COLDCARD RNG incident the public record, collected and explained
Informational only, and this site never asks for your seed words. details

Informational only. This is an open source collection of what others have published about the incident, together with an explanation of it. It is not financial, security or legal advice, and not a substitute for professional advice about your own situation. It is not affiliated with, endorsed by, or speaking for Coinkite. Material is attributed and quoted as published; where sources disagree their scenarios are kept separate with their assumptions rather than reconciled into one answer. Everything is meant to be checked against the linked evidence rather than taken on trust. Act on your own judgement about a particular situation. Editorial standards and corrections.

Do not disclose recovery material to a website, form, message or support account. This site never asks for it, and contributions containing recovery words or private keys are not accepted.

r/coldcard: call for more user-entropy options in COLDCARD

reddit-user-entropy-options

https://www.reddit.com/r/coldcard/comments/1vcr9uo/time_for_cold_card_to_implement_more_user_entropy/

Latest reviewed change

source content difference between and

New comment reports that a user-entropy option is already in progress, linking Coldcard firmware GitHub pull request 707.

seen +10 -0 full history below
 Its not impossible, but its hard, and it takes hard work an dedication. 
 
 I will agree with you that i'm not sure coinkite has it in them to do what it takes, but i hope so, otherwise my investments with their devices is lost
+
+comment: p289hy2
+parent: t3_1vcr9uo
+author: CornFly2014
+created_utc: 1786092823

First lines only. The complete diff is in the timeline below.

Organisation
reddit
Evidence role
Community discussion
Published
not established
Source changes
2
Detected differences
2
Unreviewed
0
Copies held
3

Every check is recorded, including checks that found no text change. A detected edit is therefore bounded between two checks. The publisher's exact save time is not observable from this record. Last checked .

  1. source content difference between and Current source content +10 -0

    New comment reports that a user-entropy option is already in progress, linking Coldcard firmware GitHub pull request 707.

    seen · Captured here 6,306 chars
    What changed from the previous capture 10 lines
     Its not impossible, but its hard, and it takes hard work an dedication. 
     
     I will agree with you that i'm not sure coinkite has it in them to do what it takes, but i hope so, otherwise my investments with their devices is lost
    +
    +comment: p289hy2
    +parent: t3_1vcr9uo
    +author: CornFly2014
    +created_utc: 1786092823
    +edited: false
    +body:
    +Update: from GitHub it seems this is already in progress: [https://github.com/Coldcard/firmware/pull/707](https://github.com/Coldcard/firmware/pull/707)
    +
    +Looks like things are improving!
    
    Extracted text as captured
    post: 1vcr9uo
    author: CornFly2014
    created_utc: 1785600418
    title: Time for cold card to implement more user entropy options
    body:
    To restore 'trust' , i think the best way to do so, is to extend the user provided entropy options in cold card. 
    
    Just like TrueCrypt did in the old days, and VeraCrypt does today, allow the user to add entropy using:
    
    1. Mashing random buttons in the keyboard, in the Q there are many keys, why not take advantage of that.
    
    2. Using the time between keystrokes as another input.
    
    3. Instead of just 1-6, allow the user to input hex values as added entropy (say from random.org)
    
    All just like today, by either using the HW entropy as base, or a known empty string as base.
    
    And also just like VeraCrypt, add a visual progress bar showing how much entropy as been inputed by the user.
    
    The idea is 'Reproduce-able' results given a given entropy, and but make it as easy as possible for user generated entropy to be added.
    
    comment: p13d8sm
    parent: t3_1vcr9uo
    author: bullett007
    created_utc: 1785601173
    edited: false
    body:
    Trust them to code that all in correctly do ya? 
    
    Knowing them, mashing the keyboard will further reduce entropy. 
    
    馃槀馃ぃ
    
    comment: p13ekbi
    parent: t3_1vcr9uo
    author: CraftClear7283
    created_utc: 1785601553
    edited: 1785601810
    body:
    And then a software bug will simply ignore the user entropy and revert to it's internal clock as the primary source of entropy?

    Excerpt only. The complete copy is held offline and backs quotations on this site. The original publication remains the canonical public source.

  2. source content difference between and source content +18 -0

    2 new Reddit comments were posted, including Interesting-Gear-992,CornFly2014.

    seen · Captured here 6,018 chars
    What changed from the previous capture 18 lines
     Self reply: elsewhere I saw you comment about how dice rolls do let you verify the math. 
     
     I didn't think inputting mouse jiggles or keyboard mashing could be verified... but if so, I am wrong above, and in that case, yes: why not make it very convenient in the device itself to generate a big old number, then prove it did what it should. I get your point.
    +
    +comment: p1mu60o
    +parent: t3_1vcr9uo
    +author: Interesting-Gear-992
    +created_utc: 1785844883
    +edited: false
    +body:
    +I think restore the trust is an impossible mission.
    +
    +comment: p1mv7to
    +parent: t1_p1mu60o
    +author: CornFly2014
    +created_utc: 1785845250
    +edited: false
    +body:
    +Its not impossible, but its hard, and it takes hard work an dedication. 
    +
    +I will agree with you that i'm not sure coinkite has it in them to do what it takes, but i hope so, otherwise my investments with their devices is lost
    
    Extracted text as captured
    post: 1vcr9uo
    author: CornFly2014
    created_utc: 1785600418
    title: Time for cold card to implement more user entropy options
    body:
    To restore 'trust' , i think the best way to do so, is to extend the user provided entropy options in cold card. 
    
    Just like TrueCrypt did in the old days, and VeraCrypt does today, allow the user to add entropy using:
    
    1. Mashing random buttons in the keyboard, in the Q there are many keys, why not take advantage of that.
    
    2. Using the time between keystrokes as another input.
    
    3. Instead of just 1-6, allow the user to input hex values as added entropy (say from random.org)
    
    All just like today, by either using the HW entropy as base, or a known empty string as base.
    
    And also just like VeraCrypt, add a visual progress bar showing how much entropy as been inputed by the user.
    
    The idea is 'Reproduce-able' results given a given entropy, and but make it as easy as possible for user generated entropy to be added.
    
    comment: p13d8sm
    parent: t3_1vcr9uo
    author: bullett007
    created_utc: 1785601173
    edited: false
    body:
    Trust them to code that all in correctly do ya? 
    
    Knowing them, mashing the keyboard will further reduce entropy. 
    
    馃槀馃ぃ
    
    comment: p13ekbi
    parent: t3_1vcr9uo
    author: CraftClear7283
    created_utc: 1785601553
    edited: 1785601810
    body:
    And then a software bug will simply ignore the user entropy and revert to it's internal clock as the primary source of entropy?

    Excerpt only. The complete copy is held offline and backs quotations on this site. The original publication remains the canonical public source.

  3. Earliest copy held
    seen · Captured here 5,529 chars
    Extracted text as captured
    post: 1vcr9uo
    author: CornFly2014
    created_utc: 1785600418
    title: Time for cold card to implement more user entropy options
    body:
    To restore 'trust' , i think the best way to do so, is to extend the user provided entropy options in cold card. 
    
    Just like TrueCrypt did in the old days, and VeraCrypt does today, allow the user to add entropy using:
    
    1. Mashing random buttons in the keyboard, in the Q there are many keys, why not take advantage of that.
    
    2. Using the time between keystrokes as another input.
    
    3. Instead of just 1-6, allow the user to input hex values as added entropy (say from random.org)
    
    All just like today, by either using the HW entropy as base, or a known empty string as base.
    
    And also just like VeraCrypt, add a visual progress bar showing how much entropy as been inputed by the user.
    
    The idea is 'Reproduce-able' results given a given entropy, and but make it as easy as possible for user generated entropy to be added.
    
    comment: p13d8sm
    parent: t3_1vcr9uo
    author: bullett007
    created_utc: 1785601173
    edited: false
    body:
    Trust them to code that all in correctly do ya? 
    
    Knowing them, mashing the keyboard will further reduce entropy. 
    
    馃槀馃ぃ
    
    comment: p13ekbi
    parent: t3_1vcr9uo
    author: CraftClear7283
    created_utc: 1785601553
    edited: 1785601810
    body:
    And then a software bug will simply ignore the user entropy and revert to it's internal clock as the primary source of entropy?

    Excerpt only. The complete copy is held offline and backs quotations on this site. The original publication remains the canonical public source.

How to check this yourself

The excerpts and plain unified diffs above show the text this project held and how it changed. To verify a quotation, compare it against the page itself or against the Internet Archive's copies, which are independent of this project.

Complete captures are held offline rather than mirrored here, so this page shows diffs and excerpts. If a quotation is ever disputed, the full copy can be produced. Ask.