This vulnerability is most severe for RNG generated seeds on Mk2 and Mk3 firmware v4.0.0-v4.1.9, but Mk4 firmware v5.0.0 onward, and all production Q and Mk5 firmware, are also impacted according to Block's report.
If you generated a seed with any of these configurations, and did not generate the seed using dice rolls only, it is recommended to move funds - as soon as you can safely - to another wallet backed with a secure seed. Multisig wallets are also at risk if enough keys were generated on Coldcards and can be recovered to meet its spending threshold. Moving the vulnerable seeds to other devices does nothing. The original seeds are vulnerable so you should generate new ones.
Mk3 update is now available: https://blog.coinkite.com/entropy-technical-backgrounder/
source
"darth was right again" vibes
Where's your link to how to set up a seed phrase?
https://darthcoin.substack.com/p/bitcoin-be-your-own-bank-think-like
Zach Herbert, CEO of Foundation Devices (a ColdCard competitor) put this out a few hours ago, alleging that this problem has its roots in CC's attempt to avoid an open source license:
Meh. They've been attacking this with words forever. Are they going to withstand a targeted attack? Time will tell.
The real question is why didn't we find a truly critical error that existed for 7 ish years?
I know why I didn't find it - I didn't review all the code back when I manually reviewed and didn't notice it. I stopped using my coldcard by the time my bot-aided review set-up was productive. I never ran it on the improved system.
I wonder why Ledger's lab didn't find it. Why in one evening we find not one but 2 critical issues. It means that my surprise at Evan being surprised someone is reviewing his code, was me living in opti dream space. No one is doing shit, we're all yolobois.
So this was the precise moment of the vulnerability?
This is pretty devastating for Bitcoin. I told my wife briefly about this, and it just sounds complicated. For all the "yeah buts" out there, go try to orange pill someone after telling them what happened with Cold Card's entropy. Bitcoin self custody is difficult enough without these sorts stories. Trying to get someone to do dice rolls to create a wallet is not the kind of intro to Bitcoin 101 that makes entry level accessible.
Exactly. Yet still you have here the hur-dur purists insisting on making the exact same mistake all over again...
My better half has been convincing me to sell all day...
I think you're right though. If the only way to secure bitcoin is to roll your own entropy the number of bitcoiners diminishes.
Still it was a vulnerability, not a quantum hack.
I told my wife about it last night and she was like: who in the world would use Bitcoin?! This is never going to work!
So if you rolled dice your seed is safe?
Yes.
This is all alot to take in and stinks to see but from what im reading the dice roll saves u they tell u to do this i assume as a precaution either way im mind blown gotta go back n help my pupils pretty sure we all rolled dice for the numbers
This looks bad for self-custody, but this is not an issue of bitcoin it is an issue of bad entropy. If use singlesig also use a strong passphrase at least, or use multisig.
End of business for coinkite?
I hope coldcard and team are doing okay, but saving people from losing their life savings is the only thing that matters right now.
man i got sweeped.....
I am never ever considering buying anything from CoinKite. And luckily my funds were not drained. I do have a few old Mk3s tho but they say:
We are not planning to update Mk3 firmware at this time, so please use newer hardware or add a BIP-39 passphrase as a stopgap.I understand mistakes happen but as far as I get this would be a trivial typo fix for the firmware to make their hw usable again, because bad entropy is sort of a big deal. Instead they say "fuck you, buy a new wallet". Well I sure will - but not a Coldcard.
maybe, but you can still use the HWW you already paid for #1536709
you can re-use the wallet, correctly this time, and roll 10 dice 9.9 times. just keep your sats off the freaking exchanges
"and did not generate the seed using dice rolls only"
what is the exposure if you generated the seed on the device and then added entropy with 100 dice rolls?
Minimum exposure. I checked it manually yesterday, and @itsrealfake got to the same conclusion independently.
The low-level mechanism of how the dice rolls are built into a seed hasn't changed in 7 years.
Holy crap! Just self custody bros are going to be down so bad!