COLDCARD RNG incident the public record, collected and explained
Informational only, and this site never asks for your seed words. details

Informational only. This is an open source collection of what others have published about the incident, together with an explanation of it. It is not financial, security or legal advice, and not a substitute for professional advice about your own situation. It is not affiliated with, endorsed by, or speaking for Coinkite. Material is attributed and quoted as published; where sources disagree their scenarios are kept separate with their assumptions rather than reconciled into one answer. Everything is meant to be checked against the linked evidence rather than taken on trust. Act on your own judgement about a particular situation. Editorial standards and corrections.

Do not disclose recovery material to a website, form, message or support account. This site never asks for it, and contributions containing recovery words or private keys are not accepted.

r/Bitcoin: generating a safe seed without a hardware wallet

reddit-safe-seed-without-hardware

https://www.reddit.com/r/Bitcoin/comments/1vekcn5/how_to_create_a_safe_seed_without_hardware_wallet/

Latest reviewed change

source content difference between and

A comment by Fluid-Scientist9912 asking whether the other user still uses their Coldcard and thinks it is safe now shows as [deleted] with author [deleted].

seen +2 -2 full history below
 
 comment: p1mqbxg
 parent: t1_p1mq6qg
-author: Fluid-Scientist9912
+author: [deleted]
 created_utc: 1785843518
 edited: false
 body:

First lines only. The complete diff is in the timeline below.

Organisation
reddit
Evidence role
Community discussion
Published
not established
Source changes
7
Detected differences
7
Unreviewed
0
Copies held
8

Every check is recorded, including checks that found no text change. A detected edit is therefore bounded between two checks. The publisher's exact save time is not observable from this record. Last checked .

  1. source content difference between and Current source content +2 -2

    A comment by Fluid-Scientist9912 asking whether the other user still uses their Coldcard and thinks it is safe now shows as [deleted] with author [deleted].

    seen · Captured here 26,672 chars
    What changed from the previous capture 4 lines
     
     comment: p1mqbxg
     parent: t1_p1mq6qg
    -author: Fluid-Scientist9912
    +author: [deleted]
     created_utc: 1785843518
     edited: false
     body:
    -And are you still using it ? Do you think is safe to keep using it ? 
    +[deleted]
     
     comment: p1mqwze
     parent: t1_p1mqbxg
    
    Extracted text as captured
    post: 1vekcn5
    author: unshak3n
    created_utc: 1785778844
    title: How to create a safe seed without hardware wallet?
    body:
    After the recent Coldcard  issue, simply buying a hardware wallet and trusting your life savings is not enough. Eventually, every trusted third party will fail or be compromised, whether it's a hardware wallet vendor, firmware, the supply chain, an RNG implementation, AI, or just a bug.
    
    If the goal is simply create a single 256-bit seed, write it down once, and keep DCA'ing into it for years, what is the best possible way to generate that seed without relying on third parties and hardware wallets?
    
    I'm genuinely curious what the current consensus is.
    
    Until a truly secure, third-party-proof solution exists, I'll stick with ETF.
    
    comment: p1hmrex
    parent: t3_1vekcn5
    author: Similar_Scar7089
    created_utc: 1785779081
    edited: false
    body:
    Seedsigner.
    
    comment: p1hn24n
    parent: t3_1vekcn5
    author: sing2nite
    created_utc: 1785779154
    edited: false
    body:
    Ian Coleman offline tool
    
    comment: p1holq8
    parent: t3_1vekcn5
    author: doctrgiggles
    created_utc: 1785779536
    edited: false
    body:
    Hey so I've been in this space a long time and seeing all this discussion about Coldcard and generating seeds has made me want to ask: why is nobody just booting up a livedisk of a reputable distro on a machine without network connectivity and using basic software to generate wallets? 256 bits of high-quality total entropy is easy to achieve on a modern machine, especially one that can pull entropy from mouse movements.
    
    It seems obvious to me that the best way to do anything in this space is by relying not on small, commercial operators but extremely large and old communities that are well-audited. Why not use a Debian live environment with no network connectivity, let it run for a while to collect entropy bits, and use it for this purpose? Is the answer that this community doesn't know how to work these tools?
    
    comment: p1hotbh

    Excerpt only. The complete copy is held offline and backs quotations on this site. The original publication remains the canonical public source.

  2. source content difference between and source content +8 -0

    The Reddit thread gained 1 new comment.

    seen · Captured here 26,742 chars
    What changed from the previous capture 8 lines
     body:
     Where can i order ?
     
    +comment: p1pf8c5
    +parent: t1_p1p7y56
    +author: DRAGULA85
    +created_utc: 1785869691
    +edited: false
    +body:
    +[https://coldcard.com/](https://coldcard.com/)
    +
     more-stub: parent t1_p1mxyeo count 0
    
    Extracted text as captured
    post: 1vekcn5
    author: unshak3n
    created_utc: 1785778844
    title: How to create a safe seed without hardware wallet?
    body:
    After the recent Coldcard  issue, simply buying a hardware wallet and trusting your life savings is not enough. Eventually, every trusted third party will fail or be compromised, whether it's a hardware wallet vendor, firmware, the supply chain, an RNG implementation, AI, or just a bug.
    
    If the goal is simply create a single 256-bit seed, write it down once, and keep DCA'ing into it for years, what is the best possible way to generate that seed without relying on third parties and hardware wallets?
    
    I'm genuinely curious what the current consensus is.
    
    Until a truly secure, third-party-proof solution exists, I'll stick with ETF.
    
    comment: p1hmrex
    parent: t3_1vekcn5
    author: Similar_Scar7089
    created_utc: 1785779081
    edited: false
    body:
    Seedsigner.
    
    comment: p1hn24n
    parent: t3_1vekcn5
    author: sing2nite
    created_utc: 1785779154
    edited: false
    body:
    Ian Coleman offline tool
    
    comment: p1holq8
    parent: t3_1vekcn5
    author: doctrgiggles
    created_utc: 1785779536
    edited: false
    body:
    Hey so I've been in this space a long time and seeing all this discussion about Coldcard and generating seeds has made me want to ask: why is nobody just booting up a livedisk of a reputable distro on a machine without network connectivity and using basic software to generate wallets? 256 bits of high-quality total entropy is easy to achieve on a modern machine, especially one that can pull entropy from mouse movements.
    
    It seems obvious to me that the best way to do anything in this space is by relying not on small, commercial operators but extremely large and old communities that are well-audited. Why not use a Debian live environment with no network connectivity, let it run for a while to collect entropy bits, and use it for this purpose? Is the answer that this community doesn't know how to work these tools?
    
    comment: p1hotbh

    Excerpt only. The complete copy is held offline and backs quotations on this site. The original publication remains the canonical public source.

  3. source content difference between and source content +16 -0

    The Reddit thread gained 2 new comments.

    seen · Captured here 26,596 chars
    What changed from the previous capture 16 lines
     body:
     Ikr, global adoption my ass
     
    +comment: p1p7o5y
    +parent: t1_p1jz3fx
    +author: Porcellanidae
    +created_utc: 1785867798
    +edited: false
    +body:
    +Throw away, as you checked your formula for that one on your computer 
    +
    +comment: p1p7y56
    +parent: t1_p1i1dkv
    +author: Porcellanidae
    +created_utc: 1785867866
    +edited: false
    +body:
    +Where can i order ?
    +
     more-stub: parent t1_p1mxyeo count 0
    
    Extracted text as captured
    post: 1vekcn5
    author: unshak3n
    created_utc: 1785778844
    title: How to create a safe seed without hardware wallet?
    body:
    After the recent Coldcard  issue, simply buying a hardware wallet and trusting your life savings is not enough. Eventually, every trusted third party will fail or be compromised, whether it's a hardware wallet vendor, firmware, the supply chain, an RNG implementation, AI, or just a bug.
    
    If the goal is simply create a single 256-bit seed, write it down once, and keep DCA'ing into it for years, what is the best possible way to generate that seed without relying on third parties and hardware wallets?
    
    I'm genuinely curious what the current consensus is.
    
    Until a truly secure, third-party-proof solution exists, I'll stick with ETF.
    
    comment: p1hmrex
    parent: t3_1vekcn5
    author: Similar_Scar7089
    created_utc: 1785779081
    edited: false
    body:
    Seedsigner.
    
    comment: p1hn24n
    parent: t3_1vekcn5
    author: sing2nite
    created_utc: 1785779154
    edited: false
    body:
    Ian Coleman offline tool
    
    comment: p1holq8
    parent: t3_1vekcn5
    author: doctrgiggles
    created_utc: 1785779536
    edited: false
    body:
    Hey so I've been in this space a long time and seeing all this discussion about Coldcard and generating seeds has made me want to ask: why is nobody just booting up a livedisk of a reputable distro on a machine without network connectivity and using basic software to generate wallets? 256 bits of high-quality total entropy is easy to achieve on a modern machine, especially one that can pull entropy from mouse movements.
    
    It seems obvious to me that the best way to do anything in this space is by relying not on small, commercial operators but extremely large and old communities that are well-audited. Why not use a Debian live environment with no network connectivity, let it run for a while to collect entropy bits, and use it for this purpose? Is the answer that this community doesn't know how to work these tools?
    
    comment: p1hotbh

    Excerpt only. The complete copy is held offline and backs quotations on this site. The original publication remains the canonical public source.

  4. source content difference between and source content +9 -9

    An existing Reddit comment was edited or removed.

    seen · Captured here 26,299 chars
    What changed from the previous capture 18 lines
     parent: t3_1vekcn5
     author: LuckySage77
     created_utc: 1785783025
    -edited: 1785783395
    -body:
    -Disclaimer: I'm no expert, please DYOR. However, from my own research/digging on the topic: you could potentially create a seed using a software wallet on a well-trusted air-gapped computer/laptop (*disconnected from the internet/LAN*). Sparrow wallet for example should be able to do this. The seed generation uses the OS's cryptographic libs "under the hood". On linux, entropy would be generated at the kernel level (i.e via /dev/random).
    +edited: 1785860306
    +body:
    +Disclaimer: I'm no expert, please DYOR. However, from my own research/digging on the topic: you could potentially create a seed using a software wallet on a well-trusted air-gapped computer/laptop (*disconnected from the internet/LAN*). Bitcoin core or Sparrow wallet for example should be able to do this. The seed generation uses the OS's cryptographic libs "under the hood". On linux, entropy would be generated at the kernel level (i.e via /dev/random).
     
     In addition, you should probably add a passphrase to the seed. Offline PW generator, 7+ words. If the seed is compromised, you're basically covered against brute-force with at least 7 words.
     
     
     comment: p1mc2ri
     parent: t1_p1iyzyr
    -author: Fluid-Scientist9912
    +author: [deleted]
     created_utc: 1785837641
     edited: false
     body:
    -So you are still using the seed generated by mk4 with 100+ dice rolls ? 
    +[deleted]
     
     comment: p1mfmd9
     parent: t3_1vekcn5
     
     comment: p1mr32n
     parent: t1_p1mqwze
    -author: Fluid-Scientist9912
    +author: [deleted]
     created_utc: 1785843788
     edited: false
     body:
    -Thanks man appreciate 
    +[deleted]
     
     comment: p1mss4h
     parent: t1_p1mr32n
     
     comment: p1mtpg9
     parent: t1_p1mss4h
    -author: Fluid-Scientist9912
    +author: [deleted]
     created_utc: 1785844720
     edited: false
     body:
    -Thank you. Can I add a passphrase to a seed that I’ve already have ? 
    +[deleted]
     
     comment: p1mwrvl
     parent: t1_p1mtpg9
    
    Extracted text as captured
    post: 1vekcn5
    author: unshak3n
    created_utc: 1785778844
    title: How to create a safe seed without hardware wallet?
    body:
    After the recent Coldcard  issue, simply buying a hardware wallet and trusting your life savings is not enough. Eventually, every trusted third party will fail or be compromised, whether it's a hardware wallet vendor, firmware, the supply chain, an RNG implementation, AI, or just a bug.
    
    If the goal is simply create a single 256-bit seed, write it down once, and keep DCA'ing into it for years, what is the best possible way to generate that seed without relying on third parties and hardware wallets?
    
    I'm genuinely curious what the current consensus is.
    
    Until a truly secure, third-party-proof solution exists, I'll stick with ETF.
    
    comment: p1hmrex
    parent: t3_1vekcn5
    author: Similar_Scar7089
    created_utc: 1785779081
    edited: false
    body:
    Seedsigner.
    
    comment: p1hn24n
    parent: t3_1vekcn5
    author: sing2nite
    created_utc: 1785779154
    edited: false
    body:
    Ian Coleman offline tool
    
    comment: p1holq8
    parent: t3_1vekcn5
    author: doctrgiggles
    created_utc: 1785779536
    edited: false
    body:
    Hey so I've been in this space a long time and seeing all this discussion about Coldcard and generating seeds has made me want to ask: why is nobody just booting up a livedisk of a reputable distro on a machine without network connectivity and using basic software to generate wallets? 256 bits of high-quality total entropy is easy to achieve on a modern machine, especially one that can pull entropy from mouse movements.
    
    It seems obvious to me that the best way to do anything in this space is by relying not on small, commercial operators but extremely large and old communities that are well-audited. Why not use a Debian live environment with no network connectivity, let it run for a while to collect entropy bits, and use it for this purpose? Is the answer that this community doesn't know how to work these tools?
    
    comment: p1hotbh

    Excerpt only. The complete copy is held offline and backs quotations on this site. The original publication remains the canonical public source.

  5. source content difference between and source content +8 -0

    1 new Reddit comment was posted, by Bryght7.

    seen · Captured here 26,449 chars
    What changed from the previous capture 8 lines
     body:
     Almost the opposite. I'm far enough into these spaces that I'm confident in my ability to create and operate secure machines. I'm obviously cautious about key management, but there are plenty of people out there using encryption technologies similar to Bitcoin with higher stakes and without the luxury of hardware wallets to keep them safe. Dissidents and reporters in plenty of places are targeted by state-level actors and still they need to be able to keep their machines secure while still actively using them. 
     
    +comment: p1o42n9
    +parent: t1_p1j7z5w
    +author: Bryght7
    +created_utc: 1785857937
    +edited: false
    +body:
    +Ikr, global adoption my ass
    +
     more-stub: parent t1_p1mxyeo count 0
    
    Extracted text as captured
    post: 1vekcn5
    author: unshak3n
    created_utc: 1785778844
    title: How to create a safe seed without hardware wallet?
    body:
    After the recent Coldcard  issue, simply buying a hardware wallet and trusting your life savings is not enough. Eventually, every trusted third party will fail or be compromised, whether it's a hardware wallet vendor, firmware, the supply chain, an RNG implementation, AI, or just a bug.
    
    If the goal is simply create a single 256-bit seed, write it down once, and keep DCA'ing into it for years, what is the best possible way to generate that seed without relying on third parties and hardware wallets?
    
    I'm genuinely curious what the current consensus is.
    
    Until a truly secure, third-party-proof solution exists, I'll stick with ETF.
    
    comment: p1hmrex
    parent: t3_1vekcn5
    author: Similar_Scar7089
    created_utc: 1785779081
    edited: false
    body:
    Seedsigner.
    
    comment: p1hn24n
    parent: t3_1vekcn5
    author: sing2nite
    created_utc: 1785779154
    edited: false
    body:
    Ian Coleman offline tool
    
    comment: p1holq8
    parent: t3_1vekcn5
    author: doctrgiggles
    created_utc: 1785779536
    edited: false
    body:
    Hey so I've been in this space a long time and seeing all this discussion about Coldcard and generating seeds has made me want to ask: why is nobody just booting up a livedisk of a reputable distro on a machine without network connectivity and using basic software to generate wallets? 256 bits of high-quality total entropy is easy to achieve on a modern machine, especially one that can pull entropy from mouse movements.
    
    It seems obvious to me that the best way to do anything in this space is by relying not on small, commercial operators but extremely large and old communities that are well-audited. Why not use a Debian live environment with no network connectivity, let it run for a while to collect entropy bits, and use it for this purpose? Is the answer that this community doesn't know how to work these tools?
    
    comment: p1hotbh

    Excerpt only. The complete copy is held offline and backs quotations on this site. The original publication remains the canonical public source.

  6. source content difference between and source content +8 -0

    1 new Reddit comment was posted, including doctrgiggles.

    seen · Captured here 26,324 chars
    What changed from the previous capture 8 lines
     
     BUT, it will also complicate your operation with the wallet, as you have to type the passphrase to use it
     
    +comment: p1njmoq
    +parent: t1_p1ir21r
    +author: doctrgiggles
    +created_utc: 1785852557
    +edited: false
    +body:
    +Almost the opposite. I'm far enough into these spaces that I'm confident in my ability to create and operate secure machines. I'm obviously cautious about key management, but there are plenty of people out there using encryption technologies similar to Bitcoin with higher stakes and without the luxury of hardware wallets to keep them safe. Dissidents and reporters in plenty of places are targeted by state-level actors and still they need to be able to keep their machines secure while still actively using them. 
    +
     more-stub: parent t1_p1mxyeo count 0
    
    Extracted text as captured
    post: 1vekcn5
    author: unshak3n
    created_utc: 1785778844
    title: How to create a safe seed without hardware wallet?
    body:
    After the recent Coldcard  issue, simply buying a hardware wallet and trusting your life savings is not enough. Eventually, every trusted third party will fail or be compromised, whether it's a hardware wallet vendor, firmware, the supply chain, an RNG implementation, AI, or just a bug.
    
    If the goal is simply create a single 256-bit seed, write it down once, and keep DCA'ing into it for years, what is the best possible way to generate that seed without relying on third parties and hardware wallets?
    
    I'm genuinely curious what the current consensus is.
    
    Until a truly secure, third-party-proof solution exists, I'll stick with ETF.
    
    comment: p1hmrex
    parent: t3_1vekcn5
    author: Similar_Scar7089
    created_utc: 1785779081
    edited: false
    body:
    Seedsigner.
    
    comment: p1hn24n
    parent: t3_1vekcn5
    author: sing2nite
    created_utc: 1785779154
    edited: false
    body:
    Ian Coleman offline tool
    
    comment: p1holq8
    parent: t3_1vekcn5
    author: doctrgiggles
    created_utc: 1785779536
    edited: false
    body:
    Hey so I've been in this space a long time and seeing all this discussion about Coldcard and generating seeds has made me want to ask: why is nobody just booting up a livedisk of a reputable distro on a machine without network connectivity and using basic software to generate wallets? 256 bits of high-quality total entropy is easy to achieve on a modern machine, especially one that can pull entropy from mouse movements.
    
    It seems obvious to me that the best way to do anything in this space is by relying not on small, commercial operators but extremely large and old communities that are well-audited. Why not use a Debian live environment with no network connectivity, let it run for a while to collect entropy bits, and use it for this purpose? Is the answer that this community doesn't know how to work these tools?
    
    comment: p1hotbh

    Excerpt only. The complete copy is held offline and backs quotations on this site. The original publication remains the canonical public source.

  7. source content difference between and source content +106 -0

    10 new Reddit comments were posted, including Fluid-Scientist9912,tchjntr,JumpProfessional3372.

    seen · Captured here 25,705 chars
    What changed from the previous capture 106 lines
     Only 1024 coin tosses or \~614 dice throws for bias free random?
     
     If I was some obscure bitcoin billionaire I surely would invest that extra hour ;)
    +
    +comment: p1mc2ri
    +parent: t1_p1iyzyr
    +author: Fluid-Scientist9912
    +created_utc: 1785837641
    +edited: false
    +body:
    +So you are still using the seed generated by mk4 with 100+ dice rolls ? 
    +
    +comment: p1mfmd9
    +parent: t3_1vekcn5
    +author: tchjntr
    +created_utc: 1785839231
    +edited: false
    +body:
    +>If the goal is simply create a single 256-bit seed, write it down once, and keep DCA'ing into it for years, what is the best possible way to generate that seed without relying on third parties and hardware wallets?
    +
    +As tedious as it might seem, this is what I did to generate a seed phrase: [https://armantheparman.com/dicev2/](https://armantheparman.com/dicev2/)
    +
    +I put a passphrase on top of it as well which I store in my password manager (just the passphrase, not the seed of course). I don't even own a so called "hardware wallet". I have a watch only wallet but I sign transactions with another device that never connects to any network. No need to trust any third party.
    +
    +comment: p1mq6qg
    +parent: t1_p1mc2ri
    +author: JumpProfessional3372
    +created_utc: 1785843466
    +edited: false
    +body:
    +Yes but the entropy wasn't generated by MK4. It was generated by me rolling the dice. MK4 only converted the 100+ numbers into a seed phrase. But I also used a python script to do the same to ensure the MK4 was converting to the same seed phrase as the script.
    +
    +comment: p1mqbxg
    +parent: t1_p1mq6qg
    +author: Fluid-Scientist9912
    +created_utc: 1785843518
    +edited: false
    +body:
    +And are you still using it ? Do you think is safe to keep using it ? 
    +
    +comment: p1mqwze
    +parent: t1_p1mqbxg
    +author: JumpProfessional3372
    +created_utc: 1785843728
    +edited: false
    +body:
    +This is the script i used to verify ( on a linux live usb ) that the  MK4 was giving me the same seed phrase of the 100+ manual dice rolls
    +
    +[https://coldcard.com/docs/rolls.py](https://coldcard.com/docs/rolls.py)
    +
    +Yes. Many are still using it. The tremendous bug found, so far, seems to be only impacting the seeds that were generated with a Random Number Generator from coldcard wallet. The paranoid guide from cold card suggest the user to manually roll the dices in case they do not trust the Random Number generator from the hardware wallet (and doing this was the right choice because, look, that RNG functionality was bugged).
    +
    +TLDR: If you have a coldcard and you followed their paranoid guide, you should not be affected by this mess. At least not as per the current knowledge.
    +
    +comment: p1mr32n
    +parent: t1_p1mqwze
    +author: Fluid-Scientist9912
    +created_utc: 1785843788
    +edited: false
    +body:
    +Thanks man appreciate 
    +
    +comment: p1mss4h
    +parent: t1_p1mr32n
    +author: JumpProfessional3372
    +created_utc: 1785844395
    +edited: 1785844615
    +body:
    +If you have a CC... Just be completely sure that you used the manual dice roll method, if you let the CC generate your entropy, then move asap to a new btc wallet.
    +
    +If you are paranoid and you still do not trust that the CC will correctly convert 100+ numbers into the right seed (and not a pre-made seed or something like that). Well in that case you can run the same numbers with that [rolls.py](http://rolls.py) which is supposed to be a simple script and used by the CC wallet. Of course, by doing this, you will expose your seed to a new device (the device running the live linux OS). But this should be extremely low risk if it is done by an experience person, with no internet, no bt, fully formatting the live linux usb, etc. At least you will sleep knowing MK4 converted 100 manual rolls to a seed using a std approach.
    +
    +I THINK if you put the same 100+ numbers into other methods (**SeedSigner**, **Sparrow Wallet's dice input**, and **Ian Coleman's BIP39 tool in Coldcard mode)** you will get the exact same seed phrase. I quickly asked the AI and according to it, they all seem to be using the same code to convert random numbers into a seed phrase.
    +
    +\---
    +
    +One more thing, do not use a seed without a passphrase, adding a pasphrase is a must, you never know if tomorrow your seed will be leaked (e.g. you had a backup and was lost/stolen). Then a passphrase will add a second layer of security.
    +
    +comment: p1mtpg9
    +parent: t1_p1mss4h
    +author: Fluid-Scientist9912
    +created_utc: 1785844720
    +edited: false
    +body:
    +Thank you. Can I add a passphrase to a seed that I’ve already have ? 
    +
    +comment: p1mwrvl
    +parent: t1_p1mtpg9
    +author: JumpProfessional3372
    +created_utc: 1785845770
    +edited: 1785846016
    +body:
    +You can, but the result will become a new wallet with 0 funds.
    +
    +Old wallet = private key made out of a seed-phrase.
    +
    +New wallet = private key made out of combination of seed-phrase + passphrase.
    +
    +comment: p1mxyeo
    +parent: t1_p1mtpg9
    +author: JumpProfessional3372
    +created_utc: 1785846163
    +edited: false
    +body:
    +If you have a seed and you add a passphrase simple like just one letter "a", then that would be very easy to guess by anyone who has your seed. If you share your seed but your passphrase is "‚hioH7 8OBNT&15465)(8973/&%T$!\[\]añ" then it is a lot harder to guess and that will give you extra time to move your funds into a new wallet. 
    +
    +BUT, it will also complicate your operation with the wallet, as you have to type the passphrase to use it
    +
    +more-stub: parent t1_p1mxyeo count 0
    
    Extracted text as captured
    post: 1vekcn5
    author: unshak3n
    created_utc: 1785778844
    title: How to create a safe seed without hardware wallet?
    body:
    After the recent Coldcard  issue, simply buying a hardware wallet and trusting your life savings is not enough. Eventually, every trusted third party will fail or be compromised, whether it's a hardware wallet vendor, firmware, the supply chain, an RNG implementation, AI, or just a bug.
    
    If the goal is simply create a single 256-bit seed, write it down once, and keep DCA'ing into it for years, what is the best possible way to generate that seed without relying on third parties and hardware wallets?
    
    I'm genuinely curious what the current consensus is.
    
    Until a truly secure, third-party-proof solution exists, I'll stick with ETF.
    
    comment: p1hmrex
    parent: t3_1vekcn5
    author: Similar_Scar7089
    created_utc: 1785779081
    edited: false
    body:
    Seedsigner.
    
    comment: p1hn24n
    parent: t3_1vekcn5
    author: sing2nite
    created_utc: 1785779154
    edited: false
    body:
    Ian Coleman offline tool
    
    comment: p1holq8
    parent: t3_1vekcn5
    author: doctrgiggles
    created_utc: 1785779536
    edited: false
    body:
    Hey so I've been in this space a long time and seeing all this discussion about Coldcard and generating seeds has made me want to ask: why is nobody just booting up a livedisk of a reputable distro on a machine without network connectivity and using basic software to generate wallets? 256 bits of high-quality total entropy is easy to achieve on a modern machine, especially one that can pull entropy from mouse movements.
    
    It seems obvious to me that the best way to do anything in this space is by relying not on small, commercial operators but extremely large and old communities that are well-audited. Why not use a Debian live environment with no network connectivity, let it run for a while to collect entropy bits, and use it for this purpose? Is the answer that this community doesn't know how to work these tools?
    
    comment: p1hotbh

    Excerpt only. The complete copy is held offline and backs quotations on this site. The original publication remains the canonical public source.

  8. Earliest copy held
    seen · Captured here 20,568 chars
    Extracted text as captured
    post: 1vekcn5
    author: unshak3n
    created_utc: 1785778844
    title: How to create a safe seed without hardware wallet?
    body:
    After the recent Coldcard  issue, simply buying a hardware wallet and trusting your life savings is not enough. Eventually, every trusted third party will fail or be compromised, whether it's a hardware wallet vendor, firmware, the supply chain, an RNG implementation, AI, or just a bug.
    
    If the goal is simply create a single 256-bit seed, write it down once, and keep DCA'ing into it for years, what is the best possible way to generate that seed without relying on third parties and hardware wallets?
    
    I'm genuinely curious what the current consensus is.
    
    Until a truly secure, third-party-proof solution exists, I'll stick with ETF.
    
    comment: p1hmrex
    parent: t3_1vekcn5
    author: Similar_Scar7089
    created_utc: 1785779081
    edited: false
    body:
    Seedsigner.
    
    comment: p1hn24n
    parent: t3_1vekcn5
    author: sing2nite
    created_utc: 1785779154
    edited: false
    body:
    Ian Coleman offline tool
    
    comment: p1holq8
    parent: t3_1vekcn5
    author: doctrgiggles
    created_utc: 1785779536
    edited: false
    body:
    Hey so I've been in this space a long time and seeing all this discussion about Coldcard and generating seeds has made me want to ask: why is nobody just booting up a livedisk of a reputable distro on a machine without network connectivity and using basic software to generate wallets? 256 bits of high-quality total entropy is easy to achieve on a modern machine, especially one that can pull entropy from mouse movements.
    
    It seems obvious to me that the best way to do anything in this space is by relying not on small, commercial operators but extremely large and old communities that are well-audited. Why not use a Debian live environment with no network connectivity, let it run for a while to collect entropy bits, and use it for this purpose? Is the answer that this community doesn't know how to work these tools?
    
    comment: p1hotbh

    Excerpt only. The complete copy is held offline and backs quotations on this site. The original publication remains the canonical public source.

How to check this yourself

The excerpts and plain unified diffs above show the text this project held and how it changed. To verify a quotation, compare it against the page itself or against the Internet Archive's copies, which are independent of this project.

Complete captures are held offline rather than mirrored here, so this page shows diffs and excerpts. If a quotation is ever disputed, the full copy can be produced. Ask.