COLDCARD RNG incident the public record, collected and explained
Informational only, and this site never asks for your seed words. details

Informational only. This is an open source collection of what others have published about the incident, together with an explanation of it. It is not financial, security or legal advice, and not a substitute for professional advice about your own situation. It is not affiliated with, endorsed by, or speaking for Coinkite. Material is attributed and quoted as published; where sources disagree their scenarios are kept separate with their assumptions rather than reconciled into one answer. Everything is meant to be checked against the linked evidence rather than taken on trust. Act on your own judgement about a particular situation. Editorial standards and corrections.

Do not disclose recovery material to a website, form, message or support account. This site never asks for it, and contributions containing recovery words or private keys are not accepted.

r/Bitcoin: 2021 COLDCARD post joking about a 'retirement attack' resurfaced

reddit-retirement-attack-resurfaced

https://www.reddit.com/r/Bitcoin/comments/1vf0ut0/coldcard_post_from_october_10_2021_retirement/

Latest reviewed change

source content difference between and

Reddit served 2 additional comment record(s); the diff preserves their text and any edits to existing records.

seen +20 -0 full history below
 body:
 It's the same as old days replay attack, where they could relay the same tx to another forked network, but who has the motivation to do it? The one that shouted the concept the most: Exchanges, since only they have the possibility to profit from it (The users wallet private key are in their possession)
 
+comment: p21u71g
+parent: t1_p1lqied
+author: Chance_Wafer9600
+created_utc: 1786020608
+edited: false

First lines only. The complete diff is in the timeline below.

Organisation
reddit
Evidence role
Community discussion
Published
not established
Source changes
26
Detected differences
26
Unreviewed
0
Copies held
27

Every check is recorded, including checks that found no text change. A detected edit is therefore bounded between two checks. The publisher's exact save time is not observable from this record. Last checked .

  1. source content difference between and Current source content +20 -0

    Reddit served 2 additional comment record(s); the diff preserves their text and any edits to existing records.

    seen · Captured here 23,371 chars
    What changed from the previous capture 20 lines
     body:
     It's the same as old days replay attack, where they could relay the same tx to another forked network, but who has the motivation to do it? The one that shouted the concept the most: Exchanges, since only they have the possibility to profit from it (The users wallet private key are in their possession)
     
    +comment: p21u71g
    +parent: t1_p1lqied
    +author: Chance_Wafer9600
    +created_utc: 1786020608
    +edited: false
    +body:
    +Can I ask a question to you, as you're being so open? Do you think you have a 'normal' range of emotions and emotional function, and would you consider yourself neurotypical? 
    +
    +Not casting any shade but would love to hear someone self-confessed's take on this. 
    +
    +comment: p22ve5y
    +parent: t1_p21u71g
    +author: Turbulent-Rub3695
    +created_utc: 1786030664
    +edited: false
    +body:
    +No, I don't have a 'normal' range of emotions imo, and I'm pretty sure I'm neurodivergant, aka Asperger's syndrome or similar.  I struggle to pick up on lots of social cues, either body language or tone or situational context.   
    +
    +I also feel like I have the emotional depth of a parking lot puddle.  
    +
     more-stub: parent t1_p1z5n4f count <live-count>
    
    Extracted text as captured
    post: 1vf0ut0
    author: Fearless-Second-7230
    created_utc: 1785820076
    title: Coldcard post from October 10, 2021: "Retirement Attack"
    body:
    \- "What's a retirement attack?"
    
    \- COLDCARD (@COLDCARDwallet): "It's when the project makers could have a "bug" in the entropy generation for later retrieval".
    
    \_\_\_\_\_
    
    Seems that they were smart enough to launch a "dice rolls" suggestion in a critical element lacking foolproof design, knowing not all users would be paranoid enough. Like "hey, if you don't trust no problem, but...you can trust buddy, the (back)door is open." ☠️
    
    Ok no, enough of conspiracy theory continuation. We know that Coldcard's post was pure coincidence. Right?...Right? 
    
    -----
    Edit: In case you're curious on more tweets mentioning "retirement attack", here is another one: 
    
    
    @nvk - 21 Dec 20: "My money is on people screwing themselves out of their BTC before any vendor tries a retirement attack.
    
    Alternatively people could just use dice ;)."
    
    https://x.com/i/status/1341213389549412353
    
    -----
    
    A strange way to warn "alternatively people" of what you have in mind to do...but Freudian slip or parapraxis theory explains that better, in case you're curious...
    
    comment: p1lcjaa
    parent: t3_1vf0ut0
    author: VictorDanville
    created_utc: 1785820367
    edited: false
    body:
    Wow, so this really was an inside job
    
    comment: p1lcq9n
    parent: t3_1vf0ut0
    author: fuckswithboats

    Excerpt only. The complete copy is held offline and backs quotations on this site. The original publication remains the canonical public source.

  2. source content difference between and source content +3 -3

    Fields within an existing Reddit post or comment changed; the diff preserves the exact served text.

    seen · Captured here 22,594 chars
    What changed from the previous capture 6 lines
     parent: t1_p1mxiiw
     author: bricksplus
     created_utc: 1785847901
    -edited: false
    -body:
    -You put trust in the institution that’s being doing high level research for decades 
    +edited: 1785988016
    +body:
    +You put trust in the institution that’s doing high level research for decades
     
     comment: p1n3t4c
     parent: t3_1vf0ut0
    
    Extracted text as captured
    post: 1vf0ut0
    author: Fearless-Second-7230
    created_utc: 1785820076
    title: Coldcard post from October 10, 2021: "Retirement Attack"
    body:
    \- "What's a retirement attack?"
    
    \- COLDCARD (@COLDCARDwallet): "It's when the project makers could have a "bug" in the entropy generation for later retrieval".
    
    \_\_\_\_\_
    
    Seems that they were smart enough to launch a "dice rolls" suggestion in a critical element lacking foolproof design, knowing not all users would be paranoid enough. Like "hey, if you don't trust no problem, but...you can trust buddy, the (back)door is open." ☠️
    
    Ok no, enough of conspiracy theory continuation. We know that Coldcard's post was pure coincidence. Right?...Right? 
    
    -----
    Edit: In case you're curious on more tweets mentioning "retirement attack", here is another one: 
    
    
    @nvk - 21 Dec 20: "My money is on people screwing themselves out of their BTC before any vendor tries a retirement attack.
    
    Alternatively people could just use dice ;)."
    
    https://x.com/i/status/1341213389549412353
    
    -----
    
    A strange way to warn "alternatively people" of what you have in mind to do...but Freudian slip or parapraxis theory explains that better, in case you're curious...
    
    comment: p1lcjaa
    parent: t3_1vf0ut0
    author: VictorDanville
    created_utc: 1785820367
    edited: false
    body:
    Wow, so this really was an inside job
    
    comment: p1lcq9n
    parent: t3_1vf0ut0
    author: fuckswithboats

    Excerpt only. The complete copy is held offline and backs quotations on this site. The original publication remains the canonical public source.

  3. source content difference between and source content +18 -0

    Reddit served 2 additional comment record(s); the diff preserves their text and any edits to existing records.

    seen · Captured here 22,596 chars
    What changed from the previous capture 18 lines
     edited: false
     body:
     Turns out a decentralised, anonymous system with no retrieval options is vulnerable to attacks from thieves, charlatans and the like. Who would have thought?
    +
    +comment: p1z5n4f
    +parent: t1_p1m7mss
    +author: ContentBlackberry0
    +created_utc: 1785980678
    +edited: false
    +body:
    +Why only do drugs on the weekend
    +
    +comment: p1z6hth
    +parent: t1_p1mw7dg
    +author: vattenj
    +created_utc: 1785980953
    +edited: false
    +body:
    +It's the same as old days replay attack, where they could relay the same tx to another forked network, but who has the motivation to do it? The one that shouted the concept the most: Exchanges, since only they have the possibility to profit from it (The users wallet private key are in their possession)
    +
    +more-stub: parent t1_p1z5n4f count <live-count>
    
    Extracted text as captured
    post: 1vf0ut0
    author: Fearless-Second-7230
    created_utc: 1785820076
    title: Coldcard post from October 10, 2021: "Retirement Attack"
    body:
    \- "What's a retirement attack?"
    
    \- COLDCARD (@COLDCARDwallet): "It's when the project makers could have a "bug" in the entropy generation for later retrieval".
    
    \_\_\_\_\_
    
    Seems that they were smart enough to launch a "dice rolls" suggestion in a critical element lacking foolproof design, knowing not all users would be paranoid enough. Like "hey, if you don't trust no problem, but...you can trust buddy, the (back)door is open." ☠️
    
    Ok no, enough of conspiracy theory continuation. We know that Coldcard's post was pure coincidence. Right?...Right? 
    
    -----
    Edit: In case you're curious on more tweets mentioning "retirement attack", here is another one: 
    
    
    @nvk - 21 Dec 20: "My money is on people screwing themselves out of their BTC before any vendor tries a retirement attack.
    
    Alternatively people could just use dice ;)."
    
    https://x.com/i/status/1341213389549412353
    
    -----
    
    A strange way to warn "alternatively people" of what you have in mind to do...but Freudian slip or parapraxis theory explains that better, in case you're curious...
    
    comment: p1lcjaa
    parent: t3_1vf0ut0
    author: VictorDanville
    created_utc: 1785820367
    edited: false
    body:
    Wow, so this really was an inside job
    
    comment: p1lcq9n
    parent: t3_1vf0ut0
    author: fuckswithboats

    Excerpt only. The complete copy is held offline and backs quotations on this site. The original publication remains the canonical public source.

  4. source content difference between and source content +8 -0

    Reddit served 1 additional comment record(s); the diff preserves their text and any edits to existing records.

    seen · Captured here 22,016 chars
    What changed from the previous capture 8 lines
     
     We're at the edge of a cliff with AI.   I feel like there will be an economic crash to consolidate power than the AI goes into full effect.
     
    +
    +comment: p1tvkge
    +parent: t1_p1oeed3
    +author: LonelyTAA
    +created_utc: 1785926493
    +edited: false
    +body:
    +Turns out a decentralised, anonymous system with no retrieval options is vulnerable to attacks from thieves, charlatans and the like. Who would have thought?
    
    Extracted text as captured
    post: 1vf0ut0
    author: Fearless-Second-7230
    created_utc: 1785820076
    title: Coldcard post from October 10, 2021: "Retirement Attack"
    body:
    \- "What's a retirement attack?"
    
    \- COLDCARD (@COLDCARDwallet): "It's when the project makers could have a "bug" in the entropy generation for later retrieval".
    
    \_\_\_\_\_
    
    Seems that they were smart enough to launch a "dice rolls" suggestion in a critical element lacking foolproof design, knowing not all users would be paranoid enough. Like "hey, if you don't trust no problem, but...you can trust buddy, the (back)door is open." ☠️
    
    Ok no, enough of conspiracy theory continuation. We know that Coldcard's post was pure coincidence. Right?...Right? 
    
    -----
    Edit: In case you're curious on more tweets mentioning "retirement attack", here is another one: 
    
    
    @nvk - 21 Dec 20: "My money is on people screwing themselves out of their BTC before any vendor tries a retirement attack.
    
    Alternatively people could just use dice ;)."
    
    https://x.com/i/status/1341213389549412353
    
    -----
    
    A strange way to warn "alternatively people" of what you have in mind to do...but Freudian slip or parapraxis theory explains that better, in case you're curious...
    
    comment: p1lcjaa
    parent: t3_1vf0ut0
    author: VictorDanville
    created_utc: 1785820367
    edited: false
    body:
    Wow, so this really was an inside job
    
    comment: p1lcq9n
    parent: t3_1vf0ut0
    author: fuckswithboats

    Excerpt only. The complete copy is held offline and backs quotations on this site. The original publication remains the canonical public source.

  5. source content difference between and source content +55 -0

    Reddit served 6 additional comment record(s); the diff preserves their text and any edits to existing records.

    seen · Captured here 21,759 chars
    What changed from the previous capture 55 lines
     edited: false
     body:
     What I meant was entering a wrong input, like 5 instead of 4. But to think about it, a few of such “fat fingering” inputs do not really matter
    +
    +comment: p1s1def
    +parent: t1_p1rrf8s
    +author: Deto
    +created_utc: 1785897423
    +edited: false
    +body:
    +Just adds entropy, I guess!
    +
    +(Probably slight reduction really)
    +
    +comment: p1s2sho
    +parent: t1_p1s1def
    +author: Adventurous_Iron_551
    +created_utc: 1785897906
    +edited: false
    +body:
    +Yeah, it does add entropy, just like any of the 200 factors like throwing the dice a bit far, at an angle, at a different speed - as long as there isn’t a pattern or a way in which it could be repeated. 
    +
    +comment: p1s37m2
    +parent: t3_1vf0ut0
    +author: Mobo24
    +created_utc: 1785898048
    +edited: false
    +body:
    +👀👀👀
    +
    +comment: p1s3tis
    +parent: t1_p1lkk63
    +author: spisplatta
    +created_utc: 1785898259
    +edited: false
    +body:
    +Can't help but think of those AI companies saying outright they are gonna fuck the world up.
    +
    +comment: p1s5nhs
    +parent: t1_p1s2sho
    +author: Deto
    +created_utc: 1785898902
    +edited: false
    +body:
    +Not really.  If the dice is unweighted then the probability distribution function should be basically flat across all 6 outcomes.  That's maximal entropy for dice rolls - you can't mathematically do better.  Fat fingering, on the other hand, probably has some asymmetry due to where the buttons are relative to the screen and your thumbs.  So the result of finger errors would make the probability distribution deviate from the ideal flat distribution and reduce the entropy as a result.
    +
    +In practice does this matter? Probably not as it's probably a very small effect.  Maybe you lose a bit or two. 
    +
    +comment: p1sgbq1
    +parent: t1_p1s3tis
    +author: Turbulent-Rub3695
    +created_utc: 1785902889
    +edited: false
    +body:
    +Dig out a copy of the Bible and read the last book.  Revelation is short, but it's a doozy.  Anyways, were doing that NOW.
    +
    +We're at the edge of a cliff with AI.   I feel like there will be an economic crash to consolidate power than the AI goes into full effect.
    +
    
    Extracted text as captured
    post: 1vf0ut0
    author: Fearless-Second-7230
    created_utc: 1785820076
    title: Coldcard post from October 10, 2021: "Retirement Attack"
    body:
    \- "What's a retirement attack?"
    
    \- COLDCARD (@COLDCARDwallet): "It's when the project makers could have a "bug" in the entropy generation for later retrieval".
    
    \_\_\_\_\_
    
    Seems that they were smart enough to launch a "dice rolls" suggestion in a critical element lacking foolproof design, knowing not all users would be paranoid enough. Like "hey, if you don't trust no problem, but...you can trust buddy, the (back)door is open." ☠️
    
    Ok no, enough of conspiracy theory continuation. We know that Coldcard's post was pure coincidence. Right?...Right? 
    
    -----
    Edit: In case you're curious on more tweets mentioning "retirement attack", here is another one: 
    
    
    @nvk - 21 Dec 20: "My money is on people screwing themselves out of their BTC before any vendor tries a retirement attack.
    
    Alternatively people could just use dice ;)."
    
    https://x.com/i/status/1341213389549412353
    
    -----
    
    A strange way to warn "alternatively people" of what you have in mind to do...but Freudian slip or parapraxis theory explains that better, in case you're curious...
    
    comment: p1lcjaa
    parent: t3_1vf0ut0
    author: VictorDanville
    created_utc: 1785820367
    edited: false
    body:
    Wow, so this really was an inside job
    
    comment: p1lcq9n
    parent: t3_1vf0ut0
    author: fuckswithboats

    Excerpt only. The complete copy is held offline and backs quotations on this site. The original publication remains the canonical public source.

  6. source content difference between and source content +16 -0

    The Reddit thread gained one reply saying the incident improved COLDCARD and another saying a few mistaken manual inputs do not matter.

    seen · Captured here 19,924 chars
    What changed from the previous capture 16 lines
     edited: false
     body:
     The dice method described also has a flaw. The average cheap dice you might obtain, are biased because scraping out the pips changes the weight of each face. The 1 is heaviest, so 6 is the most likely roll etc.
    +
    +comment: p1rr4bo
    +parent: t1_p1n6apo
    +author: CowDogRatGoose
    +created_utc: 1785894030
    +edited: false
    +body:
    +ColdCard has been made better as a result of this real world experience.
    +
    +comment: p1rrf8s
    +parent: t1_p1pzzfh
    +author: Adventurous_Iron_551
    +created_utc: 1785894130
    +edited: false
    +body:
    +What I meant was entering a wrong input, like 5 instead of 4. But to think about it, a few of such “fat fingering” inputs do not really matter
    
    Extracted text as captured
    post: 1vf0ut0
    author: Fearless-Second-7230
    created_utc: 1785820076
    title: Coldcard post from October 10, 2021: "Retirement Attack"
    body:
    \- "What's a retirement attack?"
    
    \- COLDCARD (@COLDCARDwallet): "It's when the project makers could have a "bug" in the entropy generation for later retrieval".
    
    \_\_\_\_\_
    
    Seems that they were smart enough to launch a "dice rolls" suggestion in a critical element lacking foolproof design, knowing not all users would be paranoid enough. Like "hey, if you don't trust no problem, but...you can trust buddy, the (back)door is open." ☠️
    
    Ok no, enough of conspiracy theory continuation. We know that Coldcard's post was pure coincidence. Right?...Right? 
    
    -----
    Edit: In case you're curious on more tweets mentioning "retirement attack", here is another one: 
    
    
    @nvk - 21 Dec 20: "My money is on people screwing themselves out of their BTC before any vendor tries a retirement attack.
    
    Alternatively people could just use dice ;)."
    
    https://x.com/i/status/1341213389549412353
    
    -----
    
    A strange way to warn "alternatively people" of what you have in mind to do...but Freudian slip or parapraxis theory explains that better, in case you're curious...
    
    comment: p1lcjaa
    parent: t3_1vf0ut0
    author: VictorDanville
    created_utc: 1785820367
    edited: false
    body:
    Wow, so this really was an inside job
    
    comment: p1lcq9n
    parent: t3_1vf0ut0
    author: fuckswithboats

    Excerpt only. The complete copy is held offline and backs quotations on this site. The original publication remains the canonical public source.

  7. source content difference between and source content +8 -0

    The Reddit thread gained a comment raising possible bias in inexpensive dice.

    seen · Captured here 19,494 chars
    What changed from the previous capture 8 lines
     edited: false
     body:
     I remember when this first happened someone posted here and everyone was like “bet you posted your seed phrase online lol dumbass.” Imagine that but every few months and OP did nothing wrong and nobody believes them 💔💔
    +
    +comment: p1r5z1k
    +parent: t3_1vf0ut0
    +author: OldWolf3
    +created_utc: 1785887191
    +edited: false
    +body:
    +The dice method described also has a flaw. The average cheap dice you might obtain, are biased because scraping out the pips changes the weight of each face. The 1 is heaviest, so 6 is the most likely roll etc.
    
    Extracted text as captured
    post: 1vf0ut0
    author: Fearless-Second-7230
    created_utc: 1785820076
    title: Coldcard post from October 10, 2021: "Retirement Attack"
    body:
    \- "What's a retirement attack?"
    
    \- COLDCARD (@COLDCARDwallet): "It's when the project makers could have a "bug" in the entropy generation for later retrieval".
    
    \_\_\_\_\_
    
    Seems that they were smart enough to launch a "dice rolls" suggestion in a critical element lacking foolproof design, knowing not all users would be paranoid enough. Like "hey, if you don't trust no problem, but...you can trust buddy, the (back)door is open." ☠️
    
    Ok no, enough of conspiracy theory continuation. We know that Coldcard's post was pure coincidence. Right?...Right? 
    
    -----
    Edit: In case you're curious on more tweets mentioning "retirement attack", here is another one: 
    
    
    @nvk - 21 Dec 20: "My money is on people screwing themselves out of their BTC before any vendor tries a retirement attack.
    
    Alternatively people could just use dice ;)."
    
    https://x.com/i/status/1341213389549412353
    
    -----
    
    A strange way to warn "alternatively people" of what you have in mind to do...but Freudian slip or parapraxis theory explains that better, in case you're curious...
    
    comment: p1lcjaa
    parent: t3_1vf0ut0
    author: VictorDanville
    created_utc: 1785820367
    edited: false
    body:
    Wow, so this really was an inside job
    
    comment: p1lcq9n
    parent: t3_1vf0ut0
    author: fuckswithboats

    Excerpt only. The complete copy is held offline and backs quotations on this site. The original publication remains the canonical public source.

  8. source content difference between and source content +16 -0

    The Reddit thread gained comments about earlier reports of recurring drains and initial disbelief from readers.

    seen · Captured here 19,185 chars
    What changed from the previous capture 16 lines
     body:
     Well people have already said nothing is going to happen to coldkite, theyll just declare bankruptcy and get away with it. So nothing will be done even if they snitched on themselves, in a tweet.
     
    +comment: p1n7h3w
    +parent: t3_1vf0ut0
    +author: Complete-MessUP
    +created_utc: 1785849130
    +edited: false
    +body:
    +he is the one % 99
    +
     comment: p1n9nox
     parent: t1_p1mtzpq
     author: 10kpizza
     edited: false
     body:
     From what I have been reading the past week about this, most used WEB BASED dice rolls lololol how stupid.
    +
    +comment: p1qyab5
    +parent: t1_p1lnwlq
    +author: Cold_Huckleberry_633
    +created_utc: 1785884786
    +edited: false
    +body:
    +I remember when this first happened someone posted here and everyone was like “bet you posted your seed phrase online lol dumbass.” Imagine that but every few months and OP did nothing wrong and nobody believes them 💔💔
    
    Extracted text as captured
    post: 1vf0ut0
    author: Fearless-Second-7230
    created_utc: 1785820076
    title: Coldcard post from October 10, 2021: "Retirement Attack"
    body:
    \- "What's a retirement attack?"
    
    \- COLDCARD (@COLDCARDwallet): "It's when the project makers could have a "bug" in the entropy generation for later retrieval".
    
    \_\_\_\_\_
    
    Seems that they were smart enough to launch a "dice rolls" suggestion in a critical element lacking foolproof design, knowing not all users would be paranoid enough. Like "hey, if you don't trust no problem, but...you can trust buddy, the (back)door is open." ☠️
    
    Ok no, enough of conspiracy theory continuation. We know that Coldcard's post was pure coincidence. Right?...Right? 
    
    -----
    Edit: In case you're curious on more tweets mentioning "retirement attack", here is another one: 
    
    
    @nvk - 21 Dec 20: "My money is on people screwing themselves out of their BTC before any vendor tries a retirement attack.
    
    Alternatively people could just use dice ;)."
    
    https://x.com/i/status/1341213389549412353
    
    -----
    
    A strange way to warn "alternatively people" of what you have in mind to do...but Freudian slip or parapraxis theory explains that better, in case you're curious...
    
    comment: p1lcjaa
    parent: t3_1vf0ut0
    author: VictorDanville
    created_utc: 1785820367
    edited: false
    body:
    Wow, so this really was an inside job
    
    comment: p1lcq9n
    parent: t3_1vf0ut0
    author: fuckswithboats

    Excerpt only. The complete copy is held offline and backs quotations on this site. The original publication remains the canonical public source.

  9. source content difference between and source content +3 -2

    An existing Reddit comment was edited to add a preference for QRNG over dice rolls.

    seen · Captured here 18,730 chars
    What changed from the previous capture 5 lines
     parent: t1_p1q4mvx
     author: NetimLabs
     created_utc: 1785879082
    -edited: 1785879461
    +edited: 1785881704
     body:
     Idk, they would have to try all the conversion methods possible anyways, that makes it much harder, if not impossible.
     
     You can come up with lots of weird ways to do that.
     
    -Ideally one should DIY their own [qrng generator](https://www.youtube.com/watch?v=CE4qXo-hYng), of course.
    +Ideally one should DIY their own [qrng generator](https://www.youtube.com/watch?v=CE4qXo-hYng), of course.  
    +I guess at that point rolling dice is more practical but if you want true randomness, qrng is the way.
     
     comment: p1qh0z8
     parent: t1_p1lzdzv
    
    Extracted text as captured
    post: 1vf0ut0
    author: Fearless-Second-7230
    created_utc: 1785820076
    title: Coldcard post from October 10, 2021: "Retirement Attack"
    body:
    \- "What's a retirement attack?"
    
    \- COLDCARD (@COLDCARDwallet): "It's when the project makers could have a "bug" in the entropy generation for later retrieval".
    
    \_\_\_\_\_
    
    Seems that they were smart enough to launch a "dice rolls" suggestion in a critical element lacking foolproof design, knowing not all users would be paranoid enough. Like "hey, if you don't trust no problem, but...you can trust buddy, the (back)door is open." ☠️
    
    Ok no, enough of conspiracy theory continuation. We know that Coldcard's post was pure coincidence. Right?...Right? 
    
    -----
    Edit: In case you're curious on more tweets mentioning "retirement attack", here is another one: 
    
    
    @nvk - 21 Dec 20: "My money is on people screwing themselves out of their BTC before any vendor tries a retirement attack.
    
    Alternatively people could just use dice ;)."
    
    https://x.com/i/status/1341213389549412353
    
    -----
    
    A strange way to warn "alternatively people" of what you have in mind to do...but Freudian slip or parapraxis theory explains that better, in case you're curious...
    
    comment: p1lcjaa
    parent: t3_1vf0ut0
    author: VictorDanville
    created_utc: 1785820367
    edited: false
    body:
    Wow, so this really was an inside job
    
    comment: p1lcq9n
    parent: t3_1vf0ut0
    author: fuckswithboats

    Excerpt only. The complete copy is held offline and backs quotations on this site. The original publication remains the canonical public source.

  10. source content difference between and source content +20 -0

    The Reddit thread gained 2 new comments about entropy generation and dice rolls.

    seen · Captured here 18,625 chars
    What changed from the previous capture 20 lines
     what im referring to is the ability to have a read only electrum wallet on an online pc. You create a transaction there, copy the transaction file via a usb stick to an offline pc sign it with electrum on the offline machine. Then take the signed file back to the online pc and send it. 
     
     The offline pc can be completely replaced with a coldwallet, afaik trezor doesn't support this.
    +
    +comment: p1qeqjq
    +parent: t1_p1q4mvx
    +author: NetimLabs
    +created_utc: 1785879082
    +edited: 1785879461
    +body:
    +Idk, they would have to try all the conversion methods possible anyways, that makes it much harder, if not impossible.
    +
    +You can come up with lots of weird ways to do that.
    +
    +Ideally one should DIY their own [qrng generator](https://www.youtube.com/watch?v=CE4qXo-hYng), of course.
    +
    +comment: p1qh0z8
    +parent: t1_p1lzdzv
    +author: alfredonoodles
    +created_utc: 1785879719
    +edited: false
    +body:
    +From what I have been reading the past week about this, most used WEB BASED dice rolls lololol how stupid.
    
    Extracted text as captured
    post: 1vf0ut0
    author: Fearless-Second-7230
    created_utc: 1785820076
    title: Coldcard post from October 10, 2021: "Retirement Attack"
    body:
    \- "What's a retirement attack?"
    
    \- COLDCARD (@COLDCARDwallet): "It's when the project makers could have a "bug" in the entropy generation for later retrieval".
    
    \_\_\_\_\_
    
    Seems that they were smart enough to launch a "dice rolls" suggestion in a critical element lacking foolproof design, knowing not all users would be paranoid enough. Like "hey, if you don't trust no problem, but...you can trust buddy, the (back)door is open." ☠️
    
    Ok no, enough of conspiracy theory continuation. We know that Coldcard's post was pure coincidence. Right?...Right? 
    
    -----
    Edit: In case you're curious on more tweets mentioning "retirement attack", here is another one: 
    
    
    @nvk - 21 Dec 20: "My money is on people screwing themselves out of their BTC before any vendor tries a retirement attack.
    
    Alternatively people could just use dice ;)."
    
    https://x.com/i/status/1341213389549412353
    
    -----
    
    A strange way to warn "alternatively people" of what you have in mind to do...but Freudian slip or parapraxis theory explains that better, in case you're curious...
    
    comment: p1lcjaa
    parent: t3_1vf0ut0
    author: VictorDanville
    created_utc: 1785820367
    edited: false
    body:
    Wow, so this really was an inside job
    
    comment: p1lcq9n
    parent: t3_1vf0ut0
    author: fuckswithboats

    Excerpt only. The complete copy is held offline and backs quotations on this site. The original publication remains the canonical public source.

  11. source content difference between and source content +20 -0

    The Reddit thread gained 2 new comments about air-gapped signing and seed migration.

    seen · Captured here 18,030 chars
    What changed from the previous capture 20 lines
     For good security you need to force the hacker to make at least 2^128 calculations. That's a lot. Dont roll your own cryptography so you dont make basic errors like this that could cost you money.
     
     You know this coldcard hack was based on the hacker doing ~2^32 calculations which is about 4 billion, still huge big number in human terms but very little for a computer.
    +
    +comment: p1q8d8k
    +parent: t1_p1p5in6
    +author: tonto515
    +created_utc: 1785877355
    +edited: false
    +body:
    +Trezor 3 and 5 are airgapped, only 7 has the Bluetooth functionality.
    +
    +That said, my Keystone Pro 3 is airgapped and I still moved my funds this morning from my old wallet with a single seed phrase to a new one with 3/5 Shamir sharding to protect it.
    +
    +comment: p1qav0u
    +parent: t1_p1q8d8k
    +author: Express_Living2264
    +created_utc: 1785878032
    +edited: false
    +body:
    +what im referring to is the ability to have a read only electrum wallet on an online pc. You create a transaction there, copy the transaction file via a usb stick to an offline pc sign it with electrum on the offline machine. Then take the signed file back to the online pc and send it. 
    +
    +The offline pc can be completely replaced with a coldwallet, afaik trezor doesn't support this.
    
    Extracted text as captured
    post: 1vf0ut0
    author: Fearless-Second-7230
    created_utc: 1785820076
    title: Coldcard post from October 10, 2021: "Retirement Attack"
    body:
    \- "What's a retirement attack?"
    
    \- COLDCARD (@COLDCARDwallet): "It's when the project makers could have a "bug" in the entropy generation for later retrieval".
    
    \_\_\_\_\_
    
    Seems that they were smart enough to launch a "dice rolls" suggestion in a critical element lacking foolproof design, knowing not all users would be paranoid enough. Like "hey, if you don't trust no problem, but...you can trust buddy, the (back)door is open." ☠️
    
    Ok no, enough of conspiracy theory continuation. We know that Coldcard's post was pure coincidence. Right?...Right? 
    
    -----
    Edit: In case you're curious on more tweets mentioning "retirement attack", here is another one: 
    
    
    @nvk - 21 Dec 20: "My money is on people screwing themselves out of their BTC before any vendor tries a retirement attack.
    
    Alternatively people could just use dice ;)."
    
    https://x.com/i/status/1341213389549412353
    
    -----
    
    A strange way to warn "alternatively people" of what you have in mind to do...but Freudian slip or parapraxis theory explains that better, in case you're curious...
    
    comment: p1lcjaa
    parent: t3_1vf0ut0
    author: VictorDanville
    created_utc: 1785820367
    edited: false
    body:
    Wow, so this really was an inside job
    
    comment: p1lcq9n
    parent: t3_1vf0ut0
    author: fuckswithboats

    Excerpt only. The complete copy is held offline and backs quotations on this site. The original publication remains the canonical public source.

  12. source content difference between and source content +12 -0

    The Reddit thread gained 1 new comment contrasting a claimed 2^32 search with a 2^128 security target.

    seen · Captured here 17,188 chars
    What changed from the previous capture 12 lines
     edited: false
     body:
     Fat fingering?  You don't have to actually remember your dice rolls for later though
    +
    +comment: p1q4mvx
    +parent: t1_p1pri25
    +author: 10kpizza
    +created_utc: 1785876359
    +edited: false
    +body:
    +No it wouldnt because theres not that many ways to partition the stream. The hacker could just try them all.
    +
    +For good security you need to force the hacker to make at least 2^128 calculations. That's a lot. Dont roll your own cryptography so you dont make basic errors like this that could cost you money.
    +
    +You know this coldcard hack was based on the hacker doing ~2^32 calculations which is about 4 billion, still huge big number in human terms but very little for a computer.
    
    Extracted text as captured
    post: 1vf0ut0
    author: Fearless-Second-7230
    created_utc: 1785820076
    title: Coldcard post from October 10, 2021: "Retirement Attack"
    body:
    \- "What's a retirement attack?"
    
    \- COLDCARD (@COLDCARDwallet): "It's when the project makers could have a "bug" in the entropy generation for later retrieval".
    
    \_\_\_\_\_
    
    Seems that they were smart enough to launch a "dice rolls" suggestion in a critical element lacking foolproof design, knowing not all users would be paranoid enough. Like "hey, if you don't trust no problem, but...you can trust buddy, the (back)door is open." ☠️
    
    Ok no, enough of conspiracy theory continuation. We know that Coldcard's post was pure coincidence. Right?...Right? 
    
    -----
    Edit: In case you're curious on more tweets mentioning "retirement attack", here is another one: 
    
    
    @nvk - 21 Dec 20: "My money is on people screwing themselves out of their BTC before any vendor tries a retirement attack.
    
    Alternatively people could just use dice ;)."
    
    https://x.com/i/status/1341213389549412353
    
    -----
    
    A strange way to warn "alternatively people" of what you have in mind to do...but Freudian slip or parapraxis theory explains that better, in case you're curious...
    
    comment: p1lcjaa
    parent: t3_1vf0ut0
    author: VictorDanville
    created_utc: 1785820367
    edited: false
    body:
    Wow, so this really was an inside job
    
    comment: p1lcq9n
    parent: t3_1vf0ut0
    author: fuckswithboats

    Excerpt only. The complete copy is held offline and backs quotations on this site. The original publication remains the canonical public source.

  13. source content difference between and source content +18 -0

    The Reddit thread gained 2 new comments.

    seen · Captured here 16,610 chars
    What changed from the previous capture 18 lines
     body:
     the sad thing is. It's still one of the better products due to the airgapped signing feature + electrum read only wallet. something trezor afaik cant do.
     
    +comment: p1pq3e0
    +parent: t3_1vf0ut0
    +author: lysergamythical
    +created_utc: 1785872511
    +edited: false
    +body:
    + "alternatively people" 
    +
    +are you being deliberately obtuse?
    +
     comment: p1pri25
     parent: t1_p1n9nox
     author: NetimLabs
     body:
     The one I linked was just an example.  
     You could use any qrng source you want, of course.
    +
    +comment: p1pzzfh
    +parent: t1_p1lj212
    +author: Deto
    +created_utc: 1785875119
    +edited: false
    +body:
    +Fat fingering?  You don't have to actually remember your dice rolls for later though
    
    Extracted text as captured
    post: 1vf0ut0
    author: Fearless-Second-7230
    created_utc: 1785820076
    title: Coldcard post from October 10, 2021: "Retirement Attack"
    body:
    \- "What's a retirement attack?"
    
    \- COLDCARD (@COLDCARDwallet): "It's when the project makers could have a "bug" in the entropy generation for later retrieval".
    
    \_\_\_\_\_
    
    Seems that they were smart enough to launch a "dice rolls" suggestion in a critical element lacking foolproof design, knowing not all users would be paranoid enough. Like "hey, if you don't trust no problem, but...you can trust buddy, the (back)door is open." ☠️
    
    Ok no, enough of conspiracy theory continuation. We know that Coldcard's post was pure coincidence. Right?...Right? 
    
    -----
    Edit: In case you're curious on more tweets mentioning "retirement attack", here is another one: 
    
    
    @nvk - 21 Dec 20: "My money is on people screwing themselves out of their BTC before any vendor tries a retirement attack.
    
    Alternatively people could just use dice ;)."
    
    https://x.com/i/status/1341213389549412353
    
    -----
    
    A strange way to warn "alternatively people" of what you have in mind to do...but Freudian slip or parapraxis theory explains that better, in case you're curious...
    
    comment: p1lcjaa
    parent: t3_1vf0ut0
    author: VictorDanville
    created_utc: 1785820367
    edited: false
    body:
    Wow, so this really was an inside job
    
    comment: p1lcq9n
    parent: t3_1vf0ut0
    author: fuckswithboats

    Excerpt only. The complete copy is held offline and backs quotations on this site. The original publication remains the canonical public source.

  14. source content difference between and source content +19 -0

    The Reddit thread gained 2 new comments.

    seen · Captured here 16,265 chars
    What changed from the previous capture 19 lines
     edited: false
     body:
     the sad thing is. It's still one of the better products due to the airgapped signing feature + electrum read only wallet. something trezor afaik cant do.
    +
    +comment: p1pri25
    +parent: t1_p1n9nox
    +author: NetimLabs
    +created_utc: 1785872880
    +edited: false
    +body:
    +The potential attackers would have to constantly monitor the stream and save it on their devices, then figure out which method you used to convert that stream to a seed phrase.
    +
    +Using different parts \[same lenght\] of the stream for each word would solve this I think.
    +
    +comment: p1ps2r8
    +parent: t1_p1nfcwj
    +author: NetimLabs
    +created_utc: 1785873032
    +edited: false
    +body:
    +The one I linked was just an example.  
    +You could use any qrng source you want, of course.
    
    Extracted text as captured
    post: 1vf0ut0
    author: Fearless-Second-7230
    created_utc: 1785820076
    title: Coldcard post from October 10, 2021: "Retirement Attack"
    body:
    \- "What's a retirement attack?"
    
    \- COLDCARD (@COLDCARDwallet): "It's when the project makers could have a "bug" in the entropy generation for later retrieval".
    
    \_\_\_\_\_
    
    Seems that they were smart enough to launch a "dice rolls" suggestion in a critical element lacking foolproof design, knowing not all users would be paranoid enough. Like "hey, if you don't trust no problem, but...you can trust buddy, the (back)door is open." ☠️
    
    Ok no, enough of conspiracy theory continuation. We know that Coldcard's post was pure coincidence. Right?...Right? 
    
    -----
    Edit: In case you're curious on more tweets mentioning "retirement attack", here is another one: 
    
    
    @nvk - 21 Dec 20: "My money is on people screwing themselves out of their BTC before any vendor tries a retirement attack.
    
    Alternatively people could just use dice ;)."
    
    https://x.com/i/status/1341213389549412353
    
    -----
    
    A strange way to warn "alternatively people" of what you have in mind to do...but Freudian slip or parapraxis theory explains that better, in case you're curious...
    
    comment: p1lcjaa
    parent: t3_1vf0ut0
    author: VictorDanville
    created_utc: 1785820367
    edited: false
    body:
    Wow, so this really was an inside job
    
    comment: p1lcq9n
    parent: t3_1vf0ut0
    author: fuckswithboats

    Excerpt only. The complete copy is held offline and backs quotations on this site. The original publication remains the canonical public source.

  15. source content difference between and source content +19 -3

    The Reddit thread gained 2 new comments.

    seen · Captured here 15,706 chars
    What changed from the previous capture 22 lines
     parent: t1_p1n3eq9
     author: youtossershad1job2do
     created_utc: 1785860550
    -edited: false
    -body:
    -What was the whole point of crypto was it was trust less. 
    +edited: 1785867322
    +body:
    +It was the whole point of crypto that it was trust-less.
     
     comment: p1om0wr
     parent: t1_p1m0pf3
     edited: false
     body:
     Dice rolls are solid. No correct dice rolls have been hacked ever. If you mean human error ie what the article you posted alludes to ( not enough actual rolls) or grouping all the numbers in order( all 1's then 2' etc) then yeah thats retarded but a true 100+dice roll actually using 100 dice is effectively un-hackable which is why coldcard users using this function remain safe.
    +
    +comment: p1p54mw
    +parent: t1_p1lka5q
    +author: Express_Living2264
    +created_utc: 1785867168
    +edited: false
    +body:
    +i don't see this as incriminating at all. They are advertising to security extremists. They added a cheap to build gimmick for marketing and then advertised it to generate engagement, that's all there is to it.
    +
    +comment: p1p5in6
    +parent: t1_p1n6apo
    +author: Express_Living2264
    +created_utc: 1785867265
    +edited: false
    +body:
    +the sad thing is. It's still one of the better products due to the airgapped signing feature + electrum read only wallet. something trezor afaik cant do.
    
    Extracted text as captured
    post: 1vf0ut0
    author: Fearless-Second-7230
    created_utc: 1785820076
    title: Coldcard post from October 10, 2021: "Retirement Attack"
    body:
    \- "What's a retirement attack?"
    
    \- COLDCARD (@COLDCARDwallet): "It's when the project makers could have a "bug" in the entropy generation for later retrieval".
    
    \_\_\_\_\_
    
    Seems that they were smart enough to launch a "dice rolls" suggestion in a critical element lacking foolproof design, knowing not all users would be paranoid enough. Like "hey, if you don't trust no problem, but...you can trust buddy, the (back)door is open." ☠️
    
    Ok no, enough of conspiracy theory continuation. We know that Coldcard's post was pure coincidence. Right?...Right? 
    
    -----
    Edit: In case you're curious on more tweets mentioning "retirement attack", here is another one: 
    
    
    @nvk - 21 Dec 20: "My money is on people screwing themselves out of their BTC before any vendor tries a retirement attack.
    
    Alternatively people could just use dice ;)."
    
    https://x.com/i/status/1341213389549412353
    
    -----
    
    A strange way to warn "alternatively people" of what you have in mind to do...but Freudian slip or parapraxis theory explains that better, in case you're curious...
    
    comment: p1lcjaa
    parent: t3_1vf0ut0
    author: VictorDanville
    created_utc: 1785820367
    edited: false
    body:
    Wow, so this really was an inside job
    
    comment: p1lcq9n
    parent: t3_1vf0ut0
    author: fuckswithboats

    Excerpt only. The complete copy is held offline and backs quotations on this site. The original publication remains the canonical public source.

  16. source content difference between and source content +8 -0

    The Reddit thread gained 1 new comment.

    seen · Captured here 15,122 chars
    What changed from the previous capture 8 lines
     If you’re that deep into self custodial wallets then take that little extra step to setup your own wallet hosted on a microcontroller.
     
     That way you can 100% guarantee you’re using a 100% air gapped device and you can test to your hearts content if the open-source wallet is faulty free. 
    +
    +comment: p1ou7vl
    +parent: t1_p1lzdzv
    +author: EyesFor1
    +created_utc: 1785864479
    +edited: false
    +body:
    +Dice rolls are solid. No correct dice rolls have been hacked ever. If you mean human error ie what the article you posted alludes to ( not enough actual rolls) or grouping all the numbers in order( all 1's then 2' etc) then yeah thats retarded but a true 100+dice roll actually using 100 dice is effectively un-hackable which is why coldcard users using this function remain safe.
    
    Extracted text as captured
    post: 1vf0ut0
    author: Fearless-Second-7230
    created_utc: 1785820076
    title: Coldcard post from October 10, 2021: "Retirement Attack"
    body:
    \- "What's a retirement attack?"
    
    \- COLDCARD (@COLDCARDwallet): "It's when the project makers could have a "bug" in the entropy generation for later retrieval".
    
    \_\_\_\_\_
    
    Seems that they were smart enough to launch a "dice rolls" suggestion in a critical element lacking foolproof design, knowing not all users would be paranoid enough. Like "hey, if you don't trust no problem, but...you can trust buddy, the (back)door is open." ☠️
    
    Ok no, enough of conspiracy theory continuation. We know that Coldcard's post was pure coincidence. Right?...Right? 
    
    -----
    Edit: In case you're curious on more tweets mentioning "retirement attack", here is another one: 
    
    
    @nvk - 21 Dec 20: "My money is on people screwing themselves out of their BTC before any vendor tries a retirement attack.
    
    Alternatively people could just use dice ;)."
    
    https://x.com/i/status/1341213389549412353
    
    -----
    
    A strange way to warn "alternatively people" of what you have in mind to do...but Freudian slip or parapraxis theory explains that better, in case you're curious...
    
    comment: p1lcjaa
    parent: t3_1vf0ut0
    author: VictorDanville
    created_utc: 1785820367
    edited: false
    body:
    Wow, so this really was an inside job
    
    comment: p1lcq9n
    parent: t3_1vf0ut0
    author: fuckswithboats

    Excerpt only. The complete copy is held offline and backs quotations on this site. The original publication remains the canonical public source.

  17. source content difference between and source content +12 -0

    The Reddit thread gained 1 new comment.

    seen · Captured here 14,643 chars
    What changed from the previous capture 12 lines
     edited: false
     body:
     What was the whole point of crypto was it was trust less. 
    +
    +comment: p1om0wr
    +parent: t1_p1m0pf3
    +author: anonymous-12358
    +created_utc: 1785862452
    +edited: false
    +body:
    +I would even go as far to say don’t trust Trezor or Ledger.
    +
    +If you’re that deep into self custodial wallets then take that little extra step to setup your own wallet hosted on a microcontroller.
    +
    +That way you can 100% guarantee you’re using a 100% air gapped device and you can test to your hearts content if the open-source wallet is faulty free. 
    
    Extracted text as captured
    post: 1vf0ut0
    author: Fearless-Second-7230
    created_utc: 1785820076
    title: Coldcard post from October 10, 2021: "Retirement Attack"
    body:
    \- "What's a retirement attack?"
    
    \- COLDCARD (@COLDCARDwallet): "It's when the project makers could have a "bug" in the entropy generation for later retrieval".
    
    \_\_\_\_\_
    
    Seems that they were smart enough to launch a "dice rolls" suggestion in a critical element lacking foolproof design, knowing not all users would be paranoid enough. Like "hey, if you don't trust no problem, but...you can trust buddy, the (back)door is open." ☠️
    
    Ok no, enough of conspiracy theory continuation. We know that Coldcard's post was pure coincidence. Right?...Right? 
    
    -----
    Edit: In case you're curious on more tweets mentioning "retirement attack", here is another one: 
    
    
    @nvk - 21 Dec 20: "My money is on people screwing themselves out of their BTC before any vendor tries a retirement attack.
    
    Alternatively people could just use dice ;)."
    
    https://x.com/i/status/1341213389549412353
    
    -----
    
    A strange way to warn "alternatively people" of what you have in mind to do...but Freudian slip or parapraxis theory explains that better, in case you're curious...
    
    comment: p1lcjaa
    parent: t3_1vf0ut0
    author: VictorDanville
    created_utc: 1785820367
    edited: false
    body:
    Wow, so this really was an inside job
    
    comment: p1lcq9n
    parent: t3_1vf0ut0
    author: fuckswithboats

    Excerpt only. The complete copy is held offline and backs quotations on this site. The original publication remains the canonical public source.

  18. source content difference between and source content +8 -0

    1 new Reddit comment was posted, by youtossershad1job2do, questioning the trustless premise of crypto.

    seen · Captured here 14,188 chars
    What changed from the previous capture 8 lines
     edited: false
     body:
     It’s convenient how the error originated in 2021 as well….
    +
    +comment: p1oeed3
    +parent: t1_p1n3eq9
    +author: youtossershad1job2do
    +created_utc: 1785860550
    +edited: false
    +body:
    +What was the whole point of crypto was it was trust less. 
    
    Extracted text as captured
    post: 1vf0ut0
    author: Fearless-Second-7230
    created_utc: 1785820076
    title: Coldcard post from October 10, 2021: "Retirement Attack"
    body:
    \- "What's a retirement attack?"
    
    \- COLDCARD (@COLDCARDwallet): "It's when the project makers could have a "bug" in the entropy generation for later retrieval".
    
    \_\_\_\_\_
    
    Seems that they were smart enough to launch a "dice rolls" suggestion in a critical element lacking foolproof design, knowing not all users would be paranoid enough. Like "hey, if you don't trust no problem, but...you can trust buddy, the (back)door is open." ☠️
    
    Ok no, enough of conspiracy theory continuation. We know that Coldcard's post was pure coincidence. Right?...Right? 
    
    -----
    Edit: In case you're curious on more tweets mentioning "retirement attack", here is another one: 
    
    
    @nvk - 21 Dec 20: "My money is on people screwing themselves out of their BTC before any vendor tries a retirement attack.
    
    Alternatively people could just use dice ;)."
    
    https://x.com/i/status/1341213389549412353
    
    -----
    
    A strange way to warn "alternatively people" of what you have in mind to do...but Freudian slip or parapraxis theory explains that better, in case you're curious...
    
    comment: p1lcjaa
    parent: t3_1vf0ut0
    author: VictorDanville
    created_utc: 1785820367
    edited: false
    body:
    Wow, so this really was an inside job
    
    comment: p1lcq9n
    parent: t3_1vf0ut0
    author: fuckswithboats

    Excerpt only. The complete copy is held offline and backs quotations on this site. The original publication remains the canonical public source.

  19. source content difference between and source content +8 -0

    1 new Reddit comment was posted, by Such_Advantage6988, noting that the error dated to 2021.

    seen · Captured here 14,019 chars
    What changed from the previous capture 8 lines
     edited: false
     body:
     Retirement attack = retirement plan
    +
    +comment: p1nzs74
    +parent: t1_p1lcjaa
    +author: Such_Advantage6988
    +created_utc: 1785856830
    +edited: false
    +body:
    +It’s convenient how the error originated in 2021 as well….
    
    Extracted text as captured
    post: 1vf0ut0
    author: Fearless-Second-7230
    created_utc: 1785820076
    title: Coldcard post from October 10, 2021: "Retirement Attack"
    body:
    \- "What's a retirement attack?"
    
    \- COLDCARD (@COLDCARDwallet): "It's when the project makers could have a "bug" in the entropy generation for later retrieval".
    
    \_\_\_\_\_
    
    Seems that they were smart enough to launch a "dice rolls" suggestion in a critical element lacking foolproof design, knowing not all users would be paranoid enough. Like "hey, if you don't trust no problem, but...you can trust buddy, the (back)door is open." ☠️
    
    Ok no, enough of conspiracy theory continuation. We know that Coldcard's post was pure coincidence. Right?...Right? 
    
    -----
    Edit: In case you're curious on more tweets mentioning "retirement attack", here is another one: 
    
    
    @nvk - 21 Dec 20: "My money is on people screwing themselves out of their BTC before any vendor tries a retirement attack.
    
    Alternatively people could just use dice ;)."
    
    https://x.com/i/status/1341213389549412353
    
    -----
    
    A strange way to warn "alternatively people" of what you have in mind to do...but Freudian slip or parapraxis theory explains that better, in case you're curious...
    
    comment: p1lcjaa
    parent: t3_1vf0ut0
    author: VictorDanville
    created_utc: 1785820367
    edited: false
    body:
    Wow, so this really was an inside job
    
    comment: p1lcq9n
    parent: t3_1vf0ut0
    author: fuckswithboats

    Excerpt only. The complete copy is held offline and backs quotations on this site. The original publication remains the canonical public source.

  20. source content difference between and source content +34 -0

    4 new Reddit comments were posted, including Always_working_hardd, Unsounded and kikikza.

    seen · Captured here 13,852 chars
    What changed from the previous capture 34 lines
     edited: false
     body:
     It’s a device to delicately shave your balls. 
    +
    +comment: p1np3g9
    +parent: t3_1vf0ut0
    +author: Always_working_hardd
    +created_utc: 1785854019
    +edited: false
    +body:
    +Meanwhile there's some Indian out there taking possession of a private jet so he can fly to the island he just bought in the Caribbean. 
    +
    +Also a former employee of coldcard.
    +
    +comment: p1npnij
    +parent: t1_p1n3eq9
    +author: Unsounded
    +created_utc: 1785854167
    +edited: false
    +body:
    +The funny thing is academia is fraught with fraudsters and bad coders.
    +
    +comment: p1nrrps
    +parent: t1_p1m1u8n
    +author: kikikza
    +created_utc: 1785854728
    +edited: false
    +body:
    +Gotta use a wall of lava lamps
    +
    +comment: p1nsfqo
    +parent: t3_1vf0ut0
    +author: beatthebook2x
    +created_utc: 1785854903
    +edited: false
    +body:
    +Retirement attack = retirement plan
    
    Extracted text as captured
    post: 1vf0ut0
    author: Fearless-Second-7230
    created_utc: 1785820076
    title: Coldcard post from October 10, 2021: "Retirement Attack"
    body:
    \- "What's a retirement attack?"
    
    \- COLDCARD (@COLDCARDwallet): "It's when the project makers could have a "bug" in the entropy generation for later retrieval".
    
    \_\_\_\_\_
    
    Seems that they were smart enough to launch a "dice rolls" suggestion in a critical element lacking foolproof design, knowing not all users would be paranoid enough. Like "hey, if you don't trust no problem, but...you can trust buddy, the (back)door is open." ☠️
    
    Ok no, enough of conspiracy theory continuation. We know that Coldcard's post was pure coincidence. Right?...Right? 
    
    -----
    Edit: In case you're curious on more tweets mentioning "retirement attack", here is another one: 
    
    
    @nvk - 21 Dec 20: "My money is on people screwing themselves out of their BTC before any vendor tries a retirement attack.
    
    Alternatively people could just use dice ;)."
    
    https://x.com/i/status/1341213389549412353
    
    -----
    
    A strange way to warn "alternatively people" of what you have in mind to do...but Freudian slip or parapraxis theory explains that better, in case you're curious...
    
    comment: p1lcjaa
    parent: t3_1vf0ut0
    author: VictorDanville
    created_utc: 1785820367
    edited: false
    body:
    Wow, so this really was an inside job
    
    comment: p1lcq9n
    parent: t3_1vf0ut0
    author: fuckswithboats

    Excerpt only. The complete copy is held offline and backs quotations on this site. The original publication remains the canonical public source.

  21. source content difference between and source content +40 -0

    5 new Reddit comments were posted, including 10kpizza,crypto_chik,ILurkReddi.

    seen · Captured here 13,131 chars
    What changed from the previous capture 40 lines
     edited: false
     body:
     Well people have already said nothing is going to happen to coldkite, theyll just declare bankruptcy and get away with it. So nothing will be done even if they snitched on themselves, in a tweet.
    +
    +comment: p1n9nox
    +parent: t1_p1mtzpq
    +author: 10kpizza
    +created_utc: 1785849763
    +edited: false
    +body:
    +The important key thing with generating private keys is that nobody else knows them. The easiest way to get a number that nobody else knows is random data. However if the random data is publicly available to others then this obviously isnt secure.
    +
    +comment: p1nb6p1
    +parent: t3_1vf0ut0
    +author: crypto_chik
    +created_utc: 1785850203
    +edited: false
    +body:
    +Chances it wasn’t an inside job are dwindling…
    +
    +comment: p1nfcwj
    +parent: t1_p1mtzpq
    +author: ILurkReddi
    +created_utc: 1785851379
    +edited: false
    +body:
    +would rather [random.org](http://random.org) or cloudflare
    +
    +comment: p1nftns
    +parent: t1_p1mtzpq
    +author: tenor_tymir
    +created_utc: 1785851509
    +edited: false
    +body:
    +How is this complex hex number practical for the average user? 
    +
    +comment: p1ng0uf
    +parent: t1_p1meno4
    +author: tenor_tymir
    +created_utc: 1785851564
    +edited: false
    +body:
    +It’s a device to delicately shave your balls. 
    
    Extracted text as captured
    post: 1vf0ut0
    author: Fearless-Second-7230
    created_utc: 1785820076
    title: Coldcard post from October 10, 2021: "Retirement Attack"
    body:
    \- "What's a retirement attack?"
    
    \- COLDCARD (@COLDCARDwallet): "It's when the project makers could have a "bug" in the entropy generation for later retrieval".
    
    \_\_\_\_\_
    
    Seems that they were smart enough to launch a "dice rolls" suggestion in a critical element lacking foolproof design, knowing not all users would be paranoid enough. Like "hey, if you don't trust no problem, but...you can trust buddy, the (back)door is open." ☠️
    
    Ok no, enough of conspiracy theory continuation. We know that Coldcard's post was pure coincidence. Right?...Right? 
    
    -----
    Edit: In case you're curious on more tweets mentioning "retirement attack", here is another one: 
    
    
    @nvk - 21 Dec 20: "My money is on people screwing themselves out of their BTC before any vendor tries a retirement attack.
    
    Alternatively people could just use dice ;)."
    
    https://x.com/i/status/1341213389549412353
    
    -----
    
    A strange way to warn "alternatively people" of what you have in mind to do...but Freudian slip or parapraxis theory explains that better, in case you're curious...
    
    comment: p1lcjaa
    parent: t3_1vf0ut0
    author: VictorDanville
    created_utc: 1785820367
    edited: false
    body:
    Wow, so this really was an inside job
    
    comment: p1lcq9n
    parent: t3_1vf0ut0
    author: fuckswithboats

    Excerpt only. The complete copy is held offline and backs quotations on this site. The original publication remains the canonical public source.

  22. source content difference between and source content +32 -0

    4 new Reddit comments were posted, including bricksplus,shadowmage666,Gooner_93.

    seen · Captured here 12,165 chars
    What changed from the previous capture 32 lines
     edited: false
     body:
     I read that at least as partially being unable to contain bragging about whatever perceived brilliance they have of themselves. They dont want people who find out to not understand their cleverness. 
    +
    +comment: p1n3eq9
    +parent: t1_p1mxiiw
    +author: bricksplus
    +created_utc: 1785847901
    +edited: false
    +body:
    +You put trust in the institution that’s being doing high level research for decades 
    +
    +comment: p1n3t4c
    +parent: t3_1vf0ut0
    +author: shadowmage666
    +created_utc: 1785848023
    +edited: false
    +body:
    +Hmm not suspicious at all 
    +
    +comment: p1n5dgp
    +parent: t3_1vf0ut0
    +author: Gooner_93
    +created_utc: 1785848496
    +edited: false
    +body:
    +And yet you will get some people calling you insane for saying it was an inside job.
    +
    +comment: p1n6apo
    +parent: t3_1vf0ut0
    +author: axb90
    +created_utc: 1785848777
    +edited: false
    +body:
    +Well people have already said nothing is going to happen to coldkite, theyll just declare bankruptcy and get away with it. So nothing will be done even if they snitched on themselves, in a tweet.
    
    Extracted text as captured
    post: 1vf0ut0
    author: Fearless-Second-7230
    created_utc: 1785820076
    title: Coldcard post from October 10, 2021: "Retirement Attack"
    body:
    \- "What's a retirement attack?"
    
    \- COLDCARD (@COLDCARDwallet): "It's when the project makers could have a "bug" in the entropy generation for later retrieval".
    
    \_\_\_\_\_
    
    Seems that they were smart enough to launch a "dice rolls" suggestion in a critical element lacking foolproof design, knowing not all users would be paranoid enough. Like "hey, if you don't trust no problem, but...you can trust buddy, the (back)door is open." ☠️
    
    Ok no, enough of conspiracy theory continuation. We know that Coldcard's post was pure coincidence. Right?...Right? 
    
    -----
    Edit: In case you're curious on more tweets mentioning "retirement attack", here is another one: 
    
    
    @nvk - 21 Dec 20: "My money is on people screwing themselves out of their BTC before any vendor tries a retirement attack.
    
    Alternatively people could just use dice ;)."
    
    https://x.com/i/status/1341213389549412353
    
    -----
    
    A strange way to warn "alternatively people" of what you have in mind to do...but Freudian slip or parapraxis theory explains that better, in case you're curious...
    
    comment: p1lcjaa
    parent: t3_1vf0ut0
    author: VictorDanville
    created_utc: 1785820367
    edited: false
    body:
    Wow, so this really was an inside job
    
    comment: p1lcq9n
    parent: t3_1vf0ut0
    author: fuckswithboats

    Excerpt only. The complete copy is held offline and backs quotations on this site. The original publication remains the canonical public source.

  23. source content difference between and source content +26 -0

    Three new comments were posted: youtossershad1job2do distrusting the online randomness generator, NetimLabs judging the risk low in this case, and Lilcheeks suggesting the attacker was partly bragging about their own cleverness.

    seen · Captured here 11,375 chars
    What changed from the previous capture 26 lines
     edited: false
     body:
     I mean, it's a fairly well known concept and you would expect people working in a company whose product is security to know about it...
    +
    +comment: p1mxiiw
    +parent: t1_p1mtzpq
    +author: youtossershad1job2do
    +created_utc: 1785846018
    +edited: false
    +body:
    +Still trust that someone hasn't made this generator vulnerable.
    +
    +You can see the dice being rolled but you can't know what's on your screen isn't dangerous. 
    +
    +comment: p1n0xdp
    +parent: t1_p1mxiiw
    +author: NetimLabs
    +created_utc: 1785847123
    +edited: false
    +body:
    +True, though I think the risk should be pretty low in this case.
    +
    +comment: p1n162l
    +parent: t1_p1lkk63
    +author: Lilcheeks
    +created_utc: 1785847199
    +edited: false
    +body:
    +I read that at least as partially being unable to contain bragging about whatever perceived brilliance they have of themselves. They dont want people who find out to not understand their cleverness. 
    
    Extracted text as captured
    post: 1vf0ut0
    author: Fearless-Second-7230
    created_utc: 1785820076
    title: Coldcard post from October 10, 2021: "Retirement Attack"
    body:
    \- "What's a retirement attack?"
    
    \- COLDCARD (@COLDCARDwallet): "It's when the project makers could have a "bug" in the entropy generation for later retrieval".
    
    \_\_\_\_\_
    
    Seems that they were smart enough to launch a "dice rolls" suggestion in a critical element lacking foolproof design, knowing not all users would be paranoid enough. Like "hey, if you don't trust no problem, but...you can trust buddy, the (back)door is open." ☠️
    
    Ok no, enough of conspiracy theory continuation. We know that Coldcard's post was pure coincidence. Right?...Right? 
    
    -----
    Edit: In case you're curious on more tweets mentioning "retirement attack", here is another one: 
    
    
    @nvk - 21 Dec 20: "My money is on people screwing themselves out of their BTC before any vendor tries a retirement attack.
    
    Alternatively people could just use dice ;)."
    
    https://x.com/i/status/1341213389549412353
    
    -----
    
    A strange way to warn "alternatively people" of what you have in mind to do...but Freudian slip or parapraxis theory explains that better, in case you're curious...
    
    comment: p1lcjaa
    parent: t3_1vf0ut0
    author: VictorDanville
    created_utc: 1785820367
    edited: false
    body:
    Wow, so this really was an inside job
    
    comment: p1lcq9n
    parent: t3_1vf0ut0
    author: fuckswithboats

    Excerpt only. The complete copy is held offline and backs quotations on this site. The original publication remains the canonical public source.

  24. source content difference between and source content +17 -0

    Two new comments were posted: NetimLabs suggesting publicly available quantum randomness streams instead of dice rolls, and CBpegasus saying the concept is well known and expected of a security company.

    seen · Captured here 10,644 chars
    What changed from the previous capture 17 lines
     >To date I have heard of zero compromised seeds that were generated using on-board RNG due to entropy issues, while there are countless examples of users losing funds due to improper dice rolls.
     
     Wow, this is your supporting reference?
    +
    +comment: p1mtzpq
    +parent: t3_1vf0ut0
    +author: NetimLabs
    +created_utc: 1785844822
    +edited: 1785845317
    +body:
    +Why bother with dice rolls?
    +We have [publicly available streams](https://qrng.anu.edu.au/random-hex/) of truly [quantum] random data
    +
    +comment: p1mw7dg
    +parent: t1_p1lp1qo
    +author: CBpegasus
    +created_utc: 1785845581
    +edited: false
    +body:
    +I mean, it's a fairly well known concept and you would expect people working in a company whose product is security to know about it...
    
    Extracted text as captured
    post: 1vf0ut0
    author: Fearless-Second-7230
    created_utc: 1785820076
    title: Coldcard post from October 10, 2021: "Retirement Attack"
    body:
    \- "What's a retirement attack?"
    
    \- COLDCARD (@COLDCARDwallet): "It's when the project makers could have a "bug" in the entropy generation for later retrieval".
    
    \_\_\_\_\_
    
    Seems that they were smart enough to launch a "dice rolls" suggestion in a critical element lacking foolproof design, knowing not all users would be paranoid enough. Like "hey, if you don't trust no problem, but...you can trust buddy, the (back)door is open." ☠️
    
    Ok no, enough of conspiracy theory continuation. We know that Coldcard's post was pure coincidence. Right?...Right? 
    
    -----
    Edit: In case you're curious on more tweets mentioning "retirement attack", here is another one: 
    
    
    @nvk - 21 Dec 20: "My money is on people screwing themselves out of their BTC before any vendor tries a retirement attack.
    
    Alternatively people could just use dice ;)."
    
    https://x.com/i/status/1341213389549412353
    
    -----
    
    A strange way to warn "alternatively people" of what you have in mind to do...but Freudian slip or parapraxis theory explains that better, in case you're curious...
    
    comment: p1lcjaa
    parent: t3_1vf0ut0
    author: VictorDanville
    created_utc: 1785820367
    edited: false
    body:
    Wow, so this really was an inside job
    
    comment: p1lcq9n
    parent: t3_1vf0ut0
    author: fuckswithboats

    Excerpt only. The complete copy is held offline and backs quotations on this site. The original publication remains the canonical public source.

  25. source content difference between and source content +18 -0

    One new comment was posted: CiaranCarroll disputing the quoted Passport claims, arguing 99 dice rolls take 15 minutes and challenging the supporting reference on on-board RNG seeds.

    seen · Captured here 10,172 chars
    What changed from the previous capture 18 lines
     edited: false
     body:
     🧡
    +
    +comment: p1mlbbq
    +parent: t1_p1lzdzv
    +author: CiaranCarroll
    +created_utc: 1785841598
    +edited: false
    +body:
    +>They used <10 dice rolls
    +
    +Sorry but it takes 15mins to do 99 dice rolls. Cold Card also allowed you to verify that it wasn't spoofing by using other websites like Ian Colemans on a test seed.
    +
    +If you cannot spare 15mins to secure your Bitcoin then you have no business in self-custody.
    +
    +>99.99999% of users are better off allowing good, multi-source, open-source random number generation like we do on Passport.
    +
    +>To date I have heard of zero compromised seeds that were generated using on-board RNG due to entropy issues, while there are countless examples of users losing funds due to improper dice rolls.
    +
    +Wow, this is your supporting reference?
    
    Extracted text as captured
    post: 1vf0ut0
    author: Fearless-Second-7230
    created_utc: 1785820076
    title: Coldcard post from October 10, 2021: "Retirement Attack"
    body:
    \- "What's a retirement attack?"
    
    \- COLDCARD (@COLDCARDwallet): "It's when the project makers could have a "bug" in the entropy generation for later retrieval".
    
    \_\_\_\_\_
    
    Seems that they were smart enough to launch a "dice rolls" suggestion in a critical element lacking foolproof design, knowing not all users would be paranoid enough. Like "hey, if you don't trust no problem, but...you can trust buddy, the (back)door is open." ☠️
    
    Ok no, enough of conspiracy theory continuation. We know that Coldcard's post was pure coincidence. Right?...Right? 
    
    -----
    Edit: In case you're curious on more tweets mentioning "retirement attack", here is another one: 
    
    
    @nvk - 21 Dec 20: "My money is on people screwing themselves out of their BTC before any vendor tries a retirement attack.
    
    Alternatively people could just use dice ;)."
    
    https://x.com/i/status/1341213389549412353
    
    -----
    
    A strange way to warn "alternatively people" of what you have in mind to do...but Freudian slip or parapraxis theory explains that better, in case you're curious...
    
    comment: p1lcjaa
    parent: t3_1vf0ut0
    author: VictorDanville
    created_utc: 1785820367
    edited: false
    body:
    Wow, so this really was an inside job
    
    comment: p1lcq9n
    parent: t3_1vf0ut0
    author: fuckswithboats

    Excerpt only. The complete copy is held offline and backs quotations on this site. The original publication remains the canonical public source.

  26. source content difference between and source content +24 -0

    Three new comments were posted: CoffeeAlternative647 asking what a 'Razor' is, Blade_Runner_69 suggesting it is a typo for Trezor, and a follow-up emoji from CoffeeAlternative647.

    seen · Captured here 9,419 chars
    What changed from the previous capture 24 lines
     And this asshole is gonna wind up in federal prison for rest of his life because he just couldn't help but make this post.   
     
     The perfect heist falls apart cuz the jerk off told on himself right off the rip.
    +
    +comment: p1meno4
    +parent: t1_p1m0pf3
    +author: CoffeeAlternative647
    +created_utc: 1785838809
    +edited: false
    +body:
    +Hummm, Sire ? Can you explain what is a Razor ?
    +
    +comment: p1mg1v5
    +parent: t1_p1meno4
    +author: Blade_Runner_69
    +created_utc: 1785839415
    +edited: false
    +body:
    +I think it's a typo 😅 prob means Trezor! 
    +
    +comment: p1mg81d
    +parent: t1_p1mg1v5
    +author: CoffeeAlternative647
    +created_utc: 1785839490
    +edited: false
    +body:
    +🧡
    
    Extracted text as captured
    post: 1vf0ut0
    author: Fearless-Second-7230
    created_utc: 1785820076
    title: Coldcard post from October 10, 2021: "Retirement Attack"
    body:
    \- "What's a retirement attack?"
    
    \- COLDCARD (@COLDCARDwallet): "It's when the project makers could have a "bug" in the entropy generation for later retrieval".
    
    \_\_\_\_\_
    
    Seems that they were smart enough to launch a "dice rolls" suggestion in a critical element lacking foolproof design, knowing not all users would be paranoid enough. Like "hey, if you don't trust no problem, but...you can trust buddy, the (back)door is open." ☠️
    
    Ok no, enough of conspiracy theory continuation. We know that Coldcard's post was pure coincidence. Right?...Right? 
    
    -----
    Edit: In case you're curious on more tweets mentioning "retirement attack", here is another one: 
    
    
    @nvk - 21 Dec 20: "My money is on people screwing themselves out of their BTC before any vendor tries a retirement attack.
    
    Alternatively people could just use dice ;)."
    
    https://x.com/i/status/1341213389549412353
    
    -----
    
    A strange way to warn "alternatively people" of what you have in mind to do...but Freudian slip or parapraxis theory explains that better, in case you're curious...
    
    comment: p1lcjaa
    parent: t3_1vf0ut0
    author: VictorDanville
    created_utc: 1785820367
    edited: false
    body:
    Wow, so this really was an inside job
    
    comment: p1lcq9n
    parent: t3_1vf0ut0
    author: fuckswithboats

    Excerpt only. The complete copy is held offline and backs quotations on this site. The original publication remains the canonical public source.

  27. Earliest copy held
    seen · Captured here 9,000 chars
    Extracted text as captured
    post: 1vf0ut0
    author: Fearless-Second-7230
    created_utc: 1785820076
    title: Coldcard post from October 10, 2021: "Retirement Attack"
    body:
    \- "What's a retirement attack?"
    
    \- COLDCARD (@COLDCARDwallet): "It's when the project makers could have a "bug" in the entropy generation for later retrieval".
    
    \_\_\_\_\_
    
    Seems that they were smart enough to launch a "dice rolls" suggestion in a critical element lacking foolproof design, knowing not all users would be paranoid enough. Like "hey, if you don't trust no problem, but...you can trust buddy, the (back)door is open." ☠️
    
    Ok no, enough of conspiracy theory continuation. We know that Coldcard's post was pure coincidence. Right?...Right? 
    
    -----
    Edit: In case you're curious on more tweets mentioning "retirement attack", here is another one: 
    
    
    @nvk - 21 Dec 20: "My money is on people screwing themselves out of their BTC before any vendor tries a retirement attack.
    
    Alternatively people could just use dice ;)."
    
    https://x.com/i/status/1341213389549412353
    
    -----
    
    A strange way to warn "alternatively people" of what you have in mind to do...but Freudian slip or parapraxis theory explains that better, in case you're curious...
    
    comment: p1lcjaa
    parent: t3_1vf0ut0
    author: VictorDanville
    created_utc: 1785820367
    edited: false
    body:
    Wow, so this really was an inside job
    
    comment: p1lcq9n
    parent: t3_1vf0ut0
    author: fuckswithboats

    Excerpt only. The complete copy is held offline and backs quotations on this site. The original publication remains the canonical public source.

How to check this yourself

The excerpts and plain unified diffs above show the text this project held and how it changed. To verify a quotation, compare it against the page itself or against the Internet Archive's copies, which are independent of this project.

Complete captures are held offline rather than mirrored here, so this page shows diffs and excerpts. If a quotation is ever disputed, the full copy can be produced. Ask.