COLDCARD RNG incident the public record, collected and explained
Informational only, and this site never asks for your seed words. details

Informational only. This is an open source collection of what others have published about the incident, together with an explanation of it. It is not financial, security or legal advice, and not a substitute for professional advice about your own situation. It is not affiliated with, endorsed by, or speaking for Coinkite. Material is attributed and quoted as published; where sources disagree their scenarios are kept separate with their assumptions rather than reconciled into one answer. Everything is meant to be checked against the linked evidence rather than taken on trust. Act on your own judgement about a particular situation. Editorial standards and corrections.

Do not disclose recovery material to a website, form, message or support account. This site never asks for it, and contributions containing recovery words or private keys are not accepted.

r/Bitcoin: why open source did not catch the low-entropy seed generation

reddit-open-source-missed-flaw

https://www.reddit.com/r/Bitcoin/comments/1ve5jyc/since_coldcard_is_opensource_why_wasnt_low/

Latest reviewed change

source content difference between and

New comment by Quantris linking a personal gist that converts seed generation to dice rolls, noting their earlier advice to mix in external entropy against hardware RNG weaknesses now looks prescient.

seen +12 -0 full history below
 edited: false
 body:
 Okay, so is Trezor fully open source by every standard of what is meant by that?
+
+comment: p256lp8
+parent: t1_p1etzos
+author: Quantris
+created_utc: 1786051775

First lines only. The complete diff is in the timeline below.

Organisation
reddit
Evidence role
Community discussion
Published
not established
Source changes
2
Detected differences
2
Unreviewed
0
Copies held
3

Every check is recorded, including checks that found no text change. A detected edit is therefore bounded between two checks. The publisher's exact save time is not observable from this record. Last checked .

  1. source content difference between and Current source content +12 -0

    New comment by Quantris linking a personal gist that converts seed generation to dice rolls, noting their earlier advice to mix in external entropy against hardware RNG weaknesses now looks prescient.

    seen · Captured here 27,703 chars
    What changed from the previous capture 12 lines
     edited: false
     body:
     Okay, so is Trezor fully open source by every standard of what is meant by that?
    +
    +comment: p256lp8
    +parent: t1_p1etzos
    +author: Quantris
    +created_utc: 1786051775
    +edited: false
    +body:
    +I did exactly this, and even wrote a script to convert to dice rolls: [https://gist.github.com/Quantris/9143112266dacdd86f1221095e792928](https://gist.github.com/Quantris/9143112266dacdd86f1221095e792928)
    +
    +caveat emptor of course (if someone else posted that, I'd be pretty leery of using it before closely examining it...so my advice is don't use it unless you understand it)
    +
    +edit: also just now rereading what I wrote back then "I do suggest it's worth using it as an additional source of entropy to guard against any potential weaknesses lurking in a hardware RNG (or the software that drives it)"...maybe I should get tested for psychic powers
    
    Extracted text as captured
    post: 1ve5jyc
    author: kevinar990
    created_utc: 1785738893
    title: Since Coldcard is opensource, why wasnt low radndomness od seed generation not found earlier?
    body:
    As a non technical person, honest question.
    
    Since Coldcard is open source, how is it possible noone looked at their seed generation algorithm? Was that not available to the public? Trying to understand, so i can make a better choice of cold wallet in the future
    
    Ty
    
    comment: p1edkin
    parent: t3_1ve5jyc
    author: cilicia3k3
    created_utc: 1785739082
    edited: false
    body:
    It was enough entropy to go under the radar
    
    comment: p1ee49w
    parent: t3_1ve5jyc
    author: PublicBarracuda5311
    created_utc: 1785739354
    edited: false
    body:
    Coldcard was under MIT license if I remember correctly.
    
    comment: p1eey3c
    parent: t3_1ve5jyc
    author: Bred_Slippy
    created_utc: 1785739767
    edited: false
    body:
    It was open for people to view the code, but not open source (others could not use their code for commercial purposes). This move away from true open source led them to change the code in a way that introduced the bug.
    
    After they moved away from it being true OS, there wasn't much incentive for people to scrutinise the code as it couldn't be used by others for their own products /services. This could well be a key reason why the bug wasn't found/exploited for over 5 years. 
    
    comment: p1ef2bt
    parent: t3_1ve5jyc
    author: garlicChaser

    Excerpt only. The complete copy is held offline and backs quotations on this site. The original publication remains the canonical public source.

  2. source content difference between and source content +12 -16

    A comment by IllllIIlIllIllllIlll recommending 48 dice rolls and 12 coin flips with BitBox diceware PDFs now shows as [deleted], a second comment by the same author dropped from the listing, and a new comment by aaj094 asks whether Trezor counts as fully open source.

    seen · Captured here 26,956 chars
    What changed from the previous capture 28 lines
     
     comment: p1ezucw
     parent: t1_p1ekxtr
    -author: IllllIIlIllIllllIlll
    +author: [deleted]
     created_utc: 1785750319
    -edited: false
    -body:
    -You don't need so many rolls 48 dice rolls and 12 coin flips are enough
    -
    -[https://bitbox.swiss/bitbox02/BitBox\_Diceware\_HowTo.pdf](https://bitbox.swiss/bitbox02/BitBox_Diceware_HowTo.pdf)
    -
    -[https://bitbox.swiss/bitbox02/BitBox\_Diceware\_LookupTable.pdf](https://bitbox.swiss/bitbox02/BitBox_Diceware_LookupTable.pdf)
    +edited: 1786028087
    +body:
    +[deleted]
     
     comment: p1f5cdb
     parent: t1_p1ezucw
     
     We need to get at least random seed generation into our own hands !
     
    -comment: p1f6cy2
    -parent: t1_p1f5cdb
    -author: IllllIIlIllIllllIlll
    -created_utc: 1785753345
    -edited: false
    -body:
    -It would be completely useless but you do you
    -
     comment: p1f6kdb
     parent: t1_p1eimhe
     author: oaga_strizzi
     edited: false
     body:
     I’d guess it was a Mythos/Fable or Astra model find, and we should expect a lot more in the coming months.
    +
    +comment: p237jdf
    +parent: t1_p1hyz3w
    +author: aaj094
    +created_utc: 1786033707
    +edited: false
    +body:
    +Okay, so is Trezor fully open source by every standard of what is meant by that?
    
    Extracted text as captured
    post: 1ve5jyc
    author: kevinar990
    created_utc: 1785738893
    title: Since Coldcard is opensource, why wasnt low radndomness od seed generation not found earlier?
    body:
    As a non technical person, honest question.
    
    Since Coldcard is open source, how is it possible noone looked at their seed generation algorithm? Was that not available to the public? Trying to understand, so i can make a better choice of cold wallet in the future
    
    Ty
    
    comment: p1edkin
    parent: t3_1ve5jyc
    author: cilicia3k3
    created_utc: 1785739082
    edited: false
    body:
    It was enough entropy to go under the radar
    
    comment: p1ee49w
    parent: t3_1ve5jyc
    author: PublicBarracuda5311
    created_utc: 1785739354
    edited: false
    body:
    Coldcard was under MIT license if I remember correctly.
    
    comment: p1eey3c
    parent: t3_1ve5jyc
    author: Bred_Slippy
    created_utc: 1785739767
    edited: false
    body:
    It was open for people to view the code, but not open source (others could not use their code for commercial purposes). This move away from true open source led them to change the code in a way that introduced the bug.
    
    After they moved away from it being true OS, there wasn't much incentive for people to scrutinise the code as it couldn't be used by others for their own products /services. This could well be a key reason why the bug wasn't found/exploited for over 5 years. 
    
    comment: p1ef2bt
    parent: t3_1ve5jyc
    author: garlicChaser

    Excerpt only. The complete copy is held offline and backs quotations on this site. The original publication remains the canonical public source.

  3. Earliest copy held
    seen · Captured here 27,251 chars
    Extracted text as captured
    post: 1ve5jyc
    author: kevinar990
    created_utc: 1785738893
    title: Since Coldcard is opensource, why wasnt low radndomness od seed generation not found earlier?
    body:
    As a non technical person, honest question.
    
    Since Coldcard is open source, how is it possible noone looked at their seed generation algorithm? Was that not available to the public? Trying to understand, so i can make a better choice of cold wallet in the future
    
    Ty
    
    comment: p1edkin
    parent: t3_1ve5jyc
    author: cilicia3k3
    created_utc: 1785739082
    edited: false
    body:
    It was enough entropy to go under the radar
    
    comment: p1ee49w
    parent: t3_1ve5jyc
    author: PublicBarracuda5311
    created_utc: 1785739354
    edited: false
    body:
    Coldcard was under MIT license if I remember correctly.
    
    comment: p1eey3c
    parent: t3_1ve5jyc
    author: Bred_Slippy
    created_utc: 1785739767
    edited: false
    body:
    It was open for people to view the code, but not open source (others could not use their code for commercial purposes). This move away from true open source led them to change the code in a way that introduced the bug.
    
    After they moved away from it being true OS, there wasn't much incentive for people to scrutinise the code as it couldn't be used by others for their own products /services. This could well be a key reason why the bug wasn't found/exploited for over 5 years. 
    
    comment: p1ef2bt
    parent: t3_1ve5jyc
    author: garlicChaser

    Excerpt only. The complete copy is held offline and backs quotations on this site. The original publication remains the canonical public source.

How to check this yourself

The excerpts and plain unified diffs above show the text this project held and how it changed. To verify a quotation, compare it against the page itself or against the Internet Archive's copies, which are independent of this project.

Complete captures are held offline rather than mirrored here, so this page shows diffs and excerpts. If a quotation is ever disputed, the full copy can be produced. Ask.