Rolling your own Bitcoin seed: A guide

Bitcoin-Seed selbst würfeln: Eine Anleitung

Your seed is the foundation of your self-custody: All keys and addresses of your wallet are derived from it. Normally, your hardware wallet's random number generator creates it. But you can also create it yourself, with dice, paper and a little patience. This guide shows you step by step how it works.

Why roll your own seed at all?

The honest answer first: You don't have to do this. A good hardware wallet generates high-quality randomness from several independent sources. The BitBox02, for example, combines five sources of entropy, from manufacturing to the device password to the secure chip, and each source can only add randomness, never reduce it.

Why many people do it anyway: When you roll dice, you create the randomness yourself and can verify it completely. You don't have to trust any random number generator, your entropy is lying right there on the table. How justified that distrust can be was demonstrated by the Coldcard entropy bug in the summer of 2026: Affected devices generated far weaker seeds than assumed.

Just one thing matters: If you do it yourself, do it properly. Humans are bad at making up "random" words. That is why we roll dice, and that is why this guide follows the proven diceware method by BitBox.

What you need

  • Five dice (a single die works too, it just takes longer)
  • A coin (or a sixth die: 1 to 3 is heads, 4 to 6 is tails)
  • A printout of the diceware lookup table with all 2048 BIP39 words
  • A hardware wallet that can calculate the final word. We show the process on the BitBox02, but it also works with the SeedSigner or Coldcard, for example
  • Pen and paper, or a durable backup medium like the Copiaro Seed Saver

Make sure you are in a private environment: Remove or switch off electronic devices, put your smartphone away, no cameras in sight. Don't say the numbers or words out loud. Write the words down only on paper or a backup medium like the Seed Saver, never digitally.

How to roll good randomness

Decide on a method beforehand and follow it through, instead of making "spontaneous" decisions along the way. The procedure:

  1. Roll all five dice and the coin together.
  2. Arrange all dice showing 1 to 4 in a line from left to right (and top to bottom if in doubt).
  3. Reroll all dice showing 5 or 6 until they show 1 to 4, and add them to the end of the line.
  4. Place the coin at the end of the line.

This gives you five digits between 1 and 4 plus one heads or tails. That is 11 bits of randomness, exactly one BIP39 word.

Tip: With five dice in five different colors, you can skip the arranging step entirely. You define a color order once (e.g. blue, green, purple, red, yellow) and simply read off the digits in that order after each roll. That is exactly what our casino dice set in 5 colors is for.

Looking up the first 23 words

After each roll, you look up the word in the lookup table:

  • The first die gives you the page of the table.
  • Dice 1 to 4 determine the row.
  • Die 5 and the coin determine the column.

Write the word down on your backup. Repeat until you have 23 words. You don't roll the 24th word, more on that in a moment.

Word 24: Your hardware wallet takes over

The 24th word is the checksum: It must be calculated from the other 23 words and cannot be chosen freely. Doing that by hand is practically impossible, so your hardware wallet takes care of it. You enter the 23 rolled words directly on the device (and nowhere else), the device determines the valid options for the final word, you pick one of them at random and write it down as word 24. Once the device confirms the word set as valid, you set your device password and you are done. On the BitBox02 this works in the setup wizard via "Restore from recovery words", and it works just the same on the SeedSigner, Coldcard and other devices with checksum completion. The same principle applies to 12-word seeds: There, too, the final word is partly a checksum.

Your wallet is now based entirely on your own randomness. The word set follows the BIP39 standard and works in any compatible wallet, which you can verify at any time by importing it into another device.

Verify your backup before the first deposit

Your notes are now the only backup of your new wallet. Verify them before you deposit even a single satoshi: In the BitBoxApp, choose "Show recovery words" under "Manage device", go through the words on the device and complete the word-by-word confirmation that follows. Only when this works without errors is your backup confirmed. After that, it is worth thinking about durability and redundancy: A fire- and corrosion-resistant medium like the Copiaro Seed Saver and a second backup in a separate location.

Excursus: Do you need casino dice for this?

No. A die from your board game shelf provides enough randomness for a secure seed, especially since only the numbers 1 to 4 count in the BitBox method. Why we carry casino dice anyway:

  • Uniform distribution by design: Razor edges, pips inlaid flush with the surface instead of drilled, and a balanced acrylic body minimize systematic bias. Ordinary board game dice with rounded corners and drilled pips are measurably less balanced.
  • Transparency: The clear acrylic would make any tampering inside visible. In casinos, this is the safeguard against loaded dice.
  • It feels right: If you create the randomness protecting your savings yourself, you reach for the best available tool. The BitBox guide, too, recommends "preferably really good casino-grade" dice.

More important than the construction of the dice, by the way, is how you roll: Shake the dice vigorously in a dice cup and let them roll out freely on a suitable surface (e.g. a felt mat) instead of tumbling them out of your hand. Proper mixing does more for randomness than any precision manufacturing.

And you can create enough randomness with ordinary dice as well: A slight imbalance makes individual numbers only marginally more likely and barely reduces the actual entropy. If you want to be sure, compensate with more rolls, so with methods that take raw dice rolls, like on the Coldcard, simply roll considerably more than the minimum.

In our shop you will find serialized 19 mm casino dice as a set of 5: In a single color (five colors available) or as a mixed set of five different colors for reading off your rolls by color order.

Looking back: What the Coldcard incident teaches about own entropy

Coldcard devices have long offered "Add Dice Rolls", a way to mix your own dice rolls into seed generation. When the entropy bug in the Coldcard firmware became known in the summer of 2026, the value of this feature became obvious: According to Coinkite, anyone who had generated their seed with at least 50 independent, private dice rolls was not at risk despite the vulnerability. Their own entropy compensated for the device's weakness. That is exactly the point of this guide. You can find the background in our article on the Coldcard entropy incident.

The most important safety rules

Checklist:

  • Roll in private and offline, with no electronic devices nearby.
  • Don't say the numbers or words out loud.
  • No photos, no notes on your phone, no markings in the lookup table.
  • The words belong only on your backup and are entered only on the hardware wallet, never on a computer, smartphone or website.
  • Burn any scratch paper if you worked with a single die and noted intermediate results.

Note: This guide follows the diceware method by BitBox (Shift Crypto AG) and reflects our state of knowledge as of August 23, 2026. The current original instructions of the respective manufacturer always take precedence. We accept no liability for completeness or currency.

Sources and further reading

Everything for your own seed: Casino precision dice as a set of 5 and the BitBox02 and other hardware wallets in stock at Copiaro.