coldcard rng tripwire - public scoreboard
Own a Coldcard? Treat any wallet created on firmware 4.x as compromised and move your funds to a freshly generated wallet now. Background and updates: from @Rob1Ham

What is this?

Coldcard hardware wallets generated wallet seeds with a broken random-number generator: a predictable software pseudo-RNG instead of true hardware entropy. The private keys can be brute-forced and the coins swept.If affected, migrate your funds now.

We fund decoy “honeypot” wallets carrying that exact flaw on mainnet, some hardened with extra dice rolls or a passphrase, and track which ones an attacker sweeps and how fast. This maps the frontier of what coins are being confiscated. Read the methodology →

honeypots3
live2
swept1
value exposed~0.0008 BTC
fastest sweep01:18
frontier-

recent activity last 5 events

time (utc) event difficulty value band tx
2026-08-04 21:37 honeypot swept HP-3146 trivial <=0.001 2b5c93..7177ad ->
2026-08-04 20:50 honeypot funded HP-96ED low (pass) <=0.001 -
2026-08-04 20:50 honeypot funded HP-FA90 low (pass) <=0.001 -
2026-08-04 20:19 honeypot funded HP-3146 trivial <=0.001 -

honeypots

handle device difficulty sec(bits) value band status age / time-to-sweep
HP-96ED mk3 v4 low (pass) 11 <=0.001 LIVE live 01:52
HP-FA90 mk3 v4 low (pass) 11 <=0.001 LIVE live 01:52
HP-3146 mk3 v4 trivial 0 <=0.001 SWEPT -> swept in 01:18
showing 3 - sort: status (live first), handle

frontier summary

difficulty deployed swept fastest still live
trivial 1 1 01:18 0
low (pass) 2 0 - 2
mid 0 0 - 0
high 0 0 - 0
extreme 0 0 - 0
difficulty bands added entropy over the attacker-known seed · dice ~2.585 bits/roll · passphrase 11 bits/word
trivial0 bitsthe control — no dice, no passphrase
low1–15 bits1–5 dice rolls, or a 1-word passphrase
mid16–30 bits6–11 dice rolls, or a 2-word passphrase
high31–45 bits12–17 dice rolls, or a 3–4 word passphrase
extreme>45 bits18+ dice rolls, or a 5+ word passphrase