COLDCARD RNG incident the public record, collected and explained
Informational only, and this site never asks for your seed words. details

Informational only. This is an open source collection of what others have published about the incident, together with an explanation of it. It is not financial, security or legal advice, and not a substitute for professional advice about your own situation. It is not affiliated with, endorsed by, or speaking for Coinkite. Material is attributed and quoted as published; where sources disagree their scenarios are kept separate with their assumptions rather than reconciled into one answer. Everything is meant to be checked against the linked evidence rather than taken on trust. Act on your own judgement about a particular situation. Editorial standards and corrections.

Do not disclose recovery material to a website, form, message or support account. This site never asks for it, and contributions containing recovery words or private keys are not accepted.

r/coldcard: asking whether another wallet could randomly produce an affected Coldcard key

reddit-randomness-collision-question

https://www.reddit.com/r/coldcard/comments/1vlbpxf/randomness_in_bitcoin_and_other_wallets/

Latest reviewed change

source content difference between and

The thread gained two new replies: phoebeethical asked whether a passphrase can produce the same master password as a different seed, and logan-807128 confirmed the wording and explained that a passphrase effectively acts as an additional seed word.

seen +22 -0 full history below
 160 bits = comparable to atoms in Earth's moon
 
 Spoiler alert, with traditional computing we will never find a collision that corresponds with a specific 160bit bitcoin address. Practically impossible. So to answer the OPs question, it is practically impossible for a proper RNG function to create one of the hacked cold-card PRNG deterministic wallets. It is THEORETICALLY possible, but it will never happen.
+
+comment: p3mstg0
+parent: t1_p32cujo
+author: phoebeethical
+created_utc: 1786709621

First lines only. The complete diff is in the timeline below.

Organisation
reddit
Evidence role
Community discussion
Published
not established
Source changes
1
Detected differences
1
Unreviewed
0
Copies held
2

Every check is recorded, including checks that found no text change. A detected edit is therefore bounded between two checks. The publisher's exact save time is not observable from this record. Last checked .

  1. source content difference between and Current source content +22 -0

    The thread gained two new replies: phoebeethical asked whether a passphrase can produce the same master password as a different seed, and logan-807128 confirmed the wording and explained that a passphrase effectively acts as an additional seed word.

    seen · Captured here 5,197 chars
    What changed from the previous capture 22 lines
     160 bits = comparable to atoms in Earth's moon
     
     Spoiler alert, with traditional computing we will never find a collision that corresponds with a specific 160bit bitcoin address. Practically impossible. So to answer the OPs question, it is practically impossible for a proper RNG function to create one of the hacked cold-card PRNG deterministic wallets. It is THEORETICALLY possible, but it will never happen.
    +
    +comment: p3mstg0
    +parent: t1_p32cujo
    +author: phoebeethical
    +created_utc: 1786709621
    +edited: false
    +body:
    +So a passphrase can convert a master password to the identical master password generated with a different set of words?  
    +
    +comment: p3ngkn5
    +parent: t1_p3mstg0
    +author: logan-807128
    +created_utc: 1786716648
    +edited: false
    +body:
    +I know what you mean although there is a technical difference in your wording, what you said is correct.
    +
    +Say you used the seed words "hello world blah ... ", it would create the private key 1747293... (a super big number). Once you add a passphrase, the private key would now become a completely different number say 4827282..., there exists another seed words "somewhere out there..." without passphrase that would generate the exact same private key 4827282...
    +
    +There is a reason why some people call the passphrase the 13th word (12 word seed) or 25th word (24 word seed) because in many ways that's more correct than thinking the passphrase as password for your seed words. 
    +
    +
    
    Extracted text as captured
    post: 1vlbpxf
    author: Few_Tea_8183
    created_utc: 1786437295
    title: Randomness in Bitcoin and Other Wallets
    body:
    Has anyone already calculated the probability that a properly functioning wallet would randomly assign one of the affected Coldcard keys?
    
    comment: p300onr
    parent: t3_1vlbpxf
    author: Mission-Disaster-447
    created_utc: 1786437660
    edited: false
    body:
    Yes. Its very small. It would be like two people randomly picking the same atom in the visible universe.
    
    comment: p301uwp
    parent: t3_1vlbpxf
    author: EricJDMBAMD
    created_utc: 1786438259
    edited: false
    body:
    I think the MK3 Coldcards before the new firmware were giving users a seed phrase out of 4 billion. With the new firmware its about 2.8 x 10^77.  That's 6.5 x 10^67 times more possible seeds after the firmware update.
    
    comment: p30led2
    parent: t1_p300onr
    author: Few_Tea_8183
    created_utc: 1786447153
    edited: false
    body:
    thank you both for your information.
    
    comment: p316d1y
    parent: t3_1vlbpxf
    author: Charming-Designer944
    created_utc: 1786454157
    edited: false
    body:
    Approximately 1/(2^(128-40)) i think for 12 word seeds. But i have not counted the exact bits.
    
    comment: p326dcf

    Excerpt only. The complete copy is held offline and backs quotations on this site. The original publication remains the canonical public source.

  2. Earliest copy held
    seen · Captured here 4,188 chars
    Extracted text as captured
    post: 1vlbpxf
    author: Few_Tea_8183
    created_utc: 1786437295
    title: Randomness in Bitcoin and Other Wallets
    body:
    Has anyone already calculated the probability that a properly functioning wallet would randomly assign one of the affected Coldcard keys?
    
    comment: p300onr
    parent: t3_1vlbpxf
    author: Mission-Disaster-447
    created_utc: 1786437660
    edited: false
    body:
    Yes. Its very small. It would be like two people randomly picking the same atom in the visible universe.
    
    comment: p301uwp
    parent: t3_1vlbpxf
    author: EricJDMBAMD
    created_utc: 1786438259
    edited: false
    body:
    I think the MK3 Coldcards before the new firmware were giving users a seed phrase out of 4 billion. With the new firmware its about 2.8 x 10^77.  That's 6.5 x 10^67 times more possible seeds after the firmware update.
    
    comment: p30led2
    parent: t1_p300onr
    author: Few_Tea_8183
    created_utc: 1786447153
    edited: false
    body:
    thank you both for your information.
    
    comment: p316d1y
    parent: t3_1vlbpxf
    author: Charming-Designer944
    created_utc: 1786454157
    edited: false
    body:
    Approximately 1/(2^(128-40)) i think for 12 word seeds. But i have not counted the exact bits.
    
    comment: p326dcf

    Excerpt only. The complete copy is held offline and backs quotations on this site. The original publication remains the canonical public source.

How to check this yourself

The excerpts and plain unified diffs above show the text this project held and how it changed. To verify a quotation, compare it against the page itself or against the Internet Archive's copies, which are independent of this project.

Complete captures are held offline rather than mirrored here, so this page shows diffs and excerpts. If a quotation is ever disputed, the full copy can be produced. Ask.