semisol on Nostr: On Twitter, there is some AI-generated misinformation going around about the safety ...
On Twitter, there is some AI-generated misinformation going around about the safety of dice-generated seeds.
Only in the following cases are your seeds NOT SAFE:
🚨 You generated your seed with the Coldcard.
🚨 You used the Password Generator to generate a passphrase, along with a CC-seed.
In the following cases, your funds are SAFE, but you need caution:
⚠️ SeedXOR: If you used the TRNG option, only one of your shards may be enough to recover the seed. However, they must find the specific shard.
⚠️ MicroSD 2FA: The passphrase stored on the SD card can be decrypted. If you destroy it, you’re fine.
⚠️ Cosign: If you used a CC-generated key, the co-sign can be bypassed + your privacy gone. Otherwise, 0 risk.
⚠️ Password generator: Passwords generated by it are not safe. Rotate them, but this has no impact on your funds.
In the following cases, your funds are SAFE:
✅ HSM mode: The weak RNG was used, but does not have any impact on fund safety.
✅ Key Teleport: The weak RNG-generated password was used on top of ECDH, which nullifies risks.
✅ Dice generation: This uses a standard algorithm.
Published at
2026-08-01 22:28:41 UTCEvent JSON
{
"id": "d0adb64cccab1df4205895a7bb41f656226ec6f3e760db84c1bc904d32a54e43",
"pubkey": "52b4a076bcbbbdc3a1aefa3735816cf74993b1b8db202b01c883c58be7fad8bd",
"created_at": 1785623321,
"kind": 1,
"tags": [
[
"client",
"Damus"
]
],
"content": "On Twitter, there is some AI-generated misinformation going around about the safety of dice-generated seeds.\n\nOnly in the following cases are your seeds NOT SAFE:\n🚨 You generated your seed with the Coldcard.\n🚨 You used the Password Generator to generate a passphrase, along with a CC-seed.\n\nIn the following cases, your funds are SAFE, but you need caution:\n⚠️ SeedXOR: If you used the TRNG option, only one of your shards may be enough to recover the seed. However, they must find the specific shard.\n⚠️ MicroSD 2FA: The passphrase stored on the SD card can be decrypted. If you destroy it, you’re fine.\n⚠️ Cosign: If you used a CC-generated key, the co-sign can be bypassed + your privacy gone. Otherwise, 0 risk.\n⚠️ Password generator: Passwords generated by it are not safe. Rotate them, but this has no impact on your funds.\n\nIn the following cases, your funds are SAFE:\n✅ HSM mode: The weak RNG was used, but does not have any impact on fund safety.\n✅ Key Teleport: The weak RNG-generated password was used on top of ECDH, which nullifies risks.\n✅ Dice generation: This uses a standard algorithm.",
"sig": "b274d33daec2ee398eee654bef803e3374f06af8a58aa394ddc57901708ff213a81d23db9f854de0807dbcc557488a672814e4b65780e4e7e77478dcf62f979f"
}