Home
/
Digital wallets
/
Wallet security
/

Step by step guide to offline dice and bip39 security

User Concern Grows | Device-Generated Entropy Under Fire Amid Coldcard Advisory

By

Liam O'Shea

Aug 5, 2026, 05:50 PM

Edited By

Elena Rossi

3 minutes to read

Person rolling dice to create a secure cryptocurrency seed phrase using BIP39 method.

A rising tide of skepticism surrounds device-generated entropy in crypto wallets, sparked by a recent Coldcard advisory. Users are rallying against the warnings, igniting debate over security protocols and seed generation methods in the crypto community.

Background: Coldcard Vulnerability Revealed

Earlier this year, a firmware blunder from March 2021 came to light, revealing that certain Coldcard models had relied on MicroPython's software PRNG instead of the chip's hardware RNG. Coinkite estimates an effective entropy reduction, with only about 40 bits on Mk2 and Mk3, and about 72 bits on newer models.

This revelation has far-reaching implications, especially after thieves drained 1,300 BTC from 1,196 addresses in just 41 minutes on July 30. This has raised serious questions about trust in the very systems meant to secure user assets. "People are now rethinking their faith in these devices," one user stated.

User Reactions: Discussion on Best Practices

Discussions in online forums reflect real concern around security practices. Users are debating how best to generate seeds securely without relying solely on device entropy. One comment called the use of dice for seed generation a safer alternative, suggesting that manually rolling and typing results shifts the control back into the user’s hands:

"You stop outsourcing the most critical part of your security to firmware you’ve never read."

Concerns remain over the trustworthiness of the hardware. Despite the inherent risks, many believe that leveraging options like Ian Coleman’s BIP39 tool offline provides a way to regain confidence. A user commented, "Creating the seed on Coldcard using dice rolls verifies accuracy."

Best Practices for Secure Seed Generation

Users are sharing best practices to mitigate these risks, emphasizing the importance of creating seeds offline:

  • Use manual methods: Dice rolls are being recommended as a more reliable entropy source.

  • Stay disconnected: Many advocate using a second device that is not networked to generate seeds for added security.

  • Verify results: After generating the seeds, it’s crucial to confirm that wallet addresses match before transferring significant amounts.

Key Insights from the Community

Critics also acknowledge the shortcomings of both hardware wallets and software tools, highlighting the need for due diligence:

  • ⚑ "This isn’t a foolproof solution; the seed passes through a general-purpose computer."

  • ⚠️ "A hardware wallet that takes dice input directly has an advantage; the seed never touches a PC."

  • 🌐 "Being honest about the downsides is crucial. Potential errors could lead to losses."

Through mixed sentiments, many participants seem to adopt a cautious yet proactive stance towards security. As discussions continue, it becomes clear that the community is pushing for greater transparency and control over seed generation methods.

The End

In a world where trust in technology is paramount, it's clear that the Coldcard incident has triggered a necessary reevaluation of seed generation practices. Users are pushing back against passive reliance on device entropy, opting to engage more directly in securing their assets.

How will these revelations shape the future of crypto security? Only time will tell.

For further reading and resources on secure crypto practices, check out Coinkite and GitHub.

Eyes on the Horizon: What’s Next for Crypto Security

As users rethink their approach to securing cryptocurrencies, there's a strong chance that manual seed generation methods will gain significant traction. Experts estimate around 60% of crypto enthusiasts may adopt dice rolls and offline tools to enhance security over the next year. This shift reflects a growing skepticism towards reliance on hardware wallets alone, especially following the Coldcard advisory. Additionally, it’s likely that manufacturers will respond to these concerns by improving security measures, resulting in innovations that blend traditional hardware security with enhanced user control. Expect an influx of forums dedicated to seed generation strategies, as the crypto community rallies for shared best practices.

A Cautionary Tale from the Past: The Y2K Bug

The current situation echoes the concerns surrounding the Y2K bug in the late 1990s. Just like today’s skepticism towards device-generated entropy, many feared the impending computer failures could lead to financial chaos. While some dismissed these fears, proactive individuals and companies took steps to secure their systems, ultimately avoiding a predicted disaster. This parallel highlights how periods of uncertainty encourage communities to take ownership of their security, pushing for better practices and transparency in the face of potential risks.