Firstly, a very beautiful visualization of the Coldcard Hack:

This particularity resonates with the thread I created a long time ago:
There are 2^256 private keys out there: how big is that number?Regarding the hack, I was almost rushing to rebuild my setup from scratch. But not being affected, I had a double thoughts about refactoring my cold wallet in a multisig with very convolute password.
I think the major risk here is the user: having a too complicated setup puts the operational risk very high, and I am thinking if this is the real risk, when the entropy used to generate the seed is sufficient.
I am finding it quite annoying how much the bitcoin podcast space had moved from single sig to multi-sig, and they are not even accepting that multi-sig can be a good practice for an individual (because it is too complicated blah blah blah). It is a bit ridiculous how fast several of them seemed to have switched to throw self-custody under the bus.
So in some sense the podcast scene has been pumping the shit out of products that end up fucking up both the privacy and the self-sovereignty aspects of bitcoin.
There were quite a few guys on this forum proclaiming that Bitkey is an inferior product to regular hardware wallets (there is even a thread, I think that has not been active lately) because the Bitkey is not really a hardware wallet in the sense of privacy and self-sovereignty as we know hardware wallets to offer (or supposed to offer) since there seem to be several ways that coins can end up getting recovered through the Bitkey without the user's key even being involved. At least, recently Bitkey added a screen, but still there seems to be a bit of theater in terms of what a bitcoin wallet should be (referring to privacy, self-sovereignty and security).
I think that self-custody by single sig and a strong passphrase and even self-custody multi-sig are still quite viable (and probably even preferable) paths - even though sometimes there could be multi-sig that would be shared amongst family members, which could work for some kinds of shared funds, and of course, in some business arrangements multi-sig within a group of key players of the business might also be quite practical for how to treat some of the funds.
I don't like the seeming recent push to give up self-autonomy or the abilities to act autonomously as the base case of bitcoin, even though there could be some cases in which a third key might be given to a 3rd party, but not as our ideas of what are base case uses of bitcoin.
...
I don't want to diminish the idea of the punches and stamping stuff into metal.
What bothers me is the execution. Putting the punches in such a "tight" container won't mix them very well even when you rotate the container and pick punches blind-folded or with closed eyes. Do you really think humans pick punches in a completely random way out of such container even when they don't look at what they're doing?
There will very likely be some bias based on the initial placement of punches. It may look random and maybe doesn't really matter, but it's not any news that humans are commonly terrible at generating good entropy (by inventing some own procedures).
Use dice or a known way to throw coins where the latter could even compensate for biased coins or if you fear that your way of tossing coins introduces a bias by itself.
I, personally, like the idea of using a deck of cards. That is 52 possible outcomes as compared with 6 on the dice and 2 on a coin should allow for fewer draws. In theory, instead of rolling a dice 100 times, you could pick 45 cards for the same amount of entropy (I checked this through AI). That saves a lot of labor. Too bad hardware wallets do not have an option to choose playing cards for their entropy creation - even though some of us might be skeptical if the wallets are the ones inputting the supposed entropy.
To practice this idea of cards, I did go to the
Github Repo of the Ian Coleman BIP39 Tool in order to try out the inputing of cards, and I had to ask AI to get assistance to make sure that I was setting it up (and doing) it correctly, so then I did a practice round of inputting my cards online (and the preference for security is to do it off-line), and it took me 61 draws to reach 256 bits of entropy, and also it was amazing that I had 27 duplicate draws (a few of them were cards I drew 3 times, such as the king of hearts 3 times and the king of spades 4 times, and I drew the jack of hearts two times, but those two times were twice in a row.
It still is a lot of work to help to ensure that the wallet is not screwing up entropy, so of course, using a tool like this still has to take some safeguards that the words are not being viewed by someone else - as compared with if we were to just have the 2048 words and to draw them from a hat.
By the way, since I had to draw cards 61 times in order to achieve 256 bits of entropy, I suppose that is not much different from rolling dice 100 times, since we could have 10 dice and then just roll 10 at a time 10 times in order to reach 100 rolls... so maybe my going through the exercise of drawing cards 61 times causes me to be less enthusiastic about cards as an entropy solution.
The only thing left are three dust addresses totalling less than 1000 satoshis. Everything else is gone, so that explains why the attackers moved to weak passphrases; there was nothing else left to do. Do not think dice rolls helped, those wallets do exist, and are also gone.
You believe that the dice rolls were not adding any entropy for those who ended up choosing the dice rolls, and that ColdCard's software was not accounting for the dice rolls for those who chose dice rolls - which supposedly 50 rolls would cause 128 bits of entropy and 100 rolls 256 bits of entropy.