A standard d6 for generating true randomness during Bitcoin seed setup. 99 rolls = 256 bits of entropy. The defense against the Coldcard firmware RNG vulnerability.
A firmware bug in Coldcard 4.0.0 (March 2021) caused devices to skip the hardware RNG and fall back to predictable software entropy. Result: 594 BTC (~$38M) swept in 25 minutes. The fix: add your own physical randomness via dice rolls. If a user enters 99 d6 rolls during seed generation, even a fully compromised device cannot produce a guessable key. These dice are the tool.