All Episodes

Bitcoin Audible

Is Rolling Your Own Entropy The New Standard? (Coldcard Q&A P1)

By Guy Swann

Aired Sep 3, 2026 · 22m · Last boosted 2h ago

View Show
Show Notes

In this Guy's Take, I walk through listener questions and comments on the Coldcard random number generation failure and what it really means for Bitcoin self-custody. We dig into why the RNG bug went unnoticed for years, the difference between source-available and truly open source hardware, and how dice rolls and strong passphrases change your threat model. I also share how I’m thinking about safer setups going forward. Chapters (00:00:00) - Why Coldcard Questions Remain (00:01:18) - Features vs Core Failure (00:03:19) - Speed Over Security Risk (00:04:54) - Car Without An En...

Nostr Boost Stats

sats
300
boosts
3
boosters
3

Nostr Community

Everyone who has boosted Is Rolling Your Own Entropy The New Standard? (Coldcard Q&A P1) on Nostr, ranked by sats sent, all time.

  1. armstrys 100 sats
  2. jespada 100 sats
  3. Cykros 100 sats
Other Episodes This Community Boosts Other shows' episodes boosted by people who boosted this episode
Nostr Boosts:25k
npub1eq94yj8…Dec 4, 2024
25k
Congrats on 1,000! Here’s to many more! 🎉🎊
See all boosts
Nostr Boosts:10k
npub1eq94yj8…Jul 20, 2024
10k
Just catching up on this weeks podcasts... Awesome show! Was awesome to chat with someone about this in person and hope we can do it again soon!
See all boosts
Nostr Boosts:1.6k
CykrosAug 18, 2026
1.6k
A million times yes. Thank you for addressing this in the right way. You're one of the only podcasts that hasn't responded to Coinkite with yet more bad options. Very much excited that Learning Bitcoin From The Command Line is getting a new edition too -- long overdue.
See all boosts
Jul 22, 2026
Nostr Boosts:1k
CykrosJul 22, 2026
1k
Re:other nodes and making news, you're clearly not watching Eric Voskuil on Twitter. Libbitcoin 4 just did IBD in 14 minutes on a consumer connection (with assumevalid height of 950k) and 55 min for full validation. Older than Knots, and older than Core being called, well, Core. They slept for a good few years but are waking up with a vengeance.
See all boosts
Nostr Boosts:1k
npub1eq94yj8…Jan 14, 2026
1k
lol of course Michael Saylor is unhinged… are we surprised?
See all boosts
Nostr Boosts:1k
CykrosMay 19, 2025
1k
Thanks for removing the friction from consuming Mises.
See all boosts
Nostr Boosts:580
CykrosAug 24, 2026
580
Welcome back Walker, congrats on the bigger family Also, xpubs will only give unhardened addresses. That said, I expect a Venn diagram of people who didn't roll dice and people using hardened addresses is probably two separate circles.
See all boosts
Nostr Boosts:580
CykrosJul 9, 2026
580
Welcome back
See all boosts
Nostr Boosts:500
CykrosAug 26, 2026
500
Hope this counts as a replacement for lost sponsor revenue per this listener.
See all boosts
Nostr Boosts:500
CykrosAug 4, 2026
500
The cloak and dagger shit with Switck is heating up. People were already looking for a reason for this to be inside. Still not totally convinced but it looks sketchy as fuck. Never been more glad I had fun playing dice games with my bitcoin.
See all boosts
Nostr Boosts:500
CykrosJul 23, 2026
500
Boston Bitdevs is coming up on July 30 at MIT Building 4. Be sure to RSVP through bostonbitdevs.org (or with the link if David wants to put it in notes). https://app.evento.so/e/evt_3M48gmwDKdbzNc63 Come with questions!
See all boosts
Nostr Boosts:500
CykrosJun 27, 2026
500
One of the best WBD's yet. Dines' coverage of the Eurodollar mechanics here and the shift that happened with LIBOR to SOFR is something far too few people are talking about (Luongo notwithstanding).
See all boosts
Nostr Boosts:500
CykrosMay 7, 2025
500
MOAR LUONGO
See all boosts
Nostr Boosts:500
CykrosDec 30, 2024
500
One of the best podcasts on the technical sides of Bitcoin I've encountered. Helps explain why IBD is taking forever on my raspi 4.
See all boosts
Nostr Boosts:200
jespadaFeb 22, 2025
100
#btc all the things
CykrosFeb 21, 2025
100
Bring on the helicopter sats!
See all boosts
Nostr Boosts:400
CykrosJan 6, 2026
400
Welcome back! Your break sounds like it was good. Missed your updates.
See all boosts
Nostr Boosts:200
jespadaFeb 19, 2025
100
Pain is the way people will learn, shitcoins gonna shitcoin , so hdsp for them until they learn
jespadaFeb 19, 2025
100
Zap zap
See all boosts
Nostr Boosts:100
CykrosAug 27, 2026
100
A hung jury isn't an acquittal, it's a mistrial. Jurors aren't voting, they're deliberating to arrive at consensus. If they can't, it's a do over. Double jeopardy only applies if a verdict is reached.
See all boosts
Aug 19, 2026
Nostr Boosts:100
CykrosAug 20, 2026
100
The Jade and Jade Plus use ESP32 microcontrollers. Just FYI.
See all boosts
Nostr Boosts:100
CykrosAug 10, 2026
100
Your analogy is odd given that the twentyfirst amendment struck the 18th amendment from the constitution... The issue with 110 is that it was ineffective and targeting an issue that barely qualifies as one. 4 MB is 4 MB.
See all boosts
Nostr Boosts:100
CykrosAug 7, 2026
100
The point of airgapping isn't that QR'sbor SD cards are inherently more secure than USB or Bluetooth. It's that the amount of data is far more limited and easier to audit with lower tech methods. If you ask me floppy disks would be even better, as SD cards have firmware that could be an attack vector. But floppies are prohibitively hard to implement in 2026.
See all boosts
Nostr Boosts:100
CykrosAug 4, 2026
100
Some of the best presentation of the issue I've encountered. Education not recommendations. The multisig evangelists are dangerous, and the guy who hosts the exchange is telling us to self custody. Man of the People @npub1cn4t4cd78… .
See all boosts
Jul 31, 2026
Nostr Boosts:100
CykrosJul 31, 2026
100
It turns out Leopold was NOT the biggest story of the day @npub1ahe2832lq… .
See all boosts
Jul 22, 2026
Nostr Boosts:100
CykrosJul 23, 2026
100
Guy with half a brain still listening reporting in 😂
See all boosts
Nostr Boosts:100
CykrosJul 10, 2026
100
I'm thinking the four year cycle is not as there as some have said. Stephen Perrenod has some great writings and math to go with it on some harmonics describing oscillations around the power law trend that seem to make more sense when thinking about fundamental factors. And it follows log time, with the last peak in 2017 and the next in 2027. There are sub harmonics, hence oscillations in between. The fun thing is, it captures the 2011 run up too...
See all boosts
Nostr Boosts:100
CykrosJul 10, 2026
100
So glad we finally got some weigh in here on the silliness that is 110. And yea, probably was a low blow last time I asked you about this topic on zoom Natalie...
See all boosts
Nostr Boosts:100
CykrosJul 9, 2026
100
Someone's out to capture Bitcoin all right. It's the ones who are running thebonly implementation and mining pool that supports this dumbass fork. They're just a lot more retarded than even Bcashers, with a single percent of blocks in any signalling period so far with only 2 to go. Most don't know enough about Bitcoin to realize how cooked they are though. And the ones who do are too sour to do anything about it. Have fun storming the castle.
See all boosts
Nostr Boosts:100
CykrosJun 25, 2026
100
I gotta say Rustin, I'm pretty disappointed in the portrayal of spam being about data space. That is hard capped at 4 MB/block. Being opposed to using that space is to be opposed to Bitcoin being used. Spam has other issues, sure. But the size on nodes is Simply noise.
See all boosts
Nostr Boosts:100
CykrosJun 22, 2026
100
Just gonna point out as a non-MSTR lover that $82.50 with 11.50 in annual dividends is a 13.94% yield. So when you say STRC hasn't done well but SATA has it's a bit weird as they're trading for the same yield...
See all boosts

Episode Boosts

Every boost sent to this episode, as published to Nostr, newest first.

  • 100 via Fountain
    You should talk to Keith from seed signer about entropy. He has been putting in the work including showing why dice rolls aren’t that “risky” I’m unconvinced anyone should ever use a passphrase - should never be compared to multisig. The single sig focused hardware marketing budgets will always try to convince you otherwise. I have no regrets in trusting level headed research from open source and DIY devs over corporate marketing.
  • 100 via Fountain
    I don't get why everyone says random generation was the most important task. It'd have been a better signer than any on the market if it didn't have an RNG at all. It was a task that if you're gonna do has to be done right though.
  • 100 via Fountain
    If anything after the entropy fuckup, they were /are lot of eyes on the coldcard code and other wallets . Coldcards force user entropy now (latest firmware) so I think they are now ok to use , even to generate the seed, hopefully they go fully open source not just src code available. So don't throw the device just yet