r/coldcard: safety of Mk4 dice-generated seeds, and alternatives
reddit-mk4-dice-seed-safety
https://www.reddit.com/r/coldcard/comments/1vdge71/is_it_safe_to_use_mk4_for_creation_of_seed_using/
Latest reviewed change
source content difference between and
Two comments by Warrior_witha_Garden disappeared: one body replaced with [removed] and account shown as [deleted], the other dropped from the listing. The removed text had claimed all Coldcards are unsafe and urged moving to Seed Signer or Tails and Electrum.
comment: p1a0ib2
parent: t3_1vdge71
-author: Warrior_witha_Garden
+author: [deleted]
created_utc: 1785687410
edited: false
body:
First lines only. The complete diff is in the timeline below.
- Organisation
- Evidence role
- Community discussion
- Published
- not established
- Source changes
- 1
- Detected differences
- 1
- Unreviewed
- 0
- Copies held
- 2
Every check is recorded, including checks that found no text change. A detected edit is therefore bounded between two checks. The publisher's exact save time is not observable from this record. Last checked .
This post is held twice: here, with this project's own note on why it matters, and again as part of the conversation captured at , which is polled for changes. Both copies are the same post; neither is a separate event.
Snapshot and diff bodies for this chain monitor are held in the local evidence archive but withheld from the public site because they can contain the addresses of people who published nothing themselves. Capture times and reviewed change summaries remain available below.
Held captures
-
Two comments by Warrior_witha_Garden disappeared: one body replaced with [removed] and account shown as [deleted], the other dropped from the listing. The removed text had claimed all Coldcards are unsafe and urged moving to Seed Signer or Tails and Electrum.
Recovered from the Internet Archive rather than captured by this project. The row records that third-party provenance separately from captures made by this project.
What changed from the previous capture 12 lines
comment: p1a0ib2 parent: t3_1vdge71 -author: Warrior_witha_Garden +author: [deleted] created_utc: 1785687410 edited: false body: -No it is not safe. ALL the cold cards are cooked ! more is coming out. get a different wallet. You can use Tails and Electrum in a pinch. save that seed. Seed Signer is the move right now. Get some dice and get to work. +[removed] comment: p1aqb2r parent: t3_1vdge71 What else is coming out ? - -comment: p1be4h8 -parent: t1_p1as272 -author: Warrior_witha_Garden -created_utc: 1785700926 -edited: false -body: -cold cards are getting bricked with new firmware. other exploits are being found. 1) if you have a usb you can use ian colemans seed generator using tails OS. free and secure. 2) you dont want a cold card for anything at this point. to much risk. if they were this sloppy its a matter of time. save your cold card for lawsuits and civil action. comment: p1bmgr9 parent: t1_p1ar3d9Extracted text as captured
post: 1vdge71 author: UnderstandingNew8001 created_utc: 1785672404 title: Is it safe to use MK4 for creation of seed using dice then move, if not what other way? body: Got my coins out of MK4 on a temp wallet, and I just got my new Trezor, and learning from what happened I am planning to create a new wallet with seeds generated using dice, however it seems Trezor doesn't have that option, and I don't have a device I can have offline to run any program to help, so I am thinking of updating the new firmware of MK4, create a new wallet with Dice, import the seeds into Trezor and add a passphrase, does this make sense? is there any possible issues? comment: p18q799 parent: t3_1vdge71 author: Quirky-Reveal-1669 created_utc: 1785673127 edited: 1785678630 body: This is also what I have been contemplating. Mk4 can be kept airgapped, and seed generation according to BIP39, using dice is mathematical, there is no use of the RNG in Mk4. The words generated could then be entered in Trezor. This is an interesting option, since Trezor cannot function totally airgapped, and Trezor does not offer the option to guide you through seed generation with dice entropy. I am currently skeptical of any RNG, so the option of dice rolls is very appealing. comment: p18qgxk parent: t3_1vdge71 author: ackyou created_utc: 1785673229 edited: false body: Yep, that makes sense. You could go the additional step of doing that multiple times with the mk4 and then verify some of those outputs with rolls.py. It’s best not to verify the one you actually use unless it’s on an air-gapped computer. Alternatively, you can generate seed words directly with 8 and 16 sided dice directly with only pen and paper but that’s more of a pain. comment: p18rqd8 parent: t3_1vdge71 author: zootreddit created_utc: 1785673706 edited: false body: The one issue with CC was seed gen. If you are going to seed gen on mk4 you might as well use the mk4 and send the trezor back for refund. comment: p18u5yr parent: t1_p18rqd8 author: ackyou created_utc: 1785674590 edited: false body: The one issue we know about which has been lurking for 5 years. If they messed up seed gen, perhaps the most crucial component, who knows what else is just waiting to be discovered.Excerpt only. The complete copy is held offline and backs quotations on this site. The original publication remains the canonical public source.
-
Recovered from the Internet Archive rather than captured by this project. The row records that third-party provenance separately from captures made by this project.
What changed from the previous capture 0 lines
Extracted text as captured
post: 1vdge71 author: UnderstandingNew8001 created_utc: 1785672404 title: Is it safe to use MK4 for creation of seed using dice then move, if not what other way? body: Got my coins out of MK4 on a temp wallet, and I just got my new Trezor, and learning from what happened I am planning to create a new wallet with seeds generated using dice, however it seems Trezor doesn't have that option, and I don't have a device I can have offline to run any program to help, so I am thinking of updating the new firmware of MK4, create a new wallet with Dice, import the seeds into Trezor and add a passphrase, does this make sense? is there any possible issues? comment: p18q799 parent: t3_1vdge71 author: Quirky-Reveal-1669 created_utc: 1785673127 edited: 1785678630 body: This is also what I have been contemplating. Mk4 can be kept airgapped, and seed generation according to BIP39, using dice is mathematical, there is no use of the RNG in Mk4. The words generated could then be entered in Trezor. This is an interesting option, since Trezor cannot function totally airgapped, and Trezor does not offer the option to guide you through seed generation with dice entropy. I am currently skeptical of any RNG, so the option of dice rolls is very appealing. comment: p18qgxk parent: t3_1vdge71 author: ackyou created_utc: 1785673229 edited: false body: Yep, that makes sense. You could go the additional step of doing that multiple times with the mk4 and then verify some of those outputs with rolls.py. It’s best not to verify the one you actually use unless it’s on an air-gapped computer. Alternatively, you can generate seed words directly with 8 and 16 sided dice directly with only pen and paper but that’s more of a pain. comment: p18rqd8 parent: t3_1vdge71 author: zootreddit created_utc: 1785673706 edited: false body: The one issue with CC was seed gen. If you are going to seed gen on mk4 you might as well use the mk4 and send the trezor back for refund. comment: p18u5yr parent: t1_p18rqd8 author: ackyou created_utc: 1785674590 edited: false body: The one issue we know about which has been lurking for 5 years. If they messed up seed gen, perhaps the most crucial component, who knows what else is just waiting to be discovered.Excerpt only. The complete copy is held offline and backs quotations on this site. The original publication remains the canonical public source.
0 presentation-noise differences. Sidebar, ticker and other page chrome churn that our review classified as not being changes to what the source says.
The excerpts and plain unified diffs above show the text this project held and how it changed. To verify a quotation, compare it against the page itself or against the Internet Archive's copies, which are independent of this project.
Complete captures are held offline rather than mirrored here, so this page shows diffs and excerpts. If a quotation is ever disputed, the full copy can be produced. Ask.
Compare the screenshot or a quotation against the original while it is available.