If anyone needs any guidance on moving keys off of a Coldcard, reach out. I'm happy to help.
MK4, MK5, and Q users who used the default key generation functionality should be moving funds TODAY.
Login to reply
Replies (31)
👀
Is the seeds generated after firmware update takes care of it??
Seed from trezor T, and passphrase of 104bits of entropy. Should I worry?
Seed derived from CC’s RNG + 100 dice rolls. Move or don’t move?
Seed auto generated on coldcard mk1 in 2019. Are my funds safe?
Appreciate you. Since the RNG did not function as expected, one might wonder if the ‘Add Dice Rolls’ feature actually functions as expected. Any known verification or way to verify?
Code has been thoroughly audited over the last few days by many pros.
I encourage you to do your own verifications with tests, looking at the python tool Coinkite published for verifying the roles, and potentially trying the dice rolls with other manufacturers' devices.
And the reason for the slipstream is so that info about the ColdCard doesn't leak? In this case, it's not N, and the only thing this coldcard is used for (well, that still has coins) is this multisig, so I don't think I have much to worry about. I'll move out of this multisig and into a new one once I have decided which wallets I want to be part of it. And holding off on destroying the seed on the CC until after I've done that, at which point I'll regenerate a new seed with plenty of dice rolls, and consider that updated CC valid.
Thanks again. Unfortunately the TRNG + Dice method cannot be reproduced / verified in the same way that Dice Only can.
From CC website:
COLDCARD TRNGs Only: This method involves the most trust, as it is using the hardware of the COLDCARD to generate entropy (randomness) for your seed. This method is not reproducible, is low risk to users, and protects the user from any possible mistakes.
COLDCARD TRNGs + Dice: This method can be considered the middle ground as far as trust is concerned. It still uses the COLDCARD hardware to generate random data, but now adds in entropy that you can create via dice rolls. This method is not reproducible, and is low risk to users. Although not reproducible and involving some trust, it is minimized and users cannot produce worse entropy than using the COLDCARD's TRNGs only method.
Dice Only: This method can remove all trust in the COLDCARD's hardware, as all of your entropy is produced by your dice rolls. This method is fully reproducible using the Verifying Dice Roll Math document. However, if warnings are not heeded, it is possible to generate seeds that will be stolen immediately.
Still solid overall?
If one would roll a new proper seed on a non-coldcard device, and would then import that seed into the coldcard, do you think it's safe to sign a transaction with that coldcard? I'm beyond paranoid at this point.
I was still thinking that coldcard was for geeks?
What’s the proper character length of a passphrase? Thx
Thank you good sir
Anyone in particular? Maybe that’s just a humble face
i got multiple hardware wallets
but if you got only a compromised MK3, MK4 or Q
fly as soon as possible to your setup
DONT send to an exchange. You got a lot of problems with that later.
use a very strong passphrase instead it generates a new wallet with the entropy of the passphrase,
21 random high tier chars should do the job,
check twice, only send small amount first
recheck the passphrase funds
then buy a different vendor wallet
use physical entropy or a strong passphrase again.
yes its hard, but the sats are all you earned.
take your time, be cautious
mk3 below 4.0.1 (03/2021)
is fine, probably checked the most during the last 48 hours
How safe is the setup if one makes a new seed with: mk4 with updated firmware, 24 words with 120+ dice rolls.. is it safe?
Were you able to wipe the old seed? Mine (mk4) wouldn't do it despite multiple attempts.
I can't thank myself enough for getting started. Despite the economic situation, I'm so happy to see €78,000 in returns from a €15,000 short-term investment with pjtradinghub. His videos are top-notch and highly educational, giving you real insights to achieve your goals and come out from debt! For a guide to a professional trader, I highly recommend everyone check out his Telegram 👉 "pjtradinghub"


Personally I would not use a coinkite device for generating more than 1 seed in a 2 of 3 quorum now - probably being paranoid but multivendor feels like the way to go with this loss of trust - who knows what else is lurking. I’m using strong pass phrases on top as well.
I would add a strong passphrase as well as a minimum. I’m going multivendor multisig after this.
Personally I would add a strong passphrase as well if single sig.
Yeh this is my worry as well, who knows what other bugs are lurking in the code. Have you got a strong passphrase?
Yeah I’ve been thinking about that. For me the immediate Step 1 was to mitigate the Coldcard seed phrase entropy problem (and not do something to create a bigger problem). Step 2 will be to figure out best practice going forward. Who knows what may be coming next and what signing devices may be affected. But I agree it seems diversification of signing device manufacturers/vendors may be a good call.
I have been thinking about this all day
I’m no expert, but I used 12 words off EFF’s short wordlist. It’s 4 dice rolls per word. 48 total dice rolls. 124 bits of entropy.


Electronic Frontier Foundation
EFF Dice-Generated Passphrases
Create strong passphrases with EFF's new random number generators! This page includes information about passwords, different wordlists, and EF...
Yes. Wiped several mk4s
I’m thinking it should be far above the 256bits but what do i know.. I’m dumb as a carrot
Thx
Want free Bitcoin in your pocket?
Satsman makes it simple—complete quick tasks and refer friends to start earning real sats daily, no investment needed. Access Satsman on your favorite devices and join thousands already building their Bitcoin stack!


Satsman
Satsman — The Bitcoin Onboarding Platform
The Duolingo of Bitcoin. Learn through daily missions, earn real satoshis, get certified, and onboard your team. 30,000+ members in 170 countries. ...