COLDCARD RNG incident the public record, collected and explained
Informational only, and this site never asks for your seed words. details

Informational only. This is an open source collection of what others have published about the incident, together with an explanation of it. It is not financial, security or legal advice, and not a substitute for professional advice about your own situation. It is not affiliated with, endorsed by, or speaking for Coinkite. Material is attributed and quoted as published; where sources disagree their scenarios are kept separate with their assumptions rather than reconciled into one answer. Everything is meant to be checked against the linked evidence rather than taken on trust. Act on your own judgement about a particular situation. Editorial standards and corrections.

Do not disclose recovery material to a website, form, message or support account. This site never asks for it, and contributions containing recovery words or private keys are not accepted.

r/coldcard: whether a 25th word passphrase protects Mk3 users

reddit-passphrase-save-mk3

https://www.reddit.com/r/coldcard/comments/1vcpdux/will_having_a_25th_word_passphrase_save_mk3_users/

Organisation
reddit
Evidence role
Community discussion
Published
not established
Source changes
0
Detected differences
0
Unreviewed
0
Copies held
1

Every check is recorded, including checks that found no text change. A detected edit is therefore bounded between two checks. The publisher's exact save time is not observable from this record. Last checked .

  1. Earliest copy held Current
    seen · Captured here 11,394 chars
    Extracted text as captured
    post: 1vcpdux
    author: bje332013
    created_utc: 1785595816
    title: Will having a '25th word' / passphrase save MK3 users?
    body:
    It was recently announced that Coldcard users who trusted the device's random number generator to generate their seed phrase ended up with seed phrases that are non-random enough that hackers could predict them and drain the wallets of Coldcard users.
    
    This is VERY similar to the very recent fiasco re: the SecondFi desktop wallet software for Cardano. That's because, in both cases, the problem had to do with random number generation being too predictable.
    
    So here's my question: **If a user** relies on a random number generator that is faulty, but **adds a 25th word / passphrase to the not-so random seed phrase, is that wallet still unsafe** or at risk of being drained?
    
    comment: p12ylwm
    parent: t3_1vcpdux
    author: bitusher
    created_utc: 1785596945
    edited: false
    body:
    > but adds a 25th word / passphrase to the not-so random seed phrase, is that wallet still unsafe 
    
    This is a horrible term Ledger started marketing which confuses many new users into believing the 25th word passphrase is a single word. 
    
    
    Passphrases = **multiple** words , passwords = often single words+extra characters, pins = small set of numbers  
    
    The extended passphrase should be at least 6-8 random words at minimum to be secure.
    
    There is another problem here with that term as well, it insinuates that users should keep the extended passphrase backed up with the existing 24 seed words because its simply another "word" needed to recover the wallet along with the other words (12 to 24) which is incorrect. The extended passphrase would be backed up but kept separately from the 12 to 24 word backup seed.
    
    Also there is a third problem with that term as it insinuates that there are only 24 word seed backups and the extended passphrase is the "25th word" which is also wrong. Seed word backups can be 12, 15, 18, 20, 21, or 24 , with 12 being the most common.
    
    You are safe temporarily as long as your passphrase is not weak or a "25th word" but should still eventually migrate over to a new seed regardless.
    
    comment: p134kza
    parent: t3_1vcpdux
    author: stay_safe_and_calm
    created_utc: 1785598691
    edited: false
    body:
    The entropy of the additional passphrase must be really high to be safe!!! That means at least 20 random characters upper and lower cases, numbers and even special characters if you want. Just choosing 2 or 3 normal words is not enough because the human languge has only about 12,000 unique words which is a really low entropy ! But keep in mind that the risk is always that you forget this passphrase and then you are screwed. So please(!) write down your passphrase at least three times on different pieces of paper and do at least two small test transactions of receiving and spending before sending large amounts to it!!! You should also write down the fingerprint of this passphrase wallet. You could also  create 3 different wallets with three different passphrases in order to spread the risk that one of them gets hacked. ... But then you have to keep 3 passphrases and the (comprromise) seed.
    

    Excerpt only. The complete copy is held offline and backs quotations on this site. The original publication remains the canonical public source.

How to check this yourself

The excerpts and plain unified diffs above show the text this project held and how it changed. To verify a quotation, compare it against the page itself or against the Internet Archive's copies, which are independent of this project.

Complete captures are held offline rather than mirrored here, so this page shows diffs and excerpts. If a quotation is ever disputed, the full copy can be produced. Ask.