Coldcard RNG Failure Pushes Bitcoin Holders Toward Dice Rolls and Strong Passphrases
Security·October 2, 2026
The Coldcard random number generation failure has reopened an old argument in Bitcoin self-custody: how much should you trust the device that creates your keys?
In the first part of a listener Q&A, the host works through audience questions and comments on the incident. The central puzzle is how a flaw in something as basic as randomness could sit unnoticed for years in a widely used hardware wallet. Weak entropy is a quiet failure. A wallet with poor randomness still produces valid seed phrases and still signs transactions normally, so nothing looks broken to the owner. The problem only matters if someone can narrow down the space of possible seeds, and by then funds may already be exposed.
That leads to the question many listeners raised: is generating your own entropy becoming the new standard? Rolling dice and feeding the results into a wallet means the key material no longer depends entirely on the device's random number generator. Even if the hardware is flawed, the dice supply independent randomness. The tradeoff is effort and the risk of user error, such as too few rolls, biased dice or mistakes when entering results.
The discussion also draws a line between source-available and truly open source hardware. Coldcard publishes its code for inspection, which lets people read and audit it, but that is not the same as the freedoms and reproducibility that come with a fully open design. The episode argues that being able to read code is not the same as having it reviewed. A bug can survive in public view for years if few people look at the right part with the right expertise.
Passphrases come up as another layer of defense. A strong passphrase added to a seed produces an entirely different wallet, so an attacker who has reconstructed the underlying seed from weak randomness still cannot reach funds protected by a passphrase they do not know. Combined with self-supplied dice entropy, it gives holders two independent protections rather than a single point of trust in the device.
None of this means hardware wallets are unusable. The takeaway is that self-custody has always assumed some verification by the user, and this incident shows what happens when that assumption is left untested. Holders who want to reduce their exposure can add their own entropy, use a long passphrase, and favor designs that outside reviewers can fully inspect and reproduce.
This is part one of the Q&A, with further listener questions on the same incident to follow.
Reporting based on an external source.