, the full copy can be produced. Ask.
Compare the screenshot or a quotation against the original while it is available.