Coldcard’s low-entropy bug pushes Bitcoin holders to rethink trust

In light of the catastrophic low-entropy bug in Coldcard hardware wallets, linked to publicly observed thefts beginning on July 30, Bitcoin holders have started to re-evaluate the trust assumptions in their hardware wallet setups. 

How Coldcard’s entropy flaw worked

The Coldcard devices were equipped with apparently functional STM32 “true random number generators” (TRNGs) that rely on physical processes to produce an unguessable seed phrase.

However, after Coldcard creator NVK decided to initiate a firmware rewrite to switch from a GPL-licensed free software model to a read-only model, a serious vulnerability appears to have been introduced.

Starting with firmware version 4.0.1, released in March 2021, the device used MicroPython’s Yasmarang PRNG instead of properly using the STM32 hardware RNG.

Random number generation is an unsolvable problem in computer science, which is why the generation of secure, unguessable private keys always has to rely on external physical processes to a degree. 

The use of the Yasmarang PRNG was widely characterized by analysts in the space as a pre-programmed fallback. However, Coinkite has now disputed this characterization in a recent X post: 

The conjecture that Coldcards were programmed to default to an obviously insecure method of seed generation has also sparked speculation on X about whether this was a deliberately placed backdoor. 

Investigative Bitcoin journalist Hodlnaut speculated that the bug stemmed from careless development practices and efforts to suppress errors through random changes.

Coinkite estimated that Mk2 and Mk3 devices generated seeds with 40 bits of entropy, while the Mk4, Mk5 and Q achieved around 70 bits. Both are well short of the 128 bits required for a secure 12-word seed phrase.

Ever since then, attackers have been successfully brute-forcing private keys, stealing over $100 million worth of BTC. How likely a wallet is to be found depends on whether or not additional dice entropy was added, or a BIP-39 passphrase and non-standard path were used. 

Related: Coldcard hackers transfer 64 BTC and 200 ETH to cryptocurrency mixers

Since then, James…

..

Source

Recommended For You

Leave a Reply

Your email address will not be published. Required fields are marked *

%d bloggers like this: