COLDCARD RNG incident the public record, collected and explained
Informational only, and this site never asks for your seed words. details

Informational only. This is an open source collection of what others have published about the incident, together with an explanation of it. It is not financial, security or legal advice, and not a substitute for professional advice about your own situation. It is not affiliated with, endorsed by, or speaking for Coinkite. Material is attributed and quoted as published; where sources disagree their scenarios are kept separate with their assumptions rather than reconciled into one answer. Everything is meant to be checked against the linked evidence rather than taken on trust. Act on your own judgement about a particular situation. Editorial standards and corrections.

Do not disclose recovery material to a website, form, message or support account. This site never asks for it, and contributions containing recovery words or private keys are not accepted.

r/Bitcoin: multisig versus single-sig with passphrase after the Coldcard issue

reddit-multisig-passphrase-debate

https://www.reddit.com/r/Bitcoin/comments/1vhv4j0/following_the_coldcard_issue_still_debating/

Organisation
reddit
Evidence role
Community discussion
Published
not established
Source changes
0
Detected differences
0
Unreviewed
0
Copies held
1

Every check is recorded, including checks that found no text change. A detected edit is therefore bounded between two checks. The publisher's exact save time is not observable from this record. Last checked .

  1. Earliest copy held Current
    seen · Captured here 19,058 chars
    Extracted text as captured
    post: 1vhv4j0
    author: lightbulb-7
    created_utc: 1786092427
    title: Following the Coldcard issue: still debating between multi sig & single sig + passphrase
    body:
    I have my life savings under a single sig.
    
    Thank God the HWW I used to generate the seed was not a Coldcard, but it could have been. I dodged the bullet out of pure luck.
    
    Now that I'm concerned about (a) how security will get increasingly difficult as AI progresses, and (b) how much of a risk it is to rely on a single provider to generate the secret to your savings, I'm preparing to upgrade my setup.
    
    As much as I read (basically on Nostr, which is the only thing I use) that *multi vendor, multi sig, with seeds generated through dice-rolling* is the way to go, I have some questions / concerns about that.
    
    Posting them here to get clarification:
    
    * Regarding storage / secret-keeping: Isn't multisig, for the average Joe, like 3x more complicated than single sig + passphrase? AFAIK you need to hide the 3 seed phrases + the wallet configuration file + two signing devices on different locations. Thinking about a security setup for say, 30 years, this comes with a huge risk (and cost). Especially if I should unexpectedly die sooner, 100% my wife would not be able to put all the pieces together
    * Regarding dice-rolling: Who gives you certainty that, rolling a dice, you actually increase the entropy with respect to the seed that is generated by a FOOS of a trusted wallet that has been successfully doing that for years (say Trezor, Sparrow, BlueWallet, Jade, etc)? I mean, not only the manufacturing of the dice can never be 100% pure and homogeneous, but also the movements that one do with the hand, the height at which one throws the dice, etc, are always constant. Don't tell me that's pure random. The dice advice, without being a technical person, doesn't sound that great to me
    * Regarding privacy: doesn't a multi sig transaction always disclose the xpub or something like that? (Sorry I might have this detail wrong). Should that be the case, isn't having multi sig a HUGE privacy concern (especially for those who use multi sig to store their life savings)? I'm not sure if this alone would be a no-go for me, should it be true
    * Regarding the passphrase: what I always read, is that the passphrase is akin to the 25th word, and that it can be any combination of numbers, letters, signs, even spaces. What is new to me, is that the recent recommendations I keep reading is that passphrases should actually be a 4 to 6 random combination of words from the BIP-39 list. I get that (because of the entropy), but isn't the point of a passphrase to be something that *doesn't look like a passphrase* (in case someone sees/finds it), or that is so embedded in our minds, that there is no need to store it physically?
       * I'm having a hard time with this one, because for what I've read in some forums, it's not necessarily about the number of bits of the said passphrase, but rather about its randomness (which is a proxy to difficulty to brute-force). So apparently some combination of e.g. \[music band name + telephone number\], just to give an example, might have a high number of bips (so one would think that it is almost impossible to guess), but the *structure* of the passphrase has almost no randomness at all (so it could take just minutes to guess). I guess I'm asking what type of passphrase do you guys recommend, weighing simplicity of storage + entropy
    * Edit, additional question: regarding hardware wallets, for any possibility of the both above (multi sig or single sig with passphrase), which HWW would you recommend, and most importantly why?
    
    Thanks in advance for any insights
    
    comment: p289rtx
    parent: t3_1vhv4j0
    author: Narrow_Entrance_3169
    created_utc: 1786092954
    edited: false
    body:
    you can overthink this into paralysis pretty quick
    
      
    dice rolls are fine. the bias on a cheap casino die is so small it doesn't matter for this use case, and your hand movements aren't nearly as predictable as you think. the point is removing trust from one piece of hardware or one software rng. it's not about perfect entropy it's about not having a single point of failure
    
      
    for the passphrase question you're mixing up two different things. a passphrase made of 4-6 bip39 words is strong because it's high entropy and you can write it down. the "doesn't look like a passphrase" idea made more sense when people were hiding a single word behind a painting or whatever but for actual security you want the bits. a music band name plus phone number is human-memorable but the structure is weak, and if someone gets your seed the passphrase is all that's standing between them and your coins. make it strong
    
      
    multisig is more work and your wife point is real. most people with a family situation should keep it simple enough that one non-technical person can recover it. single sig with strong passphrase and a metal backup in two locations beats a multisig setup nobody can reconstruct

    Excerpt only. The complete copy is held offline and backs quotations on this site. The original publication remains the canonical public source.

How to check this yourself

The excerpts and plain unified diffs above show the text this project held and how it changed. To verify a quotation, compare it against the page itself or against the Internet Archive's copies, which are independent of this project.

Complete captures are held offline rather than mirrored here, so this page shows diffs and excerpts. If a quotation is ever disputed, the full copy can be produced. Ask.