COLDCARD RNG incident the public record, collected and explained
Informational only, and this site never asks for your seed words. details

Informational only. This is an open source collection of what others have published about the incident, together with an explanation of it. It is not financial, security or legal advice, and not a substitute for professional advice about your own situation. It is not affiliated with, endorsed by, or speaking for Coinkite. Material is attributed and quoted as published; where sources disagree their scenarios are kept separate with their assumptions rather than reconciled into one answer. Everything is meant to be checked against the linked evidence rather than taken on trust. Act on your own judgement about a particular situation. Editorial standards and corrections.

Do not disclose recovery material to a website, form, message or support account. This site never asks for it, and contributions containing recovery words or private keys are not accepted.

r/coldcard: whether a dice-rolled reseed on updated firmware is safe

reddit-safe-after-reseed

https://www.reddit.com/r/coldcard/comments/1vc9la8/are_we_safe_after_updating_firmware_and/

Latest reviewed change

source content difference between and

The thread gained a comment suggesting a repurposed COLDCARD could be used as a seed generator or password manager instead of being discarded.

seen +8 -0 full history below
 edited: false
 body:
 Anything is better now!
+
+comment: p2auvib
+parent: t3_1vc9la8
+author: Intelligent_Map_246
+created_utc: 1786122634

First lines only. The complete diff is in the timeline below.

Organisation
reddit
Evidence role
Community discussion
Published
not established
Source changes
2
Detected differences
2
Unreviewed
0
Copies held
3

Every check is recorded, including checks that found no text change. A detected edit is therefore bounded between two checks. The publisher's exact save time is not observable from this record. Last checked .

  1. source content difference between and Current source content +8 -0

    The thread gained a comment suggesting a repurposed COLDCARD could be used as a seed generator or password manager instead of being discarded.

    seen · Captured here 6,138 chars
    What changed from the previous capture 8 lines
     edited: false
     body:
     Anything is better now!
    +
    +comment: p2auvib
    +parent: t3_1vc9la8
    +author: Intelligent_Map_246
    +created_utc: 1786122634
    +edited: false
    +body:
    +Why throw it when you can use it as a seed generator or PW manager 
    
    Extracted text as captured
    post: 1vc9la8
    author: insubordinate_kralc
    created_utc: 1785547739
    title: Are we safe after updating firmware and generating a new seed with dice rolls? How do we even know?
    body:
    Explain it to me like I’m 15… 
    
    comment: p0zptxd
    parent: t3_1vc9la8
    author: zootreddit
    created_utc: 1785548642
    edited: false
    body:
    It was such a basic fix new seed on new firmware with added dice rolls will get you a strong private key. 
    
    If you want to verify find another offline seed generator. Roll your dices, write them down, generate seed. Then run them through updated coldcard using the dice roll import method and make sure you get same wallet/result.  Once confirmed create a new wallet with another round of dice rolls.
    
    comment: p0zxg3g
    parent: t3_1vc9la8
    author: Either_Display_6624
    created_utc: 1785551426
    edited: false
    body:
    Throw coldcard in garbage bro
    
    Buy another device ...
    
    comment: p0zz9nt
    parent: t1_p0zxg3g
    author: ironmoosen
    created_utc: 1785552100
    edited: false
    body:
    I understand the sentiment and I’m sure I won’t be buying any more coldcards, but there’s nothing wrong with using it to sign transactions so I’m not throwing mine away. 
    
    comment: p0zzqui
    parent: t1_p0zz9nt
    author: Either_Display_6624
    created_utc: 1785552277
    edited: false

    Excerpt only. The complete copy is held offline and backs quotations on this site. The original publication remains the canonical public source.

  2. source content difference between and source content +64 -0

    7 new Reddit comments were posted, including Solid_Wolverine1639.

    seen · Captured here 5,961 chars
    What changed from the previous capture 64 lines
     A) if signed tx exported by coldcard is leaking something private 
     
     B) if the coldcard gets in the wrong hand and some way to exploit is found to access your seed + passphrase 
    +
    +comment: p1no81j
    +parent: t1_p10q59k
    +author: Solid_Wolverine1639
    +created_utc: 1785853786
    +edited: false
    +body:
    +Why are you suggesting coinkite can survive in any capacity?
    +
    +comment: p1nocbm
    +parent: t1_p15ll2d
    +author: Solid_Wolverine1639
    +created_utc: 1785853818
    +edited: false
    +body:
    +Why would you even suggest they could survive?  I wouldn't give them 1 oz of possibility
    +
    +comment: p1noj02
    +parent: t1_p18o9ey
    +author: Solid_Wolverine1639
    +created_utc: 1785853868
    +edited: false
    +body:
    +In other words trash it and don't trust it
    +
    +comment: p1nolde
    +parent: t1_p15xqru
    +author: Solid_Wolverine1639
    +created_utc: 1785853885
    +edited: false
    +body:
    +It's amazing enough of the people making comments need to hear this
    +
    +comment: p1np5j6
    +parent: t1_p0zz9nt
    +author: Solid_Wolverine1639
    +created_utc: 1785854035
    +edited: false
    +body:
    +And what other possible attack vectors are there beyond the the random generator not being so random?
    +
    +Whether you know or not asking that question should be more than enough to give you the answer based on what just happened days ago...
    +
    +The devices themselves can be compromised... Beyond the generator... In fact this hack might have started with backup plans for the stubborn people that want to keep their cold card Bitcoin... Even with changes, like new seed...
    +
    +Some back door?  
    +
    +comment: p1npdko
    +parent: t1_p0zzqui
    +author: Solid_Wolverine1639
    +created_utc: 1785854094
    +edited: false
    +body:
    +Amazing that you could have a negative count on your comment...  
    +
    +Cold card maxis have been revealed!
    +
    +comment: p1npl8o
    +parent: t1_p14257u
    +author: Solid_Wolverine1639
    +created_utc: 1785854151
    +edited: false
    +body:
    +Anything is better now!
    
    Extracted text as captured
    post: 1vc9la8
    author: insubordinate_kralc
    created_utc: 1785547739
    title: Are we safe after updating firmware and generating a new seed with dice rolls? How do we even know?
    body:
    Explain it to me like I’m 15… 
    
    comment: p0zptxd
    parent: t3_1vc9la8
    author: zootreddit
    created_utc: 1785548642
    edited: false
    body:
    It was such a basic fix new seed on new firmware with added dice rolls will get you a strong private key. 
    
    If you want to verify find another offline seed generator. Roll your dices, write them down, generate seed. Then run them through updated coldcard using the dice roll import method and make sure you get same wallet/result.  Once confirmed create a new wallet with another round of dice rolls.
    
    comment: p0zxg3g
    parent: t3_1vc9la8
    author: Either_Display_6624
    created_utc: 1785551426
    edited: false
    body:
    Throw coldcard in garbage bro
    
    Buy another device ...
    
    comment: p0zz9nt
    parent: t1_p0zxg3g
    author: ironmoosen
    created_utc: 1785552100
    edited: false
    body:
    I understand the sentiment and I’m sure I won’t be buying any more coldcards, but there’s nothing wrong with using it to sign transactions so I’m not throwing mine away. 
    
    comment: p0zzqui
    parent: t1_p0zz9nt
    author: Either_Display_6624
    created_utc: 1785552277
    edited: false

    Excerpt only. The complete copy is held offline and backs quotations on this site. The original publication remains the canonical public source.

  3. Earliest copy held
    seen · Captured here 4,323 chars
    Extracted text as captured
    post: 1vc9la8
    author: insubordinate_kralc
    created_utc: 1785547739
    title: Are we safe after updating firmware and generating a new seed with dice rolls? How do we even know?
    body:
    Explain it to me like I’m 15… 
    
    comment: p0zptxd
    parent: t3_1vc9la8
    author: zootreddit
    created_utc: 1785548642
    edited: false
    body:
    It was such a basic fix new seed on new firmware with added dice rolls will get you a strong private key. 
    
    If you want to verify find another offline seed generator. Roll your dices, write them down, generate seed. Then run them through updated coldcard using the dice roll import method and make sure you get same wallet/result.  Once confirmed create a new wallet with another round of dice rolls.
    
    comment: p0zxg3g
    parent: t3_1vc9la8
    author: Either_Display_6624
    created_utc: 1785551426
    edited: false
    body:
    Throw coldcard in garbage bro
    
    Buy another device ...
    
    comment: p0zz9nt
    parent: t1_p0zxg3g
    author: ironmoosen
    created_utc: 1785552100
    edited: false
    body:
    I understand the sentiment and I’m sure I won’t be buying any more coldcards, but there’s nothing wrong with using it to sign transactions so I’m not throwing mine away. 
    
    comment: p0zzqui
    parent: t1_p0zz9nt
    author: Either_Display_6624
    created_utc: 1785552277
    edited: false

    Excerpt only. The complete copy is held offline and backs quotations on this site. The original publication remains the canonical public source.

How to check this yourself

The excerpts and plain unified diffs above show the text this project held and how it changed. To verify a quotation, compare it against the page itself or against the Internet Archive's copies, which are independent of this project.

Complete captures are held offline rather than mirrored here, so this page shows diffs and excerpts. If a quotation is ever disputed, the full copy can be produced. Ask.