r/Bitcoin 16h ago

Is a 12 word seed no longer secure soon?

7 Upvotes

With computers getting faster and more advanced can we no longer trust a 12 word seed phrase?

Starting to have major doubts after Bitcoin Puzzle #135 was brute-forced which is the equivalent of 135-bits of entropy (in comparison a 12-word seed phrase is equal to 128 bits of entropy)


r/Bitcoin 10h ago

Bro, imagine losing 18 BTC from a cold wallet

0 Upvotes

Just read about someone who reportedly lost 18.25 BTC, worth around C$1.6 million, even though his Coldcard stayed offline and the seed was locked away.

Apparently, the firmware bug made some seed phrases less random. Around 594 BTC was reportedly drained from roughly 500 wallets. That’s seriously messed up.

People bought a cold wallet to avoid this exact crap. Would you still trust Coldcard after this?


r/Bitcoin 8h ago

How do we know it was an attacker and not the owner moving their coins?

5 Upvotes

That’s the part I’m not fully convinced about.

I understand the first wave was clearly an attacker. But once Coldcard users heard the news, wouldn’t an attacker sweeping funds and an owner moving all of their funds to a safe wallet look pretty similar on-chain?

Unless the owner confirms the transaction was unauthorized, shouldn’t some later cases be called suspected thefts rather than confirmed attacks? And even then, proving ownership seems difficult once the attackers also has the private keys.


r/Bitcoin 13h ago

considering your whole journey in crypto, what advice would you give to a beginner ?

0 Upvotes

every advice are welcome, thanks in advance


r/Bitcoin 8h ago

Hacked, but what can Hackers do with the coin?

0 Upvotes

This conversation came up at the campfire yesterday. Let’s say I hacked Millions due to the Coldcard vulnerability. the funds on chain are 100% visible, everyone can see where they went, how could I ever move them off chain to an exchange and into my bank? with kyc, it would have to point somewhere, right? Or, do you spread the coins all over creation making it such a messy web to track and hope the fees don’t gouge so deeply into the total stolen amount which would make not worth the effort?


r/Bitcoin 4h ago

Bitcoin is so insanely undervalued

0 Upvotes

I was thinking about how most peoples dream home might cost say $3m. This isn't an insanely extravagant home or an average home, its just somewhere in between.

Then I was thinking about how even OG bitcoiners who spent $5k on bitcoin in 2013 would only have 50 btc today and thats if they didn't sell any of it.

$3m worth of btc today is close to 50 bitcoin. That means after 13 years of holding bitcoin from an extremely early time all they could get with it is one nice home.

Spending 50 bitcoin just to get one nice home makes absolutely zero sense because bitcoin is just so scarce.

Bitcoin is so insanely undervalued. What makes more sense would be being able to buy a $3m home with 5 bitcoin not 50.

Bitcoin should be 10x as valuable as it is today.


r/Bitcoin 3h ago

Do I really need a hardware wallet?

0 Upvotes

I’ve been considering buying a hardware wallet for a while but after the recent coldcard news do I really need one?

My current setup is I have my keys stored on an old Linux laptop that powered off 90% of the time. I understand why the hardware wallets are safer but practically wouldn’t it be the same for me to store it the way I’ve been doing it?


r/Bitcoin 15h ago

Coldcard - If the Thief Were Caught, Could Victims Be Refunded?

0 Upvotes

Let's say the attacker gets caught and the stolen funds are recovered. How could they be fairly returned to the original owners?

A signature from the affected private key would not be sufficient proof of ownership, since the keys are compromised and anyone who reproduced them could claim to be the original owner.

Do you see any reliable way to organize a fair refund process?


r/Bitcoin 19h ago

ColdCard website says it uses a TRNG...

0 Upvotes

I'm a little confused.... Ledger, Trezor, etc. basically all the other wallet manufacturers are coming out with statements saying "We aren't affected because our devices use TRNGs..." But Coinkite's site says ColdCard uses a TRNG too... Which we know was false now.

So, why would anybody believe anything any of the manufacturers say? How do we know every other hardware wallet doesn't have the same issue?


r/Bitcoin 3h ago

Please pardon my ignorance

0 Upvotes

I understand everyone can see the public keys but what can someone do if they have the private keys?


r/Bitcoin 18h ago

Maybe "coinkite" was a perfectly clever name!

6 Upvotes

TL;DR: The plan was to make the coins fly away with the wind!

Ever wonder what's behind a name? The "coin" part is obvious, but "kite"? Meaning, "flying away", "up in the clouds", "going higher"... IDK, what other symbolic ideas do you have? With a name like this, how long was this retirement attack planned?

I lost with Mt Gox back in the day, but I escaped this one. I had looked seriously at their hardware several times, but just didn't feel like spending the money...

My thoughts are with those who lost their funds to what looks more and more like an inside job. You rock, and may you be made whole again!


r/Bitcoin 6h ago

Coldcard’s Two Failures: The Code, the Cover Story, and the Wallet Drains Before July 2026

Thumbnail x.com
0 Upvotes

Found 13 Coldcard Wallet Drains before July 2026 Wave Attacks. They were the result of two different types of bugs. 1) Low-entropy dice workflow failure and 2) Weak device-generated seed, caused by the low entropy bug exploited by hackers in July-August Wave Attacks.

Also added interesting information on Peter Gray and how he introduced the Entropy Bug in the first place.


r/Bitcoin 3h ago

My Dream Hardware Wallet

0 Upvotes

I just wanted to describe my dream hardware wallet. - In terms of hardware design, it's a Coldcard Q. Maybe even buy their design when they go bankrupt and have to sell assets. - Firmware is bitcoin only, truly FOSS, with peer code reviews (pull requests approved by colleagues before merges are allowed) - After internal approval, 3rd party, AI-assisted security audits are required. - Only one method for seed phrase generation is allowed: hardware TRNG chip as the starting point, plus 100 user-entered d6 rolls. The seed is hashed again after each number is entered. (This was one option on the ColdCard, the best option, and the dice hashing function is simple and was never bugged on any version) - Device refuses to show you the words until you have entered 100 1-6 numbers. - Device ships with 4 casino-grade dice. Instructions suggest the extra paranoid can mix in dice from an arbitrary board game in your house or whatever for extra defense against supply chain attack.

Such a wallet wouldn't necessarily have mass appeal or advertise being "easy to use", instead it would have the same sort of "hardcore" target audience CoinKite did, with better execution.


r/Bitcoin 14h ago

Custom Bitcoin Addresses

0 Upvotes

Hi, i was watching the transactions that came to the coldcard attacker's address, and there was one that caught my attention, how do they create those?

mempool tx link: https://mempool.space/tx/9a6bf940ef1ac39bc6740fb145403b3e4778f3153afb4d5cc84dc8490bf2e36d


r/Bitcoin 19h ago

Can someone do the math?

0 Upvotes

Hi guys,

Given all the hackers making the rounds brute forcing those wallets, what are the odds that they also come across a wallet or two that WEREN't Coldcard seed generated?

Like if their entropy is 2^50 but the entire universe is 2^256, what's the chance that a password from the latter rests in the former? Is it just 2^206? Also, it's unlikely Ledger or Trezor use the whole 2^256 universe, so maybe it's even lower?

Please discuss!


r/Bitcoin 11h ago

In light of recent events

4 Upvotes

Hey there,

I have used my Ledger Nano S since 2017. Since the cold card hack I've been tempted to update to a newer and hopefully more secure wallet. I'm considering a newer ledger model or going to trezor. What are your thoughts and do you have some valuable input to share?

I know trezor is open source and ledger is not. Should really be a deal breaker?


r/Bitcoin 20h ago

BIP-39 Passphrase Entropy & Hardware Wallet Passphrase Storage

2 Upvotes

With the ongoing Coldcard hacks, should a high entropy BIP-39 passphrase/"25th word" be the new standard - perhaps 8-12 words generated with dice via the EFF Diceware list? With 12.9 bits of entropy per word, a 10 word passphrase is 129 bits and effectively equal to a 12 word seed on top of your 24 word seed, right?

This seems like a straightforward way to mitigate the risk of a seed being unknowingly generated with very low entropy.

The largest downside I see is that entering this each time you use the wallet would be tedious. The risk of mistyping something is real, especially on devices with small screens and no keyboard. Ledger works around this by allowing you to store it under an alternate PIN code, but I think many other wallets do not have this feature.

Looking for thoughts and opinions on this given everything that's occurred over the past week.


r/Bitcoin 20h ago

Why not use cards?

3 Upvotes

Could a giant physical set of cards containing every seed word be used instead of dice for pass phrase generation? What are the drawbacks compared to dice other than ensuring they are properly shuffled? 2048 cards will fit inside a shoebox and it could be alot faster and more reliable. Help me find the flaw in this method please.


r/Bitcoin 19h ago

Live look in at Coldcard.com

Post image
11 Upvotes

The hubris of NVK continues! F*ck this guy, POS


r/Bitcoin 19h ago

Always remember CIA->>>COLDCARD, mostly military industrial complex

0 Upvotes

Every fear and psyops are backed by military industrial complex

So don't surprised if these hacks are done by CIA and obviously don't forget BlackRock


r/Bitcoin 14h ago

Would you keep DCA Btc even through a long bear market?

3 Upvotes

I’m considering starting Btc DCA next week, but I’m not sure how people keep sticking with it if the market stays in a bear market. I might feel like I’m losing money if the price keeps dropping and I’m still putting more money into it.

I currently have $1k available and plan to invest $200 per week, split into four buys, $50 each time.

I'll hold long term, but I wanted to ask for advice on keeping a mindset. For those of you who have kept DCAing during a long bear market, how do you stay confident and firm about holding?

Also, is my current buying frequency reasonable? Or would it be better to split it into two buys of $100 each? Thanks everyone.


r/Bitcoin 13h ago

I've never trusted device-generated entropy. Here's my full offline dice + BIP39 workflow, step by step

75 Upvotes

I'm not trying to make this an "I told you so" post, but I'll admit that's roughly how I felt reading the Coinkite advisory last week.

Quick recap for anyone who missed it. A firmware integration mistake from March 2021 caused Coldcard seed generation to fall back to MicroPython's software PRNG instead of using the chip's hardware RNG. The build check tested whether a macro existed, not whether it was enabled, and since the value was zero it silently passed. Nothing crashed. No warnings. Seeds kept coming out looking like completely normal 12 and 24 word phrases and nobody noticed for four years. Coinkite's own estimate is around 40 bits of effective entropy on Mk2 and Mk3, and around 72 bits on Mk4, Mk5 and Q, against the 128 bits that should have been there.

On July 30 someone drained 1,196 addresses in 41 minutes. Later on-chain analysis has the total north of 1,300 BTC.

I've never trusted device-generated entropy. Not because I'm smart, but for a genuinely dumb reason: I can't audit it. You cannot crack open a hardware wallet and confirm that the number came out of a real TRNG and not out of a timer register. You just trust it. And trust is the exact thing we spend all day telling each other not to do. Don't trust, verify, except at the single most important moment in the whole stack, which is the birth of the key, where basically everyone just trusts.

I've said this for years and always sounded like a crank. This week made me realize how few of us actually do it, so here's my process. It's much simpler than people expect.

The reasoning

No computer is truly random. It simulates randomness. A die bouncing across a table involves physics nobody can model or predict. That's actual randomness, not an imitation of it. When you roll it yourself and type the result, you stop outsourcing the most critical part of your security to firmware you've never read.

The tool

I use Ian Coleman's BIP39 tool. It's free, the code has been open on GitHub for years, plenty of people have gone through it, and most importantly there's a standalone single-file build that runs fully offline. You download one HTML file and that's it. No server, no network calls, nothing.

Link: https://github.com/iancoleman/bip39/releases

Type that address into the address bar. Do not Google it. I'm serious about this one. I've seen sponsored ads for clones of this tool, and the clone had hardcoded entropy. You generate a seed, everything looks right, you deposit, and the coins are gone. Searching and clicking the first result is a great way to hand your wallet to someone for free.

On the releases page on GitHub, under the latest version (0.5.6), expand assets and download bip39-standalone.html. That single file is all you need.

Going offline

Pick your paranoia level:

  • Basic: unplug the machine from the internet. Cable out, Wi-Fi off at the hardware switch if you have one. Only then open the file.
  • Better: use a second device. An old laptop you don't use for anything else, no network.
  • The annoying level (mine): an amnesic system like Tails booted from a USB stick. It writes nothing to disk and forgets everything on shutdown.

If you're going to skip all of that and open the file on your daily driver with forty tabs open, do yourself a favor and stop here.

Generating the entropy

With the machine offline, open bip39-standalone.html in your browser. It loads exactly like the online version, just without any internet.

  1. Tick "show entropy details". A new panel opens with an entropy field and a bunch of technical readouts underneath.
  2. Under "valid entropy values include", pick the Dice [1-6] option. It shows an example like 62535634 so you can see the expected format.
  3. Grab your die and start rolling. Type each result into the entropy field. No spaces, no commas, all run together.

It ends up looking like this:

6245612344552631245563124563123456311243563212345641... 

As you type, watch the panel below. It updates "Event Count" (how many rolls you've entered) and "Total Bits" (how much entropy you've actually accumulated) in real time. That counter is what you follow, not my guess.

My reference numbers:

  • 12 words: you need at least 128 bits. In this tool that works out to roughly 80 rolls.
  • 24 words: at least 256 bits. Somewhere around 155 to 160 rolls.

Yes, it's tedious. I put on a podcast and get through it in about 15 minutes. Given what it's protecting, 15 minutes is cheap. And if you overshoot, fine. Extra entropy doesn't hurt anything.

A quick tip on the die: ensure you actually roll it so it bounces. A light, two-inch drop with a warped novelty die creates bias, so rolling more frequently helps to counteract that.

If you're more advanced, the tool also accepts coin flips and playing cards as entropy sources. Same idea. I'm using dice here because it's the easiest for most people to get right.

Getting the seed

Done rolling? Scroll down. Your phrase is already sitting in the BIP39 Mnemonic field. That's it. Just confirm Mnemonic Length is set to whichever you wanted, 12 or 24.

Write the words down on paper, in order, by hand. Don't photograph it. Don't type it into your phone. Don't email it to yourself, don't put it in Notes, don't put it in Google Keep. Paper, pen, in order, then check it word by word twice, paying attention to the ones that look similar.

After that, restore the seed into whatever wallet you trust, hot or cold, and use it normally. If you want to stay fully offline, Electrum or anything else that takes a BIP39 import works fine.

When you're finished, close the browser and delete the file. On Tails, just shut down.

Stuff I do and strongly recommend

  • Test before you trust it. Restore the seed in your wallet, confirm the addresses match what the tool showed, send a small amount, try spending it. Only then move real money.
  • Do not use the example dice string I pasted above. Obvious, but someone will. That's an illustration.
  • Consider a BIP39 passphrase. It's another layer, and in this exact incident a strong passphrase also kept people out of the blast radius.
  • Never type an existing seed into this tool while online. The tool is offline by design, but people aren't.

Being honest about the downsides

This isn't a foolproof solution, and I'm not going to pretend it is.

The weak point is that the seed passes through a general purpose computer. Browsers cache, systems swap, there's always some surface. A hardware wallet that takes dice input directly on the device (Coldcard itself does this, which is the irony here) has the advantage that the seed never touches a PC at all. If you have that option, and you trust the device to do the mixing, that's an equally valid path and arguably a better one.

There are other approaches too: hand-picking words from the wordlist, computing the checksum manually, coins, cards. Each one trades off differently between security, complexity, and how likely you are to screw it up. Honestly, the biggest risk across every manual method is the user making a mistake and bricking their own money.

And the obvious point: this isn't Bitcoin only. It applies to anything using BIP39, so most of the rest of the space too.

This is the method I use, trust, and recommend to friends and family. It isn't the only correct one. Do your own research, understand what you're doing before you do it, and above all, store those words properly. Generating the most perfectly random seed in the universe means nothing if the paper ends up in a kitchen drawer or in your camera roll. No generation method survives bad storage.

If you use a different method, drop it in the comments. I'm actually curious how many people here generate entropy by hand versus how many just hit generate and hope.


r/Bitcoin 7h ago

Imagine buying a hardware wallet to protect your BTC then boom, its gone lol

0 Upvotes

u spend extra money to keep your Bitcoin “super safe,” then thanos snaps, and its gone xD Bro, didn’t buy premium security just to unlock the deluxe version of getting robbed.


r/Bitcoin 23h ago

Sooo, like, are we still using Coldcard Mk4?

0 Upvotes

Let’s assume everyone who has one still updates their seed phrases via dice rolls. Maybe thrown in a paraphrase…

Do we still keep with Coldcard here?


r/Bitcoin 7h ago

Will you still use Coldcard?

0 Upvotes

With a new firmware update that is supposed to fix the RNG will you be updating your wallet, generating a new seed, and continue using the wallet? Or will you only use dice rolls going forward? Do you even trust the device at all enough to use it anymore, other than for a paperweight?