COLDCARD RNG incident the public record, collected and explained
Informational only, and this site never asks for your seed words. details

Informational only. This is an open source collection of what others have published about the incident, together with an explanation of it. It is not financial, security or legal advice, and not a substitute for professional advice about your own situation. It is not affiliated with, endorsed by, or speaking for Coinkite. Material is attributed and quoted as published; where sources disagree their scenarios are kept separate with their assumptions rather than reconciled into one answer. Everything is meant to be checked against the linked evidence rather than taken on trust. Act on your own judgement about a particular situation. Editorial standards and corrections.

Do not disclose recovery material to a website, form, message or support account. This site never asks for it, and contributions containing recovery words or private keys are not accepted.

r/Bitcoin: Forrest video from nine months ago that may have helped Coldcard users

reddit-forrest-video-coldcard

https://www.reddit.com/r/Bitcoin/comments/1vm15sk/9_months_ago_a_video_from_forrest_couldve/

Latest reviewed change

source content difference between and

Reddit served 4 additional comment record(s); the diff preserves their text and any edits to existing records.

seen +41 -0 full history below
 edited: false
 body:
 I know. As I said below, but given they have a touchscreen why not allow manual entropy *as well* for users who want to use it? It would be relatively simple to do and more entropy options is better as a rule of thumb. 
+
+comment: p3m9071
+parent: t1_p3m1ntg
+author: Laukess
+created_utc: 1786701920

First lines only. The complete diff is in the timeline below.

Organisation
reddit
Evidence role
Community discussion
Published
not established
Source changes
4
Detected differences
4
Unreviewed
0
Copies held
5

Every check is recorded, including checks that found no text change. A detected edit is therefore bounded between two checks. The publisher's exact save time is not observable from this record. Last checked .

  1. source content difference between and Current source content +41 -0

    Reddit served 4 additional comment record(s); the diff preserves their text and any edits to existing records.

    seen · Captured here 18,986 chars
    What changed from the previous capture 41 lines
     edited: false
     body:
     I know. As I said below, but given they have a touchscreen why not allow manual entropy *as well* for users who want to use it? It would be relatively simple to do and more entropy options is better as a rule of thumb. 
    +
    +comment: p3m9071
    +parent: t1_p3m1ntg
    +author: Laukess
    +created_utc: 1786701920
    +edited: false
    +body:
    +Yeah, if only more companies would remove features that has been extremely useful and be more like Trezor so we have more choices in hardware wallets with no air gapped features or miniscript support. 
    +
    +You don't need these things because Trezor does not support them, so no reason to spend resources implementing them.
    +
    +comment: p3mfcia
    +parent: t1_p3m9071
    +author: Strong_Judge_3730
    +created_utc: 1786704664
    +edited: false
    +body:
    +Again it turns out the hardware wallet with the least devs and the most features is the one that gets hacked due to a bug in their firmware.
    +
    +
    +comment: p3ofa4w
    +parent: t1_p3m238k
    +author: PaperPigGolf
    +created_utc: 1786725807
    +edited: false
    +body:
    +Bad take.  Why the ghost library written by the cto under a psuedonym?
    +
    +comment: p3ofri7
    +parent: t1_p3l01fc
    +author: PaperPigGolf
    +created_utc: 1786725933
    +edited: false
    +body:
    +Is it though? Do you trust your sha256 checksum? 
    +
    +Did you pad the data correctly? 
    +
    +It's not impossible, you just have to admit,  it's difficult for almost anyone but an engineer.  
    +
    +more-stub: parent t1_p3ofri7 count <live-count>
    
    Extracted text as captured
    post: 1vm15sk
    author: bitcoinphilosophy
    created_utc: 1786500487
    title: 9 months ago a video from Forrest could've possibly helped ColdCard users.
    
    comment: p35u9qv
    parent: t3_1vm15sk
    author: Embarrassed-Bet-8857
    created_utc: 1786500822
    edited: false
    body:
    If wishes were fishes, we'd all swim in riches
    
    comment: p35wcfh
    parent: t1_p35u9qv
    author: fueltheburns
    created_utc: 1786501528
    edited: false
    body:
    If onlys and justs were candies and nuts, then every day would be Erntedankfest. - Dwight Schrute
    
    comment: p35y58j
    parent: t1_p35u9qv
    author: 6thcoin
    created_utc: 1786502150
    edited: false
    body:
    When if is a fifth we all can get drunk.
    
    comment: p35yd6z
    parent: t3_1vm15sk
    author: Jimbob404error
    created_utc: 1786502228
    edited: false
    body:
    No cold storage is safe 
    
    comment: p35yqy2
    parent: t1_p35wcfh
    author: ackyou

    Excerpt only. The complete copy is held offline and backs quotations on this site. The original publication remains the canonical public source.

  2. source content difference between and source content +72 -0

    Reddit served 7 additional comment record(s); the diff preserves their text and any edits to existing records.

    seen · Captured here 17,824 chars
    What changed from the previous capture 72 lines
     Basically, if you are trusting software to do the right thing, how do you come about trusting that it has done the right thing. 
     
     In your case, the software is some conversion from actualy seed to the BIP-39. 
    +
    +comment: p3l01fc
    +parent: t1_p3j3sim
    +author: word-dragon
    +created_utc: 1786680718
    +edited: false
    +body:
    +This is a riot!  I’ve written software all my life and always thought in terms of explaining to the computer what process it has to go through to accomplish its task.  Occasionally you have to run through it yourself to verify it’s gonna do what you want.
    +
    +The software is me.  I don’t plan on using anyone’s computer hardware or someone’s software I’d have to verify.  In the case you are asking:  There are 2048 words often listed as 1 to 2048, but actually representing the bit patterns from 00000000000 to 11111111111 (000 to 7ff, in hex).  So you take your first 11 bits that you generated using your manual process, and write down the corresponding word. Then you take the next eleven bits…and so on.  Since 11 bits times 24 words is 264 bits, you’ll run out of bits in the last word.  The last 8 bits are the first 8 bits of the SHA-256 hash of the key. How you get that manually is left as an exercise for the reader, lol!
    +
    +comment: p3lea3d
    +parent: t1_p378azi
    +author: Strong_Judge_3730
    +created_utc: 1786686978
    +edited: false
    +body:
    +Trezor allow you to add your own enthropy. A passphrase is doing exactly that. 
    +
    +Using a cryptographically safe random number generator is safe for most people.
    +
    +Creating a complicated process to generate a seed using dice is basically security theatre.
    +
    +comment: p3ll3o5
    +parent: t1_p3lea3d
    +author: Laukess
    +created_utc: 1786690237
    +edited: false
    +body:
    +They also allow you to roll your seed on another device and import it.  
    +Or roll the 24 words and just guess the 24th  
    +Or doing the above and XOR it with the seed they generate.
    +
    +They could also just offer the easy tools, but the dont.
    +
    +A feature that has potentially saved a lot of people a lot of money is not security theatre. 
    +
    +comment: p3m1ntg
    +parent: t1_p3ll3o5
    +author: Strong_Judge_3730
    +created_utc: 1786698408
    +edited: false
    +body:
    +Cold card focused on security theatre features like being able to roll dice to generate a seed. If they focused on their core product no one would have been hacked.
    +
    +Maybe people should listen to the hardware wallet manufacturers that did implement their firmware properly 
    +
    +comment: p3m1rul
    +parent: t1_p37tp8h
    +author: Strong_Judge_3730
    +created_utc: 1786698463
    +edited: false
    +body:
    +Trezor already combines multiple enthropy sources including from your PC.
    +
    +comment: p3m238k
    +parent: t1_p3b9g7g
    +author: Strong_Judge_3730
    +created_utc: 1786698621
    +edited: false
    +body:
    +They were just incompetent engineers. Ie focus on sales and not engineering. They wanted add all these bells an whistles to their HW to stand out to paranoid and gullible fools.
    +
    +It clearly worked because many people shilled it as being a more secure product.
    +
    +comment: p3m3tuh
    +parent: t1_p3m1rul
    +author: Mooks79
    +created_utc: 1786699468
    +edited: false
    +body:
    +I know. As I said below, but given they have a touchscreen why not allow manual entropy *as well* for users who want to use it? It would be relatively simple to do and more entropy options is better as a rule of thumb. 
    
    Extracted text as captured
    post: 1vm15sk
    author: bitcoinphilosophy
    created_utc: 1786500487
    title: 9 months ago a video from Forrest could've possibly helped ColdCard users.
    
    comment: p35u9qv
    parent: t3_1vm15sk
    author: Embarrassed-Bet-8857
    created_utc: 1786500822
    edited: false
    body:
    If wishes were fishes, we'd all swim in riches
    
    comment: p35wcfh
    parent: t1_p35u9qv
    author: fueltheburns
    created_utc: 1786501528
    edited: false
    body:
    If onlys and justs were candies and nuts, then every day would be Erntedankfest. - Dwight Schrute
    
    comment: p35y58j
    parent: t1_p35u9qv
    author: 6thcoin
    created_utc: 1786502150
    edited: false
    body:
    When if is a fifth we all can get drunk.
    
    comment: p35yd6z
    parent: t3_1vm15sk
    author: Jimbob404error
    created_utc: 1786502228
    edited: false
    body:
    No cold storage is safe 
    
    comment: p35yqy2
    parent: t1_p35wcfh
    author: ackyou

    Excerpt only. The complete copy is held offline and backs quotations on this site. The original publication remains the canonical public source.

  3. source content difference between and source content +14 -0

    Reddit served 1 additional comment record(s); the diff preserves their text and any edits to existing records.

    seen · Captured here 14,756 chars
    What changed from the previous capture 14 lines
     edited: false
     body:
     Don't remember who it was but there was one wallet a decade ago that kept getting hacked.  It turned out they were using random.org to generate random numbers and random.org went down or changed urls or something resulting in the number 404  being the random number that was always used.
    +
    +comment: p3j3sim
    +parent: t1_p3e8i0w
    +author: PaperPigGolf
    +created_utc: 1786657922
    +edited: false
    +body:
    +How do you suggest converting into 24 words? How do you verify that the software you are using to do that conversion is working propery.
    +
    +I'm not... arguing, I think this is ultimately what the entire community is scratching their heads right now.
    +
    +Basically, if you are trusting software to do the right thing, how do you come about trusting that it has done the right thing. 
    +
    +In your case, the software is some conversion from actualy seed to the BIP-39. 
    
    Extracted text as captured
    post: 1vm15sk
    author: bitcoinphilosophy
    created_utc: 1786500487
    title: 9 months ago a video from Forrest could've possibly helped ColdCard users.
    
    comment: p35u9qv
    parent: t3_1vm15sk
    author: Embarrassed-Bet-8857
    created_utc: 1786500822
    edited: false
    body:
    If wishes were fishes, we'd all swim in riches
    
    comment: p35wcfh
    parent: t1_p35u9qv
    author: fueltheburns
    created_utc: 1786501528
    edited: false
    body:
    If onlys and justs were candies and nuts, then every day would be Erntedankfest. - Dwight Schrute
    
    comment: p35y58j
    parent: t1_p35u9qv
    author: 6thcoin
    created_utc: 1786502150
    edited: false
    body:
    When if is a fifth we all can get drunk.
    
    comment: p35yd6z
    parent: t3_1vm15sk
    author: Jimbob404error
    created_utc: 1786502228
    edited: false
    body:
    No cold storage is safe 
    
    comment: p35yqy2
    parent: t1_p35wcfh
    author: ackyou

    Excerpt only. The complete copy is held offline and backs quotations on this site. The original publication remains the canonical public source.

  4. source content difference between and source content +8 -0

    Reddit served 1 additional comment record(s); the diff preserves their text and any edits to existing records.

    seen · Captured here 14,195 chars
    What changed from the previous capture 8 lines
     When I create an account, I do so like it’s going to last 30+ years.  Once I’ve made it, I load it with enough coin to be worth stealing, and then let it sit for 6-12 months before I trust it.  So actually it already takes me a year to set up a new account.  I sleep better that way.
     
     I have not added entropy checking to my process, but plan to.  Probably not with dice rolls - that was just an example.  Whatever entropy method I choose, it will be manual and not computer assisted.  The nice thing about manually creating a key is that it doesn’t matter if you make a mistake or two in the correct application of a coin flip or dice roll.  Once you have a random key, you can convert to 24 words - again a mistake or two will do little to change the entropy.  Then you just present it as your seeds to your signing device.  I treat larger accounts as deposit only, so I enter the seeds into an air-gapped device, and transfer the public key to a software wallet and just use it to watch it and generate receive addresses.  The seeds then get stored on metal in secure storage and I reset the device.
    +
    +comment: p3eot4k
    +parent: t3_1vm15sk
    +author: rydan
    +created_utc: 1786611257
    +edited: false
    +body:
    +Don't remember who it was but there was one wallet a decade ago that kept getting hacked.  It turned out they were using random.org to generate random numbers and random.org went down or changed urls or something resulting in the number 404  being the random number that was always used.
    
    Extracted text as captured
    post: 1vm15sk
    author: bitcoinphilosophy
    created_utc: 1786500487
    title: 9 months ago a video from Forrest could've possibly helped ColdCard users.
    
    comment: p35u9qv
    parent: t3_1vm15sk
    author: Embarrassed-Bet-8857
    created_utc: 1786500822
    edited: false
    body:
    If wishes were fishes, we'd all swim in riches
    
    comment: p35wcfh
    parent: t1_p35u9qv
    author: fueltheburns
    created_utc: 1786501528
    edited: false
    body:
    If onlys and justs were candies and nuts, then every day would be Erntedankfest. - Dwight Schrute
    
    comment: p35y58j
    parent: t1_p35u9qv
    author: 6thcoin
    created_utc: 1786502150
    edited: false
    body:
    When if is a fifth we all can get drunk.
    
    comment: p35yd6z
    parent: t3_1vm15sk
    author: Jimbob404error
    created_utc: 1786502228
    edited: false
    body:
    No cold storage is safe 
    
    comment: p35yqy2
    parent: t1_p35wcfh
    author: ackyou

    Excerpt only. The complete copy is held offline and backs quotations on this site. The original publication remains the canonical public source.

  5. Earliest copy held
    seen · Captured here 13,812 chars
    Extracted text as captured
    post: 1vm15sk
    author: bitcoinphilosophy
    created_utc: 1786500487
    title: 9 months ago a video from Forrest could've possibly helped ColdCard users.
    
    comment: p35u9qv
    parent: t3_1vm15sk
    author: Embarrassed-Bet-8857
    created_utc: 1786500822
    edited: false
    body:
    If wishes were fishes, we'd all swim in riches
    
    comment: p35wcfh
    parent: t1_p35u9qv
    author: fueltheburns
    created_utc: 1786501528
    edited: false
    body:
    If onlys and justs were candies and nuts, then every day would be Erntedankfest. - Dwight Schrute
    
    comment: p35y58j
    parent: t1_p35u9qv
    author: 6thcoin
    created_utc: 1786502150
    edited: false
    body:
    When if is a fifth we all can get drunk.
    
    comment: p35yd6z
    parent: t3_1vm15sk
    author: Jimbob404error
    created_utc: 1786502228
    edited: false
    body:
    No cold storage is safe 
    
    comment: p35yqy2
    parent: t1_p35wcfh
    author: ackyou

    Excerpt only. The complete copy is held offline and backs quotations on this site. The original publication remains the canonical public source.

How to check this yourself

The excerpts and plain unified diffs above show the text this project held and how it changed. To verify a quotation, compare it against the page itself or against the Internet Archive's copies, which are independent of this project.

Complete captures are held offline rather than mirrored here, so this page shows diffs and excerpts. If a quotation is ever disputed, the full copy can be produced. Ask.