Roll Your Own Bitcoin Seed: How to Create a Wallet You Don't Have to Trust

Roll Your Own Bitcoin Seed: How to Create a Wallet You Don't Have to Trust

By Zachary Addair · 8/4/2026

In late July 2026, attackers drained thousands of ColdCard wallets by exploiting a years-old firmware bug that quietly weakened the device's randomness. The seeds were guessable. But there was a group the thieves couldn't touch: the people who had rolled their own dice when they set up. This is a plain-language guide to doing exactly that, two ways. The easy Blockstream Jade version, and the hardcore air-gapped version, plus how to keep the second one safe without needing a computer science degree.

On July 30, 2026, in a window of about forty minutes, someone moved roughly 594 bitcoin out of around 500 wallets. Then they kept going. Wave after wave, across days, the total climbed past 1,150 coins, then kept climbing toward something like 1,367 bitcoin spread across more than 4,500 addresses. Call it eighty-some million dollars, and understand that the figure was still moving as the dust settled.

The people who were robbed were mostly not the people you'd expect. They'd done the thing we all tell you to do. They bought a well-regarded hardware wallet, a ColdCard, one of the most respected signing devices in Bitcoin. They took self-custody seriously. They held their own keys.

And they still got cleaned out. So what actually happened?

The bug was in the randomness

Here's the uncomfortable heart of it. A code change back on March 1, 2021 caused certain ColdCards to silently fall back to a software random number generator instead of the hardware one during seed creation. On the Mk3, the practical result was brutal: the effective search space for a seed collapsed from the 128-plus bits it was supposed to have down to something closer to 40 bits. (Mk2 and Mk3 units on firmware 4.0.1 through 4.1.9 were the core of it. Some later models generated before the fixed releases came out weaker too.)

Forty bits sounds abstract. It isn't. It means a determined attacker with a decent computer can precompute the possible seeds offline, sit on the list, and then, one quiet afternoon, sweep every wallet that used one. Which is precisely what happened. The keys were never "stolen" in the movie sense. They were guessed, because there weren't enough genuinely random possibilities to hide inside.

Coinkite, ColdCard's maker, patched the firmware fast and did the responsible thing by telling affected users to move their coins to a fresh seed. But the deeper lesson doesn't live in the patch notes. It lives in one line of their advisory, the line that should reframe how you think about every hardware wallet you'll ever own.

Users who had added at least 50 of their own dice rolls during setup were not at risk. Their dice alone had contributed at least 128 bits of entropy. The device's broken randomness simply didn't matter, because they hadn't relied on it.

The people who rolled dice were fine.

What "entropy" really is, and why it's so damn important

You see, a Bitcoin seed phrase (those 12 or 24 words) isn't really "words." It's a number. A staggeringly large, supposedly unguessable number, dressed up in human-readable clothing so you can write it on paper without going cross-eyed. The security of everything downstream, your PIN, your steel plate, your air gap, your passphrase, all of it, rests on one question asked at the very beginning: was that number actually random?

The quality of your randomness has a name in this world. Entropy. It's just a measure of how much genuine unpredictability went into the number. A fair six-sided die produces about 2.585 bits of entropy per roll. Roll it 50 times and you've generated roughly 129 bits, which is exactly the target for a 12-word seed. Roll it 99 times and you're at about 256 bits, the target for 24 words.

Now here's the thing nobody tells you when you unbox a shiny signing device. When you let the device generate your seed, you are trusting its entropy. You're trusting the chip, the firmware, the build process, and the integration code, as one unbroken chain, to have produced a real random number and not a predictable one. You can't see that randomness. You can't audit it after the fact. As one write-up put it after the hack, a wallet's fate is decided at the moment of creation, before a single one of your other precautions gets a chance to matter.

The ColdCard incident wasn't a freak event. It was a demonstration of a structural truth: device-generated randomness asks you to trust a black box at the one step where trust is most expensive.

This is just "don't trust, verify" applied to step one

Bitcoiners love a maxim, and the best one is "don't trust, verify." We apply it everywhere. We run our own nodes so we don't trust someone else's version of the ledger. We verify receive addresses on the device screen. We hold our own keys precisely so we don't have to trust an exchange that can freeze us, a custodian that can lose our stack, or a bank that needs the coins to keep the lights on.

And then, at the single most important moment, the creation of the key itself, most people quietly hand the job back to a machine and trust it completely.

The cypherpunks saw this coming a long time ago. Nick Szabo, one of the intellectual godfathers of Bitcoin, wrote an essay in 2001 with a title that could be tattooed on the inside of every hardware wallet: "Trusted Third Parties Are Security Holes." His point was that every entity you're forced to trust is a place where things can quietly go wrong, a soft spot in an otherwise hard system. The genius of Bitcoin was replacing a trusted third party (the central bank, the clearing house) with math anyone can check.

A device's internal RNG is a trusted third party hiding in your own pocket. Dice are how remove that trusted third party entirely.

Before you start: three rules that keep you safe

These apply to both methods below. They are not optional, and they're the part where people actually lose money, so I'm putting them first.

  1. Do it in private. No cameras, no phones on the table filming your rolls, no smart speakers listening. Your dice results are your seed. Treat each roll like a digit of your bank password, because that's what it is.
  2. Never type your finished seed into an internet-connected device. Not a website, not a note-taking app, not a photo. If a tool is involved, it runs offline, on a device with no network, ideally one that never touches the internet again.
  3. Test before you fund. Once your wallet exists, verify a receive address on the device itself, send a tiny amount, confirm it arrives and that you can spend it, and only then move real money.

Good. Now the two paths.

Method 1: The Blockstream Jade way (friendly, no math)

This is the one to recommend to a smart friend who is not a nerd. It's clean, it's physical, and it involves zero arithmetic on your part. Blockstream published a printable guide for it, and it's genuinely elegant (link below).

The trick is a small numerical coincidence that, as a Bitcoiner, I find beautiful. The BIP39 word list has exactly 2,048 words. And 16 times 16 times 8 equals exactly 2,048. So if you take two 16-sided dice and one 8-sided die and roll all three together, every possible result points to exactly one word. No leftovers, no bias, no fudging. One throw, one word, chosen with full randomness by your own hand.

Here's the process:

  1. Get the dice. You need two 16-sided dice (mark one as D1, one as D2) and one 8-sided die (D3). Any decent tabletop-gaming dice set has these, but if you only have D20s, like myself, you can just throw out any rolls with 17-20 and roll again. Print Blockstream's lookup table, linked at the end.
  2. Roll all three at once. Say D1 lands on 10, D2 on 9, D3 on 8. Find that combination on the table. In Blockstream's example, 10-9-8 gives you the word "ocean." Write it down as word one.
  3. Repeat. Roll again for word two, again for word three, and so on. Do this 11 times for a 12-word seed, or 23 times for a 24-word seed.
  4. Let the device finish the last word. Here's the one clever bit. The final word of a BIP39 seed isn't fully free; it carries a checksum, a built-in error-detection code. So you don't roll it. You enter your 11 (or 23) rolled words into the Jade using its "Calculate" feature, and Jade computes a valid final word for you.

Notice what you just did. Every scrap of randomness in that seed came from your dice, on your table, in your hand. The Jade never generated your entropy. All it did was compute a checksum, which is public, deterministic math that reveals nothing and protects nothing secret. Even if you distrusted the device entirely, it had no room to weaken you. That's the whole point.

And you don't have to use a Jade. The Jade is just the friendliest device for this final step. The same dice-to-words method works with any signing device or wallet that lets you import a seed or calculate a checksum word. Blockstream even says so on the guide: any tool that requires final-word calculation will do. Two strong open-source options, if you'd rather not buy a Jade, are SeedSigner and Krux. Both are cheap, air-gapped, camera-based signers you can build yourself, and both have a built-in dice-entropy mode that walks you through it. Whichever you pick, once the seed exists you can load it into whatever wallet you actually plan to use day to day.

That's it. For most people, most of the time, Method 1 is the right answer. Full self-generated entropy, no computer, no math, an afternoon's work.

Method 2: The Arman the Parman way (maximum paranoia, air-gapped)

Now for the black-diamond run. Arman the Parman, a well-known self-custody educator, publishes a dice method built for people who want to trust nothing and no one, not even a single signing device, and who are setting up serious or multisignature cold storage. It's more work and it involves real steps on an air-gapped computer. It is also bulletproof when done correctly. Here's the shape of it, in plain terms.

  1. Turn dice into bits. Roll dice and record each result as a single binary digit: a 1, 2, or 3 becomes 0, and a 4, 5, or 6 becomes 1. (Three low faces, three high faces, perfectly fair.) Keep going until you've recorded 256 of these digits for a 24-word seed. Rolling five dice at a time and reading them left to right speeds this up.
  2. Turn bits into words. Chop your 256 digits into groups of 11. Convert each 11-digit binary group into a regular number, add 1, and look that number up on the official BIP39 word list. Each group gives you one word. You'll get 23 words this way, with a few digits left over.
  3. Compute the checksum word. This is the step that scares people. On an offline computer, you run your bit string through a SHA256 hash, take the first few bits of the result, combine them with your leftover digits, and that produces your 24th word. Arman gives the exact command.
  4. Verify across independent tools. Enter your 24 words into a downloaded, offline copy of Ian Coleman's BIP39 tool and confirm the entropy matches your dice. Then do it again in Electrum. If two independent programs agree on the same wallet, you know your words are right, and you never trusted just one of them.

Every step is designed so that no single piece of hardware or software has to be trusted on its own. That's the payoff, and for a large multisig treasury, it's worth the effort.

How to simplify Arman's method without giving up any safety

Can we make this easier without making it weaker? Yes, and the key is understanding which steps carry your security and which are just plumbing.

The security lives entirely in step one. The dice. That's your entropy, and nothing else in the process can add to it or (if you protect it) take it away. Steps two, three, and four are just format conversion and double-checking. So here's where you can safely cut:

Skip the manual checksum math, not the dice. The 24th word contains a checksum, and a checksum is public, deterministic, and secret-free. It carries no entropy. So the scariest step, running SHA256 on an air-gapped Linux terminal, isn't protecting anything secret. You can hand that job to a purpose-built, air-gapped device without losing a single bit of real security, because the thing it's computing was never secret in the first place. Arman himself notes you can even just guess-and-check the final word.

Let an air-gapped signer do the conversion. Instead of converting binary to words by hand on a general-purpose computer, feed your dice straight into a dedicated open-source signer that has a dice mode: SeedSigner, or Krux both accept dice rolls directly and produce the finished seed. You keep the crown jewel (your own dice entropy) and you drop the two most error-prone steps (hand math and juggling a general-purpose computer). A dedicated signer that only ever does Bitcoin, never stores your seed, and never touches a network is a smaller thing to trust than a laptop with an operating system and a thousand other programs on it.

Match the verification to the stakes. The full cross-check across two independent programs is genuinely valuable for a high-value or multisig setup, and I wouldn't skip it there. For a single-signature wallet you're funding modestly, verifying on one independent offline tool, plus the mandatory test transaction, is a reasonable stopping point.

So the simplified-but-still-safe version reads like this: roll your own dice for full entropy, feed them into a cheap air-gapped signer built only for this job, verify the result on one independent offline tool, and send a test transaction before you fund it. You've kept every ounce of the safety that matters (owner-controlled randomness you can verify) and shed the parts that were only ever mechanics. The difference between Method 1 and this is really just how many independent tools you make agree before you trust the result.

The point of the whole exercise

Step back and look at what you've actually done by rolling dice. You've removed a trusted third party from the most important moment in your Bitcoin life. You've made yourself the source of your own randomness, which means the source of your own security, which means, in the end, the source of your own sovereignty. No manufacturer's firmware sits between you and the unguessable number that is your wealth. You watched it come into existence, one roll at a time.

That's not paranoia. That's the entire thesis of Bitcoin, carried through to its first and most literal step. We don't trust the central bank to be honest about the money supply; we verify it, block by block. We don't trust a custodian to still have our coins on the morning we want them; we hold the keys ourselves. And now we don't trust a black box to have rolled the dice fairly, because we rolled them ourselves, on the kitchen table, where we could see.

Not your keys, not your coins. And underneath that, quieter but just as true: not your entropy, not your keys. It all starts with the randomness. Own that, and you own everything downstream of it.

If you want the convenience of buying and holding Bitcoin without ever giving up that self-custody, that's the whole reason Bitcoin Well exists: modern, easy access to Bitcoin, with your keys staying yours from the very first roll.

Links and further reading

ZA
Zachary Addair

Philosopher, computer nerd and Bitcoin Maxi since 2014. Helping spread the good word of Bitcoin and Freedom.