COLDCARD RNG incident the public record, collected and explained
Informational only, and this site never asks for your seed words. details

Informational only. This is an open source collection of what others have published about the incident, together with an explanation of it. It is not financial, security or legal advice, and not a substitute for professional advice about your own situation. It is not affiliated with, endorsed by, or speaking for Coinkite. Material is attributed and quoted as published; where sources disagree their scenarios are kept separate with their assumptions rather than reconciled into one answer. Everything is meant to be checked against the linked evidence rather than taken on trust. Act on your own judgement about a particular situation. Editorial standards and corrections.

Do not disclose recovery material to a website, form, message or support account. This site never asks for it, and contributions containing recovery words or private keys are not accepted.

r/Bitcoin: whether to throw away a COLDCARD

reddit-throw-away-coldcard

https://www.reddit.com/r/Bitcoin/comments/1veuene/do_i_throw_away_my_coldcard/

Latest reviewed change

source content difference between and

Reddit served 1 previously held comment record(s) omitted; the diff preserves their text and any edits to existing records.

seen +0 -8 full history below
 body:
 Trezor seems to have a decent track record
 
-comment: p1klqw9
-parent: t3_1veuene
-author: According-Rain-1936
-created_utc: 1785810013
-edited: false

First lines only. The complete diff is in the timeline below.

Organisation
reddit
Evidence role
Community discussion
Published
not established
Source changes
5
Detected differences
5
Unreviewed
0
Copies held
6

Every check is recorded, including checks that found no text change. A detected edit is therefore bounded between two checks. The publisher's exact save time is not observable from this record. Last checked .

  1. source content difference between and Current source content +0 -8

    Reddit served 1 previously held comment record(s) omitted; the diff preserves their text and any edits to existing records.

    seen · Captured here 8,440 chars
    What changed from the previous capture 8 lines
     body:
     Trezor seems to have a decent track record
     
    -comment: p1klqw9
    -parent: t3_1veuene
    -author: According-Rain-1936
    -created_utc: 1785810013
    -edited: false
    -body:
    -yes
    -
     comment: p1knvvd
     parent: t1_p1kktig
     author: jb7734
    
    Extracted text as captured
    post: 1veuene
    author: jb7734
    created_utc: 1785801899
    title: Do I throw away my Coldcard?
    body:
    Hey guys! I’m a long time bitcoin holder. I don’t have a huge stack but it’s a decent chunk and the entirety has been in storage in my Coldcard Q pretty much since that device launched. I migrated over to it from a Mark 3 and made a new wallet on the Q using 24 words generated by the device with no dice rolls or passphrase. When I first saw the reports of what was happening on Saturday night my stomach sank. I checked my wallet app with my heart racing and saw that my coins were untouched right where I left them. I feel extremely lucky that my btc wasn’t stolen, and I immediately moved the coin to my Coinbase account temporarily. My next steps were wiping the old seed, upgrading the firmware on the Coldcard and generating a new seed. I also added about 80 dice rolls this time obviously not trusting that Coldcard got it right this time. I moved my BTC back to this new cold wallet but now I’m feeling uncertain if I should dump this device completely and get something else. Am I safe with the dice rolls added entropy? I’m curious what other Coldcard users are doing now. 
    
    TLDR: my Coldcard didn’t get hacked but I’m still using it, now with added dice rolls. Am I safe or should I get something new?
    
    comment: p1jxrl2
    parent: t3_1veuene
    author: QuailRadiant7344
    created_utc: 1785802111
    edited: false
    body:
    You have balls of steel bro.
    
    comment: p1jy3zi
    parent: t3_1veuene
    author: buddhac2is
    created_utc: 1785802222
    edited: false
    body:
    Yes
    
    comment: p1jy4si
    parent: t3_1veuene
    author: Doritos707
    created_utc: 1785802229
    edited: false
    body:
    Real answer. If you rolled more than 50 dice rolls, and are using 24 words seeds, you are safe. 
    
    comment: p1jy6q4
    parent: t3_1veuene
    author: Constant-Number4020
    created_utc: 1785802246
    edited: false
    body:
    I'm sticking with my Q.

    Excerpt only. The complete copy is held offline and backs quotations on this site. The original publication remains the canonical public source.

  2. source content difference between and source content +16 -0

    The Reddit thread gained 2 new comments about device replacement and seed entropy.

    seen · Captured here 8,553 chars
    What changed from the previous capture 16 lines
     edited: false
     body:
     So, does that mean storing Bitcoin in a cold wallet ultimately depends on a third-party company staying in business forever?
    +
    +comment: p1qajqy
    +parent: t1_p1l4n9p
    +author: R7SOA19281
    +created_utc: 1785877947
    +edited: false
    +body:
    +Don’t they have like an extra 100 million now? /s
    +
    +comment: p1qb7r9
    +parent: t1_p1mziox
    +author: First-Check-164
    +created_utc: 1785878126
    +edited: false
    +body:
    +Depends on if you want updated hardware or not.  Things change with time.  If your 24 words have proper entropy, you are good.  
    
    Extracted text as captured
    post: 1veuene
    author: jb7734
    created_utc: 1785801899
    title: Do I throw away my Coldcard?
    body:
    Hey guys! I’m a long time bitcoin holder. I don’t have a huge stack but it’s a decent chunk and the entirety has been in storage in my Coldcard Q pretty much since that device launched. I migrated over to it from a Mark 3 and made a new wallet on the Q using 24 words generated by the device with no dice rolls or passphrase. When I first saw the reports of what was happening on Saturday night my stomach sank. I checked my wallet app with my heart racing and saw that my coins were untouched right where I left them. I feel extremely lucky that my btc wasn’t stolen, and I immediately moved the coin to my Coinbase account temporarily. My next steps were wiping the old seed, upgrading the firmware on the Coldcard and generating a new seed. I also added about 80 dice rolls this time obviously not trusting that Coldcard got it right this time. I moved my BTC back to this new cold wallet but now I’m feeling uncertain if I should dump this device completely and get something else. Am I safe with the dice rolls added entropy? I’m curious what other Coldcard users are doing now. 
    
    TLDR: my Coldcard didn’t get hacked but I’m still using it, now with added dice rolls. Am I safe or should I get something new?
    
    comment: p1jxrl2
    parent: t3_1veuene
    author: QuailRadiant7344
    created_utc: 1785802111
    edited: false
    body:
    You have balls of steel bro.
    
    comment: p1jy3zi
    parent: t3_1veuene
    author: buddhac2is
    created_utc: 1785802222
    edited: false
    body:
    Yes
    
    comment: p1jy4si
    parent: t3_1veuene
    author: Doritos707
    created_utc: 1785802229
    edited: false
    body:
    Real answer. If you rolled more than 50 dice rolls, and are using 24 words seeds, you are safe. 
    
    comment: p1jy6q4
    parent: t3_1veuene
    author: Constant-Number4020
    created_utc: 1785802246
    edited: false
    body:
    I'm sticking with my Q.

    Excerpt only. The complete copy is held offline and backs quotations on this site. The original publication remains the canonical public source.

  3. source content difference between and source content +16 -0

    Two new comments were posted: DoctorDownvotesDelux noting a seed generated elsewhere and imported should be fine though they probably would not, and NuggedClarp asking whether cold storage ultimately depends on a third-party company staying in business.

    seen · Captured here 8,169 chars
    What changed from the previous capture 16 lines
     edited: false
     body:
     That's why I only have minimal funds at banks
    +
    +comment: p1mz4l2
    +parent: t3_1veuene
    +author: DoctorDownvotesDelux
    +created_utc: 1785846545
    +edited: false
    +body:
    +The problem was with how it generated your seed. If you generate your seed elsewhere (like on a trezor) and import it to the coldcard you should be fine. Would I? Probably not
    +
    +comment: p1mziox
    +parent: t1_p1k0lef
    +author: NuggedClarp
    +created_utc: 1785846672
    +edited: false
    +body:
    +So, does that mean storing Bitcoin in a cold wallet ultimately depends on a third-party company staying in business forever?
    
    Extracted text as captured
    post: 1veuene
    author: jb7734
    created_utc: 1785801899
    title: Do I throw away my Coldcard?
    body:
    Hey guys! I’m a long time bitcoin holder. I don’t have a huge stack but it’s a decent chunk and the entirety has been in storage in my Coldcard Q pretty much since that device launched. I migrated over to it from a Mark 3 and made a new wallet on the Q using 24 words generated by the device with no dice rolls or passphrase. When I first saw the reports of what was happening on Saturday night my stomach sank. I checked my wallet app with my heart racing and saw that my coins were untouched right where I left them. I feel extremely lucky that my btc wasn’t stolen, and I immediately moved the coin to my Coinbase account temporarily. My next steps were wiping the old seed, upgrading the firmware on the Coldcard and generating a new seed. I also added about 80 dice rolls this time obviously not trusting that Coldcard got it right this time. I moved my BTC back to this new cold wallet but now I’m feeling uncertain if I should dump this device completely and get something else. Am I safe with the dice rolls added entropy? I’m curious what other Coldcard users are doing now. 
    
    TLDR: my Coldcard didn’t get hacked but I’m still using it, now with added dice rolls. Am I safe or should I get something new?
    
    comment: p1jxrl2
    parent: t3_1veuene
    author: QuailRadiant7344
    created_utc: 1785802111
    edited: false
    body:
    You have balls of steel bro.
    
    comment: p1jy3zi
    parent: t3_1veuene
    author: buddhac2is
    created_utc: 1785802222
    edited: false
    body:
    Yes
    
    comment: p1jy4si
    parent: t3_1veuene
    author: Doritos707
    created_utc: 1785802229
    edited: false
    body:
    Real answer. If you rolled more than 50 dice rolls, and are using 24 words seeds, you are safe. 
    
    comment: p1jy6q4
    parent: t3_1veuene
    author: Constant-Number4020
    created_utc: 1785802246
    edited: false
    body:
    I'm sticking with my Q.

    Excerpt only. The complete copy is held offline and backs quotations on this site. The original publication remains the canonical public source.

  4. source content difference between and source content +8 -0

    One new comment was posted: nachtraum ('That's why I only have minimal funds at banks').

    seen · Captured here 7,657 chars
    What changed from the previous capture 8 lines
     edited: false
     body:
     Do you feel the tellers at your bank are highly skilled money managers?
    +
    +comment: p1mru4g
    +parent: t1_p1mmcif
    +author: nachtraum
    +created_utc: 1785844056
    +edited: false
    +body:
    +That's why I only have minimal funds at banks
    
    Extracted text as captured
    post: 1veuene
    author: jb7734
    created_utc: 1785801899
    title: Do I throw away my Coldcard?
    body:
    Hey guys! I’m a long time bitcoin holder. I don’t have a huge stack but it’s a decent chunk and the entirety has been in storage in my Coldcard Q pretty much since that device launched. I migrated over to it from a Mark 3 and made a new wallet on the Q using 24 words generated by the device with no dice rolls or passphrase. When I first saw the reports of what was happening on Saturday night my stomach sank. I checked my wallet app with my heart racing and saw that my coins were untouched right where I left them. I feel extremely lucky that my btc wasn’t stolen, and I immediately moved the coin to my Coinbase account temporarily. My next steps were wiping the old seed, upgrading the firmware on the Coldcard and generating a new seed. I also added about 80 dice rolls this time obviously not trusting that Coldcard got it right this time. I moved my BTC back to this new cold wallet but now I’m feeling uncertain if I should dump this device completely and get something else. Am I safe with the dice rolls added entropy? I’m curious what other Coldcard users are doing now. 
    
    TLDR: my Coldcard didn’t get hacked but I’m still using it, now with added dice rolls. Am I safe or should I get something new?
    
    comment: p1jxrl2
    parent: t3_1veuene
    author: QuailRadiant7344
    created_utc: 1785802111
    edited: false
    body:
    You have balls of steel bro.
    
    comment: p1jy3zi
    parent: t3_1veuene
    author: buddhac2is
    created_utc: 1785802222
    edited: false
    body:
    Yes
    
    comment: p1jy4si
    parent: t3_1veuene
    author: Doritos707
    created_utc: 1785802229
    edited: false
    body:
    Real answer. If you rolled more than 50 dice rolls, and are using 24 words seeds, you are safe. 
    
    comment: p1jy6q4
    parent: t3_1veuene
    author: Constant-Number4020
    created_utc: 1785802246
    edited: false
    body:
    I'm sticking with my Q.

    Excerpt only. The complete copy is held offline and backs quotations on this site. The original publication remains the canonical public source.

  5. source content difference between and source content +16 -0

    Two new comments were posted by FavorableMadness: advising to keep the patched device as it remains as good as any other, and asking whether bank tellers are highly skilled money managers.

    seen · Captured here 7,512 chars
    What changed from the previous capture 16 lines
     edited: false
     body:
     You can generate the codes yourself using dice, regardless of the device you will eventually use, OMG. Otherwise, rolling dice and not relying on HW generators (Trezor and others have more than one) is stupidity. Literally no one ever cared about this before. But now? Suddenly it's mandatory and necessary? LOL.
    +
    +comment: p1mlxpk
    +parent: t3_1veuene
    +author: FavorableMadness
    +created_utc: 1785841845
    +edited: false
    +body:
    +Keep the device. It is superior in so many other ways. Patched, it is as good as any other. Acting like someone else built a better mouse trap is probably incorrect.
    +
    +comment: p1mmcif
    +parent: t1_p1lai0l
    +author: FavorableMadness
    +created_utc: 1785842007
    +edited: false
    +body:
    +Do you feel the tellers at your bank are highly skilled money managers?
    
    Extracted text as captured
    post: 1veuene
    author: jb7734
    created_utc: 1785801899
    title: Do I throw away my Coldcard?
    body:
    Hey guys! I’m a long time bitcoin holder. I don’t have a huge stack but it’s a decent chunk and the entirety has been in storage in my Coldcard Q pretty much since that device launched. I migrated over to it from a Mark 3 and made a new wallet on the Q using 24 words generated by the device with no dice rolls or passphrase. When I first saw the reports of what was happening on Saturday night my stomach sank. I checked my wallet app with my heart racing and saw that my coins were untouched right where I left them. I feel extremely lucky that my btc wasn’t stolen, and I immediately moved the coin to my Coinbase account temporarily. My next steps were wiping the old seed, upgrading the firmware on the Coldcard and generating a new seed. I also added about 80 dice rolls this time obviously not trusting that Coldcard got it right this time. I moved my BTC back to this new cold wallet but now I’m feeling uncertain if I should dump this device completely and get something else. Am I safe with the dice rolls added entropy? I’m curious what other Coldcard users are doing now. 
    
    TLDR: my Coldcard didn’t get hacked but I’m still using it, now with added dice rolls. Am I safe or should I get something new?
    
    comment: p1jxrl2
    parent: t3_1veuene
    author: QuailRadiant7344
    created_utc: 1785802111
    edited: false
    body:
    You have balls of steel bro.
    
    comment: p1jy3zi
    parent: t3_1veuene
    author: buddhac2is
    created_utc: 1785802222
    edited: false
    body:
    Yes
    
    comment: p1jy4si
    parent: t3_1veuene
    author: Doritos707
    created_utc: 1785802229
    edited: false
    body:
    Real answer. If you rolled more than 50 dice rolls, and are using 24 words seeds, you are safe. 
    
    comment: p1jy6q4
    parent: t3_1veuene
    author: Constant-Number4020
    created_utc: 1785802246
    edited: false
    body:
    I'm sticking with my Q.

    Excerpt only. The complete copy is held offline and backs quotations on this site. The original publication remains the canonical public source.

  6. Earliest copy held
    seen · Captured here 7,062 chars
    Extracted text as captured
    post: 1veuene
    author: jb7734
    created_utc: 1785801899
    title: Do I throw away my Coldcard?
    body:
    Hey guys! I’m a long time bitcoin holder. I don’t have a huge stack but it’s a decent chunk and the entirety has been in storage in my Coldcard Q pretty much since that device launched. I migrated over to it from a Mark 3 and made a new wallet on the Q using 24 words generated by the device with no dice rolls or passphrase. When I first saw the reports of what was happening on Saturday night my stomach sank. I checked my wallet app with my heart racing and saw that my coins were untouched right where I left them. I feel extremely lucky that my btc wasn’t stolen, and I immediately moved the coin to my Coinbase account temporarily. My next steps were wiping the old seed, upgrading the firmware on the Coldcard and generating a new seed. I also added about 80 dice rolls this time obviously not trusting that Coldcard got it right this time. I moved my BTC back to this new cold wallet but now I’m feeling uncertain if I should dump this device completely and get something else. Am I safe with the dice rolls added entropy? I’m curious what other Coldcard users are doing now. 
    
    TLDR: my Coldcard didn’t get hacked but I’m still using it, now with added dice rolls. Am I safe or should I get something new?
    
    comment: p1jxrl2
    parent: t3_1veuene
    author: QuailRadiant7344
    created_utc: 1785802111
    edited: false
    body:
    You have balls of steel bro.
    
    comment: p1jy3zi
    parent: t3_1veuene
    author: buddhac2is
    created_utc: 1785802222
    edited: false
    body:
    Yes
    
    comment: p1jy4si
    parent: t3_1veuene
    author: Doritos707
    created_utc: 1785802229
    edited: false
    body:
    Real answer. If you rolled more than 50 dice rolls, and are using 24 words seeds, you are safe. 
    
    comment: p1jy6q4
    parent: t3_1veuene
    author: Constant-Number4020
    created_utc: 1785802246
    edited: false
    body:
    I'm sticking with my Q.

    Excerpt only. The complete copy is held offline and backs quotations on this site. The original publication remains the canonical public source.

How to check this yourself

The excerpts and plain unified diffs above show the text this project held and how it changed. To verify a quotation, compare it against the page itself or against the Internet Archive's copies, which are independent of this project.

Complete captures are held offline rather than mirrored here, so this page shows diffs and excerpts. If a quotation is ever disputed, the full copy can be produced. Ask.