r/Bitcoin: birthday-bound estimate of seed collisions from reduced entropy
reddit-seed-collision-odds
https://www.reddit.com/r/Bitcoin/comments/1vdr94r/93000_coldcardgenerated_seeds_is_all_it_takes_for/
Latest reviewed change
source content difference between and
The Reddit thread gained a new participant comment suggesting earlier 2021-2022 thefts could have been organic seed collisions.
Yo fuck a coinkite.
So glad ColdCard wasn't my first device.
+
+comment: p2cj9wr
+parent: t3_1vdr94r
+author: satoshisfeverdream
+created_utc: 1786138738
First lines only. The complete diff is in the timeline below.
- Organisation
- Evidence role
- Community discussion
- Published
- not established
- Source changes
- 2
- Detected differences
- 2
- Unreviewed
- 0
- Copies held
- 3
Every check is recorded, including checks that found no text change. A detected edit is therefore bounded between two checks. The publisher's exact save time is not observable from this record. Last checked .
This post is held twice: here, with this project's own note on why it matters, and again as part of the conversation captured at , which is polled for changes. Both copies are the same post; neither is a separate event.
Snapshot and diff bodies for this chain monitor are held in the local evidence archive but withheld from the public site because they can contain the addresses of people who published nothing themselves. Capture times and reviewed change summaries remain available below.
Held captures
-
The Reddit thread gained a new participant comment suggesting earlier 2021-2022 thefts could have been organic seed collisions.
Recovered from the Internet Archive rather than captured by this project. The row records that third-party provenance separately from captures made by this project.
What changed from the previous capture 8 lines
Yo fuck a coinkite. So glad ColdCard wasn't my first device. + +comment: p2cj9wr +parent: t3_1vdr94r +author: satoshisfeverdream +created_utc: 1786138738 +edited: false +body: +Supposedly there were some thefts reported back in 2021-2022 timeframe that could have simply been organic collisions.Extracted text as captured
post: 1vdr94r author: IsolatedNetworkNode created_utc: 1785699240 title: 93,000 Coldcard-Generated Seeds Is All It Takes for a 50% Chance Two People End Up With the Same Wallet body: You probably heard the birthday paradox, having 23 people in a room creates a 50% chance that at least two of them share the same birthday. Applying it to the vulnerable search space in the ColdCard bug (Following reports that search space was reduced to 2\^32, approx 4 billion) 50% collision odds ≈ √(2 × 4.3 billion) ≈ 93,000 ColdCard Wallet Generated Seeds. If this bug was somehow never discovered and Coldcard sold around 93k units that generated a seed on the vulnerable firmware, there would be a 50% chance that two innocent, unaware people would end up with the exact same seed phrase, and by extension every bitcoin address derived from it, giving each other access to the others funds. Just a fun thought experiment in these dark times. comment: p1bjfv9 parent: t3_1vdr94r author: PrometheusFires created_utc: 1785702420 edited: false body: Crazy scenario comment: p1bvbee parent: t3_1vdr94r author: slvbtc created_utc: 1785705834 edited: false body: This is why once every few months we saw people posting on reddit saying their funds were drained even after taking every precaution and doing nothing wrong. Instead of coinkite looking into these issues and checking for bugs they simply called these victims "crying panhandlers" and ignored them. comment: p1bykn8 parent: t1_p1bvbee author: StarCommand1 created_utc: 1785706797 edited: falseExcerpt only. The complete copy is held offline and backs quotations on this site. The original publication remains the canonical public source.
-
1 new Reddit comment was posted, by CompetitionDouble420, expressing relief at having used another device.
Recovered from the Internet Archive rather than captured by this project. The row records that third-party provenance separately from captures made by this project.
What changed from the previous capture 10 lines
edited: false body: Validate bitcoin to grandpa they said + +comment: p1nqj03 +parent: t3_1vdr94r +author: CompetitionDouble420 +created_utc: 1785854400 +edited: false +body: +Yo fuck a coinkite. + +So glad ColdCard wasn't my first device.Extracted text as captured
post: 1vdr94r author: IsolatedNetworkNode created_utc: 1785699240 title: 93,000 Coldcard-Generated Seeds Is All It Takes for a 50% Chance Two People End Up With the Same Wallet body: You probably heard the birthday paradox, having 23 people in a room creates a 50% chance that at least two of them share the same birthday. Applying it to the vulnerable search space in the ColdCard bug (Following reports that search space was reduced to 2\^32, approx 4 billion) 50% collision odds ≈ √(2 × 4.3 billion) ≈ 93,000 ColdCard Wallet Generated Seeds. If this bug was somehow never discovered and Coldcard sold around 93k units that generated a seed on the vulnerable firmware, there would be a 50% chance that two innocent, unaware people would end up with the exact same seed phrase, and by extension every bitcoin address derived from it, giving each other access to the others funds. Just a fun thought experiment in these dark times. comment: p1bjfv9 parent: t3_1vdr94r author: PrometheusFires created_utc: 1785702420 edited: false body: Crazy scenario comment: p1bvbee parent: t3_1vdr94r author: slvbtc created_utc: 1785705834 edited: false body: This is why once every few months we saw people posting on reddit saying their funds were drained even after taking every precaution and doing nothing wrong. Instead of coinkite looking into these issues and checking for bugs they simply called these victims "crying panhandlers" and ignored them. comment: p1bykn8 parent: t1_p1bvbee author: StarCommand1 created_utc: 1785706797 edited: falseExcerpt only. The complete copy is held offline and backs quotations on this site. The original publication remains the canonical public source.
-
Recovered from the Internet Archive rather than captured by this project. The row records that third-party provenance separately from captures made by this project.
What changed from the previous capture 0 lines
Extracted text as captured
post: 1vdr94r author: IsolatedNetworkNode created_utc: 1785699240 title: 93,000 Coldcard-Generated Seeds Is All It Takes for a 50% Chance Two People End Up With the Same Wallet body: You probably heard the birthday paradox, having 23 people in a room creates a 50% chance that at least two of them share the same birthday. Applying it to the vulnerable search space in the ColdCard bug (Following reports that search space was reduced to 2\^32, approx 4 billion) 50% collision odds ≈ √(2 × 4.3 billion) ≈ 93,000 ColdCard Wallet Generated Seeds. If this bug was somehow never discovered and Coldcard sold around 93k units that generated a seed on the vulnerable firmware, there would be a 50% chance that two innocent, unaware people would end up with the exact same seed phrase, and by extension every bitcoin address derived from it, giving each other access to the others funds. Just a fun thought experiment in these dark times. comment: p1bjfv9 parent: t3_1vdr94r author: PrometheusFires created_utc: 1785702420 edited: false body: Crazy scenario comment: p1bvbee parent: t3_1vdr94r author: slvbtc created_utc: 1785705834 edited: false body: This is why once every few months we saw people posting on reddit saying their funds were drained even after taking every precaution and doing nothing wrong. Instead of coinkite looking into these issues and checking for bugs they simply called these victims "crying panhandlers" and ignored them. comment: p1bykn8 parent: t1_p1bvbee author: StarCommand1 created_utc: 1785706797 edited: falseExcerpt only. The complete copy is held offline and backs quotations on this site. The original publication remains the canonical public source.
0 presentation-noise differences. Sidebar, ticker and other page chrome churn that our review classified as not being changes to what the source says.
The excerpts and plain unified diffs above show the text this project held and how it changed. To verify a quotation, compare it against the page itself or against the Internet Archive's copies, which are independent of this project.
Complete captures are held offline rather than mirrored here, so this page shows diffs and excerpts. If a quotation is ever disputed, the full copy can be produced. Ask.
Compare the screenshot or a quotation against the original while it is available.