COLDCARD RNG incident the public record, collected and explained
Informational only, and this site never asks for your seed words. details

Informational only. This is an open source collection of what others have published about the incident, together with an explanation of it. It is not financial, security or legal advice, and not a substitute for professional advice about your own situation. It is not affiliated with, endorsed by, or speaking for Coinkite. Material is attributed and quoted as published; where sources disagree their scenarios are kept separate with their assumptions rather than reconciled into one answer. Everything is meant to be checked against the linked evidence rather than taken on trust. Act on your own judgement about a particular situation. Editorial standards and corrections.

Do not disclose recovery material to a website, form, message or support account. This site never asks for it, and contributions containing recovery words or private keys are not accepted.

r/coldcard: safety of Mk4 dice-generated seeds, and alternatives

reddit-mk4-dice-seed-safety

https://www.reddit.com/r/coldcard/comments/1vdge71/is_it_safe_to_use_mk4_for_creation_of_seed_using/

Latest reviewed change

source content difference between and

Two comments by Warrior_witha_Garden disappeared: one body replaced with [removed] and account shown as [deleted], the other dropped from the listing. The removed text had claimed all Coldcards are unsafe and urged moving to Seed Signer or Tails and Electrum.

seen +2 -10 full history below
 
 comment: p1a0ib2
 parent: t3_1vdge71
-author: Warrior_witha_Garden
+author: [deleted]
 created_utc: 1785687410
 edited: false
 body:

First lines only. The complete diff is in the timeline below.

Organisation
reddit
Evidence role
Community discussion
Published
not established
Source changes
1
Detected differences
1
Unreviewed
0
Copies held
2

Every check is recorded, including checks that found no text change. A detected edit is therefore bounded between two checks. The publisher's exact save time is not observable from this record. Last checked .

  1. source content difference between and Current source content +2 -10

    Two comments by Warrior_witha_Garden disappeared: one body replaced with [removed] and account shown as [deleted], the other dropped from the listing. The removed text had claimed all Coldcards are unsafe and urged moving to Seed Signer or Tails and Electrum.

    seen · Captured here 10,228 chars
    What changed from the previous capture 12 lines
     
     comment: p1a0ib2
     parent: t3_1vdge71
    -author: Warrior_witha_Garden
    +author: [deleted]
     created_utc: 1785687410
     edited: false
     body:
    -No it is not safe. ALL the cold cards are cooked ! more is coming out. get a different wallet. You can use Tails and Electrum in a pinch. save that seed. Seed Signer is the move right now. Get some dice and get to work.
    +[removed]
     
     comment: p1aqb2r
     parent: t3_1vdge71
     What else is coming out ?
     
     
    -
    -comment: p1be4h8
    -parent: t1_p1as272
    -author: Warrior_witha_Garden
    -created_utc: 1785700926
    -edited: false
    -body:
    -cold cards are getting bricked with new firmware. other exploits are being found. 1) if you have a usb you can use ian colemans seed generator using tails OS. free and secure. 2) you dont want a cold card for anything at this point. to much risk. if they were this sloppy its a matter of time. save your cold card for lawsuits and civil action. 
     
     comment: p1bmgr9
     parent: t1_p1ar3d9
    
    Extracted text as captured
    post: 1vdge71
    author: UnderstandingNew8001
    created_utc: 1785672404
    title: Is it safe to use MK4 for creation of seed using dice then move, if not what other way?
    body:
    Got my coins out of MK4 on a temp wallet, and I just got my new Trezor, and learning from what happened I am planning to create a new wallet with seeds generated using dice, however it seems Trezor doesn't have that option, and I don't have a device I can have offline to run any program to help, so I am thinking of updating the new firmware of MK4, create a new wallet with Dice, import the seeds into Trezor and add a passphrase, does this make sense? is there any possible issues?
    
    comment: p18q799
    parent: t3_1vdge71
    author: Quirky-Reveal-1669
    created_utc: 1785673127
    edited: 1785678630
    body:
    This is also what I have been contemplating. Mk4 can be kept airgapped, and seed generation according to BIP39, using dice is mathematical, there is no use of the RNG in Mk4. The words generated could then be entered in Trezor.
    
    This is an interesting option, since Trezor cannot function totally airgapped, and Trezor does not offer the option to guide you through seed generation with dice entropy. I am currently skeptical of any RNG, so the option of dice rolls is very appealing.
    
    comment: p18qgxk
    parent: t3_1vdge71
    author: ackyou
    created_utc: 1785673229
    edited: false
    body:
    Yep, that makes sense. You could go the additional step of doing that multiple times with the mk4 and then verify some of those outputs with rolls.py. It’s best not to verify the one you actually use unless it’s on an air-gapped computer. Alternatively, you can generate seed words directly with 8 and 16 sided dice directly with only pen and paper but that’s more of a pain.
    
    comment: p18rqd8
    parent: t3_1vdge71
    author: zootreddit
    created_utc: 1785673706
    edited: false
    body:
    The one issue with CC was seed gen. If you are going to seed gen on mk4 you might as well use the mk4 and send the trezor back for refund.
    
    comment: p18u5yr
    parent: t1_p18rqd8
    author: ackyou
    created_utc: 1785674590
    edited: false
    body:
    The one issue we know about which has been lurking for 5 years. If they messed up seed gen, perhaps the most crucial component, who knows what else is just waiting to be discovered.

    Excerpt only. The complete copy is held offline and backs quotations on this site. The original publication remains the canonical public source.

  2. Earliest copy held
    seen · Captured here 10,905 chars
    Extracted text as captured
    post: 1vdge71
    author: UnderstandingNew8001
    created_utc: 1785672404
    title: Is it safe to use MK4 for creation of seed using dice then move, if not what other way?
    body:
    Got my coins out of MK4 on a temp wallet, and I just got my new Trezor, and learning from what happened I am planning to create a new wallet with seeds generated using dice, however it seems Trezor doesn't have that option, and I don't have a device I can have offline to run any program to help, so I am thinking of updating the new firmware of MK4, create a new wallet with Dice, import the seeds into Trezor and add a passphrase, does this make sense? is there any possible issues?
    
    comment: p18q799
    parent: t3_1vdge71
    author: Quirky-Reveal-1669
    created_utc: 1785673127
    edited: 1785678630
    body:
    This is also what I have been contemplating. Mk4 can be kept airgapped, and seed generation according to BIP39, using dice is mathematical, there is no use of the RNG in Mk4. The words generated could then be entered in Trezor.
    
    This is an interesting option, since Trezor cannot function totally airgapped, and Trezor does not offer the option to guide you through seed generation with dice entropy. I am currently skeptical of any RNG, so the option of dice rolls is very appealing.
    
    comment: p18qgxk
    parent: t3_1vdge71
    author: ackyou
    created_utc: 1785673229
    edited: false
    body:
    Yep, that makes sense. You could go the additional step of doing that multiple times with the mk4 and then verify some of those outputs with rolls.py. It’s best not to verify the one you actually use unless it’s on an air-gapped computer. Alternatively, you can generate seed words directly with 8 and 16 sided dice directly with only pen and paper but that’s more of a pain.
    
    comment: p18rqd8
    parent: t3_1vdge71
    author: zootreddit
    created_utc: 1785673706
    edited: false
    body:
    The one issue with CC was seed gen. If you are going to seed gen on mk4 you might as well use the mk4 and send the trezor back for refund.
    
    comment: p18u5yr
    parent: t1_p18rqd8
    author: ackyou
    created_utc: 1785674590
    edited: false
    body:
    The one issue we know about which has been lurking for 5 years. If they messed up seed gen, perhaps the most crucial component, who knows what else is just waiting to be discovered.

    Excerpt only. The complete copy is held offline and backs quotations on this site. The original publication remains the canonical public source.

How to check this yourself

The excerpts and plain unified diffs above show the text this project held and how it changed. To verify a quotation, compare it against the page itself or against the Internet Archive's copies, which are independent of this project.

Complete captures are held offline rather than mirrored here, so this page shows diffs and excerpts. If a quotation is ever disputed, the full copy can be produced. Ask.