r/Bitcoin: why affected COLDCARDs did not produce duplicate addresses
reddit-same-address-collision-question
https://www.reddit.com/r/Bitcoin/comments/1vemf3k/how_come_multiple_same_addresses_werent_created/
Latest reviewed change
source content difference between and
Two comments were removed or replaced with a deleted-account placeholder, including a claim about earlier COLDCARD losses and a statement about hash collisions.
body:
lol, a typo obviously. I wrote it correctly the previous sentence.
-comment: p1k5nrd
-parent: t1_p1i45ke
-author: OldHamburger7923
-created_utc: 1785804673
-edited: false
First lines only. The complete diff is in the timeline below.
- Organisation
- Evidence role
- Community discussion
- Published
- not established
- Source changes
- 4
- Detected differences
- 4
- Unreviewed
- 0
- Copies held
- 5
Every check is recorded, including checks that found no text change. A detected edit is therefore bounded between two checks. The publisher's exact save time is not observable from this record. Last checked .
This post is held twice: here, with this project's own note on why it matters, and again as part of the conversation captured at , which is polled for changes. Both copies are the same post; neither is a separate event.
Snapshot and diff bodies for this chain monitor are held in the local evidence archive but withheld from the public site because they can contain the addresses of people who published nothing themselves. Capture times and reviewed change summaries remain available below.
Held captures
-
Two comments were removed or replaced with a deleted-account placeholder, including a claim about earlier COLDCARD losses and a statement about hash collisions.
Recovered from the Internet Archive rather than captured by this project. The row records that third-party provenance separately from captures made by this project.
What changed from the previous capture 12 lines
body: lol, a typo obviously. I wrote it correctly the previous sentence. -comment: p1k5nrd -parent: t1_p1i45ke -author: OldHamburger7923 -created_utc: 1785804673 -edited: false -body: -There was at least two people posting about losing their funds off coldcard in the last few years. - comment: p1k5z39 parent: t1_p1ica5d -author: OldHamburger7923 +author: [deleted] created_utc: 1785804775 edited: false body: -Hash collisions don't require the exact same inputs. +[deleted] comment: p1mo5q0 parent: t1_p1jciijExtracted text as captured
post: 1vemf3k author: bellydisguised created_utc: 1785783305 title: How come multiple same addresses weren’t created by affected Coldcards? body: If hackers were able to find these addresses rather easily, and the randomness wasn’t all that random after all, how come there weren’t “random” addresses made for users that were already in use? comment: p1i40mg parent: t3_1vemf3k author: groundkittenbeef created_utc: 1785783481 edited: false body: Wut? comment: p1i45ke parent: t3_1vemf3k author: the_bitcoin_kid created_utc: 1785783516 edited: false body: Good question. In short, it seems the key space was large enough over the short term to avoid a collision. There were thousands of customers, but a brute force attack generates far more seeds in a short period of time. Over a long enough time period there could have been a collision. comment: p1i51lo parent: t3_1vemf3k author: qwertyuiop121314321 created_utc: 1785783743 edited: false body: Part of the RNG used boot time from the device. So two users that booted their device at the same time, would cause a possible address collision, having the same addresses.Excerpt only. The complete copy is held offline and backs quotations on this site. The original publication remains the canonical public source.
-
1 new Reddit comment was posted, by DragonflyBoom, arguing that different 40-bit inputs cannot collide after expansion to a BIP39 seed.
Recovered from the Internet Archive rather than captured by this project. The row records that third-party provenance separately from captures made by this project.
What changed from the previous capture 8 lines
* **Your Mk3 seed colliding with another among 1 million vulnerable seeds:** about **1 in 1.1 million** Rare enough to chalk any instances up to user error, not rare enough to say it never happened. + +comment: p1o9kr3 +parent: t1_p1k5z39 +author: DragonflyBoom +created_utc: 1785859329 +edited: false +body: +ColdCards entropy was 40 bits and a BIP39 seed has at least 128 bits. So it's impossible for two different numbers in the 40 bit range to produce the same hash. You get collisions with larger data sets if they are reduced to 128 bits (which is also very very unlikely).Extracted text as captured
post: 1vemf3k author: bellydisguised created_utc: 1785783305 title: How come multiple same addresses weren’t created by affected Coldcards? body: If hackers were able to find these addresses rather easily, and the randomness wasn’t all that random after all, how come there weren’t “random” addresses made for users that were already in use? comment: p1i40mg parent: t3_1vemf3k author: groundkittenbeef created_utc: 1785783481 edited: false body: Wut? comment: p1i45ke parent: t3_1vemf3k author: the_bitcoin_kid created_utc: 1785783516 edited: false body: Good question. In short, it seems the key space was large enough over the short term to avoid a collision. There were thousands of customers, but a brute force attack generates far more seeds in a short period of time. Over a long enough time period there could have been a collision. comment: p1i51lo parent: t3_1vemf3k author: qwertyuiop121314321 created_utc: 1785783743 edited: false body: Part of the RNG used boot time from the device. So two users that booted their device at the same time, would cause a possible address collision, having the same addresses.Excerpt only. The complete copy is held offline and backs quotations on this site. The original publication remains the canonical public source.
-
1 new Reddit comment was posted, by marvelish, quoting an AI-generated comparison of vulnerable-seed collision odds.
Recovered from the Internet Archive rather than captured by this project. The row records that third-party provenance separately from captures made by this project.
What changed from the previous capture 13 lines
edited: false body: Yea, but not being called at all effectively results in a very weak RNG. Some RNG was still even in that testing PRNG version that was being called instead, just far less of it. And the device ID was one source of entropy of that weak PRG, making it output at least not always the same thing. But some small space of 2\^40, together with a couple other weak sources. + +comment: p1nv7vh +parent: t3_1vemf3k +author: marvelish +created_utc: 1785855629 +edited: false +body: +from ChatGPT: + +* **Powerball jackpot:** about **1 in 292 million** +* **Your Mk3 seed colliding with another among 1 million vulnerable seeds:** about **1 in 1.1 million** + +Rare enough to chalk any instances up to user error, not rare enough to say it never happened.Extracted text as captured
post: 1vemf3k author: bellydisguised created_utc: 1785783305 title: How come multiple same addresses weren’t created by affected Coldcards? body: If hackers were able to find these addresses rather easily, and the randomness wasn’t all that random after all, how come there weren’t “random” addresses made for users that were already in use? comment: p1i40mg parent: t3_1vemf3k author: groundkittenbeef created_utc: 1785783481 edited: false body: Wut? comment: p1i45ke parent: t3_1vemf3k author: the_bitcoin_kid created_utc: 1785783516 edited: false body: Good question. In short, it seems the key space was large enough over the short term to avoid a collision. There were thousands of customers, but a brute force attack generates far more seeds in a short period of time. Over a long enough time period there could have been a collision. comment: p1i51lo parent: t3_1vemf3k author: qwertyuiop121314321 created_utc: 1785783743 edited: false body: Part of the RNG used boot time from the device. So two users that booted their device at the same time, would cause a possible address collision, having the same addresses.Excerpt only. The complete copy is held offline and backs quotations on this site. The original publication remains the canonical public source.
-
2 new Reddit comments were posted, including Icy_Giraffe_21,skr_replicator.
Recovered from the Internet Archive rather than captured by this project. The row records that third-party provenance separately from captures made by this project.
What changed from the previous capture 16 lines
edited: false body: Hash collisions don't require the exact same inputs. + +comment: p1mo5q0 +parent: t1_p1jciij +author: Icy_Giraffe_21 +created_utc: 1785842707 +edited: false +body: +RNG wasn't weak. It was never called upon during the creation of the seed. All of coldcards hardware is top notch and sound. They chose not to use it + +comment: p1moo6t +parent: t1_p1mo5q0 +author: skr_replicator +created_utc: 1785842903 +edited: false +body: +Yea, but not being called at all effectively results in a very weak RNG. Some RNG was still even in that testing PRNG version that was being called instead, just far less of it. And the device ID was one source of entropy of that weak PRG, making it output at least not always the same thing. But some small space of 2\^40, together with a couple other weak sources.Extracted text as captured
post: 1vemf3k author: bellydisguised created_utc: 1785783305 title: How come multiple same addresses weren’t created by affected Coldcards? body: If hackers were able to find these addresses rather easily, and the randomness wasn’t all that random after all, how come there weren’t “random” addresses made for users that were already in use? comment: p1i40mg parent: t3_1vemf3k author: groundkittenbeef created_utc: 1785783481 edited: false body: Wut? comment: p1i45ke parent: t3_1vemf3k author: the_bitcoin_kid created_utc: 1785783516 edited: false body: Good question. In short, it seems the key space was large enough over the short term to avoid a collision. There were thousands of customers, but a brute force attack generates far more seeds in a short period of time. Over a long enough time period there could have been a collision. comment: p1i51lo parent: t3_1vemf3k author: qwertyuiop121314321 created_utc: 1785783743 edited: false body: Part of the RNG used boot time from the device. So two users that booted their device at the same time, would cause a possible address collision, having the same addresses.Excerpt only. The complete copy is held offline and backs quotations on this site. The original publication remains the canonical public source.
-
Recovered from the Internet Archive rather than captured by this project. The row records that third-party provenance separately from captures made by this project.
What changed from the previous capture 0 lines
Extracted text as captured
post: 1vemf3k author: bellydisguised created_utc: 1785783305 title: How come multiple same addresses weren’t created by affected Coldcards? body: If hackers were able to find these addresses rather easily, and the randomness wasn’t all that random after all, how come there weren’t “random” addresses made for users that were already in use? comment: p1i40mg parent: t3_1vemf3k author: groundkittenbeef created_utc: 1785783481 edited: false body: Wut? comment: p1i45ke parent: t3_1vemf3k author: the_bitcoin_kid created_utc: 1785783516 edited: false body: Good question. In short, it seems the key space was large enough over the short term to avoid a collision. There were thousands of customers, but a brute force attack generates far more seeds in a short period of time. Over a long enough time period there could have been a collision. comment: p1i51lo parent: t3_1vemf3k author: qwertyuiop121314321 created_utc: 1785783743 edited: false body: Part of the RNG used boot time from the device. So two users that booted their device at the same time, would cause a possible address collision, having the same addresses.Excerpt only. The complete copy is held offline and backs quotations on this site. The original publication remains the canonical public source.
0 presentation-noise differences. Sidebar, ticker and other page chrome churn that our review classified as not being changes to what the source says.
The excerpts and plain unified diffs above show the text this project held and how it changed. To verify a quotation, compare it against the page itself or against the Internet Archive's copies, which are independent of this project.
Complete captures are held offline rather than mirrored here, so this page shows diffs and excerpts. If a quotation is ever disputed, the full copy can be produced. Ask.
Compare the screenshot or a quotation against the original while it is available.