
Is Rolling Your Own Entropy The New Standard? (Coldcard Q&A P1)
By Guy Swann
Aired Sep 3, 2026 · 22m · Last boosted 2h ago
Chapters
Show Notes
In this Guy's Take, I walk through listener questions and comments on the Coldcard random number generation failure and what it really means for Bitcoin self-custody. We dig into why the RNG bug went unnoticed for years, the difference between source-available and truly open source hardware, and how dice rolls and strong passphrases change your threat model. I also share how I’m thinking about safer setups going forward. Chapters (00:00:00) - Why Coldcard Questions Remain (00:01:18) - Features vs Core Failure (00:03:19) - Speed Over Security Risk (00:04:54) - Car Without An En...
Nostr Boost Stats
- sats
- 300
- boosts
- 3
- boosters
- 3
- sats
- 300
- boosts
- 3
- T#24
- boosters
- 3
- T#24
- sats
- 300
- boosts
- 3
- T#89
- boosters
- 3
- T#82
- sats
- 300
- boosts
- 3
- boosters
- 3
Nostr Community
Everyone who has boosted Is Rolling Your Own Entropy The New Standard? (Coldcard Q&A P1) on Nostr, ranked by sats sent, all time.
Episode Boosts
Every boost sent to this episode, as published to Nostr, newest first.
-
You should talk to Keith from seed signer about entropy. He has been putting in the work including showing why dice rolls aren’t that “risky” I’m unconvinced anyone should ever use a passphrase - should never be compared to multisig. The single sig focused hardware marketing budgets will always try to convince you otherwise. I have no regrets in trusting level headed research from open source and DIY devs over corporate marketing.
-
I don't get why everyone says random generation was the most important task. It'd have been a better signer than any on the market if it didn't have an RNG at all. It was a task that if you're gonna do has to be done right though.
-
If anything after the entropy fuckup, they were /are lot of eyes on the coldcard code and other wallets . Coldcards force user entropy now (latest firmware) so I think they are now ok to use , even to generate the seed, hopefully they go fully open source not just src code available. So don't throw the device just yet




























