Keeping your recovery words secret is essential. But there is another requirement: nobody should be able to guess them. A wallet generated from a small set of possible secrets can be vulnerable even if its backup never leaves your drawer.Following the Coldcard seed-generation vulnerability, we received many questions about entropy and how wallets generate randomness. Wallets created on a BitBox02 or BitBox02 Nova were not affected by that issue. Still, the underlying question is useful for every Bitcoin user: what makes the secret behind a wallet hard to guess?
What is entropy?
First of all, let’s shed some light on this weird term everyone is throwing around: In simple terms, entropy measures the amount of information – or the level of uncertainty when you’re trying to guess something, depending on from which side you look at it. In the context of a Bitcoin wallet, entropy expresses how hard or easy it is to guess a wallet’s seed phrase.
Entropy is measured in bits. Given that computers also use bits, this naturally makes sense, but there is also a practical reason for it: Imagine flipping a coin, where heads and tails are equally likely outcomes. Some would call these chances “fifty-fifty”, information theorists call it one bit of entropy.
Flip it twice, with each flip independent of the other, and there are 2² or four equally likely sequences: heads–heads, heads–tails, tails–heads and tails–tails. You now have two bits of entropy.
Each additional independent and fair flip doubles the number of possible sequences. Four flips give 16 possibilities. With 256 flips, there are 2²⁵⁶ possibilities, an enormous number that makes “just trying to guess it” impossible in practice.
This is true for a coin flip, because each flip adds the same level of uncertainty, but cannot be applied to everything. Entropy does not necessarily relate to the size or length of a number. Again, let’s imagine 256 bits, but this time, all are either set to zero, or all are set to one. The number itself is very long, but its entropy is now 1 bit, because there is uncertainty between just two cases: all ones or all zeroes.
At the same time, a run of repeated digits does not by itself prove that a random number generator is broken: patterns can occur by chance. What matters is how the number was generated, and what an attacker can know about that process. In other words: you cannot determine the quality of a wallet’s randomness just by looking at its recovery words.
“Looks random” is not good enough
Computers are good at following instructions precisely. They are built to be deterministic. If you ask it to do something multiple times using the same instructions, the output will always be the same. As a result, they are very bad at creating randomness and need help from external entropy sources.
Let’s look at two common ways random numbers are drawn and used on computers.
Pseudorandom number generators
A pseudo-random number generator, or PRNG for short, generates exactly what the name already implies: numbers that are not actually random. They use an algorithm to produce a sequence of numbers from a starting value and internal state. The starting value is often called a seed. Here, that means the seed of the PRNG, not the seed of a Bitcoin wallet.
Start the same generator with the same state, and it always produces the same sequence. This is useful for reproducing a simulation or a software test. But an ordinary PRNG is not designed to keep its next output secret from someone studying its previous outputs.
To return different values every time they are used, PRNGs are often seeded with values tied to the current environment, instead of a static key that never changes. As the most basic example, you could use the current time and date as a seed value.
This works great if you just want a few different values to test something, but it’s obviously far from secure, as anyone can try to guess the time frame you started using the PRNG to reproduce the same “random” numbers.
Cryptographically secure PRNGs
Pseudorandomness is not automatically unsuitable for security. A cryptographically secure PRNG, usually abbreviated CSPRNG, is designed to make its outputs infeasible to predict without knowing its secret internal state. However, it must be initialized with sufficient entropy, and that state must be protected.
Such generators can produce many useful random-looking numbers from a much smaller secret. However, they cannot create additional entropy out of nowhere. A generator whose only secret input is a random 32-bit seed has just 2³² possible starting secrets, even if it produces a 256-bit output. If you didn’t know, this is precisely the mechanism that affected the Coldcard entropy vulnerability in August 2026: wallet creation relied on a CSPRNG seeded with insufficient entropy.
The main thing to take away from this is: PRNGs, whether cryptographically secure or not, do not create random numbers. They are just mathematical functions that derive seemingly random values from an initial secret.
True random number generators
A true random number generator, or TRNG, obtains entropy from a physical process. Electronic circuits can, for example, measure thermal noise caused by the random motion of charge carriers, or tiny variations in timing. They turn these “physical phenomena” into bits.
Because these physical events happen without a predictable pattern or repeating cycle, the data cannot be reproduced or guessed ahead of time – even if you know how the device works.
The physical source still needs careful engineering. Its output may be biased, and hardware can fail. Random-number systems therefore use techniques such as health checks and conditioning, which processes the raw measurements into a more suitable form.
A more illustrative and often cited example for a source of entropy are lava lamps. Their movement and shape is always a bit different and hard to predict. Cloudflare famously has an entire wall of lava lamps, and continuously observes them with cameras to use them as a source of entropy. This is a different kind of TRNG, but in principle, it follows the same process: observing a physical process that is infeasible to predict.

Before you start ordering lava lamps now to create your next Bitcoin wallet, let’s circle back to how the BitBox uses different sources of entropy to generate a wallet.
Why mix multiple sources?
Depending on a single source of entropy is fine, as long as that entropy source works as expected. However, if it turns out there is a hardware flaw in a TRNG leading to biased results, you may have a problem.
There is one neat thing about randomness: It stays. What this means is we can combine multiple sources of entropy, without having to worry about one of them being weaker than the other. What matters is that at least one of them is truly random.
In other words: If you combine a weak random number (e.g. you ask your friend to say ten random numbers) with a truly random number (e.g. 256 independent and fair coin flips), the result is still a truly random number.
The five inputs used by the BitBox
During normal wallet creation, the BitBox combines five different inputs. They have different roles and their quality of randomness is not necessarily equal. The main idea behind them is to be independent of each other, acting as additional failsafes.
- TRNG on the MCU: The microcontroller, or MCU, is the chip that runs the BitBox firmware. Its hardware random-number generator contributes fresh randomness.
- TRNG on the secure chip: A separate hardware source independent of the MCU. The BitBox02 uses an ATECC608B secure chip; the BitBox02 Nova uses the OPTIGA Trust M V3.
- A factory-installed random value: Each BitBox receives its own random value during manufacturing. This stays fixed over the device’s lifetime, so it is an additional input, not fresh randomness for every wallet.
- Entropy from the host device: The BitBoxApp obtains randomness from the operating system’s cryptographic random-number generator (e.g. /dev/urandom on Linux) and supplies it to the BitBox. This is therefore a source outside and independent of the hardware wallet.
- A hash derived from your device password: The BitBox mixes in a cryptographic hash of the password you choose yourself during setup. This makes it a source independent of both the host device and the hardware wallet.
Remember: as long as at least one of these sources is truly random, any of the other four can be biased without affecting the quality of randomness of the resulting wallet.
This design is also described on our security page – and for the experts, it can also be verified in our open-source firmware code. It means wallet generation does not depend on a human choosing a highly random password, or on the connected computer being trustworthy as the only source of randomness.
Rolling your own entropy
Most users can let the BitBox generate their wallet during normal setup – in fact, it’s what we generally recommend users to do. For experienced users who want to supply the randomness themselves, dice offer a physical process they can perform and observe on their own.
Our dice seed generation guide explains how to use dice and a printed lookup table to generate recovery words. In the 24-word method, you generate the first 23 words, enter them directly on the BitBox through the standard recovery workflow, and choose from the eight valid final words it displays. The last word contains a checksum, which is why you need the BitBox to help you choose one that is valid.
The important thing here is to actually follow the full guide rather than improvising on the fly. Biased dice, inconsistent ordering, recording errors or choosing words that “feel random” can undermine the result. Keep the process private and the words offline.
Note that this method replaces the normal generation of recovery words with your own randomness as a single source – it does not mix your dice rolls with the other five sources of entropy.
Adding your own entropy
The BitBox does not offer a dedicated step to mix in dice rolls or coin flips into an otherwise automatically generated wallet. Advanced users can nevertheless contribute their own randomness through the initial device password.
A long, independently generated device password, such as a sequence of words selected with dice, contributes as one of the entropy sources when the new wallet is created. In other words: If you want to add your own entropy, using the device password is a way to achieve that. After creating and backing up the wallet, you can change to a more practical device password through the device settings. At that point, the wallet is already generated, so changing the device password has no effect on the wallet entropy anymore.
Note that an optional passphrase, which is also often referred to in this context, serves a different purpose. A strong, independently generated passphrase adds a secret to a later step in the derivation of your private keys, effectively creating a separate wallet. It does not alter the recovery words or improve their entropy. Protection is only added to the passphrase wallet itself, provided the passphrase is strong enough.
These are advanced choices we mention for the sake of completeness, not requirements for a secure setup. Read about the benefits and risks of optional passphrases before using one.
Conclusion
Wallet entropy is arguably the most important aspect of any Bitcoin wallet. If the random value used to create it is not actually random, an attacker may be able to recreate the wallet without ever seeing your recovery words.
The BitBox combines multiple sources of entropy to avoid reliance on any single one. The two independent TRNGs and the factory-installed random value provide sources from within the device. Host entropy adds randomness from your connected computer or phone, independent of the BitBox. And the hash of your device password contributes your own input, which you can choose independently of both the host and the BitBox.
For most users, the practical steps are straightforward: let the BitBox generate the wallet, verify your backup and store it securely offline. Using dice is an option for those who understand how it works, but it is not a necessary step.
And remember: nobody can check the quality of your wallet’s randomness by asking you to disclose your recovery words. BitBox will never ask for them. There are many phishing campaigns these days trying to leverage the entropy topic to inflict fear and urgency. Never enter your recovery words into a website, an “entropy checker” or a support chat.

Don’t own a BitBox yet?
Keeping your crypto secure doesn't have to be hard. The BitBox hardware wallets store the private keys for your cryptocurrencies offline. So you can manage your coins safely.
Both the BitBox02 Nova and the BitBox02 also come in a Bitcoin-only edition, featuring a radically focused firmware: less code means less attack surface, which further improves your security when only storing bitcoin.
Buy the BitBox02 Nova or grab a BitBox02 in our shop!

Shift Crypto is a privately-held company based in Zurich, Switzerland. Our team of Bitcoin contributors, crypto experts, and security engineers builds products that enable customers to enjoy a stress-free journey from novice to mastery level of cryptocurrency management. The BitBox02, our second generation hardware wallet, lets users store, protect, and transact Bitcoin and other cryptocurrencies with ease — along with its software companion, the BitBoxApp!
